Data Processing Addendum (DPA)

Effective starting: August 24, 2025

Introduction

This Data Processing Addendum (“DPA”) forms part of the Suprim Customer Agreement and applies when Suprim processes Customer Data on behalf of Customer.

1. Roles of the Parties

Customer acts as Data Controller. Suprim acts as Data Processor.

2. Processing of Customer Data

Suprim processes data only as instructed by Customer. Processing is limited to providing products and services under the Agreement.

3. Security

Suprim implements reasonable technical and organizational measures to protect Customer Data against unauthorized access, loss, or disclosure.

4. Sub-processors

Suprim may use sub-processors (e.g., hosting providers). A current list can be requested at legal@suprimco.com

5. Data Transfers

Where data is transferred outside the country of origin, Suprim ensures adequate protection through recognized legal mechanisms (such as Standard Contractual Clauses).

6. Assistance

Suprim will reasonably assist Customer with data subject requests and compliance obligations under GDPR, CCPA, or similar laws.

7. Deletion

At termination of services, Suprim will delete or return Customer Data as requested, unless retention is required by law.