**AIPartner.cloud**

*Cloud Partner Concierge Service*

**Data Processing Addendum (“DPA”)**

[*AIPartner.io*](http://AIPartner.io) *, a company established in Estonia (“**Company**”) – August 12th, 2026*

This Data Processing Addendum (“DPA”) applies where Company and the entity identified in the applicable Contract (“**Client**”) have entered into a written or electronic services Contract referencing this DPA, pursuant to which Company has agreed to process Personal Data on behalf of Client, or independently as a controller, in connection with Company's cloud resell and partnership services (the “**Contract**”). This DPA is incorporated into and made subject to the Contract. Any capitalized terms not defined in this DPA have the meaning set forth in the Contract.

**PART I — DEFINITIONS**

**•  1\. “Applicable Privacy Laws”** means, as applicable, any and all applicable domestic and foreign laws, rules, directives, and regulations, on any local, provincial, state or deferral or national level, pertaining to data privacy, data security, and/or the protection of personal data, including the Privacy and Electronic Communications Directive 2002/58/EC (and respective local implementing laws) concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), including any amendments or replacements to them, the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. ("CCPA"), Canada Personal Information Protection and Electronic Documents Act 2000 ("PIPEDA") the United Kingdom’s Data Protection Act 2018 (“UK-GDPR”), and the Israeli Protection of Privacy Law, 1981 and the regulations promulgated thereunder ("PPL"). 

**•  2\. “Authorized Personnel”** means an individual (including an employee, temporary worker, Contract or agency worker) authorized to process Personal Data under the authority of Company.

**• 3.“Data Privacy Framework”** refers to the approved body of rules certifying and safeguarding transfers of Personal Data between the EU Countries, the UK, Switzerland and the USA, where applicable.

**•  4\. “Instructions”** means Client's written instructions directing Company to process Personal Data as provided under the Contract, this DPA, through Client's use of the features and functionality of the Services, or as otherwise mutually agreed in writing by authorized signatories of both parties.

**•  5\. “Personal Data”** shall have the meaning given to Personal Data under the Contract or, if not defined there, means any information relating to an identified or identifiable natural person that Company processes on Client's behalf. This definition is primarily taking into account the definition under Section 4.1 of the GDPR. 

**•  6\. “Personal Data Breach”** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Company's possession or under its control (including when transmitted or stored by Company).

**•  7\. “Services”** means the cloud resell, partnerships, consulting services and related Services described in the Contract.

**•  8\. “Standard Contractual Clauses”** or “**SCCs**” or “**Clauses**” shall mean, as relevant, the “Standard Contractual Clauses” under, and as defined by, Regulation EU) 2016/679 of the European Parliament and of the Council has adopted on June 4, 2021, by the European Commission Decision (EU) 2021/914 (“SCCs”), attached hereto as Exhibit A, as an integral part of this DPA; any standard contractual clauses under the UK GDPR; and any future applicable statutory instruments amending or repealing the above mentioned statutory clauses.

**•  9\. “Sub-processor”** means any person or entity, including Company's affiliates, appointed by or on behalf of Company in connection with the processing of Personal Data under the Contract.

**• 10\. “Third Country”** means countries that, where so regulated by Applicable Privacy Laws, have not received an adequacy decision from an applicable authority (including the European Commission or the UK Information Commissioner's Office) relating to data transfers.

In this DPA, the following terms (and any substantially similar terms defined under Applicable Privacy Laws) have the meanings, and are otherwise interpreted in accordance with, Applicable Privacy Law: Data Controller, Data Processor, Data Subject, Sale, Service Provider, Share, Supervisory Authority, process(ing), and transfer.

**PART II — COMPANY AS A DATA CONTROLLER**

**Role of the parties.** For the purposes of the GDPR and substantially similar Applicable Privacy Laws, Company is an independent Controller with respect to its processing of the business contact and account information of Client's administrators and authorized users (“**Account Data**”), as further described in Exhibit A. Company processes Account Data for the purpose of its business operations incident to providing the Services, including account and contract management, billing, technical support, securing its systems, and combating fraud, as further set out in the Contract.

