Attribute
Log in

Data Processing Addendum

Effective Date: August 3, 2026
Last Updated: August 30, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Ultimate, Inc., which offers the Enterprise Services under the Attribute brand ("Attribute"), and the Customer identified in the applicable Order Form or other agreement ("Customer") governing Customer's use of the Enterprise Services (the "Agreement"). This DPA applies when Attribute processes Customer Personal Data on Customer's behalf.

By executing an Order Form or Agreement that incorporates this DPA, or by otherwise accepting this DPA through an authorized electronic process, the parties agree to its terms. Capitalized terms not defined here have the meanings given in the Agreement.

Role summary Customer is generally the controller or business, and Attribute is generally the processor, service provider, or contractor. If Customer acts as a processor for another controller, Attribute acts as Customer's subprocessor for that processing. Attribute remains an independent controller for limited business-operations processing that it determines independently, such as billing, direct account administration, service security, and legal compliance, as described in the Privacy Policy.

1. Scope and precedence

1.1 Scope

This DPA applies only to Customer Personal Data processed by Attribute on Customer's behalf in connection with Enterprise Services. It does not apply to information for which Attribute acts as an independent controller or business, including the limited processing described in Section 3.4, or to personal services used by a Direct User outside an organization Workspace.

The subject matter, duration, nature, purposes, Personal Data categories, Data Subject categories, and service-specific instructions are described in the Agreement, Customer's configuration and use of the Services, and Annex A. If an Order Form expressly modifies Annex A for a Customer, the Order Form controls for that Customer.

1.2 Order of precedence

For matters concerning Customer Personal Data, this DPA controls over conflicting provisions of the Agreement. The International Transfer Terms in Annex D, including any incorporated Standard Contractual Clauses, control over conflicting provisions of this DPA to the extent required for a Restricted Transfer. An Order Form controls only where it expressly identifies the DPA provision being modified and does not reduce protections required by Applicable Data Protection Law.

1.3 No reduction of mandatory rights

Nothing in this DPA reduces a Data Subject's mandatory rights, limits a regulator's lawful authority, or relieves either party of obligations imposed directly on it by Applicable Data Protection Law. Contract labels do not determine the parties' legal roles where the law requires a fact-based determination.

2. Definitions

"Applicable Data Protection Law" means a law or regulation applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK Data Protection Laws, the Swiss Federal Act on Data Protection, the CCPA, and other U.S. state comprehensive privacy laws.

"AI Provider" means a third-party model developer, model host, cloud AI platform, inference service, model router or broker, or similar service that processes data for an AI Feature. Depending on who selects, contracts for, configures, or controls the connection, an AI Provider may be an Attribute Subprocessor or a Customer-directed recipient.

"CCPA" means the California Consumer Privacy Act of 2018, as amended, and its implementing regulations.

"Controller" means the entity that determines the purposes and means of processing Personal Data, including a "business" or equivalent term under Applicable Data Protection Law.

"Customer Personal Data" means Personal Data contained in Customer Data that Attribute processes on Customer's behalf. It excludes Personal Data for which Attribute acts as an independent Controller and information that has been validly deidentified so it is no longer Personal Data under applicable law.

"Customer Personal Data Breach" means a confirmed breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Attribute's or a Subprocessor's possession or control. It excludes unsuccessful attempts that do not compromise Customer Personal Data, such as blocked probes, scans, pings, denial-of-service attempts, or failed login attempts.

"Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates, including a consumer where that term is used by Applicable Data Protection Law.

"Deidentified Data" means information processed so that it cannot reasonably be linked to an identified or identifiable individual or Customer, taking into account applicable legal standards and reasonably available means.

"Documented Instructions" means written or electronically recorded instructions from Customer, including the Agreement, Order Form, configured settings, authorized user actions, API calls, integration commands, support requests, and other instructions described in Section 4.

"GDPR" means Regulation (EU) 2016/679.

"Generalized AI Model Training" means training or materially fine-tuning a model intended to serve users or customers generally, rather than performing inference, retrieval, or Customer-specific processing to provide the enabled Services.

"Personal Data" means information defined as personal data, personal information, or an equivalent term under Applicable Data Protection Law.

"Processor" means an entity that processes Personal Data on behalf of a Controller, including a service provider, contractor, or equivalent role under Applicable Data Protection Law.

"Restricted Transfer" means a transfer of Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.

"Sensitive Data" means Personal Data subject to heightened protection under Applicable Data Protection Law, including government identifiers, account credentials, financial information, precise location, biometric or genetic data, health information, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, data concerning children, and other legally designated sensitive information.

"Subprocessor" means a third party engaged by Attribute to process Customer Personal Data on Customer's behalf. A Customer-directed recipient that receives data under Customer's independent contract or instruction is not necessarily an Attribute Subprocessor.

"UK Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, and applicable UK privacy and electronic-communications law, each as amended.

3. Roles and legal compliance

3.1 Customer as Controller or business

Customer determines the purposes and essential means of processing Customer Personal Data and acts as Controller or business. Customer is responsible for the lawfulness, fairness, transparency, accuracy, and proportionality of its processing; for identifying a lawful basis; and for providing required notices, obtaining required consents, honoring rights, and issuing lawful instructions.

3.2 Customer as Processor

If Customer processes Customer Personal Data on behalf of another Controller, Customer acts as a Processor and appoints Attribute as a Subprocessor. Customer represents that the relevant Controller has authorized Customer to appoint Attribute and that Customer's instructions to Attribute are consistent with the Controller's instructions. Customer remains Attribute's sole contractual counterparty unless otherwise agreed in writing.

3.3 Attribute as Processor, service provider, or contractor

Attribute will process Customer Personal Data only on Documented Instructions, in accordance with this DPA, and as required by Applicable Data Protection Law. Attribute will comply with obligations imposed directly on it in its role as Processor, service provider, contractor, or Subprocessor and will provide the level of privacy protection required by applicable law.

If Attribute reasonably believes an instruction violates Applicable Data Protection Law, Attribute will promptly inform Customer unless prohibited by law and may suspend the affected processing until the parties resolve the issue. Attribute is not required to perform an instruction that is technically impossible, would compromise security or another customer, or is not required by the Agreement, but will explain the limitation and reasonably cooperate on an alternative.

