Data Processing Agreement

Version Date: 8.17.2026

This Data Processing Addendum ("DPA") governs the Processing of Customer Personal Data by Bind Data LLC ("Bind") on behalf of a customer ("Customer") in connection with services provided by Bind under a written agreement between Bind and Customer (the "Agreement").

This DPA forms part of the Agreement only if:

  1. the Agreement expressly incorporates this DPA by reference;
  2. this DPA is attached to or executed with the Agreement; or
  3. the parties otherwise agree in writing that this DPA applies.

The version of this DPA identified in or attached to the applicable Agreement will govern that Agreement. Publication of a later version on Bind's website does not amend an existing Agreement unless the Agreement expressly provides otherwise or the parties agree to the amendment in writing.

Merely viewing this DPA on Bind's public website does not create a contractual relationship.

This DPA does not govern personal information Bind collects for its own purposes through its public marketing website.

1. Definitions

"Applicable Data Protection Law" means a privacy, data protection, or data security law applicable to Bind's Processing of Customer Personal Data under the Agreement.

"Customer Data" has the meaning assigned in the Agreement and includes data, content, credentials, authorizations, and other information provided or made available by or on behalf of Customer in connection with the Services.

"Customer Personal Data" means Personal Data contained in Customer Data that Bind Processes on behalf of Customer in providing the Services.

"Customer-Controlled Platform" means a third-party software platform, application, or system that Customer separately selects, licenses, contracts for, administers, or otherwise controls, and to or from which the Services transfer data at Customer's direction — except to the extent Bind separately engages the operator of that platform to Process Customer Personal Data on Bind's behalf, in which case that operator is a Subprocessor with respect to that Processing. Customer's having a direct agreement with a platform operator does not by itself prevent that operator from being a Subprocessor.

"European Data Protection Law" means, to the extent applicable to the relevant Processing:

"Personal Data" means information relating to an identified or identifiable individual or information otherwise defined as "personal data," "personal information," or a substantially similar term under Applicable Data Protection Law.

"Process" and "Processing" mean an operation performed on Personal Data, including receiving, accessing, transmitting, transferring, synchronizing, mapping, transforming, organizing, storing, retrieving, using, disclosing, securing, or deleting Personal Data.

"Security Incident" means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data Processed by Bind.

A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, network scans, pings, or unsuccessful attacks.

"Services" means the software integration, middleware, platform, implementation, support, or related services Bind provides to Customer under the Agreement.

"Subprocessor" means a third party engaged by Bind to Process Customer Personal Data on Bind's behalf in connection with the Services.

A Customer-Controlled Platform is not a Subprocessor, and its operator is not a Subprocessor, merely because the Services interoperate with, connect to, or exchange data with that platform.

Terms including "Controller," "Processor," "Business," "Service Provider," "Contractor," "Consumer," "Sell," and "Share" have the meanings assigned under the Applicable Data Protection Law that uses those terms.

2. Roles of the Parties

2.1 Customer as Controller

Where Customer determines the purposes and means of Processing Customer Personal Data, Customer acts as the Controller or Business and Bind acts as the Processor, Service Provider, or Contractor, as applicable.

2.2 Customer as Processor

Where Customer Processes Customer Personal Data on behalf of another Controller or Business, Customer acts as a Processor or Service Provider and Bind acts as Customer's Subprocessor.

2.3 Bind's Independent Processing

This DPA does not apply to Personal Data Bind Processes independently for its own legitimate business purposes, such as:

except where Applicable Data Protection Law requires otherwise.

3. Processing Instructions and Purposes

Bind will Process Customer Personal Data only:

  1. to establish, configure, operate, maintain, monitor, support, troubleshoot, and secure the Services;
  2. to receive, transmit, synchronize, map, transform, validate, or route data between systems designated by Customer;
  3. to authenticate and maintain authorized connections to systems designated by Customer;
  4. to maintain logs and records reasonably necessary to operate, troubleshoot, secure, and support the Services;
  5. according to Customer's configuration and use of the Services;
  6. according to documented instructions contained in the Agreement, an applicable statement of work, or other written instructions from Customer;
  7. as necessary to comply with applicable law; or
  8. as otherwise permitted by Applicable Data Protection Law.

Bind will not Process Customer Personal Data for a materially unrelated purpose except as authorized by Customer or permitted by Applicable Data Protection Law.

If Bind reasonably believes an instruction violates Applicable Data Protection Law, Bind may notify Customer and suspend the affected Processing until the parties resolve the issue, except where applicable law prohibits Bind from doing so.

