DRAFT — This document is pending legal review.

Data Processing Addendum

Last Updated: February 10, 2026

This Data Processing Addendum ("DPA") supplements the Customer Agreement between RunAI Inc ("RunAI", "Processor") and the Customer ("Controller") and governs the processing of personal data by RunAI on behalf of the Customer.

1. Roles and Scope

1.1 Roles

Party Role Responsibilities
Customer Data Controller Determines the purposes and means of processing personal data
RunAI Data Processor Processes personal data only on documented instructions from the Controller

1.2 Categories of Data Subjects

1.3 Types of Personal Data

1.4 Processing Activities

2. GDPR Compliance

2.1 Processor Obligations

RunAI shall:

2.2 Controller Obligations

The Controller shall:

3. Security Measures

RunAI implements and maintains the following technical and organizational measures:

3.1 Encryption

3.2 Access Controls

3.3 Infrastructure

3.4 Organizational

4. Sub-processors

4.1 Authorization

The Controller provides general written authorization for RunAI to engage sub-processors. RunAI shall:

4.2 Objection

If the Controller objects to a new sub-processor, the parties will work in good faith to find a resolution. If no resolution is reached within 30 days, the Controller may terminate the affected Service by providing written notice.

4.3 Liability

RunAI remains fully liable to the Controller for the performance of its sub-processors' obligations.

5. Data Breach Notification

5.1 Notification Timeline

RunAI shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Controller's data.

5.2 Notification Content

The notification shall include, to the extent available:

5.3 Cooperation

RunAI shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

6. International Transfers

To the extent that processing involves the transfer of personal data outside the European Economic Area, the parties agree to the EU Standard Contractual Clauses (Module Two: Controller to Processor), which are incorporated by reference into this DPA.

7. Audit Rights

Upon reasonable notice (no less than 30 days), and no more than once per year, the Controller may audit RunAI's compliance with this DPA. Audits shall be conducted during normal business hours, at the Controller's expense, and subject to reasonable confidentiality obligations.

RunAI may satisfy audit requests by providing relevant certifications, audit reports (e.g., SOC 2), or other documentation demonstrating compliance.

8. Term and Termination

This DPA remains in effect for the duration of the Customer Agreement. Obligations relating to data deletion, confidentiality, and cooperation with audits survive termination.