Skip to content

US Country Addendum

This US Country Addendum (the “US Addendum”) supplements and amends the Fig Platform Customer Subscription Agreement (the “Agreement”) between Fig Technology Limited (the “Supplier” or “Fig”) and the Customer, and applies where the Order Form identifies the Customer as established or primarily operating in the United States, or where the Order Form selects a United States governing law. Where any term of this US Addendum conflicts with the body of the Agreement or any other document, this US Addendum prevails in respect of US-related subject matter. Capitalised terms used and not otherwise defined here have the meanings given in the Agreement.

1. US privacy and data protection

1.1 CCPA/CPRA service-provider terms

Where the Supplier processes “personal information” (as defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act, the “CCPA/CPRA”) on behalf of the Customer, the Supplier acts as a “service provider” and not as a “third party” or as a “contractor” with an independent business purpose. The Supplier shall not: (a) sell or share personal information (as those terms are defined in the CCPA/CPRA); (b) retain, use or disclose personal information for any purpose other than providing the Fig Services as set out in the Agreement and the Documentation, or as otherwise permitted by the CCPA/CPRA; (c) retain, use or disclose personal information outside the direct business relationship between the Supplier and the Customer; or (d) combine personal information received from the Customer with personal information from any other source, except as permitted under 11 CCR § 7050(b). The Supplier shall provide the same level of privacy protection as is required of businesses by the CCPA/CPRA and certifies that it understands and will comply with these restrictions.

1.2 Other state privacy laws

Equivalent service-provider or processor obligations apply, with any necessary changes, in respect of personal data of individuals in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Indiana, Iowa, Montana, New Hampshire, New Jersey, Tennessee and any other US state with a comprehensive consumer privacy law in force during the subscription term.

1.3 HIPAA

Where the Customer is a “covered entity” or “business associate” within the meaning of the Health Insurance Portability and Accountability Act (“HIPAA”) and the Fig Services process or access “protected health information” (PHI), the parties shall, before any PHI is processed through the Fig Services, execute the Supplier’s standard Business Associate Agreement (“BAA”). Absent an executed BAA, the Customer shall not transmit PHI to, or cause PHI to be processed by, the Fig Services.

1.4 GLBA

Where the Customer is a “financial institution” within the meaning of the Gramm-Leach-Bliley Act (“GLBA”) and provides the Supplier with “non-public personal information” (NPI) of consumers, the Supplier shall (a) maintain the confidentiality and security of such NPI in accordance with the GLBA Safeguards Rule (16 CFR Part 314); (b) use NPI solely to perform the Fig Services for the Customer and as permitted by the GLBA; and (c) not disclose NPI to any third party except as required to provide the Fig Services or as required by law.

1.5 Breach notification

In addition to the timelines in the Data Processing Agreement, the Supplier shall notify the Customer of any security incident (including any unauthorised acquisition, access, use or disclosure of personal information) within the timeframes required by applicable US state breach-notification statutes, and in any event without unreasonable delay and no later than 48 hours after becoming aware. The Customer is responsible for onward notification to regulators and affected individuals as required by applicable US law.

2. Insurance

During the subscription term, the Supplier shall maintain, at its own cost, the insurance coverage described in its insurance requirements and, on the Customer’s reasonable written request, shall provide a certificate of insurance evidencing that coverage. Failure to maintain the required insurance is a material breach of the Agreement. The Customer shall maintain insurance reasonably appropriate to its business, including commercial general liability and cyber-liability coverage with limits no less than any amounts agreed in the Order Form.

3. Equitable relief; class action waiver; jury trial waiver

3.1 Equitable relief

Notwithstanding the jurisdiction provisions of the Agreement, each party acknowledges that a breach of the restrictions, ownership or confidentiality provisions of the Agreement may cause irreparable harm for which monetary damages would be an inadequate remedy. The non-breaching party is entitled to seek injunctive or other equitable relief in any court of competent jurisdiction, including a US state or federal court outside the agreed forum, without the requirement to post bond or prove actual damages, in addition to any other rights or remedies it may have.

