Data Processing Agreement (DPA)

Last Updated: August 14, 2026

We have updated this DPA. If you are a new Customer, this DPA is effective as of August 14, 2026. If you are an existing Customer, these changes take effect thirty (30) days after we notify you of them in accordance with Section 15.4, unless Your agreement with Us states otherwise.

This Data Processing Agreement (the "DPA") forms part of the Services Agreement between the person or entity that is the Account Owner or Customer under that Services Agreement ("You", "Your" or "Customer") and Screened Pte. Ltd. (UEN 202423637K), 3 Coleman Street #03-24, Singapore 179804 ("Screened", "We", "Us" or "Our"). This DPA applies where Screened Processes Personal Data in Customer Data on Customer's behalf. Customer and Screened are each a "Party" and together the "Parties".

1. Definitions

Capitalized terms not defined in this DPA have the meanings given to them in the Services Agreement.

In this DPA, the following terms shall have the following meanings:

"CCPA" shall mean the California Consumer Privacy Act of 2018, as amended, including by the California Privacy Rights Act of 2020.

"Customer Data" means all data, information or materials submitted to or Processed through the Services by or on behalf of Customer, including by Customer's users or candidates. Customer Data does not include aggregated, anonymized or de-identified data that does not identify and cannot reasonably be used to identify Customer, its users, candidates or any other individual.

"Data Protection Laws" means the data protection laws of the country in which Customer is established and any data protection laws applicable to Customer in connection with the Services Agreement, including but not limited to (a) laws and regulations applicable to the GDPR, (b) in respect of the UK, the GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom European Union (Withdrawal) Act 2018 ("UK GDPR") and the Data Protection Act 2018, (c) the Swiss Federal Data Protection Act and its implementing regulations ("Swiss DPA"), and (d) in respect of Singapore, the Personal Data Protection Act 2012 (2020 Rev Ed) ("PDPA"), in each case as amended, superseded or replaced.

"GDPR" shall mean the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).

"Personal Data" means any information relating to an identified or identifiable natural person Processed by Screened in providing the Services to Customer, as described in Appendix I.

"Restricted Transfer" means: (i) where the GDPR applies, a transfer of Personal Data from the EEA to a country outside the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data from the UK to any other country which is not based on adequacy regulations pursuant to Section 17A of the Data Protection Act 2018; and (iii) where the Swiss DPA applies, a transfer of Personal Data to a country outside of Switzerland which is not included on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.

"Standard Contractual Clauses" or "SCCs" means (i) where the GDPR applies, the standard contractual clauses as approved by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021) and available here ("EU SCCs"); (ii) where the UK GDPR applies, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, Version B1.0, in force from 21 March 2022, set forth as Appendix IV ("UK SCCs"); and (iii) where the Swiss DPA applies, the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner (the "Swiss SCCs") (in each case, as updated, amended or superseded from time to time).

"Sensitive Personal Information" means information that relates to an individual's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation. It also includes information about an individual's criminal offences or convictions, as well as any other information deemed sensitive under applicable data protection laws.

"Services Agreement" means Screened's Terms of Service available at https://screened.io/terms, or any master subscription agreement or other agreement between Screened and Customer governing Customer's use of the Services, in each case together with any applicable service order and incorporated documents.

"Controller", "Data Subject", "Personal Data Breach", "Processor" and "Processing" shall have the meanings given to them in the GDPR, and "Process", "Processes" and "Processed" shall be construed accordingly.

2. Scope and Responsibilities

2.1. This DPA applies to Screened's Processing, on Customer's behalf, of Personal Data forming a part of the Customer Data.

2.2. Screened's scope and responsibilities as a Controller and as a Processor

2.2.1 Screened as a Controller - A Controller is the party that alone or jointly with others determines the purposes and means of the processing of personal data. While using Screened to engage with candidates, our customers (You) are the Controllers because you determine the purpose (e.g. recruiting a candidate) and the means (using Screened) of processing the personal data. Separately, Screened is a Controller for the personal data associated with customer's (Your) Screened account (e.g. your business contact information) because we control the means and purposes of this processing for our use: invoicing, to communicate information about their account and for other administrative functions.

