1. Applicability
1.1
This Addendum applies where the Customer is a regulated entity as per Art. 2(1) DORA and obligated to comply with DORA. This Addendum applies to the extent FingerprintJS is considered an ICT service provider as per Art. 3(19) DORA. The Parties acknowledge that the Services provided by FingerprintJS under the Agreement and this Addendum do not support critical or important functions of the Customer as per Art. 3(22) DORA. Therefore, the enhanced contractual requirements set out in Art. 30(3) DORA, the associated RTS, and any other requirements applicable to the provision of services supporting critical or important functions shall not apply.1.2
This Addendum supplements the Agreement and shall control in the event of any conflict between the terms of this Addendum and the Agreement, with respect to the subject matter herein.1.3
This Addendum is effective as of the effective date of the Agreement (“Effective Date”).2. Definitions
2.1
Capitalized terms used in this Addendum have the following meanings:- 2.1.1 “EEA” means European Economic Area.
- 2.1.2 “ESA” means European Supervisory Authorities including the European Banking Authority, the European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority.
- 2.1.3 “ICT” means information and communication technology services as per Art. 3(21) DORA.
- 2.1.4 “ICT-related incident” means unplanned events as per Art. 3(8) DORA.
- 2.1.5 “Resolution Authority” means an authority designated by an EU Member State as a resolution authority in accordance with Art. 3 Directive (EU) 2014/59 and the respective EU Member State law transposing the Directive.
- 2.1.6 “RTS” means the regulatory technical standards developed by the ESAs which supplement DORA, adopted by the European Commission as delegated acts.
2.2
Other capitalized terms used and not defined in this Addendum shall have the meaning given to them in DORA and the Agreement.3. ICT Service Description and Compliance with Applicable Law
3.1
Annex 1 of this Addendum includes a description of all functions and ICT services to be provided. According to such description, the Services do not support critical or important functions of the Customer as per Art. 3(22) DORA.3.2
A service level description, including updates and revisions thereof is included in Annex 3, which FingerprintJS may amend from time to time.4. Location of the Services
4.1
This Addendum lists in Annex 2 the locations where the Services will be provided by FingerprintJS and where personal and non-personal data (together “Data”) will be stored and processed by FingerprintJS on behalf of the Customer. FingerprintJS will notify the Customer in advance of any change to such locations.5. Right of Instruction
5.1
Customer shall use commercially reasonable efforts to inform FingerprintJS in writing as quickly as possible of any legally binding recommendations, regulatory standards or other binding publications received from, or published by the competent authorities (including ESAs) under DORA that would be applicable to FingerprintJS’ performance of the Services under the Agreement.5.2
Both Parties will work together, in good faith, to amend this Addendum as needed to meet any reasonable mandated requirements of Customer’s relevant competent authorities or Resolution Authorities in so far as such changes apply to the provision of the Services to the Customer and are required for Customer to comply with its legal and regulatory obligations under DORA.6. Data Protection and Information Security
6.1
The Parties have agreed as part of the Agreement a data processing agreement (“DPA”) the terms of which govern the processing of personal data in the context of the delivery of the Services. The provisions in the DPA and its Annex in relation to the availability, authenticity, integrity, and confidentiality of personal data shall herewith be extended to also cover non-personal data, subject to the subsequent restrictions.6.2
Information regarding the technical and organizational measures implemented by FingerprintJS at the time of entering into the Agreement are available at https://dev.fingerprint.com/docs/dpa-gdpr#technical-and-organisational-security-measures. FingerprintJS will make available significant changes via the referenced site.6.3
In the event of the insolvency, resolution, or discontinuation of the business operations of Customer, where reasonable and necessary, FingerprintJS will return, grant access to, or recover in an easily accessible format relevant Data processed under this Addendum at Customer’s request (by Customer contacting FingerprintJS’ technical support team for download access and instructions), except for Data relating to or constituting FingerprintJS’ confidential information (such as trade secrets) and subject to the time/retrieval periods, limitations, requirements and restrictions set out in the Agreement as regards the Data of Customer. If Customer requests to receive a copy of its Data in any other format than foreseen by FingerprintJS, such format will be at Customer’s cost and the Parties will agree such costs in advance in an order form signed by both Parties. FingerprintJS shall ensure that access, recovery and retrieval of Customer Data is available to Customer for a maximum of one (1) month after any of the mentioned circumstances occur.7. Assistance and Cooperation
