# Data Processing Addendum

Version: 2026-08-05

This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between the customer identified in the Agreement (“Customer”) and d5s B.V. (“d5s”), for services under which d5s processes Customer Personal Data. This DPA is accepted together with the Agreement. No signature is required. A copy signed by d5s is available on request to legal@d5s.tech.

## 1. Definitions

“Applicable Data Protection Law” means the GDPR and other data-protection law applicable to the relevant processing.

“Customer Personal Data” means personal data contained in Customer Content that d5s processes on Customer's behalf under the Agreement.

“Controller”, “data subject”, “personal data”, “personal data breach”, “processing”, “processor”, “supervisory authority”, and “subprocessor” have the meanings in Applicable Data Protection Law.

“GDPR” means Regulation (EU) 2016/679.

“Capitalised terms” not defined in this DPA have the meaning given in the Agreement.

“SCCs” means the European Commission standard contractual clauses for transfers to third countries adopted by Decision (EU) 2021/914, as updated or replaced.

## 2. Roles and scope

Customer is controller of Customer Personal Data and d5s is processor, except where Customer acts as a processor for another controller, in which case d5s is Customer's subprocessor.

Each party will comply with Applicable Data Protection Law for its role. Customer is responsible for the lawfulness, fairness, transparency, accuracy, and minimisation of Customer Personal Data; required notices and legal bases; and the legality of its instructions.

This DPA does not govern personal data for which d5s independently determines purposes and means, such as account administration, billing, security, legal compliance, and business communications described in the Privacy Notice.

## 3. Processing details

The subject matter, duration, nature, purpose, personal-data types, and data-subject categories are described in Annex 1 and the Agreement. Customer may provide further documented instructions through authorised configuration and use of the Service, support requests, and an Order or SOW agreed by the parties.

## 4. Documented instructions

d5s will process Customer Personal Data only:

1. on Customer's documented instructions;
2. to provide, secure, maintain, and support the ordered Service; and
3. as required by Union or Member State law applicable to d5s.

If law requires processing beyond Customer's instructions, d5s will inform Customer before processing unless the law prohibits notice on important grounds of public interest.

d5s will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. d5s may suspend the affected processing until the parties resolve the issue and is not required to perform an unlawful instruction.

## 5. Confidentiality and personnel

d5s will ensure that persons authorised to process Customer Personal Data:

- process it only as necessary for their duties and the documented instructions;
- are bound by confidentiality or an appropriate statutory duty; and
- receive proportionate privacy and security guidance.

d5s will limit access according to role and business need and will remain responsible for its personnel's compliance with this DPA.

## 6. Security

Taking account of the state of the art, implementation cost, scope, context, purposes, and risks, d5s will implement and maintain appropriate technical and organisational measures under Article 32 GDPR.

The measures applicable to the ordered Service are described in Annex 2, or in a security schedule expressly incorporated in an Order Form. d5s may update measures provided the overall protection is not materially reduced during the Agreement.

Customer is responsible for using available security controls, managing access and connectors, protecting credentials and endpoints, and making backups or exports where not expressly included in the Service.

## 7. Personal data breaches

d5s will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification will include information reasonably available to d5s concerning:

1. the nature of the breach, including affected categories and approximate numbers where known;
2. likely consequences;
3. measures taken or proposed to address and mitigate it; and
4. a contact for follow-up.

Information may be provided in phases. d5s will take reasonable steps to contain, investigate, remediate, and document the breach and will reasonably assist Customer with legally required notifications. Notification is not an admission of fault or liability.

Customer is responsible for determining whether and how to notify authorities or data subjects unless law assigns that duty directly to d5s.

## 8. Subprocessors

Customer gives general written authorisation for d5s to use the subprocessors identified in the approved Subprocessor List for the Service.

d5s will:

- impose data-protection obligations that provide materially equivalent protection for Customer Personal Data;
- remain responsible for each subprocessor's performance of those obligations to the extent required by law; and
- provide at least 30 days' advance notice of a new subprocessor that will process Customer Personal Data, except where urgent replacement is reasonably necessary for security, continuity, or law.

Customer may object during the notice period on reasonable data-protection grounds, explaining the objection. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate the affected feature or Service, and d5s will refund prepaid fees for the unused terminated portion.

