Version 2.0 · Effective September 2, 2026 · Supersedes the version dated 30 June 2018
This Data Processing Agreement (the "DPA") records the terms on which Cense Data, Inc. DBA LicenseSpring Software ("Company", "we", "us") processes personal information on behalf of its customers. It is the written agreement required by Article 28(3) of the General Data Protection Regulation.
How this DPA applies to you. This DPA forms part of, and is incorporated into, the agreement under which Company provides the LicenseSpring software licensing platform and related services to you (the "Agreement"), whether that agreement is Company's Terms of Service or a signed Master Software Licensing Agreement. In this DPA, "Licensee" means the entity that has entered into the Agreement with Company. Where the Parties have signed a separate data processing agreement, that signed agreement prevails over this DPA in relation to the Agreement it forms part of.
Signed copy. A countersigned copy of this DPA, and where required a signed set of the Standard Contractual Clauses, is available on request from privacy@licensespring.com.
Changes. Company may update this DPA. Company will give Licensee at least thirty (30) days' notice of a change through the notification mechanism described in Sect. 5.2, and will publish the version number and effective date on this page. A change takes effect only prospectively, and only where the updated version is no less protective of Licensee and of data subjects than the version it replaces. Where an update is required to comply with a change in Data Protection Laws, it takes effect on the date that change becomes applicable.
Annexes. Annex 1 (Contact persons); Annex 2 (Details of the Processing); Annex 3 (Technical and organisational measures); Annex 4 (Approved Sub-processors); Annex 5 (Standard Contractual Clauses and completed Appendix). Each Annex forms an integral part of this DPA.
1.1 Scope. Under the Agreement, Company provides the LicenseSpring software licensing platform and the associated software development kits, application programming interfaces and support and maintenance services (together, the "Services") to Licensee. In providing the Services, Company Processes Personal Data on behalf of Licensee.
1.2 Purpose. This DPA is the written agreement required by Article 28(3) GDPR and records the Parties' respective obligations in relation to that Processing.
1.3 Capitalised terms. Capitalised terms used but not defined in this DPA have the meanings given to them in the Agreement.
1.4 Incorporation. This DPA is incorporated into and forms part of the Agreement. The Parties agree that this DPA is included within the entire agreement between them, notwithstanding any entire agreement provision of the Agreement.
2.1 "Data Protection Laws" means Regulation (EU) 2016/679 ("GDPR") and the national laws implementing or supplementing it; the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 ("UK GDPR") together with the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); and US State Privacy Laws, in each case to the extent applicable to the Processing under this DPA, together with any binding guidance or decision of a competent Supervisory Authority, court or the European Data Protection Board, and as amended or replaced from time to time.
2.2 "Licensee Personal Data" means Personal Data that Company Processes on behalf of Licensee under the Agreement, as described in Annex 2.
2.3 "Personal Data" means information that identifies, relates to, describes, or is reasonably capable of being associated with, an identified or identifiable individual, and that Company processes on behalf of Licensee under the Agreement. It includes "personal information", "personal data" and equivalent terms as defined under Data Protection Laws.
2.4 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as applied under Annex 5. Where those clauses are replaced or amended by the European Commission, the replacement or amended clauses apply from the date they take effect and the Parties shall complete any information required in their appendix.
2.5 "Sub-processor" means any third party engaged by Company, or by a Sub-processor, to Process Licensee Personal Data.
2.6 "US State Privacy Laws" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, and its implementing regulations (together, the "CCPA"), and any other law of a state of the United States governing the processing of personal information that applies to Licensee's use of the Services.
2.7 The terms "Controller", "Data Subject", "Personal Data Breach", "Process" and "Processing", "Processor" and "Supervisory Authority" have the meanings given to them in the GDPR, and cognate terms are construed accordingly.
3.1 Roles. In respect of Licensee Personal Data, Licensee is the Controller (or, where Licensee Processes on behalf of a third party, a Processor acting for that third party) and Company is the Processor. Where Licensee acts as a Processor, Licensee warrants that it is authorised by the relevant Controller to appoint Company as a Sub-processor on the terms of this DPA.
3.2 Documented instructions. Company shall Process Licensee Personal Data only on documented instructions from Licensee, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law to which Company is subject. Where Company is subject to such a requirement, it shall inform Licensee of that legal requirement before Processing, unless the law prohibits it from doing so on important grounds of public interest.
