Data Processing Agreement

Last Updated September 10, 2026

This Data Processing Agreement, including Attachments 1 and 2 ("DPA") is incorporated into each Agreement between Articulate Global, LLC (together with its Affiliates, “Articulate”) and the customer named in the Agreement (“Customer”, “you”, “your”) for Articulate’s provision to Customer of the Services, as defined below. Customer enters into this DPA on behalf of itself and any of its Affiliates that it permits to use the Services pursuant to the Agreement (“Authorized Affiliate”). Articulate and Customer are each referred to individually as a “Party” and collectively as the “Parties”.

1. Definitions

For purposes of this DPA, capitalized terms have the meanings set forth below. Other capitalized terms have the meaning set forth in the Agreement.

1.1. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a party to this DPA, where “control” means ownership of more than 50% of the voting interests of such an entity.

1.2. “Agreement” means the Online Services Agreement, or other underlying services agreement(s) entered into by Articulate and Customer.

1.3. Applicable Data Protection Law” means privacy, data protection, data security, breach notification, and international data transfer laws applicable to Articulate’s Processing of Customer Personal Data under the Agreement, including the General Data Protection Regulation (GDPR), UK Data Protection Laws, and other applicable national or regional privacy laws such as the California Consumer Privacy Act (“CCPA”), in each case as amended, replaced, or superseded. Each party is responsible only for the Applicable Data Protection Law applicable to it.

1.4. “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

1.5. “Customer Content” (or “Your Content”) means data, content, files, text, images, audio, video, prompts, and materials that Customer and its Users upload, create, submit, import, transmit, or otherwise make available to or through the Services, including Input and Output. 

1.6. “Customer Personal Data” means Personal Data that Articulate Processes as a Processor on behalf of Customer in connection with the Services, including Personal Data submitted, collected, observed, inferred, or generated through Customer’s or its Users’ use of the Services.

1.7. “Data Subject” means an identified or identifiable natural person. Where the CCPA applies, the term also includes an identified or identifiable household.

1.8. “De-Identified Data” means data derived from Customer Content, Usage Data or Personal Data that Articulate has processed so that it can no longer reasonably be used, alone or in combination, to identify an individual, a Customer, or the substance of Customer’s proprietary content.

1.9. “Personal Data” or “Personal Information” (as defined under CCPA) means any information relating to an identified or identifiable individual to the extent that information is protected in an Applicable Data Protection Law.

1.10. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

1.11. “Process and “Processing” mean any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

1.12. “Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

1.13. “Services” means both the hosted, web-based applications and any downloadable, installable client applications that Articulate makes available as part of its platform including features, functionality, updates or upgrades made generally available to customers. Services do not include Non-Articulate Services.

1.14. “Standard Contractual Clauses and “2021 SCCs” mean the clauses issued pursuant to the EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at http://data.europa.eu/eli/dec_impl/2021/914/oj and completed as described in the “Data Transfers” section below.

1.15. “Subprocessor means any subcontractor engaged by Articulate for the Processing of Personal Data.

1.16. “Trust & Compliance Documentation” means the documentation regarding privacy, data security, and Subprocessor information applicable to the specific Services purchased by Customer, as may be updated periodically, and accessible via Articulate’s website at https://articulate.com/trust and https://articulate.com/gdpr.

1.17. “UK SCC Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (available as of the Effective Date at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf), completed as set forth in the “Data Transfers” section below.

1.18. “User” means an individual or individuals that Customer permits to access and use the Services, including end users engaging with Customer Content.

2. Scope and Relationship of the Parties

2.1. This DPA applies to Customer Personal Data that Articulate Processes as a Processor on behalf of Customer in connection with the Services, as further described in Attachment 1.

2.2. To the extent Articulate Processes Personal Data for its independently determined legitimate business purposes as described in the Agreement or Privacy Notice, Articulate acts as an independent Controller for that Processing.

2.3. Each Party is responsible for complying with the obligations applicable to its own Controller activities.

2.4. If you are acting on behalf of a third-party Controller (or on behalf of intermediaries such as other Processors of the Controller):

2.4.1. You represent that you are acting with full authority on behalf of the Controller;

2.4.2. You will serve as the sole point of contact for Articulate with regard to any such third parties;

2.4.3. Articulate need not interact directly with any such third party in matters relating to this DPA; and

2.4.4. Where Articulate would otherwise be required to provide information, assistance, cooperation, or anything else to such third party, Articulate may provide it solely to you; but

2.4.5. Articulate is entitled to follow the instructions of such third party with respect to such third party’s Personal Data instead of your instructions if Articulate reasonably believes this is legally required under the circumstances.

