2. Processing of Customer Personal Data
2.1. Customer is a Controller of Customer Personal Data and Endorsed is a Processor of Customer Personal Data. If Customer is itself acting as a Processor for Customer Personal Data on behalf of a Controller of such data, Endorsed will Process such data as a Sub-Processor to Customer. The details of Endorsed's Processing of Customer Personal Data are described in Schedule 1 to this DPA.
2.2. Endorsed will only Process Customer Personal Data as a Processor on behalf of and in accordance with Customer's prior written instructions, including any instructions provided through Customer's use of the Service. Customer hereby instructs Endorsed to Process Customer Personal Data to the extent necessary to provide the Service as set forth in the Agreement and this DPA. Endorsed shall not (1) retain, use, or disclose Customer Personal Data other than as provided for in the Agreement, as needed to provide the Service, or as otherwise permitted by Data Protection Laws; (2) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Endorsed, including by combining Customer Personal Data with Personal Data Endorsed receives from third parties, other than Customer, except as permitted by the Data Protection Laws; or (3) Sell or Share Customer Personal Data. Notwithstanding clauses (2) and (3) of the foregoing sentence, Endorsed may Process Customer Personal Data for the Fraud and Security Purposes described in Section 2.5 (Fraud and Security Purposes), which Processing the parties acknowledge does not constitute a Sale or Share of Customer Personal Data. Upon notice to Endorsed, Customer may take reasonable and appropriate steps to remediate Endorsed's use of Customer Personal Data in violation of this DPA.
2.3. Endorsed will immediately inform Customer if, in its opinion, an instruction from Customer infringes the Data Protection Laws. If applicable laws preclude Endorsed from complying with Customer's instructions, Endorsed will inform Customer of its inability to comply with the instructions, to the extent permitted by law.
2.4. Each of Customer and Endorsed will comply with their respective obligations under the Data Protection Laws. Endorsed shall notify Customer if it determines that it cannot meet its obligations under the Data Protection Laws. Customer has the right to take reasonable steps to ensure that Endorsed uses Customer Personal Data in a manner consistent with Customer's obligations under Data Protection Laws by exercising Customer's audit rights in Section 10 of this DPA.
2.5. Fraud and Security Purposes. Customer acknowledges that the Service is a fraud prevention and security service that operates, by design, on a cross-customer basis, and that the cross-customer Processing described in this Section 2.5 is the service that Customer engages Endorsed to perform.
2.5.1. Customer instructs and authorizes Endorsed to retain, use and disclose Customer Personal Data, including by combining Customer Personal Data with Personal Data that Endorsed receives from or on behalf of its other customers or that Endorsed collects from its own interaction with Data Subjects, in each case solely to the extent reasonably necessary and proportionate to prevent, detect or investigate data security incidents, or to protect against malicious, deceptive, fraudulent or illegal activity, including identity fraud, impersonation and material misrepresentation in connection with job applications, hiring and workforce engagement (the "Fraud and Security Purposes"). The Fraud and Security Purposes include creating, deriving, maintaining and updating fraud- and security-related signals, indicators, scores, flags and similar outputs from data across Endorsed's customer base ("Network Signals") and making Network Signals available to Endorsed's customers; Network Signals made available to any other Endorsed customer will not identify Customer as their source.
2.5.2. The parties acknowledge and agree that: (a) Endorsed performs the Processing described in this Section 2.5 in its capacity as a Processor and "service provider," and such Processing is expressly permitted of a service provider under the CCPA and its implementing regulations, including Cal. Civ. Code § 1798.140(e)(2) and Cal. Code Regs. tit. 11, § 7050(a)(4), and analogous provisions of other Data Protection Laws; (b) such Processing does not cause Endorsed to be a "third party" under the CCPA, and neither Customer's disclosure of Customer Personal Data to Endorsed nor Endorsed's Processing described in this Section 2.5 constitutes a Sale or Share of Personal Data by either party; and (c) Endorsed does not collect and sell Personal Data within the meaning of Cal. Civ. Code § 1798.99.80, and the parties do not intend that Endorsed be deemed a "data broker" thereunder or under any similar Data Protection Law by reason of the Processing described in this Section 2.5.
2.5.3. Where Endorsed Processes Customer Personal Data as a Sub-Processor to Customer pursuant to Section 2.1, the instructions and acknowledgements in this Section 2.5 apply equally to such Processing, and Customer represents and warrants that it is authorized to provide such instructions on behalf of the applicable Controller(s).
2.5.4. Endorsed will not retain, use, or disclose Customer Personal Data pursuant to this Section 2.5 for advertising or marketing purposes or for any purpose other than the Fraud and Security Purposes, and will not disclose Customer Personal Data pursuant to this Section 2.5 other than (i) in the form of Network Signals as described in Section 2.5.1, (ii) to Sub-Processors engaged in accordance with Section 5 of this DPA, or (iii) as required by applicable law. The use of data to train fraud detection models remains governed solely by Section 3.6 of the Agreement.
2.5.5. Endorsed will not use Customer Personal Data to develop, train or improve any product, service or model unrelated to fraud prevention, security or the provision of the Service. Any breach by Endorsed of its obligations under this Section 2.5 will constitute a material breach of the Agreement for purposes of the termination provisions of the Agreement.