BACI

DATA PROCESSING ADDENDUM

Version 1.0 · Effective Date: 10 September 2026 · Last Updated: 10 September 2026

This Data Processing Addendum ("DPA") forms part of the Agreement between BACI LLC ("BACI") and the Customer identified in the applicable Order or Agreement ("Customer") and governs BACI's Processing of Customer Personal Data on Customer's behalf in connection with the Services.

This DPA is intended to satisfy applicable contractual requirements imposed upon controllers and processors, businesses and service providers, and equivalent relationships under Applicable Data Protection Law. It applies only to Processing for which BACI acts as Customer's processor, service provider, contractor or equivalent regulated recipient. Processing for which BACI independently determines the purposes and means is governed by the BACI Privacy Policy and Applicable Data Protection Law.

1. DEFINITIONS

"Affiliate" means an entity that directly or indirectly controls, is controlled by or is under common control with a party.

"Applicable Data Protection Law" means privacy, data-protection, data-security and consumer-privacy laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, applicable United States state privacy laws and other national or regional data-protection laws.

"Controller" means the entity that determines the purposes and means of Processing Personal Data, including a "business" or equivalent role where applicable.

"Customer Personal Data" means Personal Data contained in Customer Data that BACI Processes on behalf of Customer under the Agreement.

"Data Subject" means an identified or identifiable individual to whom Personal Data relates.

"GDPR" means Regulation (EU) 2016/679.

"Personal Data" means information relating to an identified or identifiable individual, or information otherwise protected as personal data, personal information or an equivalent category under Applicable Data Protection Law.

"Process", "Processed" and "Processing" mean any operation performed on Personal Data.

"Processor" means an entity that Processes Personal Data on behalf of a Controller, including a service provider, contractor or equivalent regulated recipient where applicable.

"Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data Processed by BACI, excluding unsuccessful attempts or activities that do not compromise Customer Personal Data.

"Subprocessor" means a third party engaged by BACI to Process Customer Personal Data on behalf of Customer in connection with the Services.

"UK GDPR" means the GDPR as incorporated into United Kingdom law.

Capitalised terms not defined in this DPA have the meanings given in the Agreement.

2. SCOPE AND ROLES

2.1 Customer is the Controller of Customer Personal Data, except where Customer acts as a Processor for another Controller, in which case BACI acts as Customer's subprocessor.

2.2 BACI acts as Processor with respect to Customer Personal Data Processed on Customer's behalf.

2.3 Each party will comply with obligations applicable to it under Applicable Data Protection Law.

2.4 Customer is responsible for ensuring that its instructions to BACI comply with Applicable Data Protection Law and that it has all notices, rights, permissions, consents and lawful bases necessary for BACI to Process Customer Personal Data in accordance with the Agreement.

2.5 BACI's role as Processor does not prevent BACI from Processing information for independent purposes where Applicable Data Protection Law permits and BACI acts as Controller for that separate Processing. Such independent Processing is outside the scope of this DPA and is governed by the BACI Privacy Policy and Applicable Data Protection Law.

3. RELATIONSHIP TO THE BACI LEGAL FRAMEWORK

3.1 This DPA forms part of the BACI Legal Framework.

3.2 In accordance with the Terms of Service order of precedence, this DPA controls over conflicting provisions of the Terms or other BACI policies with respect to BACI's Processing of Customer Personal Data on Customer's behalf.

3.3 The Security Addendum controls contracted security obligations to the extent the Agreement gives it higher precedence for those obligations. The International Data Transfer Addendum and applicable transfer mechanisms govern international-transfer matters to the extent expressly applicable.

3.4 Nothing in this DPA reduces a mandatory obligation imposed by Applicable Data Protection Law.

4. CUSTOMER INSTRUCTIONS

4.1 BACI will Process Customer Personal Data only on Customer's documented instructions, including as necessary to provide, secure, support, maintain and administer the Services and otherwise perform the Agreement, unless Applicable Law requires BACI to Process the data.

4.2 The Agreement, Customer's configuration and use of the Services, authorised support requests and other documented directions consistent with the Agreement constitute Customer's documented instructions.

