COPLEY SOFTWARE, INC. DATA PROCESSING ADDENDUM

Effective: May 21, 2026

This Data Processing Addendum ("DPA") forms part of and is incorporated into the Agreement between Copley Software, Inc. ("Copley") and ("Customer") (together, the "Parties"). This DPA sets forth Customer's instructions for the processing of Personal Data in connection with the services provided under the Agreement (the "Services") and the rights and obligations of both Parties. Except as expressly set forth in this DPA, the Agreement shall remain unmodified and in full force and effect. In the event of any conflicts between this DPA and the Agreement, this DPA will govern to the extent of the conflict.

Definitions.

For the purposes of this DPA, the following terms shall have the meanings set out below. Capitalized terms used but not defined in this DPA shall have the meanings given in the Agreement. All other terms in this DPA not otherwise defined in the Agreement shall have the corresponding meanings given to them in Privacy Laws.

"Controller to Processor Clauses" means (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 2 (Controller to Processor) ("EU SCCs"); and (ii) in respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner ("UK Addendum"), in each case as amended, updated or replaced from time to time.

"EU/UK Privacy Laws" means, as applicable: (a) the General Data Protection Regulation 2016/679 (the "GDPR"); (b) the Privacy and Electronic Communications Directive 2002/58/EC; (c) the UK Data Protection Act 2018, the UK General Data Protection Regulation as defined by the UK Data Protection Act 2018 as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (together with the UK Data Protection Act 2018, the "UK GDPR"), and the Privacy and Electronic Communications Regulations 2003; and (d) any relevant law, directive, order, rule, regulation or other binding instrument which implements any of the above, in each case, as applicable and in force from time to time, and as amended, consolidated, re-enacted or replaced from time to time.

"Personal Data" means any information Copley processes on behalf of Customer to provide the Services that is defined as "personal data" or "personal information" under any Privacy Law.

"Privacy Laws" means, as applicable, EU/UK Privacy Laws, US Privacy Laws and any similar law of any other jurisdiction which relates to data protection, privacy or the use of Personal Data, in each case, as applicable and in force from time to time, and as amended, consolidated, re-enacted or replaced from time to time.

"Processor to Processor Clauses" means (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of personal data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 3 (Processor to Processor); and (ii) in respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner, in each case as amended, updated or replaced from time to time.

"Third Country" means any country or territory outside of the scope of the data protection laws of the European Economic Area or the UK, as relevant, excluding countries or territories approved as providing adequate protection for Personal Data by the relevant competent authority from time to time.

"US Privacy Laws" means, as applicable, the California Consumer Privacy Act and any similar law of any other state that regulates the processing of Personal Data.

Amendments.

The Parties agree to negotiate in good faith modifications to this DPA if changes are required for Copley to continue to process the Personal Data as contemplated by the Agreement or this DPA in compliance with Privacy Laws, or to address the legal interpretation of the Privacy Laws.

Roles of the Parties.

The Parties acknowledge that for purposes of Privacy Laws, Customer is the "controller," "business," or any similar term provided under Privacy Laws, and Copley is the "service provider," "processor," "contractor," or any similar term provided under Privacy Laws.

Details of Processing.

The Parties agree that the details of processing are as described in Annex 1.

Customer Obligations.

Customer shall comply with all Privacy Laws in providing Personal Data to Copley in connection with the Services. Customer represents and warrants that: (a) the Privacy Laws applicable to Customer do not prevent Copley from fulfilling the instructions received from Customer and performing Copley's obligations under this DPA; (b) all Personal Data was collected and at all times processed and maintained by or on behalf of Customer in compliance with all Privacy Laws, including with respect to any obligations to provide notice to and/or obtain consent from individuals; and (c) Customer has a lawful basis for disclosing the Personal Data to Copley and enabling Copley to process the Personal Data as set out in this DPA. Customer shall notify Copley without undue delay if Customer makes a determination that the processing of Personal Data under the Agreement does not or will not comply with Privacy Laws, in which case, Copley shall not be required to continue processing such Personal Data.

Processing of Personal Data.

In processing Personal Data under the Agreement, Copley shall:

Anonymized Data.

Copley may aggregate and/or anonymize Personal Data such that it no longer constitutes Personal Data under Privacy Laws and process such data for its own purposes. To the extent Copley receives de-identified data (as such term is defined under applicable US Privacy Laws) from Customer, Copley shall: (i) take commercially reasonable measures to ensure that the data cannot be associated with an identified or identifiable individual; (ii) publicly commit to maintain and use the data only in a de-identified fashion; and (iii) not attempt to re-identify the data.

Prohibitions.

To the extent required by applicable US Privacy Laws, and except to the extent permitted by such US Privacy Laws, Copley is prohibited from:

The Services are not designed or intended for the processing of (a) protected health information governed by the U.S. Health Insurance Portability and Accountability Act ("HIPAA"); (b) financial account information governed by the Gramm-Leach-Bliley Act ("GLBA"); or (c) student education records governed by the Family Educational Rights and Privacy Act ("FERPA"). Copley is not a Business Associate under HIPAA, a financial institution under GLBA, or a school official under FERPA. Customer shall not provide such Personal Data to the Services and acknowledges that any such use is at Customer's sole risk.