7.1
In case of an ICT-related incident or in case of an operational or security payment related incident that materially impacts the confidentiality, integrity, or availability of the ICT Service provided to Customer, FingerprintJS shall provide reasonable assistance to the Customer at a cost to be borne by Customer that shall be determined beforehand by the Parties in writing.7.2
FingerprintJS shall fully cooperate with the competent authorities and the Resolution Authorities of the Customer, including their appointed representatives. The Parties shall use commercially reasonable efforts to assist each other in complying with any notification obligation in the event of incidents.8. Security Awareness Programs and Training
8.1
Where appropriate and where Customer can, contrary to Sec. 8.3, demonstrate that FingerprintJS’ employees role require interaction with Customer ICT systems, protocols and tools and is not adequately sensitized and trained (i.e., through certificates or trainings performed by FingerprintJS), the Parties will agree on the requirements for Customer to request FingerprintJS to procure that its personnel whose roles require direct interaction with Customer ICT systems when providing ICT Services under the Agreement participate in Customer’s ICT security awareness programs and digital operational resilience training as per Art. 13(6) DORA.8.2
FingerprintJS employees will participate in such training sessions at Customer’s request and cost. Such costs will be agreed by the Parties in writing in a separate order form signed by both Parties.8.3
The Parties acknowledge that except in relation to the implementation of the Services, no FingerprintJS employee is generally dedicated solely to delivering the Services to the Customer. The Parties therefore agree that it is regularly not necessary to include FingerprintJS’ personnel in the relevant training schemes of the Customer.9. Adaption and Termination
9.1
The termination rights and the minimum notice periods for the termination of the Agreement can be subject to changes mandated by the competent authorities and Resolution Authorities. If the Parties cannot reach an agreement on the amendments to the Agreement required to reflect the mandatory changes within three (3) months after receipt of a binding instruction by the competent authority or Resolution Authority, either Party shall be entitled to an extraordinary right to terminate the Agreement with a notice period of three (3) months, which shall be the Customer’s sole and exclusive remedy. The Customer shall continue to pay for the Services during any such notice period but will be entitled to a partial refund for any fees paid in advance for the Services affected by the termination.9.2
In addition to the termination rights under the Agreement, and as set out above in Sec. 9.1, Customer shall be entitled to terminate the Agreement by providing thirty (30) days written notice to FingerprintJS in any of the following circumstances:- 9.2.1 Evidenced significant breach by FingerprintJS of applicable laws, regulations, or the obligations under this Addendum after an unsuccessful passing of a cure period of three (3) months after receiving Customer’s written breach notice.
- 9.2.2 Reasonable, evidenced and substantiated circumstances identified throughout the monitoring of FingerprintJS’ third-party risk that are deemed capable of materially impairing the performance of the functions provided through the Agreement and failure by both Parties to agree to a reasonable remediation plan in respect of such identified circumstances, including material changes that affect the Agreement or the situation of FingerprintJS after an unsuccessful passing of a cure period of three (3) months following receipt of Customer’s written notice.
- 9.2.3 FingerprintJS’ evidenced substantial weakness pertaining to its overall ICT risk management and particularly in the way it ensures the availability, authenticity, integrity, and confidentiality, of Data, which are material in nature and not resolved after an unsuccessful passing of a cure period of three (3) months following receipt of Customer’s written notice of any such identified weaknesses.
- 9.2.4 Where the competent authority of the Customer can no longer effectively supervise the Customer as a result of the conditions of, or circumstances related to, the Agreement, or as otherwise directed by a supervisory authority. To exercise the foregoing right, Customer shall serve a written notice of termination of no less than fourteen (14) business days and provide FingerprintJS with reasonable evidence of the grounds of termination.