4.3 If Applicable Law requires BACI to Process Customer Personal Data other than on Customer's instructions, BACI will inform Customer of that legal requirement before Processing unless the law prohibits such notice on important grounds of public interest.

4.4 BACI will promptly inform Customer if, in BACI's reasonable opinion, an instruction infringes Applicable Data Protection Law. BACI may suspend the affected Processing until the parties resolve the issue where necessary to avoid unlawful Processing.

4.5 BACI is not required to follow an instruction that would require BACI to violate Applicable Law or materially compromise the security of the Services.

5. DETAILS OF PROCESSING

The subject matter, nature, purpose, duration, categories of Data Subjects and types of Customer Personal Data are described in Annex I to this DPA and may be further specified in the applicable Order, Statement of Work or Service configuration.

6. CONFIDENTIALITY

6.1 BACI will ensure that persons authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations or a statutory duty of confidentiality.

6.2 BACI will limit access to Customer Personal Data to personnel and authorised parties who require access for purposes consistent with the Agreement.

6.3 BACI will maintain appropriate personnel controls and access-management practices proportionate to the nature of the Processing.

7. SECURITY OF PROCESSING

7.1 BACI will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

7.2 Measures will be appropriate to the risk and may include, as applicable, access controls; authentication; encryption; tenant and organisational isolation; logging and monitoring; secure development practices; vulnerability management; backup and recovery; incident response; personnel security; vendor risk management; business continuity; and measures supporting confidentiality, integrity, availability and resilience.

7.3 BACI may update security measures as technology, threats and the Services evolve, provided the overall level of protection applicable to Customer Personal Data is not materially reduced during the applicable Service term.

7.4 Detailed contracted security commitments may be set out in the BACI Security Policy or Security Addendum and Annex II.

8. SECURITY INCIDENTS

8.1 BACI will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

8.2 Notification will include information reasonably available to BACI that Customer requires to satisfy applicable breach-notification obligations, which may include the nature of the Security Incident; categories of affected information and Data Subjects where known; likely consequences where reasonably assessable; measures taken or proposed; and an appropriate BACI contact.

8.3 Where information cannot reasonably be provided at the same time, BACI may provide it in phases without undue further delay.

8.4 BACI will take reasonable steps to contain, investigate and remediate a Security Incident and to mitigate reasonably foreseeable harmful effects.

8.5 BACI's notification or response to a Security Incident is not an admission of fault or liability.

8.6 Customer is responsible for determining whether notification to Data Subjects, regulators or other parties is legally required, except where Applicable Law imposes that obligation directly upon BACI.

8.7 Security matters may be reported to security@bacihq.com.

9. SUBPROCESSORS

9.1 Customer generally authorises BACI to engage Subprocessors to Process Customer Personal Data in accordance with this DPA.

9.2 BACI will maintain a current Subprocessor list through its Subprocessor Policy & List or another designated BACI location.

9.3 BACI will impose written data-protection obligations on each Subprocessor that Processes Customer Personal Data on BACI's behalf, requiring protection of Customer Personal Data to a standard appropriate to the Processing and consistent with BACI's applicable obligations under this DPA.

9.4 BACI remains responsible for its Subprocessors' performance of their data-protection obligations to the extent required by Applicable Data Protection Law and the Agreement.

9.5 Where Applicable Data Protection Law requires notice of a new Subprocessor, BACI will provide an appropriate notice mechanism before the Subprocessor begins relevant Processing.

9.6 Customer may object to a new Subprocessor on reasonable, documented data-protection grounds within the period stated in BACI's applicable Subprocessor notice, or if no period is stated, within thirty (30) days after notice. The parties will work in good faith to address a valid objection. If no commercially reasonable alternative is available, BACI may permit Customer to discontinue the materially affected Service without penalty for the unused prepaid portion attributable to that Service, where required by Applicable Data Protection Law or the Agreement.

9.7 An objection may not be used solely to obtain commercial concessions unrelated to legitimate data-protection concerns.

