Legal
Data Processing Addendum
The terms under which Drytis processes personal data on behalf of customers who are controllers, as required by the Terms and the Privacy Policy.
Last updated: September 15, 2026
Drytis, Inc. — Data Processing Addendum (DPA)
Effective Date: September 15, 2026, | Last Updated: September 15, 2026
This Data Processing Addendum (this "DPA") forms part of, and is incorporated into, the Drytis Terms of Service, together with any Order Form and any separately executed agreement between Drytis, Inc., a Nevada corporation ("Drytis," "we," or "us"), and the customer that accepts them ("Customer" or "you") (collectively, the "Agreement").
This DPA applies where and to the extent Drytis Processes Customer Personal Data on behalf of Customer in providing the Services and that Processing is subject to Data Protection Laws. It governs only the Processing of Customer Personal Data. All other matters, including fees, ownership and licensing of Workspace Content and Generated Output, confidentiality, warranties, indemnities, limitation of liability, and dispute resolution, are governed by the Agreement.
Capitalized terms used in this DPA and not defined in it have the meanings given to them in the Agreement, including in Section 2 of the Terms of Service. No separate signature is required for this DPA to take effect; Customer accepts it by accepting the Agreement. Customer enters into this DPA on behalf of itself and each of its Affiliates permitted to use the Services under the Agreement.
1. DEFINITIONS
1.1. "Data Protection Laws" means the laws and regulations applicable to Drytis's Processing of Customer Personal Data under the Agreement, including, where applicable: Regulation (EU) 2016/679 (the "GDPR"); the UK General Data Protection Regulation and the Data Protection Act 2018, each as amended, including by the Data (Use and Access) Act 2025 (together, the "UK GDPR"); the Swiss Federal Act on Data Protection (the "FADP"); the California Consumer Privacy Act as amended by the California Privacy Rights Act, together with its implementing regulations (the "CCPA"); and other U.S. state privacy laws that impose obligations on Drytis in its capacity as a processor or service provider.
1.2. "Customer Personal Data" has the meaning given in the Agreement, and means Personal Data contained in Workspace Content that Drytis Processes on Customer's behalf in providing the Services. Customer Personal Data does not include Usage Data, or data that Drytis Processes as an independent controller under Section 2.1.
1.3. "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given under applicable Data Protection Laws. "Business," "Service Provider," "Consumer," "Sell," "Share," and "Sensitive Personal Information" have the meanings given under the CCPA. "Personal Data" has the meaning given in the Agreement, and where a Data Protection Law defines an equivalent term, that meaning applies for the purposes of that law.
1.4. "Model Provider" means a third-party model provider as referred to in Section 8.6 of the Agreement.
1.5. "Restricted Transfer" means a transfer of Customer Personal Data that is subject to Chapter V of the GDPR, the equivalent provisions of the UK GDPR, or the cross-border disclosure provisions of the FADP, and for which a transfer mechanism is required.
1.6. "Sub-processor" means any third party engaged by Drytis to Process Customer Personal Data in connection with the Services, including Drytis Affiliates and Model Providers. Sub-processors do not include third-party services Customer connects or enables under Section 12 of the Agreement, which are addressed in Section 5.5.
1.7. "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner and in force from 21 March 2022. "SCCs" means those instruments together, as applicable and as completed in Appendix 4.
2. ROLES, SCOPE AND INSTRUCTIONS
2.1. Roles
a) With respect to Customer Personal Data, Customer is the Controller and Drytis is the Processor. Where the CCPA applies, the parties intend that Customer acts as a Business and Drytis as a Service Provider, and Drytis will Process Customer Personal Data consistently with that role. Drytis does not determine the purposes or means of the Processing of Customer Personal Data.
b) As Section 17.2 of the Agreement provides, Drytis acts as an independent controller with respect to Account, registration, billing, authentication, security, support, and service-operation data, including Usage Data, and with respect to the records Drytis maintains under Section 10.10 of the Agreement. That Processing is governed by the Privacy Policy and not by this DPA, and does not extend to Workspace Content.
c) Where Customer is itself a processor acting for a third-party controller, Customer represents that it is authorized to instruct Drytis as a sub-processor and to enter into this DPA on that controller's behalf.
2.2. Documented instructions
a) Drytis will Process Customer Personal Data only on Customer's documented instructions, including as to Restricted Transfers, unless required to Process by applicable law. Where Drytis Processes on the basis of a legal requirement, it will inform Customer of that requirement before Processing unless the law prohibits it on important grounds of public interest.
b) Customer's documented instructions comprise the Agreement, this DPA, the AUP, Customer's configuration and use of the Services, and any further written instructions the parties agree. Drytis will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, without any obligation to conduct a legal review of Customer's Processing.
c) Customer instructs Drytis, and Drytis is in any event required by applicable law, to detect, remove or disable access to, preserve, and report apparent child sexual abuse material and associated information to the National Center for Missing and Exploited Children, law enforcement, or other competent authorities. Section 4.2 of the AUP describes the corresponding operational measures.
