Data Processing Addendum

Last updated: September 15, 2026

This Data Processing Addendum (this “DPA”) is incorporated by reference into the agreement between Digital Workers of California, Inc. d/b/a Hyperspell (“Hyperspell”) and the customer identified in the applicable Order Form (“Customer”), comprising the Order Form and the Hyperspell SaaS Services Terms incorporated therein (together, the “Agreement”). This DPA supplements the Agreement and takes effect on the Effective Date of the Order Form. In the event of any inconsistency or conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, the terms of this DPA will govern solely to the extent of such inconsistency or conflict.

This DPA sets out the terms that apply when Customer Personal Data is Processed by Hyperspell under the Agreement. The purpose of the DPA is to ensure that such Processing is conducted in accordance with Data Protection Legislation and respects the rights of individuals whose Personal Data is Processed under the Agreement, and it applies to Hyperspell and any of its affiliates involved in the Processing of Customer Personal Data.

Execution. By executing an Order Form that incorporates this DPA, each party is deemed to have executed: (a) this DPA; (b) the Standard Contractual Clauses as incorporated and completed under Section 3.7 and Appendix 1, including Annexes I, II and III thereto; and (c) the UK Addendum as completed at Appendix 2, including Tables 1 to 4 thereto. Each signatory to the Order Form warrants that it is duly authorised to execute each of the foregoing on behalf of the party for which it signs. A countersignature version of this DPA is available upon request to legal@hyperspell.com.

1. Definitions

“Controller” means “Controller” or “Business” as those terms are defined by applicable Data Protection Legislation.

“Customer Personal Data” means Personal Data that is included in documents or workspaces created by Customer or its Users using the Services, or contained within Customer sources connected to the Services. Customer Personal Data does not include Personal Data that Hyperspell collects to administer the Services.

“Confidential Information” means the “Proprietary Information” of Customer as that term is defined in the Agreement.

“Data Protection Legislation” means privacy and data protection laws and regulations applicable to Hyperspell’s Processing of Customer Personal Data in the provision of the Services to Customer, including, as applicable: (a) the GDPR; (b) any legislation which implements or supplements the GDPR; (c) any legislation which implements the European Community’s Directive 2002/58/EC; (d) in respect of the United Kingdom, the Data Protection Act 2018 and the EU GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018; and/or (e) U.S. Privacy Laws; in each case, as may be amended, superseded, or replaced from time to time.

“Data Subject” means an individual to whom Customer Personal Data relates.

“GDPR” means the General Data Protection Regulation (EU) 2016/679 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, and any amendment or replacement to it.

“Order Form” refers to the Hyperspell SaaS Services Order Form entered into by the parties, as may be amended or supplemented from time to time.

“Personal Data” means any data or information that constitutes “personal data,” “personal information,” or any analogous term as defined by applicable Data Protection Legislation.

“Process,” “Processing,” and “Processed” have the meaning as defined by applicable Data Protection Legislation or, if not defined by applicable Data Protection Legislation, mean collect, hold, use, disclose, process, store, transfer, access, correct, deal with or handle.

“Processor” means “Processor,” “Service Provider,” or “Contractor” as those terms are defined by applicable Data Protection Legislation.

“Sale” and “Selling” have the meaning defined in applicable U.S. Privacy Laws.

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise Processed.

“Services” means the platform, websites, and/or services provided by Hyperspell to Customer as described in the Agreement and applicable Order Form.

“Standard Contractual Clauses” or “SCCs” means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended or replaced from time to time.

“Supervisory Authority” will have the meaning ascribed to it in the GDPR.

“UK Addendum” means the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022), as completed at Appendix 2.

“Users” will have the meaning ascribed to it in the Agreement or, if not defined there, means Customer’s employees, agents, contractors, and other individuals authorized by Customer to access or use the Services.

“U.S. Privacy Laws” means U.S. privacy and data protection laws and regulations applicable to Hyperspell’s Processing of Customer Personal Data in the provision of the Services to Customer.

The terms “Business,” “Share,” and “Service Provider” as used in this DPA will have the meanings ascribed to them in the California Consumer Privacy Act, Cal. Civ. Code §1798.100 et seq., as amended by the California Privacy Rights Act, and its implementing regulations (“CCPA”). All capitalized terms not defined in this DPA will have the meaning given to them in the Agreement.

2. Processing of Data

2.1 Scope and Purpose of Processing.

This DPA applies only where and to the extent Data Protection Legislation governs Hyperspell’s Processing of Customer Personal Data on behalf of Customer in the course of providing the Services pursuant to the Agreement, including Hyperspell’s Processing of Customer Personal Data for the nature, purposes, and duration set forth in Appendix 1. Hyperspell will not collect, use, disclose, release, disseminate, transfer, or otherwise communicate or make available to a third party Customer Personal Data except to provide the Services or as expressly permitted by the Agreement or this DPA.

2.2 Processor and Controller Responsibilities.

The parties acknowledge and agree that as between the parties: (a) Hyperspell is the Processor of Customer Personal Data under the Data Protection Legislation; (b) Customer is the Controller of Customer Personal Data under the Data Protection Legislation; and (c) each party will comply with the obligations applicable to it under the Data Protection Legislation regarding the Processing of Customer Personal Data.

2.3 Authorization by Third-Party Controller.

If Customer is a Processor, Customer warrants to Hyperspell that Customer’s instructions and actions with respect to Customer Personal Data, including its appointment of Hyperspell as another Processor, have been authorized by the relevant Controller.

2.4 Customer Instructions.

Customer instructs Hyperspell to Process Customer Personal Data: (a) for all activities described in the Agreement and this DPA (including Appendix 1), or otherwise required by Customer’s use of the Services pursuant thereto; and (b) to comply with other reasonable instructions provided by Customer or a User where such instructions are consistent with the terms of the Agreement. Customer will ensure that its instructions for the Processing of Customer Personal Data comply with the Data Protection Legislation. Customer has sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer obtained the Customer Personal Data. Customer will disclose Customer Personal Data to Hyperspell solely pursuant to a valid business purpose. Customer will ensure that, if required under the Data Protection Legislation, Data Subjects are notified of and give their consent to Hyperspell’s Processing of Customer Personal Data.

2.5 Hyperspell’s Compliance with Customer Instructions.

Hyperspell will only Process Customer Personal Data in accordance with Customer’s instructions and will treat Customer Personal Data as Confidential Information. Hyperspell may Process Customer Personal Data other than on the written instructions of Customer if it is required under applicable law to which Hyperspell is subject. In this situation, Hyperspell will inform Customer of such requirement before Hyperspell Processes the Customer Personal Data unless prohibited by applicable law. Hyperspell will immediately inform Customer if, in Hyperspell’s opinion, Customer’s instructions infringe Data Protection Legislation. Hyperspell may suspend such Processing until Customer modifies the instruction to resolve the non-compliance.

2.6 Assistance with Customer’s Obligations.

Hyperspell provides Customer the ability to access, correct, amend or delete Customer Personal Data contained in the Services. Hyperspell will promptly comply with reasonable requests by Customer to assist with such actions to the extent Hyperspell is legally permitted and able to do so. Hyperspell may charge a reasonable fee for any assistance not strictly required by Data Protection Legislation.

2.7 Notification Obligations.

Hyperspell will, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject for access to, correction, amendment, deletion of or objection to the Processing of Customer Personal Data relating to such individual. Hyperspell will forward such Data Subject requests relating to Customer Personal Data to Customer, and Customer will be responsible for responding to any such request using the functionality of the Services. Hyperspell will provide Customer with commercially reasonable cooperation and assistance in relation to the handling of a Data Subject request, to the extent legally permitted and to the extent Customer does not have access to such Customer Personal Data through its use or receipt of the Services. Hyperspell will not be liable in cases where Customer fails to respond to the Data Subject’s request completely, correctly, or in a timely manner. Notwithstanding the foregoing, nothing in this Section 2.7 will restrict Hyperspell from responding to a request from a Data Subject where it is required to do so under the Data Protection Legislation.

2.8 General Authorization for Subprocessors.

Customer generally authorizes the use of subprocessors to Process Customer Personal Data in connection with fulfilling Hyperspell’s obligations under the Agreement and/or this DPA, and explicitly approves the list of subprocessors located at https://trust.hyperspell.com.

2.9 New Subprocessors.

When Hyperspell engages a new subprocessor to Process Customer Personal Data, Hyperspell will, at least thirty (30) days before the new subprocessor Processes any Customer Personal Data, notify Customer by updating its list of subprocessors located at https://trust.hyperspell.com and give Customer the opportunity to object to such subprocessor. Customer may sign up on the website to receive notifications of changes to the subprocessor list. If Customer has reasonable grounds to object to Hyperspell’s change in subprocessors related to data protection concerns, Customer shall notify Hyperspell promptly within thirty (30) days after receipt of Hyperspell’s notice. Hyperspell will use reasonable efforts to find an acceptable, reasonable, alternate solution; otherwise, Customer may suspend or terminate the Services.

2.10 Hyperspell Obligations.

Hyperspell will remain liable for the acts and omissions of its subprocessors to the same extent Hyperspell would be liable if performing the services of each subprocessor directly. Hyperspell will contractually impose data protection obligations on its subprocessors that are at least equivalent to those data protection obligations imposed on Hyperspell under this DPA.

2.11 Audit Rights.

Upon Customer’s written request to legal@hyperspell.com no more than once per year, Hyperspell will provide a copy of its then most recent third-party audits or certifications, as applicable, or any summaries thereof, such that Customer may reasonably verify Hyperspell’s compliance with the technical and organizational measures required under this DPA. Where required by the applicable Data Protection Legislation, Hyperspell will allow Customer, or a mutually agreed upon independent auditor appointed by Customer, to conduct an audit (including inspection), no more than once per year upon eight weeks’ notice sent to legal@hyperspell.com complete with a detailed audit plan describing the proposed scope, duration, and start date of the audit. Hyperspell will contribute to such audits, whose sole purpose will be to verify Hyperspell’s compliance with its obligations under this DPA. The auditor must execute a written confidentiality agreement acceptable to Hyperspell before conducting the audit. The audit must be conducted during Hyperspell’s normal business hours, subject to Hyperspell’s policies, and may not unreasonably interfere with Hyperspell’s business activities. Any audits are at Customer’s sole cost and expense. Customer will promptly notify Hyperspell with information regarding any non-compliance discovered during the course of an audit.

2.12 Limits on Auditing Party.

Nothing in this DPA will require Hyperspell to disclose to an independent auditor or Customer, or to allow an independent auditor or Customer to access: (a) any data of any other user or customer of Hyperspell; (b) Hyperspell’s internal accounting or financial information; (c) any trade secret of Hyperspell; (d) any premises or equipment not controlled by Hyperspell; or (e) any information that, in Hyperspell’s reasonable opinion, could: (i) compromise the security of Hyperspell’s systems or premises; (ii) cause Hyperspell to breach its obligations under Data Protection Legislation or the rights of any third party; or (iii) any information that an independent auditor seeks to access for any reason other than the good faith fulfillment of Customer’s rights under the Data Protection Legislation. Customer will contractually impose, and designate Hyperspell as a third-party beneficiary of, any contractual terms that prohibit any independent auditor from disclosing the existence, nature, or results of any audit to any party other than Customer unless such disclosure is required by applicable law.

2.13 No Model Training.

Hyperspell will not use Customer Data or Customer Personal Data to train, fine-tune, retrain, or otherwise develop or improve any machine learning or artificial intelligence model, whether Hyperspell’s own or that of any third party. Hyperspell will contractually prohibit each subprocessor and model provider that Processes Customer Data or Customer Personal Data from using it for any such purpose. For clarity, inputs submitted to and outputs generated by any model in the course of providing the Services are not used to train, fine-tune, or improve any model. Nothing in this Section restricts Hyperspell from using aggregated operational telemetry that contains no Customer Data and no Personal Data to monitor, secure, and operate the Services.

3. GDPR

3.1 Applicability.

Section 3 only applies to Hyperspell’s Processing of Customer Personal Data subject to the GDPR or UK Data Protection Legislation.

3.2 Data Privacy Impact Assessments.

Hyperspell will take reasonable measures to cooperate and assist Customer in conducting a data protection impact assessment and related consultations with any Supervisory Authority, if Customer is required to do so under Data Protection Legislation.

3.3 International Transfers.

The parties will transfer Customer Personal Data internationally only pursuant to a transfer mechanism valid under the Data Protection Legislation or applicable law, i.e. a valid mechanism in the exporting country to ensure an adequate level of protection, or within a permitted derogation. The SCCs and the UK Addendum, as incorporated and completed under Section 3.7 and Appendices 1 and 2, apply to Hyperspell in its role as the “data importer” and to Customer in its role as the “data exporter.” Upon request, Hyperspell will provide information related to the transfer mechanism utilized.