10. INTERNATIONAL DATA TRANSFERS

10.1 BACI may Process Customer Personal Data in countries other than the country in which Customer or the relevant Data Subject is located, subject to the Agreement and Applicable Data Protection Law.

10.2 Where a restricted international transfer requires a transfer mechanism, the parties will use an applicable lawful mechanism, which may include an adequacy decision, the European Commission Standard Contractual Clauses ("EU SCCs"), the UK International Data Transfer Addendum or other recognised UK mechanism, or another legally valid mechanism.

10.3 BACI will not represent that a particular certification, framework, binding corporate rules programme or adequacy mechanism applies unless BACI has actually obtained and maintains the relevant status.

10.4 Annex III sets out the parties' default implementation of the EU SCCs and UK transfer provisions where they are legally required and no other valid transfer mechanism governs.

10.5 BACI may conduct or support transfer-risk assessments and implement supplementary measures where required by Applicable Data Protection Law.

11. DATA SUBJECT REQUESTS

11.1 Taking into account the nature of the Processing, BACI will provide reasonable assistance through appropriate technical and organisational measures, insofar as possible, to enable Customer to respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.

11.2 If BACI receives a request directly from a Data Subject concerning Customer Personal Data for which BACI acts solely as Processor, BACI may direct the requester to Customer and will not independently respond substantively except as authorised by Customer or required by Applicable Law.

11.3 Customer is responsible for responding to Data Subject requests as Controller.

11.4 BACI may provide self-service functionality that enables Customer to access, correct, export or delete Customer Personal Data.

12. DATA PROTECTION IMPACT ASSESSMENTS AND PRIOR CONSULTATION

Taking into account the nature of Processing and information available to BACI, BACI will provide reasonable assistance to Customer with data-protection impact assessments and prior consultation with supervisory authorities where required by Applicable Data Protection Law and where the relevant Processing concerns BACI's Services.

BACI is not responsible for conducting Customer's controller assessment or determining the lawfulness of Customer's business purpose.

13. RECORDS AND REGULATORY COOPERATION

13.1 BACI will maintain records of Processing activities required of BACI by Applicable Data Protection Law.

13.2 BACI will cooperate with competent supervisory authorities as required by Applicable Data Protection Law.

13.3 BACI will provide information reasonably necessary to demonstrate compliance with the processor obligations applicable to BACI under this DPA, subject to appropriate confidentiality, security and proportionality controls.

14. AUDITS AND ASSESSMENTS

14.1 BACI may satisfy reasonable audit requirements by providing current independent audit reports, certifications, security documentation, questionnaires or other relevant compliance materials where available and sufficient for Customer's legal obligations.

14.2 If those materials are insufficient for Customer to satisfy a mandatory audit right under Applicable Data Protection Law, Customer may request an additional audit of BACI's relevant Processing controls.

14.3 Any additional audit must be reasonable in scope, coordinated in advance, conducted during normal business hours, avoid unreasonable disruption, protect other customers' information and BACI confidential information, and be conducted no more than once in any twelve-month period unless a Security Incident, regulator requirement or reasonable evidence of material non-compliance justifies an additional audit.

14.4 An audit may be performed by Customer or an independent auditor that is not a competitor of BACI and is bound by appropriate confidentiality obligations.

14.5 Customer will bear the reasonable costs of a Customer-requested additional audit unless the audit identifies BACI's material non-compliance with this DPA, in which case allocation of reasonable audit costs will be determined under the Agreement and Applicable Law.

14.6 Nothing in this section requires BACI to disclose information that would compromise the security of another Customer, reveal another Customer's data, disclose privileged material, disclose information prohibited by law, or provide access to systems beyond what is reasonably necessary to satisfy the applicable audit requirement.

15. RETURN AND DELETION

15.1 Upon termination or expiration of the applicable Services, BACI will, at Customer's choice where required by Applicable Data Protection Law, return or delete Customer Personal Data, subject to the Agreement and available Service functionality.

15.2 BACI may retain Customer Personal Data to the extent required by Applicable Law or reasonably necessary for the establishment, exercise or defence of legal claims, security, fraud prevention or dispute resolution, provided retained Customer Personal Data remains protected and is not Processed for unrelated purposes.

