Fourthwall Vendor Data Processing Agreement
Version: 2026-Aug-21
This Data Processing Agreement (“DPA”) is incorporated into and forms part of (and if applicable, amends the current version of) the Agreement (as defined below) between Fourthwall, Inc. (“Fourthwall”), and the company providing Services (as defined in the Agreement) to Fourthwall (“Vendor”), each a “Party” and collectively the “Parties.”
This DPA may be executed by signature, or entered into by Vendor's acceptance of, agreement to, or performance under, any purchase order, statement of work, order form, or other agreement or ordering document between the Parties that references this DPA. Each of the foregoing constitutes execution of this DPA, including deemed execution of the SCCs incorporated herein, by both Parties.
This DPA applies to and takes precedence over the agreement between the Parties and any associated contractual document between the Parties, such as a Master Services Agreement, order form, statement of work or data protection addendum thereunder (collectively, the “Agreement”), to the extent of any conflict. Fourthwall and Vendor agree as follows:
- Definitions. For purposes of this DPA:
- “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a party to this DPA, where “control” refers to direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
- “Data Protection Laws” means all applicable laws, regulations, and other legally binding requirements relating to privacy, data security, or the Processing of Personal Data, including, to the extent applicable, the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”); the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”); the United Kingdom Data Protection Act of 2018 (“UK GDPR”); and the Swiss Federal Act on Data Protection (“FADP”).
- “Data Subject” means an identified or identifiable natural person to whom Personal Data relates, and is deemed to also refer to “consumer” as defined in Data Protection Laws.
- “EU SCCs” means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, located http://data.europa.eu/eli/dec_impl/2021/914/oj, and completed as set forth below.
- “Personal Data” includes “personal data,” “personal information,” “personally identifiable information,” and analogous terms, as defined by applicable Data Protection Laws, that Vendor Processes in relation to the Agreement.
- “Process” and its cognates “Processing,” “Processed,” etc. mean any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Security Breach” means any accidental or unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- “Services” means the services that Vendor performs on behalf of Fourthwall pursuant to the Agreement.
- “Subprocessor” means any third party or Vendor Affiliate that Vendor engages to Process Personal Data.
- “UK SCCs” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (available as of the Effective Date at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf).
- The terms “Business,” “Consumer,” “Controller,” “Processor,” and “Service Provider” are defined as in Data Protection Laws. “Controller” is deemed to also refer to “Business,” and “Processor” is deemed to also refer to “Service Provider.”
- Role of the Parties; Scope and Purposes of Processing.
- This DPA applies to all Personal Data that Vendor Processes in relation to the Agreement.
- Where Fourthwall acts as a Controller, Vendor is Fourthwall’s Processor. Where Fourthwall acts as a Processor or Service Provider, Vendor is Fourthwall’s subprocessor.
- Vendor will Process Personal Data solely (i) in compliance with Data Protection Laws, including without limitation all applicable provisions of the CCPA; (ii) on Fourthwall’s behalf; and (iii) as necessary to fulfill its obligations to Fourthwall under the Agreement, including this DPA. For the avoidance of doubt, Vendor will Process Personal Data solely to provide the Services to Fourthwall under the Agreement for the following express business purposes: processing of manufacturing and order data associated with ecommerce transactions of Fourthwall or Fourthwall customers, and as otherwise set forth in the Agreement.
- Personal Data Processing Requirements.
- Vendor will not retain, use, or disclose Personal Data outside of the direct business relationship between Fourthwall and Vendor, or for any purpose (including any commercial purpose) not set forth in this DPA. Without limiting the foregoing, for the avoidance of doubt, Vendor will not Process Personal Data for its own internal analytics.
- Vendor will not “sell” or “share” any Personal Data, as such terms are defined in Data Protection Laws. Without limiting the foregoing, for the avoidance of doubt, Vendor will not disclose or make available Personal Data for cross-context behavioral advertising or targeted advertising.
