Data Protection Agreement EU & UK

FISCALNOTE CUSTOMER DATA PROCESSING AGREEMENT FOR THE PROCESSING OF EU & UK RESIDENTS DATA

PREAMBLE

FiscalNote Inc., having its registered office at 1201 Pennsylvania Avenue NW, 6th Fl. Washington D.C. 20004, U.S.A. ("Provider") provides global policy and market intelligence software-as-a-service solutions to help customers navigate evolving political, corporate and regulatory environments. This Data Processing Agreement ("DPA") covers all services provided in the United States, Europe, and the United Kingdom by Provider and/or its Affiliates (each and together referred to as the “Provider”), including, but not limited to, the software-as-a-service offerings (collectively, the “Services”).

This DPA forms part of the Terms and Conditions referenced in the Order Form between Customer and Provider and sets out the obligations with respect to the Personal Data processed by Provider when Customer uses or receives Services from Provider.  Capitalized terms used but not defined in this DPA shall have the meanings assigned to them in the Terms and Conditions.

This DPA contains the clauses required by Article 28(3) of the EU GDPR & UK GDPR for contracts between controllers and processors and is applicable where Provider is providing Services which involve the processing of EU and UK Residents Data only.

DEFINITIONS

1. Applicable Data Protection Laws means:

(a) the General Data Protection Regulation ((EU) 2016/679), as amended by the Data Protection, Privacy and Electronic Communication (Amendments etc.) (EU Exit) Regulations 2019 (the “UK GDPR”);

(b) the General Data Protection Regulation ((EU) 2016/679) (the “EU GDPR”);

(c) any other secondary legislation implemented in connection with (or replacing) the EU GDPR or the UK GDPR in relation to the protection of personal data.

2. Applicable Laws means:

(a)  To the extent the UK GDPR applies, the law of the United Kingdom or of a part of the United Kingdom.

(b) To the extent EU GDPR applies, the law of the European Union or any member state of the European Union to which the is subject.

3. Personal Data: any personal data which the Provider processes in connection with this agreement, in the capacity of a processor on behalf of the Customer.

4. Purpose: the purposes for which the Personal Data is processed, as set out in the Terms and Conditions.

5. Sub-Processor: any person or entity appointed by or on behalf of FiscalNote, or by or on behalf of an existing Sub-Processor, to process Personal Data on behalf of the Customer in connection with the Agreement.

6. Standard Contractual Clauses: the European Commission’s 2021 standard contractual clauses for the transfer of personal data to third countries which, as at the date of this Agreement, are available here https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en

7. International Data Transfer Addendum: The UK Information Commissioner Office International Data Transfer Addendum to the EU Standard Contractual Clauses, which as at the date of this Agreements, are available here international-data-transfer-addendum.pdf (ico.org.uk)

8. Standard Contractual Clauses: the European Commission’s 2021 standard contractual clauses for the transfer of personal data to third countries which, as at the date of this Agreement, are available here https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en

9. International Data Transfer Addendum: The UK Information Commissioner Office International Data Transfer Addendum to the EU Standard Contractual Clauses, which as at the date of this Agreements, are available here international-data-transfer-addendum.pdf (ico.org.uk)

1. DATA PROTECTION

1.1. For the purposes of this Clause 1, the terms controller, processor, data subject, personal data, personal data breach and processing shall have the meaning given to them in the UK and EU GDPR.

1.2. Both parties will comply with all applicable requirements of Applicable Data Protection Laws. This clause 1 is in addition to, and does not relieve, remove or replace, a party's individual obligations or rights under Applicable Data Protection Laws.

1.3. The parties have determined that, for the purposes of Applicable Data Protection Laws Provider shall process the Personal Data set out in Appendix 1, as a processor on behalf of the Customer in respect of the processing activities set out in the Terms and Conditions.

1.4. Should the determination in clause 1.3 change, then each party shall work together in good faith to make any changes which are necessary to this clause 1 or the related appendices.