**Standard Contractual Clauses.** To the extent Company transfers Account Data to a Sub-processor located in a Third Country, Company will ensure the transfer is made subject to the Standard Contractual Clauses (or, where the recipient is self-certified under the EU-U.S. Data Privacy Framework, in reliance on that framework) or another valid transfer mechanism recognized under Applicable Privacy Laws. The information required for the purposes of the SCCs, where applicable, is provided in Exhibit C.

**PART III — COMPANY AS A DATA PROCESSOR (OR SUB-PROCESSOR)**

***1\. Processing of Data***

**\-**  The parties acknowledge and agree that, with respect to the processing of Personal Data under this Part III, Company is a Data Processor and Client is a Data Controller, except where Client is itself a Data Processor, in which case Company is a Sub-processor of Client.

**\-**  This Part III applies where and solely to the extent that Company processes Personal Data on behalf of Client for the purpose of providing the Services pursuant to the Contract. Company will process such data solely for the “ Purpose” further defined in Exhibit A. The subject matter, nature, purpose, and duration of processing, and the types of Personal Data and categories of data subjects, are described in Exhibit A.

**\-**  Company will process Personal Data only as set out in the Contract, in accordance with Exhibit A, and in accordance with the Instructions. Company will promptly notify Client if, in Company's opinion, an Instruction infringes Applicable Privacy Laws. Except as expressly permitted by Client or Applicable Privacy Laws, Company will not (i) sell or share Personal Data collected pursuant to this DPA, nor (ii) retain, use, or disclose such Personal Data for any purpose other than the Purpose, or outside the direct business relationship with Client. Company certifies that it understands the foregoing restrictions and will comply with them.

Company “processes” (as this term is defined by GDPR and/or by any applicable law or regulation) personal data that is made available by the Client in connection with the Contract (whether directly by the Client or indirectly by a third party retained by and operating for the benefit of the Client);

Notwithstanding anything to the contrary in the DPA and Applicable Privacy Laws, Client acknowledges that Company shall have the right to collect, use and disclose: (A) data collected in the context of providing the Services, for the purpose of the operation, support or use of its services for its legitimate business purposes, such as account and contract management (including for billing, audit and recordkeeping purposes), technical support, troubleshooting, security, protecting against fraudulent or illegal activity, billing, and for the purpose of establishment/exercise and defense of legal claims; and (B) aggregated and/or anonymized information.

**\-**  Client will, in its use of the Services, at all times process Personal Data, and provide Instructions, in compliance with Applicable Privacy Laws. Client represents and warrants that it has obtained, or will obtain, all necessary consents and has a valid legal basis for the processing of Personal Data under this DPA and, if Client is itself a Data Processor, that its instructions and appointment of Company as a Sub-processor have been authorized by the relevant Data Controller.

**\-**  Following completion of the Services, Company will return or delete Personal Data as set out in the Contract, or provide Client the ability to delete it directly through the Services, except (a) where deletion is not permitted by applicable law or the order of a governmental or regulatory body; (b) where Company retains such data for internal record-keeping and compliance with legal obligations; or (c) where Company's back-up systems store such data, in which case it will remain protected under this DPA.

***2\. Authorized Personnel***

**\-**  Company will ensure that all Authorized Personnel are made aware of the confidential nature of Personal Data and have executed confidentiality Contracts, or are otherwise subject to binding duties of confidentiality, that prohibit them from processing Personal Data except in accordance with the Instructions and their obligations under the Contract.

**\-**  Company will take commercially reasonable steps to ensure Authorized Personnel receive data protection training appropriate to the nature of their processing and the requirements of Applicable Privacy Laws.

