Mizo Named Runner-Up in ConnectWise IT Nation PitchIT Competition 2025 Read the full press release

Mizo Data Processing Agreement

Last updated on July 12th, 2026


EXHIBIT B — DATA PROCESSING AGREEMENT

This Exhibit B (this “DPA”) is incorporated into and forms part of the License Agreement (the “Agreement”) between Mizo Technology Inc. (carrying on business as “Mizo”) (“Provider”) and Customer, as identified in the applicable Order Form. This DPA governs the processing of Personal Data by Provider on Customer’s behalf in connection with the Service.

Capitalized terms not defined herein have the meanings given to them in the Agreement. In the event of any conflict between this DPA and the Agreement, this DPA shall govern with respect to data protection matters. In the event of any conflict between this DPA and an applicable jurisdiction-specific Schedule (B-1, B-2, or B-3), the applicable Schedule shall govern to the extent of that conflict.

This DPA includes the following Schedules, each of which is incorporated herein by reference:

  • Schedule 1 to Exhibit B – Processing Particulars
  • Schedule B-1: Canada Data Protection Schedule (Québec Law 25 / PIPEDA)
  • Schedule B-2: EU Data Protection Schedule (GDPR + Standard Contractual Clauses)
  • Schedule B-3: US Data Protection Schedule (CCPA and applicable US state laws)
  • Schedule B-4: Data Residency Appendix
  • Schedule B-5: United Kingdom Data Protection Schedule (UK GDPR + Data Protection Act 2018)

1. Definitions

The following terms have the meanings given below. Terms defined in the Agreement and not redefined herein retain their Agreement meanings.

1.1 “Applicable Privacy Law” means the data protection and privacy legislation applicable to Provider’s processing of Personal Data under a given Order Form, as determined by Customer’s elected DPA Schedule: (a) Schedule B-1: Québec Law 25 and PIPEDA; (b) Schedule B-2: GDPR; (c) Schedule B-3: CCPA and applicable US state privacy laws; and (d) Schedule B-5: UK GDPR and the Data Protection Act 2018.

1.2 “Controller” means the entity that determines the purposes and means of processing Personal Data. For the purposes of this DPA, Customer is the Controller.

1.3 “Data Subject” means a natural person whose Personal Data is contained within Customer Data.

1.4 “GDPR” means the EU General Data Protection Regulation (Regulation (EU) 2016/679) and any implementing legislation in applicable EU member states. For clarity, “GDPR” does not include the UK GDPR.

1.5 “UK GDPR” means the EU General Data Protection Regulation as it forms part of the law of England, Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended from time to time, read together with the Data Protection Act 2018. “DPA 2018” means the Data Protection Act 2018 (UK).

1.6 “Law 25” means Québec’s Act respecting the protection of personal information in the private sector (CQLR c P-39.1, as amended), and PIPEDA means the Personal Information Protection and Electronic Documents Act (Canada).

1.7 “Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”) contained within Customer Data, as defined under Applicable Privacy Law. Personal Data does not include anonymous or de-identified data that cannot reasonably be re-identified.

1.8 “Processing” or “Process” means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure, transfer, or deletion.

1.9 “Processor” means an entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, Provider is the Processor.

1.10 “Security Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

1.11 “Sensitive Data” means Personal Data subject to heightened protection under Applicable Privacy Law, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health information, biometric data, genetic data, financial account information, and government-issued identifiers.

1.12 “Sub-Processor” or “Subprocessor” means any third party engaged by Provider to process Personal Data on Customer’s behalf in connection with the Service.

1.13 “Standard Contractual Clauses” or “SCCs” means the standard data protection clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (Module 2: Controller to Processor).

2. Roles and Appointment

2.1 Controller and Processor. The Parties acknowledge and agree that, with respect to the processing of Personal Data under this DPA: (a) Customer is the Controller; and (b) Provider is the Processor acting on Customer’s behalf in accordance with Customer’s documented instructions.

2.2 Appointment. Customer hereby appoints Provider as a Processor to process Personal Data on Customer’s behalf solely for the purposes described in Section 3 and the applicable Processing Particulars in Schedule 1 to this DPA.

2.3 Compliance. Each Party shall comply with its respective obligations under Applicable Privacy Law. Customer, as Controller, is responsible for: (a) ensuring it has a lawful basis for providing Personal Data to Provider; (b) providing any required notices to Data Subjects; and (c) ensuring Customer’s instructions to Provider comply with Applicable Privacy Law.

2.4 Provider Not a Business Associate. For the avoidance of doubt, this DPA does not constitute Provider acting as a “Business Associate” for HIPAA purposes. The Service is not designed or intended for use with Protected Health Information as defined by HIPAA.

3. Processing Instructions and Purpose Limitation

3.1 Documented Instructions. Provider shall process Personal Data only: (a) in accordance with Customer’s documented instructions as set out in this DPA and the Agreement; (b) as necessary to deliver the Service and fulfill its obligations under the Agreement; and (c) as required by applicable law, in which case Provider shall inform Customer of that legal requirement before processing, unless prohibited by law.

3.2 Purpose Limitation. Provider shall not process Personal Data for any purpose other than: (a) delivering and operating the Service; (b) providing technical support to Customer; (c) security monitoring, incident detection, and vulnerability management; (d) complying with applicable law; and (e) such other purposes as Customer may authorize in writing from time to time.

3.3 Instructions Outside Scope. If Provider reasonably determines that any Customer instruction infringes Applicable Privacy Law, Provider shall promptly notify Customer. Provider may suspend processing of the affected Personal Data pending resolution, without liability to Customer.

3.4 AI-Specific Processing — Self-Learning Layer. Provider’s Service includes a Self-Learning Layer that uses reinforcement learning signals derived from Customer feedback on AI Agent outputs (such as approval, rejection, or correction of recommended actions) to improve the accuracy and effectiveness of the AI Agent within Customer’s own tenant environment. Processing within the Self-Learning Layer: (a) is performed exclusively on a per-tenant basis — no Customer Data or feedback signals are combined with data from other customers; (b) constitutes processing necessary for the delivery and continuous improvement of the Service under the Agreement; and (c) does not involve the use of Personal Data for any purpose unrelated to Service delivery to Customer. Customer may disable the Self-Learning Layer at any time by written notice to Provider, in which case Provider shall cease reinforcement learning processing for Customer’s tenant within five (5) Business Days of receipt of such notice. Disabling the Self-Learning Layer may reduce the effectiveness of the AI Agent for Customer’s use case.

4. Processing Particulars

4.1 Processing Particulars Table. The following table sets out the key particulars of Provider’s processing of Personal Data under this DPA:

ParameterDetails
Subject matter of processingDelivery of the Mizo AI-native agentic service desk platform (the “Service”) as described in the Agreement
Duration of processingFor the duration of the Subscription Term and the data retention periods set out in Section 15 of this DPA
Nature of processingCollection, storage, use, automated processing, AI inference, vector embedding, analysis, and deletion of Personal Data in connection with Service delivery
Purposes of processingIT service desk automation; AI Agent operations within Customer’s Connected Systems; knowledge base construction and semantic search; per-tenant reinforcement learning from Customer feedback (see Section 3.4); technical support; security monitoring
Categories of Personal DataNames and email addresses of Customer personnel and end-users; IT asset identifiers; IT ticket content (which may contain incidental Sensitive Data — see Section 6.2); PSA system data; RMM system data; M365 interaction data; authentication credentials (processed by Okta on Provider’s behalf); AI Agent action logs
Categories of Data SubjectsCustomer’s employees, contractors, and agents; Customer’s MSP end-users; Customer’s PSA/RMM system users
Special categories / Sensitive DataNot systematically collected. Ticket content may incidentally contain Sensitive Data. Customer is responsible for the Sensitive Data it submits through the Service — see Section 6.2
Frequency of processingContinuous — the Service processes Customer Data in real time as Customer and its Authorized Users interact with the Service
Retention periodDuration of Subscription Term; post-termination: production systems 30 days; backups 90 days — see Section 12

5. Lawful Basis and Customer Obligations

5.1 Customer’s Lawful Basis. Customer, as Controller, confirms that it has identified and shall maintain a valid lawful basis under Applicable Privacy Law for each category of Personal Data provided to Provider for processing under this DPA.

5.2 Service Delivery Processing. The primary lawful basis for Provider’s processing of Personal Data in connection with Service delivery is performance of the contract between the Parties (or, under Law 25, the legitimate purpose of service delivery).

5.3 Self-Learning Layer — Lawful Basis. The lawful basis for processing Personal Data within the Self-Learning Layer is as follows: (a) under GDPR (Schedule B-2) and UK GDPR (Schedule B-5): performance of the contract between the Parties (Article 6(1)(b)), on the basis that the Self-Learning Layer is a core feature of the Service that Customer has contracted to receive, and its operation is necessary to deliver the Service as described in the Agreement; alternatively, where a supervisory authority determines that Article 6(1)(b) does not apply, Provider relies on its legitimate interests under Article 6(1)(f) in improving the quality and accuracy of the Service for Customer’s benefit, balanced against the minimal additional risk to Data Subjects given that processing is per-tenant and limited to feedback signals on AI Agent outputs; (b) under Law 25 (Schedule B-1): performance of the mandate between the Parties and the legitimate purpose of delivering and improving the Service (Law 25, Art. 18); (c) under CCPA (Schedule B-3): a permitted business purpose of performing the Service (see Schedule B-3, Section 3.1). Customer may opt out of Self-Learning Layer processing at any time in accordance with Section 3.4.

5.4 Privacy Notices. Customer is solely responsible for providing all required notices and disclosures to Data Subjects about Provider’s processing of their Personal Data, including through Customer’s own privacy policy.

6. Sensitive Data Restrictions

6.1 No Systematic Collection. The Service is not designed for the systematic collection or processing of Sensitive Data. Provider does not seek to collect Sensitive Data in the ordinary course of Service delivery.

6.2 Customer Restriction. Customer shall not submit Sensitive Data to the Service (whether via ticket content, PSA integrations, or Connected Systems) without obtaining all necessary consents from affected Data Subjects.

