Privacy Addendum

This EnFi Consumer Privacy Law Addendum (this “Privacy Addendum”), effective as of the Effective Date, forms part of the Master Subscription and Services Agreement (the “Agreement”) between Customer and EnFi.  This Privacy Addendum applies where, and to the extent that, EnFi processes personal information of consumers on behalf of the Customer when providing products, software or services under the Agreement (the “Products and Services”).  All capitalized terms used as defined terms but not otherwise defined in this Privacy Addendum shall have the meanings given to such terms in the Agreement.

Additionally, where the California Consumer Privacy Act of 2018 and its implementing regulations, as amended effective January 1, 2023 by the California Privacy Rights Act and its implementing regulations (the two laws collectively, as amended, restated or supplemented from time to time, the “CCPA”) applies, the terms “business,” “combine,” “commercial purpose,” “consumer,” “contractor,” “personal information,” “processing,” “sell” (and its corresponding “sale”), “sensitive personal information,” “share” and “service provider” shall have the meanings given to such terms in CCPA; and where any of the state privacy laws listed below and their respective implementing regulations (each, an “Other State Law,” and, collectively, the “Other State Laws”) apply, the terms “consumer,” “controller,” “processing,” “processor,” “sell” (and its corresponding “sale”) and “targeted advertising” shall have the meanings given to such terms in the applicable Other State Law, and the terms “personal information” and “sensitive personal information” shall have the same meaning as the term “personal data” and “sensitive personal data” as such terms are defined in the applicable Other State Law.  The Other State Laws are:

  • The Virginia Consumer Data Protection Act, effective January 1, 2023 (as amended, restated or supplemented from time to time, the “VCDPA”);
  • The Colorado Privacy Act, effective July 1, 2023 (as amended, restated or supplemented from time to time, the “CPA”);
  • The Connecticut Personal Data Privacy and Online Monitoring Act, effective July 1, 2023 (as amended, restated or supplemented from time to time, the “CPDPOMA”);
  • The Utah Consumer Privacy Act, effective December 31, 2023 (as amended, restated or supplemented from time to time, the “UCPA”);
  • The Montana Consumer Data Privacy Act, effective July 1, 2024 (as amended, restated or supplemented from time to time, the “MCDPA”);
  • The Oregon Consumer Privacy Act, effective July 1, 2024 (as amended, restated or supplemented from time to time, the “OCPA”);
  • The Texas Data Privacy and Security Act, effective July 1, 2024 (as amended, restated or supplemented from time to time, the “TDPSA”);
  • The Delaware Personal Data Privacy Act, effective January 1, 2025 (as amended, restated or supplemented from time to time, the “DPDPA”);
  • The Iowa Consumer Data Protection Act, effective January 1, 2025 (as amended, restated or supplemented from time to time, the “IACDPA”);
  • The Tennessee Information Protection Act, effective July 1, 2025 (as amended, restated or supplemented from time to time, the “TIPA”); and
  • The Indiana Consumer Data Protection Act, effective January 1, 2026 (as amended, restated or supplemented from time to time, the “INCDPA”).

In consideration of the mutual obligations set forth herein, the parties agree to the terms and conditions of this Privacy Addendum.

