Data Processing Addendum

Effective Date: 5 September 2026

This Data Processing Addendum applies when Sparkify Social processes personal data on behalf of a client while providing software, AI, automation, hosting, integration, development, or technical services. It supplements applicable project agreements.

Definitions — Client is the controller or other party determining the purpose and means of processing. Sparkify Social is the processor when it processes personal data on the client’s behalf. Personal data, processing, controller, processor, and data subject have the meanings given by applicable data protection law.

Processing Instructions and Purpose — Sparkify Social will process personal data only on documented client instructions, including as necessary to provide and support the agreed services, unless applicable law requires otherwise. Processing may include collection, storage, access, transmission, analysis, integration, hosting, maintenance, and deletion as necessary for the service.

Categories of Personal Data — The categories and data subjects processed depend on the client’s use of the services and may include contact details, account information, business records, communications, technical data, or other information supplied by or collected for the client’s authorized workflow.

Confidentiality and Security Measures — Sparkify Social will require personnel authorized to process personal data to observe confidentiality and will implement reasonable technical and organizational measures appropriate to the nature of the processing and the agreed services.

Subprocessors — Sparkify Social may use subprocessors, including cloud, hosting, database, AI, analytics, communication, and development infrastructure providers, where reasonably necessary to provide the services. Sparkify Social will impose appropriate data protection obligations on relevant subprocessors.

International Data Transfers — Where personal data is transferred internationally, the parties will take steps appropriate to applicable law and the service arrangement. The client remains responsible for ensuring its instructions and use of services are lawful.

Data Subject Requests and Compliance Assistance — Taking account of the nature of the processing, Sparkify Social will reasonably assist the client with data subject requests, security obligations, impact assessments, and regulatory inquiries where such assistance is required and commercially reasonable.

Security Incidents — Sparkify Social will notify the client without undue delay after becoming aware of a confirmed security incident involving personal data processed on the client’s behalf, and will provide reasonable information available to assist the client’s response.

Data Return and Deletion — At the end of services, Sparkify Social will return or delete personal data in accordance with the applicable agreement, client instructions, and legal or operational retention requirements.

Audit Information — On reasonable written request, Sparkify Social may make available information reasonably necessary to demonstrate compliance with this addendum, subject to confidentiality, security, feasibility, and cost considerations.

Client Obligations — The client is responsible for the lawfulness of personal data and instructions, providing required notices, obtaining necessary permissions, and ensuring the configuration and use of the services are appropriate for its processing activities.

Conflict With Other Agreements and Term — This addendum applies for the duration of processing personal data on the client’s behalf. If it conflicts with a signed project agreement, the signed agreement controls to the extent of the conflict.

© 2026 Sparkify Social. All rights reserved.

© 2026 Sparkify Social. All rights reserved.