Data Processing Agreement
Data Processing Agreement
Last updated August 05, 2026
DATA PROCESSING ADDENDUM
Last updated: August 2026
This Data Processing Addendum (this “DPA”) forms part of and is subject to the terms and conditions of the Service Agreement (as defined below) by and between the entity identified as the Customer under the Service Agreement and Traact, Inc. (“Vendor”). Customer and Vendor may be referred to herein together as the “Parties”, and each may be referred to herein as a “Party”. This DPA is hereby incorporated into, and subject to, the terms of the Service Agreement. In the event of a conflict between the terms of this DPA and the terms of the Service Agreement, the terms of this DPA shall control. For good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, Customer and Vendor hereby agree as follows:
1. Definitions
“Applicable Laws” means, collectively, all now existing or hereinafter enacted or amended laws, rules, regulations, and/or sanctions programs applicable to a Party’s performance hereunder and/or obligations with respect to data protection, including but not limited to CCPA, European Data Protection Law, and PIPEDA.
“CCPA” means the California Consumer Privacy Act of 2018 (Title 1.81.5 of the Civil Code of the State of California), as amended by the California Privacy Rights Act of 2020 (CPRA), together with all effective regulations adopted thereunder (in each case, as amended from time to time).
“Customer Data” means all information, data, content and other materials, in any form or medium, that is submitted, posted, collected, transmitted or otherwise provided by or on behalf of Customer through the Services.
“Customer Personal Data” means Customer Data that is Personal Data processed by Vendor on behalf of Customer in the provision of the Services under the Service Agreement.
“Controller” means (i) under and in the context of European Data Protection Law, the data “controller” (as defined by GDPR), (ii) under and in the context of CCPA, the “business” or “third party” (each, as defined by CCPA), and (iii) under and in the context of any other privacy or data protection law, rule, or regulation applicable to a Party’s performance hereunder, a “controller”, “business”, or corresponding term denoting a substantially similar definition, role, and obligations under such law, rule or regulation.
“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (and each successor regulation, directive or other text of the foregoing, in each case as amended from time to time).
“European Data Protection Law” means each of EU GDPR, UK GDPR, and the Federal Data Protection Act of 19 June 1992 (Switzerland) (as the same may be superseded by the Swiss Data Protection Act 2020 and as amended from time to time).
“GDPR” means, as applicable, (i) the EU GDPR and/or (ii) the UK GDPR.
“Personal Data” means any information that constitutes “personal information,” “personal data,” and/or other term denoting a substantially similar definition and obligations under, and in the context of, any Applicable Laws.
“PIPEDA” means Canada’s Federal Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (as amended from time to time).
“Process” means any operation or set of computer operations performed on Personal Data, including, but not limited to, collection, recording, organization, structuring, storage, access, adaptation, alteration, retrieval, consultation, use, transfer, transmit, sale, rental, disclosure, dissemination, making available, alignment, combination, deletion, erasure, or destruction.
“Processor” means (i) under and in the context of European Data Protection Law, the data “processor” (as defined by GDPR), (ii) under and in the context of CCPA, a “service provider” (as defined by CCPA), and (iii) under and in the context of any other privacy or data protection law, rule, or regulation applicable to a Party’s performance hereunder, a “processor”, “service provider”, or corresponding term denoting a substantially similar definition, role, and obligations under such law, rule or regulation.
“Security Incident” means (i) any accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to, Customer Personal Data or (ii) any other event that constitutes a “security breach”, “personal data breach”, or substantially similar term with respect to Customer Personal Data under Applicable Laws.
“Service Agreement” means, collectively, the agreements and/or terms of service (including, as applicable, each of the Statements of Work/SOWs/Orders/Order Forms and exhibits thereunder) between Customer and Vendor. “Services” means, collectively, the products and/or services provided by Vendor to Customer under the Service Agreement.
“Sub-Processor” means a contractor, subcontractor, consultant, third-party service provider, or agent engaged by Vendor for further Processing of Customer Personal Data.
“UK GDPR” has the meaning ascribed thereto in section 3(10) (as supplemented by section 205(4)) of the UK Data Protection Act 2018 (as amended from time to time).
2. Data Processing Obligations
2.1 General
Each Party shall comply with its obligations relating to Personal Data under this DPA and under Applicable Laws at its own cost. With respect to Customer Personal Data, (i) Customer is a Controller and (ii) Vendor is a Processor that Processes Customer Personal Data only upon the instructions of Customer, including, without limitation, in accordance with the applicable Service Agreement, this DPA, and any other documented instructions provided by Customer. Notwithstanding the foregoing, Vendor may Process Customer Personal Data as required by Applicable Laws. Vendor shall immediately inform Customer if, in the Vendor’s opinion, an instruction of Customer infringes Applicable Laws. Schedule I sets forth specific details regarding Vendor’s processing of Customer Personal Data.
Vendor shall Process Customer Personal Data only on behalf of and for the benefit of Customer, for the purposes of Processing Customer Personal Data in connection with the Agreement, and to carry out its obligations pursuant to this DPA, the Service Agreement and Customer’s written instructions.
Vendor and its employees and contractors shall hold in strict confidence (i) the existence and terms of this DPA, and any related agreement, and (ii) any and all Customer Personal Data.
With regard to Vendor employees and contractors engaged in Processing Customer Personal Data, Vendor shall ensure that such employees and contractors are informed of the confidential nature of the Customer Personal Data. . Vendor shall use commercially reasonable methods to limit access to Customer Personal Data to its employees and contractors who have a need to know the Customer Personal Data as a condition to Vendor’s performance of its obligations under the Service Agreement for or on behalf of Customer and who have explicitly agreed to comply with legally enforceable confidentiality and security obligations that are substantially similar to those required by this DPA. Vendor shall exercise the necessary and appropriate supervision over its employees and contractors to maintain appropriate privacy, confidentiality, and security of Customer Personal Data in accordance with this DPA. Vendor shall provide training, as appropriate, regarding the requirements set forth in this DPA to those employees and contractors who have access to Customer Personal Data.
Customer will have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer obtains the Customer Personal Data, including, without limitation, obtaining appropriate consent to collect the Customer Personal Data and share such data with Vendor in accordance with Applicable Laws.
2.2 Standard Contractual Clauses
If Vendor Processes Customer Personal Data relating to an EEA, United Kingdom, or Switzerland data subject (including, without limitation, the transfer of such Customer Personal Data from the EEA, United Kingdom, or Switzerland to a third country not providing an adequate level of protection) outside of the EEA, United Kingdom, and Switzerland, the Processing will be further governed by Schedule II to this DPA (together with all Appendices and Annexes thereto, and as the same may be amended, supplemented, or otherwise modified from time to time, the “Personal Data SCCs”), which is incorporated by reference into this DPA solely with respect to Customer Personal Data relating to EEA, United Kingdom and/or Switzerland data subjects. If there is any conflict between (x) the terms and conditions of either this DPA or the Service Agreement, on the one hand, and (y) the terms and conditions of the Personal Data SCCs, on the other hand, then, with respect to Customer Personal Data relating to an EEA, United Kingdom and/or Switzerland data subject(s), the terms and conditions of the Personal Data SCCs will prevail and control. Vendor may only transfer Customer Personal Data relating to an EEA, United Kingdom, or Switzerland data subject outside the EEA, United Kingdom, and Switzerland in compliance with Applicable Laws and the Personal Data SCCs.
For the avoidance of doubt, Vendor shall not transfer Customer Personal Data outside the country in which the Customer Personal Data was originally provided to Vendor for Processing, (or, if it was originally delivered to a location inside the EEA or Switzerland, outside the EEA or Switzerland) without the consent of Customer Vendor processes data in the United States, and therefore, Customer consents to the transfer of Customer Personal Data to and from the U.S. for processing by providing the Customer Personal Data.
