CUSTOMER DATA PROCESSING AGREEMENT – EFFECTIVE JULY 1, 2026

(Include GDPR / UK GDPR / Swiss FADP / U.S. State Privacy Law Addendum)

This Customer Data Processing Agreement, including its exhibits and appendices (the "Addendum"), is entered into between Dan Lok Education, Inc., operating as Certainty Engine, with a registered address at 170 – 422 Richards Street, Vancouver, BC V6B 2Z4, Canada ("Certainty Engine," "we," "us," or "Processor"), and the counterparty accepting this Addendum by subscribing to the Certainty Engine platform (the "Customer," "you," or "Controller") (each a "Party" and together the "Parties").

This Addendum is incorporated by reference into, and forms part of, the Certainty Engine Terms of Service (the "Agreement") that governs Customer's subscription to and use of the Certainty Engine platform, including any white-labeled instance of it (the "Services"). This Addendum takes effect automatically upon Customer's acceptance of the Agreement, without any further action required by either Party, and applies for as long as Certainty Engine Processes Customer Personal Data on Customer's behalf.

In the event of any conflict between this Addendum and the Agreement, this Addendum shall prevail with respect to the subject matter herein. In the event of any conflict between this Addendum and the Standard Contractual Clauses ("SCCs") incorporated in Exhibit B, the SCCs shall prevail.

1. DEFINITIONS

For the purposes of interpreting this Addendum, the following terms (and their cognates) have the meanings set out below:

  • "Account" means any account or instance created by, or on behalf of, the Customer or its Affiliates within the Services.

  • "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.

  • "Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Customer Personal Data under this Addendum, including but not limited to those identified in Exhibit B.

  • "Certainty Engine Sub-Processor" means any third party (including the Platform Provider defined below) appointed by or on behalf of Certainty Engine to Process Customer Personal Data in connection with the Services.

  • "Customer Personal Data" means Personal Data contained within Customer Data that Certainty Engine Processes on behalf of Customer to provide the Services under the Agreement. Customer Personal Data does not include Customer's own Account registration and billing information, which Certainty Engine Processes as an independent Controller under the Certainty Engine Privacy Policy.

  • "Data Exporter" and "Data Importer" have the meanings assigned in Part A of Exhibit A.

  • "GDPR" means the EU GDPR and the UK GDPR, as defined in Exhibit B, as applicable.

  • "Jurisdiction Specific Terms" means the terms applicable to Processing of Personal Data originating from, or protected by, the Applicable Data Protection Laws of a jurisdiction identified in Exhibit B.

  • "Platform Provider" means GoHighLevel, Inc. and its affiliate LeadConnector LLC, the underlying software-as-a-service infrastructure provider on which the Certainty Engine platform is built and white-labeled, and which Processes Customer Personal Data as a Sub-Processor of Certainty Engine pursuant to GoHighLevel's own Customer Data Processing Addendum.

  • "Restricted Transfer" means a transfer of Customer Personal Data protected by Applicable Data Protection Laws to a Third Country or an international organization in a Third Country (including storage on servers located abroad).

  • "SCCs" / "Standard Contractual Clauses" means the model clauses for Restricted Transfers adopted from time to time by the relevant authorities identified in Exhibit B, to the extent approved as an appropriate safeguard for Restricted Transfers.

  • "Services" means the Certainty Engine software platform and related AI-enabled marketing, CRM, voice-AI, and automation services made available to Customer under the Agreement, whether via a direct subscription or a white-labeled reseller arrangement.

  • "Sub-Processor" means a direct Processor of a Processor. Certainty Engine Sub-Processors are Sub-Processors for purposes of this Addendum.

The terms "Controller," "Data Protection Assessment," "Data Subject," "Member State," "Personal Data," "Personal Data Breach," "Processing," "Processor," "Rights of the Data Subject," "Supervisory Authority," and "Third Country" have the meanings given under the Applicable Data Protection Laws, and cognate terms shall be construed accordingly. Capitalized terms not defined herein have the meaning given in the Agreement.

