================================================================================

DATA PROCESSING ADDENDUM

HQPartizan - Firebird SQL Query Optimization Tool

IBSurgeon Software (Processor) and Customer (Controller)

Version 1.0 - Effective Date: February 1, 2025

================================================================================

TABLE OF CONTENTS

1. Scope and Application

2. Definitions

3. Roles and Processing Instructions

4. Security Measures

5. Sub-Processors

6. Data Subject Rights

7. Personal Data Breaches

8. International Data Transfers

9. Data Retention and Deletion

10. Audits

11. Liability

12. Term and Termination

13. General Provisions

14. Execution

================================================================================

1. SCOPE AND APPLICATION

================================================================================

1.1 Purpose

This DPA governs IBSurgeon’s processing of Personal Data on behalf of Customer

when using the SQL Query Optimization Tool.

1.2 When This DPA Applies

- Customer processes Personal Data using the Software

- Customer is subject to GDPR, UK GDPR, LGPD, CCPA/CPRA, or similar laws

- Customer needs Standard Contractual Clauses for international transfers

1.3 Incorporation

This DPA is part of the EULA. For data protection matters, this DPA prevails

over the EULA.

1.4 Execution

Execute this DPA via email to [email protected]

================================================================================

2. DEFINITIONS

================================================================================

Controller: Customer (determines purposes and means of Processing)

Processor: IBSurgeon (Processes Personal Data on behalf of Customer)

Personal Data: Information relating to an identified or identifiable person

Data Subject: Individual to whom Personal Data relates

Processing: Any operation on Personal Data (collection, storage, use,

deletion, etc.)

Sub-Processor: Third party engaged by IBSurgeon to Process Personal Data

Personal Data Breach: Security breach affecting Personal Data

Data Protection Laws: GDPR, UK GDPR, LGPD, CCPA/CPRA, and similar laws

Standard Contractual Clauses (SCCs): EU-approved clauses for international

transfers

================================================================================

3. ROLES AND PROCESSING INSTRUCTIONS

================================================================================

3.1 Customer’s Role (Controller)

Customer:

- Determines whether to use the Software and which databases to connect

- Is responsible for legal basis for Processing

- Must obtain necessary consents from Data Subjects

- Must provide privacy notices to Data Subjects

- Must comply with Data Protection Laws

3.2 IBSurgeon’s Role (Processor)

IBSurgeon:

- Processes Personal Data only on Customer’s instructions

- Will not use Personal Data for own purposes (except anonymized aggregated data)

- Implements security measures per Section 4

- Assists with Data Subject rights per Section 6

3.3 Processing Instructions

Customer instructs IBSurgeon to:

- Collect database metadata and query information

- Transmit to LLM Services (OpenAI in USA, DeepSeek in China) for optimization

- Store successful Optimization Data in AWS S3 (USA)

- Return optimization results to Customer

- Delete data per Section 9

3.4 Processing Details

Subject Matter: SQL query optimization using AI/ML

Duration: Subscription Term + 90 days post-termination

Nature: Collection, transmission, analysis, storage, deletion

Purpose: Optimize query performance; improve Software algorithms

Types of Personal Data: Database metadata (if containing identifiers), query patterns (anonymized)

Categories of Data Subjects: Database developers, administrators, end users (indirect)

3.5 Restrictions

IBSurgeon will NOT:

- Sell, rent, or lease Personal Data

- Use Personal Data for marketing or profiling

- Disclose Personal Data except to Sub-Processors or as required by law

- Process outside Customer’s instructions

3.6 Aggregated Data (Not Subject to This DPA)

Once data is fully anonymized (no identifiers, cannot be re-identified),

IBSurgeon may use it as an independent Controller for product development and

research.

