Privacy Schedule

This Privacy Schedule and its Addenda (“Privacy Schedule”) shall be deemed part of the Agreement. Capitalized terms not specifically defined herein shall have the meaning set forth in the Agreement.

The terms of this Privacy Schedule shall apply to the processing of SodaStream Personal Data by Supplier as a Processor in connection with Supplier’s provision of the Services or Products to SodaStream and/or SodaStream Affiliates.

1. PURPOSE OF THE PRIVACY SCHEDULE & ORDER OF PRECEDENCE. 

            1. Purpose of the Privacy Schedule. The purpose of the Privacy Schedule is to establish Supplier’s obligations in relation to the Processing of SodaStream Personal Data.

            2. Order of Precedence. Nothing in this Privacy Schedule relieves Supplier of any obligations under the Agreement, nor shall be deemed a waiver by SodaStream of any rights or remedies therein. In the event any term or condition in this Privacy Schedule conflicts with a term or condition of any Agreement with Supplier, then the term or condition of this Privacy Schedule shall take precedence and control over any conflicting terms in the Agreement. In the event any term or condition of the Transfer Mechanism(s) conflict with a term or condition of the Privacy Schedule and/or the Agreement, then the term or condition of the Transfer Mechanism(s) shall take precedence and control over any conflicting terms in the Privacy Schedule and/or the Agreement.

             3. Addenda to the Privacy Schedule:

Addendum 1 - Description of the Processing Operations

Addendum 2 – Population of Transfer mechanisms

Addendum 3 - California Addendum

0. DEFINITIONS.

“Approved Subcontractor” means any Supplier Affiliate or third party contractor of Supplier listed in Addendum 1 or approved in accordance with Section 9 of this Schedule. 

“Applicable Laws” means the applicable local, state, and federal laws, including but not limited to the GDPR, California Consumer Privacy Act, executive orders, rules, regulations, ordinances, codes, orders, and decrees of all governments or agencies of domestic or foreign jurisdictions (including Privacy Laws) in which the Services are performed or to which the Services are performed pursuant to the Agreement, as amended from time to time.

“CCPA” means the California Consumer Privacy Act of 2018 and any regulations promulgated thereunder, in each case, as amended from time to time.

“Controller” means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the Processing of Personal Data; where the purposes and means of Processing are determined by applicable Privacy Law, the Controller or the criteria for the Controller's nomination will be as designated by applicable Privacy Law.

“Data Subject” means an identified or identifiable natural person including as specified in Addendum 1. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity. 

“EEA” means the European Economic Area.

“FADP” means the Federal Act on Data Protection of 19 June 1992, and as revised as of 25 September 2020, the “Revised FADP”.

“GDPR” means: (i) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“EU GDPR”); and (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended) (“UK GDPR”), including in each case (i) and (ii) any applicable national implementing or supplementary legislation (e.g. the UK Data Protection Act 2018), and any successor, amendment or re-enactment, to or of the foregoing. 

“Security Incident” means “Security Incident” as defined in the Security Schedule.

"SodaStream Affiliates” means any companies and/or other entities: (i) which are directly or indirectly controlled by SodaStream International Ltd., control SodaStream International Ltd. or are under common control with SodaStream International Ltd.; and (ii) on whose behalf Supplier and/or any Sub-Processor Processes any SodaStream Personal Data under or in connection with the Agreement. For these purposes, “control” and its inflections mean to hold or control, directly or indirectly, more than 50% of of the voting interests of the subject company or entity.

“SodaStream Personal Data” means any Personal Data, including Sensitive Personal Data, of which SodaStream, or SodaStream Affiliates is the Controller and which SodaStream, or SodaStream Affiliates will provide to Supplier or which Supplier collects for Processing on its or their behalf, including as specified in Addendum 1.

“Personal Data” means any information relating to an identified or identifiable Data Subject or as otherwise defined by Privacy Law.

“Privacy Law” means all Applicable Laws and regulations relating to the processing of Personal Data and privacy that may exist in the relevant jurisdictions. 

“Process”, “Processing”, or “Processed” means any operation or set of operations which is performed on or with Personal Data whether or not by automatic means (including, without limitation, accessing, collecting, recording, organizing, retaining, storing, adapting or altering, retrieving, consulting, using, disclosing, making available, aligning, combining, blocking, erasing and destroying Personal Data) and any equivalent definitions in Privacy Law to the extent that such definitions should exceed this definition.