2. SCOPE AND APPLICABILITY

  • Duration. This Addendum takes effect on the date Customer accepts the Agreement and continues for as long as Certainty Engine Processes Customer Personal Data under the Agreement.

  • Scope. This Addendum applies to all Processing of Customer Personal Data, regardless of country of origin, place of Processing, or location of the Data Subjects. Processing of data that does not constitute Customer Personal Data (e.g., Certainty Engine's own website analytics or Customer's own Account/billing data) is outside the scope of this Addendum and is instead governed by the Certainty Engine Privacy Policy.

  • Exhibits. This Addendum includes: Exhibit A (Details of Processing); Appendix I to Exhibit A (Technical and Organizational Security Measures); Exhibit B (Jurisdiction Specific Terms); and Appendix I to Exhibit B (Supplemental Clauses to the SCCs).

3. PROCESSING OF CUSTOMER PERSONAL DATA

Certainty Engine will act as a Processor of Customer Personal Data. Customer will act as the Controller of Customer Personal Data. To the extent Customer itself acts as a Processor on behalf of its own end clients or contacts (for example, where Customer is an agency reselling the Services under its own brand to its own clients), Certainty Engine will act as Sub-Processor to Customer.

Certainty Engine shall:

  • Comply with all Applicable Data Protection Laws in its Processing of Customer Personal Data;

  • Not Process Customer Personal Data other than on Customer's documented instructions — including to provide, secure, and improve the Services (which instructions include authorization to anonymize, de-identify, or aggregate Customer Personal Data, and to use Certainty Engine's AI-enabled features solely to provide the specific Services Customer has subscribed to) — unless required to do otherwise by Applicable Data Protection Laws; and

  • Promptly inform Customer if, in Certainty Engine's reasonable opinion, an instruction from Customer infringes Applicable Data Protection Laws.

Full details of the Processing are set out in Exhibit A. Customer instructs Certainty Engine (and authorizes Certainty Engine to instruct each Certainty Engine Sub-Processor) to Process, and where necessary transfer, Customer Personal Data only as reasonably necessary to provide the Services and consistent with the Agreement and this Addendum.

4. PERSONNEL

Certainty Engine shall take reasonable steps to ensure:

  • the reliability of any employee, contractor, or agent who may access Customer Personal Data;

  • that access to Customer Personal Data is limited to individuals who need such access to perform Customer's documented instructions or to comply with Applicable Data Protection Laws; and

  • that all such individuals are bound by written confidentiality obligations.

5. SECURITY OF PROCESSING

Certainty Engine shall implement and maintain the administrative, technical, and organizational security measures identified in Appendix I to Exhibit A, appropriate to the risk of the Processing, taking into account the state of the art, the costs of implementation, the nature and purposes of the Processing, and the risks to the rights and freedoms of natural persons — in particular the risk of a Personal Data Breach. Because the Services are built on the Platform Provider's infrastructure, these measures include, and are supplemented by, the technical and organizational measures maintained by the Platform Provider as further described in Appendix I to Exhibit A.

6. SUB-PROCESSORS

  • Authorization for Existing Sub-Processors. Customer authorizes Certainty Engine's continued use of the Certainty Engine Sub-Processors engaged as of the Effective Date, including, without limitation, the Platform Provider (GoHighLevel, Inc. and LeadConnector LLC) as the underlying infrastructure and communications provider for the Services, and other Sub-Processors listed at www.certaintyengine.io/sub-processors (the "Sub-Processor List"). Customer further authorizes Certainty Engine and its Sub-Processors to appoint additional Sub-Processors, provided the obligations of this Section 6 are met.

  • Notice of New Sub-Processors. Certainty Engine will provide Customer with prior written notice (which may take the form of an update to the Sub-Processor List, together with an email or in-app notice) before appointing an additional Sub-Processor, describing the Processing to be undertaken.

  • Objection. Customer will be deemed to have consented to a new Sub-Processor if no objection is received within thirty (30) days of notice. Customer may object in writing, stating the name of the Sub-Processor and a reasonable basis for objection. If the Parties cannot reach a mutually agreeable resolution, Customer may terminate the Agreement upon written notice, with no further fees due other than those already accrued, and Certainty Engine shall cease Processing Customer Personal Data.

  • Flow-Down Obligations. With respect to each Sub-Processor, Certainty Engine shall (i) restrict the Sub-Processor's access to Customer Personal Data to what is necessary to provide the relevant part of the Services, and (ii) impose data protection terms on the Sub-Processor that offer materially the same level of protection as this Addendum, to the extent applicable to the services provided by that Sub-Processor.

  • Liability for Sub-Processors. Where a Sub-Processor fails to fulfil its data protection obligations, Certainty Engine remains fully liable to Customer for the performance of that Sub-Processor's obligations, subject to the limitations of liability in the Agreement.

7. RIGHTS OF THE DATA SUBJECTS

Taking into account the nature of the Processing, Certainty Engine shall assist Customer, through appropriate technical and organizational measures insofar as reasonably possible (including features made available within the Services to export, correct, or delete Customer Personal Data), to respond to valid requests to exercise the Rights of the Data Subjects under Applicable Data Protection Laws.

With respect to such requests, Certainty Engine shall:

  • promptly notify Customer if it, or any of its Sub-Processors, receives a request directly from a Data Subject relating to Customer Personal Data;

  • not respond to that request itself, except on Customer's documented instructions or as required by Applicable Data Protection Laws (in which case Certainty Engine will inform Customer of that legal requirement before responding, to the extent legally permitted); and

  • promptly comply with Customer's documented instructions regarding a response to such a request.

8. PERSONAL DATA BREACHES

  • Breach Response. If Certainty Engine discovers, is notified of, or has reason to suspect a Personal Data Breach affecting Customer Personal Data under its or a Sub-Processor's control, Certainty Engine will (i) take prompt measures to contain and stop the unauthorized access, (ii) secure the Customer Personal Data, and (iii) notify Customer without undue delay and, in any event, within 72 hours of becoming aware of the suspected Personal Data Breach.

  • Breach Obligations. Certainty Engine's notification shall, to the extent reasonably available, describe: (i) the nature of the Personal Data Breach; (ii) the categories and approximate number of affected Data Subjects and Personal Data records; (iii) the likely consequences of the Personal Data Breach; and (iv) the measures taken or proposed to address it. Certainty Engine will supplement the notification as further information becomes available and will reasonably assist Customer in meeting its own notification obligations to Supervisory Authorities or Data Subjects.

  • No Admission. A notification or response under this Section is not an acknowledgment of fault or liability by Certainty Engine.

9. DATA PROTECTION IMPACT ASSESSMENTS

The Platform is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from individuals under the age of 16. If we learn that we have inadvertently collected such information, we will take steps to delete it.

10. DELETION OR RETURN OF PERSONAL DATA

  • Certainty Engine shall provide Customer with technical means, consistent with how the Services are provided, to delete Customer Personal Data, subject to any retention required by applicable law.

  • Upon Customer's request following termination of the Services, Certainty Engine shall promptly delete or return all Customer Personal Data (including copies), subject to legally required retention.

  • Certainty Engine shall cause its Sub-Processors that received Customer Personal Data to likewise delete or return it, subject to legally required retention.

  • This Section does not apply to Customer Personal Data archived on back-up systems, which will be securely isolated and protected from further Processing except as required by law, consistent with Certainty Engine's standard back-up retention cycle described in Appendix I to Exhibit A.