6.3 Incidental Sensitive Data. Customer acknowledges that IT ticket content may incidentally contain Sensitive Data. Customer is responsible for implementing controls on its end to minimize the submission of Sensitive Data through tickets and for ensuring any such incidental submission is permitted under Customer’s legal obligations.

6.4 Sensitive Personal Data Processing. Where Customer’s data includes systematic collection of Sensitive personal data (as defined in Section 1.10), Customer must notify Provider and the Parties shall enter into the Sensitive Data Addendum (Exhibit E).

7. International Transfers of Personal Data

7.1 Primary Processing Location. Provider processes Personal Data within Canada (Azure Canada Central and Canada East regions). Canada is recognized as providing an adequate level of data protection for certain transfers from the European Economic Area under EU adequacy decisions.

7.2 US-Based Sub-Processors. Provider engages certain US-based Sub-Processors for business operations purposes, as identified in the Trust Page For Customers who have elected Schedule B-2 (EU DPA Schedule), transfers to these Sub-Processors are subject to the transfer mechanisms described in Schedule B-2.

7.3 Transfer Mechanism Election. The applicable international transfer mechanism for each Customer is determined by Customer’s elected DPA Schedule, as follows:

Elected ScheduleJurisdictionTransfer Mechanism
Schedule B-1Canada (Law 25 / PIPEDA)Not applicable — processing occurs within Canada. PIPEDA cross-border transfer disclosure obligations apply for US Sub-Processors.
Schedule B-2EU / EEA (GDPR)SCCs (Module 2: Controller to Processor) for transfers from Customer to Provider; SCCs (Module 3 or adequacy) for transfers to US-based Sub-Processors. See Schedule B-2.
Schedule B-3United States (CCPA)Not applicable — no EEA cross-border transfer. CCPA Service Provider framework applies.
Schedule B-5United Kingdom (UK GDPR)UK adequacy decision for Canada covers the primary transfer (UK Customer to Provider in Canada Central / Canada East). For transfers to US-based Sub-Processors: UK International Data Transfer Addendum to EU SCCs (ICO, s.119A DPA 2018). See Schedule B-5.

7.4 No Other Transfers. Provider shall not transfer Personal Data to any country or territory outside the countries specified in this Section 7 and Trust Page without Customer’s prior written consent and the implementation of an appropriate transfer mechanism.

8. Law Enforcement Requests

8.1 Notification. If Provider receives a request from any law enforcement, regulatory, judicial, or governmental authority (an “Authority”) to disclose Personal Data, Provider shall, to the extent permitted by applicable law: (a) promptly notify Customer of the request; (b) cooperate with Customer in challenging the request or seeking a protective order; and (c) disclose only the minimum Personal Data required to comply with the legally binding request.

8.2 Legal Prohibition. If Provider is legally prohibited from notifying Customer of a request, Provider shall use commercially reasonable efforts to challenge the prohibition. Provider shall disclose Personal Data to the Authority only to the minimum extent legally required.

8.3 Extraordinary Measures Assessment. For requests from Authorities in countries without an EU adequacy decision (where relevant), Provider shall assess whether the request constitutes an extraordinary measure inconsistent with an open, democratic society and shall notify Customer of such assessment.

9. Confidentiality of Processing

9.1 Personnel Obligations. Provider shall ensure that all personnel authorized to process Personal Data are subject to written confidentiality obligations, whether by employment agreement, contractor agreement, or equivalent binding arrangement. Such obligations shall survive the termination of the individual’s engagement with Provider.

9.2 Access Limitation. Provider shall limit access to Personal Data to personnel who require such access to perform their functions in connection with the Service.

10. Security Measures

10.1 Technical and Organizational Measures. Provider shall implement and maintain the technical and organizational measures (“TOMs”) describedin the Trust Page to protect Personal Data against: (a) accidental or unlawful destruction, loss, or alteration; (b) unauthorized disclosure or access; and (c) all other unlawful forms of processing.

10.2 Level of Security. In determining the appropriate level of security, Provider shall take account of: (a) the state of the art; (b) the costs of implementation; (c) the nature, scope, context, and purposes of processing; and (d) the risk to the rights and freedoms of Data Subjects.

10.3 Updates to Security Measures. Provider may update or modify the TOMs from time to time, provided that any such modification does not materially reduce the overall level of protection afforded to Personal Data.

10.4 SCC Annex II. For Customers who have elected Schedule B-2, the Trust Page constitute the technical and organizational security measures for the purposes of Annex II of the Standard Contractual Clauses. Customers may request a current description of such measures in accordance with the audit rights set out in Exhibit C, Section 12.

11. Sub-Processors

11.1 Authorized Sub-Processors. Customer hereby provides general written authorization for Provider to engage Sub-Processors for the purposes of delivering the Service, subject to the conditions in this Section 11. The current list of authorized Sub-Processors is set out in the Trust Page.

11.2 Sub-Processor Obligations. Before engaging any Sub-Processor, Provider shall: (a) conduct reasonable due diligence on the Sub-Processor’s data protection practices; and (b) enter into a written agreement with the Sub-Processor imposing data protection obligations that are no less protective than those in this DPA.

11.3 Change Notification. Provider shall provide Customer with written notice at least 5 Business Days before adding or replacing any Sub-Processor.

11.4 Customer Objection. Customer may object to the addition or replacement of a Sub-Processor on legitimate data protection grounds by providing written notice to Provider within the notice period specified in Section 11.3. The Parties shall negotiate in good faith. If the objection cannot be resolved, Customer may terminate the affected Order Form without penalty.

11.5 Emergency Changes. Where a Sub-Processor must be changed immediately due to a Security Breach, service disruption, or urgent security concern, Provider may make such change immediately and notify Customer within twenty-four (24) hours.

11.6 Provider Responsibility. Provider remains fully responsible to Customer for the performance of each Sub-Processor’s data protection obligations under this DPA to the same extent as if Provider performed them directly.

12. Data Subject Rights Assistance

12.1 Customer Responsibility. Customer, as Controller, is responsible for receiving, assessing, and responding to Data Subject requests to exercise their rights under Applicable Privacy Law (including rights of access, rectification, erasure, restriction, portability, and objection).

12.2 Provider Assistance. Provider shall, taking into account the nature of the processing, provide reasonable technical and organizational assistance to Customer to enable Customer to fulfil its obligations to respond to Data Subject requests. Such assistance shall include: (a) making available to Customer the relevant Personal Data held in Customer’s account; (b) making available the data export function described in Section 14.1; and (c) assisting with deletion of specific Personal Data at Customer’s written request.

12.3 Response Period. Provider shall respond to Customer’s requests for assistance under this Section 12 within ten (10) Business Days of receipt.

12.4 Misdirected Requests. If Provider receives a Data Subject request directly, Provider shall promptly notify Customer and shall not respond to such request without Customer’s prior written authorization, except as required by applicable law.

13. Data Protection Impact Assessments

13.1 Provider Assistance. To the extent required by Applicable Privacy Law (including GDPR Article 35), Provider shall provide reasonable assistance to Customer in conducting Data Protection Impact Assessments (“DPIAs”) where the processing of Personal Data is likely to result in a high risk to Data Subjects’ rights and freedoms.

13.2 AI Agent Processing. Customer acknowledges that the use of the AI Agent in Autonomous Mode and the processing of Personal Data within Connected Systems may trigger DPIA obligations under GDPR Article 35 and equivalent provisions of Applicable Privacy Law. Customer is solely responsible for conducting any required DPIAs.

13.3 DPIA Information. Upon Customer’s written request, Provider shall make available such information about its processing operations as is reasonably required for Customer to conduct a DPIA, subject to Provider’s confidentiality obligations.

14. Security Incidents and Breach Notification

14.1 Detection and Assessment. Provider shall implement the detection and monitoring measures described in Exhibit C, Section 9, to identify Security Breaches promptly.

14.2 Customer Notification. Upon becoming aware of a confirmed Security Breach affecting Personal Data, Provider shall notify Customer without undue delay and in any event within forty-eight (48) hours of Provider’s confirmation of the Security Breach. Initial notification shall include, to the extent then known: (a) a description of the nature of the Security Breach, including the categories and approximate number of Data Subjects affected; (b) the name and contact details of Provider’s data protection contact; (c) the likely consequences of the Security Breach; and (d) the measures taken or proposed to address the Security Breach.

14.3 Regulatory Notification. Provider shall cooperate with Customer in meeting Customer’s regulatory notification obligations. Where Applicable Privacy Law requires Customer (as Controller) to notify the applicable supervisory authority, Provider shall provide Customer with all information necessary to make such notification within a timeframe that enables Customer to comply with the applicable notification deadline. Under GDPR (Schedule B-2), this deadline is seventy-two (72) hours from Customer’s awareness of the Security Breach. Under UK GDPR (Schedule B-5), this deadline is also seventy-two (72) hours from Customer’s awareness of the Security Breach, to be notified to the Information Commissioner’s Office (ICO). Under Law 25, the applicable deadline is as prescribed by the Commission d’accès à l’information du Québec.

14.4 Ongoing Updates. Provider shall provide Customer with updates on the Security Breach at intervals of no more than forty-eight (48) hours until the Security Breach is fully resolved.

14.5 Post-Incident Review. Provider shall conduct a post-incident review within ten (10) business days of resolution and shall make a written summary available to Customer upon request.

14.6 Notification Not Acknowledgment. Provider’s notification of a Security Breach under this Section 14 does not constitute an admission of fault, liability, or negligence.

15. Return and Deletion of Personal Data

15.1 Data Portability During Term. At any time during the Subscription Term, Customer may request an export of Personal Data in JSON format. Provider shall make such export available within commercially reasonable period, generally not exceeding fifteen (15) Business Days of Customer’s written request.

15.2 Post-Termination Wind-Down. Following termination or expiry of the Agreement: (a) Provider shall maintain Customer Data, including Personal Data, in an accessible state for a period of thirty (30) days from the effective date of termination or expiry (the “Wind-Down Period”) to enable Customer to retrieve its data; (b) upon expiry of the Wind-Down Period, Provider shall permanently delete all Personal Data from production systems within thirty (30) days; and (c) backup copies of Personal Data shall be deleted within ninety (90) days following the effective date of termination or expiry.