“Processor” means any natural or legal person, public authority, agency or any other body which processes Personal Data on behalf of a Controller or as a sub-processor on the instruction of a Processor acting on behalf of a Controller.

“Restricted Transfer” means the disclosure, grant of access or other transfer of SodaStream Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “EEA Restricted Transfer”); (ii) in the context of the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”); and (iii) in the context of Switzerland, any country or territory outside Switzerland, which does not benefit from an adequacy decision from the Swiss authorities (a “Swiss Restricted Transfer”), which would be prohibited without a legal basis under Chapter V of the GDPR.

“Schedule Effective Date” means the effective date of the Agreement.

“Sensitive Personal Data” means any information relating to a person’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or sex life, biometric and genetic data or as otherwise defined by Privacy Law. 

"Standard Contractual Clauses" or “SCCs” means the standard contractual clauses approved by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

“Services” means those services and activities to be supplied to or carried out by or on behalf of Supplier for SodaStream and/or any SodaStream Affiliate under the Agreement.

“Sub-Processor” means any third party, including Supplier affiliates, engaged to Process SodaStream Personal Data on behalf of Supplier. 

“Supervisory Authority” (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office; and (iii) in the context of any other applicable Privacy Laws, means the relevant regulatory or governmental authorities, or other public bodies, with competent jurisdiction under those laws.

“Transfer Mechanism(s)” means the SCCs, UK Transfer Addendum, and/or Swiss transfer mechanism; as applicable to the relevant Restricted Transfer.

“UK” means the United Kingdom of Great Britain and Northern Ireland.

“UK Transfer Addendum” means the template Addendum B.1.0 issued by the Information Commissioner’s Office (ICO) and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section ‎‎18 of the UK Mandatory Clauses included in Part 2 thereof (the “UK Mandatory Clauses”). 

0. APPOINTMENT OF SUPPLIER AS A PROCESSOR & COMPLIANCE WITH INSTRUCTIONS. 

1. SodaStream hereby appoints Supplier as a Processor in respect of all such SodaStream Personal Data in order to provide the Services or Products.  Supplier shall Process SodaStream Personal Data in accordance with Addendum 1 and as required to execute this Privacy Schedule and the Agreement.  

2. Supplier shall only Process SodaStream Personal Data to the extent and in a manner necessary to provide the Services or the Products (including as described in Addendum 1) and in accordance with SodaStream’s documented instruction (which may be specific or general in nature as set out in this Agreement or otherwise notified in writing by SodaStream to Supplier under this Agreement) or as strictly required by Applicable Laws and shall not Process SodaStream Personal Data for any other purpose. To the extent permitted by Applicable Laws, Supplier shall inform SodaStream of any Processing to be carried out and the relevant legal requirements that require it to carry out such Processing. Supplier certifies that it and any Supplier personnel and any other persons acting under its authority who will receive or have access to SodaStream Personal Data understand the requirements and instructions of this Privacy Schedule and applicable Privacy Law and will comply with them.

3. Supplier shall promptly notify SodaStream in writing, unless prohibited from doing so under Applicable Law, if:

1. it believes that any instruction from SodaStream violates Privacy Law; 

2. it is unable to comply with SodaStream’s instructions for any reason; or

3. it is unable to comply with SodaStream’s instructions or the terms of the Agreement and/or Privacy Schedule in relation to the Processing of SodaStream Personal Data due to legislation applicable to it or arising as a result of a change to that legislation or the introduction of new legislation. 

           4. Supplier acknowledges that is has no right, title or interest in SodaStream Personal Data (including all intellectual property or proprietary information) and may not sell, rent or lease SodaStream Personal Data to anyone.

To the extent that Supplier Processes SodaStream Personal Data protected by the CCPA, then the terms specified in Addendum 3 (California Addendum) to this Privacy Schedule shall apply in addition to the terms of this Privacy Schedule.

0. COMPLIANCE WITH LAWS.

1. Supplier shall at all times comply with its obligations under applicable Privacy Law to which it is subject as a service provider and Processor of SodaStream Personal Data or which is otherwise applicable to its information security, privacy and data protection obligations in connection with the Services or the Products. 

2. Supplier shall not perform its obligations under the Agreement in a manner that causes, or might reasonably be expected to cause, SodaStream to violate applicable Privacy Law. 

3. Supplier shall co-operate with and provide SodaStream with the assistance it deems necessary to ensure SodaStream Personal Data is Processed in compliance with Privacy Law applicable to SodaStream and SodaStream Affiliates including as specified in Sections 5.4 and 6.2. 