9.3
In the case of a justified termination under section 9.2, the Customer shall be entitled to a pro-rata refund of pre-paid fees.10. Miscellaneous
10.1
This Addendum shall be governed by and construed in accordance with the laws that govern the Agreement.10.2
This Addendum may be executed in multiple counterparts, each of which is an original, but all together constitute the same document. The Parties agree that this Addendum may be executed electronically whereby transmission of an executed counterpart of this Addendum by email (in PDF, JPEG or other common format) shall be constitute delivery of an executed counterpart in this Addendum.10.3
The Parties agree that material changes to the Agreement that fall within the scope of this Addendum are to be formalized in a written document which is dated and signed (at least electronically) by the Parties, and which shall specify the renewal process for the relevant contractual arrangements.Annex 1 — Description of ICT Services
FingerprintJS provides to the Customer a cloud-based device intelligence service comprising the following products: Identification and Smart Signals (the “Service”) The Service enables customers to identify and classify devices and sessions interacting with their web and mobile applications. Identification returns a Visitor ID that remains stable over time and across routine software updates. Smart Signals provide additional context for detection and response, including suspect scoring and velocity indicators. The Service is intended for fraud prevention, risk scoring, abuse mitigation (e.g., account takeover, new account fraud, SMS pumping), bot detection, and personalization use cases. The Service does not execute payments, hold customer funds, perform regulated financial services, or provide managed security operations. FingerprintJS will render the agreed Services in accordance with the terms of the Agreement.Annex 2 — Location(s) of the ICT Services Directly Provided by FingerprintJS
Annex 3 — Service Level Agreement
1. Support Services
During the Subscription Term, FingerprintJS will provide the support services described in this Annex 3 (the “Support Services Term”).2. Definitions
“Downtime” means a period of time where the Service is unavailable to Customer due to reasons that are within FingerprintJS’ reasonable control. For clarity, “Downtime” does not include periods where the Service is unavailable to Customer due to (a) Customer’s negligence, hardware or software malfunction or other causes beyond the reasonable control of FingerprintJS such as, by way of example and without limitation, generalized telecommunications failures, packet loss, network, or internet problems, or (b) a problem with third party software not licensed through FingerprintJS. “Emergency Downtime” means Downtime due to a short-term emergency condition, provided that: (a) the incident lasts less than three (3) hours; and (b) there have been no prior Emergency Downtime incidents within 90 days before the incident. “Error” means a failure of the Service to conform to the specifications set forth in the Documentation, resulting in the inability to use, or material restriction in the use of, the Service. “Excused Downtime” means any Downtime that is Maintenance Downtime or Emergency Downtime, or Downtime that relates to FingerprintJS’ blocking of data communications or other service in connection with the Service in accordance with its policies. “Maintenance Downtime” means Downtime for maintenance or backup purposes, provided that: (a) the incident is scheduled with Customer at least three (3) business days in advance and (b) the aggregate duration of incidents in any month is less than one (1) hour. “Monthly Availability Percentage” means the percentage of time over the course of each calendar month during the Support Services Term, excluding Excused Downtime, that the Service is available for use by Customer. “Start Time” means the time at which FingerprintJS first becomes aware of an Error.3. Support Services
During the Support Services Term, FingerprintJS shall provide customer support through email during normal business hours, which shall be Monday through Friday, 9 a.m. to 5 p.m. (Central Time) (the “Support Services”). All submitted Errors will be classified as “Minimal Business Impact” as described in Table 1 below.4. Service Availability
4.1 Availability
The Service shall have a Monthly Availability Percentage equal to or greater than 99.9%:4.2 Downtime Credits
If the Service does not meet the Monthly Availability Percentage, FingerprintJS shall provide Customer with a credit in an amount equal to 0.4% of Subscription Term fees (“Downtime Credit”) for each period of Downtime lasting longer than 1 hour that is not an Excused Downtime; provided, however, that no more than one (1) Downtime Credit will accrue per day. In order to receive Downtime Credit, Customer must notify FingerprintJS in writing within 24 hours from the time of Downtime (such notice, a “Downtime Notice”). Failure to provide a Downtime Notice will forfeit Customer’s right to receive Downtime Credit for the applicable period of Downtime. For purposes of Downtime Credits, Downtime will begin to accrue as soon as FingerprintJS receives a Downtime Notice, and continues until the availability of the Service is restored. Downtime Credits may not be redeemed for cash. For any one (1) calendar month, Customer can receive a maximum of Downtime Credits equal to one (1) week of Subscription Term fees. FingerprintJS will only apply Downtime Credits to the month in which the incident occurred. Downtime Credits are non-transferable and are not redeemable for cash. Customer will not be entitled to any Downtime Credits if any undisputed invoice is overdue or if Customer is in breach of the Agreement.4.3 Error Management
FingerprintJS will use its commercially reasonable efforts to adhere to the response and resolution times for Errors as set forth below in Table 1.Table 1 – Error Management
* All times during regular business hours: 9 a.m. – 5 p.m. (Central Time, Monday through Friday).