2.3. Customer responsibilities
a) Customer is responsible for the accuracy, quality and lawfulness of Customer Personal Data and the means by which it was obtained; for establishing and maintaining a lawful basis for the Processing it instructs; for providing the notices and obtaining the consents required under Section 17.3 of the Agreement; and for ensuring that its instructions comply with Data Protection Laws.
b) Customer will not submit to or generate within the Services any category of regulated or restricted data identified in Section 17.5 of the Agreement, including protected health information subject to HIPAA, cardholder data subject to PCI DSS, nonpublic personal information subject to GLBA, information subject to ITAR or EAR licensing requirements, government classified information, biometric identifiers, and children's personal information subject to COPPA or comparable law, and will not submit special-category data within the meaning of Article 9 of the GDPR or Sensitive Personal Information, unless Drytis has expressly designated the applicable Service as approved for that category and the parties have executed any additional agreement that category requires, including a business associate agreement.
2.4. Processing details - The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Appendix 1.
2.5. Permitted Processing - Drytis Processes Customer Personal Data to:
a) provide the Services and deliver the functionality Customer requests, including generating Generated Output, hosting and serving Deployed Applications, and performing Engineer Services;
b) operate, maintain, secure, support and troubleshoot the Services, and meter and substantiate Fees;
c) detect, investigate, prevent and remediate security incidents, fraud, abuse, technical faults, and violations of the Agreement or the AUP, including enforcement action under Section 13 of the AUP; and
d) comply with applicable law, legal process, and valid governmental requests.
e) This Section reflects the license granted at Section 7.2 of the Agreement and does not expand it. Drytis will not use Workspace Content for any purpose unrelated to providing and supporting the Services for Customer, except as this DPA permits or Customer instructs in writing.
2.6. Model Providers - Drytis may disclose Customer Personal Data to Model Providers to the extent necessary to deliver the AI Features Customer uses, as Section 8.6 of the Agreement contemplates. Model Providers are Sub-processors and are subject to Section 5. Consistent with Section 7.4 of the Agreement, Drytis will contractually require each Model Provider that Processes Customer Personal Data to Process it only to provide the relevant capability to Drytis, and not to conduct Model Training on it. Any retention of inputs or outputs by a Model Provider is identified in Appendix 3.
2.7. Model Training
a) Drytis will not use Workspace Content for Model Training and will not authorize a Sub-processor or Model Provider to do so, absent Customer's express written authorization, as Section 7.4 of the Agreement provides.
b) Where Customer grants such authorization, Drytis will Process Customer Personal Data only within the scope, for the purposes, and for the retention period the authorization specifies, and Customer is responsible for the lawful basis for that Processing. Customer may withdraw the authorization prospectively at any time; withdrawal does not require Drytis to retrain, reverse, or delete a model already modified in reliance on it.
c) No de-identification, aggregation, pseudonymization, transformation, or other processing of Workspace Content will be used to circumvent this Section. Drytis's use of Usage Data under Section 15.3 of the Agreement does not authorize Model Training on Workspace Content.
2.8. Engineer Services and Engineer Session Data
a) Access - When Customer requests or enables an Engineer Service, Customer instructs and authorizes Drytis and its assigned Engineers to access and Process Customer Personal Data on the terms and within the limits set out in Sections 9.2, 9.3 and 9.4 of the Agreement. Drytis will apply least-privilege and need-to-know controls, will limit access to the scope and duration reasonably required for the requested Engineer Service, and will revoke access on completion of the Session.
b) Status of Engineers - Engineers are employees or contractors of Drytis and are not Customer's employees, agents, representatives, or fiduciaries, as Section 9.5 of the Agreement provides. Engineers are bound by written confidentiality obligations under Section 9.7 of the Agreement, and Drytis remains responsible for their compliance.
c) Customer Personal Data within Engineer Session Data - To the extent Engineer Session Data contains Personal Data within Workspace Content, that data is Customer Personal Data and Drytis Processes it as a Processor under this DPA. Customer instructs Drytis to Process it for the purposes stated in Section 9.6 of the Agreement, namely, to deliver, secure, support and quality-assure the Engineer Services, train Drytis personnel in the delivery of Engineer Services, investigate abuse and security incidents, resolve disputes, substantiate Usage Charges, and comply with applicable law. Where a purpose in this paragraph can reasonably be achieved using de-identified or redacted data, Drytis will use de-identified or redacted data.