4. Any request for co-operation or assistance by SodaStream pursuant to Section 4.3 shall be made in writing setting out SodaStream’s requirements and related instructions and shall be met by Supplier to the extent reasonably possible and within a reasonable period of time.  To the extent that compliance with this Section 4.3, constitutes a material change to the scope of the Services, the parties shall, acting reasonably, agree on appropriate amendments to the Agreement and the payment of any reasonable and material associated costs to Supplier. 

0. SECURITY & SECURITY INCIDENT.

1. Supplier shall implement and maintain appropriate physical, technical and organizational measures, including the minimum standards set out in the Security Schedule, to ensure the privacy, integrity and availability of SodaStream Personal Data and the systems and technologies used for Processing SodaStream Personal Data, which shall be appropriate to protect SodaStream Personal Data against accidental or unlawful destruction, encryption, acquisition or accidental loss, alteration, unauthorized disclosure or access in particular where the processing involves transmission of data over a network, and against all other unlawful forms of processing. The technical and organizational measures shall ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature and scope, context and purpose of processing and risks of varying likelihood and severity for the rights and freedoms of individuals. These measures shall include, as appropriate, (a) pseudonymization and encryption of personal data, (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing (the “Security Measures”). 

2. Supplier warrants and represents on an ongoing basis that the Security Measures it applies currently, and further undertakes that at all relevant times any updated Security Measures shall, meet or exceed the standards required by applicable Privacy Laws and now- or then-current good industry practice.

3. Subject to Section 4.3, Supplier shall provide all reasonable assistance to SodaStream, as required, to ensure that SodaStream can comply with its obligations in relation to security, data breach notification, conducting privacy impact assessments, which SodaStream reasonably considers to be required of it by Article 35 or Article 36 GDPR or equivalent provisions of any other applicable Privacy Laws, and possible consultations with Privacy Authorities under Privacy Law, taking into account the nature of the processing and the information available to Supplier.

4. Supplier shall take reasonable measures to ensure that access to SodaStream Personal Data is strictly limited to those individuals who need to know or access the relevant SodaStream Personal Data for the purposes described in this Privacy Schedule and the Agreement and that persons within its organization who are authorized to access and Process SodaStream Personal Data are suitable for the accessing and handling such Personal Data. In addition, every such person shall be informed of the confidential nature of SodaStream Personal Data and be subject to a statutory or binding confidentiality obligation in respect of the SodaStream Personal Data.

5. Supplier shall hold periodical training sessions for any person within its organization authorized to process SodaStream's Personal Data on their respective privacy and data protection obligations under the Privacy Law and this Privacy Schedule, (as applicable to their tasks). Such trainings shall take place at least once every two years from the commencement of the processing of SodaStream's Personal Data, and for any new person joining the Supplier's organization – as soon as possible after his or her employment. The Supplier shall maintain a registry of the trainings conducted to be provided to SodaStream upon request.

6. In the event that Supplier experiences or reasonably suspects a Security Incident affecting SodaStream Personal Data, Supplier shall comply with the section entitled “Supplier Requirements – Notifications” of the Security Schedule. Supplier shall co-operate with SodaStream and take such reasonable steps as may be directed by SodaStream to assist in the investigation of any such Security Incident.

1. COMMUNICATIONS & DATA SUBJECT RIGHTS. 

1. Supplier shall within three (3) business days of receipt, forward any request, complaint, notice or other communication from a Data Subject or a Supervisory Authority in connection with SodaStream Personal Data (“Communication”) to SodaStream at sodastream.privacy1@pepsico.com and will not respond, or take any other action, to a Communication except on the written instructions of SodaStream or as required by applicable Privacy Laws. 

2. Subject to Section 4.3, Supplier shall co-operate fully with SodaStream in connection with a Communication and promptly provide SodaStream with information it reasonably requires to respond to the Communication. To the extent SodaStream is not able to access SodaStream Personal Data Processed by Supplier itself, Supplier shall promptly provide SodaStream with any SodaStream Personal Data in its possession in the form reasonably requested by SodaStream as SodaStream may reasonably require, including to respond to a Communication.  

3. Taking into account the nature of the Processing, Supplier shall assist SodaStream with appropriate technical and organizational measures to fulfil SodaStream and SodaStream Affiliates’ obligations under Privacy Law to respond to requests from Data Subjects for exercising their rights of information, access, restriction, erasure, portability and objection in connection with SodaStream Personal Data Processed by Supplier.

