Data Processing Addendum

This Data Processing Addendum (“DPA”) is incorporated into and forms a part of the Master Service Agreement or other applicable service order, order form or statement of work (or any similar agreement for Services) (“Principal Agreement”) between Simplify Infotech Private Limited and the customer or client (“Customer”), with respect to the Customer’s use of the Platform and/or Services.

Wherever the context so requires, the Company and the Customer shall hereinafter be collectively referred to as “Parties” and individually as the “Party”.

WHEREAS:

  1. The Parties have entered into the Principal Agreement in relation to the Company’s Platform and Services (each as described in the Principal Agreement).
  2. In the course of provision of the Services by the Company and access and use of the Platform by the Customer and its Users (described in the Principal Agreement), the Company is likely to be a recipient of Personal Data (described below) owned or controlled by the Customer, including without limitation personally identifiable information of the Users and/or other Persons.
  3. The Parties have entered into this DPA to set out their respective rights, liabilities, and obligations (i.e. with the Customer as the data fiduciary or data controller, and the Company as the data processor) in relation to the Personal Data.

IT IS AGREED BY AND BETWEEN THE PARTIES AS FOLLOWS:

  1. DEFINITIONS
  1. Definitions:  Capitalized terms not defined herein shall have the meaning given in the Principal Agreement. In this DPA, the following terms (and derivations of such terms) shall have the following meanings:
  1. "Applicable Laws" means all privacy and data protection laws that apply to the processing of Personal Data that is the subject matter of the Principal Agreement (including, where applicable, Digital Personal Data Protection Act, 2023, the General Data Protection Regulations (and any modification or adoption or implementation thereof in any form by EU Member States), California Consumer Privacy Act of 2018, California Privacy Rights Act of 2020, Colorado Privacy Act, Texas Data Privacy and Security Act, and other applicable data privacy and data protection laws).
  2. "Controller" means Customer or the entity that determines the purposes and means of the processing of Personal Data, by whatever term described or referred under Applicable Laws, including as a data controller or data fiduciary.
  3. Customer” means the ‘Client’ as defined in the Principal Agreement.
  4. “Data Subject” means (i) a natural person whose Personal Data are processed in the context of this DPA and whose rights are protected by Applicable Laws; or (ii) a “data subject” as that term is defined in the GDPR; or (iii) or “data principal” as that term is defined in the DPDPA.
  5. “Data Subject Rights” means those rights identified in Applicable Laws granted to Data Subjects.
  6. "Personal Data" means any information which is provided by Customer or an End User (directly or indirectly) to Company and Processed by Company as part of its provision of Services to Customer and which either (i) is subject to Applicable Laws and defined as “personal information” or “personal data” or “personally identifiable information” or “personally identifiable data” under Applicable Laws; or (ii) relates to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.  
  7. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
  8. Processing” shall have the meaning given under Applicable Laws.
  9. "Processor" means an entity that processes Personal Data on behalf of the Controller.
  10. “Sub-Processor” means an entity engaged by the Processor or any further sub-contractor to process Personal Data on behalf of and under the instructions of the Controller.
  1. DATA PROTECTION
  1. This DPA is incorporated into and supplemental to the Principal Agreement, and may be read along with the Privacy Policy available at https://www.koinx.com/privacy-crypto-tax. Except as modified below, the terms of the Principal Agreement and the Privacy Policy shall remain in full force and effect.
  2. Relationship of the Parties:  As between the Parties and for the purposes of this DPA, the Customer is the Controller of the Personal Data that is the subject of the Principal Agreement (the "Data") and lawfully appoints the Company as a Processor to process the Data on behalf of the Customer.
  3. Limitations: The Customer shall comply with Applicable Laws while disclosing and/or causing the processing of such Data, including but not limited to obtaining Data Subjects’ clear, specific, and prior consent where required, and/or providing notice to Data Subjects in relation to their rights and/or any Personal Data Breach. The Customer will be solely responsible to ensure that the Customer does not disclose or transfer any Data which is not subject to a clear, specific, and prior consent of the Data Subject, and/or which is not necessary to be disclosed, transferred or processed for the purpose of the Services. The Company shall not be liable or responsible for any damages resulting from any failure by the Customer in complying with its obligations as a Controller, and the Customer shall defend and hold the Company harmless from any claims, liabilities, damages, expenses, or other losses incurred as a result of any such failure.
  4. Purpose and Processing Limitation:  The Company shall process the Data as a Processor only as necessary to perform the Services for the Customer under the Principal Agreement, and strictly in accordance with the documented instructions of the Customer (including those in this DPA and the Principal Agreement); and the Customer shall only give lawful instructions to the Company that comply with Applicable Laws. In no event shall the Company process the Data for its own purposes or those of any third party. The Customer shall disclose Personal Data to the Company subject to Applicable Laws and solely to enable the Company to perform the Services. The Company is prohibited from: (i) selling or sharing the Personal Data; (ii) retaining, using, or disclosing the Personal Data for a commercial purpose other than providing the Services or as permitted by Applicable Laws; (iii) retaining, using, or disclosing the Personal Data outside of the Principal Agreement with the Customer; and (iv) combining the Customer’s Personal Data with other personal information, other than to provide the Services to the Customer. The Customer shall be solely responsible for compliance with Applicable Laws regarding the collection of and transfer of Personal Data. The Customer agrees not to provide any Data concerning a natural person's health, sexual orientation, ethnicity, religion or any other special or sensitive categories of data.
  5. Subcontracting:  Subject to the conditions set forth in this DPA, the Customer authorizes the Company to continue to use and disclose Data to Sub-Processors currently engaged by the Company in the context of providing the Services. The Company shall not subcontract any processing of the Data to a third party Sub-Processor unless: (i) such Sub-Processor is subject to an agreement with the Company which contains the same data protection terms as those provided for by this DPA; and (ii) the Company provides at least thirty (30) days' prior notice of the addition or replacement of such Sub-Processor (including the details of the processing it performs or will perform, and the location of such processing). The Customer shall notify the Company within ten (10) business days after receipt of the Company’s notice, if it objects to the addition or replacement of a Sub-Processor. The Customer’s objection should be sent to the authorised representative of the Company in writing (emails accepted) and explain the reasonable grounds for the objection. If the Customer objects to the Company's appointment of a third party Sub-Processor on reasonable grounds relating to the protection of the Data, and the Company is unable to adequately address the reasonable grounds, then the Company will not appoint the Sub-Processor. The Company shall remain fully liable for any breach of this DPA that is caused by an act, error or omission of its Sub-Processor. Please refer to Annexure B to find the current list of our Sub-Processors.
