Data Processing Agreement

The data processing terms that apply when Modelware processes personal data on behalf of a customer.

Version 1.0| Not yet in effect

This Data Processing Agreement (the "DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Modelware Solutions LLC ("Modelware", "we", "us", or "our") and the customer ("Customer", "you", or "your") for the provision of the Modelware products and services (the "Service"). It applies to the extent Modelware processes Personal Data on behalf of the Customer in connection with the Service.

In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.

1Definitions

(a)"Applicable Data Protection Laws" means the data protection and privacy laws that apply to the processing of Personal Data under the Agreement, which may include the California Consumer Privacy Act as amended ("CCPA") and the EU and UK General Data Protection Regulation ("GDPR").

(b)"Personal Data" means information relating to an identified or identifiable natural person that Modelware processes on behalf of the Customer under the Agreement.

(c)"Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the Applicable Data Protection Laws.

(d)"Sub-processor" means any third party engaged by Modelware to process Personal Data on the Customer's behalf.

2Roles and Scope

For Personal Data processed under the Agreement, the Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Modelware is the Processor. With respect to the CCPA, Modelware acts as a "service provider" and will not sell or share Personal Data, and will not retain, use, or disclose it except as necessary to provide the Service or as permitted by Applicable Data Protection Laws. Modelware will process Personal Data only on the Customer's documented instructions, including as set out in the Agreement and this DPA, unless required by law.

3Details of Processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A. The processing continues for the duration of the Agreement and until deletion of Personal Data in accordance with this DPA.

4Modelware Obligations

Modelware will:

(a)process Personal Data only on the Customer's documented instructions;

(b)ensure that persons authorized to process Personal Data are bound by confidentiality obligations;

(c)implement and maintain the technical and organizational security measures described in Annex B;

(d)assist the Customer, taking into account the nature of the processing, in responding to Data Subject requests and in meeting the Customer's obligations relating to security, breach notification, and data protection impact assessments; and

(e)promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.

5Customer Obligations

The Customer is responsible for the accuracy and legality of the Personal Data it provides and for having a lawful basis for the processing. The Customer's instructions for processing must comply with Applicable Data Protection Laws.

6Confidentiality

Modelware will treat Personal Data as confidential information of the Customer and will limit access to personnel who need it to provide the Service and who are bound by appropriate confidentiality obligations.

7Security Measures

Modelware will implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex B. Modelware may update these measures provided that the level of protection is not materially reduced.

8Sub-processors

The Customer authorizes Modelware to engage Sub-processors to process Personal Data, subject to this section. A current list of Sub-processors is set out in Annex C. Modelware will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for its Sub-processors' performance. Modelware will provide notice of any intended addition or replacement of a Sub-processor and give the Customer a reasonable opportunity to object on reasonable data-protection grounds.

9Data Subject Requests

Taking into account the nature of the processing, Modelware will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If Modelware receives such a request directly, it will, unless legally prohibited, direct the Data Subject to the Customer.

10Personal Data Breach Notification

Modelware will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting the Customer's Personal Data, and will provide information reasonably available to it to help the Customer meet its notification obligations. Modelware will take reasonable steps to contain and remediate the breach.

11International Data Transfers

Where processing involves the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the parties will rely on an appropriate transfer mechanism. The parties will complete and execute the applicable module of the Standard Contractual Clauses (for example, the controller-to-processor module) as part of the Order or a separate data transfer agreement where required, and the Standard Contractual Clauses prevail over this DPA to the extent of any conflict regarding such transfers.

12Return and Deletion of Data

Upon termination or expiration of the Agreement, and upon the Customer's request made within thirty (30) days, Modelware will make Personal Data available for export and will thereafter delete it in the ordinary course, unless retention is required by law.

13Audits

Modelware will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by Applicable Data Protection Laws, and subject to reasonable notice, confidentiality, and no more than once per year (unless required by a supervisory authority), Modelware will allow for and contribute to audits, which may be satisfied by providing third-party certifications or reports where available. Any further audit is conducted at the Customer's expense, on reasonable prior notice, during normal business hours, by an independent third party mutually agreed by the parties and bound by confidentiality, and in a manner that does not unreasonably disrupt Modelware's operations. If an audit reveals a material breach of this DPA by Modelware, Modelware will bear the reasonable costs of that audit.

14Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

15Term

This DPA takes effect on the effective date of the Agreement and remains in effect until Modelware has ceased all processing of Personal Data on the Customer's behalf and deleted or returned it in accordance with this DPA.

16Governing Law

This DPA is governed by the same law and subject to the same jurisdiction as the Agreement, being the laws of the State of California and the courts located in Orange County, California, except to the extent Applicable Data Protection Laws require otherwise.

17Annexes

Annex A · Details of Processing.

Subject matter: provision of the Modelware products and services.

Nature and purpose: hosting, storage, and processing of Customer Data as necessary to operate, secure, and support the Service.

Categories of Data Subjects: the Customer's authorized users and any individuals whose Personal Data is contained in Customer Data.

Types of Personal Data: account and contact details of authorized users (such as name and email) and any Personal Data the Customer chooses to include in Customer Data. The Service is not intended for special categories of Personal Data.

Duration: the term of the Agreement plus the deletion period described in this DPA.

Annex B · Security Measures. Access controls and least-privilege access; encryption of data in transit and, where applicable, at rest; network and system protections; logging and monitoring; secure development and change-management practices; personnel confidentiality and training; and backup and recovery procedures.

Annex C · Sub-processors. A current list of Sub-processors, including the processing activity and location of each, is maintained by Modelware and made available to the Customer on request.