Section 1 — Roles and Responsibilities
Roles. Showpad shall be considered Processor or Service Provider (or similar applicable definition), and Customer shall be considered Controller or Business (or similar applicable definition), under Applicable Data Protection Law concerning Showpad’s Processing of Customer Personal Data in the framework of this Data Processing Addendum (the “DPA”).
Instructions. Customer instructs Showpad to Process Customer Personal Data as necessary and proportionate for Showpad to provide the Products and Services to Customer under the Agreement, including this DPA, and/or as separately instructed by the Customer. Showpad shall inform Customer if, in Showpad’s opinion, an instruction from Customer, its representatives, Administrators, or Authorized Users infringes an Applicable Data Protection Law. Where there is a legal requirement under Applicable Data Protection Law for Showpad to Process Customer Personal Data outside of the instructions of Customer or its representatives, Administrators, or Authorized Users, Showpad shall inform Customer of that legal requirement before Processing, unless prohibited by the relevant Applicable Data Protection Law.
Showpad Responsibilities.
Section 2 — Sub‑Processors
List of Sub‑Processors. A list of Showpad’s then‑current Sub‑Processors, including the specifics of their Processing activities, is available through the administrator section of the Products and Services (admin settings > privacy > data agreement specifics), via the Showpad public website (www.showpad.com/subprocessors), or upon request.
Addition or Replacement. Showpad shall publish any additions or replacements with respect to its Sub‑Processors on the Showpad public website at least thirty (30) days in advance. Customer may subscribe to that webpage to receive notifications with respect to additions and replacements of the Sub‑Processors. Any publication under this Section 2.2 shall be considered a notification to Customer. Each publication will be confirmed in an email notification sent by Showpad to the addresses as subscribed.
Objection. Customer shall be allowed to object to an addition or replacement of Sub‑Processors under Section 2.2 by providing an opposition based upon reasonable and substantial grounds. Customer must provide Showpad with notice of any such opposition within twenty (20) days following the relevant notification by Showpad under Section 2.2, in the absence of which Customer shall have accepted the respective addition or replacement.
Resolution. Following a timely opposition under Section 2.3, Showpad shall have the right to resolve Customer’s opposition through one of the following solutions (to be selected at Showpad’s sole discretion). Showpad may: (i) cancel its plans to use the relevant Sub‑Processor or offer an alternative; (ii) take reasonable corrective steps as requested by Customer in its opposition to rectify the basis for Customer’s opposition and proceed with the Sub‑Processor; or (iii) cease to provide, temporarily or permanently, the particular component of the Products and Services that is impacted by such addition or replacement, subject to the mutual agreement of the Parties to adjust the applicable Fees for the applicable Products and Services under the Agreement.
Sub‑Processor Obligations. Showpad has executed a written contract with each Sub‑Processor that meets the respective data protection obligations of this DPA and provides sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the Processing will meet the requirements of this DPA. When a Sub‑Processor is certified under a Third‑Party Assurance Report (TPAR) that relates to the Processing activities covered under this DPA, the Parties agree that such certification satisfies the applicable requirements of this DPA to the extent such TPAR: i) was issued within the prior twelve (12) months, and ii) confirms there are no known material deficiencies in the controls audited under such TPAR.
Responsibilities. In the event a Sub‑Processor fails to fulfil its data protection obligations, Showpad shall remain liable to Customer for the performance of that Sub‑Processor’s obligations.
Section 3 — International Data Transfers
Transfer of Personal Data Into Or Circulation Within EEA. Where Showpad transfers Customer Personal Data into the EEA or circulates Customer Personal Data to a Sub‑Processor within the EEA, the provisions of GDPR shall apply and will regulate such transfer or circulation. Customer agrees that transfers into the EEA and circulation within the EEA under the provisions of GDPR are adequate and provide for appropriate safeguards to allow for such transfers to take place.
International Transfer of Personal Data. Showpad is self‑certified pursuant to the EU‑US Data Privacy Framework. Showpad shall ensure where Customer Personal Data is transferred internationally from the EEA to an onward Sub‑Processor outside of the EEA, such transfer shall, to the extent required by Applicable Data Protection Laws, be covered under:
If for any reason an applicable data transfer mechanism is deemed inadequate by the appropriate regulatory body, the Parties will act in good faith and, where necessary, establish the appropriate data transfer mechanism(s) to provide for such international transfer.
EU Model Clauses. Where Showpad, Inc. is the contracting party to this DPA, and to the extent Showpad, Inc. is importing Personal Data into the United States originating from the EEA, UK, or Switzerland, Showpad, Inc. shall abide by and accept the provisions of the EU Model Clauses, which are incorporated herein by reference and further detailed in Annex 3.
Section 4 — Assistance
Tools And Features of the Products and Services. During the term of the Agreement, Customer can use the functionalities of the user interface of the Products and Services to access, retrieve, download, correct, and delete Customer Content and individual records of a data subject. Customer may retrieve and download (i) Customer Content in its native format; and, (ii) analytics relating to Customer’s use of the Products and Services in a structured, commonly used, and machine‑readable format (e.g., .csv format).
