Effective Date: October 1, 2026 Last Updated: October 1, 2026
1. Scope and Role of the Parties
This Data Processing Addendum (“DPA”) forms part of the IO Global Supplier Terms between IO Global Group, Inc., a Delaware corporation (“IO Global,” “we,” “us,” “Processor”), and the Supplier accepting those terms (“you,” “Customer,” “Controller”).
This DPA applies only where IO Global processes personal data on your behalf and on your instructions — specifically, personal data contained in contact lists, customer records, CRM data, or similar material that you upload into a Supplier workspace on the Platform (“Customer Personal Data”).
This DPA does not apply to:
- Personal data of your own personnel that you provide to open and administer your account. IO Global is an independent controller of that data, and its Privacy Policy applies.
- Buyer contact data disclosed to you when a Buyer contacts you through the Platform. IO Global and you are joint controllers of that disclosure under Article 26 of the GDPR, as set out in Section 5.2 of the Supplier Terms, not controller and processor.
- Platform usage, analytics, security, and billing data. IO Global is an independent controller of that data.
Where the roles in a given activity are unclear, the parties will determine them by reference to who actually determines the purposes and essential means of the processing, not by reference to how a document labels them.
2. Definitions
“Data Protection Law” means all laws applicable to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); the UK GDPR and the Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection; and applicable U.S. state privacy laws including the California Consumer Privacy Act as amended (“CCPA”).
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processing,” and “Supervisory Authority” have the meanings given in the GDPR. “Business,” “Service Provider,” “Sell,” and “Share” have the meanings given in the CCPA.
“Subprocessor” means any processor engaged by IO Global to process Customer Personal Data.
3. Processing Instructions
IO Global will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law to which it is subject — in which case IO Global will inform you of that requirement before processing, unless the law prohibits it.
Your instructions are: this DPA, the Supplier Terms, and your use of the Platform’s features and configuration settings.
IO Global will immediately inform you if, in its opinion, an instruction infringes Data Protection Law.
IO Global will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than performing the services, retain, use, or disclose it outside the direct business relationship between the parties, or combine it with personal data received from another source except as permitted by the CCPA. IO Global certifies that it understands and will comply with these restrictions.
4. Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the IO Global platform Supplier workspace |
| Duration | The term of your Supplier account, plus the retention period in Section 10 |
| Nature and purpose | Hosting, storage, organization, structuring, retrieval, display, transmission, backup, and deletion of Customer Personal Data so that you can manage your contacts and communications through the Platform |
| Types of personal data | Business contact details — name, job title, employer, business email, business telephone, business address — and correspondence, notes, and activity records you associate with those contacts |
| Categories of data subjects | Your customers, prospects, business contacts, and their personnel |
| Special categories | None. You will not upload special category data or criminal offence data to the Platform |
5. Confidentiality
IO Global will ensure that every person authorized to process Customer Personal Data is bound by an appropriate obligation of confidentiality, is subject to access controls limiting access to what their role requires, and has received data protection training.
6. Security
IO Global will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
Those measures include, at minimum:
- encryption of personal data in transit and at rest;
- role-based access controls and multi-factor authentication for administrative access;
- logical separation of each customer’s data;
- logging and monitoring of access to production systems;
- regular vulnerability scanning and periodic penetration testing;
- documented change management and secure development practices;
- backup and disaster recovery with tested restoration procedures;
- personnel screening and security training; and
- a documented incident response plan, tested at least annually.
IO Global will not materially reduce the overall security of the Platform during the term.
7. Subprocessors
General authorization. You give IO Global general written authorization to engage Subprocessors. A current list of Subprocessors, including their names, locations, and the processing they perform, is published at ioglobalgroup.com/legal/subprocessors.
Notice and objection. IO Global will give you at least 30 days’ notice before adding or replacing a Subprocessor, by updating that page and, where you have subscribed to notifications, by email. You may object on reasonable grounds relating to data protection within 15 days of the notice. If you object, the parties will discuss in good faith; if no resolution is reached, you may terminate the affected part of the services without penalty and receive a pro-rata refund of prepaid fees.
Flow-down and liability. IO Global will impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to you for each Subprocessor’s performance.
8. Assistance to the Controller
IO Global will:
- Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. Where IO Global receives such a request directly, it will not respond on the substance and will refer the data subject to you and notify you within 5 business days.
- Article 32 to 36 assistance. Assist you in ensuring compliance with your obligations regarding security, personal data breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority, taking into account the nature of the processing and the information available to IO Global.