================================================================================

4. SECURITY MEASURES

================================================================================

4.1 Encryption

- At Rest: AES-256 encryption (AWS S3 server-side encryption)

- In Transit: TLS 1.2+ for all data transmission

4.2 Anonymization

- SHA-256 hashing of database object names (tables, columns, indexes)

- Literal value stripping from SQL queries

- Irreversible pseudonymization

4.3 Access Controls

- Multi-Factor Authentication (MFA) required for all admin access

- Role-Based Access Control (RBAC) - least privilege principle

- Access logging and quarterly access reviews

- Strong password policies (12+ characters, complexity requirements)

4.4 Network Security

- Firewalls and intrusion detection/prevention

- Network segmentation (production isolated from dev/test)

- Regular vulnerability scanning

4.5 Monitoring and Response

- 24/7 security monitoring and alerting

- Centralized logging (12-month retention)

- Incident response procedures

- Annual penetration testing

4.6 Personnel Security

- Background checks (where legally permitted)

- Confidentiality agreements for all personnel

- Annual security and privacy training

4.7 Backup and Recovery

- Regular backups (weekly full, daily incremental)

- 30-day backup retention

- Encrypted backups

4.8 Planned Certifications

- SOC 2 Type 2: Q4 2026 (in progress)

- ISO 27001: Q2 2027 (planned)

================================================================================

5. SUB-PROCESSORS

================================================================================

5.1 Current Sub-Processors

┌─────────────┬─────────────────────┬──────────┬───────────────────────┐

│Sub-Processor│ Entity │ Location │ Purpose │

├─────────────┼─────────────────────┼──────────┼───────────────────────┤

│ OpenAI │ OpenAI LLC │ USA │ LLM optimization │

├─────────────┼─────────────────────┼──────────┼───────────────────────┤

│ DeepSeek │ Beijing DeepSeek AI │ China │ LLM optimization │

├─────────────┼─────────────────────┼──────────┼───────────────────────┤

│ AWS │ Amazon Web Services │ USA │ Storage/infrastructure│

└─────────────┴─────────────────────┴──────────┴───────────────────────┘

5.2 New Sub-Processors

IBSurgeon will provide 30 days’ advance notice before engaging new

Sub-Processors via:

- Email to registered account

5.3 Objection Rights

Customer may object within 30 days if:

- Sub-Processor is in jurisdiction with inadequate data protection

- Sub-Processor has history of breaches

- Engagement violates Customer’s legal obligations

To object: Email [email protected] with grounds for objection within 30 days

5.4 Resolution

If objection is reasonable and cannot be resolved:

- Customer may terminate without penalty

- Customer receives pro-rated refund

5.5 Sub-Processor Obligations

All Sub-Processors bound by agreements requiring:

- Data protection obligations no less protective than this DPA

- Appropriate security measures

- Confidentiality obligations

- Audit rights

================================================================================

6. DATA SUBJECT RIGHTS

================================================================================

6.1 Assistance Obligation

IBSurgeon will provide reasonable assistance to help Customer respond to Data Subject requests.

6.2 Data Subject Rights

┌────────────────┬─────────────────────────┬──────────────────────────┐

│ Right │ Description │ IBSurgeon Response Time │

├────────────────┼─────────────────────────┼──────────────────────────┤

│ Access │ Obtain copy of Personal │ 15 business days │

│ │ Data │ │

├────────────────┼─────────────────────────┼──────────────────────────┤

│ Rectification │ Correct inaccurate data │ 10 business days │

├────────────────┼─────────────────────────┼──────────────────────────┤

│ Erasure │ Delete Personal Data │ 30 calendar days │

├────────────────┼─────────────────────────┼──────────────────────────┤

│ Restriction │ Suspend Processing │ 5 business days │

├────────────────┼─────────────────────────┼──────────────────────────┤

│ Portability │ Export in JSON format │ 15 business days │

├────────────────┼─────────────────────────┼──────────────────────────┤

│ Object │ Stop Processing │ 5 business days │

└────────────────┴─────────────────────────┴──────────────────────────┘

6.3 Request Process

If Data Subject contacts IBSurgeon directly: IBSurgeon redirects to Customer

If Customer forwards request to IBSurgeon:

- Email: [email protected]

- Subject: “Data Subject Request - [Type]”

- IBSurgeon acknowledges within 2 business days

- IBSurgeon provides assistance per timeframes above

6.4 Fees

- First 2 requests per year: No charge

- Additional requests: Reasonable fees may apply

6.5 Customer Responsibility

Customer is responsible for:

- Receiving and verifying Data Subject requests

- Determining validity

- Responding to Data Subjects within legal deadlines (e.g., 30 days under GDPR)

- Instructing IBSurgeon

================================================================================

7. PERSONAL DATA BREACHES

================================================================================

7.1 Notification Obligation

IBSurgeon will notify Customer within 48 hours of becoming aware of a Personal

Data Breach affecting Customer’s Personal Data.

