[LEGAL] — DATA PROCESSING ADDENDUM
Valar Customer Data Processing Addendum
This Customer Data Processing Addendum (“DPA”) is incorporated by reference into the Valar Terms of Use (or other agreement) governing the use of the services provided by Valar Ltd. (the “Agreement”) entered into between you, the customer (as defined in the Agreement) (“Customer”) and Valar Ltd (“Valar”), and reflects the parties’ agreement as to the Processing of Personal Data by Valar solely on behalf of the Customer. Both parties shall be referred to as the “Parties” and each, a “Party”.
Capitalized terms not defined in this DPA shall have the meanings given to them in the Agreement.
By using the Services, Customer accepts this DPA and the person accepting this DPA on Customer’s behalf represents and warrants that they have full authority to bind the Customer. If you cannot, or do not, agree to comply with and be bound by this DPA, please do not provide Personal Data to us.
In the event of any conflict between certain provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement solely with respect to the Processing of Personal Data. In the event of any conflict between this DPA and its Schedules, the Schedules shall, in respect of the matters governed by them, prevail over the main body of this DPA.
See also our Terms of Service and Privacy Policy.
Definitions
For the purposes of this DPA, the following terms shall have the meanings set out below.
- “Affiliate”
- means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
- “Authorized Affiliate”
- means any of Customer’s Affiliates that is permitted to use the Services pursuant to the Agreement between Customer and Valar but has not signed its own agreement with Valar and is not a “Customer” as defined under the Agreement.
- “CCPA”
- means the California Consumer Privacy Act of 2018, Cal. Civ. Code Sections 1798.100 et seq. (as amended by the California Privacy Rights Act) and its implementing regulations, each as amended or superseded from time to time.
- “Completion Window”
- means the maximum period within which Valar undertakes to return the first token following receipt of a Prompt, as selected by Customer for each request through the completion window parameter of the API, ranging from real-time execution to a maximum of twelve (12) hours.
- “Controller, Member State, Processor, Processing, Supervisory Authority”
- means have the same meanings as in the GDPR.
- “Customer Personal Data”
- means Personal Data Processed by Valar solely on behalf of Customer under this DPA and the Agreement. References in this DPA to “Personal Data” shall, in context, mean Customer Personal Data.
- “Data Incident”
- means the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by Valar on behalf of the Customer.
- “Data Protection Laws”
- means all applicable and binding privacy and data protection laws and regulations, including those of the European Union, the European Economic Area and their Member States, Switzerland, the United Kingdom, the United States of America, and Israel, as applicable to the Processing under this DPA, including (without limitation) the GDPR, the UK GDPR, CCPA, PPL, and the FADP, each as amended or superseded from time to time.
- “Data Subject”
- means the identified or identifiable person to whom the Personal Data relates.
- “Data Subject Request”
- means a request from a Data Subject to exercise rights under Data Protection Laws, including, where applicable, the rights of access, rectification, restriction of Processing, erasure, data portability, objection to Processing, and the right not to be subject to automated individual decision-making.
- “FADP”
- means the Swiss Federal Act on Data Protection of 25 September 2020.
- “GDPR”
- means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
- “Model”
- means a third-party artificial intelligence model made available through the Services and selected by Customer for the execution of a Prompt.
- “Output”
- means the content generated by a Model in response to a Prompt and returned to Customer through the Services.
- “Personal Data”
- means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable natural person.
- “PPL”
- means Israel’s Protection of Privacy Law, 5741-1981, together with the regulations promulgated thereunder (including Amendment 13 / “Tikun 13”, in force from 14 August 2025), as amended or superseded from time to time.
- “Prompt”
- means the content submitted by or on behalf of Customer to the Services for execution against a Model.
- “Security Documentation”
- means the technical and organizational measures applicable to the Services purchased by Customer, as further detailed in the Valar Trust Center accessible at https://trust.valarhq.ai/. Valar grants Customer access to the Trust Center on request.
- “Self-Managed Deployment”
- means a deployment of the Services within Customer’s own infrastructure or within a cloud environment controlled by Customer, in which Prompts and Outputs are processed within that environment.
- “Services”
- means the services provided to Customer by Valar in accordance with the Agreement.
- “Standard Contractual Clauses”
- means (a) where the GDPR applies, the standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”); and (b) where the UK GDPR applies, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B.1.0, issued by the UK Information Commissioner’s Office under the Data Protection Act 2018 (the “UK Addendum”).
- “Sub-processor”
- means any third party (including any Affiliate of Valar) that Processes Customer Personal Data under the instruction or supervision of Valar.
