Data Processing Agreement (DPA)

Pensero Inc.STE 2998 New York, NY 10016
A corporation having its principal place of business at 169 Madison Ave STE 2998 New York, NY 10016
(“Provider”)

This Data Processing Agreement (“DPA”) is entered into by and between Pensero Inc. (“Provider”) and the undersigned Customer (“Customer”). This DPA is incorporated by reference into the applicable Order Form. By executing the Order Form containing the link to this DPA, the Customer expressly agrees that this DPA forms an integral and binding part of the contractual relationship between the Parties.

1. RECITALS

WHEREAS, Provider supplies software-as-a-service (SaaS) solutions and related services (collectively, the “Services”), including the Pensero AI Software and

WHEREAS, in connection with the provision of the Services, Provider—acting solely as a Data Processor/Service Provider—may process Customer Data on behalf of the Customer; and

WHEREAS, Provider’s data processing activities are described in detail in Pensero’s Privacy Policy, which is incorporated herein by reference—and the Parties desire to set forth their respective rights and obligations concerning the processing and protection of Personal Data in compliance with applicable data protection laws;

NOW, THEREFORE, in consideration of the mutual covenants herein and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, the Parties agree as follows:

2. GENERIC PROVISIONS (APPLICABLE TO ALL JURISDICTIONS)

2.1 Definitions

For purposes of this DPA, capitalized terms not defined herein shall have the meanings assigned to them in the Service Agreement (“Main Agreement”). In this DPA, the following definitions apply:

2.2 Scope and Purpose

2.3 General Obligations and Responsibilities

2.3.1 Provider Obligations

2.3.2 Customer Obligations

The Customer is responsible for ensuring the lawfulness of its data to the Provider. The Customer shall provide clear, documented instructions regarding Processing its data and ensure that such instructions, including any referenced in the Privacy Policy, comply with applicable data protection laws. The Customer shall promptly notify Provider of any changes to these instructions.

2.4 Minimum Security Measures and Compliance

3. JURISDICTION-SPECIFIC PROVISIONS

The following provisions apply only if the Customer’s use of the Services falls within the scope of the respective regulatory frameworks.

3.1 United States Data Protection Provisions

3.1.1 Scope and Applicability

This section applies when the Processing of Personal Data involves U.S. consumers or is subject to U.S. privacy laws, such as the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), or other applicable federal or state privacy regulations.

3.1.2 Specific Requirements

3.2 United Kingdom Data Protection Provisions

3.2.1 Scope and Applicability

This section applies when the Processing of Personal Data is subject to UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and other relevant local legislation.

3.2.2 Specific Requirements

3.3 European Union (GDPR) Provisions

3.3.1 Scope and Applicability

This section applies when the Processing of Personal Data falls within the EU General Data Protection Regulation (GDPR) scope.

3.3.2 Specific Requirements

4. SUBPROCESSORS

Provider may engage Subprocessors to process Customer Data on its behalf, provided that each Subprocessor is bound by contractual obligations no less protective than those contained herein. Provider shall notify the Customer before engaging new Subprocessors.

5. LIABILITY AND INDEMNIFICATION

5.1 Limitation of Liability

Except as required by applicable law, Provider’s total aggregate liability under this DPA shall not exceed the fees paid by the Customer for the Services during the twelve (12) months immediately preceding the event giving rise to the claim.

5.2 Indemnification

Each Party shall indemnify, defend, and hold harmless the other Party from and against any claims, losses, or damages arising out of its breach of its obligations under this DPA or any violation of applicable data protection laws, subject to any mandatory provisions under law.

6. GOVERNING LAW AND DISPUTE RESOLUTION

7. MISCELLANEOUS

7.1 Entire Agreement

This DPA, together with the Main Agreement and the Order Forms executed by the Parties, constitutes the entire agreement between the Parties regarding data Processing and supersedes all prior agreements, understandings, or representations related thereto.

7.2 Amendments

No amendment to this DPA shall be effective unless it is in writing and signed by both Parties.

7.3 Severability

If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall continue in full force and effect.

7.4 Conditional Applicability

The jurisdiction-specific provisions in Sections 3.1, 3.2, and 3.3 shall apply only if the Customer’s use of the Services falls within the scope of the respective regulatory framework. Where such regulatory requirements are not applicable, the generic provisions outlined in Sections 2, 4, 5, 6, and 7 shall govern the Processing of Customer Data.

8. ACCEPTANCE

By signing the Order Forms linked to the Main Agreement that incorporates this DPA via the provided link, the Customer acknowledges that it has read, understood, and agrees to be bound by the terms of this DPA. The Customer further confirms that executing the Order Form constitutes accepting all data protection obligations. The signing of the Service Agreement and any associated Order Forms shall constitute acceptance of this DPA.