Data Processing Addendum

Effective Date: June 17, 2024

This Data Processing Addendum (“DPA”) forms part of the Master Services Agreement or Terms of Service (“Principal Agreement”) between [Customer Legal Entity Name] (“Customer” or “Data Controller”) and Proceve Inc. (“Provider” or “Data Processor”), collectively referred to as the “Parties,” to reflect the parties’ agreement with regard to the Processing of Personal Data, recognizing that Proceve’s users may be located in and accessing Proceve’s services from anywhere in the world.

1. Definitions

Any capitalized terms not defined in this DPA shall have the meanings set forth in the Principal Agreement. In this DPA, the following terms shall have the meanings set out below:

“Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (EU) 2016/679 (GDPR), and other relevant laws depending on the jurisdiction.

“Personal Data” means any information relating to an identified or identifiable natural person that is processed by the Provider as a Data Processor on behalf of the Customer as a Data Controller.

2. Processing of Personal Data

2.1. Roles and Regulatory Compliance

The Customer is the Data Controller of Personal Data and the Provider is the Data Processor

2.2. Purpose and Duration

The Provider shall process Personal Data as necessary to perform the services pursuant to the Principal Agreement and as further instructed by the Customer in writing. The processing of Personal Data by the Provider is limited to the duration of the Principal Agreement.

2.3. Customer Obligations

The Customer agrees to ensure that Customer’s instructions for the processing of Personal Data shall comply with the Data Protection Laws. The Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which the Customer acquired Personal Data.

3. Rights of Data Subjects

The Provider shall, to the extent legally permitted, promptly notify the Customer if the Provider receives a request from a Data Subject to exercise the Data Subject’s right under the Data Protection Laws with respect to Personal Data.

4. Provider’s Personnel

The Provider shall ensure that its personnel engaged in the processing of Personal Data are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities, and have executed written confidentiality agreements.

5. Security

The Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate, the measures referred to in Article 32(1) of the GDPR, PIPEDA, and any applicable provincial regulations.

6. Sub-processors

6.1. Consent

The Customer consents to the Provider appointing third-party sub-processors to process Personal Data. The Provider shall notify the Customer in advance of any changes concerning the addition or replacement of such sub-processors.

6.2. Sub-processor Obligations

The Provider shall impose data protection terms on any sub-processor it appoints that require it to protect the Personal Data to the standard required by the Data Protection Laws.

7. Data Transfer

The Provider shall not transfer Personal Data outside of the respective jurisdiction unless the prior written consent of the Customer has been obtained and the following conditions are fulfilled: compliance with Data Protection Laws including mechanisms such as Standard Contractual Clauses or adequacy decisions where applicable.

8. Audit Rights

The Customer shall have the right to conduct audits to verify compliance with this DPA.

9. Termination

9.1. Deletion of Data

Upon termination of the Principal Agreement, the Provider shall, at the choice of the Customer, delete or return all Personal Data to the Customer.

9.2. Post Termination

Following expiration or termination of the Agreement, the Provider must, in accordance with the Documentation, delete all Customer Personal Data. Notwithstanding the foregoing, the Provider may retain Customer Personal Data (i) as required by Applicable Data Protection Law or (ii) in accordance with its standard backup or record retention policies, provided that, in either case, the Provider will maintain the confidentiality of, and otherwise comply with the applicable provisions of this DPA with respect to retained Customer Personal Data and not further Process it except as required by Applicable Data Protection Law.

10. Governing Law

This DPA shall be governed by the laws of Canada and the province in which the Customer is located, without regard to its conflict of laws principles.

11. Miscellaneous

11.1. Amendment

This DPA may only be amended by the written agreement of the Parties.

11.2. Severability

If any provision of this DPA is held to be invalid or unenforceable, the remainder of this DPA shall remain in full force and effect

This DPA is entered into and becomes a binding part of the Principal Agreement between the Parties on the date the Principal Agreement is signed by the Customer.