Data Processing Addendum (DPA)

Effective: August 23, 2026, Last updated: September 9, 2026

This Data Processing Addendum ("DPA") is incorporated into and forms part of the

PipelinePulse Terms of Service (the "Agreement") between PipelinePulse, Inc.,

a North Carolina S-corporation ("Provider" or "PipelinePulse"), and the customer

entity that accepts the Agreement ("Customer"). It governs Provider's processing

of personal data on Customer's behalf in connection with Customer's use of the

PipelinePulse service (the "Service").

Effective date and acceptance. This DPA is effective as of the date Customer

first accepts the Agreement — by creating an account or otherwise using the

Service — and remains in effect for as long as Provider processes Customer

Personal Data. Customer's use of the Service constitutes acceptance of this DPA;

no signature is required. Where Customer requires a countersigned copy for its

records, Provider will make one available on request. Capitalized terms not

defined here have the meanings given in the Agreement.

Updates. Provider may update this DPA from time to time; material changes will

be notified as provided in the Agreement, and continued use of the Service after

an update's effective date constitutes acceptance of the updated DPA.

Provider's data-export and business-continuity commitments (wind-down, data-out)

are addressed in the Agreement and in Annex 4; this DPA addresses the processing

of personal data.

1. Definitions

- "Customer Data" — the data Customer and its authorized users submit to, or

  generate through, the Service, including proposal content and documents,

  recipient and stakeholder information, document-engagement telemetry, and

  e-signature records.

- "Customer Personal Data" — personal data contained in Customer Data that

  Provider processes on Customer's behalf: information about Customer's personnel

  and about the recipients and reviewers of Customer's proposals. Annex 1

  describes the processing.

- "Controller" and "Processor" — as commonly defined in Data

  Protection Laws (including, when applicable, Regulation (EU) 2016/679, the

  "GDPR"): the Controller determines the purposes and means of processing;

  the Processor processes on the Controller's documented instructions.

- "Data Protection Laws" — all data protection and privacy laws applicable

  to the processing of Customer Personal Data under this DPA, including U.S.

  federal and state laws (e.g., the CCPA where applicable) and, from the point

  it applies to the parties' processing, the GDPR and UK GDPR.

- "Personal Data Breach" — a breach of security leading to accidental or

  unlawful destruction, loss, alteration, unauthorized disclosure of, or

  access to Customer Personal Data.

- "Subprocessor" — a third party engaged by Provider to process Customer

  Personal Data in support of the Service (Annex 3).

2. Roles of the parties

Customer is the Controller of Customer Personal Data; Provider is the

Processor, acting only on Customer's documented instructions. The parties

agree the Agreement, this DPA, and Customer's configuration and use of the

Service are Customer's complete documented instructions. Customer's own systems

remain Customer's system of record.

3. Customer responsibilities

Customer is responsible for: (a) the accuracy and lawful collection of

Customer Personal Data submitted to the Service, including any notice or

lawful basis required to share proposal-recipient information with Provider;

(b) its configuration choices in the Service (e.g., viewer-consent posture,

gate fields, link expiry); and (c) ensuring its instructions comply with Data

Protection Laws.

4. Provider obligations as Processor

Provider will:

1. Process only on instructions (§2), and not sell Customer Personal Data

   or use it for advertising, profiling beyond the Service's engagement

   analytics, or any purpose other than providing and supporting the Service.

2. Confidentiality — ensure persons authorized to process Customer

   Personal Data are bound by confidentiality obligations.

3. Security — maintain the technical and organizational measures described

   in Annex 2, and not materially reduce the overall protection of Customer

   Personal Data during the term.

4. Breach notification — notify Customer **without undue delay, and no

   later than seventy-two (72) hours** after becoming aware of a Personal Data

   Breach. The notice will describe the nature of the breach, the categories

   of data affected, measures taken or planned, and a contact point, and

   Provider will provide timely updates as the investigation proceeds. The

   same commitment applies to breaches reported to Provider by a Subprocessor.

5. Assistance — provide reasonable assistance with data subject requests

   (access, correction, deletion), data protection impact assessments, and

   regulator consultations, taking into account the nature of the processing.

6. Deletion and return — on termination of the Service or on Customer's

   request, delete or return Customer Personal Data per the retention schedule

   in Annex 4: complete export available per the Agreement;

   deletion within thirty (30) days of termination or request; backup

   copies age out fully within a further seven (7) days under Provider's

   rolling backup retention; written confirmation of deletion on request.

   Deletion is performed with verified operator tooling, not best-effort.

5. Subprocessors

Customer authorizes the Subprocessors listed in Annex 3. Provider will give

thirty (30) days' advance written notice before adding or replacing a

Subprocessor; Customer may object on reasonable data-protection grounds, and

if the parties cannot resolve the objection Customer may terminate the

affected Service. Provider remains responsible for its Subprocessors'

performance to the standard of this DPA.

6. Data subject requests

If Provider receives a request directly from a data subject relating to

Customer Personal Data (e.g., a proposal recipient requesting deletion),

Provider will forward it to Customer without undue delay and will not respond

substantively except to direct the person to Customer, unless legally

required. Provider will act on Customer's resulting instructions within

thirty (30) days.

7. Retention

Provider retains Customer Personal Data per the schedule in Annex 4.

Retention limits for ephemeral data are enforced automatically in the

platform (scheduled purge jobs), not merely documented. A legal hold or

active dispute suspends deletion until resolved, after which the schedule

resumes.

8. California (CCPA)

To the extent the CCPA applies, Provider acts as Customer's "Service

Provider": Provider will not sell or share Customer Personal Data, will not

retain, use, or disclose it outside the direct business relationship or for

any purpose other than the business purposes in this DPA, and certifies it

understands these restrictions.

9. Processing location & international transfers; GDPR roadmap

9.1 Customer Personal Data is processed and stored in the United States

(Annex 3). Provider will not transfer Customer Personal Data outside the

United States without ensuring a lawful transfer mechanism under applicable

Data Protection Laws.

9.2 GDPR roadmap. Provider is pursuing full GDPR alignment of the Service

on an ongoing basis. If and when Customer Personal Data includes data subjects

in the EU/EEA or UK, the parties will promptly execute the applicable Standard

Contractual Clauses (and UK Addendum, as applicable), which will be

incorporated into this DPA by amendment to Annex 1. The definitions and

obligations of this DPA are drafted to be compatible with GDPR Article 28 so

that such an amendment does not require renegotiating the body of this DPA.

10. Demonstration of compliance

On Customer's reasonable written request (no more than annually, unless

following a Personal Data Breach), Provider will make available the current

Security & Data Protection Overview and respond in writing to reasonable

security questionnaires. Provider does not currently hold SOC 2 or ISO 27001

certification and does not represent otherwise.

11. General

This DPA is subject to the limitations of liability in the Agreement. If this

DPA conflicts with the Agreement, this DPA controls as to the processing of

Customer Personal Data. Obligations survive termination until all Customer

Personal Data is deleted or returned.

---

Annex 1 — Details of processing

- Data subjects: Customer's personnel (sales reps, administrators);

  recipients and reviewers of Customer's proposals (prospects, their

  colleagues to whom a proposal is forwarded).

- Categories of personal data: name, business email address, phone

  number, job title, company; document engagement telemetry (view sessions,

  time-on-page, forwards); e-signature records (typed or drawn signature

  image, signer name/title, email-verification status, timestamps, document

  hash). No IP addresses are stored for document-viewing or engagement

  telemetry (coarse country-level geolocation only), and no device

  fingerprinting is used. One disclosed exception: at signature execution,

  the signing audit record captures the signer's IP address as electronic-

  signature evidence, governed by Customer's own "Audit Trail Rigor"

  configuration: region-aware (the default — masked/truncated for

  EU/EEA/UK signers and when the country is unknown, full otherwise),

  always-masked, or always-full. This value is used solely for the

  executed contract's legal defensibility, never for analytics.

  No special categories of data are intended to be processed.

- Nature and purpose: hosting and delivering proposal documents;

  tracking engagement and notifying Customer; capturing and sealing

  e-signatures; providing the API and webhooks Customer configures.

- Duration: for the term of Customer's use of the Service, then per

  Annex 4.

Annex 2 — Security measures

As described in the PipelinePulse Security & Data Protection Overview

(current version available on request), including: PostgreSQL Row-Level

Security as the tenant-isolation enforcement boundary; private storage

buckets with per-organization UUID prefixes and server-brokered short-lived

signed URLs; TLS in transit and encryption at rest; hashed API keys;

encrypted webhook secrets with HMAC-signed deliveries; email-verified

e-signature finalization with SHA-256 document hashing; daily backups with a

7-day rolling window.

Annex 3 — Subprocessors

| Subprocessor | Purpose | Location |

|---|---|---|

| Vercel, Inc. | Application hosting | United States |

| Supabase, Inc. (on AWS) | Database, authentication, file storage, realtime | United States (US-East) |

| Stripe, Inc. | Payment processing and subscription billing | United States |

| Postmark (ActiveCampaign, LLC) | Transactional email delivery | United States |

| PostHog, Inc. | Product analytics | European Union (Germany) — PostHog EU Cloud |

| Zoho (Zoho Corporation ) | Marketing and CRM| United States |

Annex 4 — Retention schedule

| Data | Retention | Enforcement |

|---|---|---|

| Customer content (proposals, revisions, executed contracts, signature records) | Life of the account | Deleted within 30 days of termination/request |

| Account & engagement data (profiles, stakeholders, sessions, notifications, ledger) | Life of the account | Deleted within 30 days of termination/request |

| Backups | 7-day rolling window | Deleted data ages out fully within 7 days of primary deletion |

| Operational logs (hosting platforms) | ≤ 30 days | Platform-managed |

| Sandbox captured email | 30 days | Automatic scheduled purge |

| Webhook test echoes | 7 days | Automatic scheduled purge |

| Email verification codes (join flow) | ~15 minutes | TTL, single-use |

| Legal hold / active dispute | Deletion suspended until resolved | Manual |