Where Vendor, with the consent of Customer, provides to a third-party access to Customer Personal Data received by Customer from the EEA or Switzerland, Vendor will enter into any written agreements as are necessary to comply with Applicable Laws concerning any cross-border transfer of Customer Personal Data, whether to or from Vendor.
2.3 CCPA
With respect to Customer Personal Data relating to a California “consumer” or “household” (each as defined by CCPA) (“CCPA Personal Data”):
Customer will be disclosing such CCPA Personal Data under the Service Agreement to Vendor for a “business purpose” (as defined by CCPA), and Vendor shall Process such CCPA Personal Data solely on behalf of Customer and only as necessary to perform such business purpose for Customer; and
Except as expressly permitted by the CCPA or its regulations, Vendor shall not: (i) “sell” or “share” (as each term is defined by the CCPA) CCPA Personal Data; (ii) retain, use, or disclose CCPA Personal Data (x) for any purpose (including a “commercial purpose” (as defined by CCPA)) other than for the business purpose(s) identified above, or (y) outside of the direct business relationship between Vendor and Customer; or (iii) combine the Customer Personal Data with Personal Data that Vendor collects or receives from another source (except in the performance of any “business purpose”).
2.4 Changes in Applicable Laws
At the time Vendor has entered into this Agreement, Vendor is not aware of any Applicable Law, or privacy or information security enforcement action, investigation, litigation or claim which prohibits Vendor from (i) fulfilling its obligations under this DPA or (ii) complying with instructions it receives from Customer concerning Customer Personal Data.If, due to any change in Applicable Laws, a Party reasonably believes that Vendor ceases to be able to provide the Services in whole or in part (e.g., with respect to a particular jurisdiction) and/or Customer ceases to be able to use the Services in whole or in part under the then-current terms and conditions of the Service Agreement and this DPA, either Party shall promptly notify the other in writing, and subsequently may terminate the Service Agreement (in whole or, if reasonably practicable, in part) in its sole discretion and without penalty of any kind .
3. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Vendor will implement and maintain appropriate technical and organizational measures to ensure a level of security for the Customer Personal Data appropriate to the risks. In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored or otherwise processed. Such measures will include reasonable administrative, physical, and technical security controls (including those required by Applicable Laws) that prevent the collection, use, disclosure, or access to Customer Personal Data that the Service Agreement does not expressly authorize, including maintaining a comprehensive information security program that safeguards Customer Personal Data. These security measures include the measures set forth in Schedule III.
If the Processing by Vendor or its employees or contractors involves the transmission of the Customer Personal Data over a network, Vendor shall implement commercially reasonable measures designed to protect the Customer Personal Data against the specific risks associated with such transmission.
If Vendor shall perform services in compliance with the Payment Card Industry Data Security Standard (“PCI DSS”), then Vendor hereby acknowledges its responsibility for the security of any Cardholder Data (as such term is defined in the PCI DSS) which it stores, transmits, or processes in connection with the Service Agreement. Vendor shall perform any and all tasks, assessments, reviews, penetration tests, scans and other activities required under the PCI DSS for merchants in the same merchant category as Customer (including any compliance guidance issued by the PCI Data Security Council or its subordinate bodies) or otherwise to validate during the term of the Service Agreement its compliance with the PCI DSS as it relates to the system elements and portions of the cardholder data environment (as such terms are defined in the PCI DSS) for which Vendor is responsible. Upon Customer’s request, Vendor shall deliver to Customer copies of all documentation necessary to verify such compliance, including without limitation, any attestation of compliance, report on compliance, self-assessment questionnaire, or testing or assessment results.
4. Supplementary Measures and Safeguards
4.1 Assistance
Vendor shall assist Customer to ensure compliance with Applicable Laws in connection with the Processing of Customer Personal Data.
4.2 Law Enforcement and Administrative Requests for Information
Vendor shall notify Customer immediately in writing of any subpoena or other judicial or administrative order by a government authority or proceeding seeking access to or disclosure of Customer Personal Data. Customer shall have the right to defend such action in lieu of and/or on behalf of Vendor. Customer may, if it so chooses, seek a protective order. Vendor shall reasonably cooperate with Customer in such defense.
4.3 Data Protection Impact Assessments for Sub-Processors in Accordance with Applicable Laws.
Vendor has conducted and maintains a Data Protection Impact Assessment (DPIA) with respect to its use of OpenAI, L.L.C. as a Sub-Processor for AI-assisted contract processing, in accordance with Applicable Laws. In conducting and updating its DPIA, Vendor relies in part on OpenAI's enterprise-grade data processing agreements and compliance documentation as evidence of appropriate safeguards at the sub-processor level. Vendor will make its DPIA available to Customer upon written request, subject to a Non-Disclosure Agreement. Vendor shall update the DPIA upon any material change to the relevant processing.
Vendor will continue to conduct and maintain DPIAs required by Applicable Laws if additional Sub-Processors that use AI-assisted processing are procured.
5. Notifications
5.1 Security Incidents
Vendor will provide Customer with written notice without undue delay, and in any event within seventy-two (72) hours, after discovering a Security Incident (including those affecting Vendor or its Sub-Processors), including any known information that Customer is required by Applicable Laws to provide to an applicable regulatory agency or to the individuals whose Personal Data was involved in the Security Incident. Vendor shall provide prompt and regular updated written notifications to Customer as Vendor’s understanding of the scope and impact of the Security Incident changes, evolves, and/or develops. Vendor shall cooperate with Customer to meet any notification obligations to individuals or regulatory authorities imposed by Applicable Laws, including providing all necessary information within the timeframes required by such laws.
For the avoidance of doubt, notification to Customer shall include all available information regarding such Security Incident, including information on: (i) the nature of the Security Incident including where possible, the categories and approximate number of affected individuals and the categories and approximate number of affected Customer Personal Data records; (ii) the likely consequences of the Security Incident; and (iii) the measures taken or proposed to be taken to address the Security Incident, including, where appropriate, measures to mitigate its possible adverse effects. Vendor shall promptly take all necessary and advisable corrective actions and shall cooperate fully with Customer in all reasonable and lawful efforts to prevent, mitigate, or rectify such Security Incident. Vendor shall (i) investigate such Security Incident and perform a root cause analysis thereon; (ii) remediate the effects of such Security Incident; and (iii) provide Customer with such reasonable assurances that such Security Incident is not likely to recur. Vendor shall provide such assistance as required to enable Customer to Customer’s obligations under Privacy Laws. Customer shall have the right at any time after learning of a Security Incident to engage and involve external forensic firms in the investigation of the Security Incident at its own expense (which will include a right to investigate Vendor systems), and Vendor shall comply with all reasonable requests of such external forensic firm. Vendor shall use commercially reasonable efforts to preserve all applicable evidence relating to the Security Incident until Customer has completed a forensic investigation or confirmed to Vendor that it waives its right to conduct such an investigation.
5.2 Data Subject Requests
Vendor shall (i) no later than five days after receipt of such request, notify Customer about any request under Applicable Law(s) with respect to Customer Personal Data received from or on behalf of the applicable data subject, and (ii) cooperate as required by Applicable Law(s) with Customer’s reasonable requests in connection with data subject requests with respect to Customer Personal Data. Vendor shall assist Customer, through appropriate technical and organizational measures, to fulfill its obligations with respect to requests of data subjects seeking to exercise rights under Applicable Law with respect to Customer Personal Data.
