Wonder Data Processing Agreement

Last updated: August 25, 2026

This Data Processing Agreement (“DPA”) is entered into between Sun Is Up Labs Ltd., an Israeli company with its registered address at Shoshanat Haamakim 41B, Kadima-Zoran, Israel (“Processor,” “Sun Is Up,” “we,” “us”), and the educational institution identified in the applicable order form or master agreement between the parties (“Controller,” “Institution,” “you”), each a “Party” and together the “Parties.”

This DPA supplements and forms part of the agreement between Sun Is Up and the Institution governing the Institution's use of the Wonder platform (the “Agreement” and the “Platform”, respectively). In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data (as defined below), this DPA governs. Capitalized terms not defined here have the meaning given in the Agreement.

1. Definitions

TermDefinition
Applicable Data Protection LawsAll data protection and privacy laws applicable to the Processing of the Personal Data under this DPA, including (as applicable) the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Israeli Privacy Protection Law, 5741-1981, as amended by Amendment 13, and applicable United States state privacy laws.
Controller, Processor, Data Subject, Processing, Personal Data BreachHave the meanings given in the GDPR, applied correspondingly under other Applicable Data Protection Laws.
InstructorsLecturers, teaching staff, and other course operators who teach, grade, and manage courses on the Platform on behalf of the Institution.
LearnersStudents enrolled in a course on the Platform through the Institution.
Personal Data / Personal InformationAny information relating to an identified or identifiable natural person, Processed by the Processor on behalf of the Controller.
Sensitive DataPersonal Data that is protected under special requirements and requires unique treatment, such as “special categories of data”, “sensitive data” or other materially similar terms under Applicable Data Protection Laws, which may include any of the following: (a) social security number, tax file number, passport number, driver's license number, or similar identifier (or any portion thereof); (b) financial or credit information, credit or debit card number; (c) information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning a person's health, sex life or sexual orientation, or data relating to criminal convictions and offences; (d) Personal Data relating to children; and/or (e) account passwords in unhashed form.
Sub-processorAny third party engaged by Sun Is Up to process Personal Data on Sun Is Up's behalf in connection with the Agreement.
Standard Contractual Clauses (SCCs)The standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), and any equivalent UK mechanism (the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs), as applicable.
CCPAThe California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, together with its implementing regulations. The terms “sell”, “sale”, “share”, “sharing”, “business”, “business purpose”, “consumer” and “service provider” have the meanings given to them in the CCPA.

2. Roles of the Parties

As between the Parties, the Institution is the Controller and Sun Is Up is the Processor with respect to the Personal Data. The Institution instructs Sun Is Up to process such Personal Data only as necessary to provide the Platform and related services described in the Agreement, and as further specified in Annex A and in the Institution's written instructions from time to time.

The Institution represents and warrants that it has complied, and will continue to comply, with Applicable Data Protection Laws in respect of its collection and use of Personal Data, including that it has a valid legal basis for the processing carried out through the Platform and for engaging Sun Is Up as a Processor, and that its instructions to Sun Is Up (including any configuration choices made through the Platform) do not require Sun Is Up to process Personal Data in a manner that would violate Applicable Data Protection Laws. Sun Is Up shall promptly inform the Institution if, in its opinion, an instruction from the Institution infringes Applicable Data Protection Laws, unless Sun Is Up is prohibited from providing such notice under Applicable Data Protection Laws.

3. Processor Obligations

3.1 Processing on instructions

Sun Is Up shall process Personal Data only on the Institution's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by Applicable Data Protection Laws; in such a case, Sun Is Up shall inform the Institution of that legal requirement before processing, unless that law prohibits such notice. The details relating to the duration, nature and purpose, types of Personal Data and categories of Data Subjects Processed under this DPA are further specified in Annex A.