3.4 Attribute as independent Controller

Attribute may act as an independent Controller for limited processing that it determines independently, such as establishing and administering the commercial relationship, billing, direct communications, preventing fraud and abuse, protecting the Services, complying with law, managing legal claims, and processing limited account or contact information as described in the Privacy Policy. This DPA does not govern that independent processing, but Attribute will not use this distinction to avoid its Processor obligations for Customer Personal Data.

4. Documented instructions

4.1 Sources of instructions

Customer instructs Attribute to process Customer Personal Data as necessary to provide, secure, maintain, support, and administer the Enterprise Services selected in the Order Form and enabled through Customer's configuration. Documented Instructions include:

• the Agreement, this DPA, Order Forms, statements of work, and product-specific terms;

• settings, permissions, retention choices, integrations, data mappings, workflows, Agents, tools, and features configured by Customer or its Administrators;

• uploads, entries, prompts, forms, API requests, integration calls, exports, and other actions performed through authorized Accounts or credentials;

• support, migration, implementation, correction, return, deletion, and security instructions submitted through authorized channels; and

• other written instructions accepted by Attribute in writing.

4.2 Reliance on authorized instructions

Attribute may rely on instructions from Customer's Administrators, Authorized Users, service accounts, integrations, and Agents to the extent they appear authorized under Customer's configuration and the Agreement. Customer is responsible for the authority and accuracy of those instructions. Attribute will maintain server-side controls designed to prevent a browser, integration payload, or AI prompt from asserting unverified identity, authority, tenant, or data-boundary facts as security facts.

4.3 Processing required by law

If law requires Attribute to process Customer Personal Data other than on Customer's instructions, Attribute will inform Customer before the processing unless the law prohibits notice on important public-interest grounds. Attribute will limit the processing to what the law requires and continue to protect the data under this DPA to the extent permitted.

5. Purpose limitation and prohibited uses

5.1 Limited purposes

Attribute will retain, use, and disclose Customer Personal Data only for the specific business purposes in Annex A, Customer's Documented Instructions, security and fraud prevention, legal compliance, and other purposes expressly permitted for a Processor under Applicable Data Protection Law. Attribute will not materially expand those purposes through documentation, a privacy-policy change, or a product setting without the authorization required by the Agreement and law.

5.2 Prohibited processing

Except where Customer provides separate affirmative authorization in a written agreement and the processing is lawful, Attribute will not:

• sell Customer Personal Data or share it for cross-context behavioral advertising;

• use Customer Personal Data for third-party advertising, data brokerage, or marketing unrelated to Customer;

• retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than the purposes specified in this DPA;

• combine Customer Personal Data with Personal Data received from another customer or collected from Attribute's independent interaction with a Data Subject, except where specifically permitted by law and necessary to provide or secure the Services;

• use Customer Personal Data to train a generalized AI model for Attribute or a third party;

• attempt to reidentify Deidentified Data except to test and improve the effectiveness of deidentification as permitted by law; or

• permit a Subprocessor to process Customer Personal Data for the Subprocessor's independent commercial purposes.

5.3 Access and disclosure minimization

Attribute will limit access and disclosure to the minimum reasonably necessary for the authorized purpose. Personnel access to Customer Personal Data will be based on job responsibility, need to know, approved support or operational purposes, and appropriate authorization. Attribute will not retrieve broad data sets and rely only on instructions to a model or person not to disclose unauthorized information.

6. Confidentiality and personnel

6.1 Confidentiality obligations

Attribute will ensure that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality and receive instructions regarding the confidential and restricted nature of the data. Those obligations survive termination of personnel access and employment as applicable.

6.2 Access administration

Attribute will grant access according to least privilege, use unique identities for personnel where practicable, periodically review privileged access, and promptly remove or adjust access when it is no longer required. Production access will be limited to personnel with an authorized operational, security, engineering, support, or legal need.

6.3 Training and conduct

Attribute will maintain privacy and security awareness measures appropriate to personnel roles and will take reasonable disciplinary or corrective action for violations of applicable confidentiality, privacy, or security requirements.

7. Security measures

7.1 Security program

Attribute will implement and maintain appropriate administrative, technical, organizational, and physical measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures will take into account the state of the art, implementation cost, the nature, scope, context, and purposes of processing, and risks to individuals.

7.2 Minimum measures

The security measures in Annex B are incorporated into this DPA. Attribute may update those measures to reflect changes in technology, threats, law, and the Services, provided the update does not materially reduce the overall security of the Enterprise Services during the applicable subscription term.

7.3 Security boundaries and authorization

Attribute will use server-side access controls designed to enforce Customer and Workspace boundaries, least privilege, resource authorization, sensitive-field restrictions, and separate authority for consequential tools or automated actions. Missing or unresolved authorization context will not be treated as public or unrestricted access. Presentation-layer controls alone do not constitute authorization enforcement.

7.4 Security certifications and reports

Any certification, independent assessment, penetration test, or audit report identified in the Order Form or Security Overview applies only to the stated scope and period. Attribute will not represent that it maintains a certification or assurance report unless it is current and applicable to the Services covered by the representation.

8. Customer responsibilities

8.1 Lawful data and instructions

Customer will ensure that Customer Personal Data and its instructions comply with Applicable Data Protection Law and the Agreement. Customer will provide required notices, obtain required permissions and consents, and have authority to disclose Customer Personal Data to Attribute and Customer-directed recipients.

8.2 Data minimization and configuration

Customer will limit Customer Personal Data to what is reasonably necessary for the enabled purpose; configure permissions, retention, sharing, integrations, and AI features appropriately; and avoid placing unnecessary secrets, credentials, full payment-card data, health information, or other restricted data into free-text fields, prompts, logs, or unsupported features.

8.3 Security responsibilities

Customer is responsible for its Accounts, identity provider, credentials, devices, networks, connected systems, Administrator appointments, user lifecycle, permissions, and lawful use of exports. Customer will promptly notify Attribute of suspected credential compromise, unauthorized access, or an instruction that should be revoked or corrected.

8.4 Accuracy and decisions

Customer remains responsible for the accuracy of source data and for reviewing extracted fields, recommendations, classifications, and other Output before relying on them for legal, financial, employment, credit, regulatory, or other consequential decisions. Attribute's assistance does not transfer Customer's Controller obligations to Attribute.

9. Data-subject and consumer requests

9.1 Customer responsibility

Customer is responsible for receiving, verifying, evaluating, and responding to requests from Data Subjects concerning Customer Personal Data. Customer will determine whether a request is valid, whether an exception applies, and what response is required.

9.2 Attribute assistance

Taking into account the nature of processing, Attribute will provide reasonable technical and organizational assistance, insofar as possible, to enable Customer to respond to requests for access, confirmation, correction, deletion, restriction, objection, portability, opt-out, consent withdrawal, appeal, or information about automated processing. Assistance may include self-service tools, administrative functions, export capabilities, support processes, or scoped engineering work.

9.3 Direct requests

If Attribute receives a request directly from a Data Subject concerning Customer Personal Data, Attribute will not independently fulfill the request unless Customer instructs it to do so or law requires. Attribute will redirect the requester to Customer or promptly forward the request to Customer when reasonably identifiable, subject to security and legal restrictions.

9.4 Request security

Attribute may require Customer to provide information reasonably necessary to locate the relevant records and verify Customer's authority. Attribute will not disclose passwords, secret credentials, full financial account numbers, private encryption keys, or information that would compromise another person or Customer in response to a rights request.

10. Compliance assistance

10.1 Security, breach, and impact-assessment assistance

Taking into account the nature of processing and information available to Attribute, Attribute will reasonably assist Customer with obligations relating to security, Customer Personal Data Breaches, data-protection impact assessments, risk assessments, automated-decision assessments, cybersecurity audits, and prior consultation with a regulator, where the obligation relates to Customer's use of the Enterprise Services.

10.2 Information supplied

Assistance may include relevant portions of this DPA, the Security Overview, Subprocessor information, data-flow information, technical documentation, independent assurance reports, responses to reasonable questionnaires, and facts in Attribute's possession necessary for Customer's assessment. Attribute is not required to disclose another customer's information, privileged material, trade secrets unrelated to the assessment, or details that would materially increase security risk.

10.3 Regulatory cooperation

Attribute will cooperate with a competent supervisory authority or regulator to the extent required by Applicable Data Protection Law for processing covered by this DPA. Customer will promptly notify Attribute of a regulatory inquiry materially relating to the Services unless prohibited by law.

10.4 Additional assistance

Standard assistance reasonably available through the Services and ordinary compliance materials is included in the fees. If Customer requests substantial bespoke assistance beyond Attribute's legal obligations or standard offering, the parties may agree on scope, timing, and reasonable fees before work begins, except where the need results from Attribute's breach of this DPA.

11. Customer Personal Data Breaches

11.1 Notification

Attribute will notify Customer without undue delay after becoming aware of a Customer Personal Data Breach. Where reasonably practicable, Attribute will provide an initial notice within 48 hours after confirming that a Customer Personal Data Breach occurred, unless a shorter period is stated in the Order Form or required by law. Notification is not an admission of fault or liability.

11.2 Information and updates

To the extent known and reasonably available, Attribute's notice will describe:

• the nature of the breach and the affected systems or Services;

• the categories of Customer Personal Data and Data Subjects affected and approximate numbers, if known;

• the likely consequences or material risks identified by Attribute;

• measures taken or proposed to contain, investigate, remediate, and mitigate the breach; and

• a contact point for follow-up.

Attribute may provide information in phases as the investigation progresses and will provide material updates without undue further delay. Customer acknowledges that early information may be incomplete and subject to correction.

11.3 Response and cooperation

Attribute will take reasonable steps to contain and remediate a Customer Personal Data Breach, preserve relevant evidence, investigate root cause, and reduce recurrence risk. Attribute will reasonably assist Customer with legally required notices and responses. Customer is responsible for determining whether to notify Data Subjects, regulators, counterparties, insurers, or others, except where law requires Attribute to notify directly.

11.4 Communications

Neither party will make a public statement identifying the other party in connection with a Customer Personal Data Breach without prior consultation, except where law, a regulator, or securities rules require otherwise. This does not prevent either party from complying with legal notice obligations or accurately responding to affected individuals.

12. Subprocessors and Customer-directed recipients

12.1 General authorization

Customer provides general written authorization for Attribute to engage Subprocessors in accordance with this Section and Annex C. Attribute will maintain a current Subprocessor List at Subprocessor List identifying each material Subprocessor, its processing purpose, and relevant processing location or transfer information.

12.2 Subprocessor obligations

Before a Subprocessor processes Customer Personal Data, Attribute will enter into a written agreement requiring the Subprocessor to protect the data through obligations materially consistent with those imposed on Attribute for the delegated processing, including confidentiality, security, purpose limitation, incident notification, deletion or return, and transfer safeguards as applicable. Attribute remains responsible for a Subprocessor's performance to the extent required by Applicable Data Protection Law and the Agreement.

12.3 Notice of changes

Attribute will provide at least 30 days' advance notice before authorizing a new material Subprocessor to process Customer Personal Data, ordinarily through the Subprocessor List, email, an administrative notice, or another durable channel. Attribute may use a shorter period for an urgent replacement necessary to protect security, availability, or legal compliance, but will provide notice as soon as reasonably practicable.

12.4 Objections

Customer may object to a new Subprocessor on reasonable and documented data-protection grounds by notifying Attribute within 15 days after notice. The parties will work in good faith to address the objection, including by providing additional information, applying reasonable safeguards, or using a commercially reasonable alternative where available. If the parties cannot resolve the objection, Customer may terminate only the affected Service by written notice within 30 days after Attribute's final response and receive a prorated refund of prepaid fees for the unused terminated portion. An objection does not excuse payment for unaffected Services.

12.5 Customer-directed recipients

When Customer instructs Attribute to transmit Customer Personal Data to a Third-Party Service selected, contracted, or controlled by Customer - such as Customer’s ERP, storefront, identity provider, payment provider, direct AI model account, model endpoint, model router, cloud project, local or private inference environment, or other integration - that recipient is a Customer-directed recipient and not an Attribute Subprocessor merely because the transfer occurs through the Services. Customer is responsible for the recipient, the transfer instruction, credentials and permissions it supplies, provider terms, fees, retention and training settings, and the recipient’s safeguards. Attribute remains responsible for securely carrying out the authorized transmission within the Services.

13. International transfers and government requests

13.1 Processing locations

Customer authorizes Attribute and its Subprocessors to process Customer Personal Data in the United States and other countries identified in the Subprocessor List or Order Form. Unless an Order Form expressly provides a data-residency commitment, the Services do not guarantee that all processing, support, logs, or backups will remain in a particular country or region.