A third-party integration that Customer independently enables and instructs d5s to contact is a Customer-directed recipient and is not necessarily a d5s subprocessor.

## 9. Data-subject requests

Taking account of the nature of processing, d5s will provide reasonable technical and organisational assistance for Customer to respond to requests to exercise data-subject rights.

If d5s receives a request relating to Customer Personal Data, d5s will, where legally permitted, redirect it to Customer and not respond substantively except on Customer's instruction or as required by law. Customer is responsible for responding and for verifying the requester.

Additional assistance outside standard Service functionality may be charged at agreed rates where permitted, unless required because of d5s's breach.

## 10. DPIAs and consultations

Taking account of the nature of processing and information available to d5s, d5s will provide reasonable assistance with Customer's data-protection impact assessments and prior consultations required under Articles 35 and 36 GDPR for use of the Service.

Customer remains responsible for deciding whether a DPIA or consultation is required and for the substance of its assessment.

## 11. Deletion and return

During the term, Customer may retrieve Customer Personal Data through available Service functionality, subject to the Agreement.

After termination or on Customer's documented request, d5s will delete or return Customer Personal Data, at Customer's choice, unless Union or Member State law requires storage. The operational timelines and backup behavior are:

- customer retrieval period: 30 days after termination, unless the Order states another period;
- deletion from active systems: within 30 days after the retrieval period ends or after an earlier valid deletion instruction;
- expiry from protected backups and non-current object versions: within seven days after active-system deletion;
- legally preserved records: isolated and processed only for the required purpose and period.

d5s may delete Customer Personal Data after the retrieval period. An authorised d5s representative will provide reasonable confirmation of deletion on request.

## 12. Information and audits

d5s will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, which may include current security documentation, independent assessment reports, certifications, or questionnaire responses where they exist.

No more than once per 12-month period, and additionally after a material incident or where required by a supervisory authority, Customer may request an audit of relevant processing. The parties will first use available reports and documentation. If those are insufficient, d5s will allow a mutually agreed remote or on-site audit by Customer or an independent auditor that:

- is bound by confidentiality and is not a competitor;
- gives at least 10 business days' notice unless urgent;
- occurs during normal business hours without unreasonable disruption;
- is limited to systems and records relevant to Customer Personal Data; and
- does not expose another customer's data or compromise security.

Customer bears reasonable audit costs unless the audit identifies a material breach by d5s. Nothing requires d5s to disclose information that would create a security risk, violate law, or breach another party's confidentiality; d5s will provide a reasonable alternative where possible.

## 13. International transfers

d5s will not transfer Customer Personal Data to a country outside the EEA unless it uses a lawful transfer mechanism.

Where the SCCs are required for a transfer by Customer to d5s, the applicable module is:

- Module Two where Customer is controller and d5s is processor;
- Module Three where Customer is processor and d5s is subprocessor.

The SCCs are incorporated by reference without modification using the selections and annex information in Annex 3. If this DPA conflicts with the SCCs, the SCCs prevail for the transfer.

Where an adequacy decision or another valid mechanism covers the transfer, that mechanism applies instead for as long as it remains valid. d5s will provide reasonable information needed for a transfer impact assessment and implement agreed supplementary measures where required.

## 14. Government requests

Unless prohibited, d5s will notify Customer of a binding government request for Customer Personal Data. d5s will review the request, challenge it where there are reasonable grounds, seek to limit disclosure, and disclose only what it reasonably believes is legally required.

## 15. Records and regulatory cooperation

d5s will maintain records required for its role under Applicable Data Protection Law and will cooperate with competent supervisory authorities as required.

## 16. Liability and precedence

Liability under this DPA is subject to the Agreement's exclusions and limitations unless Applicable Data Protection Law requires otherwise. Nothing in the Agreement limits a data subject's rights or either party's regulatory obligations.

For data-protection subject matter, this DPA prevails over conflicting Agreement terms. The SCCs prevail over both for the transfers they govern.

## 17. Term

This DPA begins when d5s first processes Customer Personal Data under the Agreement and continues until d5s has deleted or returned it in accordance with this DPA.

## Annex 1 — Processing description

### A. Subject matter and duration

Provision of the d5s collaborative AI agent workspace and ordered support/professional services for the Agreement term, plus the retrieval and deletion periods stated above.

