Opens in a new tab

Effective Date: October 2, 2026 | Version 1.1

This Data Processing Addendum (this ‘DPA’) forms part of, and is incorporated into, the Customer Agreement between Accela, Inc. (‘Accela’) and the Customer identified in the Customer Agreement. This DPA applies to the extent Accela Processes Customer Personal Data on Customer’s behalf in providing the Subscription Services. In the event of a conflict between this DPA and the Customer Agreement with respect to the Processing of Customer Personal Data, this DPA controls; provided that the limitations and exclusions of liability in the Customer Agreement control over this DPA unless and to the extent expressly prohibited by Applicable Data Protection Laws. This DPA controls over the Accela AI Processing Policy in the event of a conflict.

1. Definitions

1.1 AI Features. means any functionality within the Subscription Services that uses machine-learning, large-language-model, generative AI, automated prediction, recommendation, summarization, extraction, or classification capabilities made available by Accela.

1.2 AI Processing Policy. means the Accela AI Processing Policy, the current version of which is available through the Accela Trust Center. Accela may update the AI Processing Policy from time to time consistent with Section 15.1.

1.3 Applicable Data Protection Laws. means the U.S. federal and state privacy, data-protection, data-security, breach-notification, and consumer-privacy laws that apply to a party’s Processing of Customer Personal Data under the Customer Agreement, in each case as amended and in effect from time to time.

1.4 Customer Agreement. means the Subscription Services Agreement (at www.accela.com/terms/) or other written agreement between Accela and Customer under which Customer receives the Accela SaaS.

1.5 Customer Personal Data. means Personal Data contained in Customer Data that Accela Processes on Customer’s behalf to provide the Subscription Services.

1.6 Personal Data. means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, and is intended to encompass ‘personal information,’ ‘personal data,’ and analogous categories under Applicable Data Protection Laws.

1.7 Process or Processing. means any operation performed on Customer Personal Data, including use, structuring, or adaptation.

1.8 Security Incident. means an actual breach of security in Accela’s or its Sub-Processor’s environment that Accela confirms has led to the unauthorized disclosure of, or access to Customer Personal Data, as solely caused by Accela and the Subscription Services. Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including pings, port scans, denial-of-service attempts, malware that is blocked before compromising Customer Personal Data, or failed log-in attempts.

1.9 Sub-Processor. means a third party engaged by Accela to Process Customer Personal Data on Customer’s behalf, including each AI Sub-Processor identified under the Accela AI Processing Policy. Sub-Processors do not include telecommunications carriers, internet service providers, or other providers of network transmission services not selected by Accela to Process Customer Personal Data.

1.10 Other Terms. ‘Customer,’ ‘Customer Data,’ ‘Aggregate Data,’ ‘Subscription Services,’ ‘Authorized Users,’ and other capitalized terms used but not defined in this DPA have the meanings given in the Customer Agreement.

2. Roles and Scope

2.1 Roles. As between the parties, Customer is the controller or business (or acts on behalf of the controller or business) and Accela is the processor, service provider, or contractor with respect to Customer Personal Data Processed to provide the Subscription Services.

2.2 Scope. This DPA applies only to Customer Personal Data that Accela Processes on Customer’s behalf in providing the Subscription Services. This DPA does not apply to information Accela processes as a controller or business for its own lawful purposes, such as account administration, billing, sales operations, product analytics that do not use Customer Personal Data, legal compliance, security, and support contact management.

2.3 Customer Responsibilities. Customer is responsible for the accuracy, quality, legality, and classification of Customer Personal Data, for providing required notices and obtaining required rights, permissions, or consents, and for configuring the Subscription Services in accordance with Customer’s legal and operational requirements.

2.4 Duration. This DPA applies for the term of the Customer Agreement and until Accela completes the return or deletion of Customer Personal Data required by Section 10.

2.5 Details of Processing. The subject matter, duration, nature and purposes of Processing, and the categories of Customer Personal Data and data subjects are described in Annex 1.

3. Processing Instructions and Restrictions

3.1 Documented Instructions. Accela will Process Customer Personal Data only (a) to provide, secure, support, maintain, and improve the Subscription Services in accordance with the Customer Agreement; (b) in accordance with Customer’s documented instructions, including instructions given through Customer’s configuration of the Subscription Services; and (c) as otherwise required by applicable law, in which case Accela will notify Customer unless legally prohibited.