13.2 Restricted Transfers

The parties will use a lawful transfer mechanism for each Restricted Transfer. Annex D incorporates the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss adaptations where applicable. If a valid adequacy decision, certification, statutory mechanism, or replacement transfer framework applies, the parties may rely on that mechanism for the covered transfer.

13.3 Transfer assessments and supplementary measures

Attribute will provide information reasonably available to it to support Customer's transfer assessment. Where required and appropriate to the risk, Attribute will apply supplementary technical, contractual, or organizational measures, which may include encryption, access restrictions, minimization, transparency measures, and procedures for government demands.

13.4 Government and legal demands

If Attribute receives a legally binding demand from a public authority for Customer Personal Data, Attribute will, to the extent legally permitted:

• review the demand for legal validity and proper scope;

• notify Customer before disclosure and provide a copy or meaningful summary;

• challenge or seek clarification of an unlawful, overbroad, or disproportionate demand where there are reasonable grounds;

• disclose only the minimum data legally required;

• request confidential treatment or protective measures where available; and

• document the demand and response as required by applicable transfer terms.

Attribute will not voluntarily provide bulk, indiscriminate, or direct government access to Customer Personal Data. Nothing in this Section requires Attribute to violate law or disclose information that law prohibits it from providing to Customer.

14. Audit and compliance information

14.1 Demonstrating compliance

Attribute will make available information reasonably necessary to demonstrate compliance with its Processor obligations under this DPA. Attribute may satisfy routine requests by providing current third-party audit reports, certifications, penetration-test summaries, policies, security documentation, or responses to a reasonable questionnaire, subject to confidentiality and security restrictions.

14.2 Customer assessments

Customer may conduct one reasonable assessment in any 12-month period, and additional assessments where required by a competent regulator, following a Customer Personal Data Breach, or where Customer has documented evidence of material noncompliance. The assessment must be proportionate to the processing and coordinated to minimize disruption.

14.3 On-site or technical inspections

An on-site inspection or intrusive technical test is permitted only where required by Applicable Data Protection Law or a regulator, or where available independent materials are insufficient to address a documented material concern. Customer will provide at least 30 days' notice unless an urgent legal or security need makes that impracticable; use an independent qualified auditor that is not a direct competitor; conduct the review during normal business hours; comply with Attribute's safety and confidentiality requirements; and avoid accessing other customers' data or systems.

14.4 Costs and findings

Customer bears its assessment costs and Attribute's reasonable costs for exceptional assistance, unless the assessment identifies a material breach of this DPA by Attribute, in which case Attribute will bear its reasonable internal cooperation costs. Customer will provide Attribute a copy of relevant findings and allow a reasonable opportunity to remediate. Audit information is Attribute Confidential Information and may be used only for Customer's compliance, risk, and procurement purposes.

15. Return, deletion, and retention

15.1 During the term

Customer may access, export, correct, or delete Customer Personal Data using available administrative and product features. Attribute will provide reasonable assistance for data that cannot be managed through ordinary features, subject to the Agreement and Section 10.4.

15.2 End of Services

At Customer's choice, Attribute will return or delete Customer Personal Data after the end of the Services involving the processing. Customer must communicate its choice before termination or during any post-termination retrieval period in the Agreement. If Customer does not make a choice, Attribute may delete the data after the retrieval period expires, subject to legal retention and backup cycles.

15.3 Copies, backups, and legal retention

Attribute will delete active copies within the period stated in the Agreement, Order Form, or applicable retention schedule. Customer Personal Data may remain in encrypted or access-restricted backups until overwritten through ordinary rotation, provided it is not restored or otherwise processed except for disaster recovery, security, or legal compliance and remains protected by this DPA. If law requires retention, Attribute will isolate the retained data, limit processing to the legal purpose, and delete it when the requirement ends.

15.4 Confirmation

Upon reasonable written request after deletion is complete, Attribute will provide a written confirmation of deletion by an authorized representative, subject to lawful retention exceptions and ordinary backup cycles.

16. Service Data and deidentified information

16.1 Service Data

Attribute may process technical, diagnostic, usage, performance, security, and operational data to provide, secure, support, administer, and improve the Services. To the extent Service Data contains Customer Personal Data processed on Customer's behalf, this DPA applies. Attribute's independent processing of limited account, billing, relationship, fraud-prevention, and legal-compliance information is governed by the Privacy Policy.

16.2 Deidentified and aggregated information

Attribute may create and use aggregated or Deidentified Data for security, capacity planning, analytics, reliability, benchmarking, and improvement, provided Attribute:

• uses reasonable measures to prevent the information from being associated with a Data Subject or Customer;

• maintains the information in deidentified or aggregated form;

• does not attempt to reidentify it except to test deidentification as permitted by law;

• does not disclose it in a form that reasonably identifies Customer or a Data Subject; and

• contractually requires any recipient to observe equivalent restrictions where required.

17. AI and automated processing

17.1 AI processing remains instructed processing

An enabled AI Feature may process Customer Personal Data to extract, validate, classify, summarize, retrieve, search, generate, recommend, or propose actions only for the purposes in Annex A and Customer's Documented Instructions. Use of an AI Feature does not convert Attribute or an AI Provider into an independent Controller of Customer Personal Data.

17.2 No generalized model training

Attribute will not use Customer Personal Data, Inputs, Outputs, document contents, embeddings, or Customer-specific derived data for Generalized AI Model Training by Attribute or a third party unless Customer provides separate affirmative authorization in a written agreement or a clearly labeled opt-in designed specifically for that purpose. Accepting the Agreement, enabling routine AI functionality, or submitting data for inference does not by itself authorize generalized model training.

17.3 AI providers, routers, and deployment options

Attribute may support AI processing through direct model providers, cloud AI platforms, multi-provider routing services, and local or private model deployments. Representative model sources may include Anthropic (Claude), Google Cloud (Gemini), OpenAI, SpaceXAI (Grok), OpenRouter, and other current or future providers, but this DPA does not guarantee availability or authorize an unnamed Subprocessor. The applicable provider, route, region, and deployment may vary by Service and Customer configuration.

17.4 Attribute-selected and Customer-selected AI processing

An AI Provider selected and controlled by Attribute that receives Customer Personal Data is a Subprocessor and is subject to Section 12. Attribute will contractually restrict it to authorized service functions, prohibit sale and targeted advertising, restrict independent use, require appropriate security and confidentiality, and prohibit Generalized AI Model Training with Customer Personal Data unless Customer separately authorizes it. When Customer supplies or selects a provider account, API key, cloud project, endpoint, router, hosted deployment, or local/private model environment, the provider is generally a Customer-directed recipient under Section 12.5. If Attribute operates a model within Attribute-controlled infrastructure, the model software or weights are not themselves a Subprocessor, but any third-party infrastructure or managed operator that processes Customer Personal Data must be classified and disclosed as applicable.

17.5 Routing, downstream providers, and fallback

Where a model router or broker is used, the router and the applicable downstream model-provider chain will be governed and disclosed to the extent required by Section 12, Annex C, and Applicable Data Protection Law. Attribute will apply configured provider allowlists, model restrictions, region, retention, training, and data-use rules to routing decisions. A fallback route may not expand Customer’s Documented Instructions or bypass a required restriction; where no eligible route is available, the affected request may fail or remain unprocessed.

17.6 Context minimization and egress controls

Attribute will apply controls designed to ensure that Customer Personal Data is admitted to an AI model or tool context only when the requesting user, Agent, service account, or integration is authorized; the purpose is enabled and within Customer's instructions; applicable data-use and provider controls permit the processing; and the context is reasonably minimized or redacted for the task. Permission to view a resource does not automatically authorize every AI purpose, export, disclosure, or tool execution.

17.7 Agents and consequential actions

Model Output alone does not authorize an Agent or workflow to execute a consequential action. Actions must pass applicable server-side identity, authorization, delegation, task, workflow, approval, tool, integration, and system-of-record controls. Customer remains responsible for configuring appropriate human review, segregation of duties, notices, appeals, and legal safeguards for automated or AI-assisted decisions.

17.8 Output and derived data

To the extent Output, extracted fields, summaries, classifications, embeddings, recommendations, or other derived data relates to an identifiable individual, it is Customer Personal Data and is protected by this DPA. Customer is responsible for correcting inaccurate source information and for deciding whether and how derived data should be retained or used.

18. Regulated and high-risk data

18.1 Supported business-onboarding information

Where enabled in the applicable Service, Customer may process business-onboarding and commercial records such as business names, contact details, tax or employer identifiers, resale certificates, licenses, trade references, commercial credit information, and supporting documents. Customer must limit those records to what is lawful and necessary and use configured sensitive-field and access controls.

18.2 Restricted categories

Unless an Order Form or product-specific agreement expressly authorizes the category and identifies required safeguards, Customer must not submit or use the Services to process:

• protected health information subject to HIPAA;

• full payment-card data or authentication data subject to PCI DSS;

• biometric templates used for unique identification, genetic data, or neural data;

• consumer-report data regulated by the Fair Credit Reporting Act for eligibility decisions;

• information about children or minors where specialized consent and protection requirements apply;

• criminal-offense data, special-category data, or highly sensitive government data at scale;

• classified information, export-controlled technical data, or government-controlled information requiring a specialized environment; or

• any data category that the Documentation identifies as unsupported.

18.3 High-impact and automated decisions

Customer may not use the Services as the sole or determinative basis for a High-Impact Decision unless an Order Form expressly authorizes that use and the parties document appropriate processing instructions, impact assessment support, accuracy and bias controls, notices, human review, rights handling, and other legal safeguards. Attribute may suspend unsupported high-risk processing to protect Data Subjects, Customer, or the Services.

19. Liability and termination

19.1 Liability framework

The liability limitations, exclusions, indemnities, and remedies in the Agreement apply to this DPA, except to the extent prohibited by Applicable Data Protection Law or an incorporated transfer mechanism. Nothing limits a Data Subject's rights or remedies under the Standard Contractual Clauses or other mandatory law.

19.2 Material inability to comply

Attribute will promptly notify Customer if it determines that it can no longer meet a material obligation under Applicable Data Protection Law or this DPA. Customer may take reasonable and appropriate steps to stop and remediate unauthorized processing, including suspending affected data flows. If material noncompliance cannot be remedied within a reasonable period, either party may terminate the affected processing or Service as permitted by the Agreement and mandatory law.

19.3 Survival

Sections concerning confidentiality, restrictions on use, security, audits, transfers, return and deletion, liability, and any provisions that by their nature should survive will remain effective for as long as Attribute retains Customer Personal Data.

20. General terms

20.1 Notices

Privacy, security, and Subprocessor notices may be delivered to the notice contacts in the Agreement, the Customer Administrator, or another durable channel configured by Customer. Customer is responsible for keeping its contacts current. Legal notices are governed by the Agreement.

20.2 Changes to this DPA

Attribute may update this DPA to reflect changes in law, transfer mechanisms, or the Services. Attribute will provide reasonable notice of a material change. An update will not materially reduce the protection of Customer Personal Data during the current subscription term without Customer's agreement, except where a change is required by law or a regulator. Updated mandatory transfer clauses may apply according to their terms.

20.3 Entire data-processing agreement

This DPA, including its Annexes and any valid Customer-specific amendment, is the parties' complete agreement concerning Attribute's processing of Customer Personal Data on Customer's behalf and supersedes prior terms on the same subject. Except as modified by this DPA, the Agreement remains in effect.

20.4 Contact

Data-protection questions and requests under this DPA should be sent to the Privacy email below. Security-incident notifications should be sent to the Security email.

Ultimate, Inc. 16192 Coastal Highway Lewes, DE 19958 United States
Legal
legal@ultimate.dev
Security
security@ultimate.dev
Privacy
privacy@ultimate.dev

Annex A - Details of processing

This Annex describes the default processing for Enterprise Services. The actual processing is limited to the Services Customer purchases, enables, configures, and uses. Customer-specific terms in an Order Form may narrow or supplement this Annex.

