Legal

Data Processing Addendum

The terms under which uRun Platform, Inc. processes Personal Data on behalf of Customer under the Agreement, incorporating the EU and UK Standard Contractual Clauses.

This Data Processing Addendum ("DPA") amends and forms part of the written agreement between Customer and uRun Platform, Inc. ("uRun") (collectively, "the parties") for the provision of services to Customer (the "Agreement"). This DPA prevails over any conflicting term of the Agreement but does not otherwise modify the Agreement.

01/Definitions

1.1 In this DPA:

a) "Data Protection Law" means all laws that apply to the Processing of Personal Data under the Agreement, including European Data Protection Law and the laws and regulations of the United States and its states, as amended from time to time, to the extent such laws and regulations apply to the relevant party.

b) "European Data Protection Law" means the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all other privacy and data protection laws of the European Economic Area ("EEA"), and their respective Member States, Switzerland and the United Kingdom ("UK") and all laws implementing or supplementing the foregoing.

c) "Personal Data" means any information that reasonably relates, directly or indirectly, to an identified or identifiable natural person that uRun may Process on Customer's behalf in performing the services under the Agreement.

d) "Processing" (including its cognate "Process") means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

e) "Security Incident" means a breach of security leading to the unauthorized or unlawful access by a third party, or confirmed accidental or unlawful destruction, loss or alteration, of Personal Data.

f) "Standard Contractual Clauses" means (i) Module 2 of the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj (the "EU SCCs"), and (ii) where the UK GDPR applies, the EU SCCs as supplemented by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Commissioner under S119A(1) Data Protection Act 2018 (the "UK SCCs").

1.2 Capitalized terms used but not defined herein have the meaning given to them in the Agreement.

02/Scope And Roles

2.1 The subject matter, nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects are set out in Annex I.

2.2 uRun agrees that it will Process Personal Data only in accordance with the Agreement and this DPA. To the extent applicable, uRun will Process Personal Data as a "processor" or "service provider" as such terms are defined under applicable Data Protection Law.

03/Data Protection

3.1 When uRun Processes Personal Data, it will:

a) Process the Personal Data in accordance with Customer's documented instructions as described in the Agreement or this DPA. uRun will notify Customer if it considers that an instruction from Customer is in breach of Data Protection Law, unless it is prohibited from doing so by law on important grounds of public interest;

b) assist Customer, taking into account the nature of the Processing and the information available to uRun, in complying with Customer's obligations to respond to requests concerning Personal Data from individuals under applicable Data Protection Law;

c) implement and maintain appropriate physical, technical and organizational measures to ensure a level of security appropriate to the risk, which include the technical and organizational measures required by applicable Data Protection Law;

d) only entrust the Processing of Personal Data to personnel who have undertaken to comply with confidentiality requirements; and

e) upon termination of the Agreement, as instructed by Customer, to the extent that uRun retains Personal Data, permit Customer to delete or obtain copies of such Personal Data consistent with the functionality of the Services and applicable law.

3.2 uRun certifies that it will not (a) "sell" (as defined in Data Protection Law) the Personal Data; (b) share the Personal Data for "cross-context behavioral advertising" (as defined in Data Protection Law); (c) retain, use, combine or disclose the Personal Data for any purpose other than as permitted under this DPA and in accordance with the Agreement; or (d) retain, use, or disclose the Personal Data other than in the context of the direct relationship with Customer in accordance with the Agreement.

3.3 Customer's documented instructions include instructions implemented through the configurations, workflows, and integrations that Customer or its authorized users deploy or enable through the Services. Subject to Section 3.2, uRun may Process Personal Data in accordance with those instructions, including by transmitting or otherwise making Personal Data available to users, third-party services, or other recipients designated through Customer's applications, as part of providing the Services on Customer's behalf.

04/Customer Responsibilities

Customer is responsible for the lawfulness of Personal Data processing under or in connection with the services. Customer will (i) provide all required notices and obtain all required consents, permissions and rights necessary under applicable Data Protection Law for uRun to lawfully Process Personal Data for the purposes contemplated by the Agreement; (ii) make appropriate use of the services to ensure a level of security appropriate to the particular content of the Personal Data; (iii) comply with all Data Protection Law applicable to the collection of Personal Data and the transfer of such Personal Data to uRun; and (iv) ensure its processing instructions comply with applicable laws (including applicable Data Protection Law).