3. Your Instructions to Articulate

3.1. Articulate will Process the Customer Personal Data only as described in the Agreement, unless obligated to do otherwise by an Applicable Data Protection Law. In such a case, Articulate shall inform you of that legal requirement before the Processing unless legally prohibited from doing so.

3.2. The details of the Processing are set forth in Attachment 1 to this DPA.

3.3. The Agreement, including this DPA, along with your configuration of any settings, integrations enabled, or other options in the Services, constitute your complete and final instructions to Articulate regarding the Processing of Customer Personal Data, including for purposes of the Standard Contractual Clauses, if they apply.

3.4. You will comply with Applicable Data Protection Laws relevant to your use of the Services, including by obtaining any consents and providing any notices required under an Applicable Data Protection Law for Articulate to provide the Services. You will ensure that you are entitled to transfer the Customer Personal Data to Articulate so that Articulate and its Subprocessors may lawfully Process the Personal Data in accordance with this DPA.

3.5. You shall not instruct Articulate to Process Customer Personal Data in violation of an Applicable Data Protection Law. Articulate shall promptly inform you if, in Articulate’s opinion, an instruction from you violates an Applicable Data Protection Law.

4. Data Use Limitation

4.1. Articulate will not “sell” Personal Data as such term is defined under the CCPA (regardless of whether the CCPA applies) and other similar state laws in the United States, and will not “share” Personal Data within the meaning of the CCPA (regardless of whether the CCPA applies). Articulate will not retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Articulate.

4.2. In the case of a legal obligation to provide Customer Personal Data to a third party, to the extent legally permitted: (i) Articulate will promptly provide Customer a reasonable opportunity to contest the legal obligation or to seek protection for the disclosure; (ii) Articulate will use reasonable efforts to redirect a government demand to Customer and to challenge any demand that Articulate reasonably believes is unlawful, disproportionate, or overbroad;  and (iii) Articulate, after consultation with Customer, will disclose only the minimum amount of Customer Personal Data necessary to comply with the legal obligation.

4.3. Articulate will comply with any applicable restrictions under the CCPA on combining Customer Personal Data with Personal Data that Articulate receives from, or on behalf of, another person or persons, or that Articulate collects from any interaction between it and a Data Subject.

4.4. De-Identified and Aggregated Data. Notwithstanding Section 4.1, Articulate may create De-Identified Data and aggregated data from Customer Personal Data and may retain, use, and disclose such data, including in combination with data derived from other customers, to operate, secure, analyze, develop, test, benchmark, tune, and improve the Services and supporting systems, and to produce aggregate, statistical, or comparative analytics, provided that such data  cannot reasonably identify Customer, any Data Subject, or the substance of Customer Content.

4.4.1. Articulate will: (i) maintain De-Identified Data in de-identified form; (ii) not attempt to re-identify any De-Identified Data, except solely to test and determine whether its de-identification processes work or as required by law; (iii) not use De-Identified Data to make decisions concerning an identified Data Subject; (iv) require any recipient to maintain the data in de-identified form and prohibit re-identification; and (v) not sell, share for cross-context behavioral advertising, or otherwise disclose Customer Personal Data,  except as permitted by this DPA and Applicable Data Protection Laws.

5. Subprocessors

5.1. Articulate may engage Subprocessors to Process Customer Personal Data in connection with providing the Services, in compliance with Applicable Data Protection Laws. Prior to a Subprocessor’s Processing of Customer Personal Data, Articulate will impose contractual obligations on the Subprocessor that are substantially the same as those imposed on Articulate under this DPA. Articulate is liable for its Subprocessors’ performance to the same extent Articulate is liable for its own performance under the Agreement.

5.2. A current list of Subprocessors is available at https://articulate.com/trust/gdpr/subprocessors. Articulate will promptly (and in any event, thirty (30) days before a new Subprocessor is scheduled to begin Processing Customer Personal Data) provide notice to Customers by updating the aforementioned subprocessor list(s) regarding any such new Subprocessor prior to its Processing of Personal Data, unless exigent circumstances (such as the failure of an existing Subprocessor) require their earlier Processing of Customer Personal Data. In such an instance, Articulate will notify Customer of the replacement as soon as reasonably practicable, and Customer retains the objection rights in 5.3.