Without limiting the foregoing, Sun Is Up Processes Personal Data for the following purposes: (a) providing the Platform and related services in accordance with the Agreement and the Institution's documented instructions, to the extent such instructions are consistent with this DPA and the Agreement, as further described in Annex A; (b) transmitting Personal Data to, or receiving Personal Data from, third parties in accordance with the Institution's instructions or pursuant to the Institution's use or configuration of the Platform, including any integrations the Institution enables between the Platform and third-party services (such as the retrieval of course-session recordings from the Institution's video-conferencing provider); (c) rendering Personal Data anonymous or aggregated, provided that the resulting data can no longer be used to identify a Data Subject; and (d) complying with Applicable Data Protection Laws or a binding order of a competent governmental or regulatory authority, subject to the notice requirement set out above.

3.2 Sensitive Data

The Parties agree that the Platform is not intended for the Processing of Sensitive Data, and that if the Institution wishes to use the Platform to Process Sensitive Data, it shall provide Sun Is Up with prior written notice, and Sun Is Up may require additional safeguards as a condition of such Processing.

3.3 Confidentiality

Sun Is Up shall ensure that any person authorized to process Personal Data (including its employees, contractors, and Sub-processors) is subject to an appropriate duty of confidentiality, whether contractual or statutory.

3.4 Security of processing

Sun Is Up shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex B. The Parties acknowledge that no technical or organizational measures can eliminate all security risk, and that the measures described in Annex B are designed to reduce that risk to a level appropriate to the processing rather than to eliminate it.

3.5 Sub-processing

The Institution authorizes Sun Is Up to engage the Sub-processors listed in Annex C as of the effective date of this DPA. Sun Is Up shall notify the Institution of any intended addition or replacement of a Sub-processor at least 7 days in advance. If the Institution reasonably objects to a new Sub-processor on data protection or security grounds within that period, the Parties shall work in good faith to resolve the objection; if they cannot do so, the Institution may, as a sole remedy, terminate the affected portion of the services provided by the objected-to Sub-processor without penalty. Sun Is Up remains liable to the Institution for the acts and omissions of its Sub-processors to the same extent it would be liable if performing their services directly, and shall impose data protection obligations on each Sub-processor that are no less protective than those in this DPA.

3.6 Assistance with data subject rights

Taking into account the nature of the processing, Sun Is Up shall provide reasonable assistance to the Institution, by appropriate technical and organizational measures, to enable the Institution to respond to requests from Data Subjects seeking to exercise their rights under Applicable Data Protection Laws. If Sun Is Up receives such a request directly from a Data Subject, it will inform the Institution without undue delay and will not respond to the request itself except to confirm receipt, on the Institution's instruction or as required by law.

3.7 Assistance with security, breach notification, and impact assessments

Sun Is Up shall notify the Institution without undue delay, and in any event within 48 hours after becoming aware of any Personal Data Breach affecting the Personal Data. Sun Is Up shall provide the Institution with sufficient information (which may be provided incrementally, as and when it becomes known to Sun Is Up) to allow the Institution to meet its own notification obligations under Applicable Data Protection Laws, and shall reasonably cooperate with the Institution's investigation and remediation of the incident. Sun Is Up shall further provide reasonable assistance to the Institution in connection with any data protection impact assessment or prior consultation with a supervisory authority that the Institution reasonably determines is required in relation to the Platform. This Section does not apply to unsuccessful attempts or to activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans and denial-of-service attacks, or to incidents arising from the acts or omissions of the Institution, its Learners or its Instructors, from use of the Platform other than as permitted under the Agreement, or from systems, devices or credentials outside Sun Is Up's control. Sun Is Up's notification of, or response to, a Personal Data Breach under this Section shall not be construed as an acknowledgment or admission by Sun Is Up of any fault or liability with respect to that Personal Data Breach.

The Institution shall not issue any public communication, notice, press release or report concerning a Personal Data Breach that identifies Sun Is Up, whether by name or by reasonably identifiable description, without Sun Is Up's prior written approval, except where and to the extent the Institution is required to do so under Applicable Data Protection Laws or by a competent supervisory authority.