3.3 What constitutes instructions. The Agreement, this DPA including its Annexes, and Licensee's use of the configuration options made available within the Services constitute Licensee's complete documented instructions. Any additional or different instruction requires the Parties' written agreement and, where it materially increases Company's cost or scope of work, may be subject to a reasonable charge.
3.4 Unlawful instructions. Company shall inform Licensee without undue delay if, in its opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is confirmed, amended or withdrawn.
3.5 No disclosure or own use. Company shall not sell, rent or otherwise disclose Licensee Personal Data to any third party, and shall not use Licensee Personal Data for its own purposes, other than as expressly permitted by this DPA.
3.6 No model training. Company shall not use Licensee Personal Data to train, fine-tune, develop, validate or otherwise improve any machine learning or artificial intelligence model, other than a model operating exclusively within Licensee's own tenant at Licensee's instruction and for Licensee's sole benefit.
3.7 Aggregated and anonymised data. Company may generate and use aggregated and anonymised data derived from the operation of the Services, from which no Data Subject or Licensee is identifiable and which cannot reasonably be re-identified, for the purposes of operating, securing, monitoring and improving the Services. Such data does not constitute Personal Data. Company shall not disclose such data externally in a form that identifies Licensee without Licensee's prior written consent.
3.8 Company as independent controller. Company acts as an independent Controller in respect of the limited Personal Data it Processes for its own administrative purposes, namely the business contact details of Licensee's personnel for account management, contracting, invoicing and collections, and security, fraud- and abuse-detection telemetry and records required for Company's own legal and regulatory compliance. This DPA does not apply to that Processing, which is governed by Company's Privacy Policy and by Data Protection Laws.
3.9 Licensee warranties and prohibited data. Licensee warrants that it has a lawful basis for the Processing it instructs, that it has provided all notices and obtained all consents required under Data Protection Laws, and that the Personal Data it makes available to Company is accurate and lawfully collected. Licensee shall not submit to the Services any special categories of Personal Data within the meaning of Article 9 GDPR, or Personal Data relating to criminal convictions and offences, unless the Parties have agreed additional measures in writing. Company's obligations under this DPA do not extend to data submitted in breach of this Sect. 3.9.
3.10 Additional terms under US State Privacy Laws. Where US State Privacy Laws apply, Company acts as a service provider or processor as defined in those laws. Company shall not: (i) sell or share Personal Data, including for cross-context behavioural or targeted advertising; (ii) retain, use or disclose Personal Data for any purpose other than performing the Services, or outside the direct business relationship between the Parties; or (iii) combine Personal Data with personal information received from or on behalf of any other person, or collected from Company's own interactions with individuals, except as permitted by those laws. Company certifies that it understands these restrictions and will comply with them. Licensee may take reasonable and appropriate steps to help ensure that Company uses Personal Data in a manner consistent with Licensee's obligations under US State Privacy Laws.
4.1 Access control. Company shall ensure that access to Licensee Personal Data is limited to those personnel who need access in order to perform the Services, and that each such person is subject to a binding obligation of confidentiality that survives the termination of their engagement.
4.2 Reliability and training. Company shall take reasonable steps to verify the reliability of personnel with access to Licensee Personal Data and shall ensure that they receive appropriate data protection and information security training at least annually.
5.1 General authorisation. Licensee gives Company a general written authorisation to engage Sub-processors, subject to this Sect. 5. The Sub-processors engaged as at the effective date of this DPA are those set out in the LicenseSpring Sub-processor List, which Company makes available to Licensee in accordance with Annex 4.
5.2 Notice of changes. Company shall notify Licensee in writing of any intended addition or replacement of a Sub-processor at least thirty (30) days before that Sub-processor begins Processing Licensee Personal Data, specifying its name, location and the Processing to be carried out. Notification by email to Licensee's data protection contact identified in Annex 1 satisfies this Sect. 5.2, and Company shall at the same time make the updated Sub-processor List available to Licensee. Licensee shall keep its data protection contact details current, and Company is not in breach of this Sect. 5.2 where notice fails to reach Licensee because those details are out of date.
