This document constitutes a template EU Standard Contractual Clauses (SCCs) package available to be formally executed between Customer and Hop Mesh, LLC ("Hop") [Counsel placeholder: state of organization to be inserted upon confirmation of corporate filings] for cross-border transfers of personal data under GDPR Chapter V.
These Clauses comply with European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
Depending on Customer's regulatory role:
This package is a template to be executed upon request with the customer, never pre-executed. Where international data transfers require formal bilateral execution of these Clauses, customers may request, complete, and execute a countersigned package by contacting privacy@hopme.sh.
(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authorit(y/ies), agency/ies or other body/ies (hereinafter "data exporter(s)") transferring the personal data, as listed in Annex I.A, and (ii) the legal entity in a third country (hereinafter "data importer", Hop Mesh, LLC), as listed in Annex I.A, have agreed to these standard contractual clauses ("Clauses"). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679. (b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.
Data subjects may invoke and enforce these Clauses as third-party beneficiaries against the data exporter and/or data importer, with the exceptions specified in Clause 3.
Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.
In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, these Clauses shall prevail.
The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.
An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer.
The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organizational measures, to satisfy its obligations under these Clauses. (Module 2 and Module 3): The data importer shall process the personal data only on documented instructions from the data exporter. The data importer shall immediately inform the data exporter if, in the data importer's opinion, instructions given by the data exporter infringe Regulation (EU) 2016/679 or other applicable data protection law. The data importer shall implement technical and organizational measures to ensure the security of the personal data, including protection against a breach of security (Annex II).
(Module 2 and Module 3): The data importer has the data exporter's general authorization for the engagement of subprocessors from an agreed list (Annex III). The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of subprocessors at least 30 days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the subprocessor(s).
The data importer shall promptly notify the data exporter of any request it has received from a data subject. It shall not respond to that request itself unless it has been authorized to do so by the data exporter. Taking into account the nature of the processing and the cryptographic architecture of the network, the data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects' requests.
The data importer shall inform data subjects in a transparent and easily accessible format of a contact point authorized to handle complaints.
Each Party shall be liable to the other Party/Parties for any damages it causes the other Party/Parties by any breach of these Clauses.
The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 shall act as the competent supervisory authority.
The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorizing access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on an understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society are not in contradiction with these Clauses (see Transfer Impact Assessment).
The data importer agrees to notify the data exporter promptly if it receives a legally binding request from a public authority, including judicial or national security authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses. Because Hop uses end-to-end encryption with keys held solely on endpoint devices, payloads cannot be decrypted by Hop in response to any government demand.
These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties select the laws of the Republic of Ireland.
Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State. The Parties agree to submit to the jurisdiction of the courts of Dublin, Ireland.
relays/{node}/kv for active connection tracking and rate limiting.The data importer maintains the following technical and organizational security measures:
The data importer engages the following approved subprocessors: