Data Processing Addendum
Our bilateral data protection agreement, governing how we securely handle, protect, and process personal data on your behalf when you use our services.
Which region applies to you?
Select North America (NA) if your company is located in the United States or Canada. Select International (INT) if your company is located anywhere else in the world (such as Europe, UK, APAC, or LATAM).
This Data Processing Addendum ("Addendum" or "DPA") is entered into by and between ThreatModeler Software, Inc. ("ThreatModeler," "we," "us," or "Service Provider") and the entity or individual executing an applicable Order, accessing, registering for, or using ThreatModeler's Products, or identified as the contracting party in an applicable Agreement or Statement of Work ("Company"). This DPA forms an integral part of, and is hereby incorporated by reference into, any governing agreement, Order, or transactional document for ThreatModeler's Products or Services between ThreatModeler and Company (the "Agreement").
BY EXECUTING AN AGREEMENT OR ORDER REFERENCING THIS DPA, OR BY REGISTERING FOR, ACCESSING, OR USING THE PRODUCTS, COMPANY AGREES TO BE BOUND BY THIS DPA.
To the extent any provision in this Addendum conflicts with a provision in the Agreement or any Order concerning the processing of Personal Information, the terms of this Addendum shall prevail and control.
1. DEFINITIONS
Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement. In this Addendum, the following terms shall have the meanings set out below:
- "Applicable US Privacy Laws" means all applicable U.S. federal and state laws and regulations concerning privacy and data protection, including but not limited to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), and any implementing regulations.
- The terms "Business," "Service Provider," "Personal Information," "Processing," "Sell," and "Share" shall have the meanings given to them in the Applicable US Privacy Laws. For the avoidance of doubt, and where applicable under US State Privacy Laws other than the CCPA/CPRA, "Business" shall also mean "Controller" and "Service Provider" shall also mean "Processor".
- "Data Subject" means the identified or identifiable natural person to whom Personal Information relates.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information transmitted, stored or otherwise Processed.
2. PURPOSE AND SCOPE
This Addendum governs the Processing of Personal Information by ThreatModeler as a Service Provider on behalf of Company as necessary to perform the services under the Agreement (the "Services"). The details of the Processing activities are described in Appendix I.
3. COMPLIANCE WITH LAWS
Each party shall comply with its respective obligations under all Applicable US Privacy Laws when Processing Personal Information.
4. THREATMODELER OBLIGATIONS
ThreatModeler, in its capacity as a Service Provider, agrees that it will:
4.1. Process Personal Information only for the limited and specified business purposes described in the Agreement and in accordance with Company’s documented instructions.
4.2. Not Sell or Share Personal Information.
4.3. Not retain, use, or disclose Personal Information for any purpose other than for the specific business purpose of performing the Services, including retaining, using, or disclosing the Personal Information for any commercial purpose other than the business purpose specified in the Agreement.
4.4. Not combine Personal Information received from Company with personal information received from other sources, except as expressly permitted under Applicable US Privacy Laws.
4.5. Ensure that all persons authorized to process the Personal Information are subject to appropriate confidentiality obligations.
4.6. Implement and maintain the reasonable technical and organizational security measures detailed in Appendix II to protect the Personal Information.
4.7. Notify Company if it makes a determination that it can no longer meet its obligations under Applicable US Privacy Laws.
4.8. Upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.
5. COMPANY OBLIGATIONS
Company represents and warrants that it has all necessary rights to provide Personal Information to ThreatModeler for Processing and that its instructions comply with all Applicable US Privacy Laws.
6. DATA SUBJECTS’ RIGHTS
Taking into account the nature of the Processing, ThreatModeler shall assist Company by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Company's obligation to respond to verified requests from Data Subjects exercising their rights under Applicable US Privacy Laws.
7. SUBPROCESSING
7.1. Company provides a general and ongoing authorization for ThreatModeler to engage subprocessors to perform the Services.
7.2. ThreatModeler’s current subprocessor list is maintained at threatmodeler.ai/legal/subprocessors. ThreatModeler may add, remove, or replace subprocessors at any time at its sole discretion, provided that any new subprocessor is bound by written data protection terms no less restrictive than those set forth in this DPA.
