Effective as of July 1, 2026 (the “Addendum Effective Date”), this Flannel Technologies Inc. (the “Flannel”) U. S. Data Processing Addendum (“US DPA”) incorporated by reference into the Terms of Service between Flannel and Customer (the “Agreement”). This US DPA applies to the Processing of Personal Information in connection with the Services.

1. DEFINITIONS

Definitions shall have the meaning set forth below, or if not defined herein, shall have the meaning set forth in the Agreement.

  1. “Applicable Privacy Laws” means any U.S. state or federal privacy or security law that are in effect during the Term, and which apply to Personal Information processed pursuant to the Agreement, including but not limited to the Virginia Consumer Data Protection Act, the California Privacy Rights Act, the Colorado Privacy Act, the Connecticut Data Protection Act, the Utah Consumer Privacy Act, each as amended, replaced or supplemented from time to time, and all subordinate legislation made under them.
  2. “Approved Sub-processor” means any third party engaged by Flannel to Process Customer Personal Data on Flannel’s behalf in connection with the Services.
  3. "Personal Information" or “Personal Data” shall mean: (1) any information relating to an identified or identifiable natural person or household; and (2) any information defined as “personally identifiable information,” “personal information,” “personal data” or similar terms as such terms are defined under Applicable Privacy Laws.
  4. “Customer Personal Information” shall mean the Personal Information of persons provided by Customer which Flannel Processes in connection with the Services.
  5. “Data Subject” means any person or household as defined by Applicable Privacy Laws.
  6. Process” or “Processing” means any set of operations performed upon Personal Information, whether or not by automatic means, including the following activities: collect, retain, process, transfer, share or otherwise use.
  7. "Incident" means the known accidental or unlawful destruction, loss, alteration, unauthorized disclosure of Personal Information, or access to, transmission of, storage of, or otherwise processing by Customer or a Sub-processor of Customer.
  8. Sensitive Information” means information defined as “sensitive” or “special category” about an individual or household under Applicable Privacy Laws, including but not limited to: financial account numbers, insurance plan numbers, precise information about health or medical conditions, medical records or pharmaceutical prescriptions, government-issued identifiers (such as a Social Security number), race, ethnicity, religion, trade union membership, status as a child under 18, sexual orientation, genetic or biometric information and precise location information such as GPS coordinates.

2. Roles; Responsibilities:

  1. With respect to Customer Personal Data, Customer is the Controller (or, where Customer acts on behalf of another Controller, a Processor), and Flannel is the Processor (or Sub-processor, as applicable). Each party shall comply with its obligations under Applicable Data Protection Laws in its respective role.
  2. Customer shall not submit, and shall not permit any Authorized User to submit, to the Services any Special Categories of Personal Data, government-issued identifiers (e.g., social security numbers), payment card data subject to PCI DSS, protected health information subject to HIPAA, or data from children under 16 (or the equivalent minimum age under applicable law), unless the parties have separately agreed in writing that the Services may be used for such data.
  3. Customer shall have the right to object to any sub-processor added to the sub-processors by providing written notice to Flannel within 30 days from the addition of such sub-processor to the list of Flannel’s sub-processors as notified by Flannel from time to time, with sufficient details regarding the reason for such objection. The parties shall discuss in good faith the reason for such objection and if the objection cannot be overcome within thirty (30) days, Customer shall have the right to terminate the Agreement within fifteen (15) days from the end of such 30-day period. Each sub-processor shall become an Approved Sub-processor if (i) Customer does not timely provide an objection, or (ii) Customer does not terminate the Agreement and/or continues to use the Services after the end of the 15-day period.

3. Scope and Instructions:

Flannel shall Process Customer Personal Data only (a) in accordance with the Agreement and this DPA; (b) on the documented written instructions of Customer (including Customer’s use and configuration of the Services); and (c) as required by applicable law, in which case Flannel shall, to the extent legally permitted, inform Customer of that legal requirement before Processing. The Agreement (including this DPA), together with Customer’s use and configuration of the Services, constitutes Customer’s complete and final instructions to Flannel for the Processing of Customer Personal Data. Any additional or alternate instructions must be agreed upon in writing.

4. Flannel Warranties:

Flannel represents, warrants and covenants that it understands the rules, restrictions, requirements and definitions of the Applicable Privacy Laws and agrees to adhere to the requirements of the Applicable Privacy Laws that applies to its Processing of Personal Information of consumers for the Services stated in the Agreement.

5. Customer Warranties:

Customer warrants that it is responsible for providing, or for any Personal Information provided by a third party, contractually requiring such third party to have legally sufficient privacy notices to applicable Data Subjects and (where required by Applicable Privacy Laws) must obtain appropriate consent from Data Subjects for Customer’s information collection and use practices relating to the Services including but not limited to the use of cookies and similar technologies for tracking purposes in connection with the Services. The foregoing also applies to Customer’s utilization of the Services to gather Personal Information, and Customer indemnifies Flannel for such use of the Services in violation of Applicable Privacy Law.