1.5. Provider will only process Customer Personal Data to provide or maintain the Services, and in compliance with Customer's documented instructions (including as set out in the Agreement and this DPA).

1.6. Without prejudice to the generality of clause 1.2, the Customer will ensure that it has all necessary appropriate lawful basis as required under Applicable Data Protection Law in place to enable lawful transfer of the Personal Data to FiscalNote for the duration and purposes of this DPA.

1.7. In relation to the Personal Data, Appendix 1 sets out the scope, nature and purpose of processing by the Provider, the duration of the processing and the types of personal data and categories of data subject.

1.8. Without prejudice to the generality of clause 1.2 FiscalNote shall, in relation to Customer Personal Data:

(a) process that Personal Data only on the documented instructions of the Customer, which shall be to process the Personal Data for the purposes set out in the Terms and Conditions, unless the Provider is required by Applicable Laws to otherwise process that Personal Data. Where Provider is relying on Applicable Laws as the basis for processing Processor Data, such as legitimate interest grounds, Provider shall notify the Customer of this before performing the processing required by the Applicable Laws unless those Applicable Laws prohibit Provider from so notifying the Customer. Provider shall inform the Customer if, in the opinion of FiscalNote, the instructions of the Customer infringe Applicable Data Protection Laws;

(b) implement the technical and organisational measures set out in the Annex to Appendix 1 to protect against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data;

(c) ensure that any personnel engaged and authorised by Provider to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory or common law obligation of confidentiality;

(d) assist the Customer insofar as this is reasonably possible (taking into account the nature of the processing and the information available to Provider), and at the Customer's cost and written request, in responding to any request from a data subject and in ensuring the Customer's compliance with its obligations under Applicable Data Protection Laws with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;

(e) notify the Customer without undue delay, and in any event within 72 hours, on becoming aware of a personal data breach involving the Personal Data;

(f) at the written direction of the Customer, delete or return Customer's Personal Data and copies thereof to the Customer on termination of the Agreement unless the Provider is required by Applicable Law to continue to process that Personal Data. Provider shall complete such deletion within thirty (30) days of Customer's written direction. Copies held on backup media shall be overwritten in the ordinary course of Provider's backup rotation cycle; and

(g) maintain records to demonstrate its compliance with this clause 1, and make available to Customer all information reasonably necessary to demonstrate compliance with this clause 1, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable prior written notice and confidentiality obligations.
 

2. TRANSFERS TO THE USA

2.1. All transfers of Personal Data out of the European Economic Area (“EEA”) from the Customer (as a Controller) to FiscalNote (as a Processor) shall be governed by the European Commission’s Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 (Module Two (Controller to Processor)) (“EU SCCs”), which are incorporated into this DPA as if set out in full. All transfers of Personal Data out of the UK from the Customer (as a controller) to FiscalNote (as a processor) shall be governed by the EU SCCs together with the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (“UK Addendum to the EU SCCs”), which is incorporated into this DPA as if set out in full.

2.2. The EU SCCs and the UK Addendum to the EU SCCs shall apply for so long as, and only to the extent that, the parties process Personal Data outside of a territory recognized as providing an adequate level of protection under Applicable Data Protection Laws, and no alternative lawful transfer mechanism has been agreed between the parties in writing.

3. Use of Sub Processors

3.1. The Customer hereby provides its prior, general authorisation for Provider to:

  1. appoint processors to process the Personal Data, provided that the Provider:
  2. shall ensure that the terms on which it appoints such processors comply with Applicable Data Protection Laws, and are consistent with the obligations imposed on the Provider in this clause 3.1;
  3. shall remain responsible for the acts and omission of any such processor as if they were the acts and omissions of the Provider; and
  4. shall inform the Customer of any intended changes concerning the addition or replacement of the processors, via the notification system Provider adopts from time to time, thereby giving the Customer the opportunity to object to such changes, provided that if the Customer objects to the changes and cannot demonstrate, to the Provider's reasonable satisfaction, that the objection is due to an actual or likely breach of Applicable Data Protection Law, the Customer shall indemnify the Provider for any losses, damages, costs (including legal fees) and expenses suffered by the Provider in accommodating the objection.