A.1 Parties and term

Customer
The entity identified as “Customer” in the applicable Agreement or Order Form
Processor
Ultimate, Inc., providing the Services under the Attribute brand
Processor address
16192 Coastal Highway, Lewes, DE 19958, United States
Privacy contact
privacy@ultimate.dev
Security contact
security@ultimate.dev
Legal contact
legal@ultimate.dev
Applicable agreement
The Agreement or Order Form incorporating this DPA
DPA term
For the duration of the applicable Agreement and any period during which Ultimate, Inc. processes Customer Personal Data on Customer's behalf
Processing elementDescription
Subject matterProcessing Customer Personal Data to provide the Enterprise Services and Customer-requested support, security, integrations, AI features, automation, and related functions.
DurationThe term of the Agreement plus any authorized post-termination retrieval, legal-retention, incident-response, and backup-rotation periods.
FrequencyContinuous, recurring, episodic, or event-driven, depending on Customer use, integrations, uploads, workflows, Agents, and support activity.
Geographic scopeUnited States and other locations identified in the Subprocessor List or Order Form, subject to Annex D.

A.2 Nature and operations

Processing may include collection, receipt, recording, organization, structuring, storage, hosting, adaptation, extraction, parsing, validation, retrieval, consultation, display, use, classification, calculation, analysis, search, indexing, embedding, summarization, generation, prediction, synchronization, transmission, disclosure to authorized recipients, restriction, correction, export, backup, restoration, audit, return, and deletion.

A.3 Specific business purposes

Service purposeSpecific purposeTypical data
Account and Workspace administrationAuthenticate Authorized Users; administer organizations, Workspaces, roles, permissions, memberships, invitations, sessions, support, and Customer configurations.Identifiers, business contact data, account and authentication metadata, organization and role information, device and security logs.
ERP and business operationsHost and process Customer-directed catalog, customer, vendor, purchasing, inventory, warehouse, manufacturing, sales, fulfillment, accounting, pricing, workflow, approval, and audit records.Business contact, professional, commercial, transaction, product, operational, communication, and audit information.
Customer and vendor onboardingReceive applications and documents; extract, validate, structure, compare, and flag missing or inconsistent information; support Customer review and approval workflows.Business identity and contact details, tax or employer identifiers, resale certificates, licenses, trade references, commercial credit information, document images, extracted fields, and review records.
Document intelligenceProcess PDFs, images, scans, forms, certificates, invoices, contracts, correspondence, and other Customer-authorized files for OCR, extraction, classification, validation, search, and retrieval.Document contents, images, metadata, signatures where present, identifiers, communications, and derived structured data.
Integrations and APIsConnect to Customer-selected ERP, commerce, identity, communications, storage, payment, and other systems; synchronize, map, import, export, and update authorized records.Integration identifiers, credentials or tokens, mapped business records, transaction data, logs, and synchronization metadata.
AI-assisted featuresPerform Customer-requested inference, retrieval, summarization, generation, classification, recommendation, document analysis, and proposed-action support.Prompts, authorized context, Customer records, documents, embeddings, Inputs, Outputs, feedback, and model-operation metadata.
Agents and automationExecute Customer-configured tasks, workflows, proposals, approvals, and authorized tool calls within defined identity, delegation, scope, and system-of-record controls.Identity, authority, task, delegation, resource, workflow, approval, tool, integration, and resulting transaction data.
Security and reliabilityPrevent, detect, investigate, and remediate fraud, abuse, vulnerabilities, unauthorized access, outages, and data-integrity issues; maintain logs, backups, recovery, and continuity.Account, device, network, authentication, authorization, event, diagnostic, audit, and incident information.
Implementation and supportConfigure, migrate, troubleshoot, maintain, and support Customer's use of Enterprise Services at Customer's request.Relevant Customer records, configuration, support communications, diagnostic data, and limited production data needed for the task.

A.4 Categories of Data Subjects

• Customer's Authorized Users, Administrators, employees, contractors, agents, applicants, and former personnel;

• Customer's prospective and existing customers, account applicants, buyers, contacts, and end users;

• vendors, suppliers, manufacturers, carriers, service providers, trade references, and business counterparties;

• individuals identified in purchasing, inventory, warehouse, sales, accounting, support, communication, or audit records;

• visitors and users of Customer applications, storefronts, portals, or integrations where Customer routes data through Attribute;

• individuals named in documents, images, correspondence, or connected-system records; and

• other individuals whose Personal Data Customer lawfully submits or makes available through the Services.

A.5 Categories of Customer Personal Data

CategoryExamples
Identifiers and contact dataName, business name, username, email, phone, postal address, customer or vendor ID, account identifiers, signatures, and similar identifiers.
Account and organization dataWorkspace membership, role, department, team, location, subsidiary, permissions, authentication metadata, sessions, and administrator activity.
Commercial and ERP recordsCustomer, vendor, catalog, pricing, quotes, orders, purchasing, inventory, warehouse, manufacturing, fulfillment, returns, accounting, approval, and transaction records.
Business onboarding and verificationApplications, tax or employer identifiers, resale certificates, business registrations, licenses, trade references, commercial credit information, and review status.
Documents and communicationsPDFs, images, scans, forms, invoices, contracts, certificates, correspondence, notes, support communications, and document metadata.
Professional and workforce dataJob title, employer, department, responsibilities, business performance or workflow records, schedules, and employment-related information submitted by Customer.
Technical and security dataIP address, device and browser data, event logs, API calls, integration metadata, authentication and authorization events, errors, monitoring, and audit records.
AI and derived dataPrompts, authorized context, extracted fields, classifications, summaries, embeddings, recommendations, proposed actions, confidence indicators, and feedback.
Location and operational dataBusiness locations, warehouses, delivery addresses, routes, and location information submitted or generated for an enabled operational purpose.

A.6 Sensitive Data

Customer Personal Data may include Sensitive Data only when Customer lawfully submits it to an enabled feature and the Agreement permits it. Typical supported sensitive business-onboarding data may include tax or employer identifiers, government-issued business or identity documentation, account login metadata, financial or commercial credit information, and the contents of private communications. Restricted categories are governed by Section 18.

A.7 Retention and deletion

Retention is determined by Customer configuration, the Agreement, the applicable record type, Customer instructions, legal requirements, security needs, dispute preservation, and backup cycles. Customer Personal Data is returned or deleted in accordance with Section 15. Customer should configure record-specific retention appropriate to its legal and operational obligations.

Annex B - Technical and organizational measures

Attribute will maintain a risk-based security program appropriate to the Enterprise Services and Customer Personal Data. The measures below are contractual control objectives; specific implementations may vary by Service, plan, architecture, and risk, provided the overall level of protection is not materially reduced.