11. AUDIT RIGHTS

Certainty Engine shall make available to Customer information reasonably necessary to demonstrate compliance with this Addendum (including relevant portions of the Platform Provider's own compliance documentation, such as SOC 2 reports, where available under confidentiality restrictions) and shall allow for and contribute to audits, including remote inspections, conducted by Customer or an auditor mandated by Customer, of Certainty Engine's Processing of Customer Personal Data. Certainty Engine may require reasonable advance notice, may limit the frequency of on-site audits to once per twelve-month period (absent a Personal Data Breach or regulatory requirement), and may charge Customer for time expended on any audit at Certainty Engine's then-current professional services rates.

12. JURISDICTION SPECIFIC TERMS

To the extent Certainty Engine Processes Customer Personal Data originating from or protected by the Applicable Data Protection Laws of a jurisdiction listed in Exhibit B, the corresponding Jurisdiction Specific Terms apply in addition to this Addendum.

13. RESTRICTED TRANSFERS

  • Restricted Transfers within the scope of this Addendum shall be conducted in accordance with Exhibit B and Applicable Data Protection Laws.

  • If a relevant authority adopts a new version of the SCCs, the Parties are deemed to have agreed to execute that new version, and Certainty Engine may update Exhibit A and Exhibit B accordingly.

  • If Certainty Engine or the Platform Provider adopts an alternative lawful transfer mechanism (such as Binding Corporate Rules or a valid adequacy decision) during the term of the Agreement, the Parties will rely on that mechanism instead, to the extent it applies.

  • Certainty Engine relies in part on its Platform Provider's certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework as an additional safeguard for transfers of Customer Personal Data processed through the underlying platform infrastructure, without prejudice to the SCCs incorporated in Exhibit B.

14. NO SELLING OF CUSTOMER PERSONAL DATA

Certainty Engine confirms that it does not receive Customer Personal Data as consideration for any Services it provides to Customer. As between Customer and Certainty Engine, Customer retains all rights and interests in Customer Personal Data. Certainty Engine shall not "sell" or "share" Customer Personal Data as those terms are defined under Applicable Data Protection Laws.

15. AMENDMENT AND ONLINE HOSTING

Certainty Engine may host the Sub-Processor List and the content of the exhibits and appendices to this Addendum online and may update them from time to time, provided that prior notice is given to Customer. If no objection is received within fourteen (14) days of such notice, Customer is deemed to have consented. If Customer objects and the Parties cannot reach a mutually agreeable resolution, Customer may terminate the Agreement upon written notice, with no further fees due other than those already accrued. Where hosted online, the latest published version of an exhibit or appendix takes precedence over the version reproduced in this Addendum.

16. LIABILITY

Subject to Applicable Data Protection Laws, each Party's liability under this Addendum is subject to the exclusions and limitations of liability set out in the Agreement.

17. GENERAL TERMS

  • Notice. The Parties shall use the Data Protection Contact set out in Part A of Exhibit A for all notices under this Addendum, including notice of a Personal Data Breach and Data Subject rights inquiries.

  • Entire Agreement on Subject Matter. This Addendum supersedes any prior data processing terms between the Parties relating to the subject matter herein. All other provisions of the Agreement not amended by this Addendum remain in full force.

  • Annual Review. Each Party shall review this Addendum (including Exhibit A) at reasonable intervals, and whenever there is a material change to the Personal Data, purposes of Processing, or risk profile of the Processing.

  • Conflicts. In the event of a conflict between the Agreement and this Addendum, this Addendum prevails. In the event of a conflict between the Jurisdiction Specific Terms and any other terms of this Addendum, the Jurisdiction Specific Terms prevail.

  • Severability. If any provision is held invalid or unenforceable, it will be replaced with a valid, enforceable provision that most closely reflects the Parties' original intent, and the remainder of the Addendum continues in effect.

  • Non-Compliance. If Certainty Engine determines it can no longer meet its obligations under this Addendum, Applicable Data Protection Laws, or the SCCs, it shall (i) promptly notify Customer and (ii) cease the relevant Processing if requested by Customer, or take other reasonable steps to remediate the non-compliance.