5.3. You may object to Articulate’s use of a new Subprocessor by notifying Articulate within ten (10) business days after Articulate notifies you of the new Subprocessor pursuant to Section 5.2. If you reasonably object to a new Subprocessor, Articulate will use reasonable efforts to make available to you a change in the Services or recommend a commercially-reasonable change to your configuration or use of the Services to avoid Processing of Customer Personal Data by the objected-to new Subprocessor without unreasonably burdening you. If Articulate is unable to make available such change within a reasonable time period, which shall in no event exceed thirty (30) days, you may terminate only the affected portion of the Services by providing written notice to Articulate and ceasing use of those Services on the effective date of the termination. If such termination results in Customer no longer being able to utilize other portions of the Services, then Articulate will refund you a prorated amount covering the remainder of the term of such Services following the effective date of termination.  If you do not object to use of the new Subprocessor and terminate as set forth above, the Subprocessor is deemed to be accepted by you. 

5.4. Your agreement to this Section 5 constitutes your consent under the Standard Contractual Clauses, if they apply, and to Processing of Customer Personal Data by the Subprocessors that are listed in the applicable Trust & Compliance Documentation as of the effective date of the Agreement.

6. Security

6.1. Articulate will assist you in your compliance with the security obligations of the GDPR and other Applicable Law, as relevant to Articulate’s role in Processing Customer Personal Data, taking into account the nature of Processing and the information available to Articulate, by implementing technical and organizational measures described in Attachment 2 to this DPA, without prejudice to Articulate’s right to make future replacements or modifications to the measures that do not materially lower the level of security of the Customer Personal Data.

6.2. You are solely responsible for reviewing any available security documentation and features (if available) and evaluating for yourself whether the Services and related security meet your needs, including your security obligations under Applicable Law.

6.3. Articulate will ensure that the individuals Articulate authorizes to Process Customer Personal Data (i) are subject to a written confidentiality agreement covering such data or are under an appropriate statutory obligation of confidentiality and (ii) receive training appropriate to their role in the Processing of the Personal Data.

7. Personal Data Breach Notification

7.1. Articulate and Customer will comply with the Personal Data Breach-related obligations directly applicable to them under the GDPR and other Applicable Data Protection Laws, including any obligations to notify Data Subjects, government authorities, or third parties.

7.2. Taking into account the nature of Processing and the information available to Articulate, Articulate will reasonably assist you in complying with the Personal Data Breach-related obligations applicable to you under an Applicable Data Protection Law by informing you without undue delay after becoming aware of a Personal Data Breach. Such notification is not an acknowledgement of fault or responsibility. To the extent available, this notification will include Articulate’s then-current assessment of the following, which may be based on incomplete information:

7.2.1. The nature of the Personal Data Breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned;

7.2.2. The likely consequences of the Personal Data Breach; and

7.2.3. Measures taken or proposed to be taken by Articulate to address the Personal Data Breach, including, where applicable, measures to mitigate its possible adverse effects.

7.3. Articulate shall make reasonable efforts to identify the cause of a Personal Data Breach and take such remediation measures as Articulate deems necessary and reasonable.

8. Assistance Responding to Data Subjects

8.1. If Articulate receives a Data Subject Request or complaint directed to Customer or an Authorized Affiliate, Articulate will forward the Data Subject Request or complaint to Customer promptly. Articulate will not respond to any Data Subject Request concerning Customer Personal Data, other than to advise the Data Subject to submit the request to Customer, except on the written instructions of Customer or as required by an Applicable Data Protection Law. 

8.2. Taking into account the nature of the Processing, Articulate will reasonably assist you with the fulfillment of your obligation to honor requests by individuals to exercise their rights under the GDPR or any other Applicable Data Protection Law (such as rights to access their Personal Data) (“Data Subject Request”) by appropriate organizational and technical measures, insofar as possible. To the extent that you, in your use of the Services, are unable to address a Data Subject Request, Articulate will upon your request provide commercially reasonable efforts to assist you in responding to such Data Subject Request, to the extent that Articulate is required to do so under an Applicable Data Protection Law and is legally authorized to do so.

