Data Processing Addendum

Data Processing Addendum, version 1.1, effective 18 September 2026. The version used with your Order Form should be cross-referenced, as an older form than the one displayed here may have been used. Older versions of this agreement are archived below.

Version 1.1, dated 18 September 2026.

This Data Processing Addendum (this "DPA") forms part of the Master Subscription Agreement (the "Agreement") between Vesara, Inc. ("Vesara") and the customer identified on the Order Form ("Customer"). It applies to the extent Vesara processes Personal Data on behalf of Customer in providing the Service. Capitalized terms not defined here have the meanings given in the Agreement.

1. Definitions

"Data Protection Laws" means all laws that apply to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other United States state privacy laws.

"Personal Data" means information within Customer Data that relates to an identified or identifiable natural person, or that is "personal information" or an equivalent term under Data Protection Laws.

"Personal Data Breach" means a Security Incident (as defined in Exhibit A to the Agreement) that involves Personal Data.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914.

"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

"Controller", "processor", "data subject", "processing", "business", "service provider", and "sell" and "share" have the meanings given in the applicable Data Protection Laws.

2. Roles and scope

2.1

Customer is the controller (or business) and Vesara is the processor (or service provider) for the Personal Data. Where Customer acts as a processor for another controller, Vesara is a subprocessor and Customer warrants that it has the authority to instruct Vesara as this DPA provides.

2.2

The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of data subjects are described in Annex 1.

3. Vesara's obligations

3.1 Instructions

Vesara processes Personal Data only on Customer's documented instructions, which consist of the Agreement, the Order Form, this DPA, and any further written instructions Customer gives that are consistent with them. Vesara will tell Customer if, in its opinion, an instruction infringes Data Protection Laws, and may then suspend the affected processing until the instruction is clarified.

3.2 Confidentiality

Vesara ensures that every person it authorizes to process Personal Data is bound by a duty of confidentiality.

3.3 Security

Vesara implements and maintains the technical and organizational measures described in Exhibit A to the Agreement, which the Parties agree are appropriate to the risk of the processing.

3.4 Subprocessors

Customer gives Vesara general authorization to engage the Subprocessors listed in Exhibit A to the Agreement. Vesara will email the Customer notice address in the Order Form at least thirty (30) days before engaging a new Subprocessor that will process Personal Data, and Customer may object on reasonable data protection grounds as Exhibit A provides. The current list and its change log are at vesara.ai/subprocessors. Vesara enters into a written agreement with each Subprocessor that imposes data protection obligations no less protective than this DPA, and Vesara remains liable for each Subprocessor's performance.

3.5 Data subject requests

Vesara will notify Customer without undue delay if it receives a request from a data subject about Personal Data and will not respond except on Customer's instruction or where law requires. Vesara will assist Customer, through appropriate technical and organizational measures and to the extent possible, in fulfilling Customer's obligations to respond to data subject requests.

3.6 Assistance

Taking into account the nature of the processing and the information available to Vesara, Vesara will assist Customer in complying with its obligations on security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities. Vesara may charge reasonable fees for assistance that goes beyond what the Agreement already requires, after telling Customer in advance.

3.7 Personal Data Breach

Vesara will notify Customer without undue delay and no later than forty-eight (48) hours after becoming aware of a suspected or confirmed Personal Data Breach, with the information described in Section A7 of Exhibit A. A preliminary notice stating what is then known is given within that period and supplemented as material facts emerge. Vesara will provide updates as they become available. Vesara's notice is not an acknowledgment of fault or liability.

3.8 Deletion and return

At the end of the Agreement, or earlier on Customer's written request, Vesara deletes or returns the Personal Data as Section 3.7 of the Agreement provides, unless applicable law requires storage. Any retained Personal Data remains subject to this DPA.

3.9 Audits

Vesara makes available to Customer the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits as Section A9 of Exhibit A provides.

3.10 Records

Vesara keeps a record of the categories of processing it carries out on Customer's behalf as Data Protection Laws require.

4. Customer's obligations

4.1

Customer is responsible for the lawfulness of the Personal Data it makes available to Vesara, including any legal basis, notice, or consent required under Data Protection Laws, and for the accuracy of its instructions.

4.2

Customer will not make available to Vesara any Personal Data that Customer has excluded from scope under the Agreement, and will use the exclusion controls in Exhibit A to keep out data classes it does not want processed.

5. International transfers

5.1 Transfers from the EEA

To the extent Vesara processes Personal Data that is subject to the GDPR in a country that the European Commission has not found to provide adequate protection, the Parties enter into the SCCs, which are incorporated into this DPA by reference, with these selections:

  • Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor.
  • Clause 7 (docking clause) is included.
  • In Clause 9, Option 2 (general written authorization) applies with a thirty (30) day notice period.
  • The optional language in Clause 11 is not included.
  • In Clause 13, the competent supervisory authority is the authority identified in Annex 1.
  • In Clause 17, Option 1 applies and the governing law is the law of Ireland.
  • In Clause 18, the courts of Ireland have jurisdiction.
  • Annex I of the SCCs is completed with the information in Annex 1 of this DPA.
  • Annex II of the SCCs is completed by Exhibit A to the Agreement.
  • Annex III of the SCCs is completed by the Subprocessor list in Exhibit A to the Agreement.

5.2 Transfers from the United Kingdom

For Personal Data subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, with Table 1 completed with the information in Annex 1, Tables 2 and 3 completed by reference to Section 5.1 and Exhibit A, and Table 4 providing that either Party may end the UK Addendum as its Section 19 sets out.