3.8 Audits

On reasonable request, and no more than once per 12-month period (except following a confirmed Personal Data Breach or as required by a supervisory authority), Sun Is Up shall make available to the Institution its then-current security documentation, which may include security reports, a completed security questionnaire, or equivalent, sufficient to demonstrate compliance with this DPA and Applicable Data Protection Laws. If Sun Is Up's security documentation is not sufficient to address the Institution's reasonable compliance concerns, the Institution may additionally request an on-site audit of Sun Is Up's relevant policies, procedures, and systems, subject to the following conditions: (a) the audit shall be conducted by an independent third-party auditor bound by confidentiality obligations to Sun Is Up's satisfaction, and not by the Institution's own personnel; (b) the Institution shall provide Sun Is Up with at least 30 days' prior written notice to schedule the audit; (c) the audit shall take place during Sun Is Up's normal business hours and shall not unreasonably interfere with Sun Is Up's operations; (d) the audit shall be limited to information reasonably necessary to verify compliance with this DPA and shall not extend to the data or systems of any third party; and (e) all costs of the audit, including Sun Is Up's reasonable costs of facilitating it, shall be borne by the Institution.

3.9 Return or deletion of Personal Data

On termination or expiration of the Agreement, Sun Is Up shall, at the Institution's election, delete or return all Personal Data processed under this DPA within 90 days, and shall delete existing copies unless Applicable Data Protection Laws require Sun Is Up to retain some or all of the Personal Data, in which case Sun Is Up shall not Process that Personal Data further, except as required by applicable law. This Section does not apply to data that Sun Is Up has anonymized or aggregated so that it no longer relates to, and can no longer be used to identify, any individual, which Sun Is Up is not required to delete or return.

3.10 CCPA Standard of Care; No Sale or Sharing of Personal Data

With respect to Personal Data that is subject to the CCPA, Sun Is Up is a “service provider” and shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than for the specific business purpose of performing the services described in the Agreement and this DPA, including as necessary to maintain, support, or improve those services; (c) retain, use, or disclose Personal Data outside of the direct business relationship between Sun Is Up and the Institution; or (d) combine Personal Data with personal information Sun Is Up receives from or on behalf of another person, except as permitted under the CCPA. Sun Is Up does not receive Personal Data as consideration for any services or other items it provides to the Institution under the Agreement or this DPA, and shall not take any action that would cause a transfer of Personal Data under the Agreement or this DPA to constitute a sale or sharing of Personal Data. Sun Is Up acknowledges that the Institution discloses Personal Data to it only for the limited and specified purposes set out in the Agreement and this DPA, and shall Process Personal Data only for those purposes and in compliance with the obligations applicable to it under the CCPA, providing the same level of privacy protection as the CCPA requires of the Institution. The Institution has the right, upon notice, to take reasonable and appropriate steps to ensure that Sun Is Up Processes Personal Data consistently with the Institution's obligations under the CCPA, and to stop and remediate any unauthorized use of Personal Data by Sun Is Up. Sun Is Up shall notify the Institution if it makes a determination that it can no longer meet its obligations under this Section.

4. International Data Transfers

Where Sun Is Up processes Personal Data originating in the European Economic Area or the United Kingdom in a country not recognized as providing an adequate level of data protection, such processing is made subject to the Standard Contractual Clauses, incorporated by reference as Annex D and deemed entered into by the Parties as set out therein: for transfers from a Controller to a Processor, Module Two applies; Sun Is Up is the “data importer” and the Institution is the “data exporter.” Where a Sub-processor located outside the EEA/UK processes such Personal Data, Module Three (Processor to Processor) applies as between Sun Is Up and that Sub-processor.

Separately, and in addition to the mechanisms described above, any transfer of Personal Data out of Israel is subject to the Israel-specific requirements set out in Annex E.

Where a U.S.-based Sub-processor is self-certified under the EU-U.S. Data Privacy Framework (or its UK Extension), transfers to that Sub-processor are made pursuant to the European Commission's adequacy decision for the Framework (Commission Implementing Decision (EU) 2023/1795) and the corresponding UK adequacy regulations, without the need for the Standard Contractual Clauses.