2. DATA QUALITY & RETENTION.

1. Supplier shall update, anonymize, correct or delete SodaStream Personal Data in its possession on SodaStream’s request.

2. Supplier shall process SodaStream Personal Data for the duration of the Agreement and retain SodaStream Personal Data in accordance with section entitled “Supplier Requirements – Secure Data Destruction or Return” of the Security Schedule.  

3. If, as a result of law applicable to Supplier, Supplier is prevented from returning or destroying SodaStream Personal Data, Supplier shall (a) notify SodaStream, (b) cease from actively Processing the retained SodaStream Personal Data, (c) maintain the SodaStream Personal Data as Confidential Information, (d) implement security measures to protect the SodaStream Personal Data, and (e) ensure a level of security appropriate to the harm that might result from unauthorized use, dissemination or publication of the SodaStream Personal Data. Supplier will act as a Controller in its own right in connection with any and all such subsequent Processing of SodaStream Personal Data, and shall comply with applicable obligations under applicable Privacy Laws in relation thereto.

3. INTERNATIONAL TRANSFERS. 

1. Where Supplier is certified under a scheme (such as the EU – US Data Privacy Framework, Swiss – US Data Privacy Framework, and/or UK Extension (as applicable)) that benefits from an adequacy decision of the EU Commission, UK Government and/or Swiss authorities (as applicable), Supplier represents and warrants to comply with the relevant principles under such scheme. Supplier shall without undue delay notify SodaStream if Supplier withdraws from such scheme or such scheme and/or respective adequacy decision is invalidated. In case Supplier withdraws from such scheme or such scheme and/or respective adequacy decision is invalidated, Supplier shall automatically be bound by the additional obligations of this clause with respect to Restricted Transfer(s).

EEA Restricted Transfers to Supplier

2. To the extent that any Processing of SodaStream Personal Data under this Privacy Schedule involves an EEA Restricted Transfer from SodaStream to Supplier, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be: 

1. populated in accordance with Part 1 of Addendum 2 (Population of Transfer Mechanisms); and

2. entered into by the Parties and incorporated by reference into this Privacy Schedule. 

UK Restricted Transfers to Supplier

3. To the extent that any Processing of SodaStream Personal Data under this Privacy Schedule involves a UK Restricted Transfer from SodaStream to Supplier, the Parties shall comply with their respective obligations set out in the UK Transfer Addendum, which is hereby deemed to be: 

1. populated in accordance with Part 2 of Addendum 2 (Population of Transfer Mechanisms); and

2. entered into by the Parties and incorporated by reference into this Privacy Schedule. 

Swiss Restricted Transfers to Supplier

4. To the extent that any Processing of SodaStream Personal Data under this Privacy Schedule involves a Swiss Restricted Transfer from SodaStream to Supplier, the Parties shall comply with their respective obligations under the Swiss transfer mechanism, which is hereby deemed to be entered into by the Parties and incorporated by reference into this Privacy Schedule. 

Provision of full-form Transfer Mechanism(s)

5. In respect of any given Restricted Transfer, on request from SodaStream, Supplier shall promptly (and in any event within seven (7) days) execute full-form version(s) of the relevant Transfer Mechanism(s) (as applicable) covering Restricted Transfer(s) to Supplier, which shall be amended and populated in accordance with Addendum 2 (Population of Transfer Mechanisms), in respect of the relevant Restricted Transfer(s).

Changes to Transfer Mechanism(s)

6. SodaStream may on notice vary this Privacy Schedule and replace the relevant Transfer Mechanism(s) with:

1. any new form of the relevant Transfer Mechanism(s) or any replacement therefor prepared and populated accordingly; or 

2. another transfer mechanism, other than the Transfer Mechanism(s),

that enables the lawful transfer of Personal Data to Provider under this Privacy Schedule in compliance with Chapter V of the GDPR. 

Access to Personal Data by public authorities

7. In case of any given Restricted Transfer:

1. To the extent permitted by Applicable Laws, each Party shall notify the other Party promptly in writing of any subpoena or other judicial or administrative order by a public authority or proceeding seeking access to or disclosure of SodaStream Personal Data. Such notification shall, to the extent permitted by Applicable Laws, include details regarding the Data Subject concerned, Personal Data requested, the requesting authority, the legal basis for the request, and any responses provided. 

2. Where Supplier receives such request, SodaStream shall have the right to defend such legal challenge in lieu of and/or on behalf of Supplier to the extent permitted by applicable laws. SodaStream may, if it so chooses, seek a protective order. Supplier shall reasonably cooperate with SodaStream in such defence.  