4. U.S. State Privacy Requirements

To the extent Bind Processes Customer Personal Data as a Processor, Service Provider, or Contractor under an applicable U.S. state privacy law, Bind will:

  1. Process Customer Personal Data only for the limited and specified purposes described in the Agreement and this DPA;
  2. not sell Customer Personal Data;
  3. not share Customer Personal Data for cross-context behavioral advertising;
  4. not retain, use, or disclose Customer Personal Data for purposes outside the direct business relationship between Bind and Customer except as permitted by Applicable Data Protection Law;
  5. not combine Customer Personal Data with Personal Data received from another source or collected through Bind's own independent interaction with an individual except where permitted by Applicable Data Protection Law;
  6. comply with obligations applicable to Bind in its role as a Processor, Service Provider, or Contractor;
  7. provide the level of privacy protection required of Bind by Applicable Data Protection Law;
  8. provide reasonable assistance to Customer with applicable consumer privacy requests;
  9. notify Customer if Bind determines that it can no longer satisfy an applicable statutory obligation concerning Customer Personal Data;
  10. permit Customer to take reasonable and appropriate steps required by Applicable Data Protection Law to verify that Bind Processes Customer Personal Data consistently with Customer's applicable obligations; and
  11. permit Customer, upon notice, to take reasonable and appropriate steps required by Applicable Data Protection Law to stop and remediate unauthorized Processing.

Bind will require each applicable Subprocessor to protect Customer Personal Data through written contractual obligations as required by Applicable Data Protection Law.

5. Customer Responsibilities

Customer is responsible for:

Customer will not instruct Bind to Process Customer Personal Data in violation of Applicable Data Protection Law.

6. Confidentiality and Personnel

Bind will ensure that personnel authorized to Process Customer Personal Data:

7. Security

Bind will implement and maintain commercially reasonable administrative, technical, and organizational measures designed to protect Customer Data within Bind's possession or control against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.

Bind is responsible for the security of systems, environments, configurations, credentials, and transmission practices under Bind's control.

Bind does not guarantee the independent security, availability, or operation of a Customer-Controlled Platform or any other third-party platform outside Bind's control.

Bind may update its security measures as technology, threats, and the Services change, provided that Bind will not materially decrease the overall level of protection applied to Customer Personal Data during the applicable service term.

The categories of security measures maintained by Bind are described in Schedule 2.

8. Security Incidents

Bind will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

To the extent information is reasonably available to Bind, Bind will provide information regarding:

Bind may provide information in phases as additional information becomes available.

For a Security Incident originating with a Subprocessor or a Customer-Controlled Platform, Bind's notice and subsequent information may be based on information provided by that third party or otherwise reasonably available to Bind. Bind will not delay an initial notice solely because complete information is unavailable.

Bind will reasonably cooperate with Customer in mitigating a Security Incident.

Customer is responsible for determining whether a Security Incident requires notice or reporting to an individual, employee, regulator, governmental authority, or other third party and for making such notice or report, except to the extent applicable law expressly requires Bind to provide it directly.

Bind's notice of a Security Incident does not constitute an admission of fault or liability.

9. Subprocessors

Customer provides Bind with general authorization to engage Subprocessors in connection with the Services.

Bind will:

  1. require each Subprocessor to enter into written data-protection obligations appropriate to the Processing and required by Applicable Data Protection Law;
  2. limit each Subprocessor's Processing to the services it performs for Bind; and
  3. maintain a current list of material Subprocessors applicable to Customer's Services, available to Customer on request as described in Schedule 3.

Where Applicable Data Protection Law requires advance notice of a new or replacement Subprocessor, Bind will provide Customer with reasonable advance notice.

Customer may object to the new Subprocessor on reasonable and documented data-protection grounds within fifteen (15) days after receiving such notice.

The parties will work in good faith to address a valid objection. If Bind cannot reasonably accommodate the objection, Bind may provide an alternative where commercially reasonable. If no reasonable alternative is available, the parties may exercise any applicable rights under the Agreement with respect to the affected Services.

Bind does not guarantee the independent availability, performance, or security of any Subprocessor or Customer-Controlled Platform, and Bind is not liable for the independent acts or omissions of the operator of a Customer-Controlled Platform.

Bind remains responsible for Bind's own acts and omissions, including its selection of Subprocessors and its configuration, instructions, credential handling, and transmission practices.

Bind is responsible for the performance of a Subprocessor's data-protection obligations only to the extent required by Applicable Data Protection Law or expressly provided in the Agreement.

All responsibility of Bind under this Section is subject to the limitations and exclusions of liability contained in the Agreement to the fullest extent permitted by applicable law.