If Sun Is Up receives a legally binding request from a public authority for disclosure of Personal Data, Sun Is Up shall, to the extent legally permitted, notify the Institution without undue delay, seek to redirect the request to the Institution, and challenge any request it considers unlawful or overbroad, disclosing only the minimum amount of Personal Data necessary to respond. On the Institution's written request, and no more than once in any 12-month period, Sun Is Up shall inform the Institution of the types of binding legal demands for Personal Data it has received, to the extent it is permitted to do so. If a transfer mechanism relied on under this Section ceases to provide a valid basis for the transfer of Personal Data, or a supervisory authority requires transfers made on that basis to be suspended, Sun Is Up may, on notice to the Institution, adopt alternative arrangements or safeguards for the affected transfers as required by Applicable Data Protection Laws.

5. Liability

Each Party's liability arising out of or in connection with this DPA is subject to the same limitations and exclusions of liability set out in the Agreement, and this DPA does not create any separate or additional basis of liability beyond what the Agreement provides.

6. Term

This DPA takes effect on the effective date of the Agreement and remains in effect for as long as Sun Is Up processes Personal Data on the Institution's behalf under the Agreement, notwithstanding the expiration or termination of the Agreement itself with respect to any Personal Data retained under Section 3.9.

7. Governing Law

This DPA is governed by the laws which govern the Agreement, without regard to conflict-of-laws principles, except that the Standard Contractual Clauses incorporated as Annex D are governed by the law specified therein.

8. Miscellaneous

Any notice required or permitted under this DPA shall be in writing and delivered to the business and legal contacts designated for notices under the Agreement (or, if none are separately designated, to the Parties' primary business contacts for the Agreement), by email with confirmation of receipt or by any other method providing reasonable evidence of delivery. This DPA may be amended only by written agreement of both Parties, except if an amendment is required by Applicable Data Protection Laws, in which case Sun Is Up may provide reasonable notice of an amendment to this DPA and such amendment shall become effective following such notification period. If any provision of this DPA is held unenforceable, the remaining provisions remain in full force and effect.

In the event of any conflict or inconsistency between the following documents regarding the Processing of Personal Data, the following order of precedence shall apply, from highest to lowest: (i) the Standard Contractual Clauses (to the extent applicable); (ii) this DPA; and (iii) the Agreement.

Annex A: Details of Processing

DetailsDescription
Data ExporterThe Institution identified in the applicable order form or master agreement between the Parties. Name, address, official registration number and contact person: as set out in the Agreement. Role: Controller. Activities relevant to the transfer: as described in this Annex A.
Data ImporterSun Is Up Labs Ltd. Address: Shoshanat Haamakim 41B, Kadima-Zoran, Israel. Contact person: as designated for notices under the Agreement. Role: Processor. Activities relevant to the transfer: as described in this Annex A.
Subject matterProvision of the Wonder learning management platform to the Institution.
DurationFor the term of the Agreement, and thereafter as set out in Section 3.9 of this DPA.
Nature and purpose of processingHosting, storage, and processing of Personal Data as necessary to operate the Platform: account creation and management to Learners, course delivery, grading and assessment, communications between Learners and Instructors, lecture recording and playback, AI-assisted content generation, and related security, support, and analytics functions.
Categories of Data SubjectsLearners and Instructors affiliated with the Institution.
Categories of Personal DataAccount and registration data of Learners; enrollment and course data; grades and assessment results; course activity and engagement data of Learners and Instructors (e.g., time spent on assignments, grading activity); lecture recordings, messages, and AI-generated content; Institution-provided roster and enrollment records.
Special categories of dataNot intentionally collected as a standard practice; where the Institution or a Learner or Instructor discloses Sensitive Data within Platform content (e.g. lecture recordings or messages that reveal health, biometric, or other special-category data as defined under Applicable Data Protection Laws), Sun Is Up processes it only as instructed by the Institution and only after the Institution has provided Sun Is Up with prior written notice in accordance with Section 3.2 of this DPA.
Frequency of transferContinuous, for the duration of the Agreement.