  1. The parties acknowledge and agree that Customer is a business and EnFi is a service provider or contractor to Customer under the CCPA, and Customer is a controller and EnFi is a processor under the Other State Laws.  The specific purpose for which EnFi is processing personal information under the Agreement (and the only purpose for which Customer discloses personal information to EnFi under this Agreement) is for EnFi to provide the Products and Services as specifically set forth in the Agreement.
  2. In its processing of personal information of consumers that Customer has transferred to EnFi for processing, that EnFi may have access to, or that EnFi has collected on Customer’s behalf, in each case in connection with performing or providing the Products and Services, EnFi shall comply with all requirements of the CCPA that are applicable to service providers and contractors and all requirements of the applicable Other State Laws that are applicable to processors.  Without limiting the foregoing, during the term of the Agreement and thereafter, EnFi shall: (i) not retain, use or disclose the personal information for any purpose (including any commercial purpose) other than for the specific purpose of providing or performing the Products and Services contemplated by the Agreement; (ii) not retain, use or disclose the personal information outside of the direct business relationship between EnFi and Customer; (iii) not sell or (where CCPA applies) share the personal information to or with any third parties; (iv) not combine the personal information that EnFi receives from, or on behalf of, Customer with personal information that EnFi receives from, or on behalf of, another person or persons, or collects from its own interaction with the consumer, provided that EnFi may combine such personal information (1) for the specific purpose of providing or performing the Products and Services contemplated by the Agreement or (2) to perform any other permitted business purpose under CCPA and/or the Other State Laws, as applicable; (v) not process personal information for the purposes of targeted advertising; (vi) limit its use of sensitive personal information to that use which is necessary to perform or provide the Products and Services and to ensure the security and integrity of the Products and Services and the infrastructure, systems and networks associated with the Products and Services; (vii) taking into account the nature of processing and the information available to EnFi, by appropriate technical and organizational measures and insofar as this is reasonably practical, promptly comply with Customer’s reasonable written instructions associated with responding to any consumer’s request to exercise the consumer’s rights under CCPA or the Other State Laws, as applicable; (viii) ensure that each person processing personal information by or on behalf of EnFi is subject to a duty of confidentiality (whether by binding written agreement or other applicable professional or statutory duty); (ix) taking into account the nature of processing and the information available to EnFi, reasonably assist Customer in meeting its obligations in relation to the security of processing personal information and in relation to providing for legally required notifications of breaches involving personal information; (x) at Customer’s direction, delete or return to Customer all personal information as requested at the end of the provision of Products and Services, subject to the terms and conditions of the Agreement and unless retention of the personal information is otherwise permitted or required by law; and (xi) notify Customer after EnFi makes a determination that it can no longer meet its obligations under this Privacy Addendum.  Customer has the right, upon written notice to EnFi, to take reasonable and appropriate steps to stop and remediate EnFi’s unauthorized use of personal information.  EnFi certifies that it understands and will comply with the restrictions, duties and obligations set forth in this Section 2.
  3. Where not prohibited by applicable law, nothing in this Privacy Addendum shall prohibit EnFi from retaining, using or disclosing the personal information in connection with: (i) retaining or employing another service provider, processor, contractor or subcontractor (as applicable), provided the service provider, processor, contractor or subcontractor meets the requirements for a service provider, processor, contractor or subcontractor under the CCPA or Other State Law, as applicable; (ii) internal use by EnFi to build or improve the quality of its services, provided that the use does not include building or modifying household or consumer profiles for use in providing services to another business, or correcting or augmenting data acquired from another source; (iii) detecting data security incidents, or protecting against fraudulent or illegal activity; (iv) complying with federal, state or local laws; (v) complying with a civil, criminal or regulatory inquiry, investigation, subpoena, or summons by federal, state or local authorities; (vi) cooperating with law enforcement agencies concerning conduct or activity that Customer, EnFi or a third party reasonably and in good faith believes may violate federal, state or local law; or (vii) exercising or defending legal claims.
  4. EnFi shall fully cooperate with Customer in responding to any consumer’s request to exercise the consumer’s rights under the CCPA and/or Other State Laws, as applicable.  In the event that any consumer makes a request directly to EnFi with respect to exercising its rights under the CCPA and/or an Other State Law, EnFi shall promptly (and in any case within five (5) days of receipt) notify Customer and forward a copy of the consumer’s request to Customer, unless legally prohibited from doing so.  EnFi shall not respond directly to any such consumer request without Customer’s prior authorization, except and only to the extent EnFi is legally compelled to do so.  If EnFi is legally compelled to respond to such a consumer request, then EnFi shall provide Customer with a copy of EnFi’s response.
  5. If EnFi authorizes any subcontractor (each, an “EnFi Subcontractor”) to process, retain or use any personal information received from Customer, accessed in connection with the Products and Services or collected on Customer’s behalf in connection with the Products and Services, then prior to any disclosure of such personal information to such EnFi Subcontractor, EnFi shall enter into a written agreement with such EnFi Subcontractor that (i) includes all required or necessary terms to ensure that such EnFi Subcontractor is deemed a service provider or contractor within the meaning of the CCPA or a processor, subprocessor or subcontractor within the meaning of any applicable Other State Law; and (ii) requires the EnFi Subcontractor to be bound by terms that are substantially equivalent to the restrictions, duties and obligations under this Privacy Addendum.  Without limiting the foregoing, EnFi shall remain primarily liable for any breach or non-compliance of the CCPA and/or Other State laws by its EnFi Subcontractors.
  6. Upon Customer’s reasonable written request, and at Customer’s expense, EnFi will make available to Customer all information in EnFi’s possession necessary to demonstrate EnFi’s compliance with the obligations in this Privacy Addendum and (solely to the extent required by applicable law) to enable Customer to conduct and document data protection assessments.  Additionally, at Customer’s expense, EnFi will allow for, and cooperate with, reasonable assessments by Customer or its designated assessor; alternatively, EnFi may (at no additional charge to Customer) arrange for a qualified and independent assessor to conduct an assessment of EnFi’s policies and technical and organizational measures in support of the obligations under this Privacy Addendum using an appropriate and accepted control standard or framework and assessment procedure for such assessments and provide a report of such assessment to Customer upon request.  Customer acknowledges and agrees that any information, reports or assessments made available to Customer under this paragraph shall be EnFi’s Confidential Information and shall be subject to all confidentiality obligations set forth in the Agreement.
  7. To the extent this Privacy Addendum is not governed exclusively by the jurisdictions set out in the CCPA and/or the Other State Laws, it shall be governed by and construed in accordance with the laws of the United States of America and the State of Delaware (as applicable), without regard to any conflicts of law provisions.  The parties expressly agree that, to the maximum extent permitted by applicable law, the exclusions or limitations of liability set forth in the Agreement apply to EnFi’s liability or obligations under this Privacy Addendum.  To the extent there is any conflict between this Privacy Addendum and the Agreement or any other data protection agreement(s) between the parties, then (i) with respect to measures for protecting the personal information from unauthorized access, use, modification, exfiltration, theft or disclosure, the agreement with the measures that are most protective of the personal information of consumers shall prevail, and (ii) with respect to all other matters pertaining to the personal information of consumers, this Privacy Addendum shall prevail.