Data Processing Agreement

The data processing terms that apply when Modelware processes personal data on behalf of a customer.

Version 1.0

This Data Processing Agreement (the "DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Modelware LLC, a California limited liability company ("Modelware", "we", "us", or "our") and the customer ("Customer", "you", or "your") for the provision of the Modelware products and services (the "Service"). It applies to the extent Modelware processes Personal Data on behalf of the Customer in connection with the Service.

In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.

1Definitions

(a)"Applicable Data Protection Laws" means the data protection and privacy laws that apply to the processing of Personal Data under the Agreement, which may include the California Consumer Privacy Act as amended ("CCPA") and the EU and UK General Data Protection Regulation ("GDPR").

(b)"Personal Data" means information relating to an identified or identifiable natural person that Modelware processes on behalf of the Customer under the Agreement.

(c)"Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the Applicable Data Protection Laws.

(d)"Sub-processor" means any third party engaged by Modelware to process Personal Data on the Customer's behalf.

2Roles and Scope

For Personal Data processed under the Agreement, the Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Modelware is the Processor. With respect to the CCPA, Modelware acts as a "service provider" and will not sell or share Personal Data, will not retain, use, or disclose it except as necessary to provide the Service or as otherwise permitted by the CCPA, will not retain, use, or disclose it outside the direct business relationship between the parties, and will not combine it with personal information received from or on behalf of any third party except as the CCPA permits. Modelware certifies that it understands these restrictions and will comply with them, and will notify the Customer if it determines that it can no longer meet them, in which case the Customer may take reasonable steps to stop and remediate the unauthorized use. Modelware will process Personal Data only on the Customer's documented instructions, including as set out in the Agreement and this DPA, unless required by law.

3Details of Processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A. The processing continues for the duration of the Agreement and until deletion of Personal Data in accordance with this DPA.

4Modelware Obligations

Modelware will:

(a)process Personal Data only on the Customer's documented instructions;

(b)ensure that persons authorized to process Personal Data are bound by confidentiality obligations;

(c)implement and maintain the technical and organizational security measures described in Annex B;

(d)assist the Customer, taking into account the nature of the processing and the information available to Modelware, in responding to Data Subject requests and in meeting the Customer's obligations relating to security, breach notification, and data protection impact assessments; and

(e)promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.

To the extent legally permitted, the Customer will reimburse Modelware for reasonable costs of assistance that materially exceeds the functionality and assistance ordinarily provided as part of the Service.

5Customer Obligations

The Customer is responsible for the accuracy and legality of the Personal Data it provides and for having a lawful basis for the processing. The Customer's instructions for processing must comply with Applicable Data Protection Laws.

6Confidentiality

Modelware will treat Personal Data as confidential information of the Customer and will limit access to personnel who need it to provide the Service and who are bound by appropriate confidentiality obligations.

7Security Measures

Modelware will implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex B. Modelware may update these measures provided that the level of protection is not materially reduced.

8Sub-processors

The Customer authorizes Modelware to engage Sub-processors to process Personal Data, subject to this section. Modelware will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for its Sub-processors' performance. Modelware maintains a current list of Sub-processors, including the processing activity and location of each, in the Sub-processors list, and the Customer may subscribe to notifications of intended new Sub-processors as described there. Modelware will provide notice of any intended addition or replacement of a Sub-processor, and the Customer may object on reasonable data-protection grounds within thirty (30) days after that notice. The parties will discuss the objection in good faith and Modelware will use reasonable efforts to make available a change in the Service, or a commercially reasonable alternative, that avoids processing by the objected-to Sub-processor. If Modelware cannot do so within a reasonable period, the Customer may terminate the affected portion of the Service by written notice and Modelware will refund prepaid fees allocable to the unused remainder of the affected Service term. Pending resolution of the objection, Modelware will not engage the objected-to Sub-processor for the Customer's Personal Data, except where continuing to withhold engagement would prevent Modelware from providing the Service or from meeting a security, legal, or regulatory requirement, in which case Modelware will tell the Customer and the Customer may terminate the affected portion of the Service on the refund terms above.

9Data Subject Requests

Taking into account the nature of the processing and the information available to Modelware, Modelware will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If Modelware receives such a request directly, it will, unless legally prohibited, direct the Data Subject to the Customer.

10Personal Data Breach Notification

Modelware will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on the Customer's behalf, and will provide information reasonably available to Modelware to assist the Customer in meeting its applicable notification obligations. Information may be provided in phases as it becomes reasonably available. Modelware will take reasonable steps to contain and remediate the breach.

11International Data Transfers

Transfer mechanism. Where processing involves the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision, the Standard Contractual Clauses apply to that transfer and are incorporated into this DPA by reference, without any further action by either party. "Standard Contractual Clauses" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914, as amended or replaced.

Module and roles. Module Two (controller to processor) applies where the Customer is a Controller, and Module Three (processor to processor) applies where the Customer is itself a Processor acting on behalf of a third-party Controller. The Customer is the data exporter and Modelware is the data importer. The parties agree the following selections: the optional docking clause in Clause 7 applies; in Clause 9, Option 2 (general written authorization) applies, with the notice period stated in the Sub-processors section of this DPA; in Clause 11, the optional independent dispute resolution language does not apply; in Clause 17, the Clauses are governed by the law of Ireland; and in Clause 18(b), disputes are resolved before the courts of Ireland.