2.2.2 Screened as a Processor - Screened is the Processor because we process personal data of candidates on our customers' behalf under an agreement in which they tell us what data to process, for what purpose(s), how long we can keep that data, and any restrictions they impose on our use of their data.

2.3. Within the scope of the Services Agreement, each Party is responsible for complying with its respective obligations as Controller or Processor under Data Protection Laws.

3. Term and Termination

3.1. This DPA becomes effective when Customer accepts it, including by accepting a Services Agreement that incorporates it. It remains in effect for as long as Screened Processes Personal Data on Customer's behalf under the Services Agreement and terminates automatically thereafter.

3.2. Where amendments are required to ensure compliance of this DPA or an Appendix with Data Protection Laws, the Parties shall make reasonable efforts to agree on such amendments upon Your request. Where the Parties are unable to agree upon such amendments, either Party may terminate the affected Services in accordance with the termination provisions of the Services Agreement.

4. Processing Instructions

4.1. Screened will Process Personal Data only in accordance with Customer's documented instructions, including those set out in this DPA or the Services Agreement and those provided through Customer's use or configuration of the Services, unless Processing is required by applicable law to which Screened is subject; in that case, Screened will inform Customer of that legal requirement before Processing, unless that law prohibits this on important grounds of public interest.

4.2. For the avoidance of doubt, any instructions that would lead to Processing outside the scope of this DPA (e.g. because a new Processing purpose is introduced) will require a prior agreement between the Parties.

4.3. Screened shall without undue delay inform You in writing if, in Screened's opinion, an instruction infringes Data Protection Laws, and provide a detailed explanation of the reasons for its opinion in writing.

5. Processor Personnel

5.1. Screened will restrict its personnel from Processing Personal Data without authorization. Screened will impose appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection and data security.

6. Disclosure to Third Parties; Data Subjects' Rights

6.1. Screened will not disclose Personal Data to any government agency, court, or law enforcement except with Your written consent or as necessary to comply with applicable mandatory laws. If Screened is obliged to disclose Personal Data to a law enforcement agency, then Screened agrees to give You reasonable notice of the access request prior to granting such access, to allow You to seek a protective order or other appropriate remedy. If such notice is legally prohibited, Screened will take reasonable measures to protect the Personal Data from undue disclosure as if it were Screened's own confidential information being requested and shall inform You promptly as soon as possible if and when such legal prohibition ceases to apply.

6.2. In case You receive any request or communication from Data Subjects that relates to the Processing of Personal Data ("Request"), Screened shall reasonably provide You with full cooperation, information and assistance ("Assistance") in relation to any such Request where instructed by You.

6.3. Where Screened receives a Request, Screened shall (i) not directly respond to such Request, (ii) forward the Request to You within five (5) business days of identifying the Request as being related to You and (iii) provide Assistance according to further instructions from You.

7. Technical and Organizational Measures

7.1. Screened shall implement and maintain appropriate technical and organizational security measures to ensure that Personal Data is Processed according to this DPA, to provide assistance and to protect Personal Data against a Personal Data Breach ("TOMs") as specified in Appendix II hereto.

8. Assistance with Data Protection Impact Assessment

8.1. Under the GDPR, a data protection impact assessment ("DPIA") is required if a data processing activity is likely to result in a high risk to the rights and freedoms of individuals. Where a DPIA is required under applicable Data Protection Laws for the Processing of Personal Data, Screened shall provide upon request to You any information and assistance reasonably required for the DPIA, including assistance for any communication with data protection authorities, where required, taking into account the nature of the Processing and the information available to Screened.

8.2. You shall pay Screened reasonable charges for providing the assistance in clause 8, to the extent that such assistance cannot be reasonably accommodated within the normal provision of the Services.

9. Information Rights and Audit

9.1. Screened shall, in accordance with Data Protection Laws, make available to You on request in a timely manner such information as is necessary to demonstrate compliance by Screened with its obligations under the Data Protection Laws.