3. To the extent permitted by Applicable Laws, each Party shall not disclose the Personal Data requested until all reasonable challenges have been exhausted and shall provide the minimum of information permissible when responding to an order to disclose the Personal Data. 

4. Where the notifying Party is prohibited from satisfying clause 8.7 under Applicable Laws, the notifying Party shall use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. Supplier agrees to document its best efforts in order to be able to demonstrate them on request of SodaStream.

5. Where a Party becomes aware of any direct access by public authorities to Personal Data (including the reasonable suspicion thereof), this Party shall promptly notify the other Party with all information available, unless otherwise prohibited by applicable laws.

6. Supplier represents and warrants that: 

1. Supplier has not purposefully created ‘backdoors’ or similar programming designed to, or that could, be used to access its systems used to store or otherwise Process SodaStream Personal Data; 

2. Supplier has not purposefully created or changed its business processes in a manner that facilitates access to its relevant systems or to SodaStream Personal Data by any governmental authority, law enforcement agency, public body or judicial body and shall not voluntarily cooperate with any such authorities, agencies or bodies in relation to the same; and 

3. no applicable law or government policy to which Supplier is subject requires Supplier to create or maintain ‘backdoors’ or to otherwise enable or facilitate access to SodaStream Personal Data or systems.

4. SUB-PROCESSING OF SODASTREAM PERSONAL DATA. 

1. Supplier may only disclose, including permit access to, SodaStream Personal Data to a Sub-Processor after having notified SodaStream and obtained specific written authorization of SodaStream and in compliance with this Section 9. 

2. SodaStream shall have twenty (20) business days from receipt of a notice of disclosure to make an assessment of the disclosure.  If SodaStream does not object to the disclosure within this time period it shall be deemed to have consented and the Sub-Processor shall qualify as an Approved Subcontractor.  If SodaStream reasonably objects to the disclosure, Supplier shall not make disclosures of SodaStream Personal Data to a Supplier’s Sub-Processor and the parties commit to cooperate to come to a mutually acceptable solution.  

3. The parties agree that the Sub-Processors listed in Addendum 1 are Approved Subcontractors. 

4. Supplier may only disclose SodaStream Personal Data to an Approved Subcontractor after:

1. Supplier has carried out adequate due diligence to ensure that the Approved Subcontractor is capable of providing the level of protection for SodaStream Personal Data required by this Privacy Schedule (including adherence to security requirements that offer at least the same level of protection for SodaStream Personal Data as the Security Measures);

2. SodaStream has been provided with details of each country in which SodaStream Personal Data is proposed to be Processed by the Approved Subcontractor;

3. Supplier has executed a valid and enforceable written contract with the Approved Subcontractor (which may include an inter-company agreement in the case of Supplier Affiliates) containing privacy and security provisions which offer at least the same level of protection for SodaStream Personal Data as those set out in this Privacy Schedule and meet the requirements if Article 28 GDPR; and

4. Supplier has put in place appropriate measures to ensure that international transfers of SodaStream Personal Data occur in compliance with Privacy Law.  

5. On SodaStream’s request, Supplier shall (as soon as reasonably practicable following such request) provide to SodaStream:

1. a list of the then-current Approved Subcontractors engaged by Supplier, together with the relevant information relating to such Approved Subcontractor shown in the Approved Subcontractor List in Addendum 1; and 

2. written certification that the arrangements between Supplier and such Approved Subcontractors meet the requirements set out in Section 9.4; and/or 

3. copies of Supplier’s agreements with any such Approved Subcontractor(s) (which may be redacted to remove confidential commercial information not relevant to the requirements of this Privacy Schedule).  

6. Supplier shall be responsible for the acts, errors and omissions of Approved Subcontractors it engages to provide the Services to SodaStream and remains fully liable for the acts, errors and omissions of the Approved Subcontractors giving rise to a  breach of this Agreement as if they were its own acts, errors or omissions. 

5. AUDITS.

1. Supplier shall keep appropriate records to demonstrate its compliance with Privacy Law, this Privacy Schedule and the Security Schedule.  Supplier shall make these records available to SodaStream upon reasonable request.

2. Supplier shall allow for and contribute to audits, including on premise inspections, by SodaStream or an auditor mandated by SodaStream in relation to the Processing of SodaStream Personal Data by Supplier and its Sub-Processors and Supplier’s compliance with its obligations under this Privacy Schedule and applicable Privacy Laws. Such audits may require Supplier to complete questionnaires and/or make available relevant documents for review and relevant Supplier and/or Sub-Processor Personnel for interviews. 

