DATA PROCESSING ADDENDUM FOR B2B PLATFORM CUSTOMERS

Effective as of 28 August 2026

INTRODUCTION

This Data Processing Addendum (“DPA”), including its Annexes, forms an integral part of and supplements the agreement governing the provision of the Services between UAB Planner 5D B2B, a legal entity incorporated under the laws of the Republic of Lithuania, registration number 304433906, with its registered office at A. Goštauto St. 12A, LT-01108 Vilnius, Lithuania (“Planner 5D B2B” or “Provider”), and the customer identified in that agreement (“Customer”). 

For the purposes of this DPA, the “Agreement” means the Planner 5D B2B Platform General Terms of Service, together with the applicable Order Form, statement of work or other document incorporated into them, or any other licence agreement, master services agreement or written agreement entered into between Planner 5D B2B and Customer 

This DPA applies if and to the extent that Planner 5D B2B Processes Personal Data on behalf of Customer in connection with the provision of the Services under the Agreement.

Where Customer acts as a Controller, Planner 5D B2B acts as its Processor. Where Customer Processes Customer Personal Data on behalf of another Controller, Customer acts as a Processor and appoints Planner 5D B2B as its sub-processor. In that case, Customer represents and warrants that it is authorized by the relevant Controller to appoint Planner 5D B2B, issue Processing instructions and enter into this DPA.

In the event of any conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA shall prevail to the extent of such conflict.

Unless otherwise defined in this DPA, capitalized terms shall have the meaning given in Section 1 of this DPA or in the Agreement, as applicable.

1. DEFINITIONS

Customer Personal Data” means any Personal Data Processed by or on behalf of Planner 5D B2B on Customer’s behalf in connection with the provision of the Services, including Personal Data contained in Customer Content or otherwise submitted or made available by or on behalf of Customer;

Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

“Data Subject” means an identifiable individual whose Personal Data is processed.

“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the Processing of the Customer Personal Data under the Agreement, including, where applicable: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the EU GDPR); (ii) Directive 2002/58/EC of the European Parliament and of the Council concerning the Processing of personal data and the protection of privacy in the electronic communications sector (the EU e-Privacy Directive); (iii) the GDPR as incorporated into the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (collectively the UK GDPR); (iv) Swiss Data Protection Act (the Swiss DPA); (v) any national data protection laws made under or pursuant to items (i) – (iv); (vi) in each case as may be amended, superseded or replaced.

Personal Data” means any information relating to an identified or identifiable individual contained within Customer’s data, that is collected and Processed by Planner 5D B2B in relation to provision of the Services under the Agreement.

Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by Planner 5D B2B and/or its Sub-processors in connection with the provision of Services under the Agreement;

Processing” means any operation or set of operations that is performed on Personal Data, whether or not by automatic means, such as viewing, accessing, collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

“Services” shall have the meaning as set forth in the Agreement;

Standard Contractual Clauses”, "SCC" and "EU SCC" means the standard contractual clauses annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021, currently found at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj, that may be amended, superseded or replaced;

Sub-processor” means any processor engaged by or on behalf of Planner 5D B2B to support the delivery of the Services under the Agreement;

UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018, currently found at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf , that may be amended, superseded or replaced;

Any capitalized terms not defined in this DPA shall be given with the meaning set forth in the Agreement, and in each case, their cognate terms shall be construed accordingly.

2. SCOPE AND TERMS OF PROCESSING

2.1. Roles of the Parties. The Parties acknowledge and agree that, with respect to the Processing of Customer Personal Data under this DPA:

(a) where Customer acts as a Controller, Planner 5D B2B acts as Customer’s Processor; and

(b) where Customer Processes Customer Personal Data on behalf of another Controller, Customer acts as a Processor and Planner 5D B2B acts as Customer’s sub-processor.

Where Customer acts as a Processor, Customer represents and warrants that it is duly authorized by the relevant Controller to appoint Planner 5D B2B as a sub-processor, issue documented Processing instructions and enter into this DPA. Any Processing of Personal Data by Planner 5D B2B as an independent Controller falls outside the scope of this DPA.

