Data Protection Clauses
Sets out the contractual data-protection commitments ASE makes when handling personal or business data on behalf of clients and partners.
Last Updated: June 8, 2026
These Data Protection Clauses (this “DPC”) apply to the processing of Personal Data by Advanced Safety & Energy, Inc. (“Safety Academy” or “Processor”) on behalf of a customer (“Customer” or “Controller”) pursuant to the main agreement for services between the parties (the “Agreement”). This DPC is incorporated into and forms an integral part of the Agreement.
Controller and Processor may be referred to herein collectively as the “Parties” and each individually as a “Party.”
1. Definitions
For purposes of this DPC, the following terms shall have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given in the Agreement.
1.1. “Applicable Laws” means all laws, statutes, regulations, ordinances, and rules of any governmental or regulatory authority applicable to the Parties’ performance under this DPC.
1.2. “Data Protection Laws” means all Applicable Laws relating to data protection, privacy, or the processing of Personal Data, including without limitation: (i) the GDPR Legislation; (ii) the U.S. State Privacy Laws; (iii) the Swiss Federal Act on Data Protection; (iv) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the Act respecting the protection of personal information in the private sector (Quebec Law 25); and (v) any other applicable national, state, provincial, or local laws, regulations, or treaties relating to the protection of Personal Data, in each case as amended or replaced from time to time.
1.3. “Data Subject” means any identified or identifiable individual whose Personal Data is processed by Processor on behalf of Controller.
1.4. “EEA” means the European Economic Area.
1.5. “GDPR Legislation” means collectively: (i) Regulation (EU) 2016/679 (the “EU GDPR”); (ii) the United Kingdom General Data Protection Regulation, as defined in section 3(10) of the UK Data Protection Act 2018 (the “UK GDPR”); and (iii) any national implementing laws, regulations, and secondary legislation, in each case as amended or updated from time to time.
1.6. “International Data Transfer Mechanisms” means the lawful safeguards available under GDPR Legislation for transfers of Personal Data outside the EEA, the United Kingdom, or Switzerland, including the Standard Contractual Clauses (SCCs), the EU-U.S. Data Privacy Framework, and other recognized mechanisms.
1.7. “Personal Data” means any information that constitutes “personal data,” “personal information,” or any equivalent term defined under any applicable Data Protection Law, including any data relating to an identified or identifiable individual, processed by Processor on behalf of Controller pursuant to the Agreement.
1.8. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
1.9. “Sensitive Personal Data” means any category of Personal Data treated as sensitive or special under any Data Protection Law.
1.10. “Sub-processor” means any third party engaged by Processor to process Personal Data on behalf of Controller.
1.11. “Technical and Organizational Security Measures” or “TOMs” means those measures aimed at protecting Personal Data against a Personal Data Breach, as further described in Annex 2.
1.12. “U.S. State Privacy Laws” means the comprehensive consumer privacy laws of any U.S. state applicable to the Parties’ processing of Personal Data, including without limitation the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
2. Roles of the Parties and Compliance
2.1. Roles. The Parties acknowledge and agree that for the purposes of this DPC, Controller is the “controller” and Processor is the “processor” of Personal Data (as such terms are defined in the GDPR Legislation).
2.2. Compliance. Each Party shall comply with all applicable requirements of Data Protection Laws. To the extent the CCPA/CPRA applies, Processor is acting as a “service provider” or “contractor” and shall not sell, share, or retain, use, or disclose Personal Data outside the direct business relationship or for any purpose other than the specific business purpose set forth in the Agreement.
3. Processing of Personal Data
3.1. Processor shall process Personal Data only on the documented instructions of Controller, as set forth in the Agreement and this DPC, unless required to do otherwise by Applicable Laws. Where Processor is required to process Personal Data by Applicable Laws, Processor shall inform Controller of that legal requirement before processing, unless prohibited by such laws.
3.2. The details of the processing are described in Annex 1.
4. Sub-processing
4.1. General Authorization. Controller grants Processor a general written authorization to engage Sub-processors. Controller acknowledges and agrees that the services are provided through the use of third-party platforms for learning management and content delivery (“Core Platform Providers”). The Core Platform Providers and other Sub-processors engaged by Processor as of the effective date of the Agreement are deemed approved by Controller.
4.2. Sub-processor List. Processor shall maintain and make available to Controller upon request a current list of its Sub-processors.
4.3. New Sub-processors and Right to Object. Processor shall inform Controller in writing of any intended addition or replacement of any Sub-processor at least thirty (30) days in advance, thereby giving Controller the opportunity to object on reasonable, documented data protection grounds. If Controller objects, the Parties shall work in good faith to resolve the objection. If no resolution is reached, Controller’s sole remedy shall be to terminate the affected services for convenience in accordance with the termination provisions of the Agreement.
4.4. Flow-down Obligations. Processor shall ensure that each Sub-processor is bound by a written contract imposing data protection obligations no less protective than those set out in this DPC. Processor shall remain fully liable to Controller for the acts and omissions of any Sub-processor in relation to the processing of Personal Data as required by Data Protection Laws.
5. Security of Processing
5.1. Technical and Organizational Security Measures. Processor shall implement and maintain appropriate TOMs as described in Annex 2 to ensure a level of security appropriate to the risk.
