# Rheaply Data Processing Addendum

**Effective Date:** November 28, 2023

This EU and UK Data Processing Addendum (“DPA”) supplements the Rheaply [Terms of Service](https://rheaply.com/terms/terms-of-service/) (the “Agreement”) and is executed by and between you (“Customer”) and Rheaply, Inc. (“Company”). By executing the DPA, Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Affiliates.

## **1. Definitions**

01. “Affiliate” means (i) an entity of which a party directly or indirectly owns fifty percent (50%) or more of the stock or other equity interest, (ii) an entity that owns at least fifty percent (50%) or more of the stock or other equity interest of a party, or (iii) an entity which is under common control with a party by having at least fifty percent (50%) or more of the stock or other equity interest of such entity and a party owned by the same person.

02. “Authorized Sub-Processor” means a third-party who has a need to know or otherwise access Customer’s Personal Data to enable Company to perform its obligations under this DPA or the Agreement.

03. “Company Account Data” means personal data that relates to Company’s relationship with Customer, including the names or contact information of individuals authorized by Customer to access Customer’s account.

04. “Company Usage Data” means Service usage data collected and processed by Company in connection with the provision of the Services.

## **2. Relationship of the Parties; Processing of Data**

1. The parties acknowledge and agree that with regard to the processing of Personal Data, Customer may act either as a controller or processor and, except as expressly set forth in this DPA or the Agreement, Company is a processor.

2. Company shall not process Personal Data for purposes other than those set forth in the Agreement and/or Exhibit A.

3. The subject matter, nature, purpose, and duration of this processing, as well as the types of Personal Data collected and categories of Data Subjects, are described in Exhibit A to this DPA.

4. Following completion of the Services, at Customer’s choice, Company shall return or delete Customer’s Personal Data, unless further storage of such Personal Data is required or authorized by applicable law.

## **3. Confidentiality**

1. Company shall ensure that any person it authorizes to process Personal Data has agreed to protect Personal Data in accordance with Company’s confidentiality obligations in the Agreement.

## **4. Authorized Sub-Processors**

1. Customer acknowledges and agrees that Company may engage its Affiliates as well as the Authorized Sub-Processors to access and process Personal Data in connection with the Services.

2. A list of Company’s current Authorized Sub-Processors is available to Customer at rheaply.com/gdpr/subprocessors.

## **5. Security of Personal Data**

1. Company shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data.

## **6. Transfers of Personal Data**

1. The parties agree that Company may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services.

## **7. Rights of Data Subjects**

1. Company shall, to the extent permitted by law, notify Customer upon receipt of a request by a Data Subject to exercise the Data Subject’s rights.

## **8. Actions and Access Requests; Audits**

1. Company shall provide reasonable cooperation and assistance where necessary for Customer to comply with its obligations under the GDPR.

## **9. Company’s Role as a Controller**

The parties acknowledge and agree that with respect to Company Account Data and Company Usage Data, Company is an independent controller, not a joint controller with Customer.

## **10. Conflict**

In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the Standard Contractual Clauses; (2) the terms of this DPA; (3) the Agreement; and (4) the Company’s privacy policy.

## **Exhibit A**

**Details of Processing**

**Nature and Purpose of Processing:** The Company will process Customer’s Personal Data as necessary to provide the Services under the Agreement.

**Duration of Processing:** Company will process Customer’s Personal Data as long as required by applicable law or regulation.

**Categories of Data Subjects:** Customer’s employees, consultants, contractors, and/or agents.

**Categories of Personal Data:** Includes name, email, job title, username, Company device identifiers (e.g. serial number), IP address for company device.

**Sensitive Data or Special Categories of Data:** Customers are prohibited from providing sensitive personal data to Company.

## **Exhibit B**

### **1. The Parties**

**Data exporter(s):**
- Name: See Order Form

**Data importer(s):**
- Name: Rheaply, Inc.  
- Address: 27 N Wacker Dr #424, Chicago IL, 60606

### **2. Description of the Transfer**
- **Data Subjects**: As described in Exhibit A of the DPA  
- **Categories of Personal Data**: As described in Exhibit A of the DPA

### **3. Competent Supervisory Authority**
- The supervisory authority shall be the supervisory authority of the Data Exporter.

## **Exhibit C**

**Description of the Technical and Organisational Security Measures implemented by the Data Importer**

|     |     |
| --- | --- |
| **Technical and Organizational Security Measure** | **Details** |
| Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | Company’s customer agreements contain strict confidentiality obligations. |
| Measures for ensuring physical security of locations at which personal data are processed | All Company processing occurs in physical data centers managed by AWS. |
| Measures for ensuring data quality | Company has a multi-tiered approach for ensuring data quality. |

## **Exhibit D**

**UK Addendum**

1. Each party agrees to be bound by the terms and conditions set out in this UK Addendum.

2. The parties do not need the consent of any third party to make changes to this UK Addendum, but any changes must be made in accordance with its terms.