2.2. Compliance with Laws. Each Party undertakes to comply with its obligations under the Applicable Data Protection Laws in respect to Processing of the Personal Data under or in connection with the Agreement or this DPA. The Customer shall be solely responsible for accuracy, quality and legality of the Personal Data and the means by which the Customer obtained the Personal Data. The Customer represents and warrants that upon transferring any Personal Data to Planner 5D B2B (i) the Customer has an appropriate and sufficient legal basis (including obtaining any necessary consents and authorizations) to collect and submit such Personal Data to Planner 5D B2B for Processing, (ii) Planner 5D B2B is entitled to further Process such Personal Data for the purposes of performing the Agreement and as per the terms hereof, (iii) all Personal Data submitted by the Customer to Planner 5D B2B is accurate, true, relevant and necessary with reference to the performance of the Agreement. The Customer shall collect and maintain throughout the term of the Agreement all necessary rights, consents and authorizations to provide the Personal Data to Planner 5D B2B and to authorize Planner 5D B2B to Process Personal Data in accordance with this DPA.

2.3. Purpose Limitation. Planner 5D B2B will process Customer Personal Data solely as needed to perform its obligations under the Agreement, including this DPA, and strictly in accordance with Customer’s documented instructions. Planner 5D B2B will not Process Customer Personal Data for any other purposes, except where and to the extent required by any applicable laws.

2.4. Customer’s Instructions. The Agreement, including this DPA and, if applicable, the SCCs, along with the Customer’s configuration of any settings or options in the Services constitute Customer’s complete instructions to Planner 5D B2B in relation to Processing of Personal Data. The Customer may provide additional reasonable instructions during the term of the Agreement, provided they are consistent with the Agreement, the nature and lawful use of the Services. If Planner 5D B2B determines that it cannot Process Customer Personal Data in accordance with the Customer's instructions due to a legal requirement under any applicable law, Planner 5D B2B will promptly inform the Customer and suspend such Processing (other than merely storing and maintaining affected Personal Data) until the moment the Customer provides revised Processing instructions with which Planner 5D B2B is able to comply. If this provision is invoked, Planner 5D B2B will not be liable to the Customer under the Agreement for any failure to perform the applicable Services until such time as the Customer issues new lawful instructions with regard to the Processing.

Planner 5D B2B is not responsible for Customer’s compliance with the Applicable Data Protection Laws and has no obligation to monitor it.

2.5. Confidentiality. Planner 5D B2B will ensure that Planner 5D B2B personnel who are authorized to Process Customer Personal Data (i) are informed of the confidential nature of the Personal Data, (ii) are subject to the appropriate confidentiality obligations and (iii) process Customer Personal Data only for the purpose of providing the Services and fulfilling other Planner 5D B2B’s obligations under the Agreement, including this DPA.

3. DATA SECURITY

3.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing of Personal Data, Planner 5D B2B will implement and maintain appropriate technical and organizational security measures to protect Customer Personal Data from Personal Data Breaches, as described in the Annex 2 to this DPA (“Security Measures”). The Security Measures may be implemented by Planner 5D B2B directly or through authorized Sub-processors. The Security Measures shall be reviewed, updated or modified by Planner 5D B2B where and when necessary, upon decision of Planner 5D B2B. The Customer agrees that Planner 5D B2B may unilaterally update or modify the Security Measures from time to time provided that such updates and modifications do not materially reduce the level of protection for the Personal Data.

3.2. The Customer shall be independently responsible for determining whether the data security provided for in the Services adequately meets Customer’s obligations under the Applicable Data Protection Laws. The Customer agrees that except as provided by this DPA, the Customer shall be responsible for its secure use of the Services, including securing its account authentication credentials, protecting the security of the Personal Data when in transit to and from the Services and taking any appropriate steps to securely encrypt or backup any Personal Data uploaded in relation to the Services.

4. PERSONAL DATA BREACH NOTIFICATION

4.1. Upon becoming aware of a Personal Data Breach, Planner 5D B2B will notify the Customer without undue delay and will provide relevant information about the Personal Data Breach to the Customer, once it becomes available to Planner 5D B2B. Planner 5D B2B will make reasonable efforts to identify the cause of the Personal Data Breach and to mitigate its effects to the extent within reasonable control of Planner 5D B2B. At Customer’s request, Planner 5D B2B will assist Customer by providing information reasonably necessary for Customer to meet its data breach reporting obligations under the Applicable Data Protection Laws. Planner 5D B2B’s notification of Personal Data Breach does not constitute an acknowledgement by Planner 5D B2B of its fault or liability.