3.4 Transfer Mechanism.

In the event there is more than one mechanism to transfer Customer Personal Data from the European Economic Area, United Kingdom, and/or Switzerland to countries which do not ensure an adequate level of data protection under the Data Protection Legislation, the transfer of Customer Personal Data will be subject to a single transfer mechanism applicable to the entity providing the Services through a valid transfer mechanism approved for transfers of Customer Personal Data from the European Economic Area, United Kingdom, or Switzerland to the U.S., such as the SCCs and/or the UK Addendum (as applicable).

3.5 Changes to Transfer Mechanism.

If Hyperspell’s compliance with Data Protection Legislation applicable to international data transfers is affected by circumstances outside of Hyperspell’s control, including if a legal instrument for international data transfers is invalidated, amended, or replaced, then Customer and Hyperspell will work together in good faith to reasonably resolve such non-compliance. In the event that additional, replacement or alternative transfer mechanisms, standard contractual clauses or UK standard contractual clauses are approved by Supervisory Authorities, Hyperspell reserves the right to choose the transfer mechanism of its preference and, notwithstanding Section 7.3, may amend this DPA and the Agreement by adding to or replacing the existing transfer mechanism by providing Customer with at least thirty (30) days’ prior written notice; provided that (a) Hyperspell will ensure continued compliance with Data Protection Legislation, and (b) if Customer reasonably objects to the new transfer mechanism on data protection grounds, Customer may terminate the affected Services on written notice to Hyperspell within such notice period.

3.6 Applicability of the Standard Contractual Clauses.

The SCCs and the UK Addendum concluded between the parties pursuant to this Section 3 will only apply insofar as strictly necessary for Hyperspell to comply with the applicable Data Protection Legislation.

3.7 Incorporation and Completion of the SCCs and UK Addendum.

The SCCs are incorporated into this DPA by reference and are completed as follows:

  • Module Two (Controller to Processor) applies. Modules One, Three and Four do not apply and are deemed deleted.

  • Clause 7 (Docking clause) is included.

  • Clause 9(a): Option 2 (General written authorisation) applies, with a notice period of thirty (30) days, as given effect by Sections 2.8 and 2.9 of this DPA.

  • Clause 11(a): the optional language providing for an independent dispute resolution body is omitted.

  • Clause 13 and Annex I.C: the competent Supervisory Authority is as set out in Appendix 1, Annex I.C.

  • Clause 17: the SCCs are governed by the laws of Ireland. In respect of transfers subject to UK Data Protection Legislation only, the SCCs as amended by the Mandatory Clauses of the UK Addendum are governed by the laws of England and Wales.

  • Clause 18(b): disputes arising from the SCCs will be resolved before the courts of Ireland, and a Data Subject may also bring legal proceedings before the courts of the EEA Member State in which he or she has his or her habitual residence. In respect of transfers subject to UK Data Protection Legislation only, disputes will be resolved before the courts of England and Wales, and a Data Subject may also bring legal proceedings before the courts of any part of the United Kingdom.

  • Annexes I, II and III to the SCCs are as set out in Appendix 1 to this DPA.

The UK Addendum is incorporated into this DPA by reference and is completed as set out in Appendix 2. In respect of transfers subject to UK Data Protection Legislation, the UK Addendum amends the SCCs to the extent necessary for them to operate for such transfers. By executing the Order Form, each party is deemed to have signed the SCCs and the UK Addendum, including their respective Annexes and Tables, in the capacities set out in Appendix 1, Annex I.A.

4. U.S. Privacy Laws

4.1 Applicability.

Section 4 only applies to Hyperspell’s Processing of Customer Personal Data subject to U.S. Privacy Laws.

4.2 Compliance Assurance.

If the provision of information provided pursuant to Section 2.11 above does not fulfil the requirements of the applicable U.S. Privacy Laws, Customer has the right to take reasonable and appropriate steps to ensure that Hyperspell uses Customer Personal Data consistent with Customer’s obligations under applicable U.S. Privacy Laws.

4.3 Compliance Remediation.

Hyperspell shall promptly notify Customer after determining that it can no longer meet its obligations under applicable U.S. Privacy Laws. Upon receiving notice from Hyperspell in accordance with this section, Customer may direct Hyperspell to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.