- Vendor will not attempt to (1) re-identify any pseudonymized, anonymized, aggregate, or de-identified Personal Data, or (2) link, identify, or otherwise create a relationship between Personal Data and non-Personal Data or any other data, without Fourthwall’s express written permission.
- Vendor will comply with any applicable restrictions under Data Protection Laws on combining the Personal Data with personal data that Vendor receives from, or on behalf of, another person or persons, or that Vendor collects from any interaction between it and any Data Subject.
- Vendor will not otherwise engage in any Processing of Personal Data that is prohibited or not permitted by Processors or Service Providers under Data Protection Laws.
- Fourthwall retains the right to take reasonable and appropriate steps to (i) ensure that Vendor Processes Personal Data in a manner consistent with Data Protection Laws, and (ii) upon notice, stop and remediate unauthorized Processing of Personal Data, including any use of Personal Data not expressly authorized in this DPA.
- Vendor will provide the same level of privacy protection for Personal Data as is required under Data Protection Laws applicable to Fourthwall.
- Vendor will ensure that the persons it authorizes to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Vendor will promptly provide Fourthwall with all reasonable assistance and cooperation for the fulfilment of Fourthwall’s obligations under Data Protection Laws, including without limitation Fourthwall’s obligation to (i) respond to requests by Data Subjects (or their lawful representatives) to exercise their rights under Data Protection Laws regarding their Personal Data; (ii) perform any required data protection impact assessment of Processing or proposed Processing of Personal Data; and (iii) consult with regulatory authorities in relation to Processing or proposed Processing of Personal Data. Vendor will notify Fourthwall within two (2) business days of any Data Subject or government request regarding Vendor’s Processing of Personal Data, and will await written instructions from Fourthwall on how, if at all, to assist in responding.
- Vendor will promptly notify Fourthwall if Vendor determines that (i) it can no longer meet its obligations under this DPA or Data Protection Laws; (ii) it has breached this DPA, and shall cooperate to remediate such breach; or (iii) in Vendor’s opinion, an instruction from Fourthwall infringes Data Protection Laws.
- Security of Personal Data. Vendor will implement appropriate administrative, technical, physical, and organizational measures to protect Personal Data as required by Data Protection Laws. Such security measures shall at a minimum comply with Schedule B.
- Security Breach. Vendor will notify Fourthwall promptly, and in any event within seventy-two (72) hours, of any Security Breach. Vendor will comply with the Security Breach-related obligations directly applicable to it under Data Protection Laws and will assist Fourthwall in Fourthwall’s compliance with its Security Breach-related obligations, including without limitation by (a) providing Fourthwall with all information required for Fourthwall to comply with such obligations, and (b) at Vendor’s own expense, taking reasonable steps to mitigate the effects of the Security Breach and reduce the risk to Data Subjects whose Personal Data was involved.
- Subprocessors.
- Fourthwall acknowledges and agrees that Vendor may use Subprocessors to Process Personal Data in accordance with the provisions within this DPA and Data Protection Laws. Where Vendor sub-contracts any of its rights or obligations concerning Personal Data to a Subprocessor, Vendor will: (i) take steps to select and retain Subprocessors that are capable of maintaining appropriate privacy and security measures to protect Personal Data consistent with applicable Data Protection Laws; and (ii) require that each Subprocessor complies with obligations that are no less restrictive than those imposed on Vendor under this DPA. Vendor shall be responsible to Fourthwall for all acts and omissions of Subprocessors as if they were committed by Vendor.
- Vendor will maintain an up-to-date list of its Subprocessors and provide such list to Fourthwall on request. Vendor will provide Fourthwall with twenty (20) days’ notice of any new Subprocessor added to the list prior to providing the new Subprocessor with Personal Data or access thereto. If Fourthwall reasonably objects to a new Subprocessor within that 30-day period, Vendor will not provide the Subprocessor with Personal Data or access thereto, and Vendor will use reasonable efforts to adjust the Services or recommend a commercially reasonable change to Fourthwall’ use of the Services to avoid Processing of Personal Data by the objected-to Subprocessor without unreasonably burdening Fourthwall. If Vendor is unable to do either of the foregoing to Fourthwall’s satisfaction, Fourthwall may, in its sole discretion, terminate the Services or that portion of the Services involving the objected-to Subprocessor on written notice to Vendor.
