Data Processing Addendum - PropelAuth

Data Processing Addendum

Effective Date: 2025-11-13

This DATA PROCESSING ADDENDUM (" DPA") forms part of the PropelAuth Terms of Service (the " Agreement") between: (i) PropelAuth, Inc. (" Vendor"), acting on its own behalf; and (ii) Customer (" Customer") acting on its own behalf (Vendor and Customer will together be referred to as the "Parties"). This DPA shall be effective as of the last signature below.

1. Definitions

1.1 In this Addendum, the following terms shall have the meanings set out below:

1.1.1 " Affiliate" means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Vendor.

1.1.2 " CCPA" means the California Consumer Privacy Act of 2018.

1.1.3 " Data Breach" means a breach of security leading to unauthorized processing of Personal Data.

1.1.4 " Data Protection Laws" means all data protection laws applicable to a Party’s Processing of Personal Data.

1.1.5 " Data Subject Request" means a request made by a Data Subject under Data Protection Laws.

1.1.6 " DORA" means Regulation (EU) 2022/2554 on digital operational resilience.

1.1.7 " EU Data Protection Laws" means all data protection laws applicable to Europe.

1.1.8 "Europe" means the EU, the EEA, and their member states, Switzerland, and the UK.

1.1.9 " EU Standard Contractual Clauses" means contractual clauses set out in Regulation (EU) 2016/679.

1.1.10 " Personal Data" means any information that identifies or relates to an identifiable natural person.

1.1.11 " Process" or " Processing" means any operation performed on Personal Data.

1.1.12 " Sensitive Data" means special categories of data under applicable Data Protection Laws.

1.1.13 " Services" means the services provided by Vendor for Customer.

1.1.14 " Subprocessor" means any person appointed by Vendor to assist in providing the Services.

1.1.15 " U.K. GDPR" means the General Data Protection Regulation as applicable in the UK.

1.2 The terms " Commission", " Controller", " Data Subject", " Member State", " Personal Data Breach", and " Supervisory Authority" shall have the same meaning as in the GDPR.

2. Processing of Personal Data

2.1 Roles of the Parties. Customer is the Controller and Vendor is the Processor with respect to the Processing of Personal Data.

2.3 Customer Obligations. Customer represents and warrants that it has complied with all applicable laws regarding its Processing of Personal Data.

2.4 Vendor’s Obligations. Vendor will adhere to Data Protection Laws and process Personal Data only in accordance with Customer’s documented instructions.

3. Subprocessing

3.1 General Authorization. Customer generally authorizes the use of Subprocessors for Processing Personal Data.

3.3 Communication With Subprocessors. Customer shall not communicate directly with Vendor’s Subprocessors.

4. Security

4.1 Security Measures. Vendor shall implement reasonable technical and organizational measures to protect Personal Data.

5. Security Breach

5.1 Notification. Vendor will notify Customer of any Security Breach without undue delay but no later than five (5) business days after becoming aware of it.

6. Termination

6.1 Termination. This DPA shall terminate upon the later of the termination or expiration of the Agreement or Vendor’s deletion or return of the Personal Data to Customer.

7. Data Subject Requests

7.1 Data Subject Requests. Vendor shall not respond to Data Subject Requests directly except as required by Data Protection Laws.

8. Jurisdiction Specific Terms

8.1 The terms of Annex B apply to the Processing of Personal Data subject to GDPR, and the terms of Annex C apply to the Processing of Personal Data subject to CCPA.

9. Limitation of Liability

9.1 Limitation of Liability. Each Party’s liability shall be subject to the limitations set forth in the Agreement.

10. Concluding Provisions

10.1 Amendments. This DPA may not be amended except through a writing duly executed by both Parties.

ANNEX A TO DPA - DESCRIPTION OF THE PROCESSING

1. Subject Matter and Details of the Processing

The Processing under the Agreement involves Vendor’s provision of the Services.

2. Types of Personal Data

Email address and other user properties as defined by the Customer.

3. Categories of Data Subjects

5. Obligations and Rights of the Controller

The obligations and rights of Customer are set out in the Agreement and DPA.