This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Terms of Service or any other master services agreement (“Agreement”) between:

1. IntegriAI Sp. z o.o., a company incorporated in Poland with its registered office at Ul. Mickiewicza 55, Warszawa, 01-625, Poland (“Processor” or “IntegriAI”); and

2. The Customer entity that is a party to the Agreement (“Controller” or “Customer”).

This DPA is effective as of the effective date of the Agreement.

1. Definitions

1.1. For the purposes of this DPA: a) “Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under the Agreement, including but not limited to the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and any other applicable US state or federal data privacy laws. b) “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Personal Data Breach” shall have the meanings given to them in the GDPR. Where such terms are not defined in the GDPR, they shall have the meaning given to them in other Applicable Data Protection Law. c) “Services” refers to the OmniAdvisor AI service provided by IntegriAI to the Customer as defined in the Agreement. d) “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as adopted by the European Commission. e) For the purposes of the CCPA, “Business,” “Service Provider,” “Consumer,” and “Sale” shall have the meanings given to them in the CCPA.

2. Roles and Responsibilities

2.1. The parties acknowledge and agree that for the purpose of the GDPR and UK GDPR, the Customer is the Controller and IntegriAI is the Processor. For the purpose of the CCPA, the Customer is the Business and IntegriAI is the Service Provider.

2.2. IntegriAI will process Personal Data only on behalf of the Customer and in accordance with the Customer’s documented lawful instructions. The Agreement and this DPA constitute the Customer’s complete and final instructions to IntegriAI for the Processing of Personal Data.

2.3. IntegriAI will not (a) “sell” or “share” Personal Data (as those terms are defined by the CCPA); (b) retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing the Services specified in the Agreement, or as otherwise permitted by the CCPA.

2.4. Each party will comply with its respective obligations under the Applicable Data Protection Law.

3. Details of Data Processing

3.1. Subject Matter: The subject matter of the data processing is the provision of the Services as described in the Agreement.

3.2. Duration: The duration of the processing is for the term of the Agreement and until all Personal Data is returned or deleted in accordance with Section 10 of this DPA.

3.3. Nature and Purpose: The purpose of the processing is to provide, maintain, and improve the OmniAdvisor AI service, enabling Customer to build and deploy AI agents for customer support, sales, and user engagement.

3.4. Categories of Data Subjects: The categories of Data Subjects are determined by the Customer and may include Customer’s end-users, employees, customers, or other individuals whose Personal Data is submitted to the Services by the Customer.

3.5. Types of Personal Data: The types of Personal Data are determined by the Customer and may include names, email addresses, usernames, IP addresses, browser and operating system information, and any other Personal Data contained within the content submitted to the Service by the Customer (“User Submissions”).

4. Security of Processing

4.1. IntegriAI shall implement and maintain appropriate technical and organizational security measures to protect the Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures shall include, as appropriate: a) The pseudonymization and encryption of Personal Data. b) The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services. c) The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident. d) A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

5. Sub-processing

5.1. The Customer provides a general authorization for IntegriAI to engage third-party sub-processors to process Personal Data on the Customer’s behalf.

5.2. IntegriAI shall maintain a list of its current sub-processors, which shall be made available to the Customer upon request. IntegriAI will notify the Customer of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Customer the opportunity to object to such changes.

5.3. Where IntegriAI engages a sub-processor, it will do so by way of a written contract which imposes on the sub-processor data protection obligations that are no less protective than those imposed on IntegriAI in this DPA.

6. Data Subject Rights

6.1. IntegriAI will, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject or Consumer to exercise their rights under Applicable Data Protection Law (e.g., access, rectification, erasure, etc.).

6.2. Taking into account the nature of the processing, IntegriAI shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer’s obligation to respond to requests for exercising such rights.

7. Personal Data Breach

7.1. In the event of a Personal Data Breach affecting Customer’s Personal Data, IntegriAI shall notify the Customer without undue delay after becoming aware of the breach.

7.2. The notification shall include, at a minimum: a) A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned. b) The name and contact details of the data protection officer or other contact point where more information can be obtained. c) A description of the likely consequences of the Personal Data Breach. d) A description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects.

8. Data Protection Impact Assessments and Prior Consultation

8.1. IntegriAI shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities which the Customer reasonably considers to be required by Applicable Data Protection Law, in each case solely in relation to the processing of Personal Data by IntegriAI.

9. International Transfers

9.1. IntegriAI will not transfer Personal Data outside the European Economic Area (EEA), the United Kingdom, or Switzerland to any country not deemed to provide an adequate level of data protection, without implementing appropriate safeguards as required by Applicable Data Protection Law. 9.2. Where such transfers occur, they shall be governed by the Standard Contractual Clauses, which shall be deemed incorporated into this DPA.

10. Return and Deletion of Personal Data

10.1. Upon termination of the Agreement, IntegriAI shall, at the choice of the Customer, delete or return all Personal Data to the Customer. IntegriAI shall delete existing copies unless applicable law requires storage of the Personal Data. The process for deletion is further described in Section 5.3 of the Agreement.

11. General Provisions

11.1. This DPA shall be governed by the laws of the jurisdiction set forth in the Agreement.

11.2. In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail in relation to the subject matter of data protection.

11.3. This DPA shall automatically terminate upon the termination of the Agreement.

11.4. Data Protection Contact: Any inquiries regarding this DPA or data protection matters may be directed to IntegriAI’s Data Protection Officer: Ioannis Karakasoglou, at dpo@omniadvisor.ai.