4.2. Planner 5D B2B will document all Personal Data Breaches (if any) including the facts relating to the Personal Data Breach, its effects and remedial action taken.

4.3. After having notified the Customer about the Personal Data Breach, Planner 5D B2B will make appropriate efforts to secure the Personal Data and limit any possible detrimental effect to the Data Subjects concerning the particular Personal Data Breach. Planner 5D B2B will cooperate with the reasonable instructions of the Customer (if any), with any third parties designated by the Customer, and with any competent supervisory authority, to respond to the Personal Data Breach.

5. ASSISTANCE AND COOPERATION

5.1. Data Subjects Requests. Considering the nature of the Processing, upon Customer written request, Planner 5D B2B will provide reasonable assistance to Customer to enable the Customer to respond to the Data Subject requests or to the requests from the data protection authorities relating to the Processing of Personal Data under the Agreement. If any such request is made directly to Planner 5D B2B, Planner 5D B2B will promptly notify the Customer, redirecting the request and providing the available details. The Customer shall remain solely responsible for responding substantively to any such requests or communications involving Processing of Customer Personal Data, unless Planner 5D B2B is required to do so in order to comply with applicable laws. Customer agrees to indemnify and hold harmless Planner 5D B2B against any claims arising from Customer’s failure to respond, or inadequate response, to Data Subject requests or requests from data protection authorities when Planner 5D B2B has notified the Customer of such requests. Planner 5D B2B’s assistance is provided on a reasonable efforts basis and does not relieve the Customer of its primary responsibilities under Applicable Data Protection Laws.

5.2. Data Protection Impact Assessment. Upon Customer’s reasonable request, and taking into account the nature of Processing, Planner 5D B2B will provide reasonable assistance to the Customer to conduct a data protection impact assessment and to consult with the relevant data protection authority, to the extent required by the Applicable Data Protection Laws.

5.3. Right to Recover Costs for Compliance. Customer agrees to reimburse Planner 5D B2B for any reasonable costs and expenses incurred in responding to Data Subject or regulatory requests, Data Protection Impact Assessments, or data audits initiated by the Customer, except where such actions arise due to Planner 5D B2B’s non-compliance with this DPA.

6. RETURN AND DELETION OF PERSONAL DATA

6.1. Upon Customer’s request, or upon termination or expiry of the Agreement resulting in cessation of Services involving the Processing of Customer Personal Data, Planner 5D B2B shall delete all copies of Customer Personal Data. Following termination or expiry, Planner 5D B2B may disable Customer’s access to the Services immediately and shall delete Customer Personal Data after the thirty-day period specified in Section 14.2 of the General Terms. This deletion requirement shall not apply to the extent Planner 5D B2B is required by any applicable law to retain some or all of the Customer Personal Data, or to Customer Personal Data archived on Planner 5D B2B’s back-up systems. In this event Planner 5D B2B shall isolate and protect the Customer Personal Data from any further Processing, except to the extent required by such law until deletion is possible.

Nothing in this Section 6.1 shall affect Planner 5D B2B’s right under Section 14.2 of the General Terms to retain limited information that it lawfully Processes as an independent Controller for security, fraud prevention, dispute resolution or enforcement purposes. Any such Processing falls outside the scope of this DPA and remains subject to Applicable Data Protection Laws.

6.2. During the term of the Agreement, Customer may download or, where agreed, be provided with Customer Personal Data submitted by it and Processed by Planner 5D B2B, in a commonly acceptable, machine-readable format, for any purpose.

6.3. Upon request, Planner 5D B2B will provide written confirmation to the Customer that the deletion or return of Personal Data has been completed.

6.4. For clarity, Planner 5D B2B may continue to process information derived from Personal Data that has been deidentified, anonymized, and/or aggregated such that the data is no longer considered Personal Data under the Applicable Data Protection Laws in a manner that does not identify individuals to improve Planner 5D B2B’s Services and systems.