  6. Cooperation and Data Subject Rights:  The Customer is responsible for responding to Data Subject requests using the Customer’s own access to the relevant Personal Data. Taking into account the nature of the processing and the information available, upon the Customer’s request, the Company shall provide all reasonable and timely assistance to enable the Customer to respond to: (i) any request from a Data Subject to exercise any Data Subject Rights under Applicable Laws; and (ii) any other correspondence received from a regulator or public authority in connection with the processing of the Data. In the event that any such communication is made directly to the Company, the Company shall promptly and without undue delay (and in any event, no later than within forty-eight (48) hours of receiving such communication) provide the Customer full details of the same and shall not respond to the communication unless specifically required by law or authorized by the Customer.
  1. DATA SECURITY
  1. Security: The Company shall implement appropriate technical and organisational measures intended to protect the Data from (i) accidental or unlawful destruction, and (ii) loss, alteration, unauthorised disclosure of, or access to the Data.
  2. Confidentiality of Processing: The Company shall ensure that any Person that it authorises to process the Data (including the Company's staff, agents and subcontractors) shall be subject to a duty of confidentiality (whether a contractual duty or a statutory duty), and shall not permit any Person to process the Data who is not under such a duty of confidentiality.
  3. Data Protection Impact Assessment:  Taking into account the nature of the processing and the information available to the Company, upon the Customer’s request, the Company shall provide Customer with commercially reasonable and timely assistance as required by Applicable Laws with any data protection impact assessments carried out by the Customer.
  4. Personal Data Breach:  Upon becoming aware of a Personal Data Breach affecting the Data which is solely and directly attributable to the Company, the Company shall inform the Customer without undue delay but no later than forty-eight (48) hours and shall provide sufficient available information and cooperation to enable the Customer to fulfil its data breach reporting obligations under (and in accordance with the timescales required by) Applicable Laws. The Company shall further take such measures and actions as are necessary to remedy and mitigate the effects of the Personal Data Breach and shall keep the Customer informed of all material developments in connection with the Personal Data Breach. The Company shall not notify any third parties of a Personal Data Breach affecting the Data unless and to the extent that: (a) the Customer has agreed to such notification, and/or (b) notification is required to be made by the Company under Applicable Laws.
  5. Deletion or Return of Data:  Upon termination or expiry of the Principal Agreement, the Company shall (at the Customer's election) delete or return all Data, including copies, in its possession or control.  This requirement shall not apply to the extent that the Company is required by Applicable Laws to retain some or all of the Data, in which event the Company shall isolate and protect the Data from any further processing except to the extent required by such law.  
  6. Audit:  The Company uses an external auditor to verify the adequacy of its security measures and controls for Services. The audit is conducted annually by an independent third-party in accordance with SOC2 standards and results in the generation of a SOC2 report (“Audit Report”) which is the Company’s confidential information. Upon written request, the Company shall provide the Customer with a copy of the Audit Report. The Company shall permit the Customer (or its independent appointed representatives) to audit the Company's compliance with this DPA and shall make available all such information, systems and staff reasonably necessary to conduct such audit as required to meet the relevant requirements of Applicable Laws. The Customer shall not exercise its audit rights except following a Personal Data Breach or following an instruction by a regulator or public authority.
  1. CONTACT INFORMATION
  1. Data Protection Representative (EU & UK)
  1. Simplify Infotech Private Limited has appointed DataRep as our Data Protection Representative for individuals in the European Union (EU), the United Kingdom (UK), and the European Economic Area (EEA). This allows our customers in these regions to contact DataRep directly in their home country regarding any data protection queries. If you are located in the EU, UK, or EEA and wish to raise a question or exercise your rights regarding your personal data, you may do so through the following methods:
  1. Email: datarequest@datarep.com (Please quote "Simplify Infotech Private Limited" in the subject line)
  2. Online Form: www.datarep.com/data-request
  3. Mail: You may send inquiries to DataRep at the most convenient address from their listed locations across the 27 EU countries, the UK, Norway, and Iceland. (Annexure A)
  1. Important: When mailing inquiries, please ensure that your letter is addressed to "DataRep" and not "Simplify Infotech Private Limited", or it may not reach us. Also, clearly reference "Simplify Infotech Private Limited" in your correspondence.
  2. Upon receiving your request, we may require verification of your identity to ensure your personal data is not disclosed to unauthorized individuals. For details on how DataRep handles personal data, please refer to their Privacy Policy.
  1. Data Protection Representative (All other regions)
  1. If you are outside the EU, UK, or EEA, please contact our Data Protection Officer (DPO) directly via email at dpo@koinx.com.
  1. INTERNATIONAL TRANSFERS
  1. The Parties acknowledge that in connection with the provision of the Services, personal data may be transferred to and processed in countries outside the European Economic Area ("EEA"), including India.
  2. Where personal data originating in the EEA is transferred to a country that has not been recognized by the European Commission as providing an adequate level of protection pursuant to Article 45 GDPR, such transfer shall be governed by appropriate safeguards in accordance with Article 46 GDPR.
  3. The Parties agree that the Standard Contractual Clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("SCCs") are hereby incorporated by reference into this Addendum and shall apply to such transfers.
  4. KoinX represents that it has implemented appropriate technical and organizational measures, including encryption at rest and in transit, access controls, and data minimization practices, to ensure a level of protection essentially equivalent to that guaranteed within the EEA.
  1. MISCELLANEOUS
  1. The obligations placed upon the Company under this DPA shall survive so long as the Company and/or its Sub-Processors process Data on behalf of the Customer.
  2. Except for the changes made by this DPA, the Principal Agreement remains unchanged and in full force and effect. If there is any conflict between this DPA and the Principal Agreement, this DPA shall prevail to the extent of that conflict.
  3. If any provision of this DPA is deemed invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended to ensure its validity and enforceability while preserving the parties’ intentions as closely as possible; or (ii) if that is not possible, then construed in a manner as if the invalid or unenforceable part had never been included herein.