9. Assistance with DPIAs and Consultation with Supervisory Authorities

9.1. Taking into account the nature of the Processing and the information available to Articulate, Articulate will, upon your written request, provide reasonable assistance and cooperation to you for your performance of any legally required data protection impact assessment of the Processing or proposed Processing of the Personal Data in connection with the Services, and with related consultation with supervisory authorities, but only to the extent such information is required by an Applicable Data Protection Law and not publicly available. Additional support for data protection impact assessments or relations with regulators will require mutual agreement on fees, the scope of Articulate’s involvement, and any other terms that the parties deem appropriate.

10. Data Transfers

10.1. You authorize Articulate and its Subprocessors to make international transfers of the Customer Personal Data in accordance with this DPA and Applicable Data Protection Law.

10.2. Data Privacy Framework. To the extent Articulate maintains a valid certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework, Articulate may rely on the applicable framework for covered transfers of Personal Data to the United States. If an applicable certification or framework is withdrawn, terminated, revoked, invalidated, or otherwise ceases to provide a valid transfer mechanism, the transfer provisions in Sections 10.3 through 10.5 will automatically apply to the affected transfers without further action by the parties.

10.3. To the extent otherwise legally required, the 2021 SCCs form part of this DPA and take precedence over the rest of this DPA to the extent of any conflict, and (except as described in Section 10.4) they will be deemed completed as follows:

10.3.1. To the extent you act as a controller and Articulate acts as your processor with respect to the Customer Personal Data subject to the 2021 SCCs, its Module 2 applies. To the extent you act as a processor and Articulate acts as your subprocessor with respect to the Customer Personal Data subject to the 2021 SCCs, its Module 3 applies.

10.3.2. Clause 7 (the optional docking clause) is included.

10.3.3. Under Clause 9 (Use of sub-processors), the parties select Option 2 (General written authorization). The current list of Subprocessors is available at https://articulate.com/trust/gdpr/subprocessors. For the purposes of Clause 9(c) and only to the extent the Standard Contractual Clauses apply, you acknowledge that Articulate may be restricted from disclosing Subprocessor agreements. Articulate will use reasonable efforts to require any Subprocessor appointed to disclose the Subprocessor agreement to you and will provide (on a confidential basis) all reasonable information. Commercial information or provisions unrelated to requirements under the Standard Contractual Clauses may be removed or redacted by Articulate in its discretion.

10.3.4. Under Clause 11 (Redress), the optional requirement that data subjects be permitted to lodge a complaint with an independent dispute resolution body does not apply.

10.3.5. Under Clause 17 (Governing law), the parties choose Option 1 (the law of an EU Member State that allows for third-party beneficiary rights). The parties select the law of Ireland.

10.3.6. Under Clause 18 (Choice of forum and jurisdiction), the parties select the courts of Ireland.

10.3.7. Under Annex I(A) of the 2021 SCCs (List of parties):

The exporter is you. The exporter’s contact information for Articulate to use is as set forth in Agreement. The exporter’s contact information for Data Subjects to use is set forth in its privacy policy, as are the identity and contact details of the exporter’s data protection officer (if any) and representative in the European Union (if any).

The exporter’s activity as relevant to the data transferred under these Clauses is its use of the relevant Services.

The importer is Articulate. The importer’s mailing address is set forth in the Agreement, and its email address is [email protected], subject to an update by Articulate of those addresses in accordance with the Agreement.

The importer’s activity as relevant to the data transferred under these Clauses is its provision of the relevant Services.

When the Customer purchases the Services, the parties are deemed to be signing Annex I(A) of the 2021 SCCs.

10.3.8. For any particular Services, the details for Annex I(B) of the 2021 SCCs (Description of transfer) are set forth in Attachment 1 of the DPA.

10.3.9. Under Annex I(C) of the 2021 SCCs (Competent supervisory authority), the parties shall follow the rules for identifying such authority under Clause 13 and, to the extent legally permissible, select the Irish Data Protection Commission.

10.3.10. Annex II of the 2021 SCCs (Technical and organizational measures) is set forth in Attachment 2 of this DPA.

10.3.11. Annex III of the 2021 SCCs (List of subprocessors) is inapplicable.

10.4. To the extent legally required under UK Data Protection Law, the UK SCC Addendum forms part of this DPA and takes precedence over the rest of this DPA as set forth in the UK SCC Addendum.  Undefined capitalized terms used in this Section 10.3 shall have the definitions set forth in the UK SCC Addendum. For purposes of the UK SCC Addendum:

10.4.1. Table 1 of the UK SCC Addendum: the Parties are you and Articulate, with contact details as set forth in Section 10.2.7 of this DPA.