3. SodaStream shall give Supplier reasonable notice of any audit or inspection to be conducted under this Section 10 and Supplier need not give access to its premises for the purposes of such audit or inspection outside normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis where: 

1. SodaStream reasonably considers necessary because of genuine concerns as to Supplier’s material non compliance with this Privacy Schedule and/or applicable Privacy Laws; or 

2. SodaStream is required or requested to carry out such audit or inspection by applicable Data Privacy Laws and/or a Supervisory Authority.

4. If it is established or shown during an audit and/or inspection that Supplier has failed to comply with its obligations under this Privacy Schedule and/or applicable Privacy Laws, without prejudice to any rights or remedies available to SodaStream, SodaStream shall notify Supplier and Supplier shall take all measures necessary to ensure its compliance as soon as reasonably practicable.

6. SODASTREAM AFFILIATES.

1. Supplier expressly agrees that a SodaStream Affiliate will have the right to enforce the provisions of this Privacy Schedule with respect to SodaStream Personal Data which Supplier or any Sub-Processor Processes on behalf of that SodaStream Affiliate as an express beneficiary thereof.

2. Any SodaStream Affiliate may amend and replace (with respect to that SodaStream Affiliate) Addendum 1 (Data Processing Details) on written notice to Supplier from time to time to accurately reflect the nature and extent of Supplier’s Processing of SodaStream Personal Data on behalf of that particular SodaStream Affiliate.

7. Each of the parties to this Privacy Schedule are hereby deemed to have separately entered into the applicable provisions of this schedule with the other applicable party(s).  Accordingly in each instance the applicable provisions shall constitute a separate and independent agreement between the relevant parties.

8. Each party represents that it has full corporate power and authority to enter into this Schedule. This Schedule may be executed in multiple counterparts which together will constitute one and the same instrument and be binding upon the parties. The parties expressly accept that electronic signatures as recognised under applicable law will be deemed original signatures and will have the same validity and effect.

 

Supplier


SodaStream International Ltd.







---------------------------
---------------------------

Signature


Signature




---------------------------
---------------------------

Name


Name




---------------------------
---------------------------

Title


Title




---------------------------
---------------------------

Date signed


Date signed





SodaStream Affiliates


--------------------------------------

Signature


--------------------------------------

Name


--------------------------------------

Title: Duly authorised to sign on behalf of all SodaStream Affiliates pursuant to a power of attorney


--------------------------------------

Date signed

 


Addendum 1

Data Processing Details

Supplier agrees that in the provision of its Services or Products, the Processing of SodaStream Personal Data will be limited to what is set out in this Addendum 1, unless SodaStream agrees otherwise in subsequent documented instructions or an SOW.


SODASTREAM / ‘DATA EXPORTER’ DETAILS

Name: [SODASTREAM], [SUFFIX]
Address: As set out in the preamble to the Agreement
Contact Details for Data Protection: Role: [INSERT]
Email: [INSERT]
SodaStream Activities: SodaStream’s activities relevant to this Privacy Schedule are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations
Role: • Controller

 

SUPPLIER / ‘DATA IMPORTER’ DETAILS

Name: [SUPPLIER, [SUFFIX]
Address: As set out in the preamble to the Agreement
Contact Details for Data Protection: Role: [INSERT]
Email: [INSERT]
Supplier Activities: [Insert description of Supplier’s activities relevant to the Services and the Processing/transfer of Personal Data in connection therewith.]
Role: Processor

 

DETAILS OF PROCESSING

Categories of Data Subjects: Relevant Data Subjects include:
[INSERT CATEGORIES OF DATA SUBJECTS]
Each category includes current, past and prospective Data Subjects.
Categories of Personal Data: Relevant Personal Data includes:
[INSERT CATEGORIES OF PERSONAL DATA]
Special Category Data / Sensitive Data, and associated additional restrictions/safeguards: Categories of ‘sensitive data’
Any ‘sensitive data’ (as defined in Clause 8.7 of the SCCs), which may comprised within data Processed on behalf of SodaStream by or on behalf of Supplier in provision of the Services – including:
[INSERT CATEGORIES OF ‘SENSITIVE DATA’]

Additional safeguards for ‘sensitive data’
[INSERT].
Frequency of transfer: [EXAMPLE: Ongoing – as initiated by SodaStream in and through its use, or use on its behalf, of the Services.]
[EXAMPLE: One-off.]
Nature of the Processing: Processing operations required in order to provide the Services in accordance with the Agreement.
Purpose of the Processing: SodaStream Personal Data will be Processed: (i) as necessary to provide the Services as initiated by SodaStream in its use thereof, and (ii) to comply with any other instructions provided by SodaStream in accordance with the terms of this Privacy Schedule.
Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and the Privacy Schedule, including Section 9 of the Privacy Schedule.
Transfers to (sub-)processors: Transfers to Sub-Processors are as, and for the purposes, described from time to time in the Sub-Processor List (as may be updated from time to time in accordance with Section 5 of the Privacy Schedule).