05/Subprocessing

5.1 Customer agrees that uRun may use the third-party suppliers listed in Annex III to Process Personal Data on its behalf for the provision of the services under the Agreement (each a "Subprocessor").

5.2 uRun will maintain a list of Subprocessors and, prior to authorizing any new Subprocessor to access Personal Data, uRun will update the list of Subprocessors. uRun will notify Customer by email prior to the appointment of a new Subprocessor. If Customer objects to the appointment of such Subprocessor within ten (10) days, it may terminate the portion of the services that cannot be provided without such Subprocessor on written notice to uRun that includes Customer's legitimate and documented grounds for non-approval.

5.3 uRun will ensure that any Subprocessors to which it transfers Personal Data enter into written agreements with uRun requiring that the Subprocessor abide by terms substantially similar to those contained in this DPA. uRun will remain liable for any breaches of this DPA caused by its Subprocessors.

06/Restricted Data Transfers

6.1 In the event that Customer is subject to European Data Protection Law and the transfer of Personal Data to uRun would be restricted in the absence of the Standard Contractual Clauses, the Parties agree that the Standard Contractual Clauses shall be incorporated into this DPA with Customer as the "data exporter" and uRun as the "data importer."

6.2 The Standard Contractual Clauses are further completed as follows: the optional docking clause in Clause 7 is implemented; Clause 9(a) option 2 is implemented and the time period therein is specified as thirty (30) days; the optional redress clause in Clause 11(a) is struck; the governing law in Clause 17 is the law of the Republic of Ireland; the court in Clause 18(b) are the Courts of the Republic of Ireland; and Annex 1, 2 and 3 to the Standard Contractual Clauses are Annex I, Annex II and Annex III of this DPA respectively. To the extent required by Data Protection Law in the UK, Part 1, tables 1, 2 and 3 of the UK SCCs will be deemed to be completed like its equivalent provisions in the EU SCCs. For the purpose of Part 1, Table 4, the party that may end the UK SCCs in accordance with Section 19 of the UK Addendum is the importer.

07/Assistance And Notifications

7.1 Upon Customer's request, uRun will provide Customer with reasonable cooperation and assistance to the extent required to fulfil Customer's obligation under European Data Protection Law to:

a) reply to investigations and inquiries from data protection regulators; and

b) carry out a data protection impact assessment related to the services, where Customer does not otherwise have access to the relevant information necessary to perform such assessment.

7.2 Unless prohibited by Data Protection Law, uRun must inform Customer without undue delay if uRun:

a) receives a request, complaint or other inquiry regarding the Processing of Personal Data;

b) receives a binding or non-binding request to disclose Personal Data from law enforcement, courts or any government body;

c) is subject to a legal obligation that requires uRun to Process Personal Data in contravention of Customer's instructions; or

d) is otherwise unable to comply with Data Protection Law or this DPA.

7.3 Upon becoming aware of a Security Incident, uRun will inform Customer without undue delay and will provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by Customer to allow Customer to fulfil its data breach reporting obligations under applicable Data Protection Law.

08/Audit

8.1 uRun will make available to Customer at Customer's request information which is necessary to demonstrate compliance with this DPA and allow for any audits, including inspections, conducted by Customer or another auditor, as requested by Customer.

8.2 To the extent uRun makes available to Customer confidential summary reports ("Audit Report") prepared by third-party security professionals, Customer agrees to accept such Audit Report, subject to confidentiality requirements, in satisfaction of its audit right; however, if Customer can demonstrate that it requires additional information, beyond the Audit Report, then Customer may request, at Customer's cost, uRun to provide for an audit subject to reasonable confidentiality procedures, which will: (i) not include access to any information that could compromise confidential information relating to other uRun customers or suppliers, uRun's technical and organizational measures, or any trade secrets; and (ii) be performed upon not less than thirty (30) days' notice, during regular business hours and in such a manner as not to unreasonably interfere with uRun's normal business activities.