4.4 Limitations on Processing.

Hyperspell will Process Customer Personal Data solely as described in the Agreement and this DPA (including Appendix 1). Except as expressly permitted therein or by the U.S. Privacy Laws, Hyperspell is prohibited from (a) Selling or Sharing Customer Personal Data, (b) retaining, using, or disclosing Customer Personal Data for any other purpose, (c) retaining, using, or disclosing Customer Personal Data outside of the direct business relationship between the parties, and (d) combining Customer Personal Data with Personal Data obtained from, or on behalf of, sources other than Customer or its Users, except as expressly permitted under applicable U.S. Privacy Laws.

4.5 Deletion Requests.

Hyperspell shall not be required to delete any Customer Personal Data to comply with a Data Subject’s request directed by Customer if retaining such information is specifically permitted by applicable U.S. Privacy Laws; provided, however, that in such case, Hyperspell will promptly inform Customer of the exceptions relied upon under applicable U.S. Privacy Laws and Hyperspell shall not use Customer Personal Data retained for any purpose other than provided for by that exception.

4.6 Sale of Data.

The parties acknowledge and agree that the exchange of Personal Data between the parties does not form part of any monetary or other valuable consideration exchanged between the parties with respect to the Agreement or this DPA.

5. Security

5.1 Hyperspell Personnel.

Hyperspell will inform its personnel engaged in the Processing of Customer Personal Data of the confidential nature of the Customer Personal Data, and subject them to obligations of confidentiality that survive the termination of that individual’s engagement with Hyperspell.

5.2 Third Party Disclosure.

Hyperspell will not disclose Customer Personal Data to any third party unless authorized by Customer or required by law. If a government entity (including a law enforcement agency) or Supervisory Authority demands access to Customer Personal Data, Hyperspell will attempt to redirect the requestor to request the data directly from Customer or notify Customer prior to disclosure, in each case unless prohibited by law.

5.3 Security.

Hyperspell will implement appropriate technical and organisational measures (and in any event no less than commercially reasonable technical and organizational measures) to safeguard Customer Personal Data, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, including the measures described in Appendix 1, Annex II.

6. Security Breach

6.1 Notification Obligations.

Upon becoming aware of any Security Incident affecting Customer Personal Data, Hyperspell shall notify Customer without undue delay and shall provide timely updates and information relating to the Security Incident as it becomes known or as is reasonably requested by Customer. Such information will include the nature of the Security Incident, the categories and number of Data Subjects affected, the categories and amount of Customer Personal Data affected, the likely consequences of the Security Incident, and the measures taken or proposed to be taken to address the Security Incident and mitigate possible adverse effects. Hyperspell’s obligations in this Section 6 do not apply to incidents that are caused by Customer or Users or to unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

6.2 Manner of Notification.

Notification(s) of Security Incidents, if any, will be delivered to one or more of Customer’s business, technical or administrative contacts by any means Hyperspell selects, including via email. It is Customer’s sole responsibility to maintain accurate contact information on Hyperspell’s systems at all times. Furthermore, it is Customer’s sole responsibility to notify the relevant Supervisory Authority and, when applicable, the Data Subjects of a Security Incident as required under Articles 33 and 34 of the GDPR or other Data Protection Legislation. Hyperspell will promptly comply with reasonable requests by Customer to assist it with meeting such notification requirements to the extent Hyperspell is legally permitted and able to do so. Notwithstanding the foregoing, nothing in this Section 6.2 will restrict Hyperspell from notifying the relevant Supervisory Authority or Data Subjects of a Security Incident where it is required to do so under the Data Protection Legislation.

7. Miscellaneous

7.1 Term of DPA.

This DPA takes effect on the Effective Date of the Order Form and will remain in effect until, and automatically expire upon, deletion of all Customer Personal Data as described in this DPA.

7.2 Deletion of Customer Personal Data.

Hyperspell will delete Customer Personal Data in its possession in accordance with the terms of the Agreement, subject to its automated deletion schedule and back-up policy. Hyperspell has no obligation to retain any portion of Customer Personal Data after such period except to the extent that Hyperspell is required under applicable law to keep a copy of the Customer Personal Data.

7.3 Amendment.

This DPA may be amended only through mutual written agreement between the parties, except as expressly provided in Section 3.5 and except for prospective updates by Hyperspell as provided in the Order Form.