d) Other Personal Data within Engineer Session Data - Engineer Session Data also contains Personal Data that is not within Workspace Content, including the identity, voice, image, and interaction records of Session participants. Drytis Processes that data as a Processor for the purpose of delivering, securing, supporting and quality-assuring the Engineer Services, and as an independent controller for the limited purposes of training its own personnel, investigating abuse and security incidents, resolving disputes, substantiating Usage Charges, and complying with applicable law, in each case as stated in Section 9.6 of the Agreement and in accordance with the Privacy Policy. Drytis does not Process Session voice or image capture for the purpose of uniquely identifying an individual. Section 9.6 of the Agreement allocates responsibility for participant notices and consents: Drytis in respect of its own personnel, and Customer in respect of its Authorized Users and any other participants it involves.
2.9. Aggregated and de-identified information - Drytis may create and use Usage Data, and aggregated or de-identified information derived solely from operation of the Services and not from the substantive content of Workspace Content, on the terms of Section 15.3 of the Agreement. Drytis will maintain that information in de-identified form, will not attempt to re-identify it except as applicable law permits for the purpose of testing the effectiveness of its de-identification measures, and will contractually obligate any recipient of that information to the same restriction, including a prohibition on further disclosure except on equivalent terms.
3. CONFIDENTIALITY
Drytis will ensure that persons authorized to Process Customer Personal Data, including personnel, contractors, Engineers, and Sub-processor personnel, are subject to written or statutory obligations of confidentiality that survive the end of their engagement, and will limit access to those who need it to provide the Services. Customer Personal Data is Customer's Confidential Information under Section 16 of the Agreement, and Section 16 governs the parties' confidentiality obligations generally.
4. SECURITY OF PROCESSING
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects, Drytis will implement and maintain the technical and organizational measures described in Appendix 2 to protect Customer Personal Data against a Personal Data Breach, and will maintain those measures throughout the period in which it Processes Customer Personal Data. Drytis may update its security measures from time to time to address evolving risk and technology, provided that no update materially decreases the overall level of protection of Customer Personal Data, consistent with Section 18.1 of the Agreement.
Security is a shared responsibility as Section 18.2 of the Agreement provides. The parties allocate responsibility as follows: Drytis is responsible for the measures in Appendix 2; Customer is responsible for its own use and configuration of the Services, including the controls described in Section 6.3 of the Agreement, access management, secrets hygiene, integration scopes, and session-access controls. This allocation constitutes the parties' agreed allocation of security responsibilities for the purposes of Data Protection Laws that require one.
5. SUB-PROCESSORS
5.1. General authorization - Customer generally authorizes Drytis to engage Sub-processors to Process Customer Personal Data in connection with the Services. Drytis will maintain a current list of Sub- processors and will provide notice of additions or replacements in accordance with Section 5.3.
5.2. Flow-down and responsibility - Drytis will engage each Sub-processor under a written agreement imposing data-protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services that Sub-processor provides, including the Model Training restriction in Section 2.7 where the Sub-processor is a Model Provider. On Customer's written request, Drytis will provide a copy of that agreement, with commercial terms and other information not necessary to assess data protection redacted. Drytis remains responsible for its Sub-processors' performance of those obligations, subject to the exclusions and limitations of liability in the Agreement.
5.3. Notice and objection - Drytis will give Customer at least thirty (30) days' prior notice of any intended addition or replacement of a Sub-processor, by updating the list and, where Customer has subscribed, by email. That notice gives Customer an opportunity to object. Customer may object on reasonable, documented data-protection grounds within fifteen (15) days of the notice, in which case the parties will work in good faith to address the objection, including by considering a commercially reasonable alternative configuration of the Services. If the objection cannot reasonably be resolved, Customer may, as its sole remedy, terminate the affected Services on written notice and receive a refund of the prepaid, unused Subscription Fees allocable to those Services for the remainder of the then-current Subscription Term.
5.4. Urgent appointments - Drytis may engage a new Sub-processor without advance notice where reasonably necessary to address an urgent security, availability, or legal risk, and will notify Customer promptly afterwards. Section 5.3 then applies from the date of that notice.
5.5. Customer-enabled third-party services - Third-party products and services that Customer connects or enables under Section 12 of the Agreement are not Drytis Sub-processors. By enabling an integration, Customer instructs Drytis to transmit and receive the data necessary to operate it within the scope Customer has authorized, and Section 12.2 of the Agreement governs responsibility for that provider's handling of the data once transmitted.
6. DATA SUBJECT RIGHTS
6.1. Assistance - Taking into account the nature of the Processing, Drytis will assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, to fulfill Customer's obligations to respond to Data Subject requests under Data Protection Laws, including requests for access, correction, deletion, restriction of Processing, portability, objection, opt-out of Sale or Sharing, and rights relating to automated decision-making. Drytis provides this assistance primarily through the functionality of the Services and will provide reasonable additional assistance where that functionality is not sufficient.