9.2. Screened shall, upon at least thirty (30) days' written notice, allow for and contribute to audits of Screened's Processing of Personal Data, as well as the TOMs (including data Processing systems, policies, procedures and records), during regular business hours, for no more than two (2) consecutive business days, and with minimal interruption to Screened's business operations. Such audits shall be conducted by You, Your affiliates, or an independent third party on Your behalf (which will not be a competitor of Screened) that is subject to reasonable confidentiality obligations. Screened may satisfy all or part of an audit request under this Section 9.2 by providing recent third-party certifications or audit reports (such as SOC 2 Type II), to the extent they reasonably address the scope of the request. The notice and duration restrictions in this Section 9.2 and the cost allocation in Section 9.3 do not apply where the audit relates to an actual or reasonably suspected Personal Data Breach, where You have reasonable grounds to suspect Screened's non-compliance with this DPA, or where a supervisory authority requires the audit. In those cases Screened will allow the audit on reasonable notice and for the time reasonably necessary. Nothing in Sections 9.2 or 9.3 limits any audit or inspection right that applies under the SCCs or that Data Protection Laws require.

9.3. You shall pay Screened reasonable costs of allowing or contributing to audits or inspections in accordance with clause 9.2 where You wish to conduct more than one audit or inspection every twelve (12) months. Screened will immediately refer to You any requests received from national data protection authorities that relate to Screened's Processing of Personal Data.

9.4. Screened undertakes to reasonably cooperate with You in its dealings with national data protection authorities and with any audit requests received from national data protection authorities.

10. Personal Data Breach Notification

In respect of any Personal Data Breach (actual or reasonably suspected), Screened shall:

10.1. Notify You of a Personal Data Breach involving Screened or a subcontractor without undue delay after becoming aware of it;

10.2. Provide reasonable information, cooperation, and assistance to You in relation to any action to be taken in response to a Personal Data Breach under Data Protection Laws, including regarding any communication of the Personal Data Breach to Data Subjects and national data protection authorities.

11. Subcontracting

11.1. You generally authorize Screened to engage the sub-processors listed in Appendix III. Screened will notify You in writing at least fifteen (15) calendar days before any new or replacement sub-processor first Processes Personal Data. You may object during that period on reasonable grounds relating to the protection of Personal Data. Screened will use commercially reasonable efforts to resolve any timely objection. If the Parties cannot resolve it, Screened will not use that sub-processor to Process Your Personal Data or, if that is not reasonably feasible, either Party may terminate the affected portion of the Services.

11.2. Where Screened engages a sub-processor under Section 11.1 to carry out specific Processing activities on Customer's behalf, Screened will enter into a binding written contract with the sub-processor that imposes, in substance, the same data protection obligations as those imposed on Screened under this DPA, to the extent applicable to the sub-processor's Processing.

11.3. Where the sub-processor fails to fulfil its data protection obligations under the subcontracting agreement, Screened shall remain fully liable to You for the fulfilment of its obligations under this DPA and for the performance of the sub-processor's obligations.

12. International Data Transfers

12.1. The Parties agree that when the transfer of Personal Data from You to Screened is a Restricted Transfer and applicable Data Protection Laws require that appropriate safeguards are put in place, such transfer shall be subject to the appropriate Standard Contractual Clauses, which shall be deemed incorporated into and form part of this DPA as follows:

12.1.a In relation to transfers of Personal Data originating from the EEA and subject to the GDPR, the EU SCCs shall apply, completed as follows:

  • 12.1.a.i Module 2 (Controller to Processor) shall apply where You are a Controller and Screened is a Processor;
  • 12.1.a.ii in Clause 7, the optional docking clause will apply;
  • 12.1.a.iii in Clause 11, the optional language will not apply;
  • 12.1.a.iv in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
  • 12.1.a.v in Clause 18(b), disputes shall be resolved before the courts of Ireland;
  • 12.1.a.vi Annex I of the EU SCCs shall be deemed completed with the information set out in Appendix I to this DPA;
  • 12.1.a.vii Annex II of the EU SCCs shall be deemed completed with the information set out in Appendix II to this DPA;
  • 12.1.a.viii Annex III of the EU SCCs shall be deemed completed with the information set out in Appendix III to this DPA;
  • 12.1.a.ix in Clause 9(a), Option 2 (General Written Authorisation) applies, and the specified period is fifteen (15) calendar days.