- “UK GDPR”
- means the UK Data Protection Act 2018, together with the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended.
- “Zero Data Retention”
- means the standing configuration of the Services under which Prompts and Outputs are not retained after the request to which they relate has been executed.
Processing of Personal Data
2.1. Roles of the Parties: The Parties acknowledge and agree that, with regard to the Processing of Customer Personal Data solely on behalf of Customer: (i) Customer is the Controller of Customer Personal Data; and (ii) Valar is the Processor of such Customer Personal Data. The terms “Controller” and “Processor” below shall, in context, signify Customer and Valar respectively. Where Customer acts as a Processor on behalf of a third-party Controller in respect of any Customer Personal Data, Customer shall be deemed the Controller for the purposes of this DPA as between the Parties, Valar shall be deemed a Sub-processor, and Part 1 of Schedule 2 shall apply accordingly.
2.2. Customer’s Processing of Personal Data: Customer, in its use of the Services and in its instructions to Valar, shall comply with Data Protection Laws. Customer shall establish and maintain any and all required lawful bases to collect, Process and transfer to Valar the Customer Personal Data, to authorize the Processing by Valar and for Valar’s Processing activities on Customer’s behalf, including providing all required notices to, and (where required) obtaining all required consents from, Data Subjects.
2.3. Valar’s Processing of Personal Data: When Processing Customer Personal Data on Customer’s behalf under the Agreement, Valar shall Process such Personal Data only for the following purposes (the “Permitted Purposes”): (i) Processing in accordance with the Agreement and this DPA; (ii) Processing for Customer as part of Valar’s provision of the Services; (iii) Processing to comply with Customer’s reasonable and documented instructions, where those instructions are consistent with the Agreement; and (iv) Processing as required under laws applicable to Valar, or as required by a court of competent jurisdiction or another competent governmental or semi-governmental authority, provided that Valar shall (unless prohibited by such law or order on important grounds of public interest) inform Customer of the legal requirement before Processing.
Valar shall inform Customer without undue delay if, in Valar’s opinion, an instruction for the Processing of Customer Personal Data given by Customer infringes applicable Data Protection Laws. To the extent Valar cannot comply with an instruction from Customer, Valar (i) shall inform Customer with relevant details, (ii) may, without liability to Customer, temporarily cease all Processing of the affected Personal Data (other than securely storing it) and/or suspend Customer’s access to the affected part of the Services, and (iii) if the Parties cannot agree on a resolution and the costs thereof, Customer may terminate the Agreement and this DPA with respect to the affected Processing, paying only for the Services actually provided up to the date of termination.
2.4. Details of the Processing: The subject matter of the Processing of Customer Personal Data by Valar is the performance of the Services pursuant to the Agreement and the Permitted Purposes. The duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects Processed under this DPA are further specified in Schedule 1 (Details of the Processing).
2.5. CCPA Terms: If Customer is a Business under the CCPA, and Valar Processes Personal Data hereunder that is subject to the CCPA, the terms set forth in Schedule 3 (CCPA Terms) hereto shall apply and bind the Parties with regards to such Personal Data and the Processing thereof.
2.6. Israel PPL Terms: If and to the extent Valar Processes Customer Personal Data subject to the PPL on Customer’s behalf, the terms set forth in Schedule 4 (Israel PPL Supplement) hereto shall apply and bind the Parties with regards to such Personal Data and the Processing thereof.
2.7. No Training or Model Development: Valar shall not, and shall not permit any Sub-processor to, use Customer Personal Data to train, fine-tune, or otherwise develop or improve artificial intelligence or machine learning systems.
2.8. Zero Data Retention: Prompts and Outputs are not retained after the request to which they relate has been executed. Prompts submitted for real-time execution are not written to persistent storage. Prompts submitted with a deferred Completion Window are held in queue storage only until the request has been executed, and in no case for more than twelve (12) hours from receipt, following which they are deleted. Outputs are returned to Customer and are not retained after delivery.
2.9. Self-Managed Deployments: Where the Services are provided as a Self-Managed Deployment, Valar does not receive, store or otherwise Process Prompts or Outputs, and this DPA applies only to Personal Data Processed by Valar in connection with account administration, support and the operational telemetry described in Schedule 1.
Data Subject Requests
Taking into account the nature of the Processing, Valar shall (to the extent legally permitted) notify Customer or refer the Data Subject to Customer if Valar receives a Data Subject Request relating to Customer Personal Data. Valar shall assist Customer by appropriate technical and organizational measures, insofar as this is possible and reasonable, in fulfilling Customer’s obligation to respond to a Data Subject Request under Data Protection Laws. Where appropriate, Valar may advise Data Subjects of the self-service features available within the Services.