7. SUB-PROCESSORS

7.1. Customer provides Planner 5D B2B with general written authorization to engage Sub-processors to Process the Customer Personal Data under the Agreement. The list of Sub-processors currently engaged by Planner 5D B2B is made available to the Customer at B2B Sub-processors List. Sub-processors that Planner 5D B2B engages with may change over time. In case of addition or replacement of any Sub-processor, Planner 5D B2B will notify Customer prior to such engagement or replacement by posting the update at B2B Sub-processors List (“Sub-processors List”). Customer may subscribe to receive email notifications when Planner 5D B2B adds or replaces a Sub-processor by filling out this form. Customer may object to Planner 5D B2B’s addition or replacement of a Sub-processor by notifying Planner 5D B2B in writing at privacy@planner5d.com within thirty days of Planner 5D B2B’s notice of the addition or replacement of a Sub-processor. Such Customer’s objection shall be based on reasonable grounds related to the ability of Sub-processor to comply with Applicable Data Protection Laws. Upon receipt of such objection, Planner 5D B2B will have the right to cure the objection through one of the following options in its sole discretion: a) Planner 5D B2B will not appoint such objected Sub-processor, if Planner 5D B2B is reasonably able to provide Services to the Customer under the Agreement without using the objected Sub-processor, or b) Planner 5D B2B will allow Customer to terminate the affected Services in accordance with the Agreement, without liability to either party, if Planner 5D B2B requires the use of the objected Sub-processor and is unable to satisfy Customer’s objection.

7.2. Where Planner 5D B2B engages Sub-processors, Planner 5D B2B will impose contractual terms on the Sub-processors which are no less protective for Personal Data than those set out in this DPA, to the extent applicable to the nature of services provided by such Sub-processors.

7.3. Planner 5D B2B will remain responsible to Customer for the performance of each Sub-processor’s data protection obligations to the same extent as if the relevant acts and omissions had been performed by Planner 5D B2B.

8. TRANSFER OF PERSONAL DATA

8.1. Customer Personal Data that Planner 5D B2B Processes under the Agreement may be Processed in any country in which Planner 5D B2B and Sub-processors maintain facilities to perform Services, as detailed in the B2B Sub-processors List.

8.2. Processing in a country includes access to Customer Personal Data from such country, including by remote access, support access, troubleshooting, maintenance, or system administration performed by Processor or its Sub-processors. Remote access shall be considered a transfer where required under Applicable Data Protection Laws.

8.3. In cases authorized by the Customer under this DPA, Customer Personal Data may be transferred from the European Economic Area (“EEA”), Switzerland and the United Kingdom to countries outside EEA, Switzerland and the United Kingdom that offer an adequate level of data protection under or pursuant to the adequacy decisions published by the EU Commission (“Adequacy Decision”), subject to a proper data processing agreement in place.

8.4. Controller acknowledges and agrees that the locations of Processing and Transfers described in this Section 8 and in the Sub-processors List form part of Controller’s documented instructions under Section 2.4 of this DPA and constitute Controller’s authorization for such Transfers, subject to the safeguards described herein.

8.5. If the Processing of Customer Personal Data includes transfers from the EEA, Switzerland and the United Kingdom to a country or recipient outside the relevant jurisdiction that is not covered by an applicable Adequacy Decision or equivalent recognition (“Restricted Transfer”), and such Restricted Transfer is not permitted through an alternative lawful transfer mechanism recognized under  the Applicable Data Protection Laws:

(a) a Restricted Transfer directly between Customer and Planner 5D B2B shall be subject to the applicable Standard Contractual Clauses, which shall be deemed entered into by the Parties and incorporated into this DPA by reference, and completed as indicated in Sections 8.5.1, 8.5.2 and 8.5.3 and the Annexes to this DPA; and

(b) a Restricted Transfer from Planner 5D B2B to a Sub-processor shall be subject to the applicable Standard Contractual Clauses or another lawful transfer mechanism entered into between Planner 5D B2B and that Sub-processor. Planner 5D B2B shall ensure that the Sub-processor is bound by the applicable transfer mechanism and shall remain responsible for the Sub-processor in accordance with Section 7 of this DPA.