6.2. Requests received by Drytis - If Drytis receives a request directly from a Data Subject in respect of Customer Personal Data, Drytis will not respond other than to confirm that the request relates to Customer, and will, to the extent legally permitted, promptly forward it to Customer. Customer remains responsible for responding to its own Data Subjects and, as Section 11.1 of the Agreement provides, to the end users of its Deployed Applications.
6.3. Stop-processing directions - On Customer's written direction given in response to an authenticated Data Subject or Consumer request, Drytis will cease Processing the identified Customer Personal Data to the extent and for the period the direction specifies, subject to Section 9.5.
6.4. Charges - Drytis may charge for assistance under this Section that is unreasonable or excessive, to the extent permitted by law.
7. PERSONAL DATA BREACH
7.1. Notification - Drytis will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, consistent with Section 17.6 of the Agreement.
7.2. Content - The notification will describe, to the extent then known and reasonably available, the nature of the breach, the categories and approximate number of affected Data Subjects and records, the likely consequences, and the measures taken or proposed. Drytis will provide further information as it becomes available.
7.3. Response and cooperation- Drytis will take reasonable steps to investigate, contain, mitigate and remediate the breach, will preserve relevant logs and evidence, and will provide reasonable cooperation to enable Customer to meet its own notification obligations to Supervisory Authorities, Data Subjects, and other regulators. Section 18.3 of the Agreement applies to security-incident cooperation generally.
7.4. No admission - Drytis's notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.
8. IMPACT ASSESSMENTS, CONSULTATIONS AND REGULATORY INQUIRIES
Taking into account the nature of the Processing and the information available to it, Drytis will provide reasonable assistance to Customer with data protection impact assessments, risk assessments, cybersecurity audits, prior consultations with Supervisory Authorities, and responses to inquiries or investigations by Supervisory Authorities or other regulators, in each case where Data Protection Laws require the assessment, audit or response, solely in relation to Drytis's Processing of Customer Personal Data, and to the extent Customer cannot reasonably obtain the relevant information itself. Drytis will make available the facts necessary for those assessments and audits and will not misrepresent them. Drytis may charge for assistance that is unreasonable or excessive, to the extent permitted by law.
9. RETURN AND DELETION OF CUSTOMER PERSONAL DATA
9.1. Export during the term - Customer may export Customer Personal Data at any time using the export functionality then available in the Services, subject to the Agreement and applicable security and technical constraints.
9.2. Post-termination export - Section 20.7 of the Agreement governs the post-termination export period, which is thirty (30) days from the effective date of expiration or termination, and not less than seven (7) days under a supervised or controlled process where Drytis terminates for cause under Section 20.5(b). Customer is responsible for exporting within that period any Customer Personal Data it wishes to retain.
9.3. Deletion or return at Customer's choice - At Customer's written direction, given at any time before the end of the applicable export period, Drytis will delete, or return and then delete, Customer Personal Data in its possession, and will instruct its Sub-processors to do the same. Drytis will comply within thirty (30) days of the direction, or within thirty (30) days of the end of the export period where the direction is given earlier and will confirm completion in writing on request. Where return is requested, Drytis will provide the data in the formats the export functionality of the Services supports.
9.4. Default deletion - Where Customer gives no direction under Section 9.3, Drytis may delete Customer Personal Data from its active systems after the applicable export period, as Section 20.7 of the Agreement provides.
9.5. Backups and permitted retention - Backup and disaster-recovery copies persist until deleted or overwritten in the ordinary course of Drytis's retention practices, and will not be actively Processed except as necessary for restoration, disaster recovery, security, or legal compliance. Drytis may retain Customer Personal Data for so long as required by applicable law or reasonably necessary to comply with legal obligations, resolve disputes, enforce the Agreement, or protect the security and integrity of the Services. Customer Personal Data retained under this Section remains subject to this DPA for as long as it is retained.
10. AUDITS AND COMPLIANCE INFORMATION
10.1. Compliance information - Drytis will make available to Customer the information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the GDPR and equivalent provisions of Data Protection Laws. This includes Drytis's security documentation and completed responses to a reasonable security questionnaire, and, where Drytis holds them, third-party audit reports, certifications or attestations, provided subject to confidentiality obligations. As Section 18.1 of the Agreement provides, Drytis makes no representation regarding compliance with any particular security framework, standard, certification, or audit report except as expressly stated.
10.2. Audits - To the extent Customer's audit rights under Data Protection Laws are not satisfied by Section 10.1, Drytis will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer and reasonably acceptable to Drytis, subject to the following: at least thirty (30) days' prior written notice; no more than once in any twelve-month period, except where required by a Supervisory Authority or following a Personal Data Breach affecting Customer Personal Data; during normal business hours; subject to confidentiality obligations; without unreasonable disruption to Drytis's operations; and at Customer's expense.