12.1.b In relation to transfers of Personal Data originating from Switzerland and subject to the Swiss DPA, the EU SCCs as implemented under sub-paragraph (a) above will apply with the following modifications and constitute the Swiss SCCs:

  • 12.1.b.i References to Regulation (EU) 2016/679 shall be interpreted as references to the Swiss DPA;
  • 12.1.b.ii References to specific Articles of Regulation (EU) 2016/679 shall be replaced with the equivalent sections of the Swiss DPA;
  • 12.1.b.iii References to "EU", "Union", "Member State", and "Member State law" shall be replaced with references to "Switzerland" or "Swiss law";
  • 12.1.b.iv The term "member state" shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., Switzerland);
  • 12.1.b.v Clause 13(a) and Part C of Annex I are not used, and the "competent supervisory authority" is the Swiss Federal Data Protection and Information Commissioner;
  • 12.1.b.vi References to the "competent supervisory authority" and "competent courts" shall be replaced with references to the Swiss Federal Data Protection and Information Commissioner and "applicable courts of Switzerland".

12.2. UK SCCs for Transfers from the UK

12.2.1. In relation to transfers of Personal Data originating from the UK and subject to the UK GDPR, the UK SCCs shall apply. For the purposes of the descriptions in the SCCs, You agree that You are the "data exporter" and Screened is the "data importer".

12.3. The Parties agree that if the Standard Contractual Clauses are replaced, amended, or no longer recognized as valid under Data Protection Laws, or if adoption of an alternative transfer solution is required by a supervisory authority or Data Protection Laws, the data exporter and data importer will: (i) promptly take such steps requested, including putting an alternative transfer mechanism in place to ensure the processing continues to comply with Data Protection Laws; or (ii) cease the transfer of Personal Data and, at the data exporter's option, delete or return the Personal Data to the data exporter.

13. Deletion or Return of Personal Data

After Screened ceases providing Services that involve Processing Personal Data on Customer's behalf, Screened will, at Customer's choice, delete or return that Personal Data and delete existing copies, unless applicable law requires its storage. While retained under that exception, Screened will continue to protect the Personal Data and Process it only as required by law. Customer may make or change its choice at any time. Until Customer communicates a choice, Screened will retain the Personal Data in accordance with the retention periods stated in Appendix I.B and delete it when those periods end. Screened will confirm deletion on request. Personal Data held in routine backups and system logs is securely isolated, protected from any further Processing, and deleted in the ordinary course of Screened's backup and log rotation cycles.

14. CCPA Undertaking

You acknowledge and agree that You are the Business and Screened is the Service Provider with respect to any Personal Information of Consumers, as those terms are understood under the CCPA, forming part of Customer Data. Screened will not: (a) sell or share Personal Information of Consumers; (b) retain, use or disclose it for any purpose other than providing the Services in accordance with the Services Agreement and within the direct relationship between Screened and You; or (c) combine it with personal information received from another source, except as permitted by the CCPA. Screened will notify You if it determines that it can no longer meet its obligations under the CCPA. Upon notice, You may take reasonable and appropriate steps in accordance with the Services Agreement to stop and remediate any unauthorized use of Personal Information. Screened certifies that it understands and will comply with the restrictions in this Section 14.

15. Miscellaneous

15.1. If there is a conflict between this DPA and the Services Agreement concerning the Processing of Personal Data, this DPA prevails. If there is a conflict between this DPA and the SCCs, the SCCs prevail.

15.2. No Party shall receive any remuneration for performing its obligations under this DPA except as explicitly set out herein or in another agreement.