8.5.1. In relation to a Restricted Transfer directly between Customer and Planner 5D B2B that is subject to the EU SCCs, the EU SCC shall apply and be completed as follows:

  • Module Two of EU SCC (Controller to Processor) shall apply where Customer acts as the data exporter and Controller of Customer Personal Data and Planner 5D B2B acts as the data importer and Processor;
  • Module Three of EU SCC (Processor to Sub-processor) shall apply where Customer acts as the data exporter and Processor of Customer Personal Data and Planner 5D B2B acts as the data importer and Sub-processor;
  • Module Four of the EU SCCs (Processor to Controller) shall apply where Planner 5D B2B acts as the data exporter and Processor of Customer Personal Data and Customer acts as the data importer and Controller;
  • In Clause 7 of EU SCC, the optional docking clause does not apply;
  • In Clause 9 of EU SCC, Option 2 (general written authorization) applies, and the time period for prior notice of Sub-processor changes shall be as set out in Clause 7.1. of this DPA;
  • In Clause 11 of EU SCC, the optional language does not apply;
  • In Clause 17 of EU SCC, Option 1 shall apply, and the EU SCC shall be governed by the laws of the Republic of Lithuania;
  • In Clause 18(b), disputes shall be resolved before the courts of the Republic of Lithuania;
  • Annexes of the EU SCC will be deemed completed with the information set out in the Annexes of this DPA, with the respective roles of the Parties as data exporter and data importer determined in accordance with paragraphs 1–3 above.

8.5.2. In relation to a Restricted Transfer directly between Customer and Planner 5D B2B that is governed by the UK GDPR, the EU SCCs shall apply as completed in accordance with Section 8.5.1. above, and shall be deemed amended as specified by the UK Addendum, which shall be deemed executed by the parties and incorporated into and forming an integral part of this DPA. In addition, Tables 1, 2 and 3 in Part 1 of the UK Addendum are deemed completed respectively with the information set out in Annexes 1 and 2 to this DPA; Table 4 in Part 1 is deemed completed by selecting “Exporter”. Any conflict between the terms of the EU SCCs and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.

8.5.3. In relation to a Restricted Transfer directly between Customer and Planner 5D B2B that is governed by the Swiss DPA, the EU SCCs will apply in accordance with Sub-section 8.5.1. above, with the following modifications:

  • Any references in the EU SCCs to “Regulation (EU) 2016/679” will be interpreted as references to the Swiss DPA, to the extent applicable, and references to specific Articles of “Regulation (EU) 2016/679” will be replaced with the equivalent article or section of the Swiss DPA;
  • References to “EU”, “Union”, “Member State” and “Member State law” will be interpreted as references to Switzerland and Swiss law, as the case may be, and will not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs;
  • Clause 13 of the EU SCCs is modified to provide that the Federal Data Protection and Information Commissioner (“FDPIC”) of Switzerland will have authority over data transfers governed by the Swiss DPA. Subject to the foregoing, all other requirements of Clause 13 will be observed;
  • References to the “competent supervisory authority” and “competent courts” will be interpreted as references to the FDPIC and competent courts in Switzerland;
  • In Clause 17, the EU SCCs will be governed by the laws of Switzerland; and
  • Clause 18(b) states that disputes will be resolved before the applicable courts of Switzerland.

8.5.4. In the event that Standard Contractual Clauses are invalidated or deemed insufficient, Planner 5D B2B and the Customer agree to cooperate in good faith to implement additional safeguards to ensure compliance with Applicable Data Protection Laws.

8.6. Customer acknowledges that Customer Personal Data may be transferred to recipients or accessed in other jurisdictions as a result of actions initiated by Customer or its authorized users, including through sharing functionalities, integrations, exports, configuration settings, or user-directed transmissions. Customer shall be solely responsible for ensuring that any such user-initiated Transfer comply with Applicable Data Protection Laws and that appropriate safeguards are implemented where required.