ANNEXURE A

Listed locations of DataRep

Country

Address

Austria

DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria

Belgium

DataRep, Rue des Colonies 11, Brussels, 1000

Bulgaria

DataRep, 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria

Croatia

DataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia

Cyprus

DataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus

Czech Republic

DataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic

Denmark

DataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark

Estonia

DataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia

Finland

DataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland

France

DataRep, 72 rue de Lessard, Rouen, 76100, France

Germany

DataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany

Greece

DataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece

Hungary

DataRep, President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary

Iceland

DataRep, Kalkofnsvegur 2, 3rd Floor, 101 Reykjavík, Iceland

Ireland

DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland

Italy

DataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy

Latvia

DataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia

Liechtenstein

DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria

Lithuania

DataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania

Luxembourg

DataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg

Malta

DataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta

Netherlands

DataRep, Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands

Norway

DataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway

Poland

DataRep, Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland

Portugal

DataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal

Romania

DataRep, 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857,

Romania

Slovakia

DataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia

Slovenia

DataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia

Spain

DataRep, Calle de Manzanares 4, Madrid, 28005, Spain

Sweden

DataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden

United Kingdom

DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom

ANNEXURE B

List of KoinX’s Sub-Processors

Name of Sub-processor

Description of Processing

Location of Sub-processor

Google Cloud

Running the Production environment including the Application

India(Mumbai)

MongoDB/AWS

Database

India(Mumbai)

Zoho CRM

CRM

India

[Remainder Left Blank]