15.3 Legal Retention Obligation. Where Provider is required by applicable law to retain certain Personal Data beyond the periods specified in Section 15.2, Provider shall: (a) notify Customer of such obligation; (b) isolate and protect the retained data from further processing; and (c) delete the data as soon as the legal retention obligation expires.

15.4 Certificate of Deletion. Upon Customer’s written request, Provider shall issue a written certificate of deletion signed by an authorized officer confirming deletion of Personal Data from all production systems and, upon completion, from all backup systems.

16. Audit Rights

16.1 Exercise of Audit Rights. Customer’s audit rights under this DPA and, where applicable, under the Standard Contractual Clauses, are exercised through the mechanisms set out in Exhibit C (Security Exhibit), Section 12. Those provisions are incorporated herein by reference.

16.2 Frequency. Audit rights may be exercised no more than once per calendar year, except on reasonable written cause (such as a confirmed or reasonably suspected Security Breach).

16.3 Costs. All reasonable costs of any audit are borne by Customer, unless the audit reveals a material breach of Provider’s obligations under this DPA, in which case Provider shall bear such costs.

16.4 Confidentiality of Audit Findings. Audit findings are Confidential Information of Provider and may be used by Customer only for the purposes of assessing compliance with this DPA.

17. Automated Decision-Making

17.1 Customer Responsibility. The AI Agent may make recommendations and, in Autonomous Mode, take automated actions within Customer’s Connected Systems. Customer, as Controller, is solely responsible for ensuring that its use of the AI Agent complies with any obligations imposed on Controllers by Applicable Privacy Law with respect to automated decision-making, including GDPR Article 22 and equivalent provisions of Law 25.

17.2 Autonomous Mode. Customer expressly acknowledges that configuring Autonomous Mode may engage automated decision-making provisions of Applicable Privacy Law. Customer is responsible for: (a) assessing whether GDPR Article 22 or equivalent applies to its specific use case; (b) implementing any required safeguards (such as the right to human review); and (c) providing required notices to Data Subjects.

17.3 Provider Assistance. Provider shall provide reasonable assistance to Customer in understanding the AI Agent’s decision logic at a high level, upon Customer’s written request, to facilitate Customer’s compliance with automated decision-making obligations.

18. Miscellaneous

18.1 Survival. Provider’s obligations under this DPA shall survive so long as Provider and/or its Sub-Processors process Personal Data on Customer’s behalf.

18.2 Conflict with Agreement. Except as modified by this DPA, the Agreement remains in full force and effect. In the event of a conflict between this DPA and the Agreement, this DPA shall govern with respect to the processing of Personal Data.

18.3 Updates to Online Terms. Provider publishes this document online and may update it from time to time. Provider shall give active Customers at least thirty (30) days prior written notice before any material update to these online terms takes effect. Updates apply to all new Order Forms executed after the effective date. For existing Order Forms, updates apply at the start of the next Renewal Term following the notice period. Updates required by applicable law or a regulatory authority may take effect immediately upon notice. The Last Updated date in the footer of each online document indicates the currently effective version. Notwithstanding the foregoing, an executed Order Form may only be amended by a written instrument signed by authorized representatives of both Parties.

18.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall continue in full force and effect.

18.5 Term. This DPA shall terminate automatically upon the later of: (a) termination or expiry of the Agreement; and (b) the date on which Provider has completed deletion of all Personal Data in accordance with Section 15.

18.6 Governing Law. This DPA is governed by the same governing law as the Agreement, as set out in Section 17 of the Agreement. For Customers who have elected Schedule B-2, the Standard Contractual Clauses shall be governed by the law specified in Schedule B-2.

18.7 Entire DPA. This DPA, together with its Schedules and the Agreement, constitutes the entire agreement between the Parties with respect to the processing of Personal Data and supersedes all prior agreements, representations, and understandings relating to such processing.


SCHEDULE 1 TO EXHIBIT B — PROCESSING PARTICULARS

This Schedule 1 supplements the processing particulars set out in Section 4 of this DPA and serves as Annex I to the Standard Contractual Clauses (where Schedule B-2 has been elected).

A. List of Parties (SCC Annex I.A)

FieldData Exporter (Customer)Data Importer (Provider)
NameAs per executed Order FormMizo Technology Inc., carrying on business as “Mizo”
AddressAs per executed Order Form201-4115 Boulevard St-Laurent, Montreal, QC, Canada, H2W 1Y7
ContactAs per executed Order FormLegal / Privacy — [email protected] / [email protected]
RoleControllerProcessor
Signature and DateAs per executed Order FormAs per executed Order Form

B. Description of Transfer (SCC Annex I.B)

ParameterDetails
Categories of Data SubjectsCustomer’s employees and contractors; Customer’s MSP end-users; personnel of Customer’s clients whose data is present in PSA/RMM systems
Categories of Personal DataNames; email addresses; IT asset identifiers; IT ticket content; PSA/RMM system data; M365 interaction data; authentication credentials; AI Agent action logs; vector embeddings derived from the foregoing
Sensitive Data transferredNot systematically transferred. Ticket content may incidentally contain sensitive categories. Customer must implement controls to minimize such incidental transfers.
Frequency of transferContinuous — ongoing transfers as Customer and Authorized Users interact with the Service
Nature of processingCollection, storage, automated AI processing, vector embedding, semantic search, AI Agent inference and action logging, deletion
Purpose of processingDelivery of the Mizo Service; AI Agent operations within Connected Systems; IT ticket automation; knowledge base management; technical support; security monitoring
Retention periodDuration of Subscription Term; post-termination: 30 days (production), 90 days (backups)
Transfers to Sub-ProcessorsAs listed in Trust Page (https://mizo.tech/trust). EU customers: US-based Sub-Processors subject to SCCs per Schedule B-2.

C. Competent Supervisory Authority (SCC Annex I.C)

For Customers who have elected Schedule B-2 (GDPR), the competent supervisory authority is determined as follows:

Customer SituationCompetent Supervisory Authority
Customer has elected Schedule B-2 and is established in an EU member stateThe supervisory authority of the member state where Customer is established — to be identified by Customer in the Order Form
Customer has elected Schedule B-2, is not established in the EU/EEA but falls within GDPR’s extraterritorial scope, and has appointed an EEA representativeThe supervisory authority of the member state where the representative is established
Customer has elected Schedule B-2, is not established in the EU/EEA, falls within GDPR’s extraterritorial scope, and has not appointed an EEA representativeThe supervisory authority of the member state where the Data Subjects are predominantly located
Customer has elected Schedule B-5 (UK customers)Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom (www.ico.org.uk)

Completion Status. As of the Last Updated date of this DPA, Schedule B-5 (United Kingdom Data Protection Schedule) is in draft form and is not available for election. Any reference in an Order Form to Schedule B-5 shall have no effect until Provider has issued a written confirmation that the Schedule has been finalized and is available for election. Customers requiring UK data protection terms should contact Provider’s legal team at [email protected] for current availability.


SCHEDULE B-1 — CANADA DATA PROTECTION SCHEDULE

This Schedule B-1 (this “Canada Schedule”) is attached to and forms part of Exhibit B (Data Processing Agreement) to the License Agreement (the “Agreement”). This Canada Schedule applies where Customer has elected Schedule B-1 in the applicable Order Form.

This Canada Schedule sets out the additional obligations of the Parties with respect to Personal Data subject to Québec’s Act respecting the protection of personal information in the private sector (CQLR c P-39.1, as amended, “Law 25”) and the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”), as applicable.

In the event of any conflict between this Canada Schedule and Exhibit B (DPA), this Canada Schedule shall govern to the extent of that conflict. Capitalized terms not defined herein have the meanings given to them in the Agreement or in Exhibit B.

1. Applicable Law

1.1 Law 25. Law 25 applies to Provider’s processing of Personal Data on behalf of Customers who are enterprises subject to Law 25, including Customers incorporated or operating in Québec. Law 25 imposes obligations on both Customer (as the enterprise responsible for the personal information) and Provider (as the person having communication of such information).

1.2 PIPEDA. PIPEDA applies to Provider’s processing of Personal Data on behalf of Customers engaged in commercial activities in Canada (outside Québec) or in interprovincial and international contexts. Where Law 25 and PIPEDA overlap, Law 25 shall govern with respect to Customers operating primarily in Québec.

1.3 Supremacy of Regulations. To the extent any provision of this Canada Schedule conflicts with a mandatory provision of Law 25 or PIPEDA, the applicable mandatory statutory provision shall prevail.

2. Accountability and Privacy Officer

2.1 Provider’s Privacy Officer. Provider has designated a privacy officer responsible for ensuring Provider’s compliance with Law 25 and PIPEDA in connection with the Service. Inquiries regarding Provider’s privacy practices may be directed to Provider’s privacy contact displayed on the Trust Page.

2.2 Privacy Policy. Provider maintains a publicly accessible privacy policy in accordance with Law 25, Article 63.3 and PIPEDA Principle 1 (Accountability). Provider’s privacy policy is available at: mizo.tech/privacy.

2.3 Customer Accountability. Customer, as the enterprise responsible for the personal information provided to Provider, remains accountable for Provider’s processing of such information under Law 25 and PIPEDA. Customer shall include appropriate references to Provider’s processing in Customer’s own privacy policy and notices.

3.1 Identified Purposes. Provider processes Personal Data under this Canada Schedule for the following identified purposes, as required by Law 25 and PIPEDA Principle 2 (Identifying Purposes):

PurposeLegal Basis (Law 25 / PIPEDA)Notes
Delivery of the Service (IT ticket automation, AI Agent operations, knowledge base management)Performance of the contract between the Parties; necessary for the purposes of the enterprisePrimary purpose — disclosed to Customer at time of contracting
Technical support and incident responseNecessary for the purposes of the enterprise; legitimate interestSecondary purpose — incidental to Service delivery
Security monitoring and vulnerability managementLegitimate interest in protecting the security of the Service and Customer DataDisclosed in Provider’s privacy policy and this Schedule
Self-Learning Layer (reinforcement learning from Customer feedback)Performance of the mandate between the Parties (Law 25, Art. 18); necessary for the purposes of the enterprise (PIPEDA Principle 2)Per-tenant processing only — no cross-customer data combination. Customer may opt out per §3.4 of Exhibit B. Purpose disclosed at time of contracting.