Valar’s assistance under this Section 3 is limited to the information and means reasonably available to it.
Confidentiality
Valar shall ensure that personnel, contractors and advisors engaged in the Processing of Customer Personal Data have committed themselves to confidentiality obligations at least as protective as those set forth in this DPA and the Agreement, or are under an appropriate statutory obligation of confidentiality, and that access to Customer Personal Data is granted on a need-to-know basis.
Sub-processors
5.1. General Authorization: Customer provides Valar with general written authorization to engage Sub-processors for the Processing of Customer Personal Data, subject to the conditions set out in this Section 5.
5.2. Current List and Notice of New Sub-processors: Valar makes available to Customer the current list of Sub-processors used to Process Customer Personal Data, including the identities and locations of those Sub-processors and the type of service rendered, available at https://trust.valarhq.ai/ (the “Sub-processor List”). The Sub-processor List as of the date of first use of the Services by Customer is hereby deemed authorized. Valar shall notify Customer of any intended addition or replacement of a Sub-processor at least fourteen (14) days before the change takes effect, by updating the Sub-processor List page and providing email notification to Customers subscribed to sub-processor change notifications via the Valar Trust Center.
5.3. Objection to new Sub-processors: Customer may reasonably object to Valar’s use of a new Sub-processor for reasons relating to the protection of Customer Personal Data by notifying Valar in writing within thirty (30) days after receipt of Valar’s notice. The objection shall include the reasons for it. Failure to object within such timeframe shall be deemed acceptance. Where Customer objects, Valar shall use reasonable efforts to make available a change in the Services or recommend a commercially reasonable change to Customer’s configuration to avoid Processing by the objected-to Sub-processor without unreasonably burdening Customer. If Valar cannot make such change available within thirty (30) days of Customer’s written objection, Customer may terminate the Agreement and this DPA with respect to those Services that cannot be provided without the objected-to Sub-processor, on written notice, paying only for the Services actually provided up to the date of termination. Until a decision is made, Valar may, upon written notice to Customer, temporarily suspend the Processing of the affected Personal Data and/or Customer’s access to the affected Services.
5.4. Flow-down obligations: Valar (or a Valar Affiliate on Valar’s behalf) has entered into a written agreement with each Sub-processor containing, in substance, the same or materially similar data-protection obligations as those set out in this DPA. Valar shall remain responsible to Customer for the performance of any of its Sub-processor’s obligations. Valar shall ensure that no Sub-processor uses Customer Personal Data to train, fine-tune, or otherwise develop or improve artificial intelligence or machine learning systems, or for any purpose other than the provision of its services to Valar in connection with the Services.
Security and Audits
6.1. Technical and Organizational Measures: Valar shall maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data, having regard to the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing and the risk of varying likelihood and severity to the rights and freedoms of natural persons. Such measures are described in the Security Documentation and may be updated from time to time provided that the updated measures provide a level of security no lower than described in the Security Documentation.
Upon Customer’s reasonable request and at Customer’s cost, Valar shall reasonably assist Customer in ensuring compliance with Customer’s obligations under Articles 32-36 of the GDPR (and equivalent UK GDPR provisions), or any other applicable obligation in this regard, taking into account the nature of the Processing and the information available to Valar.
6.2. Audits and Inspections: Upon Customer’s fourteen (14) days’ prior written request at reasonable intervals (no more than once every twelve (12) months, except that such limitation shall not apply in the event of a Data Incident or where required by a supervisory authority), and subject to reasonable confidentiality undertakings by Customer, Valar shall, at Valar’s cost, make available to Customer (provided Customer is not a competitor of Valar) — or to Customer’s independent, reputable, third-party auditor that is not a competitor of Valar and is not in conflict with Valar, subject to the auditor’s confidentiality and non-compete undertakings — information necessary to demonstrate Valar’s compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by them, provided that:
- 6.2.1. Valar may, in the first instance, seek to satisfy this obligation by providing recent and relevant third-party certifications, attestations and audit reports; provided, however, that Customer may, acting reasonably, require on-site audit access where such certifications and audit reports do not, in Customer’s reasonable determination, adequately demonstrate compliance;
- 6.2.2. audit information, audits, inspections and the results thereof — including any documents reflecting the outcome of the audit and/or inspection — shall be used by Customer solely to assess compliance with this DPA or to comply with its contractual obligations to third parties, and shall not be used for any other purpose or disclosed to any third party without Valar’s prior written approval;
- 6.2.3. upon Valar’s first written request, Customer shall return all records and documentation in its possession or control provided by Valar in the context of the audit and/or inspection; provided that Customer may retain a copy of such records to comply with its applicable statutory and contractual obligations;
- 6.2.4. if and to the extent the Standard Contractual Clauses apply, nothing in this Section 6.2 shall vary or modify the audit rights of Customer under the Standard Contractual Clauses (which prevail in that respect);
- 6.2.5. in the event of an audit or inspections as set forth above, Customer shall ensure that it (and each of its mandated auditors) will not cause (or, if it cannot avoid, minimize) any damage, injury or disruption to Valar’s premises, equipment, personnel and business while conducting such audit or inspection; and
- 6.2.6. the audit rights set forth in this Section 6.2 shall only apply to the extent that the Agreement does not otherwise provide Customer with audit rights that meet the relevant requirements of Data Protection Laws.