***3\. Company Sub-processors***

**\-**  Client provides Company with general written authorization to engage Sub-processors to process (including transfer) Personal Data in connection with the Services.

**\-**  A list of Company's current Sub-processors is available at [https://aipartner.cloud/sub-processors](https://aipartner.cloud/sub-processors). These Sub-processors are deemed authorized by Client. At least ten (10) days before enabling a new Sub-processor to process Personal Data, Company will add it to the Sub-processor List and notify Client. 

**Authorization for Subprocessors.** Client provides a general authorization to Company to appoint (and permit each Sub-Processor appointed in accordance with this Clause to appoint) Processors and/or Sub Processors in accordance with this Clause. 

Company may continue to use those Processors and/or Sub Processors already engaged by Company as at the date of this Agreement, subject to Company, in each case as soon as practicable, meeting the obligations set out in this Clause. 

Company can at any time and without justification appoint a new Processor and/or Sub-Processor provided that Client is given ten (10) days prior notice and the Client does not legitimately object to such changes within that timeframe. Legitimate objections must contain reasonable and documented grounds relating to a Processor and/or Sub-Processor's non-compliance with Data Protection Law. If, in Company’s reasonable opinion, such objections are legitimate, Company shall either refrain from using such Processor and/or Sub-Processor in the context of the processing of personal data or shall notify Client of its intention to continue to use the Processor and/or Sub-Processor. Where Company notifies Client of its intention to continue to use the Processor and/or Sub-Processor in these circumstances, Client may, by providing written notice to Company, terminate the Agreement immediately.

With respect to each Processor and/or sub-processor, Company shall ensure that the arrangement between Company and the Processor and/or Sub Processor is governed by a written contract including terms which offer at least the same level of protection as those set out in this DPA and meet the requirements of Data Protection Law; 

Company will be responsible for any acts, errors or omissions by its Sub-Processors, which may cause Company to breach any of its obligations under this DPA.

Company will only disclose personal data to Sub-Processors for the specific purposes of carrying out the Services on Company's behalf. Company does not sell or disclose personal data to third parties for commercial purposes, except as required under applicable laws.

***4\. Security of Personal Data***

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, Company will maintain appropriate technical and organizational measures designed to (i) ensure a level of security appropriate to the risk presented by the processing, and (ii) protect Personal Data from unauthorized access, destruction, use, modification, or disclosure. These measures include, at a minimum, those set out in Exhibit B.

***5\. Transfers of Personal Data***

**\-**  Client acknowledges that Company and its Sub-processors may process Personal Data in the European Economic Area, the United Kingdom, and in any other location where Company or a Sub-processor maintains data processing operations, as set out in the Sub-processor List. Company will at all times provide an adequate level of protection for personal data, in accordance with Applicable Privacy Laws.

**\-**  Where personal data is transferred from the EEA, the UK, or Switzerland to a Third Country, the transfer is subject to the Standard Contractual Clauses, Module Two (“Controller to Processor”) or Module Three (“Processor to Processor”), as applicable. The information required for the purposes of the SCCs is provided in Exhibit C.

**\-**  Alternatively, and where available and applicable under Applicable Privacy Laws, the parties may rely on any other data transfer mechanism or certification approved under Applicable Privacy Laws, including, the EU-U.S. Data Privacy Framework and the adequacy decisions as specified at: [https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions\_en](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en) 

**\-**  To the extent additional or substitute safeguards are required to transfer Personal Data to a Third Country, the parties will implement them as soon as practicable.

***6\. Cooperation; Audit and Records Requests***

**\-**  Company will, to the extent permitted by law, promptly notify Client following receipt and verification of a request from a data subject to exercise their rights, or will advise the data subject to submit the request to Client directly. Client will be responsible for responding to the request.

**\-**  At Client's request, and taking into account the nature of the processing, Company will apply appropriate technical and organizational measures to help Client comply with its obligation to respond to such requests, provided Client is unable to do so without Company's assistance. Client will be responsible for any costs arising from that assistance.