15.3 Customer Personal Data contained in backups may be deleted through BACI's ordinary secure backup-rotation process where immediate deletion is not technically practicable and Applicable Law permits.

15.4 Further retention and deletion rules are governed by the BACI Data Retention & Deletion Policy and applicable Order.

16. NO GENERAL MODEL TRAINING BY DEFAULT

16.1 Unless Customer expressly agrees in writing or affirmatively opts into a clearly identified programme, BACI will not use Customer Confidential Information, Customer Personal Data, private Inputs or private Outputs to train or fine-tune general-purpose or shared AI models for the benefit of other customers.

16.2 This restriction does not prevent BACI from Processing Customer Personal Data as necessary to provide requested Services, execute Customer instructions, secure or maintain the Services, detect abuse, troubleshoot, provide support, comply with law or perform other Processing permitted by this DPA.

16.3 Customer-specific private training or fine-tuning requested by Customer may be governed by an Order or applicable Supplemental Terms and remains subject to this DPA where Customer Personal Data is Processed.

16.4 This Section establishes a contractual data-processing restriction and may not be weakened by the Privacy Policy, Responsible AI Policy or other lower-precedence policy.

17. AGGREGATED AND DE-IDENTIFIED INFORMATION

Subject to Applicable Data Protection Law and the Agreement, BACI may create aggregated or de-identified information from Customer Data where the resulting information no longer reasonably identifies an individual, Customer or Customer Confidential Information. Where Applicable Law requires de-identified information to remain de-identified, BACI will maintain it in de-identified form and will not attempt to re-identify it except where legally permitted for security, testing, validation or compliance.

18. GOVERNMENT REQUESTS

18.1 If BACI receives compulsory governmental or law-enforcement process seeking Customer Personal Data, BACI will assess the request in accordance with Applicable Law and the Agreement.

18.2 Where legally permitted and reasonably practicable, BACI will notify Customer before disclosure.

18.3 BACI may seek clarification, narrowing or legal review of a request BACI reasonably believes is unlawful, defective or materially overbroad.

18.4 BACI will not voluntarily provide a governmental authority with unrestricted access to Customer environments merely because the authority makes an informal request.

18.5 BACI will disclose only Customer Personal Data that BACI reasonably determines it is legally required to disclose, subject to Applicable Law.

19. UNITED STATES STATE PRIVACY REQUIREMENTS

19.1 To the extent BACI Processes Customer Personal Data as a service provider, contractor, processor or equivalent role under applicable United States state privacy law, BACI will Process that data only for the limited and specified purposes permitted by the Agreement and Applicable Law.

19.2 BACI will not sell or share Customer Personal Data, as those terms are defined by applicable state privacy law, except where Customer expressly directs a transaction that Applicable Law permits.

19.3 BACI will not retain, use or disclose Customer Personal Data outside the direct business relationship with Customer or for purposes prohibited for a service provider, contractor or processor under Applicable Data Protection Law.

19.4 BACI will not combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from BACI's own interaction with a Data Subject, where such combination is prohibited by Applicable Data Protection Law.

19.5 BACI will provide the level of privacy protection required of its regulated role, will notify Customer if BACI determines it can no longer meet an applicable obligation, and will permit Customer to take reasonable and appropriate steps required by Applicable Data Protection Law to stop and remediate unauthorised use.

19.6 The parties acknowledge that the specific statutory terminology and requirements vary by jurisdiction; this Section will be interpreted to satisfy applicable mandatory service-provider, contractor and processor requirements without converting BACI into Customer's Controller.

20. EUROPEAN ECONOMIC AREA PROCESSING

Where the GDPR applies to BACI's Processing of Customer Personal Data, BACI will comply with Article 28 obligations applicable to processors, including Processing on documented instructions; confidentiality; appropriate security; compliant Subprocessor engagement; reasonable assistance with Data Subject rights; assistance concerning Articles 32 through 36 taking into account the nature of Processing and information available; deletion or return at the end of Services subject to lawful retention; and making available information necessary to demonstrate compliance and allowing audits as provided by this DPA.

21. UNITED KINGDOM PROCESSING

Where the UK GDPR applies, the provisions of this DPA will be interpreted to satisfy applicable processor obligations under UK data-protection law. References to GDPR provisions include corresponding UK GDPR provisions where appropriate. Restricted transfers from the United Kingdom will use a legally valid UK transfer mechanism as described in Annex III.

22. OTHER JURISDICTIONS

Where Applicable Data Protection Law in another jurisdiction imposes mandatory processor, service-provider, cross-border-transfer, security, deletion, assistance or contractual requirements beyond those expressly stated in this DPA, this DPA will be interpreted to incorporate those mandatory requirements to the extent legally permissible. BACI may issue a regional addendum where additional jurisdiction-specific language is appropriate.

23. CUSTOMER OBLIGATIONS

Customer will use the Services in compliance with Applicable Data Protection Law; provide legally required notices; obtain legally required permissions or consents; configure access and permissions appropriately; avoid submitting data that the Agreement does not authorise BACI to Process; respond to Data Subject requests for which Customer is responsible; maintain appropriate security for Customer-controlled systems, credentials, devices and integrations; and provide BACI only lawful instructions.

Customer will not instruct BACI to Process Customer Personal Data in a manner Customer knows or reasonably should know is unlawful.

24. SPECIAL CATEGORIES AND REGULATED DATA

Customer will not submit specially regulated, classified or restricted data to an ordinary BACI environment where the applicable Service has not been expressly authorised for that data.

Where BACI expressly agrees to Process special-category, sensitive or otherwise regulated Customer Personal Data, the parties may establish additional safeguards through an Order, Security Addendum, regional schedule or Supplemental Terms.

25. AI AND AUTOMATED PROCESSING

Customer acknowledges that certain Services may use AI, machine learning or automated processing to provide Customer-requested functionality. Such Processing remains subject to Customer's instructions and this DPA where it involves Customer Personal Data.

Where Customer determines the purpose and use of automated decision-making affecting Data Subjects, Customer is responsible for its Controller obligations concerning lawful basis, transparency, human review, impact assessments and Data Subject rights, without reducing BACI's obligations as Processor.

26. DATA LOCALISATION AND RESIDENCY

BACI does not promise that Customer Personal Data will remain exclusively within a particular country or region unless the applicable Order or Supplemental Terms expressly provide that commitment.

Where Customer purchases or contracts for a data-residency configuration, BACI will provide that configuration according to the applicable contractual terms, subject to documented exceptions for support, security, resilience, legal compliance or other expressly disclosed purposes.

27. LIABILITY

Liability arising under this DPA is subject to the exclusions, limitations, enhanced caps and other liability provisions of the Agreement. Nothing in this DPA limits liability to the extent such limitation is prohibited by Applicable Law.

The DPA does not create a separate duplicative liability cap unless the applicable Agreement expressly states otherwise.

28. TERM AND SURVIVAL

This DPA becomes effective when it is incorporated into the Agreement and remains in effect for as long as BACI Processes Customer Personal Data on Customer's behalf.

Obligations that by their nature must continue after termination, including confidentiality, security for retained data, deletion or return, international-transfer protections and applicable audit or regulatory obligations, survive for as long as relevant Customer Personal Data remains subject to them.

29. CHANGES

BACI may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, regulatory guidance, transfer mechanisms, Services or BACI's data-processing architecture.

BACI will not materially reduce Customer's mandatory data-protection rights during an existing Service term through a unilateral update where Applicable Law or the Agreement prohibits such reduction.

Where required by the Agreement or Applicable Data Protection Law, BACI will provide appropriate notice of a material change.

30. CONFLICTS AND INTERPRETATION

If a provision of this DPA conflicts with another provision of the Agreement concerning BACI's Processing of Customer Personal Data on Customer's behalf, this DPA controls except where the Terms' order of precedence gives an executed amendment, applicable Order or Security Addendum priority for the expressly addressed matter.