3.2 No Unauthorized Purposes. Provider shall not process Personal Data for any purpose other than those identified in Section 3.1 without Customer’s prior written consent and, where required by Law 25, without identification of a new purpose and provision of required notice to Data Subjects.

3.3 Customer Consent Obligations. Customer is responsible for ensuring that any consent required from Data Subjects under Law 25 or PIPEDA for the processing described in Section 3.1 has been validly obtained, or that another lawful basis applies.

4. Cross-Border Transfers and Foreign Jurisdiction Disclosure

4.1 Disclosure of Foreign Processing. In accordance with PIPEDA Principle 1 and Law 25, Provider hereby notifies Customer that certain Personal Data processed under this Schedule may be communicated to Sub-Processors located in a foreign jurisdiction, specifically the United States, for internal business operations purposes.

4.2 US-Based Sub-Processors. The following categories of Personal Data may be processed by US-based Sub-Processors as identified in the Trust Page:

Data CommunicatedPurposeJurisdiction
Names, email addresses, notification identifiersEmail and SMS notification deliveryUnited States
Staff names, email addresses, communication metadataInternal business communicationsUnited States
Customer contact names, email addressesCRM and sales pipeline managementUnited States
Contact names, email addressesEmail marketing and outreachUnited States

4.3 Equivalent Protection. Provider has entered into contractual arrangements with each US-based Sub-Processor requiring the Sub-Processor to maintain data protection standards equivalent to those required under this Schedule and Exhibit B. Notwithstanding such contractual protections, Customer acknowledges that, once Personal Data is communicated to a US-based Sub-Processor, it may be subject to access by US government authorities under US law, including the US Foreign Intelligence Surveillance Act (FISA) and other national security laws.

4.4 Customer Notice Obligation. Customer shall include disclosure of the cross-border communication described in this Section 4 in Customer’s privacy policy and any applicable consent forms presented to Data Subjects, in accordance with Law 25 and PIPEDA.

4.5 Privacy Impact Assessment — Cross-Border. Customer may request that Provider conduct or cooperate in a privacy impact assessment (PIA) of the cross-border transfer arrangements described in this Section 4, in accordance with Law 25, Article 3.3.

5. Individual Rights under Law 25 and PIPEDA

Data Subjects whose Personal Data is processed under this Canada Schedule have the following rights. Customer, as the enterprise responsible for the personal information, is the primary point of contact for Data Subject rights requests. Provider shall assist Customer as described in Exhibit B, Section 12.

RightLegal SourceProvider’s Role
Right of access — to know what personal information is held and how it is usedLaw 25, Art. 37; PIPEDA Principle 9Assist Customer by making available the Personal Data held in Customer’s account upon Customer’s written request
Right of rectification — to have inaccurate personal information correctedLaw 25, Art. 37; PIPEDA Principle 9Assist Customer by correcting or enabling correction of Personal Data upon Customer’s written request
Right to withdraw consent — to withdraw consent for processing where consent is the basisLaw 25, Art. 23; PIPEDA Principle 3Cease processing upon Customer’s instruction following valid withdrawal; does not apply to processing based on legitimate interest or contractual necessity
Right to erasure (de-indexation) — to have personal information deleted where no legitimate purpose existsLaw 25, Art. 28.1 (as of Sept. 22, 2023)Delete or de-index Personal Data upon Customer’s instruction, subject to legal retention obligations
Right to data portability — to receive personal information in a structured, commonly used formatLaw 25, Art. 37 (as of Sept. 22, 2023)Provide Customer Data export in JSON format within commercially reasonable period, generally not exceeding fifteen (15) Business Days of Customer’s written request per Exhibit B, Section 15.1
Right to be informed of automated decision-making — to be informed of and contest significant decisions made solely by automated meansLaw 25, Art. 12.1See Section 6 of this Canada Schedule
Right to lodge a complaint — with the Commission d’accès à l’information du Québec (CAI)Law 25, Art. 37.1Not directly applicable to Provider; Customer to include in its privacy policy

6. Automated Decision-Making — Law 25, Article 12.1

6.1 Application. Law 25, Article 12.1 requires enterprises to inform individuals before making exclusively automated decisions about them that produce legal effects or significantly affect them, and to offer the individual the right to request human review of such decisions.

6.2 Customer’s Obligation. Customer, as the enterprise using the AI Agent within its operations, is solely responsible for determining whether its use of the AI Agent constitutes exclusively automated decision-making under Law 25, Article 12.1, and for fulfilling all associated disclosure and review obligations toward affected Data Subjects.

6.3 Autonomous Mode. Customer expressly acknowledges that configuring the AI Agent in Autonomous Mode may engage Law 25, Article 12.1 obligations where the AI Agent takes automated actions within Customer’s Connected Systems that significantly affect Customer’s MSP end-users. Customer is responsible for: (a) assessing whether Article 12.1 applies to its specific use case; (b) implementing any required human review mechanism; and (c) providing required notices to affected Data Subjects.

6.4 Provider Assistance. Upon Customer’s written request, Provider shall provide Customer with a plain-language description of the AI Agent’s decision logic to assist Customer in meeting its Law 25, Article 12.1 disclosure obligations.

7. Privacy Impact Assessments and Sensitive Data — Law 25, Article 3.3

7.1 PIA Obligation. Law 25, Article 3.3 requires enterprises to conduct a privacy impact assessment (PIA) before implementing any project involving the collection, use, communication, keeping, or destruction of personal information.

7.2 Customer’s PIA Responsibility. Customer is responsible for conducting any PIA required in connection with its deployment of the Service, including the use of the AI Agent within Connected Systems and any cross-border transfer of Personal Data to US-based Sub-Processors.

7.3 Provider’s Cooperation. Provider shall cooperate with Customer in conducting any required PIA by making available relevant technical and organizational information about the Service, including the security measures in Exhibit C and the Sub-Processor information in the Trust Page.

7.4 Biometric Data and AI. Where a Customer’s use of the Service involves processing that is likely to engage Law 25’s enhanced requirements for biometric data or automated decision-making, Provider shall flag such processing to Customer and cooperate in any required PIA.

7.5 Sensitive Data Processing. Where Customer’s data includes systematic collection of Sensitive personal data (as defined in Section 1.10), Customer must notify Provider and the Parties shall enter into the Sensitive Data Addendum attached as Exhibit E.

8. Privacy Breach Notification

8.1 Provider Notification to Customer. As set out in Exhibit B, Section 14.2, Provider shall notify Customer within forty-eight (48) hours of confirming a Security Breach affecting Personal Data.

8.2 Customer’s Regulatory Notification — Law 25. Under Law 25, Article 3.5, Customer (as the enterprise responsible for the personal information) must notify the Commission d’accès à l’information du Québec (“CAI”) and affected individuals of a confidentiality incident where there is a risk of serious harm. Provider shall cooperate with Customer in making such notification, including by providing: (a) a description of the Personal Data affected; (b) the approximate number of Data Subjects affected; (c) the cause of the incident; and (d) the measures taken to mitigate harm.

8.3 Customer’s Regulatory Notification — PIPEDA. Under PIPEDA, Section 10.1, Customer must notify the Office of the Privacy Commissioner of Canada (“OPC”) and affected individuals of a breach involving a real risk of significant harm. Provider shall cooperate with Customer as described in Section 8.2 above.

8.4 Notification Timeline. Provider shall provide Customer with the information required for regulatory notification within a timeframe that enables Customer to comply with its notification obligations. Customer is responsible for assessing the risk of serious harm / significant harm and making any required regulatory notifications.

8.5 Breach Register. Provider shall maintain a log of all confirmed Security Breaches affecting Personal Data processed under this Canada Schedule, including the date, nature, and scope of each breach and the measures taken. Provider shall make this log available to Customer upon request.

9. Retention and Disposal

9.1 Retention Limitation. Provider shall not retain Personal Data longer than necessary for the identified purposes set out in Section 3.1 of this Canada Schedule. The retention periods set out in Exhibit B, Section 15 (30 days production / 90 days backup post-termination) govern.

9.2 Disposal Standards. Upon deletion of Personal Data in accordance with Exhibit B, Section 15, Provider shall ensure that the Personal Data is destroyed in a manner that prevents reconstruction, in accordance with best practices for secure data disposal.

9.3 Certificate of Disposal. Provider shall issue a certificate of deletion to Customer upon request, confirming disposal in accordance with this Section 9 and Exhibit B, Section 15.4.

10. Competent Regulatory Authority

Applicable LawRegulatory AuthorityContact
Québec Law 25Commission d’accès à l’information du Québec (CAI)www.cai.gouv.qc.ca
PIPEDA (federal)Office of the Privacy Commissioner of Canada (OPC)www.priv.gc.ca

Customer is responsible for all filings and notifications with these regulatory authorities in connection with Customer’s processing of Personal Data under this Canada Schedule.


SCHEDULE B-2 — EU DATA PROTECTION SCHEDULE

This Schedule B-2 (this “EU Schedule”) is attached to and forms part of Exhibit B (Data Processing Agreement) to the License Agreement (the “Agreement”). This EU Schedule applies where Customer has elected Schedule B-2 in the applicable Order Form.

This EU Schedule sets out the additional obligations of the Parties with respect to Personal Data subject to Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”) and any national implementing or supplementary data protection legislation of the Member States of the European Economic Area (collectively, “EU Data Protection Law”).

In the event of any conflict between this EU Schedule and Exhibit B (DPA), this EU Schedule shall govern to the extent of that conflict. Capitalized terms not defined herein have the meanings given to them in the Agreement or in Exhibit B. GDPR-specific capitalized terms (“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Supervisory Authority”) have the meanings given to them in Article 4 of the GDPR.

1. Applicable Law and Roles

1.1 GDPR. The GDPR applies to Provider’s processing of Personal Data on behalf of Customers established in the European Economic Area (“EEA”), or where the processing relates to the offering of goods or services to, or the monitoring of, Data Subjects located in the EEA (GDPR, Article 3).

