Data Processing Agreement

Last updated: 24 September 2025

This Data Processing Agreement (“DPA”) forms part of and is incorporated into any agreement, including in a form of the Terms of Service, between Spendbase, Inc. or another legal entity within the Spendbase group of companies (collectively, “Spendbase”) and the applicable customer entity (“Customer”) (each a “Party” and together the “Parties”) that governs Customer’s use of Spendbase’s services (the “Agreement”).

This DPA applies to all processing of personal data by Spendbase on behalf of Customer under the Agreement. All capitalized terms not defined in this DPA shall have the meaning given to them in the Agreement. This DPA is effective as of the effective date of the Agreement (the “Effective Date”).

By entering into the Agreement with Spendbase, the Parties are deemed to have executed this DPA, including the Standard Contractual Clauses, which form part of this DPA.

This DPA applies equally where the contracting entity is Spendbase, Inc. or another Spendbase affiliate.

WHEREAS:

(A)     In connection with the provision of Services, Processor will process certain personal data on behalf of Controller within the meaning of Article 28 GDPR;

(B)     The Parties wish to ensure that such processing of personal data is carried out in compliance with Applicable Data Protection Laws, in particular Regulation (EU) 2016/679 (the “GDPR”);

(C)     The Parties agree that Vendors shall process personal data under their own responsibility and on the basis of separate agreements (including their own data processing agreements and privacy policies). For the avoidance of doubt, this DPA does not apply to such Vendor processing activities.

(D)     The Parties therefore enter into this DPA, which sets out the rights and obligations of the Parties with respect to the processing of personal data by Processor on behalf of Controller.

NOW, THEREFORE, the Parties agree as follows:

1. Definitions

In this DPA, the following terms shall have the meaning set out below. Capitalized terms not defined herein shall have the meaning given to them under the GDPR.

Applicable Data Protection Laws” means the GDPR and any other applicable federal or state laws and regulations relating to the protection of personal data and privacy;

Controller Personal Data” means any personal data processed by Processor on behalf of Controller in connection with the Services, as further described in Annex 1 Details of Processing;

“Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Controller Personal Data;

Data Subject Request” means a request from a data subject to exercise rights under the GDPR;

Restricted Country” means a country or territory outside the European Economic Area that does not benefit from an adequacy decision by the European Commission;

Restricted Transfer” means (i) a transfer of Controller Personal Data from Controller to Processor in a Restricted Country; or (ii) an onward transfer of Controller Personal Data from Processor to a Subprocessor in a Restricted Country;

Services” means the SaaS platform and related services provided by Processor to Controller;

Subprocessor” means any legal entity appointed by Processor to process Controller Personal Data in connection with the Services;

Vendor” means a third-party provider of software-as-a-service (SaaS) products or services.

The terms “personal data”, “special categories of data”, “data subject”, “processing”, “controller”, “processor”, and “supervisory authority” shall have the meanings given in the GDPR.

2. Processing instructions and scope

2.1  This DPA governs the processing of Controller Personal Data by Processor on behalf of Controller in connection with the Services. The nature, purpose, and details of such processing are described in Annex 1 Details of Processing. Processor shall process Controller Personal Data only on instructions from Controller and shall not process Controller Personal Data for any other purpose, except where required to do so under Applicable Data Protection Laws.

2.2 By entering into this DPA, Controller instructs Processor to process Controller Personal Data solely as necessary to:

(i)     provide the Services and related technical support;

(ii)     comply with documented instructions from Controller; and

(iii)     comply with applicable laws to which Processor is subject.

2.3  Controller acknowledges that the Services enable Controller to engage Vendors of its choice. Each Vendor processes personal data independently under its own terms, privacy policies, and data processing agreements. For the avoidance of doubt, Processor does not act as processor with respect to any personal data processed by Vendors, and this DPA does not apply to such processing.

2.4 Controller shall not provide, and Processor does not request or intend to process, any special categories of data as defined under the GDPR.

2.5 Controller warrants that it has established a valid legal basis under Applicable Data Protection Laws for all processing of Controller Personal Data by Processor as contemplated by this DPA.

3. Confidentiality and security

3.1 Processor shall ensure that persons authorized to process Controller Personal Data are subject to an appropriate duty of confidentiality, whether contractual or statutory, and that such obligations remain in effect after the termination of their engagement.

3.2 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall implement and maintain appropriate technical and organizational measures to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. A description of such measures is set out in Annex 2 Technical and Organizational Measures.

3.3 Controller is responsible for:

(i)     securing its access credentials and devices used to access the Services;

(ii)     ensuring a level of security appropriate to the risk in its use of the Services; and

(iii)     determining whether the Services and the measures described in Annex 2 Technical and Organizational Measures meet Controller’s legal and regulatory requirements.

3.4 Processor has no obligation to protect Controller Personal Data that Controller elects to store or transfer outside of the Services or Subprocessors’ systems (e.g., offline or on-premise storage).

4. Subprocessors

4.1 Controller acknowledges and agrees that Processor may engage Subprocessors to process Controller Personal Data in connection with the Services. Processor may continue to use all Subprocessors engaged by it as of the Effective Date of this DPA.

4.2 The list of Subprocessors is located at spendbase.co/subprocessors and incorporated into this DPA by reference. Processor may update this list from time to time and will notify the Controller of any new Subprocessor by publishing the updated list at the Processor’s website.

4.3 Processor shall ensure that each Subprocessor is bound by a contract imposing data protection obligations no less protective than those set out in this DPA, including obligations relating to confidentiality, security, and data protection.