Showpad Assistance. To the extent the functionalities under Section 4.1 above are not sufficient to permit Customer to fulfill Customer’s obligations under Applicable Data Protection Law, Showpad shall cooperate with Customer’s reasonable requests for assistance in fulfilling such obligations.
Data Subject Requests. Showpad shall not act upon direct requests or instructions from data subjects regarding Customer Personal Data, nor shall Showpad provide any information to data subjects, unless Customer specifically instructs Showpad to do so and then only to the extent of Customer’s instructions. Showpad shall forward such data subject requests to the appropriate customer without undue delay after Showpad determines the identity of the respective customer. The foregoing shall not prohibit Showpad from communicating with a data subject in order to determine the Showpad customer to which the respective requests relate.
Direct Requests From Supervisory Authorities Or Law Enforcement. Showpad shall as soon as practicable notify Customer about any legally binding request for disclosure of the Customer Personal Data by a supervisory authority or law enforcement authority (including without limitation any foreign administrative or judicial authority) unless otherwise prohibited by law from doing so. Unless Showpad’s cooperation is required by law, Showpad shall cooperate with such supervisory authority or law enforcement authority only to the extent instructed by Customer. Where Showpad is obligated to cooperate with such supervisory authority or law enforcement authority outside of a Customer instruction, Showpad shall limit the disclosure of the Customer Personal Data to what is necessary to meet the legal obligation.
Data Protection Impact Assessment (DPIA) / Third Party Assurance Report (TPAR) / Certifications / Documentation. At Customer’s reasonable request, Showpad shall provide Customer with documentation, TPARs, and/or evidence of certifications necessary to assist Customer in carrying out a DPIA, to demonstrate Showpad’s compliance with this DPA or Applicable Data Protection Laws, and to enable Customer to demonstrate compliance with Customer’s obligations. Any documentation, TPAR, and/or certification shared by Showpad shall be considered Confidential Information of Showpad and shall be covered under applicable confidentiality provisions in the Agreement or in an applicable non‑disclosure agreement.
Section 5 — Personal Data Breach
Notification. Showpad shall notify Customer without undue delay, and within no more than forty‑eight (48) hours, after becoming aware of a Personal Data Breach. Such notification shall at least:
Documentation. Showpad shall document Personal Data Breaches, including the facts relating to the Personal Data Breach, its effects, and the remedial action taken, and provide on request such documentation to Customer that Customer requires for the supervisory authority to verify compliance.
Section 6 — Audits
Customer Audit.
Regulatory Audit. If Customer is required under Applicable Data Protection Law by a supervisory authority to perform an on‑site audit at Showpad’s premises on Showpad’s systems and procedures related to or used for the Products and Services, Customer shall provide reasonable prior notice to Showpad. Such regulatory audit shall be executed — if and to the extent legally allowed by Applicable Data Protection Law — in accordance with the provisions of this Section 6 or, if full compliance with Section 6 is not possible, as close to the provisions of this Section 6 as reasonably possible.
Action Plan. In the event an audit under this Section 6 reveals material non‑conformities with this DPA or Applicable Data Protection Law, Showpad will, at its cost: i) promptly deliver an action plan to mitigate such non‑conformities without delay; and, ii) perform the necessary mitigation actions as soon as reasonably possible.
Cost. Each Party will bear its own costs in relation to the audit. Notwithstanding the foregoing, where the Customer audit plan (or aspects thereof) is unreasonable or materially exceeds what is customary in the applicable industry for the types of Products and Services offered by Showpad, the Parties shall meet in good faith to either adjust the audit plan to address removal of the non‑standard requests or determine an equitable division of costs for the non‑standard requests. In case the results of the audit reveal a material non‑conformity regarding this DPA or Applicable Data Protection Law, Showpad shall, upon request, reimburse the Customer for such audit costs as reasonably incurred by Customer in relation to the material non‑conformity in question.
Section 7 — Term
This DPA will terminate simultaneously and automatically with the termination or expiration of the Agreement.
Section 8 — Definitions
Capitalized terms not otherwise defined herein have the meanings given to them in the Agreement. The terms “Business“, “Service Provider“, and “Share” shall have the meanings given in the California Consumer Privacy Act.
“Administrator(s)” means the individual(s) employed or engaged by Customer having an “administrator”, “account owner”, or similar role with regard to the Products and Services, and who is or are responsible within the Customer organisation for maintaining, supporting, testing, or administering all or part of the Products and Services or Authorized User accounts.
“Applicable Data Protection Law” means applicable data protection laws, including, but not limited to, (a) the GDPR; (b) the UK Data Protection Act 2018; (c) the Swiss federal data protection act; (d) the CCPA; (e) the Virginia Consumer Data Protection Act; (f) the Colorado Privacy Act; (g) the Utah Consumer Privacy Act; and (h) the Connecticut Data Privacy Act.