**\-**  If Company receives a subpoena, court order, or other legal demand seeking disclosure of Personal Data, Company will, where legally permitted, promptly notify Client, and will only comply where legally required to do so, providing reasonable cooperation to Client at Client's expense if Client wishes to challenge the disclosure.

**\-**  Company will provide Client with reasonable cooperation and assistance to comply with its obligations under Applicable Privacy Laws, including obligations to conduct a data protection impact assessment or consult with a Supervisory Authority.

**\-**  Upon Client's request, no more than once per calendar year, Company will make available for review copies of certifications or reports demonstrating its compliance with Applicable Privacy Laws. Solely where such materials are insufficient and required by Applicable Privacy Laws, Company will make available additional information and allow for audits, including inspections, of the data processing facilities within its control, conducted by Client or an auditor mandated by Client, subject to at least sixty (60) days' prior written notice, confidentiality obligations, and Company's reasonable pre-approval of scope. Any information disclosed will be deemed Company's confidential information.

***7\. Personal Data Breach***

**\-**  After becoming aware of a Personal Data Breach, Company will, without undue delay, inform Client and take such steps as it reasonably deems necessary to remediate the breach, to the extent remediation is within its control.

**\-**  Taking into account the nature of the processing and the information reasonably available to it, Company will (a) provide Client with reasonable cooperation and assistance necessary for Client to comply with its notification obligations under Applicable Privacy Laws, and (b) provide information in Company's reasonable control concerning the nature of the Personal Data Breach, the categories and approximate number of data subjects and records concerned, and the likely consequences of the breach.

**\-**  The obligations in this Section 7 do not apply where a Personal Data Breach results from the acts or omissions of Client. Company's cooperation or reporting under this Section will not be construed as an acknowledgment of fault or liability.

**PART IV — MISCELLANEOUS**

**Notices.** All notices to Client under this DPA will be sent by email to Client's designated administrator and, where provided, its legal and privacy notices contact. Client may update these contacts by emailing [legal@aipartner.cloud.io](mailto:legal@aipartner.io) 

**Liability.** The liability of Company and its employees, directors, officers, affiliates, successors, and assigns arising out of or related to this DPA, whether in contract, tort, or another theory of liability, is subject to the limitation and exclusion of liability provisions of the Contract, and any reference in those provisions to Company's liability means the aggregate liability of Company under the Contract and this DPA together.

**Precedence.** This DPA is without prejudice to the rights and obligations of the parties under the Contract, which remains in full force and effect. In the event of a conflict between this DPA and the Contract, this DPA prevails. 

**Governing Law.** Unless otherwise required under this DPA or Applicable Privacy Law, the dispute resolution provisions of the Contract (including governing law and venue) apply to this DPA.

The following Exhibits form part of the Standard Contractual Clauses and must be completed and approved by the parties.

**EXHIBIT A**

1. **List of Parties**

**DATA EXPORTER (Controller)**

| Name: | Client’s corporate name |
| :---- | :---- |
| Address: | Registered address |
| Activities relevant to the data transferred under these Clauses: | Data exporter is a Client of data importer and provides certain personal data to data importer in order to allow data importer to provider services |
| DPO (if applicable): |  |
|  |  |

By entering into the Contract and DPA, Data Exporter is deemed to have approved and accepted this DPA and the  Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Contract.

| Signature date | Click-through terms acceptance date |
| :---- | :---- |

**DATA IMPORTER (Processor)**

| Name: | Company’s corporate name |
| :---- | :---- |
| Address: | Registered address |
| Contact person’s name, position and contact details: |  legal@aipartner.cloud.io |
| Activities relevant to the data transferred under these Clauses: | Data importer provides services, consulting and support related to Cloud services, and imports certain Personal Data in order to provide said services |
| DPO (if applicable): | legal@aipartner.cloud |

By entering into the Contract and DPA, Data Exporter is deemed to have approved and accepted this DPA and the  Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Contract.

| Signature date: | Click-through terms acceptance date |
| :---- | :---- |

2. **Description of Transfer**

Categories of data subjects whose personal data is transferred  
Client's personnel, contractors using the Services and, where applicable, Client's channel partner representatives.