9. AUDIT

9.1. Customer shall have the right at its own expense, on at least thirty (30) calendar days’ notice, to perform audits (including inspections) of Planner 5D B2B’s and its Sub-processors’ activities in accordance with the Agreement in relation to the Processing of Customer Personal Data by Planner 5D B2B pursuant to the terms of this DPA. Any audit under this DPA shall be limited to assessing Planner 5D B2B’s compliance with this DPA, specifically regarding technical and organizational security measures, and shall be conducted at Customer‘s expense. Except in the case of a confirmed Personal Data Breach, such audits shall not occur more than once in any twelve (12) month period.

9.2. The audit methodology shall be specified and agreed upon between the parties before the audit is carried out. Planner 5D B2B reserves the right to limit the scope and frequency of any audit or inspection requested by the Customer to reasonable intervals. Such audits and inspections shall be conducted either by the Customer itself or by a mutually agreed independent, reputable, third party auditor, who is not a competitor of Planner 5D B2B, provided that such third-party auditor or Customer (in case the audit or inspection is conducted by Customer itself) shall be subject to confidentiality obligations and provided that such audits and inspections and the results therefrom, including the documents reflecting the outcome of the audit and/or the inspections, shall only be used by the Customer to assess the Planner 5D B2B‘s compliance with this DPA, and shall not be used for any other purpose or disclosed to any third party without Planner 5D B2B’s prior written approval, unless otherwise is mandatory required by the Applicable Data Protection Laws. Upon Planner 5D B2B’s first request, following completion of such audit or inspection, Customer shall return all records or documentation in Customer’s possession or control provided by Planner 5D B2B in the context of the audit and/or the inspection. The audit shall be performed on a business day during the working hours of Planner 5D B2B and it shall not unreasonably disturb Planner 5D B2B’s usual course of business or jeopardize the secrecy and confidentiality of any third party’s information being in the Planner 5D B2B’s possession at the time of audit / inspection. Planner 5D B2B will disclose only the information reasonably necessary to verify compliance with this DPA, and the Customer agrees to maintain the confidentiality of any disclosed security information.

10. GENERAL PROVISIONS

10.1. Validity. This DPA shall become effective from the moment of conclusion of the Agreement and shall remain valid until Planner 5D B2B Processes Customer Personal Data on behalf of the Customer or until the end of the term of the Agreement, whichever is the later. Planner 5D B2B may amend and update the terms of this DPA from time to time by posting a revised version of the DPA at this URL: https://planner5d.com/pages/data-processing-addendum-for-b2b-platform-customers.

10.2. Order of Precedence. If any terms and conditions contained in this DPA are in conflict with the terms and conditions set forth in the Agreement, the terms and conditions set forth in this DPA shall be deemed to be the controlling terms and conditions to the extent of such conflict only. Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect. 

10.3. Severability. Should any provision of this DPA be determined to be invalid or unenforceable, then the validity and enforceability of the other provisions of this DPA shall not be affected.

10.4. Governing Law. This DPA shall be governed and construed in accordance with the governing law and jurisdiction provisions set in the Agreement, unless otherwise required by the Applicable Data Protection Laws or the Standard Contractual Clauses.

10.5. Limitation of Liability. Any claim or remedy Customer may have against Planner 5D B2B, its employees, agents, affiliates and Sub-processors, arising under or in connection with this DPA (including Standard Contractual Clauses), whether in contract, tort or under any other theory or liability, shall to the maximum extent permitted by law be subject to the limitations and exclusions of liability stated in this DPA and the Agreement. The total aggregate liability of Planner 5D B2B arising under or in connection with this DPA (including Standard Contractual Clauses) shall not exceed the amount paid by Customer to Planner 5D B2B for use of the Services and Provider Materials during the twelve (12) months preceding the incident giving rise to the liability. Any such claim or remedy shall be brought solely by the Customer entity that is a party to the Agreement.

10.5.1. Planner 5D B2B shall not be liable for data breaches or Personal Data exposure caused directly or indirectly by the Customer’s actions, including but not limited to sharing login credentials, misconfiguring security settings, or any other act or omission on the Customer’s part that compromises security. In such cases, the Customer shall indemnify and hold harmless Planner 5D B2B from any resulting claims, costs, or liabilities.