1.2 Roles of the Parties. For the purposes of EU Data Protection Law, Customer is the “Controller” (or, where applicable, a “Joint Controller” or a “Processor” acting on behalf of a third-party Controller) of Personal Data processed under this EU Schedule, and Provider is the “Processor” acting on Customer’s documented instructions. Where Customer acts as a Processor on behalf of a third-party Controller, Customer warrants that it has obtained the necessary authorizations to engage Provider as a sub-processor.

1.3 Supremacy of Regulation. To the extent any provision of this EU Schedule conflicts with a mandatory provision of EU Data Protection Law, the applicable mandatory statutory provision shall prevail.

2. Processor Commitments (GDPR Article 28(3))

In accordance with GDPR, Article 28(3), Provider, as Processor, undertakes the following commitments. These commitments supplement and restate, for clarity, the obligations already set out in Exhibit B; in the event of any difference in wording, the broader protection for Data Subjects shall apply.

2.1 Documented Instructions (Art. 28(3)(a)). Provider shall process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which Provider is subject; in such case, Provider shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this DPA, and Customer’s use of the Service through its configuration controls constitute Customer’s documented instructions.

2.2 Confidentiality (Art. 28(3)(b)). Provider shall ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, as further described in Exhibit B, Section 9.

2.3 Security of Processing (Art. 28(3)(c) and Art. 32). Provider shall take all measures required pursuant to Article 32 of the GDPR (Security of Processing), as further described in Exhibit B, Section 10 and Exhibit C (Security Exhibit).

2.4 Sub-Processors (Art. 28(3)(d) and Art. 28(2), (4)). Provider shall respect the conditions referred to in Article 28(2) and (4) of the GDPR for engaging another processor, as further described in Exhibit B, Section 11. Provider shall ensure that any Sub-Processor it engages is bound by a written contract imposing data protection obligations equivalent to those imposed on Provider under this EU Schedule and Exhibit B, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.

2.5 Assistance with Data Subject Rights (Art. 28(3)(e)). Taking into account the nature of the Processing, Provider shall assist Customer by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of Customer’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR, as further described in Exhibit B, Section 12 and Section 4 of this EU Schedule.

2.6 Assistance with Controller Obligations (Art. 28(3)(f) and Arts. 32–36). Provider shall assist Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of Processing and the information available to Provider. This includes assistance with: (a) security of Processing (Art. 32); (b) notification of a personal data breach to the Supervisory Authority (Art. 33) and communication of a personal data breach to the Data Subject (Art. 34), as further described in Section 7 of this EU Schedule; (c) data protection impact assessments (Art. 35); and (d) prior consultation with the Supervisory Authority (Art. 36).

2.7 Return or Deletion (Art. 28(3)(g)). At the choice of Customer, Provider shall delete or return all the Personal Data to Customer after the end of the provision of services relating to Processing, and delete existing copies, unless Union or Member State law requires storage of the Personal Data, as further described in Exhibit B, Section 15.

2.8 Audits and Information (Art. 28(3)(h)). Provider shall make available to Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, as further described in Exhibit B, Section 16.

2.9 Notice of Infringing Instruction (Art. 28(3), final paragraph). Provider shall immediately inform Customer if, in its opinion, an instruction from Customer infringes the GDPR or other Union or Member State data protection provisions. Provider shall have no obligation to act on such instruction pending its clarification or withdrawal by Customer.

3. International Transfers of Personal Data

3.1 Transfers Overview. Personal Data processed under this EU Schedule may be transferred outside the EEA in the following circumstances: (a) to Provider in Canada for the purpose of providing the Service; and (b) to Sub-Processors located in third countries as identified in the Trust Page (https://mizo.tech/trust). Each transfer is implemented in accordance with Chapter V of the GDPR.

3.2 Adequacy Decisions. Where the destination country benefits from a European Commission adequacy decision under GDPR, Article 45, the transfer is made on the basis of that adequacy decision. In particular, transfers to Provider in Canada are made on the basis of the European Commission’s adequacy decision of 20 December 2001 (Commission Decision 2002/2/EC) concerning the adequate protection of personal data provided by the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”), as affirmed by the European Commission’s first periodic review of 15 January 2024 (COM(2024) 7 final), and as may be amended, replaced, or supplemented from time to time. The Parties acknowledge that the PIPEDA adequacy decision is limited to processing within the scope of PIPEDA, and does not, by its terms, extend to processing of Personal Data that takes place wholly within the Province of Québec and is governed solely by the Act respecting the protection of personal information in the private sector (CQLR c P-39.1, “Law 25”). To the extent any transfer to Provider falls outside the scope of the PIPEDA adequacy decision (including by reason of being governed solely by Law 25), the transfer shall be governed by the EU SCCs as set out in Section 3.3 below.

3.3 Standard Contractual Clauses — Fallback. Where no adequacy decision applies, or where the transfer falls outside the scope of an applicable adequacy decision, the Parties agree that the transfer shall be governed by the Standard Contractual Clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”), which are hereby incorporated by reference into this EU Schedule, with the following selections:

(a) Modules. Module Two (Controller to Processor) applies to transfers from Customer to Provider. Module Three (Processor to Processor) applies to onward transfers from Provider to its Sub-Processors where Customer is the original Controller.

(b) Docking Clause (Clause 7). The optional docking clause applies, allowing additional parties to accede to the EU SCCs.

(c) Sub-Processor Authorisation (Clause 9). Option 2 (general written authorisation) applies. The list of Sub-Processors and the change-notification mechanism are set out in Exhibit B, Section 11 and the Trust Page.

(d) Redress (Clause 11). The optional independent-dispute-resolution provision does not apply.

(e) Governing Law (Clause 17). Option 1 applies. The EU SCCs shall be governed by the law of the EU Member State in which Customer is established, or, where Customer is not established in an EU Member State, by the law of Ireland.

(f) Choice of Forum (Clause 18). The competent courts shall be those of the EU Member State in which Customer is established, or, where Customer is not established in an EU Member State, the courts of Ireland.

(g) Annexes. Annex I.A (List of Parties) is populated by the Parties’ details in the Order Form. Annex I.B (Description of the Transfer) is set out in Schedule 1 to this Exhibit B (Processing Particulars) and the Trust Page. Annex I.C (Competent Supervisory Authority) is the Supervisory Authority of the Member State in which Customer’s EU representative is established, or, where Customer is established in the EEA, the Supervisory Authority of Customer’s main establishment. Annex II (Technical and Organisational Measures) is set out in Exhibit C (Security Exhibit). Annex III (List of Sub-Processors) is set out in the Trust Page.

3.4 Transfer Impact Assessment. Where Personal Data is transferred under the EU SCCs, Provider shall carry out and maintain an assessment of the laws and practices of the relevant third country (a “Transfer Impact Assessment” or “TIA”), in accordance with Clause 14 of the EU SCCs and having regard to the recommendations of the European Data Protection Board. Provider shall make a summary of the TIA available to Customer upon written request.

3.5 Supplementary Measures. Where the TIA identifies that the laws of a third country may prevent Provider or a Sub-Processor from complying with the EU SCCs, Provider shall implement supplementary technical, organisational, or contractual measures to ensure an essentially equivalent level of protection, including, where appropriate: (a) encryption in transit and at rest; (b) strict access controls; and (c) contractual prohibitions on disclosure to public authorities absent valid legal process. The measures applicable to the Service are described in Exhibit C.

3.6 Conflict with Exhibit B. In the event of a conflict between the EU SCCs and any other term of this DPA, the EU SCCs shall prevail with respect to transfers governed by them.

4. Data Subject Rights

Data Subjects whose Personal Data is processed under this EU Schedule have the following rights under the GDPR. Customer, as Controller, is the primary point of contact for Data Subject rights requests. Provider shall assist Customer in fulfilling these requests as described in Exhibit B, Section 12 and below.

RightLegal Source (GDPR)Provider’s Assistance Obligation
Right to be informedArticles 13 and 14Provider supports Customer’s information notices by maintaining a publicly accessible privacy policy and by providing the information set out in this DPA, Schedule 1, and the Trust Page
Right of accessArticle 15Make available to Customer the Personal Data held in Customer’s account upon Customer’s written request within ten (10) Business Days
Right to rectificationArticle 16Correct or enable correction of Personal Data upon Customer’s written instruction
Right to erasure (“right to be forgotten”)Article 17Delete Personal Data upon Customer’s written instruction, subject to legal retention obligations and to the deletion timelines in Exhibit B, Section 15
Right to restriction of processingArticle 18Restrict Processing of specified Personal Data upon Customer’s written instruction (e.g., suspend access pending a dispute)
Right to data portabilityArticle 20Provide Customer Data export in JSON format per Exhibit B, Section 15.1, within a commercially reasonable period generally not exceeding fifteen (15) Business Days
Right to objectArticle 21Cease Processing upon Customer’s instruction following a valid objection; not applicable to processing strictly necessary for performance of the contract
Right not to be subject to automated decisionsArticle 22See Section 5 of this EU Schedule
Right to lodge a complaint with a Supervisory AuthorityArticle 77Not directly applicable to Provider; Customer to include in its privacy notices

4.1 Response Timing. Provider shall respond to Customer’s requests for Data Subject rights assistance within ten (10) Business Days. Customer is responsible for responding to Data Subjects within the one-month timeframe required by GDPR, Article 12(3) (extendable by two further months where necessary).

4.2 Verification. Customer is responsible for verifying the identity of Data Subjects who submit rights requests before instructing Provider to take action on such requests.

4.3 Direct Requests to Provider. Where Provider receives a Data Subject rights request directly, Provider shall, without undue delay and without responding to the request substantively, forward the request to Customer and provide such assistance as Customer reasonably requests in responding.

5. Automated Decision-Making — GDPR, Article 22

5.1 Application. GDPR, Article 22(1) provides Data Subjects with the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, except where the decision is necessary for entering into or performance of a contract, authorised by Union or Member State law, or based on the Data Subject’s explicit consent.