6. Data Retention:

Flannel shall retain Customer Personal Information only for as long as necessary to provide the Services. Upon termination of the parties Agreement for any reason, Flannel shall erase, delete, or destroy all or any part of such Customer Personal Information in accordance with Flannel’s standard termination policy policy.

7. Security:

  1. Information Security Standard. Flannel agrees that it will use commercially reasonable efforts to maintain administrative, technical, and physical safeguards that are no less rigorous than industry standard practices to ensure the security and confidentiality of Personal Information, protect against any anticipated threats or hazards to the confidentiality, availability or integrity of Personal Information, and protect against unauthorized access, use, or alteration of Personal Information.
  2. Written Information Security Program. Flannel shall maintain, in writing, reasonable security procedures and practices (“Written Information Security Program” or “WISP”) that are necessary to protect Customer Personal Information within its control from unauthorized access, destruction, use, modification, or disclosure.
  3. Incident Procedures. Any Incident shall be subject to the following procedures:
    1. Flannel shall notify Customer without undue delay (within 72 hours) of any Incident by sending an email with all available and relevant details to Customer’s designated email address(es).
    2. Flannel shall investigate the Incident, and provide reasonable and necessary cooperation with Customer, including facilitating interviews with relevant personnel, making available all relevant records, logs, files, data reporting and other materials, and providing Customer with reasonable physical access to the facilities affected.
    3. Unless required by law, Flannel shall not inform any third party of any Incident without first obtaining Customer’s prior written consent, other than to inform a complainant that the matter has been forwarded to Customer’s legal counsel.
    4. Following a Incident, Flannel shall document responsive actions taken in connection with the Incident and shall conduct a post-breach review of events and actions taken, if any, to make changes in security practices and procedures to prevent such Incident from occurring again in the future.
  4. Incident Remediation. Flannel shall use its commercially reasonable efforts to mitigate and remedy any Incident and prevent any further Incident at its sole expense.
  5. Third Party notification. Flannel agrees that, unless applicable law states otherwise, Customer shall have the sole right to determine (i) whether notice of the Incident is to be provided to any individuals, regulators, law enforcement agencies, consumer reporting agencies or others as required by law or regulation, or otherwise in Customer’s discretion, (ii) the contents of such notice, and (iii) whether any type of remediation may be offered to affected persons, as well as the nature and extent of any such remediation. Flannel agrees to reimburse Customer for reasonable costs described in this section for Incidents and/or as required by applicable law to the extent caused by Flannel’s breach of this US DPA or Applicable Privacy Law.

8. Compliance Audits:

Customer (or a mutually agreed independent third-party auditor that is not a competitor of Flannel) may, at Customer’s expense, conduct an audit of Flannel’s relevant policies and procedures upon at least thirty (30) days’ prior written notice, no more than once per twelve (12) month period (except where required by a Supervisory Authority (as defined in Applicable Privacy Law) or following an Incident), during normal business hours, in a manner that does not unreasonably interfere with Flannel’s operations and that complies with Flannel’s reasonable security and confidentiality requirements.

9. Liability:

Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set forth in the Agreement.

10. Data Subject Requests:

  1. Flannel shall assist Customer to provide reasonably appropriate technical and organizational measures, and any reasonably necessary product features and functionality to allow the Customer to effectively fulfill its obligations to respond to Data Subject requests for information, access, correction, rectification, restriction, portability, objection, and deletion requests pertaining to Customer Personal Information as required under Applicable Privacy Laws (each, a “Data Subject Request”). At the direction of a Customer Affiliate, Flannel shall promptly, and in any event within thirty (30) days, unless otherwise agreed in writing, use commercially reasonable efforts to completely respond to and fulfill a Customer’s request for further Data Subject Request assistance. The parties shall otherwise reasonably communicate to ensure compliance with Applicable Privacy Laws in honoring each Data Subject Request.
  2. Flannel shall reasonably maintain complete and accurate records in connection with each of Customer’s Data Subject Requests.
  3. Except as required by law, Flannel shall notify Customer of any Data Subject Requests that it receives, without responding to the individual except to acknowledge receipt of the Data Subject Request.

11. Legal Compliance:

Both parties agree to notify the other party within five (5) business days if it (i) has reason to believe that it is unable to comply with any of its obligations under this US DPA and it cannot cure this inability to comply within a reasonable timeframe; or (ii) becomes aware of any circumstances or change in applicable Applicable Privacy Laws that is likely to prevent it from fulfilling its obligations under this US DPA. If this US DPA, or any actions to be taken or contemplated to be taken in performance of this US DPA, does not or would not satisfy either party’s obligations under such Applicable Privacy Laws, the Parties will negotiate in good faith an amendment to this US DPA.