15.3. Where this DPA requires a "written notice", such notice can also be communicated by email to the other Party. Notices shall be sent to the contact persons set out in Appendix I.

15.4. Except for updates to the sub-processor list made in accordance with Section 11.1, any supplementary agreement or amendment to this DPA must be agreed by both Parties in writing, including electronically. Notwithstanding the foregoing, Screened may update this DPA by giving Customer at least thirty (30) days' written notice (including by email) where the update is required by Data Protection Laws or does not materially reduce the protections for Personal Data under this DPA.

15.5. Should individual provisions of this DPA become void, invalid or non-viable, this shall not affect the validity of the remaining conditions of this DPA.

15.6. Each Party's liability, taken together in the aggregate, arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Services Agreement.

The following Appendices form an integral part of this DPA:

APPENDIX I

A. LIST OF PARTIES UNDER THE SCCs

Data exporter(s): The Data Exporter is Customer, and its contact details are those provided under the Services Agreement. Signature and date: By entering into a Services Agreement that incorporates this DPA, or otherwise accepting this DPA, the Data Exporter is deemed to have signed the SCCs incorporated into this DPA, including their Annexes, as of the date this DPA is accepted.

Role: Controller

Data importer(s):

Name: Screened Pte. Ltd.

Address: 3 Coleman Street, #03-24, Singapore 179804.

Contact person's name, position and contact details:

Name: Wen Chen

Position: CEO

Email: policy@screened.io

Activities relevant to the data transferred under these Clauses: As specified in Part B.

Signature and date: By entering into a Services Agreement that incorporates this DPA, or otherwise agreeing to this DPA, the Data Importer is deemed to have signed the SCCs incorporated into this DPA, including their Annexes, as of the date this DPA is accepted.

Role (Controller / Processor): Processor

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred

Unless provided otherwise by the data exporter, transferred Personal Data relates to the following categories of Data Subjects: candidates and applicants of the Customer, employees, contractors, business partners or other individuals whose Personal Data is stored by, transmitted to, made available to, accessed by or otherwise Processed by the data importer.

Categories of personal data transferred

The transferred Personal Data concerns the following categories of data: Customer determines the categories of data and/or data fields which may be transferred through the Services as stated in the Services Agreement. The transferred Personal Data typically relates to the following categories of data: name, phone numbers, e-mail address, address data, system access / usage / authorization data, company name, contract data, invoice data, resume/CV and application data, interview recordings and transcripts, answers to job-related questions, and assessment outputs (such as scores, summaries and recommendations), as applicable based on the Services used, plus any application-specific data transferred by authorised personnel.

Sensitive data transferred (if applicable) and applied restrictions or safeguards

The Services are not intended to and do not require the Processing of Sensitive Personal Information, and Screened does not solicit it. Such information may be incidentally captured where individuals volunteer it in resumes or interview answers. Any such Processing is limited to providing the Services, no biometric analysis is performed, and responsibility for ensuring a lawful basis rests with the Customer as Controller.

The frequency of the transfer

Data is transferred on a continuous basis.

Nature of the processing

Collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data (whether or not by automated means).

Purpose(s) of the data transfer and further processing

Personal Data is transferred in the course of access to and use of the Services so that the data importer may provide, support, maintain and improve the Services in accordance with the Services Agreement.

The data importer may further transfer personal data to third-party service providers that host and maintain the data importer's applications, backup, storage, payment processing, analytics and other services as specified in the section on sub-processors below. These third-party service providers may have access to or process personal data for the purpose of providing these services to the data importer.