7.3. ThreatModeler will update the subprocessor webpage of any changes. Company’s continued use of the Services following any such update shall constitute acceptance of the modified subprocessor list.
8. SECURITY INCIDENT NOTIFICATION
8.1. In the event of a Security Incident, ThreatModeler shall notify the Company without undue delay after becoming aware of the incident, providing sufficient information to allow Company to meet its notification obligations under Applicable US Privacy Laws. ThreatModeler shall provide reasonable cooperation to the Company in the investigation and remediation of the Security Incident.
8.2. Any notifications, security-related reports, or communications from Company to ThreatModeler regarding potential or confirmed security incidents, Personal Data Breaches, or security vulnerabilities must be directed exclusively to security@threatmodeler.com.
9. RETURN OR DELETION OF DATA
Upon termination of the Agreement, ThreatModeler shall, at Company's election, delete or return all Personal Information. Where Personal Information is stored in archival backups, ThreatModeler shall isolate such data from any further processing and ensure its eventual deletion in accordance with its internal retention policies.
10. AUDITS AND ASSESSMENTS
Upon reasonable written request, ThreatModeler shall provide Company with documentation necessary to demonstrate compliance with this Addendum, including summaries of relevant third-party audit reports (e.g., ISO 27001), subject to appropriate confidentiality obligations.
11. GOVERNING LAW AND JURISDICTION
This Addendum shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of law principles. The Parties agree to submit to the exclusive jurisdiction of the state and federal courts located in New Castle County, Delaware for any dispute arising out of this Addendum.
12. LIMITATION OF LIABILITY
Any liability arising under or in connection with this DPA (whether in contract, tort, or otherwise) shall be subject to the limitations and exclusions of liability set forth in the Agreement (including any aggregate caps on liability). For the avoidance of doubt, any reference to the liability of a Party in the Agreement shall include such Party’s liability under this DPA, and all claims brought under this DPA shall be aggregated with, and count towards, the single aggregate liability cap established under the Agreement.
13. ORDER OF PRECEDENCE
In the event of any conflict or inconsistency between the terms of this DPA and the terms of the Agreement (including any Order Forms or Statements of Work), the terms of this DPA shall prevail and control solely to the extent of such conflict or inconsistency as it relates to the Processing of Personal Information.
14. DPA CONTACTS AND NOTICES
14.1. Privacy and Data Protection Inquiries. All inquiries, requests, or formal notices regarding data protection, compliance with Data Protection Laws, or the exercise of Data Subject rights (Section 6) must be directed to ThreatModeler at privacy@threatmodeler.com.
14.2. Security Incidents and Vulnerabilities. All notifications, reports, or communications regarding potential or confirmed Security Incidents, Personal Data Breaches (Section 8), or security vulnerabilities must be directed to ThreatModeler at security@threatmodeler.com.
14.3. Company Contacts. ThreatModeler shall send any notices or communications under this DPA to Company’s primary email address associated with Company’s account or the notice email specified in the most recent Order Form or Agreement.
APPENDIX I
DETAILS OF THE PROCESSING ACTIVITIES
| Category | Details |
| Data Subjects | - Users: Employees, contractors, and other authorized users of the Company who access and use the Services or interact with ThreatModeler personnel during the provision of Professional Services. - Third Parties: Any individuals whose Personal Information is included within content uploaded by Users. |
| Personal Information Categories | - Account & Contact Data: Identifiers (e.g., name, email). - Service Usage & Technical Data: Technical Identifiers (e.g., IP address, device IDs) and Service Activity Data. - Company-Uploaded Content: Any Information that Users choose to include within content they create or upload (e.g., in threat models, reports, or support tickets). |
| Nature & Purpose of Use | Processing is limited to the provision, maintenance, and support of the Services as defined in the Agreement. This includes: - Core Service Delivery: Authenticating users, storing and managing Company content, and enabling platform features. - Support & Maintenance: Diagnosing and resolving technical issues. - Professional Services: Providing consulting or training as agreed in a Statement of Work. - Service Improvement: Analyzing aggregated and anonymized usage data to improve the product. |
APPENDIX II
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
1. Physical Access Controls. ThreatModeler will take reasonable measures to prevent physical access, such as security personnel and secured buildings, to prevent unauthorized persons from gaining access to personal data.