3.2 Purpose Limitation. Accela will not retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties or for any purpose other than the business purposes described in this DPA and the Customer Agreement, except as permitted or required by Applicable Data Protection Laws.

3.3 No Sale or Sharing. Accela will not sell or share Customer Personal Data as those terms are defined under Applicable Data Protection Laws. Accela will not disclose Customer Personal Data to a third party for cross-context behavioral advertising or for the third party’s independent commercial purposes.

3.4 No Prohibited Combination. Accela will not combine Customer Personal Data with personal data Accela receives from, or on behalf of, another customer or other source, except as permitted for processors, service providers, or contractors under Applicable Data Protection Laws, including to provide, secure, maintain, troubleshoot, or improve the Subscription Services.

3.5 AI and Model Training. Accela will not use Customer Personal Data to train, fine-tune, retrain, or improve any general-purpose AI model, any model made available to third parties, or any model used to provide services to another customer. AI Sub-Processors are contractually bound to materially equivalent restrictions. Customer Personal Data Processed through AI Features remains logically segregated from other customers’ data.

3.6 Unlawful Instructions. Accela will notify Customer if Accela determines that a Customer instruction violates Applicable Data Protection Laws. Accela has no obligation to independently monitor the lawfulness of Customer’s instructions.

3.7 Aggregate and De-Identified Data. Nothing in this DPA limits Accela’s rights to create and use Aggregate Data or de-identified data as permitted by the Customer Agreement. Accela will maintain de-identified data in de-identified form, will not attempt to re-identify it except as permitted by Applicable Data Protection Laws to test the effectiveness of de-identification, will implement technical safeguards and business processes designed to prevent re-identification and inadvertent release, and will contractually obligate recipients to materially equivalent commitments.

4. Confidentiality and Personnel

4.1 Confidentiality. Accela ensures that personnel authorized to Process Customer Personal Data are subject to written, statutory, or professional confidentiality obligations and Process Customer Personal Data only on a need-to-know basis to perform their roles.

4.2 Access Controls. Accela maintains role-based access controls, least-privilege practices, and authentication controls for administrative access to production systems containing Customer Personal Data. Accela periodically reviews privileged access and removes access when no longer required.

5. Security

5.1 Safeguards. Accela maintains administrative, physical, and technical safeguards designed to protect the security, confidentiality, availability, and integrity of Customer Personal Data, as summarized in Annex 2 and further described in the Accela Information Security Policy and the Accela Trust Center. Accela will not materially diminish the overall protection of these safeguards during the term of the Customer Agreement.

5.2 Security Program. Accela’s security program includes risk management, vulnerability management, secure software development practices, logging and monitoring, incident response, business continuity and disaster recovery planning, personnel security, vendor security review, and periodic control testing.

5.3 Attestations. Accela maintains a SOC 2 Type II attestation covering the Subscription Services and makes the then-current report available to Customer under Section 9, subject to Accela’s SOC2 NDA confidentiality requirements.

5.4 Customer Controls. Customer is responsible for securely administering its tenant, accounts, credentials, roles, permissions, integrations, endpoints, networks, and configuration choices, and for the actions of its Authorized Users and External Users.

5.5 AI Security Controls. Security controls specific to AI Features are described in the AI Processing Policy. Accela maintains controls designed to restrict prompts, inputs, outputs, logs, and AI-related telemetry from unauthorized access and from use for prohibited model training.

6. Sub-Processors

6.1 General Authorization. Customer provides general authorization for Accela to engage Sub-Processors to Process Customer Personal Data. Accela maintains the current list of Sub-Processors, including AI Sub-Processors, through the Accela Trust Center.

6.2 Infrastructure Providers. Accela’s covered cloud infrastructure providers for the applicable U.S. production environments are Amazon Web Services and Microsoft Azure, except where an Order or mutually agreed addendum states otherwise.

6.3 Notice and Objection. Accela will provide prior notice of any new Sub-Processor as described in the Customer Agreement or the Accela Trust Center. Unless a shorter period is required for security, continuity, legal, or emergency reasons, Accela will provide at least thirty (30) days’ notice before authorizing a new Sub-Processor to Process Customer Personal Data. Customer may object on reasonable, data-protection-related grounds within the notice period. The parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may terminate the affected portion of the Subscription Services and receive a pro-rata refund of prepaid, unused fees as Customer’s sole and exclusive remedy.