  • Disclosure to Supervisory Authorities. Either Party may disclose this Addendum and relevant privacy provisions of the Agreement to a Supervisory Authority or other competent regulator upon request.

  • Authority to Sign. A person accepting this Addendum on behalf of a Party represents that they have authority to bind that Party and its Affiliates.

EXHIBIT A — DETAILS OF PROCESSING

A. List of Parties

Details

Certainty Engine (Data Importer / Processor)

Dan Lok Education, Inc., 170 – 422 Richards Street, Vancouver, BC V6B 2Z4, Canada

Data Protection Contact — Certainty Engine

Privacy Officer at [email protected]

Customer (Data Exporter / Controller)

Customer's legal entity name as provided on the Certainty Engine Platform Account

Data Protection Contact — Customer

The contact details provided by Customer in its Platform Account

B. Details of Processing

Details

Subject Matter

Provision of the Certainty Engine Services under the Agreement.

Nature and Purpose

Processing of Customer Personal Data as necessary to provide, secure, support, and improve the Services, including CRM, marketing automation, communications (SMS/RCS/email/voice), AI-enabled voice and chat features, and related functionality, in accordance with Customer's instructions.

Duration

For as long as Customer maintains an active Platform Account and uses the Services, plus any post-termination retention period described in Section 10 and the Certainty Engine Privacy Policy.

Categories of Data Subjects

Customer's own personnel and authorized users; and individuals with whom Customer communicates through the Services, including Customer's leads, prospects, clients, subscribers, and end customers.

Categories of Personal Data

Identifiers such as name, email address, phone number, mailing address; communications content and metadata (SMS, voice call recordings/transcripts, email, chat); CRM and pipeline data; appointment and calendar data; payment-related identifiers processed via integrated payment providers; device/IP and usage data; and any other Personal Data Customer elects to input into the Services.

Special Categories of Personal Data

The Parties do not anticipate the Processing of special category data. Customer shall not submit special category data (e.g., health, biometric, genetic data, data revealing racial/ethnic origin, religious belief, sexual orientation, or trade union membership) into the Services unless it has first notified Certainty Engine in writing and the Parties have agreed on appropriate additional safeguards.

Frequency of Transfer

Continuous, for as long as Customer uses the Services.

Sub-Processors

As set out in Section 6 and the Sub-Processor List, including the Platform Provider (GoHighLevel, Inc. / LeadConnector LLC).

APPENDIX I TO EXHIBIT A — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

Throughout the term of the Agreement, Certainty Engine shall implement and maintain at least the following (or superior) technical and organizational measures ("TOMs") to safeguard Customer Personal Data. Because the Services run on the Platform Provider's infrastructure, several of these measures are inherited from, and contractually flowed down by, the Platform Provider.

Category

Details

Encryption

Personal Data at rest is encrypted (AES-256); Personal Data in transit is encrypted using TLS 1.2 or higher.

Access Control

Role-based access control (RBAC), sub-account-level authentication, and least-privilege access restricted to personnel who need access to perform their job function.

Confidentiality & Integrity

Endpoint protection on user devices; managed cloud infrastructure (Google Cloud Platform / AWS, via the Platform Provider) with vendor-managed patching and hardening; uptime monitoring and alerting.

Availability & Resilience

Automated backups with frequent (e.g., five-minute) granularity via the Platform Provider's infrastructure, enabling timely restoration in the event of a physical or technical incident.

Testing & Assessment

Reliance on the Platform Provider's third-party vulnerability scanning and annual penetration testing of systems that store and process Personal Data; Certainty Engine maintains its own account-level access reviews.

Authentication

Encrypted, signed session tokens; role-based authorization; support for password protection and multi-factor authentication on Customer Accounts.

Transmission Security

HTTPS/TLS 1.2+ for all data transmission; SSL certificates on all customer-facing endpoints.