6. Sub-Processors
Vendor shall not have Customer Personal Data Processed by a Sub-Processor unless such Sub-Processor is bound by a written agreement with Vendor that includes data protection obligations at least as protective as those contained in this DPA and the Service Agreement and that meet the requirements of Applicable Laws. Vendor is and shall remain fully liable to Customer for any failure by any Sub-Processor to fulfill Vendor’s data protection obligations under Applicable Laws.
Vendor’s list of all Sub-Processors who access Customer Personal Data is available at Annex III to Exhibit A of Schedule II (the “Sub-Processor List”). Customer authorizes and instructs Vendor to engage the Sub-Processors listed in the Sub-Processor List. Vendor will notify Customer of any changes to the Sub-Processors listed on the Sub-Processor List and grant Customer the opportunity to object to such change. Upon Customer’s request, Vendor will provide all information necessary to demonstrate that the Sub-Processors will meet all requirements set forth in this Section 6. If Customer reasonably objects to any Sub-Processor on data protection grounds, Vendor may choose either not to engage the Sub-Processor or, if engagement is unavoidable, Customer may terminate the affected portion of the Services without penalty upon thirty (30) days’ prior written notice.
For the avoidance of doubt, Vendor shall not share, transfer, disclose or otherwise provide access to any Customer Personal Data to any third party, or contract any of its rights or obligations concerning Customer Personal Data to a third party, except a Sub-Processor, unless Customer has authorized Vendor to do so in writing, which may be in the applicable SOW, except as required by law. Where Vendor, with the consent of Customer, provides to a third-party access to Customer Personal, or contracts such rights or obligations to a third party, Vendor shall enter into a written agreement with each third party that imposes obligations on the third party that are substantially the same as those imposed on Vendor under this DPA.
7. Deletion
Vendor shall, at the choice of Customer: (i) delete or return all Customer Data to Customer after such Customer Data is no longer necessary for the provision of the Services, and (ii) delete existing copies of such Customer Data. Such deletion or return shall be completed within a reasonable period and, except where prohibited by Applicable Laws, not later than ninety (90) days following the request. Backup copies will be deleted in accordance with Vendor’s documented data retention and disposal policy.
8. Documentation; Audit
Vendor shall, upon Customer’s request, provide Customer (a) comprehensive documentation of Vendor’s technical and organizational security measures, (b) any and all third-party audits and certifications available with respect to such security measures, including Vendor’s SOC 2 Type II report, and (c) all other information reasonably necessary to demonstrate compliance with Vendor’s obligations under this DPA and/or under Applicable Laws. Where (a) – (c) of this section are not sufficient for compliance with Applicable Laws, then upon reasonable notice and appropriate confidentiality agreements, Vendor shall cooperate with assessments, audits, or other steps performed by or on behalf of Customer at Customer’s sole expense and in a manner that is minimally disruptive to Vendor’s business that are necessary to confirm that Vendor is processing Customer Personal Data in a manner consistent with this DPA.
9. Term; Termination
This DPA shall remain in effect until (a) the Service Agreement has terminated and (b) all obligations that Vendor has under the Service Agreement and under Applicable Laws with respect to Customer Personal Data, and all rights that Customer has under the Service Agreement and under Applicable Laws with respect to Customer Personal Data, have terminated. Notwithstanding termination of this DPA, any provisions hereof that by their nature are intended to survive shall survive termination.
10. Limitation of Liability
For the avoidance of doubt, this DPA incorporates Section 9 of the Master Service Agreement as if fully stated herein.
11. Miscellaneous
11.1 Notices
Any notice made pursuant to this DPA will be in writing and will be deemed delivered on (a) the date of delivery if delivered personally, (b) five (5) calendar days (or upon written confirmed receipt) after mailing if duly deposited in registered or certified mail or express commercial carrier, or (c) one (1) calendar day (or upon written confirmed receipt) after being sent by email, addressed to Customer at the address or email address on record with Vendor, or addressed to Vendor at the address or email address designated below, or to such other address or email address as may be hereafter designated by either Party:
By email to: dpo@traact.com
By mail to:
Traact, Inc.
2 S. Biscayne Boulevard, Suite 2450
Miami, Florida 33131, USAAttn: Data Protection Officer
11.2 Governing Law
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Service Agreement, unless required otherwise by Applicable Laws.
11.3 Assignment
Neither Party may assign or transfer any part of this DPA without the written consent of the other Party; provided, however, that this DPA, collectively with the Service Agreement, may be assigned without the other Party’s written consent by either Party to a person or entity who acquires, by sale, merger or otherwise, all or substantially all of such assigning Party’s assets, stock or business. Subject to the foregoing, this DPA shall bind and inure to the benefit of the Parties, their respective successors and permitted assigns. Any attempted assignment in violation of this Section shall be void and of no effect.
11.4 Counterparts
The Parties may execute this DPA in counterparts (including, without limitation, DocuSign and/or other electronic signature, PDF, and other electronic copies), which taken together shall constitute one instrument.
SCHEDULE I — Details of Customer Personal Data
Nature and Purpose of Processing
To provide the Services pursuant to the Service Agreement.
Categories of Personal Data Subject to Processing
First and last name, phone number, address, email addresses, and position of Customer’s authorized users, including, without limitation, Customer’s employees, contractors, and agents (collectively, the “Authorized Users”).
Any other category of Personal Data that is included within the data, information, and materials Customer, or third parties on behalf of Customer, submits to the Services.
Categories of Data Subjects Whose Personal Data is Transferred
Authorized Users.
Any other category of Data Subjects whose Personal Data is contained or embedded within the data, information, and materials Customer, or third parties on behalf of Customer, submits to the Services.
Frequency of Transfer
Continuous basis for the duration of the Services pursuant to the Service Agreement.
Duration of Processing
For the duration of the Services pursuant to the Service Agreement.
Period for Which Personal Data Will Be Retained
As long as necessary to provide the Services pursuant to the Service Agreement.
SCHEDULE II — EU SCCs
1. Definitions
“EU SCCs” means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at http://data.europa.eu/eli/dec_impl/2021/914/oj and completed as described in this Schedule II.
“UK SCCs” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, available at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf and completed as described in this Schedule II.
2. EU Transfers
With respect to Customer Personal Data transferred from the European Economic Area, the EU SCCs will apply and form part of this Schedule II, unless the European Commission issues updates to the EU SCCs, in which case the updated EU SCCs will control. Undefined capitalized terms used in this provision will have the meanings given to them (or their functional equivalents) in the definitions in the EU SCCs. For purposes of the EU SCCs, they will be deemed completed as follows:
Because Customer is a Controller and Vendor is a Processor of the Customer Personal Data, Module 2 applies.
Clause 7 (the optional docking clause) is not included.
Under Clause 11 (Redress), the optional dispute resolution body language is not included.
Under Clause 17 (Governing law), the Parties select Option 1 (the law of an EU Member State that allows for third-party beneficiary rights). The Parties select the law of Ireland.
Under Clause 18 (Choice of forum and jurisdiction), the Parties select the courts of Ireland.
Annexes I, II and III of the EU SCCs are set forth in Exhibit A to this Schedule II.
By entering into this DPA, the Parties are deemed to be signing the EU SCCs.
3. UK Transfers
With respect to Customer Personal Data transferred from the United Kingdom for which the law of the United Kingdom (and not the law in any European Economic Area jurisdiction) governs the international nature of the transfer, the UK SCCs form part of this Schedule II and take precedence over the rest of this Schedule II as set forth in the UK SCCs, unless the United Kingdom issues updates to the UK SCCs, in which case the updated UK SCCs will control. Undefined capitalized terms used in this provision will have the meanings given to them (or their functional equivalents) in the definitions in the UK SCCs. For purposes of the UK SCCs, they will be deemed completed as follows:
Table 1: The Parties’ details are the Parties and their affiliates to the extent any of them is involved in such transfer, including those set forth in Exhibit A. The Key Contacts are the contacts set forth in Exhibit A.