5.3 Objection. Licensee may object to a proposed Sub-processor on reasonable grounds relating to data protection, by written notice given within that thirty (30) day period. The Parties shall discuss the objection in good faith. If Company is unable to make available a commercially reasonable alternative within thirty (30) days of the objection, Licensee may terminate the affected part of the Services on written notice, and Company shall refund any fees prepaid in respect of the terminated Services for the period after termination. This is Licensee's sole and exclusive remedy in respect of such an objection.
5.4 Flow-down. Before engaging a Sub-processor, Company shall carry out appropriate due diligence and shall impose on that Sub-processor, by written contract, data protection obligations that are in substance no less protective than those in this DPA and that meet the requirements of Article 28(3) GDPR.
5.5 Sub-processor transfers. Where the engagement involves a transfer of Licensee Personal Data outside the EEA that is not covered by an adequacy decision, Company shall put in place an appropriate transfer safeguard under Chapter V GDPR, including where applicable the Standard Contractual Clauses under the appropriate module, and shall carry out and document a transfer impact assessment.
5.6 Liability for Sub-processors. Company remains liable to Licensee for the performance of each Sub-processor's data protection obligations. On Licensee's reasonable written request, Company shall make available a copy of the data protection terms agreed with a Sub-processor, which may be redacted to protect commercial terms and other confidential information.
5.7 Confidentiality of the Sub-processor List. The Sub-processor List is Company's confidential information and is subject to the confidentiality provisions of the Agreement. Licensee may use and disclose it as reasonably necessary to assess and document Company's compliance with Data Protection Laws, including disclosure to its own controllers, professional advisers, auditors and a competent Supervisory Authority, in each case on terms of confidentiality no less protective than those in the Agreement. Nothing in this Sect. 5.7 restricts a disclosure required by law.
6.1 Canadian adequacy. Company is established in Canada. Transfers of Personal Data from the EEA to recipients in Canada that are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) are covered by the European Commission's adequacy decision of 20 December 2001 (Commission Decision 2002/2/EC), the continued adequacy of which the European Commission confirmed in its report of 15 January 2024. Company warrants that it is an organisation subject to PIPEDA in respect of its Processing of Licensee Personal Data and shall notify Licensee promptly if that ceases to be the case.
6.2 Standard Contractual Clauses. The Standard Contractual Clauses (Module Two: Controller to Processor), as applied under Annex 5, are entered into by the Parties and apply to any transfer of Licensee Personal Data from the EEA to Company to the extent, and for so long as, that transfer is not covered by an adequacy decision under Article 45 GDPR. The Parties agree that the SCCs take effect automatically, without further action by either Party, if the adequacy decision referred to in Sect. 6.1 is suspended, repealed, amended or annulled, or is held not to apply to the transfer.
6.3 Elections under the SCCs. For the purposes of the SCCs: Licensee is the data exporter and Company is the data importer; the optional docking clause at Clause 7 does not apply; Clause 9 applies with Option 2 (general written authorisation) and the notice period in Sect. 5.2 of this DPA; the optional paragraph of Clause 11(a) does not apply; Clause 17 is governed by the law of the EU Member State in which the data exporter is established, or where the data exporter is not established in an EU Member State, by the law of Ireland; Clause 18(b) designates the courts of that Member State, or where the data exporter is not established in an EU Member State, the courts of Ireland; and the Appendix to the SCCs is completed as set out in Annex 5.
6.4 United Kingdom. Where and to the extent the UK GDPR applies to a transfer, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B.1.0, in force 21 March 2022) applies as set out in Part 2 of Annex 5, and the SCCs are deemed amended accordingly.
6.5 Switzerland. Where and to the extent the FADP applies to a transfer, the SCCs apply with the following modifications: references to the GDPR are to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and references to a Member State shall not deprive Data Subjects of the right to bring proceedings in their place of habitual residence in Switzerland.
6.6 Transfer impact assessment. Company shall carry out, document and make available to Licensee on request a transfer impact assessment in respect of transfers made in reliance on the SCCs, and shall implement any supplementary technical, organisational or contractual measures reasonably required.
7.1 Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing as well as the risk to Data Subjects, Company shall implement and maintain the technical and organisational measures set out in Annex 3, which shall at all times meet the requirements of Article 32 GDPR.
7.2 Changes to measures. Company may update the measures in Annex 3 from time to time, provided that the overall level of security is not materially reduced.