6.4 Flow-Down; Responsibility. Accela engages each Sub-Processor under a written agreement imposing data-protection, confidentiality, security, and deletion obligations no less protective in substance than those in this DPA as applicable to the Sub-Processor’s services. Accela remains responsible for each Sub-Processor’s performance of those obligations.

6.5 Foreign Adversary Restrictions. Accela will not knowingly engage any Sub-Processor that is a ‘foreign adversary controlled entity’ within the meaning of the Protecting Americans’ Data from Foreign Adversaries Act, or that would cause a ‘restricted transaction’ or ‘prohibited transaction’ within the meaning of 28 C.F.R. Part 202 (U.S. Department of Justice Bulk Sensitive Personal Data Program), in each case with respect to Customer Personal Data Processed under this DPA.

7. Data Subject Requests and Privacy Assistance

7.1 Assistance. Taking into account the nature of the Processing, Accela provides reasonable assistance to Customer in responding to requests by data subjects to exercise rights under Applicable Data Protection Laws, including through access, export, correction, deletion, and retention capabilities of the Subscription Services.

7.2 Direct Requests. If Accela receives a request directly from a data subject relating to Customer Personal Data, Accela will direct the data subject to Customer and will not otherwise respond except (a) to confirm that the request relates to Customer, (b) as instructed by Customer, or (c) as required by applicable law.

7.3 Assessments and Consultations. Taking into account the nature of the Processing and the information available to Accela, Accela will provide reasonable cooperation reasonably necessary for Customer to complete data-protection assessments, privacy impact assessments, cybersecurity audits, risk assessments, or regulator consultations required by Applicable Data Protection Laws, subject to Section 9 and reasonable confidentiality, security, and scope limitations.

8. Security Incident Notification

8.1 Notice. Accela will notify Customer of a Security Incident affecting Customer Personal Data without undue delay and in any event no later than seventy-two (72) hours after Accela’s confirmation of the Security Incident. ‘Confirmation’ occurs when Accela has determined with a reasonable degree of certainty that a Security Incident has occurred.

8.2 Content. Accela’s notice will describe, to the extent known and legally permitted, the nature of the Security Incident, the categories and approximate volume of Customer Personal Data affected, the likely consequences if known, the measures taken or planned to contain and remediate the Security Incident, and a contact point for follow-up.

8.3 Investigation and Remediation. Accela will take commercially reasonable steps to investigate, contain, and remediate the Security Incident and will provide reasonable status updates as information becomes available. Accela’s notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.

8.4 Customer Notifications. Accela will provide reasonable cooperation to support Customer’s own notification obligations under Applicable Data Protection Laws. Customer is responsible for determining whether and how to notify data subjects, regulators, law enforcement, customers, or other parties, except where Applicable Data Protection Laws impose a direct notification obligation on Accela.

8.5 Responsibility. Accela is responsible for a Security Incident only to the extent it results from Accela’s or its Sub-Processor’s failure to comply with this DPA. Accela is not responsible for any incident to the extent caused by Customer, Customer’s Authorized Users or External Users, Customer’s systems, Customer’s integrations, Customer’s configuration choices, or other causes outside Accela’s reasonable control. For the avoidance of doubt, Accela’s notification obligation under Section 8.1 applies to Security Incidents in Accela’s or its Sub-Processor’s environment regardless of cause.

9. Audits and Documentation

9.1 Standard Means. Accela makes available, upon reasonable request and subject to confidentiality requirements, documentation reasonably necessary to demonstrate compliance with this DPA, including Accela’s then-current SOC 2 Type II report, security summaries, relevant Trust Center materials, and responses to reasonable security questionnaires.

9.2 Supplemental Review. Notwithstanding anything to the contrary, the parties acknowledge and agree that the materials described in Section 9.1 fully satisfy Customer’s audit and information rights except where Applicable Data Protection Laws mandate more. Where more is legally mandated, Customer may request a summary review limited to the legally required scope, conducted during normal business hours, no more than once annually unless required by a regulator or following a confirmed Security Incident, and in a manner that does not, in Accela’s sole discretion, compromise Accela’s security, confidentiality obligations, or other customers’ information.

9.3 Third-Party Audits. If a regulator, independent auditor, or other third party requires information relating to Accela’s Processing of Customer Personal Data, Accela will reasonably cooperate through written responses and production of existing documentation. On-site audits require reasonable advance notice, mutually agreed scope and timing, and appropriate confidentiality and security controls.