Table 2: The Approved EU SCCs referenced are the EU SCCs as executed by the Parties pursuant to this Schedule II.
Table 3: Annex 1A, 1B, II and III are set forth in Exhibit A.
Table 4: Either party may terminate the Service Agreement as set forth in Section 19 of the UK SCCs.
By entering into this DPA, the Parties are deemed to be signing the UK SCCs and their applicable Tables and Appendix Information.
4. Swiss Transfers
With respect to Customer Personal Data transferred from Switzerland for which Swiss law (and not the law in any European Economic Area jurisdiction) governs the international nature of the transfer, the EU SCCs will apply and will be deemed to have the following differences to the extent required by the Swiss Federal Act on Data Protection (“FADP”):
References to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR.
The term “member state” in the EU SCCs will not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs.
References to Personal Data in the EU SCCs also refer to data about identifiable legal entities until the entry into force of revisions to the FADP that eliminate this broader scope.
Under Annex I(C) of the EU SCCs (Competent supervisory authority): where the transfer is subject exclusively to the FADP and not the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner; where the transfer is subject to both the FADP and the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner insofar as the transfer is governed by the FADP, and as set forth in the EU SCCs insofar as the transfer is governed by the GDPR.
EXHIBIT A TO SCHEDULE II
ANNEX I
A. List of Parties
Data exporter(s):
Name: Entity identified as “Customer” in the DPA.
Address: See the Service Agreement.
Contact person’s name, position and contact details: See the Service Agreement.
Activities relevant to the data transferred under these Clauses: To receive the Services (as defined in the DPA).
Role (controller/processor): Controller.
Data importer(s):
Name: Traact, Inc. (“Vendor”).
Address: 2 S. Biscayne Boulevard, Suite 2450, Miami, Florida 33131, USA
Contact person:
Name: Helio Noronha
Role: Data Protection Officer
Address: 2 S. Biscayne Boulevard, Suite 2450, Miami, Florida 33131, USA
Email: dpo@traact.com
Activities relevant to the data transferred under these Clauses: To provide Customer with the Services (as defined in the DPA).
Role (controller/processor): Processor.
B. Description of Transfer
Categories of data subjects whose personal data is transferred: See Schedule I.
Categories of personal data transferred: See Schedule I.
Sensitive data transferred (if applicable) and applied restrictions or safeguards: Vendor does not require any special categories of data in order to provide the Services and does not intentionally collect or process such data in connection with the provision of the Services.
Frequency of the transfer: See Schedule I.
Nature of the processing: See Schedule I.
Purpose(s) of the data transfer and further processing: See Schedule I.
Period for which the personal data will be retained: See Schedule I.
For transfers to (sub-) processors, subject matter, nature and duration of the processing: To provide the Services pursuant to the Service Agreement.
C. Competent Supervisory Authority
The supervisory authority mandated by Clause 13. If no supervisory authority is mandated by Clause 13, then the Irish Data Protection Commission (DPC), and if this is not possible, then as otherwise agreed by the parties consistent with the conditions set forth in Clause 13.
ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
See Schedule III.
SCHEDULE III — Security Measures
1. General Security Measures
Vendor will comply with industry-standard security measures (including with respect to personnel, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, and incident response measures necessary to protect against unauthorized or accidental access, loss, alteration, disclosure or destruction of personal data), as well as with all applicable data privacy and security laws, regulations and standards. Vendor maintains SOC 2 Type II certification, available to Customer upon request subject to a Non-Disclosure Agreement.
2. Contact Information
Vendor’s security and data protection inquiries can be directed to dpo@traact.com. General customer support inquiries can be directed to support@traact.com.
3. Compliance
Vendor complies with the standards and practices described on the Vendor website: https://www.traact.com/privacy. For additional information, contact dpo@traact.com.
4. Information Security Program
The objective of Vendor’s Information Security Program is to maintain the confidentiality, integrity and availability of its computer and data communication systems while meeting necessary legislative, industry, and contractual requirements. Vendor shall establish, implement, and maintain an information security program that includes technical and organizational security and physical measures as well as policies and procedures to protect Customer Data processed by Vendor against accidental loss; destruction or alteration; unauthorized disclosure or access; or unlawful destruction.
4.1 Secure Software Development
Vendor maintains policies and procedures to ensure that system, application, and infrastructure development is performed in a secure manner. This includes trained code review and testing of all Vendor applications, regular scanning for common security vulnerabilities, periodic penetration testing, multi-factor authentication, utilizing infrastructure-as-code and industry-recommended configurations for infrastructure.
4.2 Human Resources Security
Vendor maintains a policy that defines requirements around enforcing security measures as they relate to employment status changes. This includes performing background checks, acknowledging and complying with Vendor’s security policies, and utilizing onboarding and termination checklists for employees and third parties.
4.3 Data Classification & Protection
Vendor maintains policies and procedures for data classification and protection, along with requirements for the classification of data containing personal data in consideration of applicable laws, regulations, and contractual obligations. Vendor also maintains requirements on data encryption and rules for transmission of data along with requirements on how access to such data should be governed.
4.4 Network Security
Vendor maintains policies and procedures around the network infrastructure used to process Customer Data, establishes and enforces safe network practices, and defines service level agreements with internal and external network services.
4.5 Physical and Environmental Security
Vendor maintains policies and procedures for physical and environmental security and ensures that critical information services are protected from interception, interference, or damage.
4.6 Business Continuity and Disaster Recovery
Vendor maintains policies and procedures to ensure that Vendor may continue to perform business-critical functions in the face of an extraordinary event. This includes data center resiliency and disaster recovery procedures for business-critical data and processing functions.
5. Access Control
Vendor maintains access control measures designed to limit access to Vendor’s facilities, applications, systems, network devices, and operating systems to a limited number of personnel who have a business need for such access. Vendor shall ensure such access is removed when no longer required and shall conduct access reviews periodically.
6. Risk Assessments
Vendor has a documented risk management procedure and Secure Software Development Life Cycle process. Vendor performs risk assessments of its products and infrastructure on a regular basis, including review of the data classification policies and targeted reviews of highly sensitive data flows.
Vendor performs application testing for new products or feature changes that are launched as well as periodic reassessments of its network. Vendor leverages peer code review and regular vulnerability scanning, and uses a combination of manual penetration testing and automated tools.
7. Third-Party Risk Assessments
Vendor conducts security due diligence on third-party service providers to assess and monitor risk. This assessment includes a review of scope of confidential information and personal data transferred to or processed by the service provider and the purpose of the work. Vendor will also conduct a risk assessment which may include the service provider’s organization and technical security measures, the sensitivity of any information processed by the service provider, storage limitations, and data deletion procedures and timelines.
8. Supplementary Policies
In addition to the general security measures set out above, Vendor maintains the following policies, each of which is reviewed and approved by management on a periodic basis:
AI & Data Handling Policy — governing the approved use of AI capabilities across the platform, including data classification rules, prohibited inputs, approved AI vendors, model and feature review procedures, employee usage guidelines, and a periodic review cadence. Available to clients and prospective clients upon request, subject to a Non-Disclosure Agreement.