If the EU SCCs, UK transfer mechanism or another mandatory transfer instrument applies and conflicts with this DPA, the mandatory transfer instrument controls for the relevant restricted transfer.

Nothing in this DPA reduces rights or obligations that cannot lawfully be reduced.

31. CONTACT

Privacy and data-protection enquiries concerning this DPA may be directed to:

BACI Privacy BACI LLC privacy@bacihq.com

Security matters may be directed to:

security@bacihq.com

ANNEX I — DETAILS OF PROCESSING

A. Subject Matter

Processing of Customer Personal Data as necessary to provide, operate, secure, support, maintain and administer the BACI Services purchased, accessed or configured by Customer.

B. Duration

For the duration of the applicable Agreement and thereafter only for the limited period and purposes permitted by the Agreement, this DPA and Applicable Data Protection Law.

C. Nature and Purpose

Processing may include collection, receipt, recording, organisation, structuring, storage, retrieval, consultation, analysis, generation, transformation, transmission, use, disclosure to authorised Subprocessors, restriction, deletion and other operations necessary to provide Customer-requested Services.

Purposes may include business intelligence; analysis; forecasting; acquisition; conversion; growth; procurement; bid and grant intelligence; investor and funding intelligence; market and competitor intelligence; campaign and content intelligence; opportunity discovery; planning; reporting; monitoring; automation; API and integration functionality; Customer-requested AI functionality; security; support; troubleshooting; reliability; and administration.

D. Categories of Data Subjects

Depending upon Customer's use of the Services, Data Subjects may include Customer employees, contractors, representatives, Authorised Users, administrators, customers, prospective customers, suppliers, business contacts, partners, investors, funders, applicants, professional contacts, website users and other individuals whose Personal Data Customer lawfully submits to or makes available through the Services.

E. Types of Personal Data

Depending upon Customer's use, Customer Personal Data may include identity and contact information; professional and organisational information; account and user information; communications; commercial information; business-contact information; transaction-related information; Customer-provided content; technical and device information; usage and interaction information; integration data; and other Personal Data Customer lawfully elects to Process through the Services.

F. Sensitive Personal Data

The Services are not intended to receive specially regulated or restricted data unless BACI expressly authorises the relevant Service or environment for that Processing. Where authorised, the categories will be determined by Customer's use and applicable contractual terms.

G. Frequency

Processing may occur continuously, periodically or on Customer request depending upon the Service and configuration.

H. Controller Instructions

The Agreement, Orders, Customer configuration, authorised use of the Services, support requests and other documented instructions consistent with the Agreement.

ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES

BACI maintains technical and organisational measures appropriate to the risk of Processing. Depending upon the Service and environment, measures may include:

1. Governance and Risk Management — security policies, assigned responsibilities, risk assessment and control review.

2. Identity and Access Management — role-based or otherwise appropriate access controls, authentication, least-privilege practices, access lifecycle management and administrative controls.

3. Tenant and Organisational Isolation — controls designed to maintain separation between Customer environments and authorised organisational contexts.

4. Encryption — appropriate protection of data in transit and at rest where supported and appropriate to the risk.

5. Logging and Monitoring — security logging, operational monitoring and investigation capabilities appropriate to the Service.

6. Secure Development — development practices intended to identify and reduce security vulnerabilities through the software lifecycle.

7. Vulnerability Management — identification, assessment, prioritisation and remediation of relevant vulnerabilities.

8. Infrastructure Security — controls appropriate to hosted infrastructure, networks, environments and administrative access.

9. Incident Response — processes for identification, containment, investigation, remediation, recovery and notification of Security Incidents.

10. Backup and Recovery — measures supporting recovery and resilience appropriate to the Service architecture.

11. Personnel Security — confidentiality obligations, appropriate access restrictions and security awareness measures.

12. Subprocessor and Vendor Risk — contractual and risk-management controls appropriate to third parties that Process Customer Personal Data.

13. Business Continuity — measures designed to support continuity and recovery of material Service functions.

14. Data Lifecycle Controls — retention, deletion and access controls appropriate to Customer Personal Data and the applicable Service.