Data Incident Management and Notification
7.1. Valar maintains documented security incident management policies and procedures and, to the extent required under applicable Data Protection Laws, shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Data Incident. Valar shall make reasonable efforts to identify and take such steps as Valar deems necessary and reasonable to remediate and/or mitigate the cause of the Data Incident to the extent remediation is within Valar’s reasonable control. The obligations herein shall not apply to incidents that are caused by acts or omissions of Customer or a user on its behalf and not by failure of Valar.
7.2. Valar’s Data Incident notification will include, to the extent then known and as it becomes available: (a) a description of the nature of the Data Incident, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the Data Incident, including measures to mitigate its possible adverse effects; and (d) a contact point for further information.
7.3. Customer shall not make, disclose, release or publish any finding, admission of liability, communication, notice, press release or report concerning a Data Incident that directly or indirectly identifies Valar (including in any legal proceeding or in any notification to regulatory authorities or affected individuals, but excluding disclosure to third-party advisors of Customer on a need-to-know basis and subject to appropriate confidentiality undertakings) without Valar’s prior written approval, unless and to the extent Customer is compelled to do so to comply with a mandatory regulatory requirement or Data Protection Laws. In that case (and unless prohibited by such laws), Customer shall provide Valar with reasonable prior notice and shall limit the disclosure to the minimum scope required.
7.4. Valar will promptly reimburse Customer for all reasonable costs and expenses incurred by Customer in connection with a Data Incident caused by Valar’s breach of this DPA, including costs of providing notice to supervisory authorities or affected Data Subjects, performance of audits or security testing, and any claims by affected Data Subjects (if determined appropriate by Customer or required by Data Protection Laws).
Return and Deletion of Personal Data
Prompts and Outputs. Customer Personal Data contained in Prompts and Outputs is deleted in the ordinary course of the Services in accordance with Zero Data Retention. No such Personal Data remains in Valar’s possession or control on termination or expiry of the Agreement, and no deletion request or return is required in respect of it.
In respect of any other Customer Personal Data Processed on Customer’s behalf (including account, administrative and support data), within thirty (30) days following termination or expiry of the Agreement (and subject thereto), Valar shall, at Customer’s choice (indicated by written notice to Valar), delete or return such Personal Data to Customer, and Valar shall delete existing copies unless applicable Data Protection Laws require otherwise. To the extent authorized or required by applicable law, Valar may retain a copy of the Personal Data solely for evidential purposes, for the establishment, exercise or defense of legal claims, or for compliance with legal obligations. Personal Data retained on the basis of this paragraph shall continue to be subject to the protective obligations of this DPA.
Trans-Border Data Transfers
9.1. Transfers to Countries with Adequate Protection: Personal Data may be transferred from EU Member States, the three other EEA Member Countries (Norway, Liechtenstein and Iceland) (together, the “EEA”), Switzerland and the United Kingdom (“UK”) to countries that offer an adequate level of data protection under or pursuant to the adequacy decisions published by the relevant data-protection authorities of the EEA, the European Union, the Member States or the European Commission, Switzerland and/or the UK as relevant (“Adequacy Decisions”), without any further safeguard being necessary.
9.2. Transfers to Other Countries: Where the Processing of Personal Data by Valar includes a transfer (either directly or via onward transfer) from the EEA (“EEA Transfer”), the UK (“UK Transfer”) and/or Switzerland (“Swiss Transfer”) to other countries that have not been subject to a relevant Adequacy Decision, and the transfer is not performed through an alternative recognized compliance mechanism for the lawful transfer of personal data, then: (i) the terms of Part 1 of Schedule 2 (EEA Trans-Border Transfers) shall apply to any EEA Transfer; (ii) the terms of Part 2 of Schedule 2 (UK Trans-Border Transfers) shall apply to any UK Transfer; (iii) the terms of Part 3 of Schedule 2 (Swiss Trans-Border Transfers) shall apply to any Swiss Transfer; and (iv) the terms of Part 4 of Schedule 2 (Additional Safeguards) shall apply to any such transfers.