Acceptable Use Policy
Change Management Policy
Employee Code of Conduct
Configuration and Asset Management Policy
Data Retention and Disposal Policy
Encryption and Key Management Policy (industry-standard encryption of TLS 1.2 or higher in transit; AES-256 at rest)
Internal Control Policy
Vulnerability Management Policy
DATA PROCESSING ADDENDUM
Last updated: August 2026
This Data Processing Addendum (this “DPA”) forms part of and is subject to the terms and conditions of the Service Agreement (as defined below) by and between the entity identified as the Customer under the Service Agreement and Traact, Inc. (“Vendor”). Customer and Vendor may be referred to herein together as the “Parties”, and each may be referred to herein as a “Party”. This DPA is hereby incorporated into, and subject to, the terms of the Service Agreement. In the event of a conflict between the terms of this DPA and the terms of the Service Agreement, the terms of this DPA shall control. For good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, Customer and Vendor hereby agree as follows:
1. Definitions
“Applicable Laws” means, collectively, all now existing or hereinafter enacted or amended laws, rules, regulations, and/or sanctions programs applicable to a Party’s performance hereunder and/or obligations with respect to data protection, including but not limited to CCPA, European Data Protection Law, and PIPEDA.
“CCPA” means the California Consumer Privacy Act of 2018 (Title 1.81.5 of the Civil Code of the State of California), as amended by the California Privacy Rights Act of 2020 (CPRA), together with all effective regulations adopted thereunder (in each case, as amended from time to time).
“Customer Data” means all information, data, content and other materials, in any form or medium, that is submitted, posted, collected, transmitted or otherwise provided by or on behalf of Customer through the Services.
“Customer Personal Data” means Customer Data that is Personal Data processed by Vendor on behalf of Customer in the provision of the Services under the Service Agreement.
“Controller” means (i) under and in the context of European Data Protection Law, the data “controller” (as defined by GDPR), (ii) under and in the context of CCPA, the “business” or “third party” (each, as defined by CCPA), and (iii) under and in the context of any other privacy or data protection law, rule, or regulation applicable to a Party’s performance hereunder, a “controller”, “business”, or corresponding term denoting a substantially similar definition, role, and obligations under such law, rule or regulation.
“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (and each successor regulation, directive or other text of the foregoing, in each case as amended from time to time).
“European Data Protection Law” means each of EU GDPR, UK GDPR, and the Federal Data Protection Act of 19 June 1992 (Switzerland) (as the same may be superseded by the Swiss Data Protection Act 2020 and as amended from time to time).
“GDPR” means, as applicable, (i) the EU GDPR and/or (ii) the UK GDPR.
“Personal Data” means any information that constitutes “personal information,” “personal data,” and/or other term denoting a substantially similar definition and obligations under, and in the context of, any Applicable Laws.
“PIPEDA” means Canada’s Federal Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (as amended from time to time).
“Process” means any operation or set of computer operations performed on Personal Data, including, but not limited to, collection, recording, organization, structuring, storage, access, adaptation, alteration, retrieval, consultation, use, transfer, transmit, sale, rental, disclosure, dissemination, making available, alignment, combination, deletion, erasure, or destruction.
“Processor” means (i) under and in the context of European Data Protection Law, the data “processor” (as defined by GDPR), (ii) under and in the context of CCPA, a “service provider” (as defined by CCPA), and (iii) under and in the context of any other privacy or data protection law, rule, or regulation applicable to a Party’s performance hereunder, a “processor”, “service provider”, or corresponding term denoting a substantially similar definition, role, and obligations under such law, rule or regulation.
“Security Incident” means (i) any accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to, Customer Personal Data or (ii) any other event that constitutes a “security breach”, “personal data breach”, or substantially similar term with respect to Customer Personal Data under Applicable Laws.
“Service Agreement” means, collectively, the agreements and/or terms of service (including, as applicable, each of the Statements of Work/SOWs/Orders/Order Forms and exhibits thereunder) between Customer and Vendor. “Services” means, collectively, the products and/or services provided by Vendor to Customer under the Service Agreement.
“Sub-Processor” means a contractor, subcontractor, consultant, third-party service provider, or agent engaged by Vendor for further Processing of Customer Personal Data.
“UK GDPR” has the meaning ascribed thereto in section 3(10) (as supplemented by section 205(4)) of the UK Data Protection Act 2018 (as amended from time to time).
2. Data Processing Obligations
2.1 General
Each Party shall comply with its obligations relating to Personal Data under this DPA and under Applicable Laws at its own cost. With respect to Customer Personal Data, (i) Customer is a Controller and (ii) Vendor is a Processor that Processes Customer Personal Data only upon the instructions of Customer, including, without limitation, in accordance with the applicable Service Agreement, this DPA, and any other documented instructions provided by Customer. Notwithstanding the foregoing, Vendor may Process Customer Personal Data as required by Applicable Laws. Vendor shall immediately inform Customer if, in the Vendor’s opinion, an instruction of Customer infringes Applicable Laws. Schedule I sets forth specific details regarding Vendor’s processing of Customer Personal Data.
Vendor shall Process Customer Personal Data only on behalf of and for the benefit of Customer, for the purposes of Processing Customer Personal Data in connection with the Agreement, and to carry out its obligations pursuant to this DPA, the Service Agreement and Customer’s written instructions.
Vendor and its employees and contractors shall hold in strict confidence (i) the existence and terms of this DPA, and any related agreement, and (ii) any and all Customer Personal Data.
With regard to Vendor employees and contractors engaged in Processing Customer Personal Data, Vendor shall ensure that such employees and contractors are informed of the confidential nature of the Customer Personal Data. . Vendor shall use commercially reasonable methods to limit access to Customer Personal Data to its employees and contractors who have a need to know the Customer Personal Data as a condition to Vendor’s performance of its obligations under the Service Agreement for or on behalf of Customer and who have explicitly agreed to comply with legally enforceable confidentiality and security obligations that are substantially similar to those required by this DPA. Vendor shall exercise the necessary and appropriate supervision over its employees and contractors to maintain appropriate privacy, confidentiality, and security of Customer Personal Data in accordance with this DPA. Vendor shall provide training, as appropriate, regarding the requirements set forth in this DPA to those employees and contractors who have access to Customer Personal Data.
Customer will have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer obtains the Customer Personal Data, including, without limitation, obtaining appropriate consent to collect the Customer Personal Data and share such data with Vendor in accordance with Applicable Laws.
2.2 Standard Contractual Clauses
If Vendor Processes Customer Personal Data relating to an EEA, United Kingdom, or Switzerland data subject (including, without limitation, the transfer of such Customer Personal Data from the EEA, United Kingdom, or Switzerland to a third country not providing an adequate level of protection) outside of the EEA, United Kingdom, and Switzerland, the Processing will be further governed by Schedule II to this DPA (together with all Appendices and Annexes thereto, and as the same may be amended, supplemented, or otherwise modified from time to time, the “Personal Data SCCs”), which is incorporated by reference into this DPA solely with respect to Customer Personal Data relating to EEA, United Kingdom and/or Switzerland data subjects. If there is any conflict between (x) the terms and conditions of either this DPA or the Service Agreement, on the one hand, and (y) the terms and conditions of the Personal Data SCCs, on the other hand, then, with respect to Customer Personal Data relating to an EEA, United Kingdom and/or Switzerland data subject(s), the terms and conditions of the Personal Data SCCs will prevail and control. Vendor may only transfer Customer Personal Data relating to an EEA, United Kingdom, or Switzerland data subject outside the EEA, United Kingdom, and Switzerland in compliance with Applicable Laws and the Personal Data SCCs.
For the avoidance of doubt, Vendor shall not transfer Customer Personal Data outside the country in which the Customer Personal Data was originally provided to Vendor for Processing, (or, if it was originally delivered to a location inside the EEA or Switzerland, outside the EEA or Switzerland) without the consent of Customer Vendor processes data in the United States, and therefore, Customer consents to the transfer of Customer Personal Data to and from the U.S. for processing by providing the Customer Personal Data.