Categories of personal data transferred  
Credentials of Client’s personnel required to sign in to Client's AIPartner account, including names, email addresses, and telephone numbers, IP addresses, billing details, access data (e.g., usernames, hashed passwords, single sign-on identifiers, API keys, multi-factor authentication data); technical and usage data (e.g., device and browser identifiers, cookies, log-in timestamps, usage and diagnostic logs); billing and financial data (e.g., VAT/tax identification numbers and invoice history, in addition to billing details already listed); and the content of support tickets, emails, or chat correspondence with Company's support team.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures  
None

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).  
Upon onboarding of Client's personnel, contractors. 

Nature of the processing  
Storing and accessing credentials in order to allow access to the Company's services (the “Purpose”)

Purpose(s) of the data transfer and further processing  
In order to allow Client to access the Company's services.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period  
Each of Client's personnel, or contractors has access to the system, as determined by Client at its sole discretion, all processing will cease upon termination of the underlying Contract or when no longer necessary for the purpose outlined herein.

3. **Competent Supervisory Authority**

The competent supervisory authority regarding this transfer, in accordance with Clause 13, is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), consistent with the election in Exhibit C, Section 5\.

**EXHIBIT B**

**Technical and Organizational Security Measures (“TOMs”)**

Company employs the following technical and organizational measures designed to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing and the risks to the rights and freedoms of natural persons. Company may update or modify these measures from time to time, provided such updates do not result in a degradation of the overall security of the Services.

**•  Pseudonymization and encryption:** Records and files containing personal data are encrypted at rest and, by default, in transit over public networks.

**•  Confidentiality, integrity, availability, and resilience of processing systems:** Policies and processes are in place to control Personal Data access, disclosure, modification, and retention. Personal data is stored in a high-availability setup and backed up on a regular basis.

**•  Restoring availability and access in a timely manner:** Business continuity and data recovery policies are in place with defined recovery time and recovery point objectives, tested at least annually.

**•  User identification and authorization:** Company follows industry-standard practices for identifying and authenticating users who access or attempt to access systems containing Personal Data.

**•  Protection of data during transmission:** Personal data in transit over public networks is encrypted in accordance with industry-standard practices.

**•  Protection of data during storage:** Personal Data at rest is encrypted in accordance with Company's system management standards.

**•  Physical security:** Access to facilities where systems processing personal data are located is limited to identified, authorized individuals, with emergency and contingency plans in place.

**•  Event logging:** Audit trails are maintained and retained in accordance with Company's retention policies and Applicable Privacy Laws.

**•  System configuration:** Configuration is managed through infrastructure as code; changes require review and approval by an authorized representative.

**•  Data minimization:** The Services require only the minimal Personal Data necessary to operate, as outlined in Exhibit A. Processing of additional personal data requires a separate written Contract between the parties.

**•  Data quality:** Input validation and database structures help ensure data quality.

**•  Limited data retention:** Data and back-up retention policies are reviewed at least annually to ensure compliance with Applicable Privacy Laws and minimization of retained data.

**•  Accountability:** Company has defined roles and responsibilities designed to ensure the confidentiality, integrity, and availability of personal data, reviewed annually. Company employs least-privilege and role-based access controls.

**•  Data portability and erasure:** Processes are in place to remove personal data contained within the Services upon termination of the Contract.

**•  Transfers to Sub-processors:** Company maintains a vendor management process to review Sub-processor compliance on an ongoing basis. Data processing Contracts and/or contractual clauses are in place to allow for data transfers as required by Applicable Privacy Laws.