2. System Access Controls. ThreatModeler will take reasonable measures to prevent personal data from being accessed and/or used without authorization. These controls shall vary based on the nature of the processing and will include at minimum authentication via password and/or two-factor authentication, documented authorization processes, documented change management processes, and logging of access of the data.
3. Data Access Controls. ThreatModeler will take reasonable measures to ensure that personal data is only accessible and manageable by properly authorized staff, direct database query access is restricted, and access rights to and within data processing systems are established and enforced to ensure that only authorized persons can access the data processing systems and the data within that they have the authorization to access. Moreover, these controls will be established and enforced to ensure that personal data cannot be read, copied, modified, or removed without authorization in the course of processing.
In addition to Sections 1-3, ThreatModeler warrants it has an implemented access policy which requires that access to its system environment, to personal data, and to other data are limited to authorized personnel only.
4. Transmission Controls. ThreatModeler will take reasonable measures to ensure that it is possible to check and establish to which entities the transfer of personal data by means of data transmission facilities is envisaged so personal data cannot be read, copied, modified, or removed without authorization during electronic transmission or transport. Without limiting the foregoing, ThreatModeler shall ensure personal data is encrypted (at least 256 bit encryption) in transit and storage.
5. Input Controls. ThreatModeler will take reasonable measures to make possible checking and establishing whether and by whom personal data has been entered into data processing systems, modified, or removed. ThreatModeler will take reasonable measures to ensure that the personal data source is under the control of the Company and the personal data integrated into the ThreatModeler’s systems is managed by a secure file transfer from the ThreatModeler and the data subject.
6. Data Backup and Deletion. ThreatModeler will ensure that secured backups are conducted on a regular basis and that personal data is encrypted when stored to protect against accidental destruction or loss when hosted by ThreatModeler. ThreatModeler will ensure that personal data can be permanently and irretrievably deleted in accordance with industry standards, including by wiping or disposing of storage devices.
7. Logical Separation. ThreatModeler will ensure that Company personal data is logically segregated on ThreatModeler’s systems to ensure that personal data that is collected for different purposes will be processed separately.
8. Additional requirements. ThreatModeler will (a) implement detection, prevention, and recovery controls to protect its systems (network, hosting, and application) against malware and other threats to the confidentiality, integrity and availability of personal data, (b) conduct security awareness training to all personnel, and (c) will prohibit and disable the use of non-managed remote devices for storing or carrying, or in use with machines handling personal data Remote devices include without limitation flash drives, CDs, DVDs, external hard drives or other mobile devices.
This Data Processing Addendum ("Addendum" or "DPA") is entered into by and between ThreatModeler Software, S.L. ("ThreatModeler," "we," "us," or "Processor") and the entity or individual executing an applicable Order, accessing, registering for, or using ThreatModeler's Products, or identified as the contracting party in an applicable Agreement or Statement of Work ("Company"). This DPA forms an integral part of, and is hereby incorporated by reference into, any governing agreement, Order, or transactional document for ThreatModeler's Products or Services between ThreatModeler and Company (the "Agreement").
BY EXECUTING AN AGREEMENT OR ORDER REFERENCING THIS DPA, OR BY REGISTERING FOR, ACCESSING, OR USING THE PRODUCTS, COMPANY AGREES TO BE BOUND BY THIS DPA.
To the extent any provision in this Addendum conflicts with a provision in the Agreement or any Order concerning the processing of Personal Data, the terms of this Addendum shall prevail and control.
This Addendum is required insofar as, in the course of providing the Services, ThreatModeler may process two categories of Personal Data: (i) contact details of the Company’s personnel, in respect of which ThreatModeler acts as an independent controller for its own business administration purposes; and (ii) additional Personal Data made available by the Company when receiving support or related services, including but not limited to data relating to end users or employees, in respect of which ThreatModeler acts as a processor on behalf of the Company.