(b) transfer Customer Personal Data outside of the EU & UK as required for the Purpose, provided that the Provider shall ensure that all such transfers are effected in accordance with Applicable Data Protection Laws. For these purposes, the Customer shall promptly comply with any reasonable request of Provider, including any request to enter into standard data protection clauses adopted by the EU Commission from time to time (where the EU GDPR applies to the transfer) or adopted by the UK Information Commissioner from time to time (where the UK GDPR applies to the transfer).

3.2. Either party may, at any time on not less than 30 days' notice, revise clause 2.2 & 2.3 by replacing it (in whole or part) with any applicable standard clauses approved by the EU Commission or the UK Information Commissioner's Office or forming part of an applicable certification scheme or code of conduct (“Amended Terms”). Such Amended Terms shall apply when replaced by attachment to this DPA, but only in respect of such matters which are within the scope of the Amended Terms.

3.3. The Provider's total aggregate liability in contract, tort (including negligence and breach of statutory duty howsoever arising), misrepresentation (whether innocent or negligent), restitution or otherwise, arising in connection with the performance or contemplated performance of this DPA or any collateral contract insofar as it relates to the obligations set out herein, shall be subject to any limitation of liability set forth in the Terms and Conditions or other agreement between Customer and Provider.

 

APPENDIX 1: DESCRIPTION OF THE PROCESSING ACTIVITIES

Nature and purpose of the processing operations

Relevant Personal Data processed will be subject to the processing activities forming part of the Terms and Conditions.

Data subjects. Relevant Personal Data processed may concern the following categories of Data Subjects:

  • Customer’s Employees 

Categories of data. Relevant Personal Data processed shall be any category of data processed as part of the Services, which may include the following categories of data:

  • Name
  • Job Role
  • Email address
  • Password
  • IP Address
  • Browser Details
  • Cookies
  • Business Address 

Special categories of data (if appropriate) and applied safeguards or restrictions

  • None

Duration and frequency of Processing. The duration of processing shall be for the duration of the Services set out in the Agreement.

Period of retention of the data (or criteria used to determine the period).  Relevant Personal Data shall be retained for the duration of the Services set out in the Agreement or as determined by the Customer.

Transfers to (sub-) processors (if applicable)

  • Atlassian
  • Heap
  • Tableau
  • Segment.io
  • Stich
  • Snowflake Inc.
  • Databricks, Inc.
  • dbt Labs
  • ChurnZero
  • Chameleon Intelligent Tech, Inc.
  • Salesforce
  • Google
  • Content Square, Inc.
  • Twilio, Inc.
  • QlikTech Inc.
  • Open AI
  • Amazon Web Services, Inc. (AWS)
  • MongoDB, Inc. (MongoDB Atlas)
  • Temporal Technologies, Inc. (Temporal.io)
  • Okta, Inc. (Auth0)
  • SendGrid
  • Metabase
  • Anthropic
  • SIgnoz
  • SolCyber
  • Datadog
  • Zendesk
  • Stripe
  • CloudAMQP
  • Bonsai
  • LaunchDarkly
  • Figma

Sub-Processor List:

Name: Amazon Web Services, Inc. (AWS)

Address: 410 Terry Avenue North, Seattle, WA 98109

Contact: aws-security@amazon.com

Description of Processing: Provides cloud infrastructure and hosting services on which the PolicyNote platform is deployed. Processes Elastic Data incidentally as part of compute, storage, and networking operations. AWS operates as an infrastructure-level sub-processor; FiscalNote configures and controls all data access and security settings within the AWS environment.

Name: Chameleon Intelligent Tech, Inc.