7.3 Separation. Company shall ensure by technical and organisational means that Licensee Personal Data is logically separated from the data of Company's other customers and from Company's own data.
7.4 Assurance. Company shall commission independent penetration testing of the production environment at least once every twelve (12) months. On request, and not more than once in any twelve (12) month period, Company shall provide Licensee with an executive summary of the most recent penetration test report. A current description of Company's security programme is available at licensespring.com/security.
8.1 Notification. Company shall notify Licensee without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Licensee Personal Data. Notice shall be given to Licensee's data protection contact identified in Annex 1.
8.2 Content. The notification shall include, to the extent then known and thereafter as it becomes available, the information described in Article 33(3) GDPR: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and to mitigate its effects. Company shall provide updates as further information becomes available.
8.3 Remediation and co-operation. Company shall take reasonable steps to contain, investigate and remediate the breach, and shall provide Licensee with reasonable co-operation and assistance in connection with Licensee's own obligations under Articles 33 and 34 GDPR.
8.4 Reporting and communications. Licensee is responsible for any notification to a Supervisory Authority or to Data Subjects. Company shall not make any public statement identifying Licensee in connection with a Personal Data Breach without Licensee's prior written consent, save where required by law.
8.5 No admission. A notification under this Sect. 8, and any initial notification made on the basis of incomplete information, is not an acknowledgement of fault or liability by Company.
9.1 Requests received by Company. Company shall notify Licensee without undue delay of any request received directly from a Data Subject in relation to Licensee Personal Data, and shall not respond to that request itself other than to direct the Data Subject to Licensee, unless instructed to do so by Licensee or required by law.
9.2 Assistance with rights requests. Taking into account the nature of the Processing, Company shall assist Licensee by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Licensee's obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR. Where the Services provide functionality by which Licensee can itself access, correct, export or delete Licensee Personal Data, Licensee shall use that functionality in the first instance.
9.3 Impact assessments. Company shall provide reasonable assistance to Licensee with data protection impact assessments under Article 35 GDPR and with prior consultations with a Supervisory Authority under Article 36 GDPR, in each case in relation to the Processing under this DPA and taking into account the information available to Company.
9.4 Charges. Assistance under Sects. 9.2 and 9.3 that requires material effort beyond the standard functionality of the Services may be charged at Company's then-current professional services rates, notified to Licensee in advance.
10.1 Notification. If Company receives a legally binding request from a public authority, including a judicial authority, for disclosure of Licensee Personal Data, Company shall notify Licensee promptly and, where possible, before disclosure, unless prohibited by law. Where notification is prohibited, Company shall use reasonable efforts to obtain a waiver of the prohibition and shall document its efforts.
10.2 Challenge. Company shall review the legality of the request, shall challenge it where there are reasonable grounds to consider it unlawful under the law of the requesting country, under its obligations under Data Protection Laws or under its international commitments, and shall seek interim measures where appropriate. Company shall disclose the minimum amount of Personal Data permissible when responding.
10.3 Non-binding requests. Company shall not respond to any non-binding request from a third party for Licensee Personal Data without Licensee's prior written authorisation.
10.4 Record. Company shall document all such requests received and the response given, and shall make that record available to Licensee on request and to the competent Supervisory Authority.
11.1 Records. Company shall maintain a record of the Processing activities carried out on behalf of Licensee as required by Article 30(2) GDPR, and shall make it available to Licensee on reasonable written request.
11.2 Information first. Company shall make available to Licensee all information reasonably necessary to demonstrate compliance with Article 28 GDPR. Licensee shall first seek to satisfy its audit rights by reviewing Company's then-current third-party certifications, audit reports, penetration test summaries and responses to Licensee's written security questionnaire, which Company shall provide once in any twelve (12) month period on request.
11.3 Audit. Where that information is not sufficient to demonstrate compliance, Licensee, or an independent third-party auditor appointed by Licensee that is not a competitor of Company and that is bound by confidentiality obligations, may conduct an audit of Company's Processing, subject to: (i) not more than one audit in any twelve (12) month period, save where required by a Supervisory Authority or following a Personal Data Breach affecting Licensee Personal Data; (ii) at least thirty (30) days' prior written notice and an audit plan agreed in advance; (iii) the audit being carried out during Company's normal business hours, with a scope limited to the systems, records and premises relevant to the Processing of Licensee Personal Data, and in a manner that does not unreasonably disrupt Company's business; (iv) any on-site element being limited to one (1) working day; and (v) all findings being treated as Company's confidential information.