10.4.2. Table 2 of the UK SCC Addendum: the Approved Standard Contractual Clauses are the Standard Contractual Clauses as set forth in Section 10.2 of this DPA. 

10.4.3. Table 3 of the UK SCC Addendum:

Annex 1A: as set forth in Section 10.2.7 of this DPA.

Annex 1B: as set forth in Attachment 1 of this DPA.

Annex II: as set forth in Attachment 2 of this DPA.

Annex III: not applicable.

10.4.4. Table 4 of the UK SCC Addendum: neither party has the termination right set forth in Section 19 of the UK SCC Addendum.

10.4.5. By entering into this DPA, the parties are deemed to be signing the UK SCC Addendum.

10.5. For transfers of Customer Personal Data that are subject to the Swiss Federal Act on Data Protection (“FADP”), the 2021 SCCs form part of this DPA as set forth in Section 10.2 of this DPA, but with the following differences to the extent required by the FADP:

10.5.1. References to the GDPR in the 2021 SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR.

10.5.2. The term “member state” in the 2021 SCCs shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the 2021 SCCs.

10.5.3. Under Annex I(C) of the 2021 SCCs (Competent supervisory authority):

Where the transfer is subject exclusively to the FADP and not the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

Where the transfer is subject to both the FADP and the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner insofar as the transfer is governed by the FADP, and the supervisory authority is as set forth in Section 10.2.9 of this DPA insofar as the transfer is governed by the GDPR.

11. Audits

11.1. Upon your written request, Articulate will make available to you all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits including inspections, conducted by you or another auditor mandated by you, as follows:

11.1.1. If the requested audit scope is addressed in an audit report issued by a third-party auditor within the prior twelve (12) months and Articulate provides such report to you and confirms that there are no known material changes in the controls audited, you agree to accept the findings presented in the report in lieu of requesting an audit of the same controls covered by the report. The report is Confidential Information of Articulate.

11.1.2. If not covered by such report, Articulate will provide a written description of its compliance measures for this DPA. This is Confidential Information of Articulate.

11.1.3. You agree to exercise any right you may have to conduct an audit or inspection, including under the Standard Contractual Clauses, if they apply, by instructing Articulate to provide the report and/or information described above. If you wish to change this instruction regarding the audit, you may request a change to this instruction by sending Articulate written notice as provided for in the Agreement. Such additional support may be available and would require mutual agreement on fees you would be charged, audit scope, the scope of Articulate’s involvement, and any other terms that the parties deem appropriate.

11.1.4. Customer must provide Articulate with sixty (60) days’ written notice before conducting an audit, and such audits may occur no more than once during twelve (12) months. Customer may only conduct audits during Articulate’s normal business hours and must minimize business disruption to Articulate.

11.1.5. To the extent legally permissible, and to the extent that audits interrupt the normal course of Articulate’s business, you will reimburse Articulate for any time expended for audit-related assistance at the rates mutually agreed upon by the parties.

11.1.6. Nothing in this DPA will require Articulate to disclose or make available:

any data of any other customer of Articulate;

access to systems;

Articulate's accounting or financial information;

any trade secret of Articulate;

any information or access that, in Articulate’s reasonable opinion, could (A) compromise the security of Articulate systems or premises; or (B) cause Articulate to breach its obligations under Applicable Law or applicable contracts; or

any information sought for any reason other than the good faith fulfillment of your obligations under Applicable Law to audit compliance under this DPA.

11.1.7. You will promptly notify Articulate of, and provide information about, any actual or suspected non-compliance discovered during an audit.

12. Return or Destruction

12.1. Upon Customer’s written request, or within 180 days after termination or expiration of the applicable Services, Articulate will return or securely delete Customer Personal Data, unless Applicable Data Protection Laws require continued retention.

12.2. Customer Personal Data retained in routine backups, security logs, or business continuity systems will remain protected under this DPA, will not be actively Processed except for security, restoration, or legal compliance, and will be deleted or overwritten under Articulate’s documented retention schedule. 

12.3. If Articulate retains Customer Personal Data because Applicable Data Protection Laws require retention, Articulate will maintain its confidentiality and Process it only for the purpose and period required by law.