ANNEX 1 to DPA

DETAILS of PROCESSING

This Annex describes the Processing of Customer Personal Data under the Agreement and this DPA. Where the Standard Contractual Clauses apply under Section 8 of the DPA, this Annex shall complete Annex I to the Standard Contractual Clauses.

The respective roles of the Parties as data exporter and data importer shall be determined by the applicable module of the Standard Contractual Clauses and Section 8.5.1 of the DPA. Nothing in this Annex shall be interpreted as creating a Restricted Transfer where the Standard Contractual Clauses are not legally required.

Any Standard Contractual Clauses applicable to a transfer from Planner 5D B2B to a Sub-processor shall be entered into and completed separately between Planner 5D B2B and the relevant Sub-processor.

1. LIST of PARTIES:

Data exporter:

Name:

The entity identified as “Customer” in this DPA.

Address:

The address of the Customer associated with Customer’s Planner 5D B2B account or otherwise specified in this DPA or the Agreement. 

Contact person’s name, position and contact details:

The contact details associated with Customer’s Planner 5D B2B account or otherwise specified in this DPA or the Agreement.

Activities relevant to the data transferred under Standard Contractual Clauses:

Customer utilizes Planner 5D B2B’s online interior and exterior design platform and related cloud-based services under the Agreement to provide an online design tool under the Customer’s own branding to its end users; Customer provides instructions regarding the Processing of Customer Personal Data in connection with its use of the Services.

Role (controller/processor):

(a) Customer acts as a Controller where it determines the purposes and means of the Processing of Customer Personal Data and as a Processor where it Processes Customer Personal Data on behalf of another Controller, as specified in Section 2.1 of the DPA;

(b) Customer acts as the data exporter and Controller under Module Two;

(c) Customer acts as the data exporter and Processor under Module Three; and

(d) Customer acts as the data importer and Controller under Module Four.

Data importer:

Name:

UAB Planner 5D B2B.

Address:

A. Goštauto St. 12A, Vilnius, Lithuania, LT-01108.

Contact person’s name, position and contact details:

Chief Legal Officer, privacy@planner5d.com

Role (controller/processor):

(a) Planner 5D B2B acts as a Processor where Customer acts as a Controller and as a Sub-processor where Customer acts as a Processor, as specified in Section 2.1 of the DPA;

(b) Planner 5D B2B acts as the data importer and Processor under Module Two;

(c) Planner 5D B2B acts as the data importer and Sub-processor under Module Three; and

(d) Planner 5D B2B acts as the data exporter and Processor under Module Four.

2. DESCRIPTION of TRANSFER:

Categories of Data Subjects whose Personal Data is being Transferred:

(a) Customer’s Authorized Users, including its employees, officers, consultants, contractors, agents and other individuals authorized to use the Services on Customer’s behalf;

(b) Customer’s End Users, customers, prospective customers and business contacts; and

(c) other individuals whose Personal Data is included in Customer Content or otherwise submitted or made available to Planner 5D B2B by or on behalf of Customer, its Authorized Users or End Users.

Categories of Personal Data being transferred:

(a) identification, contact and account data, including name, email address, username, user or account identifier, organization, position or role, authentication records and password hashes;

(b) Customer Content containing Personal Data, including information contained in projects, designs, text, images, files, communications or other materials submitted or made available through the Services;

(c) technical, device and usage information that may constitute Personal Data, including Internet Protocol address, device and browser information, operating system and platform, Internet service provider, language, approximate location, time zone, log data, timestamps and information concerning interaction with and use of the Services;

(d) support and communication data, including support requests, correspondence, feedback and information submitted for troubleshooting; and

(e) any other Personal Data submitted or made available by or on behalf of Customer through the Services in accordance with the Agreement and this DPA.

Sensitive data transferred (if applicable) and applied restrictions or safeguards:

The Services are not intended for the Processing of special categories of data (as defined under Article 9 GDPR). Customer shall not submit such data. Planner 5D B2B does not intentionally collect or require such data for the provision of the Services.

Frequency of transfer:

Customer Personal Data may be transferred on a continuous or one-off basis depending on the Customer’s use of Services and Customer’s Processing instructions.

Purposes of the data transfer and further Processing:

To provide, maintain and improve Services provided to data exporter under the Agreement.