10.3. The auditor may not access the data of any other customer, or Drytis's Confidential Information, including the security architecture and assessment materials identified in Section 16.1 of the Agreement, beyond what is strictly necessary for the audit. Penetration testing, vulnerability scanning, and other intrusive testing are not permitted under this Section and are governed by Section 5.2(c) and Section 18.4 of the Agreement and Section 10 of the AUP.
10.4. Independent assessment - Where Data Protection Laws permit, Drytis may satisfy Section 10.2 by arranging, at its own expense and at least annually, for a qualified and independent assessor to assess Drytis's policies and technical and organizational measures against an appropriate and accepted control standard, framework and assessment procedure, and by providing the resulting report to Customer on request. Where applicable law conditions this alternative on Customer's agreement, Drytis will use it only with Customer's consent.
11. INTERNATIONAL DATA TRANSFERS
11.1. Processing locations - Drytis is established in the United States. Drytis may Process Customer Personal Data in the United States and in other countries in which Drytis, its Affiliates, or its Sub- processors operate, as Section 17.4 of the Agreement provides, in each case using a valid transfer mechanism where Data Protection Laws require one. Processing locations are identified in Appendix 3.
11.2. EEA transfers - Where a Restricted Transfer is subject to the GDPR, the EU SCCs are incorporated by reference and completed as set out in Appendix 4. Module Two (Controller to Processor) applies where Customer is a controller and Drytis is a processor. Module Three (Processor to Processor) applies where Customer is a processor and Drytis is a sub-processor. By accepting the Agreement, each party is deemed to have signed the SCCs, including their Annexes, as of the effective date of the Agreement.
11.3. UK transfers - Where a Restricted Transfer is subject to the UK GDPR, the UK Addendum is incorporated by reference and completed as set out in Appendix 4.B.
11.4. Swiss transfers- Where a Restricted Transfer is subject to the FADP, the EU SCCs apply with the amendments set out in Appendix 4.C.
11.5. Onward transfers - Drytis will ensure that onward transfers of Customer Personal Data to its Sub- processors are subject to appropriate safeguards as Data Protection Laws require, in accordance with Clause 8.8 of the EU SCCs.
11.6. Transfer risk assessments - On Customer's reasonable request, Drytis will provide the information within its possession that Customer reasonably requires to carry out a transfer risk assessment under Clause 14 of the EU SCCs or an equivalent assessment under the UK GDPR or the FADP, including information about the laws and practices of the destination country relevant to the transfer and about government access requests Drytis is permitted to disclose. Drytis will notify Customer as required by Clause 15 of the EU SCCs.
11.7. Alternative and successor mechanisms - Where and for so long as available and applicable, Drytis may instead rely on an adequacy decision or on an active self-certification under the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework, on the terms of Appendix 4.D. If the European Commission, the UK Information Commissioner, or the Swiss Federal Data Protection and Information Commissioner adopts a replacement or additional set of standard contractual clauses, including clauses applicable where the data importer's Processing is directly subject to the GDPR under Article 3(2), the parties will implement those clauses in place of or in addition to the SCCs within the period the adopting authority specifies, and Section 15.3 applies to that change.
11.8. Conflict - In the event of a conflict between this DPA and the SCCs, the SCCs prevail with respect to the transfers they govern.
12. GOVERNMENT AND THIRD-PARTY REQUESTS
If Drytis receives a legally binding request from a government authority or other third party for disclosure of Customer Personal Data, Drytis will, unless legally prohibited, notify Customer and redirect the requesting party to Customer. Drytis will assess each request for validity, will use reasonable efforts to challenge requests that are unlawful, overbroad, or inconsistent with Data Protection Laws, and will disclose only the minimum Customer Personal Data necessary to respond. Where notice is prohibited, Drytis will use reasonable efforts to obtain a waiver and will document its efforts for provision to Customer where permitted. Section 16.4 of the Agreement applies to compelled disclosure of Confidential Information generally. This Section does not apply to, and does not delay, the reporting and preservation measures described in Section 2.2.
13. CCPA AND U.S. STATE PRIVACY LAWS
This Section applies where Drytis Processes Customer Personal Data as a Service Provider under the CCPA or as a processor under another U.S. state privacy law.