 

Approved Subcontractor List

 

Name of Sub-Processor: Services performed / brief details of Processing activities: Category(ies) of SodaStream Personal Data concerned: Location of the Sub-Processor Addendum/SCC in place with Sub-Processor (yes or no)

 

Population of Transfer mechanisms

Notes:

  • The SCCs populated in accordance with Part 1 of this Addendum 2 are incorporated by reference into and form an effective part of the Privacy Schedule.
  • The UK Transfer Addendum amended and populated in accordance with Part 2 of this Addendum 2 are incorporated by reference into and form an effective part of the Privacy Schedule. 
  • The Swiss transfer mechanism amended and populated in accordance with Part 3 of this Addendum 2 are incorporated by reference into and form an effective part of the Privacy Schedule.

 

PART 1: POPULATION OF SCCs

1. SIGNATURE OF THE SCCs:

Where applicable in accordance with Section 8 of the Privacy Schedule: 

(a)each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs; and 

(b)those SCCs are entered into by and between the Parties with effect on and from (i) the Schedule Effective Date; or (ii) the date of the first EEA Restricted Transfer to which they apply in accordance with Section 8 of the Privacy Schedule, whichever is the earlier.

2. MODULES

Module Two of the SCCs applies to any EEA Restricted Transfer involving Processing delegated to Supplier by SodaStream acting as Controller in its own right.

3. POPULATION OF THE BODY OF THE SCCs

3.1 The SCCs shall be populated as follows for each Module of the SCCs as and where applicable to that Module and the Clauses thereof:

(a)The optional ‘Docking Clause’ in Clause 7 is included in full.

(b)In Clause 9: 

(i)OPTION 1: SPECIFIC PRIOR AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Sub-Processors shall be the period specified in Section 9.2 of this Privacy Schedule; and

(ii)OPTION 2: GENERAL WRITTEN AUTHORISATION is not used and that optional language is deleted.

(c)In Clause 11, the optional language is not used and is deleted. 

(d)In Clause 13, all square brackets are removed and all text therein is retained. 

(e)In Clause 17: 

(i)OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Germany; and

(ii)OPTION 2 is not used and that optional language is deleted. 

(f)For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs shall be resolved by the courts of Germany, and Clause 18(b) is populated accordingly.    

3.2 In this Paragraph 3, references to “Clauses” are references to the Clauses of the SCCs.

4. POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs

4.1 Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Addendum 1 (Data Processing Details) to the Privacy Schedule, with:

(a)SodaStream being ‘data exporter’; and 

(b)Supplier being ‘data importer’.

4.2 Part C of Annex I to the Appendix to the SCCs is populated as below:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit

Gustav-Stresemann-Ring 1

65189 Wiesbaden

4.3 Annex II to the Appendix to the SCCs is populated as below:

Information Security: please refer to the Security Measures determined by and set out in Section 5.1 of the Privacy Schedule.

Sub-Processors: when Supplier engages a Sub-Processor under these Clauses, Supplier shall enter into a binding contractual arrangement with such Sub-Processor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the Privacy Schedule – including in respect of: 

- applicable information security measures;

- notification of Security Incidents to Supplier; 

- return or deletion of SodaStream Personal Data as and where required; and 

- engagement of further Sub-Processors.


PART 2: POPULATION OF UK TRANSFER ADDENDUM

1. Where relevant in accordance with Section 8 to the Privacy Schedule, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below –

1.1. Part 1 to the UK Transfer Addendum. The Parties agree: 

(a)Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 to the Privacy Schedule and the foregoing provisions of this Addendum 2 (subject to the variations effected by the UK Mandatory Clauses described in (b) below); and 

(b)Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Exporter’ being deemed to have been ticked. 

1.2 Part 2 to the UK Transfer Addendum. The Parties agree to be bound by the UK Mandatory Clauses of the UK Transfer Addendum.