Control domainContractual measure
Governance and risk managementAssigned security and privacy responsibilities; documented policies and procedures; periodic risk review; asset and data classification appropriate to the Services; change control; and management oversight of material security risks.
Identity and access managementUnique user and personnel identities where practicable; role-, scope-, and boundary-based access; least privilege; multi-factor authentication for privileged administrative access; session and credential controls; access review; and prompt deprovisioning.
Authorization and tenant separationServer-side authorization at protected service boundaries; logical separation of Customer and Workspace data; default-deny behavior when required identity, authority, target, or boundary facts cannot be resolved; and independent authorization for sensitive fields, tools, integrations, and consequential Agent actions.
Encryption and key managementEncryption of Customer Personal Data in transit over public networks using current industry-standard transport protection; encryption at rest for production data stores and backups where supported by the hosting platform; controlled key access; and protected secret-management processes.
Credentials and integrationsProtection of passwords, API keys, tokens, service credentials, and integration secrets; one-way hashing where verification does not require secret recovery; encrypted storage where recovery is required; rotation and revocation processes; and narrowly scoped integration permissions.
Application securitySecure development practices; code review appropriate to risk; dependency and vulnerability management; testing before material production changes; separation of development and production; input validation; secure error handling; and remediation based on severity.
Infrastructure and network securityCloud and network controls appropriate to the architecture; environment separation; firewall or equivalent traffic controls; secure administrative access; patching; malware and abuse protections where appropriate; configuration management; and availability monitoring.
Logging, monitoring, and auditLogging of relevant authentication, authorization, administrative, integration, Agent, security, and system events; monitoring and alerting proportionate to risk; time synchronization; restricted log access; protection against ordinary alteration; and retention suitable for incident response and accountability.
Data minimization and secure processingCollection and processing limited to enabled purposes; minimization of sensitive content in logs, prompts, diagnostics, and authorization metadata; masking or redaction where appropriate; and restrictions on production-data use in non-production environments.
AI and document safeguardsAuthorized-context controls, purpose and provider checks, minimization or redaction, contractual no-training restrictions, protected document storage, bounded extraction and retrieval, separate tool authorization, and review controls for consequential actions.
Backup, resilience, and recoveryRisk-appropriate backups; access restriction and encryption for backups; redundancy and resilience measures; documented restoration or continuity procedures; periodic recovery testing; and controlled restoration of Customer Personal Data.
Incident responseDocumented incident-response process; detection, escalation, containment, investigation, evidence preservation, remediation, notification, post-incident review, and corrective action appropriate to the event.
Personnel securityConfidentiality obligations; security and privacy awareness; role-appropriate training; access based on job need; screening where lawful and appropriate; and termination or role-change procedures.
Subprocessor and vendor securityRisk-based diligence before material Subprocessor engagement; written data-protection and security obligations; transfer safeguards; breach-notification duties; ongoing review proportionate to risk; and exit or replacement planning for material providers.
Physical securityUse of cloud or colocation facilities with physical and environmental controls appropriate to the hosted systems; restricted facility access; monitoring; and media handling. Attribute personnel offices do not ordinarily host production infrastructure unless documented.
Deletion and media handlingLogical deletion from active systems in accordance with product and retention processes; backup expiration through controlled rotation; secure disposal or sanitization of media; and legal-retention isolation.
Security testing and improvementPeriodic assessment of security controls; vulnerability scanning or equivalent review; penetration testing or independent testing based on risk and maturity; remediation tracking; and updates in response to material threats or architectural changes.

B.1 Customer-specific measures

Any Customer-specific encryption, data-residency, key-management, private-networking, authentication, audit-retention, or security-control commitment must be expressly stated in an Order Form or Security Addendum. General product documentation does not create a Customer-specific contractual guarantee unless the Agreement incorporates it.

Annex C - Subprocessor framework

C.1 Current list and notices

Current Subprocessor List: Subprocessor List

Customer should maintain a monitored legal, privacy, or security contact for Subprocessor notices. The current list identifies material providers that may process Customer Personal Data for Attribute-managed Services, subject to the service and configuration notes stated there.

CategoryPurposeTypical dataRequired entry
Cloud hosting, compute, and storageApplication hosting, object storage, backups, networking, and managed infrastructure.Customer records, documents, application data, logs, backups.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List
Managed database and data servicesProduction databases, search, caching, queues, and related persistence.Structured Customer Data, metadata, indexes, backups.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List
Identity and authenticationAuthentication, single sign-on, identity verification, and session support.User identifiers, contact details, authentication metadata.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List
Security, monitoring, and diagnosticsLogging, error monitoring, abuse prevention, vulnerability or performance monitoring.Technical events, identifiers, diagnostics, limited content where necessary.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List
Communications and supportTransactional email, support ticketing, incident communications, and Customer-requested support.Business contact details, support communications, limited relevant Customer Data.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List
Document processingOCR, document conversion, extraction, classification, and validation.Uploaded documents, images, extracted text and fields, metadata.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List
AI and model inferenceLanguage-model, embedding, classification, retrieval, generation, or related inference.Prompts, authorized context, Inputs, Outputs, embeddings, limited metadata.the provider, location, and applicable transfer mechanism identified in the current Subprocessor List

C.2 Provider changes and objections

The notice, objection, resolution, and termination process in Section 12 applies. A change in a provider's corporate name, affiliate, or processing location that does not materially alter processing risk may be notified through an updated list without creating a new objection right, unless Applicable Data Protection Law requires otherwise.

C.3 Customer-directed services

Customer-selected integrations, direct AI provider accounts, bring-your-own API keys, model endpoints, OpenRouter or another Customer-controlled router, Customer cloud projects, local or private model deployments, identity providers, payment services, storage destinations, and other Customer-directed recipients must be identified separately from Attribute Subprocessors. Attribute must not list a Customer-directed recipient as if Attribute controlled the recipient’s independent processing. Conversely, an Attribute-selected router or provider may not be hidden as a Customer integration merely because the Customer chooses among models exposed through the Service.

Annex D - International transfer terms

D.1 EEA Restricted Transfers

For a Restricted Transfer of Customer Personal Data governed by the GDPR from Customer or a Customer Affiliate (the "data exporter") to Attribute or an Attribute Subprocessor not otherwise subject to an adequate transfer mechanism (the "data importer"), the Standard Contractual Clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are incorporated by reference and completed as follows:

• Module Two applies where the data exporter is a Controller and the data importer is a Processor.