11.4 Costs. Each Party bears its own costs of the first audit in any twelve (12) month period. Company may charge its reasonable costs for any further audit, and for assistance beyond the first working day, at its then-current professional services rates, save where the audit reveals a material breach by Company of this DPA.
11.5 Remediation. Where an audit identifies a material non-compliance, Company shall remedy it at its own cost within a reasonable period agreed by the Parties.
11.6 Sub-processors. Licensee's audit rights in relation to Sub-processors are exercised through Company. On Licensee's reasonable request, Company shall exercise its own audit rights against a Sub-processor, or shall procure and provide an audit report or certification in respect of that Sub-processor.
12.1 Export. Throughout the term of the Agreement, and for the period following its termination or expiry stated in the Agreement (and where the Agreement states no such period, for thirty (30) days), Licensee may export Licensee Personal Data through the functionality made available within the Services, including the management application programming interface, in a structured, commonly used and machine-readable format.
12.2 Deletion or return. At the end of the period described in Sect. 12.1, or earlier on Licensee's written instruction, Company shall at Licensee's election delete or return all Licensee Personal Data and shall delete existing copies, including from the systems of its Sub-processors. Company shall confirm deletion in writing on request.
12.3 Exceptions. Sect. 12.2 does not apply to the extent Union, Member State or other applicable law requires Company to retain Licensee Personal Data, or to backup copies pending their expiry in the ordinary course of Company's backup cycle, which shall not exceed thirty-five (35) days. Company shall continue to protect any retained data in accordance with this DPA and shall Process it only for the purpose and duration required by that law or, in the case of backups, not at all pending deletion.
13.1 Application of the Agreement. Each Party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to the exclusions and limitations of liability set out in the Agreement, which apply to this DPA as if set out in it in full. Liability under this DPA and liability under the Agreement are aggregated for the purposes of that limit. This DPA does not create any separate, additional or uncapped liability, and no provision of this DPA constitutes an indemnity.
13.2 Mandatory rights preserved. Nothing in this DPA limits or excludes either Party's liability to a Data Subject or to a Supervisory Authority under Data Protection Laws, or the third-party beneficiary rights of Data Subjects under the SCCs.
13.3 Apportionment. Where one Party has paid compensation or an administrative fine for which the other Party is responsible under Article 82 GDPR, it may claim back from that other Party the part corresponding to that other Party's responsibility, subject to Sect. 13.1.
14.1 Duration. This DPA takes effect on the date the Agreement takes effect and continues for as long as Company Processes Licensee Personal Data, notwithstanding the expiry or termination of the Agreement.
14.2 Survival. Obligations which by their nature are intended to survive termination shall survive.
15.1 Order of precedence. In the event of a conflict, the following order of precedence applies, in each case only in relation to the Processing of Personal Data: (i) the Standard Contractual Clauses, to the extent they apply; (ii) any data processing agreement signed by both Parties; (iii) the main body of this DPA; (iv) the Annexes to this DPA; and (v) the Agreement. In all other respects the Agreement prevails over this DPA.
15.2 Variation. Either Party may propose variations to this DPA that it reasonably considers necessary to address the requirements of Data Protection Laws, and the Parties shall negotiate in good faith with a view to agreeing them. Company may update Annex 3 in accordance with Sect. 7.2 and Annex 4 in accordance with Sect. 5.2 without a formal amendment to this DPA.
15.3 Severance. If any provision of this DPA is or becomes invalid or unenforceable, the remainder is unaffected and the invalid provision shall be replaced by a valid provision that most closely reflects the Parties' original intention.
16.1 General. This DPA is governed by, and shall be construed in accordance with, the law that governs the Agreement, and the Parties submit to the jurisdiction agreed in the Agreement.