- Data Transfers.
- Vendor will not engage in any cross-border Processing of Personal Data, or transmit, directly or indirectly, any Personal Data to any country outside of the country from which such Personal Data was collected, without complying with applicable Data Protection Laws. Where Vendor engages in an onward transfer of Personal Data, Vendor shall ensure that a lawful data transfer mechanism is in place prior to transferring Personal Data from one country to another.
- To the extent legally required, by entering into this DPA, Fourthwall and Vendor are deemed to have signed the EU SCCs, which form part of this DPA and (except as described in Section 7(c) and (d) below) will be deemed completed as follows:
- Module 2 of the EU SCCs applies to transfers of Personal Data from Fourthwall (as a controller) to Vendor (as a processor) and Module 3 of the EU SCCs applies to transfers of Personal Data from Fourthwall (as a processor) to Vendor (as a subprocessor).
- Clause 7 (the optional docking clause) is included;
- Under Clause 9 (Use of subprocessors), the Parties select Option 2 (General written authorization). The initial list of subprocessors shall be provided to Fourthwall and Vendor shall update that list and provide a notice to Fourthwall in advance of any intended additions or replacements of subprocessors as provided in Section 6.
- Under Clause 11 (Redress), the optional language requiring that data subjects be permitted to lodge a complaint with an independent dispute resolution body shall not be deemed to be included;
- Under Clause 17 (Governing law), the Parties choose Option 1 (the law of an EU Member State that allows for third-Party beneficiary rights). The Parties select the laws of Ireland;
- Under Clause 18 (Choice of forum and jurisdiction), the Parties select the courts of Ireland;
- Annex I(A) and I(B) (List of Parties) are completed as set forth in Schedule A of this DPA;
- Under Annex I(C) (Competent supervisory authority), the Parties shall follow the rules for identifying such authority under Clause 13 and, to the extent legally permissible, select the Irish Data Protection Commission;
- Annex II (Technical and organizational measures) is completed with Schedule B of this DPA; and
- Annex III (List of subprocessors) is not applicable as the Parties have chosen General Authorization under Clause 9.
- With respect to Personal Data transferred from the United Kingdom for which United Kingdom law (and not the law in any European Economic Area jurisdiction or Switzerland) governs the international nature of the transfer, the UK SCCs form part of this DPA and takes precedence over the rest of this DPA as set forth in the UK SCCs. Undefined capitalized terms used in this provision shall mean the definitions in the UK SCCs. For purposes of the UK SCCs, they shall be deemed completed as follows: (i) the Parties’ details shall be the Parties and their affiliates to the extent any of them is involved in such transfer; (ii) the Key Contacts shall be the contacts set forth in Schedule A; (iii) the Approved EU SCCs referenced in Table 2 shall be the EU SCCs as executed by the Parties; (iv) Annex 1A, 1B, II, and III shall be set forth in Schedules A and B below; (v) either Party may end this DPA as set out in Section 19 of the UK SCCs; and (vi) by entering into this DPA, the Parties are deemed to be signing the UK SCCs.
- For transfers of Personal Data that are subject to the FADP, the EU SCCs form part of this DPA as set forth in Section 7(b) of this DPA, but with the following differences to the extent required by the FADP: (i) references to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR; (ii) references to personal data in the EU SCCs also refer to data about identifiable legal entities until the entry into force of revisions to the FADP that eliminate this broader scope; (iii) the term “member state” in EU SCCs shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs; and (iv) the relevant supervisory authority is the Swiss Federal Data Protection and Information Commissioner (for transfers subject to the FADP and not the GDPR), or both such Commissioner and the supervisory authority identified in the EU SCCs (where the FADP and GDPR apply, respectively).