7.4 Claims.

Any claim or remedy Customer may have against Hyperspell, its subsidiaries, employees, agents, or subprocessors, arising under or in connection with this DPA, whether in contract, tort (including negligence) or under any other theory of liability, shall be subject to the limitations and exclusions of liability in the Agreement to the maximum extent permitted by law. Accordingly, any reference in the Agreement to the liability of a party means the aggregate liability of that party under and in connection with the Agreement and this DPA together. This DPA shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws provisions, consistent with the governing law and jurisdiction provisions of the Agreement, unless otherwise required by applicable Data Protection Legislation (including as provided in Section 3.7 with respect to the SCCs and the UK Addendum).

7.5 Severability.

If any part of this DPA is held unenforceable, the validity of all remaining parts will not be affected.

APPENDIX 1 — ANNEXES TO THE STANDARD CONTRACTUAL CLAUSES

The Annexes below form Annexes I, II and III to the SCCs as incorporated under Section 3.7, and also constitute the Appendix Information for the purposes of the UK Addendum at Appendix 2.

Annex I

A. List of Parties

Data exporter: Customer, as identified in the Order Form (legal name, address, and contact person as stated therein). Activities relevant to the data transferred: use of the Services to make Customer’s internal workplace knowledge searchable and usable by Customer personnel and Customer-authorised AI agents, as described in Annex I.B. Signature and date: executed via the Order Form. Role: Controller.

Data importer: Digital Workers of California, Inc. d/b/a Hyperspell, 1065 Folsom St, San Francisco, CA 94103, United States. Contact: legal@hyperspell.com. Activities relevant to the data transferred: provision of the Services as described in Annex I.B. Signature and date: executed via the Order Form. Role: Processor.

B. Description of the Transfer

1. Categories of data subjects: employees, contractors, and other workforce members of the data exporter who use, or whose communications and documents appear in, the workplace sources connected to the Services; and other individuals who appear incidentally in the content of those sources, for example external business correspondents participating in emails, messages, or documents.

2. Categories of personal data transferred: personal data contained within the data exporter’s connected workplace sources, comprising (a) identification and contact data of workforce members and correspondents (names, business email addresses, usernames and handles, and profile information from the connected sources); and (b) content data (the text and attachments of messages, emails, and documents in the connected sources, and associated metadata such as timestamps, authorship, channel or folder membership, and sharing and permission information), to the extent such content contains personal data.

3. Sensitive data transferred: none required. The Services do not require special category personal data. Incidental appearance of sensitive data, for example in the body of an email within a connected source, remains the responsibility of the data exporter as Controller. Any exclusions of specific data categories or sources agreed by the parties are stated in the Order Form and control.

4. Frequency of the transfer: continuous. Following initial connection of each source by the data exporter’s authorised administrators, content is ingested on an ongoing basis via authorised API connections (scheduled incremental synchronisation and, where supported by the source, webhook-based updates).

5. Nature of the processing: ingestion via API connections authorised by the data exporter; transmission and storage; parsing, fact and feature extraction, assembly into an interconnected knowledge graph, and generation of vector embeddings for indexing; retrieval, search and relevance ranking; AI-assisted synthesis of responses using large language models; display of results to the data exporter’s authorised users; and deletion. Model inputs and outputs are not used to train, fine-tune, or improve any model, whether the data importer’s or a third party’s, consistent with Section 2.13 of the DPA.

6. Purposes of the data transfer and further processing: solely to provide the Services under the Agreement and in accordance with the data exporter’s documented instructions: unifying the data exporter’s connected workplace sources into a queryable knowledge layer for the data exporter’s personnel and authorised AI agents. The data importer does not use personal data for its own commercial purposes, including profiling or advertising.

7. Retention period: for the duration of the Agreement, while the data exporter’s account is active. Thereafter, Customer Personal Data is deleted in accordance with Section 7.2 of this DPA and the Agreement, except where retention is required by law.

8. Transfers to (sub-)processors: as set out in Annex III. Each subprocessor Processes personal data only as necessary to deliver its function within the Services (infrastructure hosting, model inference, connector synchronisation, workflow orchestration, authentication, monitoring), for the same duration as the data importer’s Processing, and subject to written agreements imposing data protection obligations consistent with this DPA. The hosting region for the data exporter’s deployment is as selected in the Order Form (United States by default; a dedicated environment in an EU or other region where so selected); customer content is stored and Processed in the selected region.