The period for which the personal data will be retained

Screen call recordings are available to Customer for the period set in Customer's recording retention settings (6 months by default), after which access ends and stored copies are deleted in the ordinary course of Screened's storage retention cycles. Other candidate records, including transcripts, evaluations and resumes, are retained for the period set in Customer's data retention settings (48 months by default). Account, contract and invoice records, including system access, usage and authorization data, are retained for the duration of the Services Agreement and afterwards until Customer requests deletion, except where applicable law requires longer retention. Upon termination or expiry of the Services Agreement, Personal Data will be deleted or returned in accordance with Section 13 of this DPA.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

Amazon Web Services

Cloud hosting, data storage, and email delivery

Based in the United States

Microsoft

Cloud services and identity provider (Microsoft sign-in)

Based in the United States

Google / Google Workspace / GCP

Cloud services, data collection, data storage, communication, calendar events, transcriptions, and AI model provider.

Based in the United States

OpenAI

AI model provider and voice integration

Based in the United States

Anthropic

AI model provider

Based in the United States

Twilio

Telephony provider

Based in the United States

Meta Platforms (WhatsApp Business Platform)

Messaging provider for candidate WhatsApp interviews

Based in the United States

Vapi

Voice integration provider

Based in the United States

Retell AI

Voice integration provider

Based in the United States

ElevenLabs

AI model provider and voice integration

Based in the United States

Deepgram

Speech-to-text (STT) and text-to-speech (TTS) provider

Based in the United States

Merge

ATS integration provider (for connecting additional applicant tracking systems)

Based in the United States

Snyk

Vulnerability management

Based in the United States

Google Analytics

Usage analytics

Based in the United States

Datadog

Application and infrastructure monitoring, logs, and error monitoring

Based in the United States

Sentry

Application and infrastructure monitoring, logs, and error monitoring

Based in the United States

Stripe

Payments

Based in the United States

Slack

Internal communications

Based in the United States

Intercom

Helpdesk ticketing

Based in the United States

Hotjar

Analytics

Based in the United States

Loops

Email delivery provider for account and product communications

Based in the United States

C. COMPETENT SUPERVISORY AUTHORITY

In respect of the SCCs:

Module 2: Transfer Controller to Processor
Where Customer is the data exporter, the supervisory authority shall be the competent supervisory authority that has supervision over the Customer in accordance with Clause 13 of the SCCs.

Appendix II - Technical and Organisational Security Measures

Screened maintains a written security program aligned with its SOC 2 Type II audit, including: (a) encryption of Personal Data in transit and at rest; (b) role-based access controls and least-privilege personnel access; (c) centralized logging and monitoring of production systems; (d) regular backups; (e) vulnerability management, including automated dependency and vulnerability scanning; (f) personnel confidentiality obligations and security training; (g) a documented incident response process; (h) sub-processor due diligence with contractual flow-down of data protection obligations; (i) physical and environmental security controls at the data centers operated by Screened's cloud hosting providers; and (j) business continuity measures, including the ability to restore the availability of and access to Personal Data in a timely manner after an incident. Additional information is available on our Security page.

Appendix III - List of Sub-processors

As set out in Part B of Appendix I.

Appendix IV: UK SCCs

These UK SCCs shall stand included as an addendum to the EU SCCs implemented under Clause 12.1(a) of this DPA.

Part 1: Tables

For data transfers from the United Kingdom that are subject to the UK SCCs, the UK SCCs will be deemed entered into (and incorporated into this DPA by this reference) and completed as follows:

(a) In Table 1 of the UK SCCs, the Parties' details and key contact information shall be as set forth in Appendix I.A.

(b) In Table 2 of the UK SCCs, information about the version of the Approved EU SCCs, modules and selected clauses which these UK SCCs are appended to shall be as set forth in Clauses 11.1 and 12.1(a)(i), (ii), (iii), (iv) and (ix) of this DPA.

(c) In Table 3 of the UK SCCs:

  • i Annex 1A: List of Parties: Parties are as set forth in Appendix I.A.
  • ii Annex 1B: Description of Transfer: Description of Transfer is as set forth in Appendix I.B.
  • iii Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data: TOMs are as set forth in Appendix II.
  • iv Annex III: List of Sub processors: Sub processors are as set forth in Appendix III.

(d) In Table 4 of the UK SCCs, both the data importer and the data exporter may end the UK SCCs in accordance with the terms of the UK SCCs.

Part 2: Mandatory Clauses

Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.