2. As permitted by Section 17 of the UK Mandatory Clauses, the Parties agree to the presentation of the information required by ‘Part 1: Tables’ of the UK Transfer Addendum in the manner set out in Section 1 of this Part 2; provided that the Parties further agree that nothing in the manner of that presentation shall operate or be construed so as to reduce the Appropriate Safeguards (as defined in Section 3 of the UK Mandatory Clauses). 

3. In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the Addendum to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Section 1 of this Part 2. 

PART 3: POPULATION OF SWISS TRANSFER MECHANISM

1. Where SodaStream Personal Data is subject to a Swiss Restricted Transfer, the SCCs apply as set forth in Part 1 of this Addendum 2 and shall be adjusted as set out below where the FADP applies to Swiss Restricted Transfers:

1.1 References to the Standard Contractual Clauses mean the Standard Contractual Clauses as amended by Section 1 (EEA Restricted Transfers) of this Schedule;

1.2 The Swiss Federal Data Protection and Information Commissioner shall be the sole Supervisory Authority for Swiss Restricted Transfers exclusively subject to the FADP;

1.3 The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the Standard Contractual Clauses shall be interpreted to include the FADP with respect to Swiss Restricted Transfers;

1.4 References to Regulation (EU) 2018/1725 are removed;

1.5 References to the “Union”, “EU” and “EU Member State” shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of exercising their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the Standard Contractual Clauses; 

1.6 Where Swiss Restricted Transfers are exclusively subject to the FADP, all references to the GDPR in the Standard Contractual Clauses are to be understood to be references to the FADP;

1.7 Where Swiss Restricted Transfers are subject to both the FDPA and the GDPR, all references to the GDPR in the Standard Contractual Clauses are to be understood to be references to the FDPA insofar as the Swiss Restricted Transfers are subject to the FADP;

1.8 The Standard Contractual Clauses as amended by this Addendum 2 also protect the Personal Data of legal entities until the entry into force of the Revised FADP.

 

Addendum 3 California Privacy Addendum

1. Order of Precedence. To the extent that the terms in this Addendum 3 (California Addendum) conflict with the terms in the rest of the Privacy Schedule, the terms in this Addendum 3 (California Addendum) prevail. Furthermore, the parties hereby agree that the terms of this California Addendum supersede and replace any respective obligations of the parties that relate to the Processing of Personal Data to the extent that such processing is subject to the CCPA.

2. Definitions. CCPA and other capitalized terms not defined in this Addendum 3 (California Addendum) are defined in the Privacy Schedule.

2.1 “business purpose”, “commercial purposes”, “sell”, “service provider” and “share” have the meanings given in the CCPA.

2.2 The definition of “Data Subject” includes “consumer” and “household” as defined in the CCPA.

2.3 The definition of “Personal Data” includes “personal information” as defined in the CCPA.

2.4 The definition of “Controller” includes “business” as defined in the CCPA.

2.5 The definition of “Processor” includes “service provider” as defined in the CCPA.

3. Obligations. 

3.1 SodaStream is providing the SodaStream Personal Data to Business Partner under the Agreement for the limited and specific business purposes as described in Addendum 1 (Data Processing Details) and otherwise performing under this Agreement.

3.2 Business Partner shall comply with its applicable obligations under the CCPA and provide the same level of privacy protection to SodaStream Personal Data as is required by the CCPA.

3.3 Business Partner acknowledges that SodaStream has the right to: (i) take reasonable and appropriate steps under Section 10 (Audit rights) of this Privacy Schedule to help to ensure that Business Partner’s use of SodaStream Personal Data is consistent with SodaStream’s obligations under the CCPA, (ii) receive from Business Partner notice and assistance under Section 6 (Communications & Data Subject Rights) of this Privacy Schedule regarding consumers’ requests to exercise rights under the CCPA and (iii) upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of SodaStream Personal Data. 

3.4 Business Partner shall notify SodaStream promptly after it makes a determination that it can no longer meet its obligations under the CCPA.

3.5 Business Partner shall not retain, use, or disclose SodaStream Personal Data: (i) for any purpose, including any commercial purposes, other than the business purposes described in Section 2.1 of this Addendum 3 (California Addendum) or (ii) outside of the direct business relationship between Business Partner with SodaStream, except, in either case, where and to the extent permitted by the CCPA. 

3.6 Business Partner shall not sell or share SodaStream Personal Data.

3.7 Business Partner shall not combine SodaStream Personal Data with other personal information except to the extent the CCPA expressly permits a service provider to do so.