- Audits. Subject to the conditions set forth herein, Vendor will make available to Fourthwall all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Fourthwall or another auditor mandated by Fourthwall, provided that such audit shall occur not more than once every twelve (12) calendar months, upon thirty (30) days’ prior written notice, at Fourthwall’s expense, and during Vendor’s normal business hours.
- Return of Destruction of Personal Data. Except to the extent required otherwise by Data Protection Laws, Vendor will, at the choice of Fourthwall, return to Fourthwall and/or securely destroy all Personal Data upon (a) written request of Fourthwall or (b) termination of the Agreement. Vendor will inform Fourthwall if it is not able to return or delete the Personal Data. For the avoidance of doubt, Vendor may retain Personal Data that is included in routine backups, and the provisions of this DPA will apply to such Personal Data for as long as Vendor retains it.
- Indemnification and Limitation of Liability. Vendor will defend, indemnify and hold Fourthwall harmless from and against all claims, damages, liabilities, losses, expenses and costs (including reasonable fees and expenses of attorneys and other professionals) arising out of or resulting from a Security Breach or Vendor’s breach of this DPA.
- Survival. The provisions of this DPA survive the termination or expiration of the Agreement for so long as Vendor or its Subprocessors Process Personal Data.
Fourthwall, Inc.
Signature: _____________________________
Printed Name: _________________________
Title: ___________________________________
Date: ___________________________________
[Vendor]
Signature: _____________________________
Printed Name: _________________________
Title: ___________________________________
Date: ___________________________________
Schedule A
ANNEX I
A. LIST OF PARTIES
Data exporter(s): Fourthwall, Inc.
Address: As provided in the Agreement.
Contact person’s name, position, and contact details: As provided in the Agreement.
Activities relevant to the data transferred under these Clauses: The data exporter receives the data importer’s Services pursuant to their underlying Agreement.
Signature and date: The Parties agree that execution of the DPA shall constitute execution of these EU SCCs by both parties.
Role: Controller or Processor
Data importer(s): Vendor, as defined in the Agreement.
Address: As provided in the Agreement.
Contact person’s name, position, and contact details: As provided in the Agreement.
Activities relevant to the data transferred under these Clauses: The data importer provides Services to the data exporter pursuant to their underlying Agreement.
Signature and date: The Parties agree that execution of the DPA shall constitute execution of these EU SCCs by both parties.
Role: Processor (where Fourthwall is a controller); subprocessor (where Fourthwall is a processor)
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred: The Personal Data transferred concerns [end users of Fourthwall customers].
Categories of personal data transferred: Any personal data provided by Fourthwall to Vendor for Vendor to perform services under the Agreement including [names and mailing addresses].
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous for the duration of the Agreement.
Nature of the processing: Vendor’s Processing activities shall be limited to those discussed in the Agreement and the DPA.
Purpose(s) of the data transfer and further processing: The purpose of the transfer to and further Processing of Personal Data by Vendor is for Vendor to provide the Services to Fourthwall as set forth in the Agreement.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for the period of time necessary for Vendor to provide the Services to Fourthwall under the Agreement and/or in accordance with applicable legal requirements.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Same as above to the extent that Personal Data is provided to Subprocessors for purposes of providing the Services under the Agreement to Fourthwall.
C. COMPETENT SUPERVISORY AUTHORITY
To the extent legally permitted, the competent supervisory authority is the Irish Data Protection Commission.
Schedule B
ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Vendor will implement and maintain the following administrative, technical, physical, and organizational security measures for the Processing of Personal Data:
- Use Restrictions
Vendor shall only access and use Personal Data in accordance with Data Protection Laws and the DPA, to fulfill its obligations under the Agreement or as explicitly directed by Fourthwall, and for no other purposes.