Nature of Processing:

Provision of Services to the Customer in accordance with the Agreement.

Duration of Processing and period for which Personal Data will be retained, or if that is not possible, the criteria used to determine that period:

The Personal Data will be retained until termination or expiry of the Agreement, as outlined in Section 6 of the DPA.

3. COMPETENT SUPERVISORY AUTHORITY:

The data exporter’s competent supervisory authority will be determined in accordance with the Applicable Data Protection Laws.

ANNEX 2 to DPA

TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

Planner 5D B2B implements and maintains appropriate technical and organisational measures to protect Personal Data in accordance with Article 32 GDPR.

Such measures are implemented either directly by Planner 5D B2B or through its authorised Sub-processors, including UAB “Planner5D”, which provides the underlying infrastructure, development, and operational security environment for the Services.

Planner 5D B2B remains contractually responsible for ensuring that such measures are maintained and enforced in accordance with this DPA.

A. Responsible Disclosure

  • All personnel of Planner 5D B2B and its Sub-processors authorised to access Personal Data are subject to confidentiality obligations under written agreements;
  • Access to production systems is restricted to authorised personnel of Planner 5D B2B and its Sub-processors on a strict need-to-know basis;
  • Planner 5D B2B strictly protects access to code or other resources, including Personal Data, which are and can be granted only on a reasonable need-to-know basis.

B. Employee Security and Safeguards

  • All personnel of Planner 5D B2B and its Sub-processors who may access Personal Data are subject to confidentiality obligations and receive appropriate security awareness training;
  • Planner 5D B2B continuously trains its personnel on best security practices, including how to identify social engineering, phishing scams and hackers.

C. Internal IT Security

  • Planner 5D B2B offices are secured by multiple levels of physical and programmatic protection;
  • all the apps as well as the websites of Planner 5D B2B are protected with SSL (HTTPS);
  • The Services are hosted in geographically distributed data centers to ensure redundancy and availability;
  • user data collected and processed by Planner 5D B2B is stored in Planner 5D B2B’s databases which have multiple levels of protection;
  • Planner 5D B2B maintains protection against distributed denial-of-service (DDoS);
  • Planner 5D B2B assures that account data is mirrored and backed up off site;
  • employees of Planner 5D B2B use single sign-on (SSO) and two-factor authentication;
  • Planner 5D B2B uses separate environments for production, staging and development activities and sensitive data from production environment is never used in other environments and is never moved therefrom;
  • any developed features before their release are carefully tested on staging environment for security and other purposes;
  • passwords of users’ accounts are hashed and Planner 5D B2B’s personnel cannot know them; if a password is lost, it cannot be retrieved and it shall be reset.

D. Data Minimization

  • The Services are designed in accordance with data minimisation principles and require only Personal Data necessary to provide the Services under the Agreement;
  • Planner 5D B2B does not store credit card data – all such data is handled exclusively by Planner 5D B2B’s payment services providers.

E. Investing in Data Security

Planner 5D B2B ensures that appropriate technical and organisational security measures are implemented and maintained in connection with the Services. Such measures are implemented by Planner 5D B2B directly and, where infrastructure and operational controls are managed by its authorised Sub-processor UAB “Planner5D”, through contractual arrangements ensuring compliance with this DPA and applicable Data Protection Laws:

  • Continuous monitoring for security vulnerabilities, including operation of a coordinated vulnerability disclosure and bug bounty program.
  • Monitoring of publicly disclosed credential leaks and implementation of appropriate account protection measures where necessary.
  • Application of secure software development lifecycle practices to reduce the risk of security vulnerabilities in code.
  • Implementation of logging and monitoring mechanisms to detect and respond to suspicious or anomalous activity affecting the Services.
  • Operation of infrastructure supporting the Services with appropriate technical support, development resources, and incident response capabilities.
  • Automated scanning of source code repositories and regular vulnerability assessments.
  • Ongoing automated and manual security testing of APIs, user interfaces, and system components.
  • Periodic review and update of information security and data protection policies relevant to the Services.

ANNEX 3 to DPA

SUB-PROCESSORS LIST

The Customer authorizes the use of the Sub-processors as listed at the following URL: B2B Sub-processors List.