10. Deletion and Return

10.1 Return or Deletion. On termination of the Customer Agreement or on Customer’s earlier written request, Accela will return or delete Customer Personal Data in accordance with the Customer Agreement and the functionality of the Subscription Services. Accela will also instruct Sub-Processors to delete Customer Personal Data in accordance with their applicable obligations.

10.2 Backups, Logs, and Retained Copies. Customer Personal Data contained in backups, logs, caches, or other system-retained copies will be overwritten, aged out, or deleted in accordance with Accela’s standard retention and backup-rotation schedules. Until deletion occurs, retained Customer Personal Data remains subject to the confidentiality, security, and use restrictions of this DPA.

10.3 Legal Retention. Accela and its Sub-Processors may retain Customer Personal Data to the extent and for so long as retention is required by applicable law or regulation, valid legal process, litigation hold, audit requirement, security investigation, or other lawful basis. Any Customer Personal Data so retained will not be Processed for any other purpose and will be deleted within thirty (30) days after the legal basis for retention expires, unless a longer period is required by law.

11. Data Residency, Government Access, and Legal Requests

11.1 U.S. Data Residency. Where Customer purchases or is assigned a U.S. data-residency hosting environment, Accela will store Customer Personal Data at rest in the United States and Process Customer Personal Data in accordance with the Data Sovereignty and Localization commitments described in the Accela AI Processing Policy and Trust Center materials. Accela will not materially change the data-residency commitment for the affected environment without prior notice to Customer.

11.2 Law Enforcement and Government Requests. Accela will not voluntarily disclose Customer Personal Data to law enforcement, national-security authorities, or other governmental authorities except with Customer’s written instruction or as required by applicable law. If Accela receives legal process or a government request for Customer Personal Data, Accela will, unless legally prohibited, promptly notify Customer, direct the requesting authority to Customer where appropriate, disclose only the minimum Customer Personal Data legally required, and use reasonable efforts to challenge or narrow requests that Accela reasonably believes are overbroad, unlawful, or inconsistent with applicable law.

11.3 Transparency. Upon Customer’s reasonable request and where legally permitted, Accela will provide information about the nature of legal requests received for Customer Personal Data. Accela will not provide Customer with information that would violate applicable law, court order, or confidentiality obligations owed to a governmental authority.

12. Government Customers

12.1 Additional Terms. Where Customer is a U.S. federal, state, local, tribal, or territorial government entity, or is acting on behalf of such an entity, the additional provisions of Annex 4 apply.

13. AI Processing

13.1 AI Policy. Accela’s Processing of Customer Data through AI Features is further described in the AI Processing Policy, which supplements this DPA. In the event of a conflict between this DPA and the AI Processing Policy, this DPA controls.

13.2 Customer Configuration. Customer controls whether and how Customer or its users use available AI Features, subject to the functionality and configuration options made available in the Subscription Services and any applicable Order. Customer is responsible for reviewing AI outputs before relying on them for legal, permitting, licensing, enforcement, eligibility, or other decisions affecting individuals.

14. Liability

14.1 Liability Cap. Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Customer Agreement, and liability under this DPA and the Customer Agreement together counts toward the same aggregate cap, except to the extent Applicable Data Protection Laws prohibit such limitation.

14.2 No Third-Party Beneficiaries. This DPA does not create any third-party beneficiary rights, including for data subjects, consumers, residents, applicants, permittees, licensees, or other individuals.

15. General

15.1 Updates. Accela may update Annex 2, the AI Processing Policy, Trust Center materials, and the Sub-Processor list from time to time, provided the overall protection of Customer Personal Data is not materially diminished. Accela may amend this DPA as required by changes in Applicable Data Protection Laws by providing Customer prior written notice. If Customer does not agree to a legally required amendment, Customer’s sole and exclusive remedy is to terminate the affected portion of the Subscription Services and receive a pro-rata refund of prepaid, unused fees.

15.2 Counterparts; Electronic Signature. This DPA may be executed in counterparts and by electronic signature, each of which is deemed an original.

15.3 Severability; Governing Law. If any provision of this DPA is held unenforceable, the remainder remains in effect. This DPA is governed by the law governing the Customer Agreement.