5.2 Customer’s Obligation. Customer, as Controller, is solely responsible for determining whether its use of the AI Agent constitutes solely automated decision-making under GDPR, Article 22, and for fulfilling all associated obligations toward affected Data Subjects, including: (a) identifying a lawful basis under Article 22(2); (b) providing the information required by Articles 13(2)(f) and 14(2)(g); (c) implementing suitable measures to safeguard the Data Subject’s rights, freedoms and legitimate interests, at least the right to obtain human intervention, to express their point of view, and to contest the decision; and (d) not basing such decisions on special categories of Personal Data unless Article 22(4) applies.

5.3 Autonomous Mode. Customer expressly acknowledges that configuring the AI Agent in Autonomous Mode (as defined in the Agreement) may engage GDPR, Article 22 obligations where the AI Agent takes automated actions within Customer’s Connected Systems that produce legal or similarly significant effects on Data Subjects. Customer is solely responsible for: (a) assessing whether Article 22 applies to its specific use case; (b) ensuring that an Article 22(2) lawful basis exists; (c) implementing a human-review mechanism; and (d) providing the required notices to affected Data Subjects.

5.4 Provider Assistance. Upon Customer’s written request, Provider shall provide reasonable assistance to Customer in understanding the AI Agent’s decision logic at a high level, to facilitate Customer’s compliance with its transparency obligations under GDPR, Articles 13(2)(f), 14(2)(g) and 15(1)(h).

6. Data Protection Impact Assessments — GDPR, Article 35

6.1 DPIA Obligation. GDPR, Article 35 requires the Controller to carry out a data protection impact assessment (“DPIA”) prior to processing that is likely to result in a high risk to the rights and freedoms of natural persons, including in particular: (a) systematic and extensive evaluation of personal aspects based on automated processing; (b) large-scale processing of special categories of data; and (c) systematic monitoring of publicly accessible areas on a large scale.

6.2 Customer’s DPIA Responsibility. Customer is responsible for conducting any DPIA required in connection with its deployment of the Service, including the use of the AI Agent within Connected Systems, any cross-border transfer of Personal Data, and any processing identified by a Supervisory Authority as requiring a DPIA under GDPR, Article 35(4).

6.3 Provider’s Cooperation. Provider shall provide reasonable assistance to Customer in conducting any required DPIA by making available relevant technical and organisational information about the Service, including the security measures in Exhibit C, the Sub-Processor information in the Trust Page, and the description of processing in Schedule 1 to this Exhibit B.

6.4 Prior Consultation. Where a DPIA indicates that the processing would result in a high risk in the absence of measures taken by Customer to mitigate the risk, Customer shall consult the competent Supervisory Authority prior to processing in accordance with GDPR, Article 36. Provider shall cooperate with Customer in such consultation upon reasonable written request.

6.5 Sensitive Data Processing. Where Customer’s data includes systematic collection of special categories of Personal Data (within the meaning of GDPR, Article 9) or data relating to criminal convictions and offences (Article 10), Customer must notify Provider and the Parties shall enter into the Sensitive Data Addendum attached as Exhibit E.

7. Personal Data Breach Notification — GDPR, Articles 33 and 34

7.1 Provider Notification to Customer. As set out in Exhibit B, Section 14.2, Provider shall notify Customer without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data Breach (within the meaning of GDPR, Article 4(12)) affecting Personal Data processed under this EU Schedule.

7.2 Information Provided. Provider’s notification shall include, to the extent then known: (a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (b) the name and contact details of Provider’s point of contact for the incident; (c) the likely consequences of the Personal Data Breach; and (d) the measures taken or proposed to be taken by Provider to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects. Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without further undue delay.

7.3 Customer’s Notification to Supervisory Authority. Customer, as Controller, is responsible for notifying the competent Supervisory Authority of a Personal Data Breach in accordance with GDPR, Article 33, without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of it, unless the Personal Data Breach is unlikely to result in a risk to the rights and freedoms of natural persons. Provider’s forty-eight (48) hour notification timeline under Section 7.1 is intended to enable Customer to meet this seventy-two (72) hour deadline.

7.4 Customer’s Communication to Data Subjects. Where the Personal Data Breach is likely to result in a high risk to the rights and freedoms of natural persons, Customer shall communicate the Personal Data Breach to the affected Data Subjects without undue delay in accordance with GDPR, Article 34. Provider shall cooperate with Customer in preparing such communication.

7.5 Breach Register. Provider shall maintain a log of all confirmed Personal Data Breaches affecting Personal Data processed under this EU Schedule, including the facts relating to the Personal Data Breach, its effects, and the remedial action taken, in accordance with GDPR, Article 33(5). Provider shall make this log available to Customer upon request.

7.6 Customer’s Risk Assessment. Customer is solely responsible for assessing the risk to the rights and freedoms of natural persons resulting from a Personal Data Breach and for determining whether notification to the Supervisory Authority or communication to Data Subjects is required.

8. Article 27 Representative and Data Protection Officer

8.1 No EU Establishment. Provider has no establishment in the European Union. To the extent the GDPR applies to Provider’s processing under Article 3(2), Provider shall designate in writing a representative in the Union in accordance with GDPR, Article 27, and shall provide the name and contact details of such representative to Customer upon written request. The Article 27 representative acts as a point of contact for Supervisory Authorities and Data Subjects on all matters relating to Provider’s processing.

8.2 Provider’s Privacy Contact. Provider has designated a privacy contact responsible for overseeing Provider’s compliance with EU Data Protection Law in connection with the Service. Inquiries regarding Provider’s privacy practices may be directed to: Mathieu Tougas, Mizo Technology Inc. (contact via mizo.tech/privacy).

8.3 Data Protection Officer. Provider has assessed its obligations under GDPR, Article 37 and has determined that it is not required to designate a Data Protection Officer. Provider shall reassess this determination as Provider’s processing activities evolve and shall notify Customer if a DPO is subsequently designated.

8.4 Customer’s DPO. Where Customer is required to designate a DPO under GDPR, Article 37, Customer shall provide the contact details of its DPO to Provider for use as the primary contact for matters arising under this EU Schedule.

9. Records of Processing and Competent Supervisory Authority

9.1 Provider Records. Provider shall maintain a record of all categories of processing activities carried out on behalf of Customer in accordance with GDPR, Article 30(2), including: (a) the name and contact details of Provider, of any Sub-Processor, and of Provider’s Article 27 representative; (b) the categories of processing carried out on behalf of Customer; (c) transfers of Personal Data to third countries and the documentation of suitable safeguards; and (d) a general description of the technical and organisational security measures referred to in Article 32(1).

9.2 Customer Access. Provider shall make its Article 30 records available to Customer upon written request, to the extent reasonably necessary for Customer to demonstrate its own compliance with GDPR, Article 30(1), or upon request from a Supervisory Authority.

9.3 Competent Supervisory Authority. The competent Supervisory Authority for the purposes of this EU Schedule and any EU SCCs is determined as follows:

Customer’s SituationCompetent Supervisory Authority
Customer is established in a single EU Member StateThe Supervisory Authority of that Member State
Customer is established in multiple EU Member StatesThe Supervisory Authority of the Member State of Customer’s main establishment, as determined under GDPR, Article 56
Customer is not established in the EEA but is subject to the GDPR under Article 3(2)The Supervisory Authority of the Member State in which Customer’s Article 27 representative is established
Customer cannot identify a lead Supervisory AuthorityThe Supervisory Authority of the Member State in which the Data Subjects whose Personal Data is processed are predominantly located

Customer is responsible for identifying its competent Supervisory Authority and for all filings and notifications with such authority in connection with Customer’s processing of Personal Data under this EU Schedule.

10. Liability under GDPR, Article 82

10.1 Statutory Allocation. Each Party shall be liable to Data Subjects in accordance with GDPR, Article 82. As between the Parties, liability for damages caused by Processing shall be apportioned in accordance with each Party’s responsibility for the event giving rise to the damage, taking into account: (a) Customer’s instructions and configuration of the Service; (b) Provider’s compliance with such instructions and with its obligations under this DPA; and (c) the limitations of liability set out in the Agreement.

10.2 Right of Recourse. Where a Party has paid full compensation for the damage suffered, that Party is entitled to claim back from the other Party that part of the compensation corresponding to that other Party’s part of responsibility for the damage, in accordance with GDPR, Article 82(5).

10.3 Administrative Fines. Administrative fines imposed on a Party under GDPR, Article 83 are the responsibility of the Party on which they are imposed and are not subject to indemnification by the other Party, save in respect of fines imposed as a direct result of that other Party’s breach of this DPA.


SCHEDULE B-3 — UNITED STATES DATA PROTECTION SCHEDULE

This Schedule B-3 (this “US Schedule”) is attached to and forms part of Exhibit B (Data Processing Agreement) to the License Agreement (the “Agreement”). This US Schedule applies where Customer has elected Schedule B-3 in the applicable Order Form.

This US Schedule sets out the additional obligations of the Parties with respect to Personal Information subject to the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 et seq., as amended by the California Privacy Rights Act) (“CCPA”) and any other applicable US state privacy legislation, as more particularly described herein (collectively, “US Privacy Law”).

In the event of any conflict between this US Schedule and Exhibit B (DPA), this US Schedule shall govern to the extent of that conflict. Capitalized terms not defined herein have the meanings given to them in the Agreement or Exhibit B. CCPA-specific capitalized terms (“Business”, “Service Provider”, “Consumer”, “Personal Information”, “Sell”, “Share”) have the meanings given to them in the CCPA.

1. Applicable US Privacy Laws

This US Schedule addresses Provider’s obligations under US state privacy laws that may apply to Customer’s use of the Service. The following laws are currently in scope:

JurisdictionLawEffective Date
CaliforniaCalifornia Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)CCPA: Jan. 1, 2020; CPRA amendments: Jan. 1, 2023
VirginiaConsumer Data Protection Act (CDPA)January 1, 2023
ColoradoColorado Privacy Act (CPA)July 1, 2023
ConnecticutAct Concerning Personal Data Privacy and Online Monitoring (CTDPA)July 1, 2023
TexasTexas Data Privacy and Security Act (TDPSA)July 1, 2024
Other enacted US state lawsAny other US state privacy law enacted and in force that applies to Customer’s processing activitiesAs enacted

1.1 Catch-All. Where a US state privacy law not listed in the table above becomes applicable to Customer’s use of the Service, the obligations of this US Schedule shall apply to such law to the extent consistent with its requirements, and the Parties shall negotiate in good faith any additional terms required for compliance.