Where Vendor, with the consent of Customer, provides to a third-party access to Customer Personal Data received by Customer from the EEA or Switzerland, Vendor will enter into any written agreements as are necessary to comply with Applicable Laws concerning any cross-border transfer of Customer Personal Data, whether to or from Vendor.
2.3 CCPA
With respect to Customer Personal Data relating to a California “consumer” or “household” (each as defined by CCPA) (“CCPA Personal Data”):
Customer will be disclosing such CCPA Personal Data under the Service Agreement to Vendor for a “business purpose” (as defined by CCPA), and Vendor shall Process such CCPA Personal Data solely on behalf of Customer and only as necessary to perform such business purpose for Customer; and
Except as expressly permitted by the CCPA or its regulations, Vendor shall not: (i) “sell” or “share” (as each term is defined by the CCPA) CCPA Personal Data; (ii) retain, use, or disclose CCPA Personal Data (x) for any purpose (including a “commercial purpose” (as defined by CCPA)) other than for the business purpose(s) identified above, or (y) outside of the direct business relationship between Vendor and Customer; or (iii) combine the Customer Personal Data with Personal Data that Vendor collects or receives from another source (except in the performance of any “business purpose”).
2.4 Changes in Applicable Laws
At the time Vendor has entered into this Agreement, Vendor is not aware of any Applicable Law, or privacy or information security enforcement action, investigation, litigation or claim which prohibits Vendor from (i) fulfilling its obligations under this DPA or (ii) complying with instructions it receives from Customer concerning Customer Personal Data.If, due to any change in Applicable Laws, a Party reasonably believes that Vendor ceases to be able to provide the Services in whole or in part (e.g., with respect to a particular jurisdiction) and/or Customer ceases to be able to use the Services in whole or in part under the then-current terms and conditions of the Service Agreement and this DPA, either Party shall promptly notify the other in writing, and subsequently may terminate the Service Agreement (in whole or, if reasonably practicable, in part) in its sole discretion and without penalty of any kind .
3. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Vendor will implement and maintain appropriate technical and organizational measures to ensure a level of security for the Customer Personal Data appropriate to the risks. In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored or otherwise processed. Such measures will include reasonable administrative, physical, and technical security controls (including those required by Applicable Laws) that prevent the collection, use, disclosure, or access to Customer Personal Data that the Service Agreement does not expressly authorize, including maintaining a comprehensive information security program that safeguards Customer Personal Data. These security measures include the measures set forth in Schedule III.
If the Processing by Vendor or its employees or contractors involves the transmission of the Customer Personal Data over a network, Vendor shall implement commercially reasonable measures designed to protect the Customer Personal Data against the specific risks associated with such transmission.
If Vendor shall perform services in compliance with the Payment Card Industry Data Security Standard (“PCI DSS”), then Vendor hereby acknowledges its responsibility for the security of any Cardholder Data (as such term is defined in the PCI DSS) which it stores, transmits, or processes in connection with the Service Agreement. Vendor shall perform any and all tasks, assessments, reviews, penetration tests, scans and other activities required under the PCI DSS for merchants in the same merchant category as Customer (including any compliance guidance issued by the PCI Data Security Council or its subordinate bodies) or otherwise to validate during the term of the Service Agreement its compliance with the PCI DSS as it relates to the system elements and portions of the cardholder data environment (as such terms are defined in the PCI DSS) for which Vendor is responsible. Upon Customer’s request, Vendor shall deliver to Customer copies of all documentation necessary to verify such compliance, including without limitation, any attestation of compliance, report on compliance, self-assessment questionnaire, or testing or assessment results.
4. Supplementary Measures and Safeguards
4.1 Assistance
Vendor shall assist Customer to ensure compliance with Applicable Laws in connection with the Processing of Customer Personal Data.
4.2 Law Enforcement and Administrative Requests for Information
Vendor shall notify Customer immediately in writing of any subpoena or other judicial or administrative order by a government authority or proceeding seeking access to or disclosure of Customer Personal Data. Customer shall have the right to defend such action in lieu of and/or on behalf of Vendor. Customer may, if it so chooses, seek a protective order. Vendor shall reasonably cooperate with Customer in such defense.
4.3 Data Protection Impact Assessments for Sub-Processors in Accordance with Applicable Laws.
Vendor has conducted and maintains a Data Protection Impact Assessment (DPIA) with respect to its use of OpenAI, L.L.C. as a Sub-Processor for AI-assisted contract processing, in accordance with Applicable Laws. In conducting and updating its DPIA, Vendor relies in part on OpenAI's enterprise-grade data processing agreements and compliance documentation as evidence of appropriate safeguards at the sub-processor level. Vendor will make its DPIA available to Customer upon written request, subject to a Non-Disclosure Agreement. Vendor shall update the DPIA upon any material change to the relevant processing.
Vendor will continue to conduct and maintain DPIAs required by Applicable Laws if additional Sub-Processors that use AI-assisted processing are procured.
5. Notifications
5.1 Security Incidents
Vendor will provide Customer with written notice without undue delay, and in any event within seventy-two (72) hours, after discovering a Security Incident (including those affecting Vendor or its Sub-Processors), including any known information that Customer is required by Applicable Laws to provide to an applicable regulatory agency or to the individuals whose Personal Data was involved in the Security Incident. Vendor shall provide prompt and regular updated written notifications to Customer as Vendor’s understanding of the scope and impact of the Security Incident changes, evolves, and/or develops. Vendor shall cooperate with Customer to meet any notification obligations to individuals or regulatory authorities imposed by Applicable Laws, including providing all necessary information within the timeframes required by such laws.
For the avoidance of doubt, notification to Customer shall include all available information regarding such Security Incident, including information on: (i) the nature of the Security Incident including where possible, the categories and approximate number of affected individuals and the categories and approximate number of affected Customer Personal Data records; (ii) the likely consequences of the Security Incident; and (iii) the measures taken or proposed to be taken to address the Security Incident, including, where appropriate, measures to mitigate its possible adverse effects. Vendor shall promptly take all necessary and advisable corrective actions and shall cooperate fully with Customer in all reasonable and lawful efforts to prevent, mitigate, or rectify such Security Incident. Vendor shall (i) investigate such Security Incident and perform a root cause analysis thereon; (ii) remediate the effects of such Security Incident; and (iii) provide Customer with such reasonable assurances that such Security Incident is not likely to recur. Vendor shall provide such assistance as required to enable Customer to Customer’s obligations under Privacy Laws. Customer shall have the right at any time after learning of a Security Incident to engage and involve external forensic firms in the investigation of the Security Incident at its own expense (which will include a right to investigate Vendor systems), and Vendor shall comply with all reasonable requests of such external forensic firm. Vendor shall use commercially reasonable efforts to preserve all applicable evidence relating to the Security Incident until Customer has completed a forensic investigation or confirmed to Vendor that it waives its right to conduct such an investigation.
5.2 Data Subject Requests
Vendor shall (i) no later than five days after receipt of such request, notify Customer about any request under Applicable Law(s) with respect to Customer Personal Data received from or on behalf of the applicable data subject, and (ii) cooperate as required by Applicable Law(s) with Customer’s reasonable requests in connection with data subject requests with respect to Customer Personal Data. Vendor shall assist Customer, through appropriate technical and organizational measures, to fulfill its obligations with respect to requests of data subjects seeking to exercise rights under Applicable Law with respect to Customer Personal Data.