- Information and audits. Make available all information necessary to demonstrate compliance with Article 28 of the GDPR. On request, and no more than once in any 12-month period unless a Personal Data Breach or a Supervisory Authority direction makes a further audit necessary, IO Global will provide its most recent security documentation and respond to a reasonable security questionnaire. Where that is insufficient to demonstrate compliance, IO Global will allow for and contribute to an audit conducted by you or an independent auditor you mandate, on 30 days’ written notice, during business hours, subject to confidentiality obligations, and at your cost.
9. Personal Data Breach
IO Global will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. Where the information is not all available at once, IO Global will provide it in phases without undue further delay.
IO Global will cooperate with you and take reasonable steps as directed to assist in your investigation, mitigation, and remediation, and will not notify any third party of the breach on your behalf without your prior written consent unless required by law.
10. Deletion and Return
On termination of your Supplier account, or on your written request at any time, IO Global will delete or return Customer Personal Data at your election.
Unless you request return, IO Global will delete Customer Personal Data from production systems within 30 days of termination, and from backups within a further 90 days as backup media cycles. IO Global will not access or process Customer Personal Data remaining in backups other than to delete it or as required for disaster recovery.
IO Global may retain Customer Personal Data to the extent required by law, in which case it will continue to protect it under this DPA and will delete it when the requirement ends. IO Global will certify deletion in writing on request.
11. International Transfers
IO Global processes Customer Personal Data in the United States and in the other countries identified in the Subprocessor list.
Transfers from the EEA. Where IO Global processes Customer Personal Data that is transferred from the EEA to a country without an adequacy decision, the parties agree that the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer, with:
- Clause 7 (docking clause) applying;
- Clause 9, Option 2 (general written authorization) applying, with the notice period in Section 7 of this DPA;
- Clause 11(a) optional redress language not applying;
- Clause 17, Option 1, governed by the law of Ireland;
- Clause 18(b), courts of Ireland;
- Annex I populated by the Annex to this DPA;
- Annex II populated by Section 6 (security measures) and the Annex to this DPA;
- Annex III populated by the Subprocessor list at ioglobalgroup.com/legal/subprocessors.
Transfers from the United Kingdom. The UK International Data Transfer Addendum to the EU Standard Contractual Clauses (version B1.0) is incorporated by reference, with Tables 1 to 4 populated by the corresponding provisions of this DPA and neither party able to terminate under Section 19 of the Addendum.
Transfers from Switzerland. The Standard Contractual Clauses apply as amended for Switzerland, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, references to Member State law read as references to Swiss law, the Federal Data Protection and Information Commissioner as the competent authority, and “data subject” including legal entities until Swiss law provides otherwise.
Competent supervisory authority. For the purposes of Clause 13 of the Standard Contractual Clauses, the competent supervisory authority is the Irish Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland, on the basis that IO Global has appointed a representative in Ireland under Article 27 of the GDPR. Where you are established in the EEA, the supervisory authority of your Member State of establishment is competent instead.
Transfer risk assessments. IO Global will provide the information reasonably necessary for you to carry out a transfer risk assessment, and will implement supplementary measures where an assessment identifies them as necessary.
Order of precedence. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
12. CCPA Terms
For Customer Personal Data subject to the CCPA, you are the Business and IO Global is a Service Provider. IO Global will comply with the obligations in Section 3 of this DPA, will comply with applicable CCPA obligations, and will provide the same level of privacy protection the CCPA requires of a Business.
You may take reasonable and appropriate steps to ensure IO Global uses Customer Personal Data consistently with your CCPA obligations, and to stop and remediate any unauthorized use. IO Global will notify you if it determines it can no longer meet these obligations.
13. General
Term. This DPA takes effect when you accept the Supplier Terms and continues for as long as IO Global processes Customer Personal Data.
Liability. Each party’s liability under this DPA is subject to the limitations in Section 15 of the Platform Terms, except where Data Protection Law does not permit those limitations.
Precedence. In the event of a conflict between this DPA and the Supplier Terms or Platform Terms, this DPA prevails as to the processing of Customer Personal Data.
Governing law. This DPA is governed by the law stated in Section 13.5 of the Platform Terms, except where the Standard Contractual Clauses specify otherwise.
Changes. IO Global may update this DPA to reflect changes in Data Protection Law or in the services, on 30 days’ notice, provided the update does not materially reduce the protections it provides.