Authorized Affiliates
10.1. Contractual Relationship: By executing or accepting this DPA, Customer enters into this DPA on behalf of itself and, as applicable, in the name and on behalf of its Authorized Affiliates, in which case each Authorized Affiliate agrees to be bound by Customer’s obligations under this DPA, if and to the extent Valar Processes Personal Data on the behalf of such Authorized Affiliate (qualifying it as the “Controller”). All access to and use of the Services by Authorized Affiliates must comply with the terms of the Agreement and this DPA and any violation by an Authorized Affiliate shall be deemed a violation by Customer.
10.2. Communication: Customer remains responsible for coordinating all communication with Valar under the Agreement and this DPA and shall be entitled to make and receive any communication in relation to this DPA on behalf of its Authorized Affiliates.
Other Provisions
11.1. Data Protection Impact Assessment and Prior Consultation: Upon Customer’s reasonable request and at Customer’s cost, Valar shall provide Customer with reasonable cooperation and assistance to fulfil Customer’s obligations under the GDPR or the UK GDPR (as applicable) to carry out a data-protection impact assessment relating to Customer’s use of the Services, to the extent Customer does not otherwise have access to the relevant information and to the extent that information is available to Valar. Valar shall provide reasonable assistance at Customer’s cost with the co-operation or prior consultation with the Supervisory Authority required by the GDPR or the UK GDPR.
11.2. Modifications to this DPA: Either Party may, on at least forty-five (45) calendar days’ prior written notice, request in writing variations to this DPA where required as a result of a change in, or decision of a competent authority under, any Data Protection Laws, to enable the Processing of Customer Personal Data to be made (or continue to be made) without breach of those Data Protection Laws. The Parties shall make commercially reasonable efforts to accommodate such variations and shall negotiate in good faith with a view to agreeing and implementing those (or alternative) variations as soon as is reasonably practicable. If the Parties are unable to reach agreement within thirty (30) days of such notice, either Party may, on written notice with immediate effect, terminate the Agreement to the extent it relates to the Services affected, paying only for the Services actually provided up to the date of termination.
Details of the Processing
Subject Matter. The subject matter of the Processing is the performance of the Services pursuant to the Agreement.
Nature and Purpose of Processing.
- Providing the Services to Customer;
- Performing the Agreement, this DPA and any other contracts executed by the Parties;
- Acting upon Customer’s instructions, where such instructions are consistent with the Agreement;
- Sharing Customer Personal Data with third parties in accordance with Customer’s instructions and/or pursuant to Customer’s use of the Services;
- Complying with applicable laws and regulations; and
- Performing all tasks related to any of the above and in accordance with the DPA and the Agreement.
Duration and Frequency.
- Prompts and Outputs: Processed continuously and on demand, on receipt of each request, for the duration of the Agreement. Retained in accordance with Zero Data Retention.
- Account, administrative and support data: Processed for the duration of the Agreement and deleted or returned in accordance with Section 8.
- Usage and log data: Processed for the duration needed for the provision of the Services under the Agreement and this DPA.
Type of Personal Data. The Personal Data Processed under this DPA falls into three categories. The extent and nature of the Personal Data contained in Prompts is determined and controlled by Customer in its sole discretion.
- Personal Data that Customer or its users choose to include in a Prompt, or that a Model generates in an Output.
- Account and administrative data (e.g. names, business email addresses, authentication identifiers and credentials).
- Usage and log data (e.g. API request metadata, IP addresses, logs, metrics).
Categories of Data Subjects.
- Customer’s administrative users, developers and other personnel who access or use the Services.
- Natural persons whose Personal Data is contained in a Prompt or an Output depending on the use case Customer implements.
Sensitive Categories of Personal Data. Valar does not require, request or intentionally Process special categories of Personal Data within the meaning of Article 9 of the GDPR, or any other category of Personal Data subject to heightened legal requirements. Customer determines, in its sole discretion, whether to include such data in a Prompt, and is responsible for establishing its lawful basis and for any additional notices or consents required.
Where Customer intends to submit Personal Data subject to sector-specific requirements, Customer shall notify Valar in advance and the Parties shall enter into any further agreement required by applicable law before such data is submitted to the Services.