13.1. Business Purposes - Customer discloses Customer Personal Data to Drytis only for the following limited and specified business purposes: providing, operating, hosting, maintaining, securing and supporting the Services; generating Generated Output and hosting and serving Deployed Applications at Customer's direction; delivering Engineer Services Customer requests, including the purposes stated in Section 2.8(c); troubleshooting and error correction; metering and substantiating Fees; detecting, investigating and preventing security incidents, fraud, abuse, and violations of the Agreement or the AUP; and complying with applicable law (the "Business Purposes"). Drytis Processes Customer Personal Data solely for the Business Purposes and as otherwise permitted by the CCPA.
13.2. Restrictions - Drytis will not: (a) Sell or Share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose, including any commercial purpose, other than the Business Purposes, or outside the direct business relationship between the parties, except as the CCPA permits; or (c) combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from Drytis's own interactions with a Consumer, except as the CCPA permits. Customer's disclosure of Customer Personal Data to Drytis is not a Sale or a Share, and Drytis provides no monetary or other valuable consideration for it. Drytis certifies that it understands and will comply with the restrictions in this Section.
13.3. Level of protection - Drytis will comply with the applicable obligations of the CCPA and will provide the same level of privacy protection to Customer Personal Data as the CCPA requires of businesses, including by implementing reasonable security procedures and practices appropriate to the nature of the data. Drytis will cooperate with and assist Customer in relation to any cybersecurity audit and any risk assessment the CCPA requires of Customer that concerns Drytis's Processing of Customer Personal Data and will comply with the CCPA's requirements governing automated decision-making technology to the extent they apply to Drytis's Processing. To the extent Sensitive Personal Information is nonetheless present in Customer Personal Data, Drytis will use it only for purposes the CCPA permits.
13.4. Consumer requests - Drytis will enable Customer to comply with Consumer requests under the CCPA, through the functionality of the Services and the assistance described in Sections 6 and 9. Customer will inform Drytis of any Consumer request requiring action by Drytis and will provide the information necessary for Drytis to act on it. Where Customer notifies Drytis of a Consumer's request to opt out of automated decision-making technology, Drytis will comply within fifteen (15) business days of receiving the notification.
13.5. Monitoring and remediation - Customer may take reasonable and appropriate steps to ensure that Drytis Processes Customer Personal Data consistently with Customer's obligations under the CCPA, using the mechanisms in Section 10. Drytis will notify Customer if it determines that it can no longer meet its obligations under the CCPA, and Customer may, on notice, take reasonable and appropriate steps to stop and remediate any unauthorized Processing.
13.6. Subcontractors - Drytis will engage each Sub-processor that Processes Customer Personal Data under a written contract that complies with the CCPA and its implementing regulations, including this Section 13, and will require each Sub-processor to impose equivalent terms on any further subcontractor it engages.
13.7. Other U.S. state privacy laws - Where another U.S. state privacy law applies to Drytis as a processor, Drytis will: adhere to Customer's instructions; ensure that each person Processing Customer Personal Data is subject to a duty of confidentiality; establish, implement and maintain reasonable administrative, technical and physical security practices appropriate to the volume and nature of the Customer Personal Data, as described in Appendix 2; assist Customer with consumer rights requests, security of Processing, breach notification, and data protection assessments, including by providing the information necessary for Customer to conduct and document them; cease Processing at Customer's direction under Section 6.3; at Customer's direction, delete or return Customer Personal Data under Section 9.3; make available the information reasonably necessary to demonstrate compliance under Section 10.1; allow and cooperate with reasonable assessments under Sections 10.2 and 10.3; and engage subcontractors under written contracts in accordance with Section 5.2, after providing Customer the opportunity to object under Section 5.3.
13.8. No sale of sensitive data - Drytis will not Sell or Share Customer Personal Data, and will not sell sensitive data, as those terms are defined under any applicable U.S. state privacy law.
14. LIABILITY
Each party's liability arising out of or relating to this DPA, whether in contract, tort, or under any other theory, is subject to the exclusions, limitations, and carve-outs in Sections 22 and 23 of the Agreement. Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws or under the SCCs.
15. GENERAL
15.1. Precedence - Order of precedence is governed by Section 1.5 of the Agreement. This DPA controls over the Terms of Service solely with respect to the Processing of Customer Personal Data. The SCCs prevail over this DPA with respect to the transfers they govern.
15.2. Term - This DPA takes effect on the effective date of the Agreement and remains in effect for as long as Drytis Processes Customer Personal Data. Its provisions survive expiration or termination of the Agreement to that extent, consistent with Section 20.8 of the Agreement.
15.3. Changes - Drytis may modify this DPA in accordance with Section 1.6 of the Agreement, including to comply with Data Protection Laws or to adopt updated Standard Contractual Clauses or transfer mechanisms. No modification will materially reduce the protection afforded to Customer Personal Data.