12.4. This Section applies only to Customer Personal Data that Articulate Processes as a Processor.

13. General

13.1. Assignment. This DPA shall inure to the benefit of, and be binding upon, any successor to all or substantially all of the business and assets of either party, whether by merger, sale of assets, or other agreements or operation of law.

13.2. Order of Precedence. With respect to the rights and obligation of the parties regarding Personal Data, in the event of a conflict between the terms of the Agreement and this DPA, the terms of this DPA will control. In the event of a conflict between the terms of this DPA and the Standard Contractual Clauses, the terms of the Standard Contractual Clauses will control.

13.3. Liability. To the extent legally permitted, this DPA is subject to the limitations of liability clause in the Agreement.

13.4. Miscellaneous. This DPA constitutes the entire understanding of the parties with respect to the subject matter of this DPA and merges all prior communications, understandings, and agreements. The failure of either party to enforce at any time any of the provisions hereof shall not be a waiver of such provision, or any other provision, or of the right of such party thereafter to enforce any provision hereof. If any provision of this DPA is declared invalid or unenforceable, such provision shall be deemed modified to the extent necessary and possible to render it valid and enforceable. In any event, the unenforceability or invalidity of any provision shall not affect any other provision of this DPA, and this DPA shall continue in full force and effect, and be construed and enforced, as if such provision had not been included, or had been modified as above provided, as the case may be.

ATTACHMENT 1

Details of The Data Processing

1. Subject Matter, Nature, and Purpose for Processing: The subject matter of the Processing is Customer Personal Data Processed in connection with Articulate’s provision of the Services. Articulate may Process Customer Personal Data, for the purposes including, but not limited to:

(a) provide, operate, host, maintain, secure, support, and administer the Services;

(b) perform Customer’s documented instructions, configurations, feature selections, and support requests;

(c) provide Customer enabled analytics, reporting, personalization, and adaptive functionality;

(d) detect, prevent, investigate, and address fraud, abuse, security incidents, technical issues, and violations of the Agreement;

(e) evaluate and improve the performance, reliability, accessibility, safety, and functionality of the Services;

(f) create De-Identified Data and aggregated information;

(g) comply with Applicable Data Protection Laws; and

(h) carry out other Processing that is consistent with the purposes above and the scope of the Services.

2. Term/Duration of Processing: As set forth in the Agreement, Price Quote, or Order Form.

3. Categories of Data Subjects: The Personal Data of persons authorized by Customer to access or interact with the Services and individuals identifiable in Customer Content.

4. Categories of Personal Data: Customer Personal Data may include the following categories, as determined by Customer’s configuration and use of the Services and are illustrative, but not exhaustive. Where Articulate makes new features and functionality generally available within the documented scope of Services, Personal Data Processed through those features falls within these categories:

(a) identity and profile data, including names, usernames, identifiers, profile images, language preferences, and approximate location;

(b) contact and organizational data, including email addresses, telephone numbers, employer, department, and other professional information;

(c) authentication, account, workspace, and platform usage data;

(d) Customer Content, comments, and support communications;

(e) images, audio, video, voice recordings, transcripts, captions, translations, and other uploaded, recorded, or generated media;

(f) learning, engagement and interaction data, including course access, progress, completion, assessment results, navigation, timing, questions, responses, review activity, sharing activity, and generated feedback;

(g) technical and usage data, including IP addresses, device and browser information, operating system, session identifiers, logs, telemetry, diagnostic data, cookies or similar identifiers, feature usage, and system performance data;

(h) data transferred through third party integrations or connectors that Customer configures; or

(i) other Personal Data included in Customer Content or generated through the Services.

5. Special Categories of Data (if any): Articulate does not intentionally collect any special categories of data. Customer or its Users may nevertheless include sensitive or special-category information in Customer Content and, if so, Customer is responsible for ensuring a valid legal basis and providing any required notices or consents.

Applied safeguards and restrictions specific to any special categories of data: Not applicable. In any case, the same high standard of protection described in Attachment 2 to the DPA applies to this and other categories of Personal Data.

The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): Continuous for as long as necessary to provide the Services pursuant to the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: For the duration of providing the Services pursuant to the Agreement, plus in accordance with Articulate’s data retention and backup schedule, or as long as required by an Applicable Data Protection Law.