1.2 Applicability Assessment. Customer is solely responsible for determining whether US Privacy Law applies to Customer’s processing of Personal Information in connection with the Service and for notifying Provider if the applicable threshold is met.

2. Service Provider Designation (CCPA)

2.1 Service Provider Status. For purposes of the CCPA, Provider is a “Service Provider” acting on behalf of Customer (as a “Business”). Provider receives Personal Information from Customer solely for the business purpose of delivering the Service as described in the Agreement.

2.2 No Sale or Sharing. Provider shall not: (a) Sell Personal Information received from Customer; (b) Share Personal Information received from Customer for cross-context behavioral advertising; (c) retain, use, or disclose Personal Information for any commercial purpose other than the business purpose of performing the Service; (d) retain, use, or disclose Personal Information outside the direct business relationship between Customer and Provider; or (e) combine Personal Information received from Customer with Personal Information collected from other sources, except as permitted under the CCPA and its regulations.

2.3 CCPA Certification. Provider certifies that it understands and shall comply with the restrictions set forth in Section 2.2 of this US Schedule.

2.4 Equivalent Treatment under Other US Laws. Under Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and materially equivalent US state laws, Provider is a “Processor” acting on behalf of Customer as the “Controller.” Provider’s obligations under this US Schedule apply equally to processing under such laws.

3. Permitted Uses of Personal Information

3.1 Business Purposes. Provider is authorized to use Personal Information received from Customer solely for the following business purposes, consistent with the Agreement and Exhibit B:

Business PurposeDescription
Service deliveryProcessing Customer Data to operate, deliver, and maintain the Service, including AI Agent operations, knowledge base management, and ticket automation
Security and fraud preventionDetecting, preventing, and responding to security incidents, unauthorized access, and fraudulent activity
Debugging and error repairIdentifying and correcting errors that impair the intended functionality of the Service
Internal research and developmentUsing de-identified or aggregated Usage Data to improve the Service; not using Personal Information for this purpose without Customer’s written consent
Legal complianceComplying with applicable law, court orders, and legal processes
AuditingInternal auditing relating to Provider’s compliance with this US Schedule and applicable law

3.2 No Other Use. Provider shall not use Personal Information for any purpose not listed in Section 3.1 without Customer’s prior written authorization.

3.3 Self-Learning Layer. Provider’s use of Personal Information within the Self-Learning Layer (reinforcement learning from Customer feedback on AI Agent outputs) constitutes a permitted business purpose under the CCPA, falling within the “performing the Service” category described in Section 3.1, first row. Processing is limited to per-tenant reinforcement learning signals and does not involve the sale, sharing, or cross-context use of Personal Information. Customer may instruct Provider to disable Self-Learning Layer processing in accordance with Section 3.4 of Exhibit B.

4. Consumer Rights Assistance

Data Subjects (“Consumers” under CCPA) have the following rights under US Privacy Law. Customer, as the Business / Controller, is the primary point of contact for Consumer rights requests. Provider shall assist Customer as described below.

Consumer RightLegal SourceProvider’s Assistance Obligation
Right to know — what Personal Information is collected, used, disclosed, or soldCCPA § 1798.110; CDPA Art. 59-1; equivalent state lawsMake available to Customer the Personal Information held in Customer’s account upon written request within 10 Business Days
Right to access — to receive a copy of Personal InformationCCPA § 1798.110; equivalent state lawsProvide Customer Data export in JSON format per Exhibit B, Section 15.1 within fifteen (15) Business Days
Right to deletion — to delete Personal InformationCCPA § 1798.105; equivalent state lawsDelete specified Personal Information upon Customer’s written instruction, subject to exceptions for legal retention and backup deletion timelines
Right to correction — to correct inaccurate Personal InformationCCPA § 1798.106 (CPRA); equivalent state lawsAssist Customer in correcting inaccurate data within Customer’s account upon written request
Right to opt-out of sale / sharingCCPA § 1798.120; equivalent state lawsNot applicable to Provider — Provider does not Sell or Share Personal Information. Provider shall not impede Customer’s compliance with opt-out requests.
Right to limit use of sensitive personal informationCCPA § 1798.121 (CPRA); equivalent state lawsProvider processes Sensitive Personal Information only as necessary for Service delivery — no use for inferring characteristics or for other secondary purposes
Right to non-discriminationCCPA § 1798.125Provider shall not discriminate against Consumers for exercising their privacy rights
Right to appeal (certain states)Virginia CDPA Art. 59-5; Colorado CPA § 6-1-1306; CT CTDPA § 14Provider shall cooperate with Customer in responding to Consumer appeals

4.1 Response Timing. Provider shall respond to Customer’s requests for Consumer rights assistance within ten (10) Business Days. Customer is responsible for responding to Consumers within the timeframes required by applicable US Privacy Law (generally 45 days under CCPA, with a 45-day extension where necessary).

4.2 Verification. Customer is responsible for verifying the identity of Consumers who submit rights requests before instructing Provider to take action on such requests.

4.3 Authorized Agents. Customer shall notify Provider if a Consumer rights request has been submitted by an authorized agent on behalf of a Consumer, and shall confirm that the agent’s authority has been verified in accordance with CCPA requirements.

5. Opt-Out Signals and Global Privacy Control

5.1 Customer Responsibility. Customer, as the Business / Controller, is responsible for receiving, processing, and honoring opt-out signals received from Consumers (including Global Privacy Control (GPC) signals under CCPA regulations), to the extent applicable to Customer’s operations.

5.2 Provider Passthrough. To the extent Customer instructs Provider in writing to treat specified Consumer accounts as having opted out of particular processing activities, Provider shall implement such instructions within a commercially reasonable timeframe. Provider is not responsible for independently receiving or processing opt-out signals from Consumers.

5.3 No Sale or Sharing — Opt-Out Not Required. Because Provider does not Sell or Share Personal Information (Section 2.2), Consumer opt-out requests directed at Provider’s processing activities do not require specific opt-out mechanisms beyond the deletion and restriction rights in Section 4.

6. Automated Decision-Making under US Privacy Law

6.1 Applicability. Several US state privacy laws (including Colorado CPA, Connecticut CTDPA, Virginia CDPA, and Texas TDPSA) include provisions governing automated decision-making and profiling, requiring either opt-out rights or data protection assessments.

6.2 Customer’s Obligation. Customer is responsible for: (a) assessing whether its use of the AI Agent constitutes “automated decision-making” or “profiling” under applicable US Privacy Law; (b) providing required opt-out mechanisms to Consumers where applicable; and (c) conducting any required data protection assessments.

6.3 Autonomous Mode. Customer acknowledges that configuring the AI Agent in Autonomous Mode may constitute automated decision-making subject to US Privacy Law protections. Customer is solely responsible for compliance.

6.4 Data Protection Assessments. Provider shall cooperate with Customer in conducting data protection assessments (“DPAs” — not to be confused with the Data Processing Agreement) required under Colorado CPA § 6-1-1309, Virginia CDPA Art. 59-10, and equivalent laws, by providing information about Provider’s processing activities upon Customer’s written request.

7. Sensitive Personal Information

7.1 CCPA Sensitive PI Categories. Under CCPA (as amended by CPRA), “Sensitive Personal Information” includes: Social Security and government ID numbers; financial account credentials; precise geolocation; racial or ethnic origin; religious beliefs; union membership; mail/email/text message contents (unless Provider is the intended recipient); genetic data; biometric data used to identify an individual; health information; and sexual orientation or sex life.

7.2 Provider’s Limitation. Provider uses Sensitive Personal Information received from Customer solely for the purposes of delivering the Service and for the other permitted business purposes in Section 3.1. Provider does not use Sensitive Personal Information to infer characteristics about Consumers or for any purpose other than those permitted by the CCPA and its regulations.

7.3 Customer Controls. Customer is responsible for implementing controls to minimize the submission of Sensitive Personal Information through the Service. If Customer’s use case systematically involves Sensitive Personal Information (for example, IT tickets containing health information), Customer must notify Provider and the Parties shall enter into the Sensitive Data Addendum attached as Exhibit E.

8. Data Breach Notification under US Law

8.1 Provider Notification. As set out in Exhibit B, Section 14.2, Provider shall notify Customer within forty-eight (48) hours of confirming a Security Breach affecting Personal Information.

8.2 State Breach Notification Laws. US state breach notification laws impose obligations on Customer (as the Business / Controller) to notify affected Consumers and, in some cases, state regulators, within specified timeframes following a breach. The following is a non-exhaustive summary:

StateNotification Deadline (Business to Consumer)Regulator Notification
CaliforniaExpedient / “most expedient time possible” without unreasonable delayCalifornia AG if breach affects 500+ CA residents
Virginia60 daysVirginia AG if breach affects 1,000+ VA residents
Colorado30 days (if 500+ CO residents affected)Colorado AG
Connecticut60 daysConnecticut AG
TexasReasonable time; not later than 60 days after discoveryTexas AG if breach affects 250+ TX residents
Other statesVaries — generally 30–90 daysVaries by state

8.3 Provider Cooperation. Provider shall provide Customer with all information necessary to comply with applicable state breach notification obligations within a timeframe that enables Customer to meet its notification deadlines. Customer is solely responsible for making all required notifications to Consumers and state regulators.

9. Subprocessor Disclosure

9.1 Subprocessors as Service Providers. Each Sub-Processor engaged by Provider to process Personal Information on Customer’s behalf is engaged as a Service Provider or equivalent (Processor) under applicable US Privacy Law. Provider has entered into written agreements with each Sub-Processor imposing CCPA-compliant Service Provider obligations equivalent to those imposed on Provider by this US Schedule.

9.2 Subprocessor List. The current list of Sub-Processors is set out in Provider’s trust page at [https://mizo.tech/trust]. All Sub-Processors listed in Trust Page, Section 1 (Core Service Subprocessors) process Personal Information exclusively within Canada. Sub-Processors listed in Trust Page, Section 2 (Business Operations Subprocessors) are US-based and process limited operational data as described in Trust Page.