15.4. Governing law and dispute resolution - This DPA is governed by the law and subject to the dispute- resolution provisions of Section 25 of the Agreement, except where Data Protection Laws or the SCCs require otherwise. Section 25 of the Agreement does not apply to, and does not limit, the rights of Data Subjects or Supervisory Authorities under the SCCs, including the choice of forum and jurisdiction in Clause 18 of the EU SCCs and the equivalent provisions of the UK Addendum.
15.5. Third-party rights - Notwithstanding Section 27.4 of the Agreement, the SCCs confer enforceable third-party beneficiary rights on Data Subjects to the extent the SCCs provide, and nothing in the Agreement limits those rights.
15.6. Affiliates - Customer Affiliates permitted to use the Services under the Agreement receive the benefit of this DPA. Customer exercises the rights under this DPA on behalf of its Affiliates, and any claim by an Affiliate may be brought only by Customer.
15.7. Contact - Data-protection inquiries may be directed to legal@drytis.com, or by mail to Drytis, Inc., 1985 Riviera Dr, Ste 103 - 1033, Mount Pleasant, SC 29464, United States.
APPENDIX 1 — DETAILS OF PROCESSING
A. List of Parties
| Party | Details |
|---|---|
| Data Exporter / Controller / Business: Customer | Name, address and contact: as set out in the Agreement and Customer's Account. Activities relevant to the transfer: use of the Services to build, host, deploy and operate software and Deployed Applications, and to obtain Engineer Services. Role: Controller, or processor where Customer acts for a third-party controller. Signature and date: as stated in Section 11.2. |
| Data Importer / Processor / Service Provider: Drytis | Drytis, Inc., 1985 Riviera Dr, Ste 103 - 1033, Mount Pleasant, SC 29464, United States. Contact: legal@drytis.com, Attn: Legal. Activities relevant to the transfer: provision of the development, AI, hosting, deployment and Engineer Services described in the Agreement. Role: Processor. Signature and date: as stated in Section 11.2. |
B. Description of the Processing
| Item | Description |
|---|---|
| Categories of Data Subjects | Customer's Authorized Users and personnel; and individuals whose Personal Data is contained in Workspace Content or in data processed by Customer's Deployed Applications, which may include Customer's end users, customers and contacts. |
| Categories of Personal Data | Identifiers and contact data; account and profile data; the content of prompts, instructions, source code, configuration files, datasets and Generated Output that Customer includes in Workspace Content; and any other Personal Data Customer chooses to include in Workspace Content. |
| Sensitive Data | Not intended to be Processed. Section 2.3 of this DPA and Section 17.5 of the Agreement prohibit the submission of special-category data, Sensitive Personal Information, and the listed categories of regulated data unless Drytis has expressly designated the applicable Service as approved and the parties have executed any additional agreement that category requires. |
| Frequency | Continuous, for the duration of the Agreement. |
| Nature and Purpose | Processing for the purposes set out in Section 2.5, including AI-assisted code generation, hosting, deployment, version history, and Engineer Services, in accordance with Customer's instructions. Model Training is governed by Section 2.7 of this DPA and Section 7.4 of the Agreement. |
| Duration | For the term of the Agreement and any retention period thereafter under Section 9 of this DPA and Section 20.7 of the Agreement. |
| Sub-processor Processing | Sub-processors Process Customer Personal Data for the purposes and durations described in Appendix 3 and this DPA. |
C. Competent Supervisory Authority
Where the EU SCCs apply, the competent Supervisory Authority is determined under Clause 13 of the EU SCCs: (i) where Customer is established in an EEA Member State, the Supervisory Authority of that Member State; (ii) where Customer is not established in an EEA Member State but falls within Article 3(2) of the GDPR and has appointed an Article 27 representative, the Supervisory Authority of the Member State in which that representative is established; and (iii) where Customer is not established in an EEA Member State and is not required to appoint a representative, the Supervisory Authority of a Member State in which the relevant Data Subjects are located. Customer will identify the applicable Supervisory Authority on request.
For the United Kingdom, the competent authority is the Information Commissioner's Office. For Switzerland, the competent authority is the Federal Data Protection and Information Commissioner.
APPENDIX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES
Drytis maintains a security program that includes the following measures, some of which are delivered through its cloud-infrastructure providers.
Access control - Role-based, least-privilege and need-to-know access; unique credentials; multi-factor authentication for administrative access; and prompt revocation on role change or departure.
Engineer access control - Scoped, time-limited Session access consistent with Sections 9.2 through 9.4 of the Agreement, with session-level logging and revocation on completion.
Secrets handling - Protections for credentials and environment variables Customer elects to store, including encryption and restricted access, consistent with Sections 6.3 and 9.3 of the Agreement.
Minimization and pseudonymization - Data-minimization practices and pseudonymization or de- identification where appropriate.
Network and application security - Firewalls, network segmentation, secure configuration, and protections against common application vulnerabilities.