Trans-Border Data Transfers
Part 1 — EEA Trans-Border Transfers. The Parties agree as follows:
- the EU SCCs are hereby incorporated by reference and shall apply to any EEA Transfer as set out in this Part 1;
- Module Two (Controller to Processor) of the EU SCCs shall apply where the EEA Transfer is made by Customer as data controller and Valar as data processor of the Personal Data;
- Module Three (Processor to Processor) of the EU SCCs shall apply where the EEA Transfer is made by Customer as data processor and Valar as a sub-processor of the Personal Data;
- Module Four (Processor to Controller) of the EU SCCs shall apply where the EEA Transfer is made by Valar as data processor and Customer as data controller of the Personal Data, and Customer is not subject to the GDPR in respect of that Processing;
- Clause 7 (Docking Clause) of the EU SCCs shall not apply;
- Option 2: GENERAL WRITTEN AUTHORISATION in Clause 9 of the EU SCCs shall apply, with the time period for prior notice of Sub-processor changes being as set out in Section 5.2 of the DPA;
- in Clause 11 of the EU SCCs, the optional language shall not apply;
- in Clause 17 of the EU SCCs, Option 1 shall apply, and the Parties agree that the EU SCCs shall be governed by the laws of the Republic of Ireland;
- in Clause 18(b) of the EU SCCs, disputes shall be resolved before the courts of the Republic of Ireland;
- Annex I.A (Parties): the data exporter and data importer, their contact details, the activities relevant to the data transferred and the role of each are completed as set out in the tables below; signature and date are deemed effected by entry into the Agreement and this DPA;
- Annex I.B (Description of Transfer): the categories of Data Subjects, the categories of Personal Data, the frequency of transfer, the nature of the Processing, the purposes of the data transfer and further Processing, and the period for which the Personal Data will be retained, are described in Schedule 1 to this DPA. In relation to transfers to Sub-processors, the subject matter, nature and duration of the Processing are described at the Sub-processor List URL set out in Section 5.2 of this DPA;
- Annex I.C (Competent Supervisory Authority): the supervisory authority in the Member State stipulated under Clause 17 / Clause 18 above shall be the competent supervisory authority;
- Annex II (Technical and Organizational Measures): the Security Documentation referred to in this DPA serves as Annex II of the EU SCCs; and
- to the extent of any conflict between the EU SCCs and any other terms of this DPA or the Agreement, the EU SCCs shall prevail.
EU SCCs Annex I.A — Parties.
Data Exporter
- Name: Customer.
- Contact details: as detailed in the Agreement.
- Activities: as in Schedule 1.
- Role: data controller.
- Signature/date: deemed effected by entry into the Agreement and DPA.
Data Importer
- Name: Valar Ltd.
- Address: Hasolelim Street 17, Tel Aviv, Israel.
- Contact: privacy@valarhq.ai
- Activities: as in Schedule 1.
- Role: data processor. Signature/date: deemed effected by entry into the Agreement and DPA.
Data Exporter
- Name: Customer.
- Role: data processor.
- Other details: as for Module Two.
Data Importer
- Name: Valar Ltd.
- Role: data processor, acting as Sub-processor of Customer.
- Other details: as for Module Two.
Data Exporter
- Name: Valar Ltd.
- Role: data processor.
- Other details: as for Module Two.
Data Importer
- Name: Customer.
- Role: data controller.
- Other details: as for Module Two.
Part 2 — UK Trans-Border Transfers. The UK Addendum is hereby incorporated by reference and shall apply to UK Transfers as set out in this Part 2, together with the EU SCCs as set out in Part 1.
- Table 1 (Parties): as stipulated in Annex I.A of Part 1;
- Table 2 (Selected SCCs, Modules and Selected Clauses): as stipulated in Part 1;
- Table 3 (Appendix Information): Annex 1A — as stipulated in Annex I.A of Part 1; Annex 1B — as stipulated in the Annex I.B paragraph of Part 1; Annex II — as stipulated in the Annex II paragraph of Part 1; Annex III — as set forth at the Sub-processor List URL detailed in Section 5.2 of this DPA; and
- Table 4 (Ending the Addendum when the Approved Addendum Changes): neither Party may end the UK Addendum in the manner set out in Section 19 of the Mandatory Clauses of the UK Addendum.
Part 2 (Mandatory Clauses) of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament under section 119A of the Data Protection Act 2018 on 2 February 2022 (as it may be revised under Section 18 of those Mandatory Clauses), shall apply.