Address: 714 Treat Ave, San Francisco, California, 94110

Contact: Pulkit Agrawal; CEO; security@trychameleon.com

Description of Processing: Receives customer activity in order to show in platform tours, tips, surveys.

Name: ChurnZero

Address: 717 D ST NW, Suite 200; Washington, DC 20004

Contact: Michael Kipp; SR. Director, Technical Operations; mkipp@churnzero.com

Description of Processing: Aggregate events, contact customers, and predict churn.

Name: Content Square, Inc.

Address: 53 Beach St, 6th Floor, New York, NY 10013

Contact: Nicole Mazaniti; Data Protection Officer; privacy@contentsquare.com

Description of Processing: Contentsquare’s Heap product: Data collection and visualization of consumer activity in FiscalNote platforms.

Name: Databricks, Inc.

Address: 160 Spear St FL 15; San Francisco, CA 94105

Contact: Neal Hannan; Director & AGC, Product & Privacy; privacy@databricks.com

Description of Processing: Data storage and transformation.

Name: dbt Labs

Address: 915 Spring Garden St Ste 500; Philadelphia, PA 19123

Contact: Randy Hanooman; Manager, Security Compliance; privacy@dbtlabs.com

Description of Processing: Build data models for operational analytics and data integrations.

Name: MongoDB, Inc. (MongoDB Atlas)

Address: 1633 Broadway, 38th Floor, New York, NY 10019

Contact: privacy@mongodb.com

Description of Processing: Provides cloud-hosted database services used to store and retrieve application data within the PolicyNote platform, which may include Elastic Data. MongoDB Atlas processes data solely as directed by FiscalNote and does not have independent access to or use of Elastic Data.

Name: Okta, Inc. (Auth0)

Address: 100 First Street, San Francisco, CA 94105

Contact: privacy@okta.com

Description of Processing: Provides identity and access management services, including authentication and authorization, for the PolicyNote platform. Processes user identity data (such as names and email addresses) as necessary to authenticate and manage end-user access. Does not process substantive Elastic Data beyond identity credentials required for access control.

Name: Open AI

Address: 3180 18th Street, San Francisco, CA 94110

Contact: privacy@openai.com

Description of Processing: Provides the underlying large language model (LLM) infrastructure that powers certain AI-assisted features within the platform.

Name: QlikTech Inc.

Address: 211 S Gulph Rd Ste 500; King of Prussia, PA 19406

Contact: Roy Horgan; Data Protection Officer; privacy@qlik.com

Description of Processing: QlikTech’s Stitch Data Transfer product: Move data from source to data warehouse.

Name: Salesforce

Address: 415 Mission St FL 3; San Francisco, CA 94105

Contact: Ben Casady; Senior Director, Privacy Compliance; privacy@salesforce.com

Description of Processing: CRM, data visualization

Name: Snowflake Inc

Address: 106 E Babcock St Ste 3A, Bozeman, MT 59715

Contact: Evan Uchida; Head of Privacy; privacy@snowflake.com

Description of Processing: Data Storage for BI/Data analytics.

Name: Temporal Technologies, Inc. (Temporal.io)

Address: 444 Castro Street, Suite 1200, Mountain View, CA 94041

Contact: legal@temporal.io

Description of Processing: Provides a workflow orchestration platform used to manage and coordinate background processing tasks within PolicyNote. May process Elastic Data as part of executing automated workflows. Temporal acts solely as directed by FiscalNote and does not independently access or use Elastic Data.

Name: Twilio Inc.

Address: 101 Spear St FL 5; San Francisco, CA 94105

Contact: Amy Holcroft; Chief Privacy Officer; privacy@twilio.com

Description of Processing: Twilio’s Segment product: Processing and collecting user and usage information from customer activity in FiscalNote platforms.

Specify the subject matter, nature and duration of the processing activities:

  • Data Analytics, Transformation and Tech Services
  • Data Storage
  • CRM

The obligations and rights of the Customer

The obligations and rights of the Customer are set out in the DPA and this Addendum.

last updated: 9/9/2026