Use of Subcontractors.

To the extent Copley engages any subcontractors to process Personal Data on its behalf:

Assistance.

To the extent required by Privacy Laws, and taking into account the nature of the processing, Copley shall, in relation to the processing of Personal Data and to enable Customer to comply with its obligations which arise as a result thereof, provide reasonable assistance to Customer, through appropriate technical and organizational measures, in:

Security Measures.

Copley shall, taking into account the state-of-the-art, the costs of implementation and the nature, scope, context and purpose of the processing, implement appropriate technical and organizational measures designed to provide a level of security appropriate to the risk, as set out in Annex 2, or otherwise agreed and documented between Customer and Copley from time to time. To the extent required by Privacy Laws, Copley shall without undue delay notify Customer in writing of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, with further information about the breach provided in phases as more details become available.

Access and Audits.

Upon reasonable request of Customer, Copley shall make available to Customer such information in its possession as is reasonably necessary to demonstrate Copley's compliance with its obligations under this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer and reasonably accepted by Copley. Customer shall be permitted to conduct such an assessment no more than once every 12 months, upon 30 days' advance written notice to Copley, and only after the Parties come to agreement on the scope of the audit and the auditor is bound by a duty of confidentiality. As an alternative to an audit performed by or at the direction of Customer, to the extent permitted by Privacy Laws, Copley may arrange for a qualified and independent auditor to conduct, at Copley's expense, an assessment of Copley's policies and technical and organizational measures in support of its obligations under Privacy Laws using an appropriate and accepted control standard or framework and assessment procedure for such assessment, and will provide a report of such assessment to Customer upon reasonable request. Notwithstanding the foregoing, in no event shall Copley be required to give Customer access to information, facilities or systems to the extent doing so would cause Copley to be in violation of confidentiality obligations owed to other customers or its legal obligations.

Deletion of Personal Data.

At Customer's written direction, Copley shall delete or return all Personal Data to Customer as requested at the end of the provision of the Services, unless retention of the Personal Data is required by law.

Data Transfers.

To the extent Copley processes Personal Data subject to EU/UK Privacy Laws in a Third Country, and it is acting as data importer, Copley shall comply with the data importer's obligations and Customer shall comply with the data exporter's obligations set out in the Controller to Processor Clauses, which are hereby incorporated into and form part of this DPA, and:

Customer acknowledges and agrees that Copley may appoint an affiliate or third-party subcontractor to process the Personal Data in a Third Country, in which case, Copley shall execute the Processor to Processor Clauses with any relevant subcontractor (including affiliates) it appoints on behalf of Customer.

For transfers of Personal Data subject to the Swiss Federal Act on Data Protection (the "FADP"), the Controller to Processor Clauses apply with the following adaptations: (i) references to the GDPR shall be interpreted as references to the Swiss FADP; (ii) references to EU Member State law shall be interpreted as references to Swiss law; (iii) the supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner; and (iv) data subjects in Switzerland shall be afforded the same protections as data subjects in the European Economic Area.

ANNEX 1 — Details of Processing

Nature of the processing

Access, use, disclosure, storage and deletion of Personal Data by Copley in connection within its provision of the Services to Customer as set out in the Agreement.

Purpose(s) of the processing

Provision of the Services by Copley to Customer as set out in the Agreement, including the provision of artificial intelligence-based features and, to the extent permitted by the Agreement, the use of Personal Data and Service outputs to fine-tune, train, or improve artificial intelligence models that Copley deploys in connection with the Services.

Categories of individuals whose Personal Data is processed

Customers, clients, and users of Customer, including any individuals that may see advertising or marketing material of Customer on platforms owned by subcontractors; contacts, leads, and other individuals represented in customer relationship management, marketing, or other systems that Customer connects to the Services; and participants in audio, video, or other communications whose recordings or transcripts are uploaded to or accessed via the Services through Third Party Services.

Categories of Personal Data processed

Full name, address, email address, phone number, and other contact details; date of birth, marketing segments, and other demographic information; browsing history, purchase history, clickstream data, and other marketing or advertising history information; device information, browser information, internet protocol (IP) address, and other usage data; content of customer relationship management records, including notes, communications history, and free-text fields; content of audio, video, or other communications and the transcripts produced from them; and outputs generated by the Services concerning data subjects.

Types of Personal Data subject to the processing that are considered "sensitive" or "special category" under Privacy Laws

May be processed where Customer uploads or ingests transcripts, customer relationship management notes, or other free-text content that contains such categories. Customer is responsible for determining whether the Services are appropriate for processing such data and for obtaining any heightened consent required by Privacy Laws.

Frequency and duration of the processing

Relevant Personal Data is processed on a continuous basis for the duration of the term of the Agreement and any post-termination retention period as set out in the Agreement.

The subject matter, nature and duration of processing carried out by any sub-processors authorized pursuant to Section 9 is as set out in this Annex 1.

ANNEX 2 — Security Measures