# DATA PROCESSING AGREEMENT

Appendix No. 1 to the Terms of Providing Services by Electronic Means — Tracebrand Platform

Terms of Service: https://app.tracebrand.ai/terms

Version: 1.0

Effective from: 2026-08-16

---

## § 1. Parties and Conclusion of the Data Processing Agreement

1. This Data Processing Agreement is concluded between the Customer, acting as the controller of personal data (hereinafter: the "Controller"), and the Provider, acting as the processor (hereinafter: the "Processor"), upon conclusion of the Framework Agreement.
2. Capitalized terms not defined in this Data Processing Agreement shall have the meaning assigned to them in the Terms of Service.
3. This Data Processing Agreement shall remain in effect for the duration of the Framework Agreement and shall expire upon the fulfillment of the obligations set out in § 9.

## § 2. Subject Matter, Nature and Purpose of Processing

1. The Controller entrusts the Processor with the processing of personal data to the extent and for the purpose necessary to provide the Services specified in the Terms of Service.
2. The nature of the processing includes: storage, organization, review, use for the purpose of performing the Services, transfer to sub-processors listed in Appendix 3, and deletion.
3. The Processor shall process the entrusted data solely for the purpose and to the extent specified in this Data Processing Agreement and on the documented instructions of the Controller. Actions taken by the Controller in the Panel shall also be deemed instructions.
4. The Processor shall not use the entrusted data for its own purposes, including analytical or marketing purposes, or for training artificial intelligence models.
5. If the Processor has doubts as to whether an instruction of the Controller infringes personal data protection law, the Processor shall inform the Controller thereof and shall suspend performance of the instruction until the matter is clarified.

## § 3. Types of Data and Categories of Data Subjects

1. The types of personal data entrusted and the categories of data subjects are specified in Appendix 1.
2. The Controller shall not enter into the Platform special categories of personal data or data relating to criminal convictions and offences. The Platform is not intended for the processing of such data.
3. The Controller shall be responsible for the lawfulness of the entrustment and for having a legal basis for the processing of the data entered into the Platform.

## § 4. Obligations of the Processor

1. The Processor shall process the entrusted data solely on the documented instructions of the Controller.
2. The Processor shall ensure that persons authorized to process the entrusted data have undertaken to maintain their confidentiality or are subject to an appropriate statutory obligation of confidentiality.
3. The Processor shall implement and maintain the technical and organizational measures set out in Appendix 2. The Processor shall review and update these measures at least once a year and whenever there is a material change in risk.
4. The Processor shall engage sub-processors on the terms set out in § 6.
5. The Processor shall assist the Controller in fulfilling its obligation to respond to requests from data subjects by making available the relevant Platform functionality and providing information held exclusively by the Processor. The Processor shall forward to the Controller any request addressed directly to the Processor within 3 Business Days of its receipt and shall not respond to it independently.
6. The Processor shall assist the Controller in fulfilling its obligations regarding the security of processing, notification of personal data breaches, and data protection impact assessments, to the extent of the information available to the Processor.
7. The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and shall allow for audits on the terms set out in § 7.
8. Following the termination of the provision of the Services, the Processor shall proceed with the data in accordance with § 9.

## § 5. Personal Data Breaches

1. The Processor shall notify the Controller of any breach of the entrusted personal data without undue delay, and no later than within 48 hours of becoming aware of the breach.
2. The notification shall include: 1) a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and data records concerned; 2) the contact details of the person responsible on the part of the Processor; 3) a description of the likely consequences of the breach; 4) a description of the measures taken or proposed to address the breach.
3. If it is not possible to provide all of the information within the period referred to in paragraph 1, the Processor shall provide it in phases, as it becomes available.
4. The Processor shall cooperate with the Controller in notifying the breach to the supervisory authority and in communicating the breach to the data subjects.

## § 6. Sub-processors

1. The Controller consents to the Processor's use of the sub-processors listed in Appendix 3.
2. The Processor shall inform the Controller of its intention to engage a new sub-processor or to replace an existing one by sending a message to the e-mail address assigned to the Account and a notice in the Panel, at least 30 days in advance.
3. The Controller shall be entitled to raise a reasoned objection within 14 days of receiving the information referred to in paragraph 2. If no agreement is reached within 30 days of the objection being raised, the Controller shall have the right to terminate the Framework Agreement with effect as of the end of the paid Billing Period, with reimbursement of the fee for the unused portion of that period.
4. The Processor shall impose on sub-processors data protection obligations equivalent to the obligations of the Processor under this Data Processing Agreement.
5. The Processor shall be liable to the Controller for the acts and omissions of sub-processors as for its own acts.