1. DEFINITIONS
Terms used in this DPA shall have the meanings given to them under Regulation (EU) 2016/679 (the General Data Protection Regulation or GDPR), including but not limited to “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Supervisory Authority”.
2. PURPOSE AND SCOPE
This Addendum governs the processing of personal data by ThreatModeler on behalf of Company as necessary to perform the services under the Agreement.
The nature, purpose, and details of the processing activities, including the categories of personal data and data subjects involved, are described in Appendix I.
3. COMPLIANCE WITH LAWS
Each Party shall comply with all applicable laws relating to privacy and data protection, including the EU General Data Protection Regulation (2016/679), the EU Privacy and Electronic Communications Directive (2002/58/EC) as implemented in each jurisdiction, and any amending or replacement legislation as updated or replaced from time to time (collectively and individually, “Data Protection Laws”).
4. PROCESSOR OBLIGATIONS
ThreatModeler, in its capacity as Processor, shall:
4.1. Process Personal Data solely on the documented instructions of the Controller. In the event ThreatModeler is required by law to disclose Personal Data to a public authority, ThreatModeler shall use reasonable efforts to notify the Company in advance, unless legally prohibited from doing so, to allow the Company to seek a protective order or other appropriate remedy;
4.2. Ensure that all persons authorised to process the Personal Data are subject to appropriate confidentiality obligations;
4.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (as further detailed in Appendix II);
4.4. Only engage subprocessors with prior specific or general written authorisation of the Controller, as set out in Section 7;
4.5. Assist the Controller in responding to Data Subject rights requests and in complying with its obligations under Articles 32 to 36 of the GDPR;
4.6. At the choice of the Controller, delete or return all Personal Data at the end of the provision of the Services and delete any existing copies unless Union or Member State law requires retention;
4.7. Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller;
4.8. Ensure that Processing is conducted strictly under the Controller’s instructions; and
4.9. Maintain a record of Processing activities as required under Article 30(2) GDPR.
5. CONTROLLER OBLIGATIONS
Company, in its capacity as Controller, shall:
a) Ensure that it has all necessary rights and lawful bases to provide Personal Data to ThreatModeler for Processing;
b) Implement appropriate technical and organisational measures to ensure and to be able to demonstrate compliance with the GDPR;
c) Make available to Data Subjects, upon request, the essential elements of this DPA;
d) Maintain records of processing activities under its responsibility, where required by law.
6. DATA SUBJECTS’ RIGHTS
Each Party shall, to the extent applicable, assist the other Party in responding to requests from Data Subjects exercising their rights under the GDPR. Requests shall be handled without undue delay and, where feasible, within one month of receipt, in accordance with Articles 12–23 GDPR. Where a request is not fulfilled, the Data Subject shall be informed without delay and provided with the reasons, as well as their right to lodge a complaint.
7. SUBPROCESSING
7.1. Company provides a general written authorization for ThreatModeler to engage subprocessors. ThreatModeler’s current list of authorized subprocessors is available at threatmodeler.ai/legal/subprocessors.
7.2. ThreatModeler shall notify Company of any intended subprocessor changes at least fifteen (15) days in advance by sending an email to Company’s registered notice email address. The current list of subprocessors shall remain available on the webpage referenced in hereby. Company may object to the change in writing within fifteen (15) days of receiving such notice based on reasonable, documented data protection grounds.
8. INTERNATIONAL DATA TRANSFERS
Any transfer of Personal Data to a country outside the European Economic Area (EEA) shall be undertaken in compliance with Chapter V of the GDPR. Where required, such transfers shall be governed by the European Commission’s Standard Contractual Clauses for controller-to-processor transfers, as referenced in Appendix III.
9. SECURITY INCIDENT NOTIFICATION
9.1. In the event of a Personal Data Breach affecting Company Personal Data, ThreatModeler shall notify the Controller without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach. Such notice shall include all relevant information to assist the Controller in meeting its legal obligations.