14. Contact
IO Global Group, Inc. A Delaware corporation 500 S Main St, #800 Orange, CA 92868 United States
privacy@ioglobalgroup.com · legal@ioglobalgroup.com · 877.550.3600
Annex — Standard Contractual Clauses, Annexes I and II
Annex I(A) — List of Parties
Data exporter (Controller)
| Field | Detail |
|---|---|
| Name | The Supplier accepting the IO Global Supplier Terms, as identified in its Platform account |
| Address | As stated in the Supplier’s Platform account |
| Contact person | The account administrator named in the Supplier’s Platform account, or the data protection contact the Supplier notifies to privacy@ioglobalgroup.com |
| Activities relevant to the transferred data | Uploading and managing its own contact lists, customer records, and CRM data within a Supplier workspace on the IO Global platform |
| Role | Controller |
| Signature and date | Acceptance of the Supplier Terms, of which this DPA forms part, on the date recorded in the Supplier’s Platform account |
Data importer (Processor)
| Field | Detail |
|---|---|
| Name | IO Global Group, Inc., a Delaware corporation |
| Address | 500 S Main St, #800, Orange, CA 92868, United States |
| Contact person | Data Protection Contact — privacy@ioglobalgroup.com, 877.550.3600 |
| Activities relevant to the transferred data | Hosting, storage, organization, retrieval, display, transmission, backup, and deletion of Customer Personal Data in the course of providing the IO Global platform |
| Role | Processor |
| Signature and date | Acceptance of the Supplier Terms by the data exporter, on the date recorded in the Supplier’s Platform account |
Annex I(B) — Description of the Transfer
| Item | Detail |
|---|---|
| Categories of data subjects | The Supplier’s customers, prospects, and business contacts, and the personnel of those organizations |
| Categories of personal data | Business contact details — name, job title, employer, business email, business telephone, business address — and correspondence, notes, and activity records the Supplier associates with those contacts |
| Sensitive data | None. The Supplier undertakes not to upload special category data or criminal offence data |
| Frequency of the transfer | Continuous, for the duration of the Supplier’s account |
| Nature of the processing | Hosting, storage, organization, structuring, retrieval, display, transmission, backup, and erasure |
| Purpose of the processing | Providing the Supplier workspace and related features of the IO Global platform |
| Retention period | The term of the Supplier’s account, plus the deletion periods in Section 10 of this DPA |
| Subprocessor transfers | As set out in the Subprocessor list at ioglobalgroup.com/legal/subprocessors, for the subject matter, nature, and duration stated there |
Annex I(C) — Competent Supervisory Authority
The Irish Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland — or, where the data exporter is established in the EEA, the supervisory authority of its Member State of establishment.
Annex II — Technical and Organizational Measures
The measures set out in Section 6 of this DPA, which the data importer undertakes to maintain for the duration of the processing, together with:
| Area | Measure |
|---|---|
| Pseudonymization and encryption | Encryption of personal data in transit using TLS 1.2 or above, and at rest using AES-256 or equivalent |
| Confidentiality of systems | Role-based access control, least-privilege provisioning, multi-factor authentication for administrative access, and logical separation of each customer’s data |
| Integrity of systems | Change management, secure development practices, and integrity monitoring of production systems |
| Availability and resilience | Redundant infrastructure, backup with tested restoration procedures, and a documented disaster recovery plan |
| Restoring availability | Backup restoration testing at least annually |
| Testing and evaluation | Regular vulnerability scanning, periodic penetration testing, and periodic review of the measures in this Annex |
| User identification and authorization | Unique user accounts, joiner-mover-leaver process, and periodic access review |
| Protection during transmission and storage | As stated above under encryption, plus restricted egress and monitored transfer channels |
| Physical security | Processing in facilities operated by cloud providers holding recognized independent security certifications |
| Event logging | Logging and monitoring of access to production systems, with logs retained in accordance with Section 9 of the Privacy Policy |
| System configuration | Hardened baseline configurations and periodic configuration review |
| Governance and management | Documented information security policies, personnel screening, security training, and a documented incident response plan tested at least annually |
| Certification and assurance | Security documentation made available under Section 8 of this DPA |
| Data minimization and quality | Processing limited to the categories in Annex I(B), on the exporter’s documented instructions |
| Accountability | Records of processing, subprocessor register, and the audit rights in Section 8 |
| Measures for subprocessors | Flow-down of obligations no less protective than this DPA, under Section 7 |