Annexes. Annex A of this DPA supplies the information required by Annex I of the Standard Contractual Clauses, describing the parties, the transfer, and the competent supervisory authority. Annex B supplies the information required by Annex II. The Sub-processors section and the list referenced there supply the information required by Annex III.

United Kingdom. For transfers subject to UK data protection law, the Standard Contractual Clauses apply as modified by the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, which is incorporated by reference. Tables 1 to 3 of the Addendum are populated by the corresponding information in this DPA and its Annexes, and in Table 4 neither party may end the Addendum as permitted by Section 19 of it.

Switzerland. For transfers subject to Swiss data protection law, the Standard Contractual Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority read as the Swiss Federal Data Protection and Information Commissioner, and the term "Member State" read so as not to prevent data subjects in Switzerland from enforcing their rights in their place of habitual residence.

Assessment and precedence. Modelware will provide information reasonably necessary for the Customer to carry out a transfer impact assessment, and will notify the Customer if it becomes subject to a legal requirement that would prevent it from meeting its obligations under the Standard Contractual Clauses. Where an alternative transfer mechanism is validly available for a transfer, the parties may rely on it instead. The Standard Contractual Clauses prevail over this DPA and the Agreement to the extent of any conflict regarding a transfer they govern.

12Return and Deletion of Data

Upon termination or expiration of the Agreement, and upon the Customer's request made within thirty (30) days, Modelware will make Personal Data available for export. Modelware will thereafter delete the Personal Data it holds, including from backups in the ordinary course of their rotation, unless retention is required by law, in which case Modelware will isolate the retained data from further processing and delete it once retention is no longer required. Modelware will confirm deletion in writing on the Customer's request.

13Audits

Modelware will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by Applicable Data Protection Laws, and subject to reasonable notice, confidentiality, and no more than once per year (unless required by a supervisory authority), Modelware will allow for and contribute to audits, which may be satisfied by providing third-party certifications or reports where available. Any further audit is conducted at the Customer's expense, on reasonable prior notice, during normal business hours, by an independent third party mutually agreed by the parties and bound by confidentiality, and in a manner that does not unreasonably disrupt Modelware's operations. If an audit reveals a material breach of this DPA by Modelware, Modelware will bear the reasonable costs of that audit.

14Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and this DPA and the Agreement are treated as a single agreement for that purpose. Where this DPA is executed before or apart from an Order, the limitations in the Terms of Service and the applicable schedule apply.

Nothing in this section limits either party's liability to a data subject under Article 82 of the GDPR, or any other liability that cannot lawfully be limited, and nothing in it affects the rights or obligations of either party under the Standard Contractual Clauses.

15Term

This DPA takes effect on the effective date of the Agreement and remains in effect until Modelware has ceased all processing of Personal Data on the Customer's behalf and deleted or returned it in accordance with this DPA.

16Governing Law

This DPA is governed by the same law and subject to the same jurisdiction as the Agreement, being the laws of the State of California and the courts located in Orange County, California, except to the extent Applicable Data Protection Laws require otherwise.

17Annexes

Annex A · Details of Processing. This Annex also supplies the information required by Annex I of the Standard Contractual Clauses.

Parties: the data exporter is the Customer identified in the Order, acting as Controller or, where applicable, as Processor on behalf of a third-party Controller. The data importer is Modelware LLC, a California limited liability company, acting as Processor, contactable at info@modelware.io. The activities relevant to the transfer are those described in this Annex.

Frequency of transfer: continuous, for the duration of the Agreement.

Subject matter: provision of the Modelware products and services.

Nature and purpose: hosting, storage, and processing of Customer Data as necessary to operate, secure, and support the Service.

Categories of Data Subjects: the Customer's authorized users and any individuals whose Personal Data is contained in Customer Data.

Types of Personal Data: account and contact details of authorized users (such as name and email) and any Personal Data the Customer chooses to include in Customer Data. The Service is not intended for special categories of Personal Data.

Duration: the term of the Agreement plus the deletion period described in this DPA.

Sub-processors: the subject matter, nature, and duration of processing by each Sub-processor are as described in the list referenced in the Sub-processors section.

Competent supervisory authority: determined in accordance with Clause 13 of the Standard Contractual Clauses, being the supervisory authority of the Member State in which the data exporter is established or, where the exporter is not established in the European Economic Area, the supervisory authority of the Member State in which the exporter's representative is established or in which the data subjects are located. For transfers subject to UK or Swiss law, the competent authority is the UK Information Commissioner or the Swiss Federal Data Protection and Information Commissioner respectively.

Annex B · Security Measures. Access controls and least-privilege access; encryption of data in transit and, where applicable, at rest; network and system protections; logging and monitoring; secure development and change-management practices; personnel confidentiality and training; and backup and recovery procedures. The hosted platform runs on cloud infrastructure operated by the Sub-processor identified in the Sub-processors list, and Modelware relies on that provider's physical and environmental security controls for the facilities in which the infrastructure is located.

18Contact

Notices, requests, and questions under this DPA, including sub-processor objections, audit requests, and data-protection enquiries, may be sent to Modelware LLC at info@modelware.io. Modelware sends notices under this DPA, including notice of a Personal Data Breach, to the contact addresses in the Order or the Customer's account, so the Customer should keep those details current.