Secure development - A secure software-development lifecycle, code review, dependency management, and change control.
Vulnerability and patch management - Regular vulnerability scanning, periodic penetration testing, and severity-based remediation.
Logging and monitoring - Logging of access and security-relevant events, monitoring for anomalous activity, and alerting.
Resilience and recovery - Backups, redundancy, and the ability to restore availability and access to Personal Data in a timely manner after an incident, including workspace version history.
Incident response - A documented incident-response and breach-notification process, including the obligations in Section 7.
Personnel security - Confidentiality obligations, security and privacy training, and, where permitted by applicable law, background screening for personnel and Engineers.
Physical security - Physical and environmental safeguards at the data-center facilities operated by Drytis's infrastructure providers.
Vendor management - Assessment and contractual controls for Sub-processors as described in Section 5.
Testing and review - Regular testing, assessment and evaluation of the effectiveness of these measures.
APPENDIX 3 — SUB-PROCESSORS
Drytis engages the Sub-processors below to Process Customer Personal Data. The current list is maintained under Section 5.1, and changes are notified under Section 5.3.
| Entity | Service | Role | Processing location |
|---|---|---|---|
| Cloud Infrastructure and Hosting Provider | Hosting, storage and compute for the Services and Deployed Applications | Sub-processor | Virginia, USA |
| Model Provider(S) | AI Features, including code generation and related functionality | Sub-processor | Virginia, USA |
| Email And Communications Provider | Transactional and service communications | Sub-processor | Virginia, USA |
| Analytics And Error-Monitoring Provider | Diagnostics, performance monitoring and security | Sub-processor | Virginia, USA |
| Customer Support Tooling Provider | Support ticketing and communications | Sub-processor | Virginia, USA |
| Payment Processor | Billing and payment processing | Sub-processor | Virginia, USA |
APPENDIX 4 — CROSS-BORDER TRANSFER MECHANISMS
EU Standard Contractual Clauses — Elections
Modules. Module Two (Controller to Processor) applies where Customer acts as a controller and Drytis as a processor. Module Three (Processor to Processor) applies where Customer acts as a processor for a third-party controller and Drytis as a sub-processor. Onward transfers by Drytis to its Sub-processors are governed by Clause 8.8 and by separate transfer mechanisms concluded between Drytis and the relevant Sub-processor.
Clause 7 (Docking clause). Applies.
Clause 9 (Use of sub-processors). Option 2, general written authorization, applies, with the thirty (30) day notice period specified in Section 5.3.
Clause 11 (Redress). The optional independent dispute-resolution language does not apply.
Clause 13 and Annex I.C (Competent supervisory authority). Determined as set out in Appendix 1.C.
Clause 17 (Governing law). The EU SCCs are governed by the law of Ireland.
Clause 18 (Choice of forum and jurisdiction). Disputes arising from the EU SCCs are resolved before the courts of Ireland, without prejudice to Clause 18(c).
Annexes. Annex I is populated by Appendix 1 and Annex II by Appendix 2. Annex III does not apply, because Option 2 of Clause 9(a) is elected; Appendix 3 is provided for information.
B. UK International Data Transfer Addendum The UK Addendum applies to Restricted Transfers subject to the UK GDPR. Table 1 is completed by Appendix 1.A. Table 2 identifies the EU SCCs and the Modules elected in paragraph A as the Approved EU SCCs. Table 3 is completed by Appendices 1 and 2. In Table 4, the parties elect that neither Party may end the UK Addendum as set out in Section 19 of the UK Addendum. The UK Addendum is governed by the laws of England and Wales, and the courts of England and Wales have jurisdiction, in accordance with its terms.
C. Swiss Amendments For Restricted Transfers subject to the FADP, the EU SCCs apply with the following amendments:
• references to the GDPR are read as references to the FADP, and references to EU or Member State law are read as references to Swiss law, in each case to the extent the FADP governs the transfer;
• the competent Supervisory Authority is the Federal Data Protection and Information Commissioner, and where a transfer is subject to both the GDPR and the FADP, each authority is competent for the Processing its law governs;
• references to EU Member States and to the courts of EU Member States do not prevent Data Subjects in Switzerland from bringing proceedings in Switzerland, in accordance with Clause 18(c) of the EU SCCs;
• "Personal Data" is interpreted in accordance with the FADP, which protects the data of natural persons; and
• Drytis will notify Customer of a Personal Data Breach under Section 7 so that Customer may make any notification required to the Federal Data Protection and Information Commissioner.
D. Data Privacy Framework Where Drytis holds and maintains an active self-certification under the EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework, Drytis may rely on that certification in place of the SCCs for the transfers it covers. If a certification lapses or is withdrawn, the SCCs and this Appendix 4 apply to those transfers.