- Information Security Management
Vendor agrees to establish and maintain a written information security and privacy program (“Information Security Program” or “ISP”) containing policies, procedures and controls to manage access to systems and data that are no less rigorous than accepted industry practices, including the following:- Restriction of access to Personal Data to only those personnel, subcontractors or agents (“Data Personnel”) requiring access to fulfill Vendor’s obligations under the Agreement or DPA, consistent with the concepts of least privilege and need-to-know. Additional measures with respect to Data Personnel include:
- immediately terminating access privileges to systems and data for any Data Personnel that no longer need such access, and conducting reviews of access lists to ensure that access privileges have been appropriately provisioned and terminated no less than quarterly;
- providing ongoing training and awareness materials on the Information Security Program to all Data Personnel, including on the topics of phishing and social engineering; and
- applying the concept of separation of duties for all Data Personnel roles with access to Personal Data.
- Maintenance of appropriate network security measures, including but not limited to firewalls to segregate internal networks from the internet, risk-based network segmentation, and intrusion prevention or detection systems to alert Vendor to suspicious network activity.
- Performance of security testing on any applications or application code provided to or developed on behalf of Vendor to ensure that the application or application code is secure against any vulnerabilities that are identified through industry standard testing, and any vulnerabilities reported to Vendor by any third party.
- Performance of regular vulnerability scans and assessments on all systems storing, processing, or transmitting Personal Data to identify all potential vulnerabilities on such systems.
- Risk-prioritized remediation of identified vulnerabilities in a timely manner, including timely implementation of all manufacturer- and developer-recommended security updates and patches to operating systems and third-party software storing, processing, or transmitting Personal Data, or otherwise installed on Vendor systems.
- Performance of periodic penetration tests as needed.
- Installation of antivirus and malware protection software with up-to-date definitions and signatures on all Vendor workstations.
- Enforcement of complex password requirements on all Vendor systems.
- Use of strong encryption for all authentication credentials to prevent unauthorized account access.
- Implementation of secure workstation protection policies for Vendor systems.
- Encryption of all Personal Data in transit and at rest using robust encryption algorithms and in accordance with industry standards for secure key and protocol negotiation and key management, including full disk encryption for all Vendor workstations.
- Requirement that all remote network and system access to Vendor systems utilize multi-factor authentication.
- Restriction of access to Personal Data to only those personnel, subcontractors or agents (“Data Personnel”) requiring access to fulfill Vendor’s obligations under the Agreement or DPA, consistent with the concepts of least privilege and need-to-know. Additional measures with respect to Data Personnel include:
- Physical Security
- Access to Vendor facilities (including offices and coworking spaces) shall be restricted to personnel with authorized access on a need-to-know basis. Restricted areas of facilities, such as server rooms if applicable, shall be subject to risk-appropriate access controls, such as by requiring key cards and/or PINs for entry. Vendor shall regularly review audit trails of access to these restricted areas.
- Vendor shall identify and log all visitors to its facilities and ensure that visitors to restricted areas are escorted by Vendor personnel at all times.
- Vendor shall implement and enforce “clean desk” (i.e., prohibiting documents with sensitive data from being left on desks, tables, etc. after work hours or for prolonged periods) policies throughout its facilities.
- Business Continuity & Disaster Recovery
Vendor shall maintain appropriate business continuity and disaster recovery procedures to ensure prompt resumption and continuation of Vendor services in the event of a disruption. Vendor shall periodically test these procedures and provide information about them to Fourthwall upon request.
- Subcontracting
- Vendor shall implement and maintain a documented vendor risk management program to ensure that:
- due diligence is conducted on any prospective subcontractor to ensure that they are capable of meeting the security standards outlined in this Annex II; and
- the subcontractor is contractually required to comply with the terms of this Annex II.
- Vendor shall implement and maintain a documented vendor risk management program to ensure that:
- Compliance Monitoring
- Vendor shall regularly test and monitor the effectiveness of the security practices and procedures in the ISP, and will evaluate and adjust the ISP and information security safeguards in light of the results of the testing and monitoring, any material changes to its operations or business arrangements, or any other circumstances that Vendor knows or reasonably should know may have a material effect on its ISP and information security safeguards.
- Upon request of Fourthwall, Vendor shall provide a copy of its most current third-party information security audit report and/or certification, if any.