7.2 Notification Method

- Email to: Security contact + primary account contact

- Phone call if high severity

- Subject: “URGENT: Personal Data Breach Notification - [Incident ID]”

7.3 Notice Contents

- Nature of breach

- Categories and approximate number of Data Subjects affected

- Volume of Personal Data records affected

- Contact point: [email protected]

- Likely consequences

- Measures taken to address breach

7.4 IBSurgeon’s Response

- Containment: Immediate (isolate systems, revoke credentials, block access)

- Investigation: 24-72 hours (determine cause, assess scope, identify affected parties)

- Remediation: Within 7 days (patch vulnerabilities, implement controls)

- Documentation: Maintain detailed records

7.5 Customer’s Obligations

IBSurgeon’s notification does NOT relieve Customer of obligations to:

- Notify Supervisory Authorities (e.g., within 72 hours under GDPR)

- Notify Data Subjects (if high risk)

7.6 Assistance

IBSurgeon will provide reasonable assistance to:

- Assess risk

- Prepare notifications

- Coordinate response

- Respond to regulatory inquiries

7.7 Sub-Processor Breaches

If breach occurs at Sub-Processor, IBSurgeon will notify Customer per above

and coordinate response.

================================================================================

8. INTERNATIONAL DATA TRANSFERS

================================================================================

8.1 Acknowledgment

Customer acknowledges Personal Data will be transferred to:

┌─────────────────┬─────────────────────┬─────────────────────────────┐

│ Destination │ Purpose │ Adequacy Status │

├─────────────────┼─────────────────────┼─────────────────────────────┤

│ United States │ OpenAI (LLM), AWS │ No adequacy decision │

│ │ (storage) │ │

├─────────────────┼─────────────────────┼─────────────────────────────┤

│ China │ DeepSeek (LLM) │ No adequacy decision; high- │

│ │ │ risk jurisdiction │

└─────────────────┴─────────────────────┴─────────────────────────────┘

8.2 Transfer Mechanisms

(a) Standard Contractual Clauses (SCCs): EU-approved SCCs apply (Module Two:

Controller to Processor; Module Three: Processor to Sub-Processor)

(b) Supplemental Measures for China:

\- Enhanced anonymization (SHA-256 hashing)

\- Encryption (TLS 1.3)

\- Contractual prohibitions on DeepSeek sharing data with Chinese

  government

\- Regular audits

8.3 Transfer Impact Assessment (TIA)

WARNING: Customer must conduct TIA before transferring Personal Data to assess:

- Whether destination country laws allow effective implementation of SCCs

- Whether government surveillance undermines protections

- Whether supplemental measures are sufficient

IBSurgeon will provide information to support TIA.

8.4 China Transfer Risks

Customer acknowledges risks:

- China National Intelligence Law (2017): Organizations must “support, assist,

and cooperate with state intelligence work”

- Cybersecurity Law and Data Security Law: Broad government access requirements

- Limited legal recourse for Data Subjects

- No effective judicial remedies against government access

IBSurgeon’s supplemental measures mitigate but CANNOT eliminate these risks.

8.5 Alternatives

If transfer risks unacceptable:

- Professional Tier: US-only (no China)

- Local-Only Tier: On-premises (no external transfers)

- Contact: [email protected]

8.6 Standard Contractual Clauses Details

- Clause 7: Docking clause (Sub-Processors may join)

- Clause 9: General authorization with objection rights

- Clause 11: Data Subjects can claim against IBSurgeon

- Clause 13: Irish Data Protection Commission supervises (for EEA customers)

- Clause 17: Irish law governs (for EEA customers)

- Clause 18: Irish courts have jurisdiction (for EEA customers)