16.2 Exception. Sect. 16.1 does not apply to the Standard Contractual Clauses, which are governed by the law and subject to the jurisdiction specified in Clauses 17 and 18 of those Clauses as elected in Sect. 6.3, nor to the mandatory rights of Data Subjects under Data Protection Laws.
| Party | Role | Contact |
|---|---|---|
| Company | Data protection contact | privacy@licensespring.com |
| Company | Security contact | security@licensespring.com |
| Licensee | Data protection contact; notices under Sects. 5.2 and 8.1 | The address notified by Licensee to privacy@licensespring.com. Where Licensee has notified no address, the notice address stated in the Agreement, or failing that the email address of Licensee's primary account administrator in the LicenseSpring platform. |
| Licensee | Security contact | The address notified by Licensee to security@licensespring.com, or failing that Licensee's data protection contact above. |
Either Party may change its contacts by written notice to the other. Licensee should keep its contacts current in the LicenseSpring platform, since breach notifications under Sect. 8.1 are sent to them.
This Annex sets out the information required by Article 28(3) GDPR and constitutes Annex I.B to the Standard Contractual Clauses.
| Item | Detail |
|---|---|
| Subject matter | Provision of the LicenseSpring software licensing platform and the related software development kits, application programming interfaces and support and maintenance services under the Agreement: software licence issuance, activation, validation and compliance; customer support; anti-piracy and abuse detection; and reporting. |
| Duration | The term of the Agreement, and thereafter for the period described in Sect. 12 of this DPA. |
| Nature and purpose | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, restriction, erasure and destruction of Licensee Personal Data, in each case as necessary to provide the Services and as instructed by Licensee. |
| Categories of Data Subjects | Licensee personnel who use or administer the LicenseSpring platform; Licensee's customers and the end users of the software in which the Services are embedded; Licensee's resellers, distributors, partners and other business contacts, where Licensee records them in the Services; individuals who submit, or are referenced in, support tickets. |
| Categories of Personal Data | Identity and contact data (name, email address, company name, telephone number, postal address); account data (user identifier, role and permissions, authentication data); licence and order data (customer identifier, order reference, licence key or identifier, product and entitlement data); device and technical data (IP address, hardware identifier or device fingerprint, operating system and SDK version, installation and activation timestamps); usage and telemetry data associated with licence activation and validation; free-text content submitted by Licensee or its users in support tickets or custom fields. Most of the above is optional. Licensee determines what it transmits to the Services and can operate the Services using pseudonymous identifiers. |
| Special categories of Personal Data | None. Licensee shall not submit Article 9 data or criminal offence data to the Services (Sect. 3.9). |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Location of Processing | Hosting and primary Processing: European Union — Amazon Web Services, Ireland (eu-west-1), with database and backup replication in Germany (eu-central-1). Development, maintenance and second- and third-line support: Croatia (EU). Customer support, account administration and platform operations: Canada. Log storage, support ticketing, CRM and internal collaboration tooling: as set out in Annex 4. Where Licensee elects a single-tenant deployment, hosting takes place in the region agreed with Licensee. |
| Retention | Licensee Personal Data is retained for the duration of the Agreement and thereafter in accordance with Sect. 12. Licensee may configure shorter retention periods for specified data categories within the Services where that functionality is available. |
| Sub-processors | As set out in Annex 4, including the subject matter, nature and duration of their Processing. |
This Annex constitutes Annex II to the Standard Contractual Clauses.