9.3 No Further Downstream Sales. Provider shall ensure that each Sub-Processor does not Sell or Share Personal Information received from Provider.

10. De-Identification and Aggregated Data

10.1 Usage Data. Provider may use de-identified or aggregated data derived from Customer’s use of the Service for product improvement, analytics, and business purposes. “De-identified” data means data that cannot reasonably be used to identify an individual, consistent with the CCPA’s definition.

10.2 De-Identification Standard. Provider shall implement technical safeguards to prevent re-identification of de-identified data and shall not attempt to re-identify de-identified data. Provider shall contractually prohibit Sub-Processors from attempting to re-identify de-identified data.

10.3 No CCPA Obligations. De-identified and aggregated data is not subject to CCPA or other US Privacy Law obligations and may be used by Provider without restriction.

11. Records of Processing Activities

11.1 Provider Records. Provider shall maintain records of its processing activities in connection with this US Schedule sufficient to demonstrate compliance with applicable US Privacy Law and with Provider’s obligations as a Service Provider / Processor.

11.2 Customer Access. Provider shall make relevant records of processing available to Customer upon written request, to the extent reasonably necessary for Customer to demonstrate its compliance with applicable US Privacy Law.


SCHEDULE B-4 — DATA RESIDENCY APPENDIX

This Schedule B-4 (this “Data Residency Appendix”) is attached to and forms part of Exhibit B (Data Processing Agreement) to the License Agreement (the “Agreement”) between Mizo Technology Inc. (carrying on business as “Mizo”) (“Provider”) and Customer.

This Schedule governs the geographic regions within which Customer Data and Personal Data are stored and processed by Provider. It sets out Provider’s current data residency commitments, the contractual obligations attaching to those commitments, and the status of planned future regions.

Capitalized terms not defined herein have the meanings given to them in the Agreement or in Exhibit B.

1. Currently Available Data Residency Regions

1.1 Available Regions. As of the date of this Schedule, Provider offers data residency in the following Microsoft Azure regions:

Region DesignationAzure RegionRoleData StoredStatus
Canada CentralAzure Canada Central (Toronto)Primary — all Customer Data stored and processed here by defaultStructured data (MongoDB), vector data (QDrant), Memory System, backups, AI inference inputs/outputsOperational — available to all Customers
Canada EastAzure Canada East (Québec City)Secondary — disaster recovery replication only; not a customer-selectable primary regionReplicated backups; failover dataOperational — DR use only; not separately selectable by Customers

1.2 Default Region. Unless a Customer has expressly elected a different region in the Order Form (where such region is available), all Customer Data is stored and processed in Canada Central (primary) with replication to Canada East for disaster recovery purposes.

1.3 Order Form Election. Customer elects its data residency region in the Order Form. The elected region becomes a contractual commitment for the duration of the applicable Subscription Term and may only be changed by mutual written amendment to the executed Order Form.

2. Contractual Data Residency Commitments

The following commitments are contractually binding on Provider for all currently operational regions. These commitments apply regardless of the DPA Schedule elected by Customer.

2.1 Primary Region Commitment. Provider shall store and process all Customer Data exclusively within the primary region elected by Customer in the Order Form, subject to the exceptions in Section 2.5 and the Sub-Processor disclosures in Section 5.

2.2 AI Inference Region Commitment. Provider uses Microsoft Azure Foundry zone-standard deployments for all AI inference (LLM inference) workloads. AI inference is executed within the same Azure region as Customer’s elected primary region. No Customer Data is transmitted outside the elected region for AI inference purposes.

2.3 Per-Tenant Database Isolation. Provider maintains the following per-Customer data separation commitments:

ComponentIsolation MechanismContractual Commitment
Structured Data (MongoDB)Dedicated MongoDB database instance per CustomerYes — contractually committed. No cross-tenant data access is possible at the database layer.
Vector Database (QDrant)Dedicated QDrant collections per CustomerYes — contractually committed. Each Customer’s Knowledge Base embeddings are stored in a separate QDrant instance.
Memory SystemDedicated per-Customer Memory System databaseYes — contractually committed. Reinforcement learning data and session context are stored in Customer-specific databases with no cross-tenant access.
AI Inference ComputeShared stateless compute infrastructure with logical isolation controlsPartial — logical (not physical) isolation. Provider implements technical controls to prevent cross-tenant data access during inference sessions, as described in Exhibit C, Section 5.1.

2.4 Backup Data Residency. All backup data (hourly incremental and daily full) is stored within Canada. Primary backup storage is in Canada Central; DR replication is in Canada East. No backup data is stored outside Canada as of the date of this Schedule.

2.5 Permitted Cross-Border Processing. Notwithstanding the above, certain business operations data is processed by US-based Sub-Processors as described in Trust Page. These Sub-Processors process limited categories of data (names, email addresses, notification identifiers) for internal business operations purposes and do not have access to the core Service data (tickets, knowledge base, PSA data, AI Agent outputs). For Customers who have elected Schedule B-2, the applicable international transfer mechanisms are described in Schedule B-2.

3. Planned Future Regions

3.1 Anticipated Availability. Provider anticipates expanding its data residency offering to the following regions, subject to infrastructure availability:

RegionAnticipated AvailabilityContractual Status
European Union (EU)Anticipated end of calendar year 2026 (EOY 2026)NOT a contractual commitment. Provider makes no representation or warranty that EU region availability will occur by EOY 2026 or at all. Customer may not rely on this anticipated date for contracting purposes.
United States (US)Anticipated EOY 2026NOT a contractual commitment. Same caveat as EU region above.

3.2 No Contractual Obligation. Provider is under no contractual obligation to make EU or US regions available by any specific date. The anticipated dates in Section 3.1 are aspirational only and reflect Provider’s current business plans, which are subject to change.

3.3 Pre-Election of Future Regions. If Customer wishes to elect a future EU or US region as its primary region, Customer may indicate such preference in the Order Form. Such preference shall be noted as a non-binding preference only. Upon availability of the elected region, Provider shall notify Customer and the Parties shall execute a written amendment to the Order Form to formalize the region election and any associated data migration obligations.

3.4 Interim Arrangement. Until the elected future region is available and the Order Form amendment is executed, Customer’s data shall continue to be stored and processed in Canada Central. Provider shall migrate Customer Data to the newly available region upon mutual agreement of the migration timeline and without disruption to the Service.

4. Interaction with Data Protection Obligations

4.1 Canada Schedule (B-1). For Customers who have elected Schedule B-1, all Customer Data is processed within Canada. Provider’s use of US-based Sub-Processors for business operations (Trust Page) constitutes a cross-border transfer of limited operational data. In accordance with PIPEDA Principle 1 and Law 25, Customer is notified herein that certain Personal Data (names, email addresses, notification identifiers) may be processed by Provider’s US-based Sub-Processors. Such processing is disclosed in Trust Page and subject to Provider’s contractual obligations with each Sub-Processor.

4.2 EU Schedule (B-2). For Customers who have elected Schedule B-2, Provider’s commitment to process Customer Data within Canada is relevant to the adequacy determination applicable to transfers from the EEA to Canada. Note that Canada’s adequacy decision covers commercial organizations subject to PIPEDA and may not automatically cover all categories of processing. The transfer of Personal Data from the EEA to Provider is governed by the Standard Contractual Clauses in Schedule B-2.

4.3 US Schedule (B-3). For Customers who have elected Schedule B-3, data residency in Canada does not create additional compliance obligations under CCPA. The CCPA Service Provider framework described in Schedule B-3 applies regardless of whether data is processed in Canada or the US.

5. Sub-Processor Data Locations

The following summarizes the data residency position for each Sub-Processor. The authoritative Sub-Processor list is Trust Page.

Sub-ProcessorProcessing LocationData Residency ImpactEU Customer Note
Microsoft AzureCanada Central (primary); Canada East (DR)Within elected region — full compliance with Canada residency commitmentCanada adequacy decision applies for EEA-to-Canada transfers
MongoDB, Inc.Canada Central (primary); Canada East (DR)Within elected region — per-tenant dedicated instancesCanada adequacy applies
QDrant, Inc.Canada Central (primary); Canada East (DR)Within elected region — per-tenant dedicated instancesCanada adequacy applies
Okta, Inc.CanadaWithin Canada — authentication data onlyCanada adequacy applies
Twilio, Inc.United StatesOutside elected region — limited operational data only (names, emails, notification IDs)
Microsoft 365United StatesOutside elected region — internal Provider communications only; no core Service data
PipeDrive, Inc.United StatesOutside elected region — CRM/contact data only
Lemlist, Inc.United StatesOutside elected region — marketing contact data only

6. Grandfathered Data Residency Deviations

6.1 Existing Customers. Certain existing customers of Provider have negotiated specific data residency terms that deviate from the standard terms in this Schedule. Such deviations are documented in the applicable customer’s executed Order Form or data residency addendum.

6.2 Governing Terms. For customers with grandfathered data residency deviations, the specific terms in their executed documentation govern and supersede the standard terms of this Schedule to the extent of any inconsistency, in accordance with Section 9.5 of the Agreement.

6.3 No Further Grandfathering. Provider does not intend to grant additional data residency deviations outside of the standard terms in this Schedule without the prior approval of Provider’s legal counsel.

7. Changes to Data Residency Commitments

7.1 No Unilateral Changes. Provider shall not unilaterally change Customer’s elected primary data residency region during the Subscription Term.

7.2 Infrastructure Changes. If Provider intends to make infrastructure changes that would affect the location of Customer Data processing (for example, a change in cloud provider or data centre), Provider shall provide Customer with at least ninety (90) days’ written notice and shall obtain Customer’s prior written consent.

7.3 New Regions. Provider may add new data residency regions at any time without Customer’s consent, provided that the addition does not affect Customer’s existing elected region or result in any Customer Data being processed outside Customer’s elected region without Customer’s consent.


SCHEDULE B-5 — UNITED KINGDOM DATA PROTECTION SCHEDULE

Reserved. This Schedule is not yet available for election and will be published in a future version of this DPA.