15.4 Order of Precedence. If there is an inconsistency among the documents, the order of precedence for matters involving Processing of Customer Personal Data is: (1) this DPA; (2) the applicable Order, but only to the extent it expressly states that it overrides this DPA; (3) the Customer Agreement; and (4) the AI Processing Policy and Trust Center materials.

Annex 1 – Details of Processing

A1.1 Subject Matter and Duration. Processing of Customer Personal Data to provide the Subscription Services for the term of the Customer Agreement plus the deletion period described in Section 10.

A1.2 Nature and Purposes. Hosting, storage, computation, display, transmission, support, maintenance, security, authentication, authorization, logging, monitoring, troubleshooting, backup, disaster recovery, AI Features as described in the AI Processing Policy, and related Processing necessary to provide, secure, support, maintain, and improve the Subscription Services.

A1.3 Categories of Data Subjects. Customer’s Authorized Users; External Users such as residents, applicants, permittees, licensees, property owners, contractors, inspectors, and other individuals submitting requests to or interacting with Customer; and other natural persons whose information Customer or its users enter into the Subscription Services.

A1.4 Categories of Customer Personal Data. As determined and entered by Customer and its users, Customer Personal Data may include name and contact details; account credentials and identifiers; government-service application, permit, license, inspection, land-management, planning, payment, and code-enforcement records; property, parcel, location, and address information; documents, forms, notes, communications, attachments, metadata, and audit logs; and other information Customer elects to submit to the Subscription Services.

A1.5 Sensitive Data. The Subscription Services are not configured by default to require sensitive categories of Personal Data such as health information, biometric information, Social Security numbers, driver’s license numbers, passport numbers, criminal justice information, federal tax information, or protected health information. Customer controls whether sensitive Personal Data is entered. Where a Customer-specific deployment is intended to Process sensitive categories, the parties will document corresponding controls, restrictions, and required addenda in the applicable Order or separate addendum.

A1.6 Frequency of Processing. Continuous for the duration of Customer’s use of the Subscription Services, subject to Customer’s configuration, use, and support requests.

Annex 2 – Security Measures (Summary)

Accela maintains the following measures, as further described in the Accela Information Security Policy, the Customer Agreement, and the Accela Trust Center. These measures are designed to provide a level of security appropriate to the risk presented by the Processing and the nature of Customer Personal Data.

A2.1 Governance and Risk Management. Written information-security policies; assigned security responsibilities; risk assessment and treatment processes; security awareness training; personnel onboarding and offboarding controls; and periodic review of security controls.

A2.2 Access Management. Role-based access controls; least-privilege access; multi-factor authentication for administrative access; privileged access management; periodic access review; secure credential management; and separation of duties where appropriate.

A2.3 Encryption and Key Management. Encryption of Customer Data in transit and at rest using industry-standard protocols and algorithms; key-management practices designed to protect encryption keys; and controls restricting administrative access to keys and secrets.

A2.4 Secure Development and Vulnerability Management. Secure software development practices; code review; application-security testing; vulnerability scanning; risk-based remediation; dependency management; change-management controls; and production deployment controls.

A2.5 Logging, Monitoring, and Detection. System logging; security monitoring; alerting; endpoint detection and response; threat-detection processes; data loss prevention controls where appropriate; and investigation procedures for suspicious activity.

A2.6 Incident Response. A written incident response plan; triage and escalation procedures; incident containment and remediation processes; periodic testing or tabletop exercises; and post-incident review practices.

A2.7 Business Continuity and Disaster Recovery. Backup and recovery processes; disaster-recovery planning; business-continuity planning; periodic backup testing; and recovery procedures designed to maintain availability of the Subscription Services.

A2.8 Vendor and Sub-Processor Security. Security review of Sub-Processors; written Sub-Processor commitments; periodic review of material Sub-Processors; and contract requirements addressing confidentiality, security, use restrictions, incident notification, and deletion.

A2.9 AI-Specific Controls. Controls specific to AI Features are described in the AI Processing Policy, including restrictions on model training, logical segregation of Customer Personal Data, AI Sub-Processor controls, and controls for prompts, outputs, and AI-related logs.

A2.10 Attestation. A SOC 2 Type II attestation covering the Subscription Services, made available under Section 9 subject to reasonable confidentiality requirements.