Full SCCs text: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

8.7 UK and Swiss Transfers

- UK: UK Addendum to SCCs applies

- Switzerland: Swiss FDPIC-approved SCCs apply

================================================================================

9. DATA RETENTION AND DELETION

================================================================================

9.1 Retention Periods

┌──────────────────────┬─────────────────────┬─────────────────────────┐

│ Data Category │ Retention Period │ Basis │

├──────────────────────┼─────────────────────┼─────────────────────────┤

│ Active Subscription │ During Term │ Service provision │

├──────────────────────┼─────────────────────┼─────────────────────────┤

│ Post-Termination │ Up to 90 days │ Transition, compliance │

├──────────────────────┼─────────────────────┼─────────────────────────┤

│ Aggregated Data │ Indefinite │ Not Personal Data │

│ (Anonymized) │ │ │

├──────────────────────┼─────────────────────┼─────────────────────────┤

│ Backup Systems │ Max 30 days │ Backup rotation │

├──────────────────────┼─────────────────────┼─────────────────────────┤

│ Legal Hold │ As required by law │ Legal obligation │

└──────────────────────┴─────────────────────┴─────────────────────────┘

9.2 Deletion Upon Request

Customer may request deletion anytime:

- Email: [email protected]

- Subject: “Data Deletion Request - [Customer Name] - [Account ID]”

- IBSurgeon acknowledges within 5 business days

- Deletion within 30 calendar days

- Written certification provided upon request

No charge for up to 5 deletion requests per year.

9.3 Deletion Upon Termination

┌────────────────────────┬──────────────────────────────────────────────┐

│ Timeline │ Action │

├────────────────────────┼──────────────────────────────────────────────┤

│ Day 0 │ Software access terminated │

├────────────────────────┼──────────────────────────────────────────────┤

│ Days 1-30 │ Data remains for transition; Customer may │

│ │ request export │

├────────────────────────┼──────────────────────────────────────────────┤

│ Days 31-90 │ IBSurgeon deletes identifiable Personal Data│

├────────────────────────┼──────────────────────────────────────────────┤

│ Day 91+ │ Only anonymized aggregated data retained │

└────────────────────────┴──────────────────────────────────────────────┘

9.4 Data Export

During 30-day transition: Request export in JSON/CSV format via

[email protected]

9.5 Deletion Method

- Digital: DoD 5220.22-M standard or cryptographic erasure

- Backups: Marking for deletion on next rotation

- Cloud (AWS S3): Object deletion with lifecycle policies

9.6 Exceptions to Deletion

IBSurgeon may retain only if:

- Required by law (e.g., tax records, litigation holds)

- Fully anonymized (no individual identifiers)

- Technically impossible (will anonymize and delete when feasible)

Customer will be notified of any exceptions.

9.7 Certification of Deletion

Upon request, IBSurgeon provides written certificate within 15 business days

including:

- Date of request and completion

- Systems from which deleted

- Sub-Processors instructed to delete

- Any exceptions with legal basis

================================================================================

10. AUDITS

================================================================================

10.1 Audit Rights

Customer may audit IBSurgeon’s Processing once per year (more frequently if

required by Supervisory Authority or after breach).

10.2 Audit Notice

90 days’ advance notice to [email protected] including:

- Proposed scope, dates, duration

- Proposed auditor (if third-party)

- Specific concerns (if any)

10.3 Audit Scope

- Review policies/procedures

- Test security controls

- Review Sub-Processor agreements

- Review incident logs

10.4 Limitations

- Business hours only (9 AM - 5 PM, Monday-Friday)

- Minimally disruptive

- Personnel bound by confidentiality

- Max 2 business days duration

- Third-party auditors must be independent and sign NDA

10.5 Alternative: Audit Reports

IBSurgeon may provide instead of on-site audit:

- SOC 2 Type 2 reports (when available)

- ISO 27001 certifications (when available)

- Penetration test summaries (redacted)

- Compliance questionnaires

10.6 Audit Costs

Included at no charge:

- Providing audit reports/certifications

- Responding to reasonable inquiries

- Up to 4 hours of personnel time per year

Additional costs (Customer pays):

- Customer’s personnel and auditors

- Travel/accommodation

- IBSurgeon time beyond 4 hours

- Extensive testing/analysis

10.7 DPIA Assistance

If Customer must conduct Data Protection Impact Assessment (DPIA), IBSurgeon

will provide reasonable assistance within 15 business days:

- Processing description

- Security information

- Risk assessment support

- Review draft DPIA

10.8 Supervisory Authority Cooperation

IBSurgeon will:

- Cooperate with Supervisory Authorities

- Respond to inquiries within required timeframes

- Notify Customer within 2 business days of any inquiry

10.9 Remediation

If audit reveals non-compliance:

- IBSurgeon acknowledges within 10 business days

- Provides remediation plan within 30 days

- Implements remediation (timeframe based on severity)

- Notifies Customer upon completion

Serious non-compliance: Customer may suspend or terminate.