6. Sub-Processors
Vendor shall not have Customer Personal Data Processed by a Sub-Processor unless such Sub-Processor is bound by a written agreement with Vendor that includes data protection obligations at least as protective as those contained in this DPA and the Service Agreement and that meet the requirements of Applicable Laws. Vendor is and shall remain fully liable to Customer for any failure by any Sub-Processor to fulfill Vendor’s data protection obligations under Applicable Laws.
Vendor’s list of all Sub-Processors who access Customer Personal Data is available at Annex III to Exhibit A of Schedule II (the “Sub-Processor List”). Customer authorizes and instructs Vendor to engage the Sub-Processors listed in the Sub-Processor List. Vendor will notify Customer of any changes to the Sub-Processors listed on the Sub-Processor List and grant Customer the opportunity to object to such change. Upon Customer’s request, Vendor will provide all information necessary to demonstrate that the Sub-Processors will meet all requirements set forth in this Section 6. If Customer reasonably objects to any Sub-Processor on data protection grounds, Vendor may choose either not to engage the Sub-Processor or, if engagement is unavoidable, Customer may terminate the affected portion of the Services without penalty upon thirty (30) days’ prior written notice.
For the avoidance of doubt, Vendor shall not share, transfer, disclose or otherwise provide access to any Customer Personal Data to any third party, or contract any of its rights or obligations concerning Customer Personal Data to a third party, except a Sub-Processor, unless Customer has authorized Vendor to do so in writing, which may be in the applicable SOW, except as required by law. Where Vendor, with the consent of Customer, provides to a third-party access to Customer Personal, or contracts such rights or obligations to a third party, Vendor shall enter into a written agreement with each third party that imposes obligations on the third party that are substantially the same as those imposed on Vendor under this DPA.
7. Deletion
Vendor shall, at the choice of Customer: (i) delete or return all Customer Data to Customer after such Customer Data is no longer necessary for the provision of the Services, and (ii) delete existing copies of such Customer Data. Such deletion or return shall be completed within a reasonable period and, except where prohibited by Applicable Laws, not later than ninety (90) days following the request. Backup copies will be deleted in accordance with Vendor’s documented data retention and disposal policy.
8. Documentation; Audit
Vendor shall, upon Customer’s request, provide Customer (a) comprehensive documentation of Vendor’s technical and organizational security measures, (b) any and all third-party audits and certifications available with respect to such security measures, including Vendor’s SOC 2 Type II report, and (c) all other information reasonably necessary to demonstrate compliance with Vendor’s obligations under this DPA and/or under Applicable Laws. Where (a) – (c) of this section are not sufficient for compliance with Applicable Laws, then upon reasonable notice and appropriate confidentiality agreements, Vendor shall cooperate with assessments, audits, or other steps performed by or on behalf of Customer at Customer’s sole expense and in a manner that is minimally disruptive to Vendor’s business that are necessary to confirm that Vendor is processing Customer Personal Data in a manner consistent with this DPA.
9. Term; Termination
This DPA shall remain in effect until (a) the Service Agreement has terminated and (b) all obligations that Vendor has under the Service Agreement and under Applicable Laws with respect to Customer Personal Data, and all rights that Customer has under the Service Agreement and under Applicable Laws with respect to Customer Personal Data, have terminated. Notwithstanding termination of this DPA, any provisions hereof that by their nature are intended to survive shall survive termination.
10. Limitation of Liability
For the avoidance of doubt, this DPA incorporates Section 9 of the Master Service Agreement as if fully stated herein.
11. Miscellaneous
11.1 Notices
Any notice made pursuant to this DPA will be in writing and will be deemed delivered on (a) the date of delivery if delivered personally, (b) five (5) calendar days (or upon written confirmed receipt) after mailing if duly deposited in registered or certified mail or express commercial carrier, or (c) one (1) calendar day (or upon written confirmed receipt) after being sent by email, addressed to Customer at the address or email address on record with Vendor, or addressed to Vendor at the address or email address designated below, or to such other address or email address as may be hereafter designated by either Party:
By email to: dpo@traact.com
By mail to:
Traact, Inc.
2 S. Biscayne Boulevard, Suite 2450
Miami, Florida 33131, USAAttn: Data Protection Officer
11.2 Governing Law
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Service Agreement, unless required otherwise by Applicable Laws.
11.3 Assignment
Neither Party may assign or transfer any part of this DPA without the written consent of the other Party; provided, however, that this DPA, collectively with the Service Agreement, may be assigned without the other Party’s written consent by either Party to a person or entity who acquires, by sale, merger or otherwise, all or substantially all of such assigning Party’s assets, stock or business. Subject to the foregoing, this DPA shall bind and inure to the benefit of the Parties, their respective successors and permitted assigns. Any attempted assignment in violation of this Section shall be void and of no effect.
11.4 Counterparts
The Parties may execute this DPA in counterparts (including, without limitation, DocuSign and/or other electronic signature, PDF, and other electronic copies), which taken together shall constitute one instrument.
SCHEDULE I — Details of Customer Personal Data
Nature and Purpose of Processing
To provide the Services pursuant to the Service Agreement.
Categories of Personal Data Subject to Processing
First and last name, phone number, address, email addresses, and position of Customer’s authorized users, including, without limitation, Customer’s employees, contractors, and agents (collectively, the “Authorized Users”).
Any other category of Personal Data that is included within the data, information, and materials Customer, or third parties on behalf of Customer, submits to the Services.
Categories of Data Subjects Whose Personal Data is Transferred
Authorized Users.
Any other category of Data Subjects whose Personal Data is contained or embedded within the data, information, and materials Customer, or third parties on behalf of Customer, submits to the Services.
Frequency of Transfer
Continuous basis for the duration of the Services pursuant to the Service Agreement.
Duration of Processing
For the duration of the Services pursuant to the Service Agreement.
Period for Which Personal Data Will Be Retained
As long as necessary to provide the Services pursuant to the Service Agreement.
SCHEDULE II — EU SCCs
1. Definitions
“EU SCCs” means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at http://data.europa.eu/eli/dec_impl/2021/914/oj and completed as described in this Schedule II.
“UK SCCs” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, available at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf and completed as described in this Schedule II.
2. EU Transfers
With respect to Customer Personal Data transferred from the European Economic Area, the EU SCCs will apply and form part of this Schedule II, unless the European Commission issues updates to the EU SCCs, in which case the updated EU SCCs will control. Undefined capitalized terms used in this provision will have the meanings given to them (or their functional equivalents) in the definitions in the EU SCCs. For purposes of the EU SCCs, they will be deemed completed as follows:
Because Customer is a Controller and Vendor is a Processor of the Customer Personal Data, Module 2 applies.
Clause 7 (the optional docking clause) is not included.
Under Clause 11 (Redress), the optional dispute resolution body language is not included.
Under Clause 17 (Governing law), the Parties select Option 1 (the law of an EU Member State that allows for third-party beneficiary rights). The Parties select the law of Ireland.
Under Clause 18 (Choice of forum and jurisdiction), the Parties select the courts of Ireland.
Annexes I, II and III of the EU SCCs are set forth in Exhibit A to this Schedule II.
By entering into this DPA, the Parties are deemed to be signing the EU SCCs.
3. UK Transfers
With respect to Customer Personal Data transferred from the United Kingdom for which the law of the United Kingdom (and not the law in any European Economic Area jurisdiction) governs the international nature of the transfer, the UK SCCs form part of this Schedule II and take precedence over the rest of this Schedule II as set forth in the UK SCCs, unless the United Kingdom issues updates to the UK SCCs, in which case the updated UK SCCs will control. Undefined capitalized terms used in this provision will have the meanings given to them (or their functional equivalents) in the definitions in the UK SCCs. For purposes of the UK SCCs, they will be deemed completed as follows:
Table 1: The Parties’ details are the Parties and their affiliates to the extent any of them is involved in such transfer, including those set forth in Exhibit A. The Key Contacts are the contacts set forth in Exhibit A.