ATTACHMENT 2

Technical and Organisational Security Measures

Articulate (the data importer) implements the following technical and organizational security measures for Customer Content including Personal Data.

  1. Pseudonymisation and encryption: Customer Content is encrypted at rest on our servers using industry standards (e.g., AES 256-bit), and key management is managed by Articulate’s hosting environment provider, Amazon Web Services (AWS).
  2. Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services: Articulate uses an intrusion detection system to analyze, detect, and report network events and other alert situations, and engages a third-party partner(s) to conduct security and application assessments. Articulate also uses Amazon Web Services (AWS) as its hosting provider, which provides redundancies (e.g., across three (3) or more physically isolated and resource independent availability zones).
  3. Disaster recovery and business continuity measures (restoring the availability and access to the services in the event of a physical or technical incident): Articulate has a disaster recovery policy and related procedures which provide that Articulate, in the event of a disaster, will rebuild its infrastructure to restore services as quickly as possible with an RTO of 72 hours and RPO of 24 hours.
  4. Testing, assessment, and evaluation of security measures: Articulate has an incident response policy that is tested at least annually, or whenever there is a material change to our security.
  5. User identification and authorization: Articulate 360 services do not store user credentials; instead, it relies on a third-party single sign-on service that implements tested and industry-accepted identity protocols to authenticate users, including encryption at rest using a minimum of AES-256 cryptographic strength.
  6. Protection of data during transmission: Customer Content is encrypted in transit using at a minimum the Transport Layer Security protocol of TLS 1.2.
  7. Protection of data during storage: Customer Content is encrypted at rest on our servers using the Advanced Encryption Standard 256-bit industry standard. Key management is managed by Articulate’s hosting environment provider, AWS.
  8. Physical security of locations at which personal data are processed: Articulate is a fully distributed company, meaning we do not have physical offices. We host Articulate services on AWS servers. AWS data centers are state of the art, using innovative architectural and engineering approaches, are housed in nondescript facilities, and physical access is strictly controlled both at the perimeter and at building ingress points (e.g., professional security staff, video surveillance).
  9. Events logging: Articulate uses SIEM solutions in alignment with defined standards for log centralization and alerting functionalities, and AWS CloudWatch and AWS CloudTrail to track all changes in infrastructure.
  10.  System configuration, including default configuration: Articulate codifies all infrastructure changes in version control and uses industry best practices for safely and securely applying these changes to Articulate services.
  11. Internal IT and IT security governance and management: Articulate employees sign confidentiality agreements and complete security training upon hire, and security training continues annually thereafter. Articulate has policies and procedures on proper data protection, management, retention, and deletion. Articulate also uses state-of-the art antivirus and mobile device management software on all Articulate workstations, monitors vendor and third-party sources for updated vulnerability information, distributes pertinent patch information promptly, and requires that the workstations for all Engineering team members and others who have access to AWS (our host) servers be encrypted at rest.
  12. Certification/assurance of processes and products: Articulate undergoes an annual SOC2 Type 2 audit conducted by a third party and has ISO 27001, 27701, and 42001 certifications. Employees are required to complete security awareness training upon hire and annually thereafter to understand their obligations and responsibilities in complying with corporate policies that are designed to protect customer data.
  13. Data minimization: Articulate collects personal data necessary to provide services to customers and grants access to personal data only if necessary to enable human resources to perform their jobs. Articulate also periodically reviews access privileges and removes privileges within 24 hours of a person being terminated from Articulate. Further, personal data is retained and securely destroyed in accordance with Articulate’s data retention policies (or earlier upon customer request), so long as there is no legal requirement to retain such data.
  14. Data quality: Articulate services validate user input and HTTP parameters.
  15. Limited data retention: Articulate has retention policies that require regular deletion of personal data. Articulate performs daily backups as part of our disaster recovery process, which data is archived for approximately 60 days and then is automatically overwritten.
  16. Accountability: Articulate has implemented a privacy program, appointed a Data Privacy Officer, implemented privacy policies and practices (including on incident response), and conducts employee trainings at least annually.
  17. Data portability and erasure: Articulate abides by the processes set forth in its Data Processing Agreement for responding to customer requests for a copy, correction, or deletion of their Users’ personal data.
  18. For transfers to (sub-) processors: specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter: The exporter’s administrators and/or Users can use self-service features in the Services for accessing, deleting, or correcting data about end users. All other relevant assistance would be provided through the customer support team.