10. Data Subject and Consumer Requests

Taking into account the nature of the Processing, Bind will provide reasonable assistance to Customer in responding to legally valid requests by individuals exercising rights under Applicable Data Protection Law.

If Bind receives a request directly from an individual concerning Customer Personal Data, Bind will ordinarily:

  1. refer the individual to Customer or notify Customer of the request; and
  2. not independently respond to the substance of the request except as instructed by Customer or required by applicable law.

Customer is responsible for determining whether and how a request should be fulfilled.

11. Compliance Assistance

Taking into account the nature of the Processing and information available to Bind, Bind will provide reasonable assistance to Customer with obligations applicable to Customer involving:

Bind may charge Customer at Bind's then-current professional-services rates for extraordinary assistance that materially exceeds the ordinary operation of the Services, unless the assistance is required because of Bind's breach of the Agreement or this DPA.

12. Return and Deletion

Customer remains responsible for retrieving any Customer Data it requires before termination of the applicable Services.

Upon termination or expiration of Services involving Customer Personal Data:

Where Applicable Data Protection Law requires Customer to have the choice between return and deletion, Bind will return or delete Customer Personal Data as Customer directs, subject to any retention required by applicable law.

Customer Personal Data retained in backups or because of a legal obligation will remain protected under this DPA and will not be actively Processed except for recovery, security, legal compliance, or other purposes permitted by Applicable Data Protection Law.

13. Audits and Compliance Information

Bind will make information reasonably necessary to demonstrate compliance with this DPA available to Customer.

Where reasonably sufficient, Bind may satisfy a request by providing:

If the information provided is not reasonably sufficient to satisfy an applicable legal requirement, Customer may request an additional audit concerning Bind's relevant Processing activities.

Except to the extent Applicable Data Protection Law or a competent regulatory authority requires otherwise, any audit under this Section is limited to systems, environments, records, and Processing activities under Bind's control. With respect to a Subprocessor or a Customer-Controlled Platform, Bind's obligation is limited to providing compliance information Bind holds or can reasonably obtain from that third party, and this Section does not grant Customer a right to audit any third party.

Unless otherwise required by Applicable Data Protection Law, a regulator, or a material Security Incident affecting Customer Personal Data:

If an audit identifies material noncompliance with this DPA, Bind will take commercially reasonable corrective action.

14. European Data Protection Law

This Section applies only to the extent European Data Protection Law applies to Bind's Processing of Customer Personal Data.

14.1 Processing Requirements

Bind will:

If Bind reasonably believes a Customer instruction infringes applicable European Data Protection Law, Bind will notify Customer unless legally prohibited from doing so.

14.2 Subprocessors

Where the EU GDPR applies, Customer grants Bind general written authorization to use Subprocessors subject to Section 9.

Bind will impose on each applicable Subprocessor data-protection obligations substantially equivalent to the obligations required under Article 28 of the EU GDPR with respect to the Processing delegated to that Subprocessor.

Where and to the extent European Data Protection Law so requires, Bind remains responsible to Customer for the performance of that Subprocessor's data-protection obligations. This paragraph applies only to Processing subject to European Data Protection Law, and any resulting liability remains subject to the limitations and exclusions of liability contained in the Agreement to the fullest extent permitted by applicable law.

14.3 International Transfers

Neither party will knowingly transfer Customer Personal Data subject to European Data Protection Law in violation of applicable international-transfer requirements.

If a transfer from the European Economic Area to Bind requires an approved transfer mechanism, the parties will implement the then-applicable European Commission Standard Contractual Clauses or another valid transfer mechanism.

If a transfer subject to UK data protection law requires an approved transfer mechanism, the parties will implement the then-current International Data Transfer Agreement, International Data Transfer Addendum, or another valid mechanism approved under UK law.

The parties will reasonably cooperate to complete information required for an applicable transfer mechanism, including information contained in the schedules to this DPA.

This DPA does not itself constitute an international data-transfer mechanism. Where an approved transfer mechanism is required, the parties will execute or incorporate the applicable transfer terms before the restricted transfer occurs.

This DPA does not create or constitute a restricted international transfer where one would not otherwise exist.

15. Government Requests

If Bind receives a legally binding demand from a governmental or law-enforcement authority seeking Customer Personal Data, Bind will, to the extent legally permitted:

16. Liability

The liability of each party arising from or relating to this DPA, Customer Personal Data, a Security Incident, or Processing performed under the Agreement is subject to the exclusions and limitations of liability contained in the Agreement.

Any defense costs, attorneys' fees, settlements, judgments, notification or remediation costs, refunds, credits, or other monetary amounts arising under this DPA will be treated in accordance with the Agreement's liability provisions.