| Area | Measures |
|---|---|
| Governance | Documented information security policy set and management system, reviewed at least annually and approved by management. Designated data protection contact and named security owner. Record of Processing activities maintained under Article 30(2) GDPR. Annual security and data protection awareness training for all personnel with access to Licensee Personal Data. |
| Access control — organisational | Access granted on a least-privilege, need-to-know basis and approved by the system owner. Role-based access control; separation of duties between development, deployment and administration. Multi-factor authentication mandatory for all administrative and remote access. Unique named accounts; no shared credentials; centralised secret management. Background checks on personnel with production access, to the extent permitted by law. |
| Access control — technical | Production environment segregated from development and test environments. Production access via VPN only; no direct public administrative access. Test and development environments do not contain production Licensee Personal Data. Password policy enforcing complexity, rotation on compromise, and hashing with a modern algorithm. |
| Encryption and pseudonymisation | Encryption in transit: TLS 1.2 or higher for all external connections; legacy protocols disabled. Encryption at rest: AES-256 for databases, object storage, backups and logs. Key management via AWS KMS, with restricted key access and audited use. Licence keys and offline licence files cryptographically signed. Licensee may operate the Services using pseudonymous customer and end-user identifiers. |
| Data segregation | Logical separation of each customer's data by tenant identifier, enforced at the application and database layer. Single-tenant deployment available as a separately priced option, in a region of Licensee's choosing. |
| Availability, resilience and backup | Hosting on Amazon Web Services in a multi-availability-zone configuration. Full backups taken daily with differential backups enabling point-in-time recovery; backup restoration tested at least annually. Documented business continuity and disaster recovery plan with defined recovery time and recovery point objectives, tested annually. Platform availability monitored continuously with automated alerting. |
| Logging and monitoring | Centralised, tamper-resistant logging of administrative actions, authentication events and access to Licensee Personal Data. Log retention of 365 days. Automated alerting on anomalous access and infrastructure events; alerting on production incidents on a 24/7 basis. |
| Vulnerability and patch management | Documented patch management policy, reviewed at least annually. Automated dependency and container vulnerability scanning integrated into the build and deployment pipeline. Independent third-party penetration testing of critical components at least annually; findings remediated on a risk-prioritised basis. Remediation targets: critical within 7 days, high within 30 days, medium in the next scheduled release. |
| Secure development | Documented secure development lifecycle; peer code review required before merge to production branches. Change management with approval and rollback procedures. Software bill of materials maintained for the distributed software development kits. |
| Incident management | Documented security incident response plan with defined severity levels, escalation paths and communication procedures. Personal Data Breach notification to Licensee within seventy-two (72) hours of becoming aware (Sect. 8.1). Post-incident review with documented root cause and corrective actions. |
| Physical security | Production infrastructure hosted in Amazon Web Services data centres, which maintain physical security controls certified under ISO/IEC 27001 and SOC 2. Company offices: access restricted to authorised personnel; visitor controls; clear desk and clear screen policy. Endpoint devices with full-disk encryption, centralised management and remote wipe capability. |
| Deletion and media disposal | Documented data deletion procedures covering primary storage, backups and Sub-processor systems. Secure erasure or destruction of storage media before disposal or reuse. |
| Sub-processor management | Data protection and security due diligence before engagement. Written contracts imposing obligations no less protective than this DPA. Periodic review of Sub-processor certifications and security posture. |
| Assistance to Licensee (SCC Clause 10(b)) | Self-service export of licence, customer and activation data through the platform and the management API in a structured, machine-readable format. Self-service correction and deletion of records held in the platform. Support channel for requests that cannot be fulfilled through self-service functionality, with response in accordance with the support terms of the Agreement. |
This Annex constitutes Annex III to the Standard Contractual Clauses.
The Sub-processors authorised as at the effective date of this DPA are those set out in the LicenseSpring Sub-processor List, which is incorporated into this Annex 4 by reference.
How to obtain it. Company provides the Sub-processor List to Licensee on provisioning of Licensee's account, and at any time on request to privacy@licensespring.com. Company shall respond to a request within five (5) business days. The version incorporated into this Annex 4 is the version in force on the date the Agreement takes effect, a copy of which Company provides to Licensee; each subsequent version replaces it on the expiry of the notice period in Sect. 5.2.
That list states, for each Sub-processor, its legal name and registered address, the country in which Processing takes place, the Processing activity carried out, the categories of Personal Data concerned, and the transfer safeguard relied on where the Sub-processor Processes outside the EEA. The duration of each Sub-processor's Processing is the duration of the Agreement, subject to Sect. 12 of this DPA.
Changes to the Sub-processor List are notified in accordance with Sect. 5.2 and do not require an amendment to this DPA. The List is confidential, per Sect. 5.7.
The standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, with Module Two selected in accordance with Clause 2(a) of those clauses, are incorporated into this DPA by reference and apply as if set out in full, without modification save for the completion of the options and the Appendix as recorded in this Annex 5 and in Sect. 6.3. The full text of those clauses is published in the Official Journal of the European Union (OJ L 199, 7.6.2021, p. 31) and Company shall provide a copy on request. By entering into the Agreement each Party is deemed to have signed those clauses on the date the Agreement takes effect.