• Module Three applies where the data exporter is a Processor and the data importer is a Subprocessor.

• Clause 7 (docking) applies.

• For Clause 9, Option 2 (general written authorization) applies, and the notice period is the period in Section 12.3 of this DPA.

• The optional language in Clause 11 does not apply unless the parties state otherwise in an Order Form.

• For Clause 17, Option 1 applies and the governing law is the law of the Republic of Ireland, unless the data exporter identifies another eligible EU Member State in the Order Form.

• For Clause 18, the courts of the Republic of Ireland have jurisdiction, unless the Order Form identifies the courts of another eligible EU Member State.

• Annex I.A is completed by the party and contact information in the Agreement, Order Form, and this DPA. Customer is the data exporter and Ultimate, Inc. is the data importer.

• Annex I.B is completed by Annex A. The frequency is continuous or event-driven during the Agreement term. Transfers to Subprocessors are described in Annex C and the Subprocessor List.

• Annex I.C is the supervisory authority determined under Clause 13 of the EU SCCs.

• Annex II is completed by Annex B.

• Annex III is completed by the current Subprocessor List.

If a term of this DPA conflicts with the EU SCCs, the EU SCCs control for the Restricted Transfer. The parties will not modify the EU SCCs in a way that contradicts them or reduces Data Subject protections.

D.2 United Kingdom Restricted Transfers

For a Restricted Transfer governed by UK Data Protection Laws, the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (the "UK Addendum") is incorporated by reference. Part 1 is completed as follows:

• Table 1: the parties and key contacts are identified in the Agreement, Order Form, and this DPA;

• Table 2: the selected EU SCC modules and clauses are those specified in Section D.1;

• Table 3: the Appendix Information is contained in Annexes A, B, and C and the Subprocessor List; and

• Table 4: the Importer may end the UK Addendum as permitted by Section 19 of its Mandatory Clauses when the approved Addendum changes.

The Mandatory Clauses of the UK Addendum apply as issued and revised by the Information Commissioner. If the UK Addendum is not an available or valid mechanism for a transfer, the parties will use another lawful UK transfer mechanism.

D.3 Switzerland

For a Restricted Transfer governed by Swiss data-protection law, the EU SCCs apply with adaptations necessary to recognize the Swiss Federal Data Protection and Information Commissioner as the competent authority, references to the GDPR as including applicable Swiss law, references to EU Member State law as including Swiss law where appropriate, and Data Subjects in Switzerland as protected beneficiaries. The parties will apply any additional modification required by the competent Swiss authority.

D.4 Alternative mechanisms

Where Attribute or a relevant Subprocessor is validly covered by an adequacy decision, recognized certification, data-privacy framework, binding corporate rules, or another lawful transfer mechanism, that mechanism may be used for the covered transfer. Loss, invalidation, or inapplicability of one mechanism does not terminate the Agreement if another valid mechanism can lawfully support the transfer.

D.5 Supplementary protections

Attribute will comply with the government-access, transfer-assessment, security, and transparency commitments in Section 13. The parties will reasonably cooperate to implement additional safeguards necessary to maintain a lawful Restricted Transfer, provided they do not materially alter the commercial scope without agreement.

Annex E - U.S. state privacy terms

This Annex applies where Attribute processes Customer Personal Data as a service provider, contractor, or Processor under the CCPA or another applicable U.S. state comprehensive privacy law. Terms such as business, consumer, personal information, sell, share, service provider, contractor, Controller, and Processor have the meanings given by the applicable law.

E.1 Specific business purposes

The parties agree that the limited and specified business purposes for processing are the purposes in Annex A that correspond to the Services Customer purchases and enables. Customer discloses Customer Personal Data to Attribute only for those purposes, and not for a generic or unspecified purpose.

E.2 Service-provider and contractor restrictions

Attribute certifies that it understands and will comply with the following restrictions for Customer Personal Data subject to this Annex. Attribute will not:

• sell or share Customer Personal Data;

• retain, use, or disclose Customer Personal Data for any purpose other than the limited and specified business purposes in Annex A, Customer's Documented Instructions, or another purpose expressly permitted by applicable law;

• retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer, except as expressly permitted by applicable law;

• combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from Attribute's own interaction with a consumer, except as expressly permitted by applicable law; or

• provide cross-context behavioral advertising using Customer Personal Data.

E.3 Required protection and cooperation

Attribute will:

• comply with applicable obligations imposed on service providers, contractors, and Processors and provide the same level of privacy protection required of Customer for the delegated processing;

• implement reasonable security procedures and practices appropriate to the nature of Customer Personal Data;

• assist Customer with consumer requests, breach obligations, risk assessments, automated-decision obligations, cybersecurity audits, and data-protection assessments as described in this DPA;

• ensure persons processing Customer Personal Data are subject to confidentiality obligations;

• delete or return Customer Personal Data at Customer's direction at the end of Services unless law requires retention;

• make information reasonably necessary to demonstrate compliance available to Customer and cooperate with reasonable assessments;

• notify Customer if Attribute determines it can no longer meet an applicable obligation; and

• bind each Subprocessor to written obligations that satisfy applicable service-provider, contractor, and Processor requirements.

E.4 Customer oversight and remediation rights

Customer may take reasonable and appropriate steps to help ensure Attribute uses Customer Personal Data consistently with Customer's obligations, including the assessment rights in Section 14. Upon notice of suspected unauthorized processing, Customer may require reasonable documentation and remediation. Attribute will promptly stop and remediate confirmed unauthorized use to the extent within its control.

E.5 Consumer requests

Attribute will enable Customer to comply with applicable consumer requests or will comply with a request when Customer provides the necessary verified instruction and information. If Attribute receives a request directly, Section 9.3 applies.

E.6 Deidentified data

If Attribute processes Deidentified Data subject to a U.S. state privacy law, Attribute will take reasonable measures to ensure the data cannot be associated with an individual, publicly commit to maintain and use it in deidentified form and not attempt reidentification except as permitted by law, and contractually require recipients to comply with applicable restrictions.

E.7 No limitation of state-specific duties

If an applicable state law imposes a more protective Processor-contract requirement than this Annex, that requirement is incorporated to the minimum extent necessary for compliance. The parties will reasonably cooperate to document any state-specific instruction or addendum required for Customer's processing.

ContactPrivacyTermsDPASubprocessorsSecurity

Know what matters. Shape what's next.