09/General

9.1 If there is any conflict between this DPA and the Agreement, this DPA will prevail to the extent of that conflict in connection with the Processing of Personal Data.

9.2 If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

9.3 Notwithstanding anything to the contrary in the Agreement or this DPA, the liability of each party under this DPA is subject to the limitations of liability set out in the Agreement.

9.4 This DPA will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement.

10/Annex I: List of Parties

A. List of Parties

Customer is the controller and the data exporter and uRun is the processor and the data importer.

B. Description of Transfer

TopicDescription
Subject MatteruRun's provision of the Services to Customer under the Agreement.
Duration of the ProcessingThe duration of the Agreement
Nature and Purpose of the ProcessingProcessing of Personal Data as necessary to provide the Services and perform the services under the Agreement, including: hosting and running AI models and Customer applications within the Platform; receiving and processing prompts, text, audio, video, and other Customer inputs to generate and deliver AI outputs; managing authentication and access to the Platform and Customer applications; and providing technical support, troubleshooting, and operational and security monitoring.
Frequency of the ProcessingContinuous
Categories of DataPersonal Data contained in prompts, messages, files, and other inputs submitted to the Services, and in outputs generated through the Platform; contact and identification data, including names, email addresses, and user identifiers; and authentication, session, and technical data, including IP addresses, device information, timestamps, usage records, and application logs, in each case to the extent processed on Customer's behalf in connection with the Services.
Special Categories of Data ProcessedN/A - no special categories of Personal Data or other Personal Data classified as sensitive under applicable Data Protection Laws are contemplated. Customer shall not submit such data to the Services unless expressly agreed in writing by the parties.
Data SubjectsCustomer's employees, contractors, agents, and authorized users; users of Customer applications and services powered by the Services; and other individuals whose Personal Data is included in inputs submitted to, or outputs generated through, the Platform on Customer's behalf.

C. Competent Supervisory Authority

The competent supervisory authority is the Irish Data Protection Commission.

11/Annex II: Technical and Organizational Measures

uRun shall implement and maintain the technical and operational measures and control listed in this Annex II in accordance with industry standards generally accepted by information security professionals as necessary to reasonably protect Personal Data during storage, processing and transmission.

1. System access. Measures to prevent unauthorized access to Processing systems, including unique user authentication, password policies, multi-factor authentication, and approved encrypted remote connections. Privileged access to production systems is restricted to authorized personnel with a business need.

2. Data access. Measures to restrict access to Personal Data based on role and business need, including least-privilege access provisioning and access control procedures governing the creation, modification, and removal of user access. Offboarding procedures ensure timely revocation of access.

3. Encryption and transmission security. Encryption of datastores containing sensitive Customer data at rest and secure transmission protocols for data in transit. Access to encryption keys is restricted to authorized users with a business need.

4. Security monitoring and vulnerability management. Measures to identify and address security threats, including network intrusion detection, security log management, infrastructure monitoring, and firewalls. Measures also include vulnerability management procedures, routine infrastructure patching, anti-malware protection, and automated security scanning of code changes. Penetration testing is performed at least annually.

5. Organizational and personnel security. Documented security policies reviewed at least annually, formally assigned security responsibilities, and a documented risk management program. Personnel measures include background checks, confidentiality agreements, and codes of conduct. Incident response procedures are maintained and tested at least annually.

6. Availability and recovery. Measures to support service availability and recovery, including infrastructure performance monitoring and documented backup policies. Business continuity and disaster recovery plans are maintained and tested at least annually.

7. Data retention and disposal. Documented retention and disposal procedures and a data classification policy governing the lifecycle of Personal Data. Customer content can be deleted through available Service functionality or upon request. Electronic media containing confidential information is securely purged or destroyed.

12/Annex III: List of Subprocessors

Customer authorizes uRun to engage the following Subprocessors:

Name of approved SubprocessorNature of Service ProvidedLocation from where service is provided
Amazon Web ServicesInfrastructure hostingUnited States
WorkOSAuthentication and single sign-onUnited States
PostHogProduct analyticsUnited States
StripeBilling and payment processingUnited States