| Option or clause | Election |
|---|---|
| Module | Module Two (controller to processor) |
| Clause 7 (docking clause) | Not used |
| Clause 9 (sub-processors) | Option 2 — general written authorisation, with the thirty (30) day notice period in Sect. 5.2 of this DPA |
| Clause 11(a) (redress) | Optional paragraph not used |
| Clause 13 and Annex I.C | The supervisory authority determined in accordance with Clause 13(a) of the SCCs, being the supervisory authority of the EU Member State in which the data exporter is established or, where the data exporter is not established in an EU Member State, the supervisory authority of the Member State in which the data exporter's Article 27 representative is established or in which the relevant Data Subjects are located |
| Clause 17 (governing law) | The law of the EU Member State in which the data exporter is established; where the data exporter is not established in an EU Member State, the law of Ireland |
| Clause 18(b) (forum) | The courts of the Member State whose law governs under Clause 17 |
Annex I.A — List of Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Licensee, as identified in the Agreement | Cense Data, Inc. DBA LicenseSpring Software |
| Address | As stated in the Agreement | Suite 211 — 744 West Hastings Street, Vancouver, British Columbia V6C 1A5, Canada |
| Contact person | Licensee's data protection contact, per Annex 1 | Data protection contact, privacy@licensespring.com |
| Activities relevant to the transfer | Use of the LicenseSpring platform and software development kits to issue, activate, validate and administer software licences | Provision of the LicenseSpring platform, software development kits, application programming interfaces and support and maintenance services, as described in Annex 2 |
| Role | Controller | Processor |
| Signature and date | By entering into the Agreement, the data exporter is deemed to have signed these Clauses on the date the Agreement takes effect | By entering into the Agreement, the data importer is deemed to have signed these Clauses on the date the Agreement takes effect |
Annex I.B — Description of the transfer. As set out in Annex 2 to this DPA: categories of Data Subjects, categories of Personal Data, special categories, frequency of the transfer, nature and purpose of the Processing, retention period, and the subject matter, nature and duration of Sub-processor Processing.
Annex I.C — Competent supervisory authority. As determined under Clause 13 of the SCCs, per the table above.
Annex II — Technical and organisational measures. As set out in Annex 3 to this DPA, including the measures for assistance to the data exporter referred to in Clause 10(b).
Annex III — List of Sub-processors. As set out in Annex 4 to this DPA. The data exporter has authorised the use of those Sub-processors under Clause 9, Option 2 (general written authorisation), with the notice period set out in Sect. 5.2 of this DPA.
This Part 2 applies only to the extent the UK GDPR applies to a transfer of Licensee Personal Data. It is the Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B.1.0, in force 21 March 2022 (the "Approved Addendum").
Table 1: Parties. Start date: the date the Agreement takes effect. Exporter: Licensee, as identified in the Agreement. Importer: Cense Data, Inc. DBA LicenseSpring Software. Key contacts: as set out in Annex 1.
Table 2: Selected SCCs, Modules and Selected Clauses. The Approved EU SCCs are those referred to in Part 1 of this Annex 5, with Module Two selected, Clause 7 not used, Clause 9 Option 2 with a thirty (30) day notice period, the optional paragraph of Clause 11 not used, and Clauses 17 and 18(b) as elected in Part 1.
Table 3: Appendix Information. Annex 1A (List of Parties), Annex 1B (Description of the Transfer), Annex II (Technical and organisational measures) and Annex III (List of Sub-processors) are as set out in the Appendix in Part 1 of this Annex 5.
Table 4: Ending this Addendum when the Approved Addendum changes. Neither Party may end the Addendum as set out in Section 19 of the Approved Addendum.
Part 2 of the Approved Addendum (Mandatory Clauses) is incorporated into this DPA by reference, as permitted by Section 2 of the Approved Addendum, and applies as if set out in full. In the event of a conflict between the Mandatory Clauses and this DPA in respect of a transfer subject to the UK GDPR, the Mandatory Clauses prevail.
Questions about this DPA: privacy@licensespring.com
Version history — v2.0, September 2, 2026: full replacement of the version dated 30 June 2018. Adds the 2021 EU Standard Contractual Clauses, the UK Addendum and Swiss terms; adds sub-processor notification and objection rights, with the Sub-processor List provided to customers on provisioning and on request rather than published; adds an audit right under Article 28(3)(h); adds US State Privacy Law service-provider terms; replaces the security description with the measures in Annex 3; updates Company's registered address, processing locations and sub-processor list.