# ScopeWorth US State Privacy Addendum Version 1.0. Status: draft for legal review. This addendum forms part of the ScopeWorth Data Processing Agreement version 1.0 and is accepted together with it. It is not executed until legal review is complete and the document manifest marks the set `published`. ## 1. Application 1.1 This addendum applies only to the extent a US state privacy law applies to ScopeWorth's processing of Customer Personal Information. That includes the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and the controller-processor provisions of other US state comprehensive privacy laws (together, "US State Privacy Laws"). Whether a law applies depends on the Customer, the data and the processing; this addendum does not state that every law applies to every dataset. 1.2 In California, personal information includes information about employees, job applicants, contractors and business contacts. Customer Personal Information covered by this addendum can therefore include the Customer's personnel and its clients' contacts. 1.3 "Customer Personal Information" means personal information, as defined by the applicable US State Privacy Law, that ScopeWorth processes on the Customer's behalf under the Agreement. ## 2. Roles 2.1 Where the Customer is a "business" or "controller", ScopeWorth is its "service provider", "contractor" or "processor". Where the Customer processes data on behalf of its own client, ScopeWorth acts as the Customer's subcontracted service provider or processor. These roles correspond to the GDPR roles in section 3 of the DPA. 2.2 ScopeWorth does not receive Customer Personal Information as a "third party" for its own independent use. ## 3. Permitted purposes and restrictions 3.1 ScopeWorth processes Customer Personal Information only for the business purpose of providing, securing, supporting and improving the service the Customer uses, as described in Annex I of the DPA, and as otherwise permitted for service providers by the applicable law. 3.2 ScopeWorth will not: - sell or share Customer Personal Information, including for cross-context behavioral advertising; - retain, use or disclose it for any purpose other than the business purpose in 3.1, or outside the direct business relationship with the Customer; - combine it with personal information ScopeWorth receives from or on behalf of another person, or collects from its own interactions with individuals, except as the applicable law expressly permits service providers to do; - use it to train general-purpose machine learning models, or permit its subprocessors to do so. ## 4. Protection and compliance 4.1 ScopeWorth provides the same level of privacy protection as the applicable US State Privacy Laws require, including the confidentiality and security measures in the DPA. 4.2 ScopeWorth will notify the Customer if it determines it can no longer meet its obligations under the applicable US State Privacy Laws. 4.3 The Customer may take reasonable and appropriate steps to ensure ScopeWorth uses Customer Personal Information consistently with the Customer's obligations, and, on notice, to stop and remediate unauthorized use. ScopeWorth makes available the information reasonably necessary to demonstrate compliance and supports reasonable assessments under section 12 of the DPA. ## 5. Consumer requests 5.1 ScopeWorth assists the Customer, by appropriate technical and organizational measures, in responding to requests to access, correct, delete or port Customer Personal Information, and to limit or opt out of its processing where the law gives that right. 5.2 ScopeWorth forwards to the Customer any request it receives about Customer Personal Information, verifies the authority of anyone instructing it on the Customer's behalf, preserves tenant boundaries, and tracks the applicable response deadline. Exporting or deleting a workspace does not by itself fulfil every individual request. ## 6. Subprocessors ScopeWorth engages subprocessors under section 7 of the DPA, including its 30-day notice and objection process, and binds each subprocessor by written contract to obligations no less protective than this addendum. ## 7. Security incidents Section 10 of the DPA applies. Where a US state law requires notice sooner than 24 hours, ScopeWorth notifies within that shorter period. ## 8. Certification ScopeWorth certifies that it understands the restrictions in section 3 and will comply with them. ## 9. Order of precedence Where this addendum conflicts with the DPA for processing a US State Privacy Law covers, this addendum prevails for that processing.