4.4 Processor remains fully responsible for the acts and omissions of its Subprocessors to the same extent as if the acts and omissions were its own.

4.5 Controller acknowledges and agrees that all current and future affiliates of Processor may act as Subprocessors under this DPA. Such affiliates shall be deemed authorized, and no separate approval by Controller is required. Processor shall remain fully responsible for its affiliates’ compliance with this DPA.

4.6 Not all Subprocessors process Controller Personal Data in connection with every Service. The specific Subprocessors involved depend on the features of the Services that Controller elects to use

5. Data subject rights

5.1 Taking into account the nature of the processing, Processor shall provide Controller with such reasonable assistance as is necessary to enable Controller to respond to requests from data subjects to exercise their rights under Applicable Data Protection Laws, to the extent such requests relate to Controller Personal Data and the Services.

5.2 If Processor receives a Data Subject Request directly, it shall promptly notify Controller and shall not respond to the request except on documented instructions from Controller or where required by Applicable Data Protection Laws.

5.3 Processor’s obligation to assist under this Section 5 shall apply only to the extent Controller cannot itself respond to the Data Subject Request through the functionality of the Services.

6. Data Breach notification

6.1 Processor shall notify Controller without undue delay after becoming aware of a suspected or actual Data Breach affecting Controller Personal Data.

6.2 Such notification shall, to the extent reasonably available to Processor, describe:

(i)     the nature of the Data Breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

(ii)     the expected consequences of the Data Breach; and

(iii)     the measures taken or proposed to be taken by Processor to address the Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

6.3 Controller is responsible for complying with any notification or communication obligations applicable to Controller in the event of the Data Breach.

6.4 Processor’s notification of or response to the Data Breach under this Section 6 shall not be construed as an acknowledgment by Processor of any fault or liability with respect to the incident

7. Data protection impact assessments. Audits

7.1 Taking into account the nature of the processing and the information available to Processor, Processor may provide reasonable assistance to Controller with data protection impact assessments and prior consultations with supervisory authorities, as required under Applicable Data Protection Laws.

7.2 To demonstrate compliance with this DPA, Processor shall make available to Controller documentation reasonably necessary to evidence its compliance with Article 28 GDPR, which may include third-party audit reports, certifications, or other information.

7.3 Audits shall be limited to remote reviews of documentation provided by Processor. Controller may conduct such audits no more than once every twelve (12) months, except where a supervisory authority requires otherwise.

7.4 Controller shall provide at least seventy-two (72) hours’ prior written notice before any audit. All audits shall be conducted in a manner that avoids disruption to Processor’s business operations. Controller shall bear all costs of any audit.

8. International transfers

8.1 The Parties agree that, to the extent any processing of Controller Personal Data involves a Restricted Transfer, such transfer shall be governed by the Standard Contractual Clauses for the transfer of personal data to third countries (Module Two: Controller to Processor) issued by the European Commission under Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“SCCs”).

8.2 The SCCs are incorporated by reference into and form part of this DPA as if set out in full.

8.3 The Parties have agreed on the following Annexes mapping:

(i)     Annex I (Description of Processing): completed by reference to Annex 1 Details of Processing.

(ii)     Annex II (Technical and Organisational Measures): completed by reference to Annex 2 Technical and Organizational Measures.

(iii)     Annex III (List of Subprocessors): completed by reference to the List of Subprocessors.

8.4 The SCCs shall be governed by the law of the EU Member State in which the Controller is established, and disputes shall be subject to the jurisdiction of the courts of that Member State.

8.5 Docking Clause (Clause 7 SCCs): The optional docking clause applies.

8.6 Where applicable, any transfer of Controller Personal Data from Controller in the United Kingdom to Processor in the European Economic Area is covered by adequacy regulations issued by the Relevant Body under Paragraph 5 of Schedule 21 of the UK Data Protection Act 2018 and therefore does not constitute a Restricted Transfer.

8.7 Where Spendbase engages Subprocessors located outside the EEA/UK, such transfers are protected by the SCCs (Module 3: Processor to Processor) or adequacy decisions, as applicable.

9. Return and deletion of data

9.1 Upon termination or expiry of the Services involving the processing of Controller Personal Data, Processor shall, at Controller’s choice, either

(i)     return all Controller Personal Data in a structured, commonly used and machine-readable format, or

(ii)     delete all Controller Personal Data, and shall certify such deletion upon Controller’s written request. Controller shall communicate its preference to Processor prior to termination.

9.2 Processor shall complete deletion or return within thirty (30) days of termination, unless longer retention is required by law, provided that such data is kept confidential and is processed only as necessary for compliance with such law.

10. Liability and miscellaneous

10.1 The liability of each Party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.

10.2 Except as otherwise required by the SCCs for Restricted Transfers, this DPA shall be governed by and construed in accordance with the governing law set out in the Agreement, and any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts specified in the Agreement.

10.3 In the event of any conflict between the terms of this DPA and the Agreement, this DPA shall prevail with respect to the subject matter of data protection.

10.4 If required to comply with Applicable Data Protection Laws or binding guidance from a competent supervisory authority, Processor may amend this DPA by providing written notice to Controller. The Parties shall cooperate in good faith to ensure continued compliance.

10.5 This DPA shall remain in force for as long as Processor processes Controller Personal Data on behalf of Controller under the Agreement.

10.6 Except as otherwise required by the SCCs, this DPA shall be governed by the governing law set out in the Agreement.

11. Contact information

Questions regarding this DPA may be directed to legal@test-partneway.prod.spendbase.co