Annex 3 – Service Provider and Processor Provisions

This Annex applies to the extent Customer is subject to any Applicable Data Protection Law that imposes service-provider, contractor, or processor obligations on Accela with respect to Customer Personal Data Processed under this DPA.

A3.1 Service Provider / Contractor / Processor Status. Accela acts as a service provider, contractor, or processor and Processes Customer Personal Data only for the business purposes described in this DPA and the Customer Agreement. Accela certifies that it understands and will comply with the restrictions in this Annex and Section 3.

A3.2 Required Restrictions. Accela will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Customer Agreement; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with personal data from other sources except as permitted under Applicable Data Protection Laws.

A3.3 Same Level of Privacy Protection. Accela will provide the level of privacy protection required of processors, service providers, or contractors under Applicable Data Protection Laws applicable to Accela’s Processing of Customer Personal Data.

A3.4 Compliance Notice. Accela will notify Customer if Accela determines it can no longer meet its obligations under this DPA or Applicable Data Protection Laws applicable to Accela’s Processing of Customer Personal Data.

A3.5 Remediation. Upon notice under A3.4, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, including suspending the affected Processing, consistent with the Customer Agreement and Section 9.

A3.6 Monitoring. Customer may take reasonable steps, consistent with Section 9, to ensure Accela’s use of Customer Personal Data is consistent with Customer’s obligations under Applicable Data Protection Laws.

A3.7 Subcontracting. Accela may engage Sub-Processors as described in Section 6. Accela will require Sub-Processors to comply with written obligations that protect Customer Personal Data to a level no less protective in substance than this DPA, as applicable to the nature of the Sub-Processor’s Processing.

A3.8 Assistance with Audits and Risk Assessments. To the extent required by Applicable Data Protection Laws, Accela will reasonably cooperate with Customer’s cybersecurity audits, risk assessments, privacy assessments, and related compliance obligations concerning Customer Personal Data collected pursuant to this DPA, subject to Section 9 and reasonable confidentiality, security, and scope limitations.

Annex 4 – U.S. Government Customer Provisions

This Annex applies where Customer is a U.S. federal, state, local, tribal, or territorial government entity, or is acting on behalf of such an entity.

A4.1 Data Residency. Customer Personal Data in U.S. government hosting regions is stored at rest in the United States and Processed consistent with the Data Sovereignty and Localization commitments in the Accela AI Processing Policy and Trust Center materials. Accela uses commercially reasonable controls designed to prevent migration of Customer Personal Data from the applicable U.S. hosting environment except as authorized by Customer, required by law, or required for security, support, continuity, or disaster-recovery activities consistent with this DPA.

A4.2 GovRAMP. AI Features and the Subscription Services are configured to support GovRAMP Progressing-level controls consistent with the GovRAMP Progressing status of the underlying Accela hosting environment for that customer, unless the applicable Order states a different authorized environment or compliance commitment.

A4.3 Criminal Justice Information. Where Customer Data includes criminal justice information subject to the FBI CJIS Security Policy, the parties will execute the applicable CJIS addendum and Accela will comply with the personnel-screening and control requirements specified in that addendum. The applicable CJIS addendum will be the form mutually agreed to in writing by the parties.

A4.4 Public Records Laws. Customer’s obligations under freedom-of-information, public-records, open-records, sunshine, and retention laws are Customer’s responsibility. If Accela receives a public-records request directed to Customer Personal Data, Accela will promptly notify Customer unless legally prohibited and will reasonably cooperate at Customer’s expense.

A4.5 Regulated Data Sets. Additional regulatory flow-downs, including IRS Publication 1075 for federal tax information, HIPAA for protected health information, PCI DSS for cardholder data, FERPA for education records, or state-specific justice, tax, health, or benefits-program requirements, apply only where expressly agreed in the Customer Agreement, an Order, or a separate written addendum. HIPAA obligations require a separate Business Associate Agreement.

A4.6 Law Enforcement Requests. For government Customers, Accela will apply Section 11.3 to subpoenas, warrants, court orders, national-security requests, law-enforcement requests, and other compulsory legal process seeking Customer Personal Data. Customer remains responsible for responding to requests directed to Customer or to records in Customer’s possession, custody, or control.

A4.7 Customer-Specific Flow-Downs. Any customer-specific, grant-specific, or procurement-specific data-protection requirements apply only to the extent expressly incorporated into the Customer Agreement, an Order, or a mutually executed addendum that identifies the requirement and the affected Subscription Services.