Relynt

Data Processing Addendum

Last updated July 1, 2026

This Data Processing Addendum (DPA) forms part of the Master Services Agreement and applies where Relynt processes personal data on behalf of a customer who acts as a controller. Capitalized terms not defined here have the meaning given in the MSA.

1. Definitions

“Data Protection Laws” means all laws and regulations applicable to the processing of personal data under the Agreement, including the GDPR, the UK GDPR, and applicable U.S. state privacy laws. “Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” have the meanings given in the applicable Data Protection Laws. “Customer Personal Data” means personal data that Relynt processes on behalf of the Customer under the Agreement.

2. Roles of the Parties

The parties agree that, with respect to Customer Personal Data, the Customer is the Controller and Relynt is the Processor, and that Relynt may engage subprocessors in accordance with this DPA. Each party will comply with its obligations under applicable Data Protection Laws.

3. Processing of Personal Data

Relynt will process Customer Personal Data only on the documented instructions of the Customer, including with regard to international transfers, unless required by law to act otherwise. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A. Relynt will inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.

4. Confidentiality

Relynt will ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and have received appropriate training on their responsibilities.

5. Security Measures

Relynt will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the processing, as further described in Annex B. These measures include encryption in transit and at rest, access controls, logging and monitoring, and regular testing of security controls.

6. Subprocessors

The Customer provides a general authorization for Relynt to engage subprocessors to process Customer Personal Data, provided that Relynt: (a) maintains a current list of subprocessors and provides a mechanism to obtain notice of changes; (b) imposes data protection obligations on each subprocessor that are no less protective than those in this DPA; and (c) remains liable for the performance of each subprocessor. The Customer may object to a new subprocessor on reasonable data-protection grounds.

7. Data Subject Requests

Taking into account the nature of the processing, Relynt will provide reasonable assistance, including by appropriate technical and organizational measures, to enable the Customer to respond to requests from data subjects exercising their rights under applicable Data Protection Laws. If Relynt receives such a request directly, it will, unless legally prohibited, promptly forward it to the Customer and not respond except on the Customer’s instructions.

8. Personal Data Breach

Relynt will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide information reasonably available to it to assist the Customer in meeting its breach-notification obligations.

9. Data Protection Impact Assessments

Relynt will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, in each case solely in relation to the processing of Customer Personal Data and taking into account the information available to Relynt.

10. International Transfers

To the extent Relynt processes Customer Personal Data subject to the GDPR or UK GDPR in a country that has not received an adequacy decision, the parties agree that the Standard Contractual Clauses, and the UK Addendum where applicable, are incorporated into this DPA and apply to such transfers.

11. Return and Deletion

Upon termination or expiration of the Agreement, Relynt will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless applicable law requires continued storage. Routine backups will be deleted in the ordinary course consistent with Relynt’s retention schedule.

12. Audits

Relynt will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality, scheduling, and security requirements. Relynt may satisfy audit requests by providing third-party certifications or reports where available.

13. Annexes

Annex A — Details of Processing. Describes the subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects.

Annex B — Technical and Organizational Measures. Describes the security measures implemented by Relynt.

Annex C — Subprocessors. Lists the subprocessors authorized as of the effective date.