3.2 Class action waiver

EACH PARTY AGREES THAT ANY DISPUTE-RESOLUTION PROCEEDING WILL BE CONDUCTED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS, CONSOLIDATED OR REPRESENTATIVE ACTION, AND EACH PARTY WAIVES ANY RIGHT TO PARTICIPATE AS A REPRESENTATIVE OR MEMBER OF ANY CLASS OF CLAIMANTS IN RESPECT OF ANY CLAIM ARISING OUT OF OR RELATED TO THE AGREEMENT.

3.3 Jury trial waiver

EACH PARTY WAIVES, TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, ANY RIGHT TO TRIAL BY JURY IN ANY ACTION OR PROCEEDING ARISING OUT OF OR IN CONNECTION WITH THE AGREEMENT.

4. US tax

4.1 Tax forms

The Supplier shall provide the Customer, on request, with a completed IRS Form W-8BEN-E (as a UK entity) certifying entitlement to treaty benefits under the US–UK income tax treaty. Where the Supplier establishes a US branch or US subsidiary that becomes the contracting party, the Supplier shall instead provide IRS Form W-9.

4.2 Withholding

If the Customer is required by US tax law to withhold any amount from a payment to the Supplier, the Customer shall (a) timely remit the withheld amount to the relevant taxing authority; (b) provide the Supplier with reasonable evidence of the withholding; and (c) reasonably co-operate with the Supplier to claim any available treaty benefit, credit or refund.

4.3 Sales and use tax

The Customer is responsible for any US sales, use, communications, gross-receipts or similar indirect taxes attributable to the Fig Services in the relevant US taxing jurisdiction. Where the Supplier is required to collect any such tax, it will add it to the relevant invoice. The Customer may provide a valid exemption certificate where applicable.

5. US sectoral and regulatory considerations

5.1 Financial institutions / NYDFS 23 NYCRR 500

Where the Customer is regulated by the New York Department of Financial Services and subject to 23 NYCRR Part 500, the Supplier shall reasonably co-operate with the Customer’s third-party service-provider due-diligence obligations under § 500.11, including by completing reasonable security questionnaires and providing the Trust Centre materials referenced in the Agreement.

5.2 Federal contractors / CMMC / FedRAMP

The Fig Services are not, as at the start date, FedRAMP-authorised or CMMC-certified. The Customer shall not use the Fig Services to process Controlled Unclassified Information (CUI), Federal Contract Information (FCI) or any other data subject to FedRAMP or CMMC Level 2 or Level 3 requirements without the Supplier’s prior written agreement, evidenced by a separate addendum.

5.3 OFAC / sanctions

Each party represents that it is not (a) located in or organised under the laws of a country subject to comprehensive US sanctions; (b) listed on the OFAC Specially Designated Nationals and Blocked Persons List or other applicable sanctions list; or (c) 50 per cent or more owned, directly or indirectly, by one or more such persons. The Customer shall not use the Fig Services in or for the benefit of any such person or jurisdiction.

5.4 Section 889

Where the Customer is, or expects to become, a US federal contractor or subcontractor subject to Section 889 of the John S. McCain National Defense Authorization Act, the Customer shall notify the Supplier in writing and the parties shall co-operate in good faith to provide any required representations or certifications.

6. US indemnity clarifications

6.1 Supplier IP indemnity (US rights)

The Supplier’s IP indemnity in the Agreement expressly extends to claims that the Customer’s authorised use of the Fig Services infringes a valid and enforceable US patent, US registered copyright, US registered trade mark or US trade secret, subject to the exclusions in the Agreement.

6.2 Defence and co-operation

The Supplier’s obligation to defend includes the obligation to assume the defence with counsel reasonably acceptable to the indemnified party. The indemnified party may, at its own expense, participate in the defence with counsel of its choice.

7. Notices to the Supplier

Legal notices to the Supplier under or in connection with the Agreement shall be sent both to legal@figgroup.co.uk and to the Supplier’s US counsel or registered agent identified in the Order Form (or, if none is identified, to such address as the Supplier notifies the Customer in writing from time to time).

8. Order of precedence

This US Addendum takes precedence over the body of the Agreement and all other documents to the extent of any conflict in respect of US-related subject matter, including governing law, jurisdiction, tax, privacy, insurance and sanctions. In all other respects the Agreement continues in full force and effect.