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
“Customer Personal Data” means Personal Data that is part of (i) the Customer Content or (ii) the analytics relating to the use of the Products and Services.
“EEA” or “European Economic Area” means the territory of the EU Member states as well as EFTA Member States.
“EU Model Clauses” means such clauses as approved by the EU Commission in its Commission implementing decision (2021/914/EU) of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, updated, or replaced.
“EU‑US Data Privacy Framework” means the mechanism for the lawful transfer of personal data from the EEA to the United States, as recognized by the European Commission under Article 45 of the GDPR.
“GDPR” means the General Data Protection Regulation (EU/2016/679) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise Processed by Showpad.
“Processing”, “Process” or “Processed” means any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, retention, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Processor” means the entity (a Service Provider) that Processes Personal Data on behalf of, and under instruction of, a Controller.
“Prospect” means a third party with whom Customer’s Administrators and/or Authorized Users are interacting through the Products and Services by sharing certain Customer Content, or with whom that third party in question is re‑sharing Customer Content through the Products and Services.
“Sell” or “Sale” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, Personal Data to a third party for monetary or other valuable consideration, or for a third party’s commercial purpose.
“Sub‑Processor” means any party, other than Showpad or Customer, carrying out specific Processing activities on Customer Personal Data for Showpad in relation to the Products and Services.
“Third Party Assurance Report” or “TPAR” means an applicable SOC, ISO, ISAE or similar audit report or certification issued by a qualified third‑party auditor (e.g., ISO 27001, ISO 27701, ISAE 3402, SSAE 16 SOC 2, or equivalent) as well as any bridge letter related thereto.
Annex 1 — Specification of the Products and Services
Depending on the role within the Products and Services (Administrator, Authorized User, or Prospect) certain categories of Personal Data may be processed as follows:
More information can be obtained from the privacy settings of the Products and Services (admin settings > privacy > data agreement specifics) or on request.
The Products and Services do not Process Sensitive Personal Data, and are not intended for Processing Sensitive Personal Data.
Annex 2 — Security
1. General
When providing the Products and Services, Showpad shall take into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organizational measures (in particular based upon the risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise Processed) to ensure a level of security appropriate to the risk, including, inter alia, as applicable:
2. Information Security Management System
Showpad has developed and implemented a security assurance program using global privacy and data protection best practices. This Information Security Management System (“ISMS”):
3. Security Measures
Showpad has developed and implemented specific security measures, including:
1. Physical access control
Technical and organizational measures to prevent unauthorized persons from gaining access to the data processing systems available in the premises and facilities (including databases, application servers, and related hardware) where Personal Data is processed include:
Showpad does not operate its own data centers but instead relies on industry‑leading, internationally recognized cloud hosting providers whose facilities are subject to rigorous physical security standards and independently audited certifications (such as ISO 27001 and SOC 2).
2. Virtual access control
Technical and organizational measures to prevent data processing systems from being used by unauthorized persons include:
3. Data access control
Technical and organizational measures to ensure that persons entitled to use a data processing system gain access only to such Personal Data per their access rights and that Personal Data cannot be read, copied, modified, or deleted without authorization, include:
4. Disclosure control
Technical and organizational measures to ensure that Personal Data cannot be read, copied, modified, or deleted without authorization during electronic transmission, transport, or storage on storage media (manual or electronic) and that Showpad can verify the companies or other legal entities to which Personal Data are disclosed, include:
5. Entry control
Technical and organizational measures to monitor whether data have been entered, updated, or deleted from data processing systems, and by whom, include:
6. Control of instructions
Technical and organizational measures to ensure that Personal Data is processed solely per the instructions of the Controller include:
7. Availability control
Technical and organizational measures to ensure that Personal Data is protected against accidental destruction or loss (physical or logical) include:
8. Separation control
Technical and organizational measures to ensure that Personal Data collected for different purposes can be processed separately include:
Annex 3 — EU Model Clauses (EU Controller to Non‑EU or EEA Processor)
In the case and to the extent Showpad, Inc., is the contracting party to this DPA, and to the extent Showpad, Inc., is importing Personal Data into the United States originating from the EEA, UK, or Switzerland, Showpad, Inc., accepts the provisions of the EU Model Clauses, which, as acknowledged by Showpad, Inc., are incorporated herein by reference as detailed below:
- Identification
- Customer as identified in the Agreement
- Role
- Controller
- Name
- Showpad, Inc.
- Address
- 1 N State Street, Suite 1100, Chicago, IL 60602 USA
- Contact
- Data Protection Officer / privacy@showpad.com
- Activities
- As specified in Annex 1 to this DPA
- Role
- Processor
For the avoidance of doubt, the Swiss interpretation shall be deemed effective concurrently with EU Model Clauses.

