### B. Nature and purpose

Hosting, storing, organising, retrieving, transmitting, displaying, analysing, generating, securing, troubleshooting, backing up where applicable, and deleting Customer Personal Data to perform Customer's instructions and provide the Service.

### C. Categories of data subjects

May include Customer's authorised users, personnel, contractors, customers, prospects, suppliers, partners, website users, correspondents, and individuals whose information Customer lawfully submits or makes accessible through an integration.

### D. Types of personal data

May include identity and contact data; business and employment data; account and authentication identifiers; communications; documents and files; prompts, messages, instructions, tool results, and generated outputs; usage and audit data; technical/device data; and other personal data Customer chooses to submit.

Special-category, criminal-offence, children's, biometric-identification, precise-location, payment-card, patient, or similarly high-risk data is not authorised unless expressly identified in an Order with appropriate instructions and safeguards.

### E. Frequency

Continuous or as initiated by Customer and authorised users during the Service term.

### F. Customer instructions

The Agreement, configured use of the Service, authorised support requests, and further written instructions agreed by the parties.

## Annex 2 — Technical and organisational measures

1. **Governance:** assigned security and privacy responsibility, documented policies, risk review, personnel confidentiality, and proportionate guidance.
2. **Access control:** unique identities, authenticated access, role-based permissions, least privilege, restricted administrative access, and removal or suspension when access is no longer authorised.
3. **Tenant and workload isolation:** organisation and workspace authorisation boundaries, private service networking, per-session sandbox isolation, and scoped storage credentials.
4. **Encryption and secrets:** TLS for supported external and service communications; encrypted object storage, secrets, and credentials using provider-managed or d5s-managed keys; access-restricted backup material; and private networking and access controls for database and in-cluster stores.
5. **Secure development:** protected source control, reviewed changes, automated tests, dependency controls, secret scanning, encrypted production configuration, and vulnerability remediation.
6. **Logging and monitoring:** security and audit events, scrubbed error monitoring, infrastructure metrics and logs, operational alerting, access restrictions, and the retention periods stated in the Privacy Notice.
7. **Availability and recovery:** automated database backups, versioned object storage, restoration procedures, workload restart and reconciliation processes, and incident recovery appropriate to the Service. No RTO or RPO is promised unless stated in an Order.
8. **Incident response:** documented detection, escalation, containment, investigation, remediation, evidence preservation, and Customer-notification procedures.
9. **Subprocessor management:** a maintained Subprocessor List, contractual data-protection terms, 30-day change notice, objection handling, and periodic reconciliation against active providers.
10. **Deletion and media handling:** authenticated deletion workflows, retryable external-object cleanup, retention enforcement, anonymisation of durable records, seven-day backup/non-current-version expiry, and deletion reapplication after restore.
11. **Customer controls:** workspace roles, connector authorisation, model and no-training choices, approval boundaries, audit visibility, export, and deletion features included in the ordered plan.
12. **Physical security:** reliance on the reviewed physical and environmental controls of the hosting and infrastructure providers identified in the Subprocessor List.

## Annex 3 — SCC selections and competent authority

The following selections apply only where the SCCs are required for the relevant transfer:

- data exporter(s): Customer and any Customer affiliates identified in the Agreement, using their address and privacy contact stated in the Order or account record;
- data importer: d5s B.V., Nieuwezijds Voorburgwal 104-108, 1012 SG Amsterdam, the Netherlands;
- module: Module Two when Customer is controller and d5s is processor; Module Three when Customer is processor and d5s is subprocessor;
- Clause 7 docking clause: included;
- Clause 9 subprocessor authorisation and notice period: Option 2, general written authorisation with 30 days' notice;
- Clause 11 optional redress: excluded;
- Clause 17 governing law: Netherlands;
- Clause 18 courts: the competent courts of the Netherlands;
- Annex I transfer details: the processing described in Annex 1 of this DPA, performed continuously or as initiated by Customer during the Agreement term and the retrieval/deletion periods;
- Annex II measures: Annex 2 of this DPA;
- Annex III subprocessors: current approved Subprocessor List;
- competent supervisory authority: determined under Clause 13; where d5s is the relevant EU-established exporter, the Autoriteit Persoonsgegevens.

The SCCs are the unmodified text of Commission Implementing Decision (EU) 2021/914, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj, and are incorporated by reference. If that text conflicts with this DPA, the SCCs prevail.