9.2. Any notifications, security-related reports, or communications from Company to ThreatModeler regarding potential or confirmed security incidents, Personal Data Breaches, or security vulnerabilities must be directed exclusively to security@threatmodeler.com.
10. RETURN OR DELETION OF DATA
Upon expiration or termination of the Agreement, ThreatModeler shall, at Company's written election, return or delete all Personal Data, unless otherwise required by applicable law. Where Personal Data is stored in archival backups, ThreatModeler shall isolate and protect such data from any further processing and shall ensure its eventual deletion in accordance with its internal data retention and destruction policies.
11. AUDITS AND ASSESSMENTS
Upon written request, ThreatModeler shall provide Company with information necessary to demonstrate compliance, including summaries of relevant third-party audit reports (e.g., ISO 27001), subject to confidentiality obligations.
12. GOVERNING LAW AND JURISDICTION
This Addendum and any dispute or claim arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the laws of Spain. Each Party irrevocably agrees that the courts of the city of Madrid, Spain shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Addendum.
13. LIMITATION OF LIABILITY
Any liability arising under or in connection with this DPA (whether in contract, tort, or otherwise) shall be subject to the limitations and exclusions of liability set forth in the Agreement (including any aggregate caps on liability). For the avoidance of doubt, any reference to the liability of a Party in the Agreement shall include such Party’s liability under this DPA, and all claims brought under this DPA shall be aggregated with, and count towards, the single aggregate liability cap established under the Agreement.
14. ORDER OF PRECEDENCE
In the event of any conflict or inconsistency between the terms of this DPA and the terms of the Agreement, the terms of this DPA shall prevail to the extent of such conflict as it relates to the processing of Personal Data. Notwithstanding the foregoing, with respect to any transfers of Personal Data outside the EEA governed by the Standard Contractual Clauses (SCCs), the terms of the SCCs shall take precedence over any conflicting provision in this DPA or the Agreement.
15. DPA CONTACTS AND NOTICES
15.1. Privacy and Data Protection Inquiries. All inquiries, requests, or formal notices regarding data protection, compliance with Data Protection Laws, or the exercise of Data Subject rights (Section 6) must be directed to ThreatModeler at privacy@threatmodeler.com.
15.2. Security Incidents and Vulnerabilities. All notifications, reports, or communications regarding potential or confirmed Security Incidents, Personal Data Breaches (Section 9), or security vulnerabilities must be directed to ThreatModeler at security@threatmodeler.com.
15.3. Company Contacts. ThreatModeler shall send any notices or communications under this DPA to Company’s primary email address associated with Company’s account or the notice email specified in the most recent Order Form or Agreement.
APPENDIX I
DETAILS OF THE PROCESSING ACTIVITIES
| Category | Details |
| Data Subjects | The Personal Data processed will concern the following categories of data subjects: - Users: Employees, contractors, and other authorized users of the Company who access and use the Services. - Third Parties: Any individuals whose Personal Data is included within the content uploaded or generated by the Users within the Services (e.g., within threat models, reports, or support tickets). |
| Personal Data Categories | The Personal Data processed will concern the following categories of data: Account & Contact Data: - Identifiers (e.g., full name, email address, user alias). Service Usage & Technical Data: - Technical Identifiers (e.g., IP address, device identifiers, cookie IDs). - Service Activity Data (e.g., login/logout times, features used, actions taken within the platform, API calls). Company-Uploaded Content: - Content Data: Any Personal Data that Users choose to include within the content they create, upload, or process through the Services. This may include, but is not limited to, data within threat model diagrams, component names, descriptions, mitigation notes, support communications, or data imported from third-party integrations (e.g., Jira, code repositories). |
| Nature & Purpose of Use | The nature and purpose of the Processing are strictly limited to the provision, maintenance, and improvement of the Services as defined in the Agreement. This includes: Core Service Delivery: - Authenticating users and providing access to the platform. - Collecting, storing, displaying, and managing content created and uploaded by users. - Enabling collaboration between users. - Generating reports and analytics based on the Company's data. Support & Maintenance: - Diagnosing and resolving technical issues. - Responding to Company support requests. Professional Services: - Providing consulting, training, implementation, or other expert services as agreed upon in a Statement of Work (SOW) or other relevant part of the Agreement. - Accessing, analyzing, and modifying Company-Uploaded Content as necessary to fulfill the objectives of the agreed-upon Professional Services. Service Improvement: - Monitoring service performance, security, and usage to ensure availability and integrity. - Analyzing aggregated and anonymized usage data to identify trends and improve the product features and user experience. |
APPENDIX II
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
1. Physical Access Controls. ThreatModeler will take reasonable measures to prevent physical access, such as security personnel and secured buildings, to prevent unauthorized persons from gaining access to personal data.