Part 3 — Swiss Trans-Border Transfers. The Parties agree that the EU SCCs in Part 1, as adjusted below, shall apply where the FADP applies to Swiss Transfers:
- references to the Standard Contractual Clauses mean the EU SCCs as amended by this Part 3;
- the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) shall be the sole Supervisory Authority for Swiss Transfers exclusively subject to the FADP;
- references to the GDPR or Regulation (EU) 2016/679 in the EU SCCs shall be interpreted to include the FADP with respect to Swiss Transfers;
- references to Regulation (EU) 2018/1725 are removed;
- Swiss Transfers subject to both the FADP and the GDPR shall be dealt with by the FDPIC insofar as the Swiss Transfer is governed by the FADP, and by the EU Supervisory Authority named in Part 1 insofar as it is governed by the GDPR;
- references to the “Union”, “EU” and “EU Member State” shall not be interpreted to exclude Data Subjects in Switzerland from the possibility of exercising their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs;
- where Swiss Transfers are exclusively subject to the FADP, all references to the GDPR in the EU SCCs are to be understood as references to the FADP; and
- where Swiss Transfers are subject to both the FADP and the GDPR, all references to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the Swiss Transfer is subject to the FADP.
Part 4 — Additional Safeguards. In the event of an EEA Transfer, UK Transfer or Swiss Transfer, the Parties supplement Parts 1-3 with the following safeguards and representations:
- Valar shall maintain, in accordance with good industry practice, measures to protect the Personal Data from interception, including in transit between Customer and Valar and between different systems and services. These measures include network protection intended to deny attackers the ability to intercept data, and encryption of Personal Data in transit and at rest intended to deny attackers the ability to read the data;
- Valar shall make commercially reasonable efforts to resist, subject to applicable law, any request for bulk surveillance relating to the Personal Data protected under the GDPR or the UK GDPR, including under section 702 of the United States Foreign Intelligence Surveillance Act (“FISA”);
- If Valar becomes aware that any government authority (including a law-enforcement authority) wishes to obtain access to or a copy of any Personal Data — whether on a voluntary or mandatory basis — then, unless legally prohibited or under a mandatory legal compulsion that requires otherwise, Valar shall (i) inform the relevant authority that Valar is a processor of the Personal Data and that the Controller has not authorized Valar to disclose the Personal Data, and direct any request to the Controller in writing; and (ii) use commercially reasonable legal mechanisms to challenge any such demand, recognizing that challenge may not always be reasonable or possible in light of the nature, scope, context and purposes of the intended access; and
- No more than once every twelve (12) months and only at Customer’s written request, Valar shall inform Customer of the types of binding legal demands for Personal Data it has received (to the extent permitted by law), including national-security orders and directives, including any process issued under section 702 of FISA.
CCPA Terms
1. Scope, Application & Interpretation.
- 1.1 This Schedule 3 shall apply and bind the Parties if and to the extent that (i) Customer is a Business under the CCPA, and (ii) Valar Processes Personal Information (as defined below) that is subject to the CCPA in the course of providing the Services to Customer pursuant to the Agreement.
- 1.2 This Schedule 3 prevails over any conflicting terms of the Agreement or the DPA but does not otherwise modify the Agreement or the DPA.
- 1.3 This Schedule 3 shall be interpreted in favor of the Parties’ intent to comply with the CCPA, and therefore any ambiguity shall be resolved in favor of a meaning that complies and is consistent with the CCPA.
- 1.4 Capitalized terms not specifically defined herein shall have the meanings ascribed to them in the DPA, as amended by this Schedule 3.
2. Definitions. For the purposes of this Schedule 3:
- 2.1 The terms “Business”, “Collects” (and “collected” and “collection”), “Consumer”, “Business Purpose”, “Sell” (and “selling”, “sale”, and “sold”), “Share” (and “shared”, or “sharing”), and “Service Provider” shall each have the same meaning as in the CCPA.
- 2.2 “Personal Information” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable Consumer or household of a Consumer, which is processed by Valar solely on behalf of Customer under this Schedule 3 and the Agreement.
3. Processing of Personal Information.
- 3.1 Customer hereby appoints Valar as a Service Provider to Process Personal Information on behalf of Customer. Customer, in its use of the Services, and Customer’s instructions to Valar, shall comply with the CCPA. Customer represents and warrants that it has provided notice consistent with Section 1798.135 of the CCPA, and has obtained consents to the extent required under the CCPA for Valar to lawfully Collect and Process the Personal Information in pursuit of the permitted purposes (as defined in Section 3.2 below).
- 3.2 Valar shall Process Personal Information solely for the purposes set forth in Section 2.3 of the DPA and as necessary to comply with this Schedule 3 and the CCPA (“Permitted Purposes”).