C. Competent Supervisory Authority: the competent supervisory authority in accordance with Clause 13 is the supervisory authority of the EEA Member State in which the data exporter is established or, where the data exporter is not established in the EEA, the supervisory authority of the EEA Member State in which the data exporter’s Article 27 GDPR representative is established or, absent such a representative, of the EEA Member State in which the relevant Data Subjects are located (for EEA data subjects); and the UK Information Commissioner’s Office (for UK data subjects). The competent authority for the Processing of Personal Data relating to Data Subjects located in the United Kingdom is the UK Information Commissioner.

Annex II — Technical and Organisational Measures

Hyperspell maintains an information security program with technical and organisational measures designed to protect Customer Personal Data against a Security Incident, appropriate to the nature of the data and the risks involved, including the following. Deployment-specific measures (for example a dedicated single-tenant environment or a specified hosting region) are as selected in the Order Form.

Hosting environment. Production systems are hosted on Amazon Web Services in the region selected in the Order Form (United States by default). All AI model inference for the Services runs within Hyperspell’s controlled environment; foundation models are consumed via AWS Bedrock in region, and document summarisation, entity extraction, relevance ranking, and text embeddings run on models and endpoints hosted within the same environment. Development, staging, and production environments are segregated, and production data is not used in development or testing except where required for debugging.

Encryption. Data in transit is protected using strong cryptography and security protocols (TLS 1.2 or higher, or a minimally equivalent protocol) across all environments and APIs. Data at rest is encrypted using strong encryption methods such as AES-256 or a minimally equivalent protocol. Hyperspell’s Encryption and Key Management Policy references NIST FIPS 140-3 and NIST SP 800-140C as guidance for encryption algorithms.

Access control. Access is granted on the principle of least privilege, provisioned through a deny-all default and granted only on formal, independent approval based on job function, business requirements, or need-to-know. Multi-factor authentication is required for access to all internal tools and vendors. Access rights for high-risk and critical systems are reviewed at least quarterly, and access is revoked on role change or departure, with offboarding completed within 24 hours of a user’s last day or sooner where necessary. Within the product, access is managed by Customer’s designated administrators, and the Services inherit and enforce the source-system permissions of the connected workplace sources.

Physical security. Production systems are hosted on AWS, inheriting AWS’s physical and environmental controls for data centres. Hyperspell’s own facilities do not contain production assets.

Change management and secure development. Software and infrastructure changes follow a formal change management process operated through reviewed, approved, and tracked pull requests, providing an auditable record and segregation of duties between implementation and approval. Hyperspell maintains hardened baseline configurations using recognised security configuration guidance such as CIS Benchmarks where applicable, and a documented Secure Development Policy requiring peer review of code.

Vulnerability and patch management. Hyperspell operates a formal vulnerability management programme. Third-party penetration testing is performed at least annually, covering the web application and cloud infrastructure, with static and dynamic analysis on an ongoing basis. Findings are scored using CVSS and remediated according to defined SLAs: Critical within 7 calendar days (72 hours where known-exploited, internet-facing, remotely exploitable without authentication, or affecting sensitive data); High within 15 days; Medium within 45 days; Low within routine maintenance cycles and within 90 days where practical.

Logging and monitoring. Logging and SIEM tooling collects event information from production systems, applications, databases, servers, message queues, load balancers, and critical services, with alerts on deviations from established baselines and correlation across sources. Logs are securely stored and retained in accordance with Hyperspell’s logging and monitoring policy.

Incident response. Hyperspell maintains a documented Security Incident Response Plan defining responsibilities, detection, reporting, escalation, verification, assessment, containment, mitigation, and post-breach response, tested and reviewed at least annually. Hyperspell notifies customers of confirmed personal data breaches without undue delay and in accordance with Section 6 of this DPA.

Business continuity and backups. Hyperspell maintains a Business Continuity and Disaster Recovery Plan reviewed and tested at least annually. Database backups are performed daily, stored in the cloud, and periodically tested for sufficiency and reliability, with documented recovery objectives for critical production systems.

Retention, deletion and portability. Customer Personal Data is retained while the account is active and deleted in accordance with Section 7.2 of this DPA and the Agreement. Upon termination, customer data can be returned in a portable format, and secure deletion follows controlled processes aligned with NIST SP 800-88 Rev. 1.