Annex B: Technical and Organizational Security Measures

Sun Is Up maintains administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, including measures addressing:

MeasureDescription
Access ControlRole-based access to Personal Data, limited to personnel who require it to perform their duties, together with unique user credentials and periodic access reviews.
AuthenticationMulti-factor authentication for administrative and remote access to systems processing Personal Data.
EncryptionEncryption of Personal Data in transit (e.g., via TLS or equivalent standard) and at rest.
Confidentiality of PersonnelContractual and/or statutory confidentiality obligations imposed on personnel and Sub-processors with access to Personal Data, together with data protection training.
Physical and Environmental SecurityPhysical access controls and environmental safeguards at the facilities operated by Sun Is Up's hosting providers.
Network and System SecurityFirewalls, network segmentation, and other controls designed to prevent unauthorized access to systems processing Personal Data.
Availability and ResilienceRegular backups and a documented process for restoring availability and access to Personal Data in a timely manner following a physical or technical incident.
Data IntegrityMeasures designed to protect Personal Data from unauthorized or accidental alteration or loss during processing, transmission, and storage.
Monitoring and LoggingLogging of access to systems processing Personal Data and monitoring for anomalous or unauthorized activity.
Testing and EvaluationA process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational security measures.
Incident ResponseA documented incident response process for identifying, investigating, containing, and responding to Personal Data Breaches, including the notification process described in Section 3.7.
Sub-processor OversightSecurity due diligence and contractual requirements imposed on Sub-processors prior to engagement, consistent with Section 3.5.

Annex C: Approved Sub-processors

Sub-processorPurposeProcessing location
Amazon Web Services (AWS)Backend hosting, file/object storage, infrastructure, logging and related cloud servicesEuropean Union (Frankfurt) for Wonder's primary production infrastructure
VercelHosting and delivery of the Wonder web applicationGlobal infrastructure
MongoDB, Inc. (MongoDB Atlas)Managed database hostingEuropean Union (Frankfurt)
OpenAI, L.L.C.AI-assisted functionality, including course-material retrieval, chat, content processing, feedback and related AI functionsGlobal
Google Cloud / Google LLCAI document processing through Vertex AI and supporting cloud storage / document-processing servicesUnited States for currently configured AI processing
AssemblyAI, Inc.Audio transcriptionUnited States
ActiveCampaign, LLC (Postmark)Transactional email deliveryUnited States
Zoom Video Communications, Inc.Video-conferencing integration and retrieval of institution-authorized meeting recordingsAs configured by the Institution / Zoom
RapidAPI / Judge0Execution of source code for programming assignmentsUnited States / provider infrastructure
AutoContentAI-assisted generation of learning media and educational contentProvider infrastructure

Annex D: International Transfer Mechanism

Where required by Section 4 of this DPA, the EU Standard Contractual Clauses, as adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng — Module Two (Controller to Processor), as between the Institution and Sun Is Up, and, as applicable to Sub-processors located outside the EEA/UK, Module Three (Processor to Processor) — apply automatically whenever a transfer under this Section 4 requires them, completed with the identity of the Parties, the Annex A details, and the Annex B security measures set out in this DPA. The EU SCCs, so completed, are deemed entered into and executed by the Parties as set out in paragraph (h) below.

The UK International Data Transfer Agreement (or, as applicable, the UK Addendum to the EU Standard Contractual Clauses), as published by the UK Information Commissioner's Office, available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/, applies on the same basis for transfers of Personal Data originating in the United Kingdom, and is likewise deemed entered into by the Parties, as set out below.

For each applicable Module of the EU SCCs, the Parties agree that: (a) the optional docking clause in Clause 7 does not apply; (b) in Clause 9, Option 2 (general written authorization) applies, and the minimum period for prior notice of Sub-processor changes is the period set out in Section 3.5 of this DPA; (c) the optional language in Clause 11 does not apply; (d) all square brackets in Clause 13 are removed, and the competent supervisory authority is the supervisory authority of the Institution as data exporter; (e) in Clause 17, Option 1 applies and the EU SCCs are governed by the laws of Ireland; (f) in Clause 18(b), disputes shall be resolved before the courts of Ireland; (g) Annex A to this DPA contains the information required by Annex I of the EU SCCs, Annex B contains the information required by Annex II, and Annex C contains the information required by Annex III; and (h) by entering into this DPA, the Parties are deemed to have signed the EU SCCs, including their Annexes.