2. System Access Controls. ThreatModeler will take reasonable measures to prevent personal data from being accessed and/or used without authorization. These controls shall vary based on the nature of the processing and will include at minimum authentication via password and/or two-factor authentication, documented authorization processes, documented change management processes, and logging of access of the data.
3. Data Access Controls. ThreatModeler will take reasonable measures to ensure that personal data is only accessible and manageable by properly authorized staff, direct database query access is restricted, and access rights to and within data processing systems are established and enforced to ensure that only authorized persons can access the data processing systems and the data within that they have the authorization to access. Moreover, these controls will be established and enforced to ensure that personal data cannot be read, copied, modified, or removed without authorization in the course of processing.
In addition to Sections 1-3, ThreatModeler warrants it has an implemented access policy which requires that access to its system environment, to personal data, and to other data are limited to authorized personnel only.
4. Transmission Controls. ThreatModeler will take reasonable measures to ensure that it is possible to check and establish to which entities the transfer of personal data by means of data transmission facilities is envisaged so personal data cannot be read, copied, modified, or removed without authorization during electronic transmission or transport. Without limiting the foregoing, ThreatModeler shall ensure personal data is encrypted (at least 256 bit encryption) in transit and storage.
5. Input Controls. ThreatModeler will take reasonable measures to make possible checking and establishing whether and by whom personal data has been entered into data processing systems, modified, or removed. ThreatModeler will take reasonable measures to ensure that the personal data source is under the control of the Company and the personal data integrated into the ThreatModeler’s systems is managed by a secure file transfer from the ThreatModeler and the data subject.
6. Data Backup and Deletion. ThreatModeler will ensure that secured backups are conducted on a regular basis and that personal data is encrypted when stored to protect against accidental destruction or loss when hosted by ThreatModeler. ThreatModeler will ensure that personal data can be permanently and irretrievably deleted in accordance with industry standards, including by wiping or disposing of storage devices.
7. Logical Separation. ThreatModeler will ensure that Company personal data is logically segregated on ThreatModeler’s systems to ensure that personal data that is collected for different purposes will be processed separately.
8. Additional requirements. ThreatModeler will (a) implement detection, prevention, and recovery controls to protect its systems (network, hosting, and application) against malware and other threats to the confidentiality, integrity and availability of personal data, (b) conduct security awareness training to all personnel, and (c) will prohibit and disable the use of non-managed remote devices for storing or carrying, or in use with machines handling personal data Remote devices include without limitation flash drives, CDs, DVDs, external hard drives or other mobile devices.
APPENDIX III
STANDARD CONTRACTUAL CLAUSES
Controller to Processor
For the purposes of transfers of Personal Data from the EEA, the Parties agree that the Standard Contractual Clauses, as approved by European Commission Implementing Decision (EU) 2021/914, are hereby incorporated by reference: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32021D0914
- Module: Module Two (Controller to Processor) will apply.
- Parties: The Company will be the "data exporter" and ThreatModeler will be the "data importer."
- Governing Law & Jurisdiction (for the SCCs): The law and courts of the EU Member State where the data exporter is established will apply.
- Annexes: The information in Appendix I and II of this DPA will serve as the information for the Annexes of the SCCs.
For transfers from the UK or Switzerland, the applicable UK or Swiss addenda are also incorporated by reference.