15. Security Testing — vulnerability assessment, testing or other assurance activities appropriate to BACI's systems and risk profile.

Detailed and environment-specific controls may be described in the BACI Security Policy or Security Addendum. This Annex does not represent that BACI holds a particular certification unless BACI expressly identifies that certification as current.

ANNEX III — INTERNATIONAL TRANSFER TERMS

1. EU Standard Contractual Clauses

Where Customer Personal Data subject to the GDPR is transferred to BACI in a country that does not benefit from an applicable adequacy decision and the transfer requires the EU SCCs, the European Commission Standard Contractual Clauses adopted by Decision 2021/914 are incorporated by reference.

Where Customer is Controller and BACI is Processor, Module Two applies. Where Customer is Processor and BACI is Subprocessor, Module Three applies.

For Clause 9, general written authorisation for Subprocessors applies subject to the notice and objection mechanism in Section 9 of this DPA.

The optional redress language in Clause 11 will not apply unless the parties expressly agree otherwise.

For Clause 17, the parties select the law of an EU Member State that permits third-party beneficiary rights under the SCCs. Unless another eligible Member State is specified in an applicable Order, the laws of the Netherlands apply.

For Clause 18(b), unless another competent EU Member State court is specified in an applicable Order, the courts of the Netherlands will be the competent courts.

Annex I of this DPA supplies the relevant transfer description. Annex II supplies the technical and organisational measures. BACI's current Subprocessor list supplies relevant Subprocessor information.

2. United Kingdom

Where a restricted transfer subject to UK data-protection law requires contractual safeguards, the applicable EU SCCs as completed above will apply together with the then-current UK International Data Transfer Addendum issued by the UK Information Commissioner's Office, or another legally recognised UK mechanism selected by BACI and Customer.

References in the UK mechanism will be populated using the information in this DPA, the Agreement and applicable Order.

3. Switzerland and Other Adaptations

Where the EU SCCs are used for transfers subject to Swiss data-protection law or another jurisdiction that permits adaptation of the SCCs, references will be interpreted and modified only to the extent necessary to satisfy mandatory local requirements.

4. Transfer Hierarchy

If an adequacy decision or another valid mechanism applies and eliminates the legal need for the SCCs for a particular transfer, BACI may rely upon that mechanism. If a transfer mechanism is invalidated, replaced or materially amended, the parties will cooperate to implement a valid replacement mechanism.

5. Supplementary Measures

Where legally required, BACI will assess relevant transfer circumstances and implement reasonable supplementary technical, contractual or organisational measures appropriate to the risk.

ANNEX IV — UNITED STATES SERVICE PROVIDER / CONTRACTOR TERMS

To the extent a United States privacy law requires specific contractual restrictions for a processor, service provider or contractor, the following apply:

1. The specific business purposes and services are those described in the Agreement and Annex I.

2. BACI will Process Customer Personal Data only for those limited and specified purposes and as otherwise permitted by applicable law.

3. BACI will provide the same level of privacy protection required of the regulated recipient under applicable law.

4. Customer may take reasonable and appropriate steps to help ensure BACI uses Customer Personal Data consistently with Customer's applicable obligations, subject to the audit and security protections in this DPA.

5. BACI will notify Customer if BACI determines it can no longer meet an applicable statutory obligation.

6. Customer may take reasonable and appropriate steps required by applicable law to stop and remediate BACI's unauthorised use of Customer Personal Data.

7. BACI will not sell or share Customer Personal Data or use it for prohibited cross-context behavioural advertising where the applicable law restricts such activity by a processor, service provider or contractor.

8. BACI will not retain, use or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law.

9. BACI will not combine Customer Personal Data with other Personal Data where such combination is prohibited by applicable law.

10. BACI will require applicable Subprocessors to protect Customer Personal Data through written obligations appropriate to the statutory role.

These terms will be interpreted according to the applicable jurisdiction's definitions and do not expand a statutory restriction beyond the law that imposes it.

BACI DATA PROCESSING ADDENDUM — VERSION 1.0 Effective 10 September 2026

RELATED

We're listening.