This DPA does not create a separate or additional liability cap. If the Agreement does not contain a limitation of liability, then to the maximum extent permitted by applicable law each party's total aggregate liability arising from or relating to this DPA will not exceed the fees paid or payable by Customer under the Agreement in respect of the twelve (12) months preceding the first event giving rise to the claim.

Nothing in this DPA limits liability to the extent a limitation is prohibited by Applicable Data Protection Law.

17. Term

This DPA becomes effective when it is incorporated into or executed as part of the Agreement.

It remains in effect for as long as Bind Processes Customer Personal Data subject to the DPA.

Obligations that by their nature must continue after termination, including confidentiality, security, deletion, and applicable international-transfer obligations, survive for as long as Bind retains the relevant Customer Personal Data.

18. Relationship to the Agreement

Except as modified by this DPA, the Agreement remains unchanged.

If this DPA conflicts with the Agreement concerning the Processing or protection of Customer Personal Data, this DPA controls to the extent of the conflict.

Notwithstanding the foregoing, the Agreement's limitations and exclusions of liability continue to apply as provided in Section 16.

If a mandatory international-transfer mechanism conflicts with this DPA or the Agreement, the mandatory transfer mechanism controls with respect to the Processing within its scope.

19. Governing Law

Except where Applicable Data Protection Law or a mandatory international-transfer mechanism requires otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Agreement.

20. Contact

Questions regarding this DPA or Bind's Processing of Customer Personal Data may be sent to Bind Data LLC at privacy@trybind.com.

Schedule 1 — Details of Processing

Subject Matter

Processing of Customer Personal Data as necessary for Bind to establish, configure, operate, maintain, monitor, support, troubleshoot, and secure the Services described in the Agreement and applicable statement of work.

Duration

For the period during which Bind provides the applicable Services, plus the limited post-termination period during which Bind retains Customer Personal Data in accordance with the Agreement, this DPA, or applicable law.

Nature and Purpose of Processing

Depending on Customer's Services and configuration, Processing may include:

Categories of Data Subjects

Depending on Customer's systems and use of the Services, data subjects may include:

Categories of Personal Data

Depending on Customer's configuration, connected systems, and applicable statement of work, Customer Personal Data may include:

Sensitive Personal Data

Depending on Customer's configuration, Customer Personal Data may include payroll, employment, financial, authentication, or other information treated as sensitive under Applicable Data Protection Law.

Customer will not use the Services to Process categories of sensitive or specially regulated information outside the agreed scope without Bind's prior written agreement where additional safeguards are reasonably required.

Frequency

Continuous, recurring, or periodic, depending on Customer's configuration and use of the Services.

Schedule 2 — Security Measures

Bind will maintain commercially reasonable technical and organizational safeguards appropriate to the nature of the Services, Customer Personal Data, and risks associated with the Processing.

Those safeguards will address, as appropriate:

  1. access controls designed to limit access to authorized personnel;
  2. authentication and credential-management practices;
  3. confidentiality obligations for personnel with access to Customer Personal Data;
  4. safeguards for transmission of Customer Data between systems;
  5. safeguards for Customer Data Processed within systems controlled by Bind;
  6. system, application, and integration logging appropriate to the Services;
  7. monitoring and detection of integration or security events appropriate to the Services;
  8. vulnerability and patch-management practices appropriate to Bind-controlled systems;
  9. backup and recovery practices appropriate to Bind-controlled systems and the Services;
  10. incident-response procedures;
  11. reasonable review of material Subprocessors and service providers; and
  12. periodic review of safeguards as technology, threats, and the Services change.

This Schedule does not represent that every security measure is applicable to every component of the Services.

Specific certifications, encryption implementations, recovery objectives, penetration-testing commitments, or other detailed technical requirements are binding only if expressly stated in the Agreement, a security exhibit, or other written document incorporated into the Agreement.

Schedule 3 — Subprocessors

Bind engages a limited number of Subprocessors to support the Services. Depending on the particular Services purchased and the systems Customer elects to connect, these may include providers in the following categories:

The Subprocessors applicable to a particular Customer's Services depend on that Customer's configuration and connected systems. Not every category above applies to every deployment.

Bind maintains a current list of the material Subprocessors applicable to a Customer's Services and will provide that list to Customer on written request to privacy@trybind.com, subject to the confidentiality obligations in the Agreement.

Bind may add or replace Subprocessors in accordance with Section 9 of this DPA.

A Customer-Controlled Platform, including a platform that Customer separately licenses or contracts for, is not a Bind Subprocessor merely because the Services connect to that platform.