================================================================================

11. LIABILITY

================================================================================

11.1 General Framework

Liability governed by EULA Section 8, except as modified below.

11.2 GDPR Article 82 Liability

For GDPR Processing:

- Both Controller and Processor may be liable for damages

- Processor liable only if failed to comply with GDPR Article 28 obligations

or acted outside/contrary to instructions

- Data Subjects have right to full compensation

- If both parties liable, liability apportioned based on fault

- Processor exempt if proves not responsible

11.3 Maximum Liability

IBSurgeon’s total liability: Greater of (i) fees paid in 12 months prior, or

(ii) $1,000 USD

Exception (cap does NOT apply):

- GDPR Article 82 damages (if caps prohibited by law)

- Gross negligence or willful misconduct

- Breach of confidentiality

- Indemnification obligations

11.4 Excluded Damages

IBSurgeon not liable for indirect, consequential, or special damages, EXCEPT:

- Where prohibited by Data Protection Laws

- GDPR Article 82 damages (if limitation prohibited)

11.5 Customer Indemnification

Customer indemnifies IBSurgeon for claims from:

- Customer’s violation of Data Protection Laws

- Failure to obtain necessary consents

- Breach of compliance obligations

- Unlawful Processing instructions

- Customer’s acts/omissions

11.6 IBSurgeon Indemnification

IBSurgeon indemnifies Customer for third-party claims where IBSurgeon’s Processing violated Data Protection Laws due to IBSurgeon’s breach

Conditions:

- Customer notifies within 10 days

- IBSurgeon controls defense

- Customer cooperates

- Claim doesn’t arise from Customer’s actions

Exceptions (no indemnification):

- Customer’s unlawful instructions

- Customer’s non-compliance

- Data that shouldn’t have been submitted

- Combination with Customer’s systems

Maximum: Subject to EULA liability caps unless prohibited.

11.7 Regulatory Fines

- Customer responsible for fines due to Customer’s violations

- IBSurgeon responsible for fines due to IBSurgeon’s violations

- If both contributed: Negotiate allocation based on fault (arbitration if no agreement)

================================================================================

12. TERM AND TERMINATION

================================================================================

12.1 Term

This DPA:

- Begins: On execution or first use of Software to Process Personal Data

- Continues: As long as IBSurgeon Processes Personal Data

- Terminates: Upon later of EULA termination or deletion of all Personal Data

12.2 Termination Rights

(a) Automatic: Terminates if EULA terminates

(b) For Cause: Either party may terminate for material breach not cured within

30 days

(c) Regulatory Changes: Either party may terminate on 30 days’ notice if Data

Protection Law changes make DPA unlawful

12.3 Effect of Termination

Upon termination:

- IBSurgeon ceases Processing (except as necessary for deletion/return)

- IBSurgeon deletes or returns all Personal Data (Customer’s choice)

- Customer must instruct within 15 days (if no instruction, IBSurgeon deletes)

- IBSurgeon directs Sub-Processors to delete

- IBSurgeon provides written certification within 30 days

- Data retained only if legally required (isolated, deleted when permitted)

12.4 Survival

Provisions that survive:

- Section 4 (Security) - for retained data

- Section 7 (Breaches) - for breaches discovered after termination

- Section 9 (Retention/Deletion)

- Section 10 (Audits) - for pre-termination Processing

- Section 11 (Liability/Indemnification)

- Section 13 (General Provisions)

================================================================================

13. GENERAL PROVISIONS

================================================================================

13.1 Relationship to EULA

- This DPA is part of EULA

- For data protection matters: DPA prevails

- For other matters: EULA prevails

13.2 Precedence

This DPA supersedes any prior data processing agreements between parties.

13.3 Amendments

IBSurgeon may amend upon 60 days’ notice (90 days for material changes

reducing protections).

Notice via email.

If Customer objects:

- May terminate before effective date without penalty

- Receives pro-rated refund

Continued use after effective date = acceptance

Regulatory amendments: Effective immediately (no objection rights).

13.4 Governing Law

EEA/UK Customers: Irish law and Irish courts

Other Customers: As specified in EULA (Delaware, USA)

Exception: Data Protection Law requirements prevail if conflict.