Data subject rights assistance. Hyperspell maintains documented processes to assist Customer in responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection) within applicable statutory timescales, in accordance with Sections 2.6 and 2.7 of this DPA.

Personnel. All employees complete mandatory security awareness training at least annually, including phishing simulation exercises, and data protection training is provided to all staff. Background checks or their equivalent are performed as permitted by local law. The board-approved Information Security Policy is reviewed at least annually and communicated to all staff.

Governance and assurance. Hyperspell conducts formal information security risk assessments at least annually and upon significant change, with identified risks tracked in a risk register. Hyperspell holds a SOC 2 Type II attestation covering the Security Trust Services Criteria, available via trust.hyperspell.com, and maintains cyber liability insurance and a confidential reporting channel.

Subprocessor management. Hyperspell uses only vetted subprocessors engaged under written agreements requiring, at a minimum, protection of the privacy and security of confidential information, including GDPR Article 28 terms where applicable and an appropriate transfer mechanism where the subprocessor Processes personal data outside the EEA or the United Kingdom. Vendor risk assessments are performed annually, and changes are notified in accordance with Section 2.9 of this DPA.

Annex III — List of Subprocessors

The Controller has authorised the use of the subprocessors listed at https://trust.hyperspell.com, under Clause 9(a), Option 2 of the SCCs (general written authorisation) with thirty (30) days’ notice of changes, as given effect by Sections 2.8 and 2.9 of this DPA. The list identifies each subprocessor’s function, the personal data processed, its location, and whether it Processes customer content. Customer may subscribe at that address to receive notification of changes. For single-tenant or region-specific deployments, a deployment-specific subprocessor list is available upon request and, where agreed, may be attached to the Order Form.

APPENDIX 2 — INTERNATIONAL DATA TRANSFER ADDENDUM TO THE EU COMMISSION STANDARD CONTRACTUAL CLAUSES

UK Information Commissioner, version B1.0, in force 21 March 2022. This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.

Part 1: Tables

Table 1 (Parties): Exporter: Customer, with the details (full legal name, trading name, main address, official registration number, and key contact) as identified in the Order Form. Importer: Digital Workers of California, Inc. (trading name: Hyperspell), 1065 Folsom St, San Francisco, CA 94103, United States; official registration number 3478385; key contact legal@hyperspell.com. Start date: the Effective Date of the Order Form. Signatures: executed via the Order Form, in accordance with Section 3.7 of this DPA.

Table 2 (Selected SCCs, Modules and Selected Clauses): the version of the Approved EU SCCs which this Addendum is appended to is the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as incorporated by reference and completed at Section 3.7 of this DPA (other identifier: Hyperspell Data Processing Addendum, Version 1.0). Module Two (Controller to Processor) is in operation; Modules One, Three and Four do not apply. Clause 7 (Docking Clause): included. Clause 9(a): Option 2, General Written Authorisation, with a thirty (30) day notice period for subprocessor changes. Clause 11: the optional independent dispute resolution language is not used. Clause 17 (Governing Law): in respect of transfers subject to UK Data Protection Legislation only, as amended by the Mandatory Clauses of this Addendum, the laws of England and Wales; for all other transfers, SCC Clause 17 as set out in Section 3.7 of the DPA (the laws of Ireland) applies. Clause 18 (Choice of forum and jurisdiction): in respect of transfers subject to UK Data Protection Legislation only, the courts of England and Wales, and a Data Subject may also bring legal proceedings before the courts of any part of the United Kingdom; for all other transfers, SCC Clause 18 as set out in Section 3.7 of the DPA applies.

Table 3 (Appendix Information): Annex 1A (List of Parties): Appendix 1, Annex I.A of this DPA, with Customer’s details as identified in the Order Form. Annex 1B (Description of Transfer): Appendix 1, Annex I.B of this DPA. Annex II (Technical and organisational measures): Appendix 1, Annex II of this DPA. Annex III (List of Subprocessors): Appendix 1, Annex III of this DPA.

Table 4 (Ending this Addendum when the Approved Addendum Changes): the Exporter may end this Addendum as set out in Section 19 of the Mandatory Clauses.

Part 2: Mandatory Clauses. Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the Information Commissioner and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, are incorporated into this Addendum by reference and form part of it. This Addendum is executed via the Order Form, in accordance with Section 3.7 of this DPA.