Storage Security

AES-256 encryption at rest for all stored Personal Data.

Physical Security

Personal Data is stored on infrastructure operated by AWS and Google Cloud Platform via the Platform Provider; physical security is governed by those providers' SOC-audited data center controls.

Logging & Monitoring

Logging of user actions and administrative activity; application and infrastructure monitoring via cloud-native tooling (e.g., Cloud Monitoring / CloudWatch).

Configuration Management

Infrastructure-as-code and version-controlled configurations; standardized, regularly patched machine images; automated update management by the underlying cloud provider.

Governance

Internal IT/security governance function; use of a managed security service provider for monitoring; mandatory confidentiality obligations and security awareness training for personnel with data access.

Certifications

Reliance on the Platform Provider's SOC 2 Type II attestation and HIPAA-readiness certification for the underlying infrastructure, where applicable to Customer's use case.

Data Minimization

Collection limited to fields necessary for the Services; optional fields are not mandatory for Customers or their contacts.

Data Quality

Customers/authorized users can update Personal Data directly within the Services; two-factor authentication supported for Account access.

Retention Controls

Customer-configurable data retention settings at the Account/sub-account level, subject to the defaults described in the Certainty Engine Privacy Policy.

Portability & Erasure

Customers can export their Personal Data from within the Services and may request deletion via support channels, consistent with Section 10 of this Addendum.

Sub-Processor TOMs

The Platform Provider's technical and organizational measures, as set out in its own Customer Data Processing Addendum, are incorporated by reference and apply to all Customer Personal Data processed via the underlying platform.

EXHIBIT B — JURISDICTION SPECIFIC TERMS

1. European Economic Area

  • "EEA" means the European Economic Area, consisting of the EU Member States, Iceland, Liechtenstein, and Norway.

  • "EEA Data Protection Laws" means the EU GDPR and all applicable EU/EEA laws and regulations governing the Processing of Customer Personal Data.

  • "EU GDPR" means Regulation (EU) 2016/679, as amended from time to time.

Restricted Transfers

With regard to any Restricted Transfer subject to EEA Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision under Article 45 GDPR; (ii) the appropriate Standard Contractual Clauses adopted by the European Commission from time to time; or (iii) any other lawful transfer mechanism recognized under EEA Data Protection Laws.

Standard Contractual Clauses

This Addendum incorporates by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("EU 2021 SCCs"). The Parties are deemed to have executed the EU 2021 SCCs in their entirety, including the annexures, with the following selections:

  • Module: Module Two (Controller-to-Processor) applies where Customer is the Controller; Module Three (Processor-to-Sub-Processor) applies where Customer is itself a Processor.

  • Clause 7 (Docking Clause): Included.

  • Clause 9 (Sub-Processors): Option 2, General Written Authorization, with the 30-day objection period set out in Section 6 of this Addendum.

  • Clause 11: The optional independent dispute resolution body language is not included.

  • Clause 13 / Annex I.C: The competent Supervisory Authority is determined in accordance with GDPR Article 51 based on Customer's establishment or main place of business in the EEA.

  • Clause 17: Governed by the laws of Ireland.

  • Clause 18: Disputes resolved by the courts of Ireland.

  • Annex I(A) and (B): As set out in Exhibit A.

  • Annex II: As set out in Appendix I to Exhibit A.

The terms in Appendix I to Exhibit B supplement the SCCs. Where the SCCs conflict with this Addendum, the SCCs prevail as to the Restricted Transfer in question.

2. United Kingdom

"UK Data Protection Laws" means the UK Data Protection Act 2018 and the UK GDPR. With regard to any Restricted Transfer subject to UK Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision under Article 45 of the UK GDPR; (ii) the UK International Data Transfer Addendum to the EU 2021 SCCs, as issued under Section 119A of the Data Protection Act 2018; or (iii) any other lawful transfer mechanism under UK Data Protection Laws.