Table 2: The Approved EU SCCs referenced are the EU SCCs as executed by the Parties pursuant to this Schedule II.
Table 3: Annex 1A, 1B, II and III are set forth in Exhibit A.
Table 4: Either party may terminate the Service Agreement as set forth in Section 19 of the UK SCCs.
By entering into this DPA, the Parties are deemed to be signing the UK SCCs and their applicable Tables and Appendix Information.
4. Swiss Transfers
With respect to Customer Personal Data transferred from Switzerland for which Swiss law (and not the law in any European Economic Area jurisdiction) governs the international nature of the transfer, the EU SCCs will apply and will be deemed to have the following differences to the extent required by the Swiss Federal Act on Data Protection (“FADP”):
References to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR.
The term “member state” in the EU SCCs will not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs.
References to Personal Data in the EU SCCs also refer to data about identifiable legal entities until the entry into force of revisions to the FADP that eliminate this broader scope.
Under Annex I(C) of the EU SCCs (Competent supervisory authority): where the transfer is subject exclusively to the FADP and not the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner; where the transfer is subject to both the FADP and the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner insofar as the transfer is governed by the FADP, and as set forth in the EU SCCs insofar as the transfer is governed by the GDPR.
EXHIBIT A TO SCHEDULE II
ANNEX I
A. List of Parties
Data exporter(s):
Name: Entity identified as “Customer” in the DPA.
Address: See the Service Agreement.
Contact person’s name, position and contact details: See the Service Agreement.
Activities relevant to the data transferred under these Clauses: To receive the Services (as defined in the DPA).
Role (controller/processor): Controller.
Data importer(s):
Name: Traact, Inc. (“Vendor”).
Address: 2 S. Biscayne Boulevard, Suite 2450, Miami, Florida 33131, USA
Contact person:
Name: Helio Noronha
Role: Data Protection Officer
Address: 2 S. Biscayne Boulevard, Suite 2450, Miami, Florida 33131, USA
Email: dpo@traact.com
Activities relevant to the data transferred under these Clauses: To provide Customer with the Services (as defined in the DPA).
Role (controller/processor): Processor.
B. Description of Transfer
Categories of data subjects whose personal data is transferred: See Schedule I.
Categories of personal data transferred: See Schedule I.
Sensitive data transferred (if applicable) and applied restrictions or safeguards: Vendor does not require any special categories of data in order to provide the Services and does not intentionally collect or process such data in connection with the provision of the Services.
Frequency of the transfer: See Schedule I.
Nature of the processing: See Schedule I.
Purpose(s) of the data transfer and further processing: See Schedule I.
Period for which the personal data will be retained: See Schedule I.
For transfers to (sub-) processors, subject matter, nature and duration of the processing: To provide the Services pursuant to the Service Agreement.
C. Competent Supervisory Authority
The supervisory authority mandated by Clause 13. If no supervisory authority is mandated by Clause 13, then the Irish Data Protection Commission (DPC), and if this is not possible, then as otherwise agreed by the parties consistent with the conditions set forth in Clause 13.
ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
See Schedule III.
SCHEDULE III — Security Measures
1. General Security Measures
Vendor will comply with industry-standard security measures (including with respect to personnel, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, and incident response measures necessary to protect against unauthorized or accidental access, loss, alteration, disclosure or destruction of personal data), as well as with all applicable data privacy and security laws, regulations and standards. Vendor maintains SOC 2 Type II certification, available to Customer upon request subject to a Non-Disclosure Agreement.
2. Contact Information
Vendor’s security and data protection inquiries can be directed to dpo@traact.com. General customer support inquiries can be directed to support@traact.com.
3. Compliance
Vendor complies with the standards and practices described on the Vendor website: https://www.traact.com/privacy. For additional information, contact dpo@traact.com.
4. Information Security Program
The objective of Vendor’s Information Security Program is to maintain the confidentiality, integrity and availability of its computer and data communication systems while meeting necessary legislative, industry, and contractual requirements. Vendor shall establish, implement, and maintain an information security program that includes technical and organizational security and physical measures as well as policies and procedures to protect Customer Data processed by Vendor against accidental loss; destruction or alteration; unauthorized disclosure or access; or unlawful destruction.
4.1 Secure Software Development
Vendor maintains policies and procedures to ensure that system, application, and infrastructure development is performed in a secure manner. This includes trained code review and testing of all Vendor applications, regular scanning for common security vulnerabilities, periodic penetration testing, multi-factor authentication, utilizing infrastructure-as-code and industry-recommended configurations for infrastructure.
4.2 Human Resources Security
Vendor maintains a policy that defines requirements around enforcing security measures as they relate to employment status changes. This includes performing background checks, acknowledging and complying with Vendor’s security policies, and utilizing onboarding and termination checklists for employees and third parties.
4.3 Data Classification & Protection
Vendor maintains policies and procedures for data classification and protection, along with requirements for the classification of data containing personal data in consideration of applicable laws, regulations, and contractual obligations. Vendor also maintains requirements on data encryption and rules for transmission of data along with requirements on how access to such data should be governed.
4.4 Network Security
Vendor maintains policies and procedures around the network infrastructure used to process Customer Data, establishes and enforces safe network practices, and defines service level agreements with internal and external network services.
4.5 Physical and Environmental Security
Vendor maintains policies and procedures for physical and environmental security and ensures that critical information services are protected from interception, interference, or damage.
4.6 Business Continuity and Disaster Recovery
Vendor maintains policies and procedures to ensure that Vendor may continue to perform business-critical functions in the face of an extraordinary event. This includes data center resiliency and disaster recovery procedures for business-critical data and processing functions.
5. Access Control
Vendor maintains access control measures designed to limit access to Vendor’s facilities, applications, systems, network devices, and operating systems to a limited number of personnel who have a business need for such access. Vendor shall ensure such access is removed when no longer required and shall conduct access reviews periodically.
6. Risk Assessments
Vendor has a documented risk management procedure and Secure Software Development Life Cycle process. Vendor performs risk assessments of its products and infrastructure on a regular basis, including review of the data classification policies and targeted reviews of highly sensitive data flows.
Vendor performs application testing for new products or feature changes that are launched as well as periodic reassessments of its network. Vendor leverages peer code review and regular vulnerability scanning, and uses a combination of manual penetration testing and automated tools.
7. Third-Party Risk Assessments
Vendor conducts security due diligence on third-party service providers to assess and monitor risk. This assessment includes a review of scope of confidential information and personal data transferred to or processed by the service provider and the purpose of the work. Vendor will also conduct a risk assessment which may include the service provider’s organization and technical security measures, the sensitivity of any information processed by the service provider, storage limitations, and data deletion procedures and timelines.
8. Supplementary Policies
In addition to the general security measures set out above, Vendor maintains the following policies, each of which is reviewed and approved by management on a periodic basis:
AI & Data Handling Policy — governing the approved use of AI capabilities across the platform, including data classification rules, prohibited inputs, approved AI vendors, model and feature review procedures, employee usage guidelines, and a periodic review cadence. Available to clients and prospective clients upon request, subject to a Non-Disclosure Agreement.
Acceptable Use Policy
Change Management Policy
Employee Code of Conduct
Configuration and Asset Management Policy
Data Retention and Disposal Policy
Encryption and Key Management Policy (industry-standard encryption of TLS 1.2 or higher in transit; AES-256 at rest)
Internal Control Policy
Vulnerability Management Policy