Where a transfer is subject to the UK GDPR, the EU SCCs apply as amended and completed by the UK Addendum, and the Parties agree that: (a) the competent supervisory authority is the UK Information Commissioner's Office; (b) the UK Addendum, and the EU SCCs as incorporated into it, are governed by the laws of England and Wales, and any dispute arising from them shall be resolved before the courts of England and Wales; (c) Annex A, Annex B and Annex C of this DPA contain the Appendix Information required by the UK Addendum, as described in paragraph (g) above; (d) by entering into this DPA, the Parties are deemed to have entered into the UK Addendum, which has the same effect as signing the EU SCCs it incorporates; and (e) either Party may end the UK Addendum, in accordance with its own terms, where a revised version issued by the UK Information Commissioner's Office would result in a substantial, disproportionate and demonstrable increase in that Party's costs or risks under it.

Annex E: Israeli Data Security Regulations (Regulation 15)

This Annex addresses the Parties' respective roles and obligations under the Israeli Protection of Privacy Regulations (Data Security), 5777-2017 (the “Data Security Regulations”), issued under the Protection of Privacy Law, 5741-1981, to the extent the Personal Data processed under this DPA is held in a database subject to Israeli law.

ItemDescription
1. RolesFor purposes of the Data Security Regulations, the Institution is the database owner and, where applicable, the database manager, and Sun Is Up is a database holder with respect to the Personal Data it processes on the Institution's behalf under this DPA.
2. Scope of AccessThe database in respect of which Sun Is Up acts as a database holder is the database comprising the Personal Data described in Annex A, as hosted within the Platform environment operated by Sun Is Up and the Sub-processors listed in Annex C. Sun Is Up's access to that database is limited to the Personal Data categories and processing purposes described in Annex A, solely for the purpose of providing the Platform and related services under the Agreement, and Sun Is Up shall not access, use, copy, or transfer any part of that database for any purpose other than those set out in Section 3.1 and Annex A.
3. Security MeasuresSun Is Up shall implement the security measures described in Annex B, which are intended to address the requirements applicable to a database holder under the Data Security Regulations, including with respect to the security level applicable to the database, as classified by the Institution as database owner.
4. Annual Compliance ReportAt least once in every 12-month period, and in addition on the Institution's written request, Sun Is Up shall provide the Institution with a written report on the manner in which it has complied with this DPA, including this Annex E and the security measures described in Annex B, to assist the Institution in meeting its own supervision, reporting and audit obligations as database owner under the Data Security Regulations.
5. NotificationSun Is Up shall notify the Institution of any severe security incident, as that term is used in the Data Security Regulations, affecting the database, in accordance with the breach notification timeline set out in Section 3.7 of this DPA.
6. Cross-Border TransfersAny transfer of Personal Data out of Israel to Sun Is Up, or onward from Sun Is Up to any Sub-processor, is subject to the Privacy Protection Regulations (Transfer of Data to Databases Outside of the State of Israel), 2001, Regulation 2(4). Sun Is Up commits, and shall require its Sub-processors to commit, to protections equivalent to those required under Israeli law with respect to Personal Data transferred to or through Israel. Where Personal Data originated in the EEA and is transferred onward from Israel, Sun Is Up shall further comply with the Privacy Protection Regulations (Instructions Regarding Data Transfers from the European Economic Area to Israel), 5783-2023. This is in addition to, and not instead of, the international transfer mechanisms described in Section 4 of this DPA, which apply independently based on the origin of the Personal Data.
7. Additional Regulation 15 MattersFor the convenience of the Institution as database owner, the following matters required to be addressed in an engagement with a database holder are set out elsewhere in this DPA and apply equally for the purposes of the Data Security Regulations: the permitted purposes of Processing and the prohibition on Processing for any other purpose (Section 3.1 and Annex A); the categories of Personal Data and Data Subjects and the duration of the Processing (Annex A); the restrictions on engaging Sub-processors and the Institution's right to object (Section 3.5); the confidentiality obligations imposed on personnel and Sub-processors with access to the database (Section 3.3); the documentation and reporting of security incidents (Section 3.7); the Institution's audit and inspection rights (Section 3.8); and the return or deletion of the Personal Data on termination or expiration of the Agreement (Section 3.9).