**EXHIBIT C**

**Standard Contractual Clauses**

The parties agree that Personal Data transferred between the parties to a Third Country is subject to the Standard Contractual Clauses, to the extent applicable and as further set out in this DPA. To the extent a transfer of personal data is subject to Article 3(2) of the GDPR by virtue of Company's establishment in Estonia, this Exhibit C does not apply to that transfer.

***1\. Clarification of Definitions and Terms***

**\-**  The terms “data controller” or “controller”, “data exporter”, “data importer”, “data processor”, and “personal data” have the meaning given under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, or other Applicable Privacy Law, as applicable.

**\-**  For transfers of personal data to a Third Country originating from outside the EU, references to the GDPR are replaced by the applicable Data Protection Law, and references to the “EU”, “Union”, or “Member State” are replaced with the applicable originating region.

**\-**  Clause 1(a) of the Standard Contractual Clauses (definition of data importer): the “data importer” means the Sub-processor or other recipient of the transfer.

**\-**  Clause 1(a) of the Standard Contractual Clauses (definition of data exporter): the “data exporter” means Company or Client, as applicable to the transfer in question.

**\-**  With respect to objections to Sub-processors under Clause 9, the process set out in Part III, Section 3 of this DPA applies.

***2\. Applicable Modules***

With respect to the processing of applicable personal data:

**\-**  Where Client is a Data Exporter and Controller, and Company is a Data Importer and Controller — Module One applies.

**\-**  Where Client is a Data Exporter and Controller, and Company is a Data Importer and Processor — Module Two applies.

**\-**  Where Client is a Data Exporter and Processor, and Company is a Data Importer and Sub-processor — Module Three applies.

**\-**  References to Module Four do not apply and are not treated as part of this DPA.

***3\. Amendments or Updates***

To the extent additional appropriate safeguards are required to export data to a Third Country, or the Standard Contractual Clauses are substituted, replaced, or not recognized under Applicable Privacy Laws, the parties will promptly implement the same, or agree on another acceptable transfer method and amend this Exhibit C accordingly.

***4\. Conflicts***

If the terms of the Contract or this DPA conflict with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

***5\. Standard Contractual Clauses Elections***

The Standard Contractual Clauses are deemed incorporated into this DPA and apply as completed below:

**\-**  In Clause 7, the optional “Docking Clause” is deemed incorporated.

**\-**  In Clause 9, Option 2 is selected; the time period for prior notice of a new or replacement Sub-processor is as set out in Part III, Section 3 of this DPA.

**\-**  In Clause 11, the optional independent dispute-resolution language does not apply.

**\-**  In Clause 13, the competent supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) where the EU SCCs apply, the UK Information Commissioner's Office where the UK Addendum applies, and the Swiss Federal Data Protection and Information Commissioner (FDPIC) where a transfer is exclusively subject to the Swiss Federal Act on Data Protection.

**\-**  In Clause 17, Option 2 is selected; the Standard Contractual Clauses are governed by the laws of Estonia, save that transfers exclusively subject to the Swiss Federal Act on Data Protection are governed by the laws of Switzerland.

**\-**  In Clause 18(b), disputes are resolved before the courts of Estonia, save that disputes concerning transfers exclusively subject to the Swiss Federal Act on Data Protection are resolved before the courts of Switzerland.

**\-**  Annexes I and II to the Clauses are as set out in Exhibit A and Exhibit B of this DPA; Annex III is as set out in the Sub-processor List referenced in Part III, Section 3\.

**\-**  For the purposes of the UK Addendum, the Standard Contractual Clauses are interpreted in accordance with Part 2 of the UK Addendum; Sections 9 to 11 of the UK Addendum override Clause 5 of the EU SCCs, and both the importer and exporter may end the UK Addendum as set out in Section 19 of the UK Addendum.

*By entering into this DPA, the parties are deemed to be signing the applicable Standard Contractual Clauses.*

