Data Processing Addendum

Data Processing Addendum for Syphe.ai

Data Processing Addendum (DPA)

Last updated: October 13, 2025

This DPA forms part of the agreement between the Customer (“Controller”) and Syphe.ai (“Processor”) for the provision of the Services.

1. Subject Matter

Syphe.ai processes Customer Personal Data solely to provide the Services described in the Agreement.

2. Roles

Customer is the Controller; Syphe.ai is the Processor.

3. Processing Instructions

Syphe.ai will process Customer Personal Data only on documented instructions from Customer, including with respect to transfers to a third country, unless required by law.

4. Confidentiality

Processor ensures that persons authorized to process the data are under confidentiality obligations.

5. Security

Processor implements appropriate technical and organizational measures (encryption, access control, logging, incident response) to ensure a level of security appropriate to risk.

6. Sub‑processing

Processor may engage subprocessors under a written agreement imposing data protection obligations. A current list is available upon request. Customer will be notified of material changes.

7. International Transfers

Transfers will rely on approved mechanisms (e.g., SCCs) as required by applicable law.

8. Data Subject Rights

Processor assists Customer by appropriate technical and organizational measures to fulfill requests to access, rectify, delete, or port data.

9. Incident Notification

Processor will notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Personal Data.

10. Return or Deletion

Upon termination, Processor will delete or return Customer Personal Data, unless retention is required by law.

11. Audits

Processor will make available information necessary to demonstrate compliance and allow for audits by Customer or an auditor mandated by Customer, subject to confidentiality.

12. Liability

Liability is governed by the Agreement. Nothing in this DPA limits either party’s liability where not permitted by law.

13. Governing Law

This DPA is governed by the law applicable to the Agreement.