## § 7. Audit

1. Upon the Controller's request, the Processor shall make available information and documentation confirming compliance with the obligations under this Data Processing Agreement, within 30 days of receiving the request.
2. The Controller shall have the right to carry out an audit, including an inspection, no more than once a year, following prior notice of at least 30 days, on Business Days, in a manner that does not disrupt the continuity of the Platform's operation or the confidentiality of other customers' data.
3. The audit shall be carried out at the Controller's expense. The frequency limitation referred to in paragraph 2 shall not apply to an audit carried out following a personal data breach or an audit carried out at the request of a supervisory authority.
4. Persons conducting the audit shall undertake to maintain confidentiality. The Processor shall be entitled to refuse to disclose information constituting the Processor's trade secrets or relating to other customers.

## § 8. Transfer of Data Outside the European Economic Area

1. The Platform's database is stored within the European Economic Area.
2. The Processor transfers data outside the European Economic Area to the extent indicated in Appendix 3, in particular the content of Prompts directed to artificial intelligence model providers.
3. The legal basis for the transfer is the European Commission's adequacy decision with respect to providers participating in the EU-US Data Privacy Framework, and, with respect to the remaining providers, standard contractual clauses.
4. Upon the Controller's request, the Processor shall provide information on the legal basis for the transfer applicable to each sub-processor.

## § 9. Termination of Processing

1. Following the termination of the provision of the Services, the Processor shall, at the Controller's choice notified within 14 days of the termination of the Plan Agreement: 1) return the entrusted data to the Controller in CSV format, or 2) delete the entrusted data.
2. If no choice is notified within the period referred to in paragraph 1, the Processor shall delete the entrusted data.
3. The Processor shall delete the entrusted data within 30 days of the expiry of the Read-Only Period, and shall delete backup copies containing such data within 90 days of the termination of the Plan Agreement. During this period, the Processor shall not use the data for any other purpose.
4. The obligation to delete data shall not apply to data whose further retention is required by law.
5. The Processor shall confirm the deletion of the data by way of a statement sent at the Controller's request, within 14 days of receiving the request.

## § 10. Liability and Final Provisions

1. The Processor's liability under this Data Processing Agreement shall be subject to the limitation set out in § 16 of the Terms of Service. This limitation shall not apply to liability towards data subjects or to administrative liability arising under personal data protection law.
2. This Data Processing Agreement shall be governed by Polish law.
3. Amendments to this Data Processing Agreement shall be made in accordance with the procedure for amending the Terms of Service set out in § 22 of the Terms of Service.
4. In the event of any conflict between this Data Processing Agreement and the Terms of Service, this Data Processing Agreement shall prevail with respect to matters concerning the processing of personal data.

---

## Appendix 1 — Scope of the Entrustment

**Categories of data subjects:**

1. Users designated by the Controller, to whom the Controller has assigned Accounts within its Organization.
2. Individuals whose data the Controller enters into the Platform as part of the Customer Content.

**Types of personal data:**

1. Identification and contact data of Users: name, e-mail address, role within the Organization.
2. Usage data: session identifiers, access timestamps, IP address.
3. Data contained in the Customer Content — solely to the extent entered by the Controller.

**Duration of processing:** for the duration of the Framework Agreement and for the periods specified in § 9.

## Appendix 2 — Technical and Organizational Measures

**Organizational measures:**

1. Named access rights to production data, granted to the extent necessary to perform assigned duties.
2. Confidentiality undertakings from persons with access to the data.
3. Logging of personnel access to customer accounts, including the reason for access.
4. Security incident response procedure.
5. Review and update of the measures at least once a year.

**Technical measures:**

1. Encryption of data in transit.
2. Storage of passwords exclusively in cryptographically hashed form.
3. Access and operation logs retained for at least 90 days.
4. Database backups.
5. Separation of the production environment from test environments.

## Appendix 3 — List of Sub-processors

| Sub-processor | Scope of entrusted data | Purpose | Place of processing |
|---|---|---|---|
| Railway | entire database | hosting | Netherlands (Amsterdam), EEA |
| OpenAI | content of Prompts | model responses | outside the EEA |
| Google | content of Prompts | model responses | outside the EEA |
| Perplexity | content of Prompts | model responses | outside the EEA |
| OpenRouter | content of Prompts | access to additional models | outside the EEA |
| SerpApi | content of Prompts | retrieval of Google AI Overview | outside the EEA |
| Langfuse | content of Prompts and model responses | AI query diagnostics | outside the EEA |
| Resend | e-mail address, message content | transactional messages | outside the EEA |
| Decodo | network traffic during page retrieval | network proxy services | outside the EEA |

The Payment Operator is not a sub-processor of the Processor. The Payment Operator processes billing data as a separate controller for the purpose of payment processing.

---