13.5 Severability

If provision held invalid:

- Modify to minimum extent to make enforceable

- If not possible, sever

- Remainder remains in effect

Special rule: SCCs cannot be modified/severed. If invalid, entire SCCs may be

void; parties implement alternative or terminate.

13.6 Entire Agreement

This DPA + EULA + SCCs + Schedules = entire agreement on Personal Data

Processing.

13.7 No Waiver

Failure to enforce ≠ waiver. Waiver must be in writing and signed.

13.8 Assignment

Customer: Cannot assign without consent (except with EULA assignment)

IBSurgeon: May assign with 30 days’ notice (merger, acquisition, affiliate)

13.9 Notices

To IBSurgeon: support@ib-aid

To Customer: Email registered in account

Effective: Email upon transmission (or next business day)

13.10 Third-Party Beneficiaries

- Data Subjects: Third-party beneficiaries under GDPR Article 82 and SCC

Clause 11

- Sub-Processors: May join SCCs under Clause 7 (docking)

- No other third parties

13.11 Language

English version controls. Any translation for convenience only.

13.12 Counterparts and Electronic Signatures

May execute in counterparts. Electronic signatures valid and binding.

13.13 Interpretation

- Defined terms have meanings in Section 2 or EULA

- Headings for convenience only

- For data protection: DPA prevails; for other matters: EULA prevails

================================================================================

14. EXECUTION

================================================================================

14.1 Execution Methods

(a) Online at www.ibsurgeon.com/dpa

(b) Countersigned PDF to [email protected]

(c) Order Form incorporating DPA by reference

14.2 Effective Date

Earlier of:

- Date of execution

- Date Customer first uses Software to Process Personal Data

14.3 Signatures

FOR CUSTOMER (CONTROLLER):

Customer Legal Name: ___________________________________________________

Signature: _____________________________________________________________

Name: __________________________________________________________________

Title: _________________________________________________________________

Date: __________________________________________________________________

Email: _________________________________________________________________

FOR IBSURGEON SOFTWARE (PROCESSOR):

IBSurgeon Software

Signature: _____________________________________________________________

Name: __________________________________________________________________

Title: Data Protection Officer / Legal Representative

Date: __________________________________________________________________

================================================================================

SCHEDULE 1: PROCESSING DETAILS

================================================================================

A. Parties

Controller: Customer [Address and email from account]

Processor: IBSurgeon Software, support@ib-aid

B. Processing Description

Subject Matter: SQL query optimization using AI/ML

Duration: Subscription Term + 90 days post-termination

Nature: Collection, transmission, analysis, storage, deletion

Purpose: Optimize query performance; improve Software algorithms

Categories of Data Subjects:

- Database developers

- Database administrators

- Application developers

- End users (indirect)

Categories of Personal Data:

- Database metadata (table/column names if containing identifiers before

anonymization)

- Query patterns (SQL text with literals stripped)

- Performance data (anonymized)

- Account information (pseudonymized)

Special Categories: Customer represents Software does NOT process special

categories (health, biometric, genetic, racial/ethnic, political, religious,

trade union, sexual orientation) unless additional safeguards implemented.

Sensitive Data: Customer represents Software does NOT process payment card

data (PCI DSS), PHI (HIPAA), student records (FERPA), or financial account

info (GLBA) unless appropriate agreements executed.

Processing Operations:

- Collection: Gather database metadata, statistics and query info to analyze performance

- Transmission: Send anonymized data to LLM Services for optimization

- Analysis: Process through AI/ML algorithms to identify improvements

- Storage: Store successful results in AWS S3 to improve algorithms

- Deletion: Remove Personal Data after retention period

C. Supervisory Authority (for SCCs)

┌───────────────────────┬─────────────────────────────────────────────────┐

│ Customer Location │ Competent Supervisory Authority │

├───────────────────────┼─────────────────────────────────────────────────┤

│ Ireland │ Irish Data Protection Commission (DPC) │

├───────────────────────┼─────────────────────────────────────────────────┤

│ EEA │ Supervisory Authority of Member State │

├───────────────────────┼─────────────────────────────────────────────────┤

│ UK │ UK Information Commissioner’s Office (ICO) │

├───────────────────────┼─────────────────────────────────────────────────┤

│ Switzerland │ Swiss FDPIC │

├───────────────────────┼─────────────────────────────────────────────────┤

│ Other │ As determined under applicable law │

└───────────────────────┴─────────────────────────────────────────────────┘

================================================================================

SCHEDULE 2: SECURITY MEASURES SUMMARY

================================================================================

Encryption:

- At Rest: AES-256 (AWS S3)

- In Transit: TLS 1.2+

Anonymization:

- SHA-256 hashing of identifiers

- Literal stripping from queries

Access Controls:

- Multi-Factor Authentication (MFA)

- Role-Based Access Control (RBAC)

- Quarterly access reviews

- Strong password policies

Network Security:

- Firewalls and intrusion detection

- Network segmentation

- Regular vulnerability scanning

Monitoring:

- 24/7 security monitoring

- Centralized logging (12-month retention)

- Incident response procedures

- Annual penetration testing

Personnel:

- Background checks

- Confidentiality agreements

- Annual security training

Backup:

- Weekly full, daily incremental

- 30-day retention

Certifications (Planned):

- SOC 2 Type 2: Q4 2026

- ISO 27001: Q2 2027

Full details available upon request or via audit.

================================================================================

SCHEDULE 3: SUB-PROCESSOR LIST

================================================================================

Current Sub-Processors (as of February 1, 2025):

1. OpenAI LLC

Location: United States

Purpose: LLM query optimization services

Data: Anonymized query text, metadata

2. DeepSeek AI (Beijing DeepSeek Artificial Intelligence Fundamental

Technology Research Co., Ltd.)

Location: People’s Republic of China

Purpose: LLM query optimization services

Data: Anonymized query text, metadata

3. Amazon Web Services (AWS)

Location: United States (Oregon region US-West-2)

Purpose: Cloud infrastructure and data storage

Data: All Optimization Data, Personal Data (if any)

Note: AWS may use its own sub-contractors per AWS Sub-Processor list at

https://aws.amazon.com/compliance/sub-processors/

Current list maintained at: www.ibsurgeon.com/subprocessors

Subscribe to change notifications: www.ibsurgeon.com/subprocessors/subscribe

Historical versions available upon request: [email protected]

================================================================================

SCHEDULE 4: STANDARD CONTRACTUAL CLAUSES (SCCs)

================================================================================

EU Standard Contractual Clauses for International Transfers

Pursuant to European Commission Implementing Decision (EU) 2021/914

Modules Applied:

☑ MODULE TWO: Transfer Controller to Processor

Data Exporter: Customer (Controller)

Data Importer: IBSurgeon Software (Processor)

☑ MODULE THREE: Transfer Processor to Processor (for Sub-Processors)

Data Exporter: IBSurgeon Software (Processor)

Data Importer: Sub-Processors

Optional Clauses:

☑ Clause 7 (Docking): Sub-Processors may join by signing Accession Agreement

☑ Clause 9 (Sub-Processors): Option 2 - General authorization with

notification and objection rights (30 days)

☑ Clause 11 (Redress): Data Subjects have third-party beneficiary rights

☑ Clause 17 (Governing Law): Ireland (for EEA customers)

☑ Clause 18 (Jurisdiction): Irish courts (Dublin) for EEA customers

Annexes to SCCs:

- Annex I: Details of Processing (incorporated by reference to Schedule 1)

- Annex II: Technical and Organizational Measures (incorporated by reference

to Schedule 2)

- Annex III: Sub-Processor List (incorporated by reference to Schedule 3)

Full SCC Text:

https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

UK Addendum (for UK GDPR):

UK International Data Transfer Addendum (Version B1.0) applies

https://ico.org.uk/media/for-organisations/documents/4019539/international-

data-transfer-addendum.pdf

Swiss Addendum (for Swiss FADP):

References to “GDPR” include Swiss FADP

References to “EU Member State” include Switzerland

Supervisory authority: Swiss FDPIC

Governing law: Irish law (or Swiss law if parties agree)

By executing this DPA, parties agree to be bound by SCCs as if fully set forth

herein.

================================================================================

END OF DATA PROCESSING ADDENDUM

================================================================================

Document Version: 1.0 (Condensed)

Effective Date: February 1, 2025

Last Updated: February 1, 2025

For Questions or Execution:

IBSurgeon Software

Data Protection Officer

Email: [email protected]

================================================================================