5.2. Sub-processor Security. Processor’s security obligations under this Section 5 with respect to Personal Data processed on the infrastructure of a Core Platform Provider or other Sub-processor shall be satisfied by entering into and maintaining agreements that require each such Sub-processor to implement and maintain TOMs at least as protective of the Personal Data as those required of Processor under this DPC. Processor shall be responsible for exercising reasonable diligence in the selection and oversight of its Sub-processors.
5.3. Encryption. Processor shall require its Core Platform Providers to maintain industry-standard encryption for Data, including encryption for Data in transit over public networks (e.g., using TLS 1.2 or higher) and at rest.
5.4. Confidentiality. Processor shall ensure that any person it authorizes to process Personal Data is subject to a duty of confidentiality (whether contractual or statutory).
6. Data Subject Rights
Processor shall promptly notify Controller of any request received from a Data Subject to exercise their rights under Data Protection Laws. Taking into account the nature of the processing, Processor shall assist Controller through appropriate technical and organizational measures, insofar as possible, to enable Controller to respond to such requests. Processor shall not respond to any Data Subject request directly, except on the documented instructions of Controller or as required by Applicable Laws.
7. Personal Data Breach
7.1. Processor shall notify Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware, of a Personal Data Breach. Where such breach occurs on the systems of a Core Platform Provider or other Sub-processor, Processor shall be deemed to have become “aware” upon its receipt of a confirmed notification of the breach from that Sub-processor.
7.2. Such notification shall include, to the extent available: (i) the nature of the breach, including categories and approximate numbers of Data Subjects and records concerned; (ii) likely consequences; (iii) measures taken or proposed to address the breach; and (iv) the name and contact details of a point of contact at Processor.
7.3. Processor shall cooperate with Controller and take such reasonable steps as Controller directs to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
8. Audits and Cooperation
8.1. Upon Controller’s written request, Processor shall make available to Controller information reasonably necessary to demonstrate compliance with this DPC.
8.2. Any audit rights shall be limited to systems, facilities, and operations owned or operated by Processor. With respect to the infrastructure and systems of any Core Platform Provider or other Sub-processor, Processor shall satisfy its audit obligations by providing, upon Controller’s reasonable request and no more than annually, copies of the most recent third-party audit and certification reports obtained from such Sub-processors (e.g., SOC 2 Type II or ISO/IEC 27001). Direct audits, inspections, penetration tests, or forensic analysis of a Sub-processor’s systems or facilities by Controller or its agents are not permitted and are outside Processor’s control.
9. International Data Transfers
9.1. Data Residency. Processor shall require its Core Platform Providers to store Data in data centers located in either the United States or the European Union. Processor shall use commercially reasonable efforts to cause such Data to be stored within the United States. Controller acknowledges that Processor relies on third-party platforms and that ultimate data storage locations are subject to the providers’ standard operational practices, which may include use of other geographic regions for service redundancy, backup, and continuity.
9.2. Transfer Mechanisms. Processor shall not transfer Personal Data subject to the GDPR Legislation to any country outside the EEA, the United Kingdom, or Switzerland unless such transfer is supported by a valid International Data Transfer Mechanism, such as certification under the EU-U.S. Data Privacy Framework or execution of the Standard Contractual Clauses.
10. Deletion or Return of Personal Data
Upon termination of the Agreement, Processor shall (at Controller’s choice) either return to Controller or securely delete all Personal Data and copies thereof, except to the extent retention is required by Applicable Laws. Processor shall certify to Controller in writing that it has complied with this Section 10 upon request.
Annex 1: Details of Processing
A. Subject Matter, Nature, and Purpose of Processing
The subject matter of the processing is the Personal Data provided by Controller to Processor to facilitate the provision of training services, including online learning modules, machine safety services, electrical safety services, and related support as described in the Agreement. The nature of the processing includes the collection, storage, access, and use of Personal Data to manage user accounts, track training progress, and provide reporting to Controller.
B. Duration of the Processing
For the duration of the Agreement, and thereafter only as required to comply with Section 10 (Deletion or Return of Personal Data) of the DPC and Applicable Laws.
C. Types of Personal Data
Personal Data processed is limited to participant name and business email address. No Sensitive Personal Data is intended to be processed.
D. Categories of Data Subjects
Employees, contractors, and other authorized users of Controller who are granted access to the services.
Annex 2: Technical and Organizational Security Measures
Processor shall require its Core Platform Providers and other Sub-processors to implement and maintain a comprehensive information security program with technical and organizational security measures designed to protect the confidentiality, integrity, and availability of Personal Data. Such measures shall include, as applicable:
1. Third-Party Audits and Certifications. Processor shall, upon reasonable request, make available to Controller copies of the most recent third-party audit and certification reports from its relevant Core Platform Providers (e.g., SOC 2 Type II, ISO/IEC 27001).
2. Access Control. Measures to prevent unauthorized persons from gaining access to data processing systems, including logical and physical access controls, user authentication protocols, and limitations on access based on the principle of least privilege.
3. System Security. Measures to protect data processing systems, including endpoint detection and response, vulnerability scanning, penetration testing conducted by the provider, and regular application of security patches.
4. Data Encryption. Measures to ensure that Personal Data is protected from unauthorized access, including encryption of Personal Data in transit over public networks (e.g., TLS 1.2 or higher) and at rest.
5. Incident Response. Maintaining a formal incident response plan to detect, respond to, and recover from security incidents and Personal Data Breaches.