5.3 Transfers from Switzerland

For Personal Data subject to Swiss law, the SCCs apply with the following changes: references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and the term "member state" is read to allow data subjects in Switzerland to enforce their rights in Switzerland.

5.4 Precedence and alternatives

If the SCCs conflict with this DPA, the SCCs prevail. If a transfer mechanism in this Section 5 is invalidated or replaced, the Parties will cooperate in good faith to put in place a lawful alternative, and Vesara may rely on any other valid transfer mechanism under Data Protection Laws.

6. California and other United States state laws

6.1

To the extent the CCPA or a similar United States state law applies, Vesara acts as a service provider or processor. Vesara will not (a) sell or share Personal Data, (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between the Parties, or (c) combine Personal Data with personal information it receives from another source, except as those laws permit.

6.2

Vesara certifies that it understands and will comply with the restrictions in Section 6.1. Vesara will notify Customer if it determines that it can no longer meet its obligations under those laws, and Customer may then take reasonable steps to stop and remediate unauthorized use of Personal Data.

7. Liability and general

7.1

Each Party's liability under this DPA is subject to the limitations and exclusions in Section 11 of the Agreement, except to the extent Data Protection Laws or the SCCs do not permit that limitation.

7.2

This DPA is governed by the governing law of the Agreement, except where the SCCs provide otherwise. If this DPA conflicts with the Agreement on the processing of Personal Data, this DPA prevails.

7.3

This DPA takes effect on the Effective Date of the Agreement and continues for as long as Vesara processes Personal Data on Customer's behalf.

Annex 1: Description of the processing

This Annex completes Annex I of the Standard Contractual Clauses and Table 1 of the UK Addendum.

Data exporterCustomer, as identified on the Order Form, acting as controller (or as processor on behalf of its own controllers). Contact: the Customer notice address on the Order Form.
Data importerVesara, Inc., 548 Market Street, #90878, San Francisco, CA 94104, United States, acting as processor. Contact: andrew.boos@vesara.ai.
Subject matterReading Customer's business records in the Connected Systems to identify open obligations, unbilled or recoverable amounts, and related items, and generating the Output.
DurationThe term of the Agreement and the applicable Order Form, plus the deletion period in Section 3.6 of the Agreement.
Nature and purposeCollection through read-only connections to the Connected Systems named in the Order Form or through documents Customer uploads; indexing; analysis using deterministic extraction and, for scanned documents and contract text, the language model operated by the Subprocessor listed in Exhibit A; review by Vesara personnel; storage for the term; and deletion. The purpose is to provide the Service to Customer. No model is trained on Personal Data unless the Order Form grants the design partner training right in Section 3.6 of the Agreement, and any such training is supervised or anonymized as that Section requires.
Categories of data subjectsCustomer's employees, contractors, and officers. Employees and representatives of Customer's customers, vendors, partners, and other counterparties. Other individuals named in Customer's business records.
Categories of Personal DataNames, business contact details, job titles, and employer. Content and metadata of business communications (email, chat, meeting transcripts, and calendar entries) within the scope Customer selects. Contract, invoice, payment, and commercial terms, and ledger and bank statement lines, that identify individuals. Customer may exclude any category through the scope controls in Exhibit A.
Sensitive dataThe Service is not intended to process special categories of data. Customer will use the exclusion controls to keep out data sources that are likely to contain them. Where such data appears incidentally in business records, Vesara processes it only as part of the Output and applies the measures in Exhibit A.
Frequency of transferContinuous through the Connected Systems for their term, and on each upload of documents by Customer.
RetentionFor the term of the Order Form, then deletion within thirty (30) days (ninety (90) days from backups).
SubprocessorsAs listed in Exhibit A to the Agreement.
Competent supervisory authorityThe supervisory authority of the EU member state in which the data exporter is established, or, where the data exporter is not established in the EU, the authority of the member state in which its representative is established or in which the data subjects are located. For the UK, the Information Commissioner.

Annex 2: Technical and organizational measures

This Annex completes Annex II of the Standard Contractual Clauses by reference to Exhibit A to the Agreement. The table maps each measure to the section of Exhibit A that describes it.

MeasureExhibit A section
Encryption of Personal Data in transit and at restA3.1
Logical segregation of each customer's dataA1.3
Read-only, least-privilege access to Connected Systems, revocable by CustomerA2
Exclusion controls applied before indexingA2.3, A11
Confidentiality, training, and background screening of personnelA4.1
Single sign-on and multi-factor authentication for Customer users, with per-workspace authorizationA4.3
Multi-factor authentication, hardware security keys for Findings review, quarterly access reviews, and prompt removal of access for Vesara personnelA4.2
Secure development, vulnerability management, and annual penetration testingA5
Logging and monitoring of access to Personal DataA5.4
Backups, restoration testing, and recovery objectivesA6
Security Incident detection and notification within forty-eight (48) hoursA7
Subprocessor contracts prohibiting training on Customer Data and limiting retentionA3.2, A8
Retention limited to the term and deletion within thirty (30) daysA3.4
Independent assurance, questionnaires, and audit rightsA9

Signature page to the Data Processing Addendum, including Annexes 1 and 2

The Parties have signed this DPA, including the Standard Contractual Clauses incorporated in Section 5, as of the Effective Date of the Agreement.

Vesara, Inc. (data importer and processor)

Vesara, Inc. (data importer and processor)

By
 
Name
Andrew Boos
Title
Chief Executive Officer
Email
andrew.boos@vesara.ai
Date
 

Customer (data exporter and controller)

Customer (data exporter and controller)

By
 
Name
 
Title
 
Email
 
Date
 

Data Processing Addendum, version 1.1, effective 18 September 2026. Older versions