- 3.3 Sections 3-8 and 11.2 of the DPA shall apply to the Processing of Personal Information and the following terms shall be replaced as follows: “Data Protection Laws” shall mean the CCPA; “DPA” shall mean this Schedule 3; “Personal Data” shall mean “Personal Information”; “Data Subject” shall mean “Consumer”; “Controller” shall mean “Business”; “Processor” shall mean “Service Provider”; and Sub-processor shall refer to the concept of a Service Provider engaged by Valar to Process Personal Information.
- 3.4 Valar shall Process Personal Information in accordance with the provisions of the CCPA, and in a manner that provides the same level of privacy protection to Personal Information as required by the CCPA. Valar certifies that it understands the rules, requirements, and definitions of the CCPA and this Schedule 3, and shall comply with them.
- 3.5 Valar acknowledges and confirms that it does not receive or process any Personal Information as consideration for any services or other items that Valar provides to Customer under the Agreement. Valar agrees to refrain from Selling and/or Sharing any Personal Information Processed hereunder without Customer’s prior written consent, nor taking any action that would cause any transfer of Personal Information to or from Valar under the Agreement or this Schedule 3 to qualify as Selling and/or Sharing such Personal Information. Valar shall not have, derive, or exercise any rights or benefits regarding the Personal Information, and shall not retain, use, or disclose any Personal Information (i) for any purpose other than the Permitted Purposes, and/or (ii) outside of the direct business relationship between the Parties.
- 3.6 Valar shall not combine Personal Information with any other data if and to the extent that this would be inconsistent with the limitations on Service Providers under the CCPA.
- 3.7 Valar shall notify Customer if Valar makes a determination that it can no longer meet its obligations under this Schedule 3 and/or the CCPA.
Israel PPL Supplement
1. Application. This Supplement forms part of, and is Schedule 4 to, the DPA and it applies to the extent Valar Processes Personal Data subject to the PPL on behalf of Customer in the course of providing the Services. It supplements and, in the event of a conflict, prevails over the main body of the DPA in respect of the matters it governs.
2. Definitions. Capitalized terms used but not defined in this Supplement have the meanings given to them in the DPA. The terms “Authorized User”, “Data Security Procedure”, “Database Systems”, “Monitoring Mechanism”, “Risk Assessment” and “Security Incident” have the meanings given to them under Israel’s Protection of Privacy Regulations (Data Security), 5777-2017 (the “Information Security Regulations”). “PPL” means Israel’s Protection of Privacy Law, 5741-1981, together with the regulations promulgated thereunder (including Amendment 13 / “Tikun 13”, in force from 14 August 2025), as amended or superseded from time to time. “Database” means a collection of Personal Data Processed by digital means by Valar solely on behalf of Customer. “Database Controller” and “Holder” have the meanings given to them under the PPL.
3. Roles. For the purposes of the PPL, Customer is the Database Controller of Customer Personal Data and Valar is the Holder, Processing it solely on Customer’s behalf; Valar’s Sub-processors are sub-Holders. Sections 2 to 8, 10 and 11.2 of the DPA apply to such Processing, with “Controller” construed as “Database Controller”, “Processor” as “Holder”, “Data Protection Laws” as the PPL and “Data Incident” as including a Security Incident.
4. Information Security. Valar implements and maintains technical and organizational measures satisfying the requirements of the Information Security Regulations applicable to the security level of the relevant Database, including: a Data Security Procedure; up-to-date documentation of the Database structure and inventory of Database Systems, accessible on a need-to-know basis; periodic Risk Assessments and penetration tests, with findings remediated; retention of Monitoring Mechanism records as required by law; controls restricting portable devices and securing remote access, including appropriate authentication of Authorized Users; and restorable backups. The Security Documentation referred to in Section 6.1 of the DPA applies to such Processing.
5. Cross-Border Transfers from Israel. Personal Data originating from Israel to a jurisdiction outside Israel shall only be transferred in compliance with Israel’s Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001 and any successor regime adopted under Amendment 13.
6. Data Subject Rights and Direct Mailing. Valar shall assist Customer (as Database Controller) in responding to inspection, rectification and erasure requests under the PPL, and shall not engage in “direct mailing” within the meaning of section 17C of the PPL using Customer Personal Data without Customer’s prior written instruction.
7. Reporting and PPA Notification. Without limiting Section 6.2 of the DPA, Valar shall, on Customer’s written request, report to Customer at least annually on the performance of its obligations under this Supplement, and shall support Customer’s compliance with any notification obligations to the Privacy Protection Authority and to Data Subjects under the PPL.