This Addendum incorporates by reference the EU 2021 SCCs together with the UK Transfer Addendum, populated using Exhibit A and Appendix I to Exhibit A, with the UK Information Commissioner's Office as the competent authority, and governed by the laws of England and Wales.

3. Switzerland

"Swiss Data Protection Laws" means the Federal Act on Data Protection (FADP) and its implementing ordinance. With regard to any Restricted Transfer subject to Swiss Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision of the Swiss Federal Data Protection and Information Commissioner ("FDPIC"); (ii) the EU 2021 SCCs as adapted for Switzerland by the FDPIC; or (iii) any other lawful transfer mechanism. Where the EU 2021 SCCs apply, the FDPIC is the competent authority, and the SCCs are governed by the laws of Switzerland, subject to the FDPIC's required modifications.

4. Canada

Where applicable, the Processing of Customer Personal Data of Canadian residents shall comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation (including Quebec's Law 25), in addition to the general obligations of this Addendum.

5. United States

"United States Data Protection Laws" means applicable U.S. state privacy laws, including but not limited to the California Consumer Privacy Act (as amended by the CPRA), and comparable laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states as enacted or amended from time to time.

  • Customer discloses Customer Personal Data to Certainty Engine solely for valid business purposes and to enable Certainty Engine to perform the Services.

  • Certainty Engine shall not (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than performing the Services or as otherwise permitted by United States Data Protection Laws; or (iii) combine Customer Personal Data with data Certainty Engine processes on behalf of other customers, except as permitted by law. Certainty Engine certifies that it understands and will comply with these restrictions.

  • Upon termination of the Agreement, Certainty Engine shall, as soon as reasonably practicable, delete or return all Customer Personal Data it Processed on Customer's behalf, unless applicable law requires or permits continued storage.

APPENDIX I TO EXHIBIT B — SUPPLEMENTAL CLAUSES TO THE STANDARD CONTRACTUAL CLAUSES

This Appendix provides additional safeguards and redress mechanisms for Data Subjects whose Personal Data is transferred under the SCCs. It supplements, and does not modify, the SCCs applicable to a given Restricted Transfer.

1. Applicability of Surveillance Laws

  • Certainty Engine represents that, as of the Effective Date, it has not received any national security order of the type described in the Schrems II judgment (Case C-311/18).

  • Certainty Engine will notify Customer if it becomes subject to a legally binding request from a public authority for disclosure of Customer Personal Data, unless prohibited by law from doing so, and will challenge such requests where it has reasonable grounds to consider them unlawful.

2. No Backdoors

Certainty Engine certifies that it has not purposefully created backdoors or similar mechanisms that would allow governmental agencies to access Customer Personal Data or its systems, and that it is not required by applicable law or government policy to create or maintain such mechanisms. If this changes, Certainty Engine will notify Customer, who may terminate the Agreement on short notice.

3. Government Access Requests

Where legally required to disclose Customer Personal Data to a public authority, Certainty Engine will (i) require an official, signed legal document before considering any request; (ii) scrutinize the request for validity and challenge or narrow overbroad requests; (iii) respond as narrowly as possible; and (iv) notify Customer of the request, unless prohibited by law.

4. Termination

This Appendix automatically terminates with respect to a given Restricted Transfer if a competent Supervisory Authority approves an alternative transfer mechanism that does not require these additional safeguards.

SIGNATURE / ACCEPTANCE

This Addendum is accepted electronically by Customer upon acceptance of the Certainty Engine Terms of Service (including by clicking "I Agree," checking an acceptance box, or continuing to use the Services after notice), and no further signature is required for it to take effect. Customers requiring a manually countersigned copy for internal compliance purposes may request one at [email protected].

Certainty Engine

Customer

Name

[Authorized Signatory Name]

[Customer Authorized Signatory Name]

Title

[Title]

[Title]

Date

Signature