partners dpa.pdf
Data Processing Addendum
Check Point Software Technologies Ltd, of Shlomo Kaplan, Tel-Aviv, Israel (“Check Point”) and you, an authorized distributor or authorized reseller of Check Point and the entity you represent (“Partner”) agree to the terms set out in this Data Processing Addendum (this “Addendum”). This Addendum shall become effective with respect to the Partner upon the effective date of the Agreement (as defined below) (the “Effective Date”), provided that this Addendum is incorporated to the Agreement by reference.
1. Definitions
1.1 Agreement
The agreement governing Partner’s relations with Check Point as follows:
(i) with respect a Partner which is distributor, such Partner’s Distribution Agreement with Check Point; and
(ii) with respect to a Partner which is a reseller of Check Point, Check Point’s Reseller Terms, as available at Check Point’s Partner MAAP and/or Check Point’s website, and/or any other agreement signed between such Partner and Check Point;
(iii) in the absence of such agreement or terms, this Addendum shall serve as a stand-alone agreement.
1.2 Affiliate
Any entity that directly or indirectly controls, is controlled by, or is under common control with the relevant Party.
1.3 Check Point Personal Data
Personal Data provided by Check Point to Partner or generated through Check Point’s portal and provided to Partner by Check Point.
1.4 Partner Personal Data
Personal Data provided by the Partner to Check Point or generated by Check Point in connection with the offering or provision of Check Point products and services by Partner to its customers and which is used solely by Check Point for the Permitted Purposes.
1.5 Data Protection Laws
All applicable laws and regulations relating to the processing of Personal Data including the Electronic Communications Data Protection Directive (2002/58/EC) and the EU’s General Data Protection Regulation (“GDPR”) (2016/679/EC).
1.6 EU Standard Contractual Clauses
The model clauses incorporated into this Addendum under clause 9 (International Transfers of Data) for the transfer of Personal Data in the EU to third countries where the exporter is a Processor and the importer is a Sub-processor as approved by the European Commission by its Implementing Decision (EU) 2021/914 of June 04, 2021 or any additional replacement model clauses.
1.10 Sub-processor
A third Party engaged by Check Point or one of its Affiliates to undertake some or all of Check Point’s obligations under the Agreement, including but not limited to Processing of Personal Data.
1.11 UK Standard Contractual Clauses Addendum
The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses incorporated into this Addendum under clause 9 (International Transfers of Data) for the transfer of Personal Data in the UK to third countries.
2. Processing of Personal Data
2.1 Roles of the Parties
The Parties acknowledge and agree that their respective roles shall be as follows:
- With regard to the Processing of Personal Data exchanged between the Parties, which includes the order details and contact details of the Partner’s personnel, each Party acts as an independent and separate Controller.
- In relation to collaborative support services provided by Partner to its customers, each of Check Point and Partner is an independent Processor.
- For contact details of potential customers and partners, the disclosing Party shall act as a Controller, and the receiving Party shall act as Processor.
- Check Point or Check Point Affiliates may engage Sub-processors pursuant to this Addendum.
2.2 Party’s Processing of Personal Data
Each Party shall ensure that it processes Personal Data in accordance with applicable Data Protection Laws.
2.3 Check Point Processing of Personal Data
Check Point shall only Process Partner Personal Data in the following ways:
(i) Processing for the purposes of provision of Check Point products and services;
(ii) Offering and providing support or technical services;
(iii) When Partner acts as Controller, Processing to comply with reasonable instructions from the Partner;
(iv) As described in the Privacy Policy.
2.4 Partner Processing of Personal Data
Partner shall only Process Check Point Personal Data in the following ways:
(i) Processing for the purposes of provision of Check Point products and services;
(ii) Offering and providing support or technical services;
(iii) When Check Point acts as Controller, Processing pursuant to reasonable instructions from Check Point.
2.6 Data Protection Impact Assessment
Each Party shall assist the other Party with reasonable cooperation needed to fulfill obligations under the GDPR for a data protection impact assessment.
2.7 Description of the Processing
Processing by Check Point
- Subject-matter: The provision and/or offering of Check Point products and services.
- Duration: As long as necessary for provision of products and services.
- Types of Personal Data: Controlled by Partner.
- Categories of Data Subjects: Controlled by Partner.
Processing by Partner
- Subject-matter: The provision and/or offering of Check Point products and services.
- Duration: As long as necessary for provision of products and services.
- Types of Personal Data: Contact details and/or other information necessary for service.
- Categories of Data Subjects: Partner’s customers, employees, and service providers.
2.8 Rights of Data Subjects
Each Party shall promptly notify the other Party if it receives a request from a Data Subject to exercise their rights under Data Protection Laws.
3. Sub-Processors
3.1 Appointment of Sub-processors
- The Partner acknowledges that when serving as Controller, Check Point may employ Sub-processors.
- Check Point shall appoint and change Sub-processors at its discretion.
- A list of Sub-processors is available on Check Point’s website.
3.2 Objection Right for New Sub-processors
Where the Partner serves as a Processor, Check Point may object to a new Sub-processor by notifying the Partner within ten (10) business days.
4. Security
4.1 Security Controls
Each Party shall maintain appropriate technical and organizational measures for protection of Partner Personal Data.
4.2 Third-Party Certifications and Audits
Each Party shall make available to the other Party summaries of their most recent third-party certifications and/or security-related audits when requested.
4.3 Right of Audit and Inspection
Each Party agrees to cooperate and allow reasonable access to relevant books and records to ensure compliance with this Addendum.
5. Incident Notification
In case of a Personal Data Breach, the affected Party shall notify the other Party without undue delay and take reasonable efforts to remediate the breach.
7. International Transfers of Data
7.1 Transfer Mechanisms
The Parties acknowledge that Personal Data may be transferred outside the European Economic Area and/or the UK.
- Such transfers shall be subject to the Module Three Transfer terms of the Standard Contractual Clauses.
7.2 Precedence of Clauses
In the event of a conflict between the provisions of this Addendum and the Standard Contractual Clauses, the Clauses shall take precedence.
7.3 Updates to Standard Contractual Clauses
The Parties will work to enter into updated Standard Contractual Clauses as required by relevant Supervisory Authorities.
8. Agreement
This Addendum supplements the Agreement. Except as amended herein, all other terms of the Agreement shall apply. This Addendum is valid only for authorized distributors or resellers of Check Point’s products and services.