Data Processing Addendum

Last Updated: September 24, 2026


This Data Processing Addendum (“Addendum”) forms part of the Subscription Agreement (the “Agreement”) between the undersigned customer which is a party to such Agreement (“Subscriber”), and Siro Technologies Inc. (“Siro”).  Subscriber and Siro are each referred to as a “Party” and collectively as the “Parties”. 

Except as modified below, the terms of the Agreement shall remain in full force and effect. Notwithstanding anything to the contrary in the Agreement, if there is a conflict between this Addendum and the Agreement, this Addendum will control. To the extent Siro processes Protected Health Information on behalf of Subscriber, which is subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), such processing shall be governed exclusively by the terms of the business associate agreement entered into between the Parties. 

1. Definitions. The terms used in this Addendum shall have the meanings set forth in this Addendum or as defined by Applicable Privacy Law, whichever is broader. Capitalized terms not otherwise defined herein or defined by Applicable Privacy Law shall have the meaning given to them in the Agreement.  The following terms have the meanings set forth below:

1.1“Affiliate” means an entity that owns or controls, is owned or controlled by, or is under common control or ownership with either Siro or Subscriber, respectively.  

1.2 “Applicable Privacy Law” shall mean applicable data privacy, data protection, and cybersecurity laws, rules and regulations to which Siro is subject, including, but not limited to, (a) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations (“CCPA”), (b) the EU General Data Protection Regulation 2016/679 including the applicable implementing legislation of each Member State (“EU GDPR”), (c) the UK Data Protection Act 2018 and the UK General Data Protection Regulation as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended (including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (“UK GDPR” and together with the EU GDPR, the “GDPR”), (d) the Swiss Federal Act on Data Protection of 19 June 1992, as amended (“FADP”), (e) any other applicable law with respect to any Personal Data in respect of which the Siro is subject to, and (f) any other data protection law and any guidance or statutory codes of practice issued by any relevant Privacy Authority, in each case, as amended from time to time and any successor legislation to the same.

1.3 “Data Subject” shall mean an identified or identifiable natural person.

1.4 “EEA” means the European Economic Area. 

1.5 “Personal Data” shall mean “personal data,” “personal information,” “personally identifiable information,” or similar term as defined by Applicable Privacy law.

1.6 “Privacy Authority” shall mean any competent supervisory authority, attorney general, or other regulator with responsibility for privacy or data protection matters.

1.7 “Process”, “Processing” or “Processed” shall mean any operation or set of operations, as defined in the Applicable Privacy Law, performed upon Personal Data whether or not by automatic means, including collecting, recording, organizing, storing, adapting or altering, retrieving, consulting, using, disclosing, making available, aligning, combining, blocking, erasing and destroying Personal Data.

1.8 “Security Breach” means a breach of Siro’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Siro’s possession, custody or control. Security Breaches do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems. 

1.9 “Services” shall mean Siro’s provision of the Siro Platform (as defined in the Agreement) and any related services as described in the Agreement or any order form or statement of work.

1.10 “Standard Contractual Clauses” means (a) with respect to restricted transfers (as such term is defined under Applicable Privacy Law) which are subject to the EU GDPR and other Applicable Privacy Laws pursuant to which the same have been adopted, the Controller-to-Processor standard contractual clauses, as set out in the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR, as may be amended or replaced by the European Commission from time to time (the “EU SCCs”), and (b) with respect to restricted transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual of 21 March 2022, as may be amended or replaced by the UK Information Commissioner’s Office from time to time (the “UK SCCs”).

1.11 “Subprocessor” means an entity engaged by Siro to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this Addendum, insofar as such an entity Processes Personal Data on behalf of Siro.

1.12“Trust Center” means the dedicated Siro website that provides customers with comprehensive information, resources and documentation about Siro’s commitment to data privacy, security, and compliance, available at https://trust.siro.ai/. 

2. Processing Requirements.

2.1 Siro shall comply with Applicable Privacy Law in the Processing of Personal Data and only Process Personal Data for the purposes of providing the Services and in accordance with Subscriber’s instructions, and as may subsequently be agreed between the Parties in writing. Siro shall promptly inform Subscriber if (a) in Siro’s opinion, an instruction from Subscriber violates Applicable Privacy Law; or (b) Siro is required by applicable law to otherwise Process Personal Data, unless Siro is prohibited by that law from notifying Subscriber under applicable law. Siro will notify Subscriber after making the relevant determination that it can no longer meet its obligations under Applicable Privacy Law. Subscriber will have the right to take reasonable and appropriate steps to (c) ensure that Siro uses Personal Data in a manner consistent with Subscriber’s obligations under Applicable Privacy Laws; and (d) upon reasonable notice, stop and remediate the unauthorized Processing of Personal Data by Siro. The details of processing are set forth in Section B of Exhibit A. 

2.2 The parties acknowledge that Siro has not and will not receive any monetary or other valuable consideration in exchange for their receipt of the Personal Data, and that any consideration paid by Subscriber to Siro under the Agreement relates only to Siro’s provision of the Services.  Unless permitted by Applicable Privacy Law, Siro shall not (a) sell or share (as such terms are defined under the CCPA) Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing the Services, including retaining, using, or disclosing Personal Data for a commercial purpose other than providing the Services; (c) retain, use, or disclose Personal Data outside of the direct business relationship between the Subscriber and Siro; or (d) combine the Personal Data with any other personal information, except as permitted under Applicable Privacy Law.  

2.3 In accordance with the terms of the Agreement, Siro shall have the right to use Personal Data to create Usage Data and Anonymized Data (as both terms are defined in the Agreement). To the extent Siro receives anonymized and aggregated data from Subscriber or the Services allow for the anonymization and aggregation of Personal Data, Siro represents and warrants that it shall not reidentify, attempt to reidentify, or direct any other party to reidentify any Personal Data that has been anonymized and aggregated.

2.4 Siro shall ensure that persons authorized to access Personal Data commit themselves to confidentiality or are under an appropriate obligation of confidentiality. 

3. Cooperation.

3.1 Data Subject Requests. In the event of a Personal Data request from a Data Subject related to Subscriber is made directly to Siro, Siro shall inform the requestor that Siro is not authorized to directly respond to the request, and recommend the requestor submit the request directly to Subscriber, unless legally compelled to respond under the law applicable to such a request. Subscriber shall bear the responsibility for responding to all such requests. In the event Subscriber requires support from Siro in responding to a request from a Data Subject, it may contact Siro for assistance. To the extent legally permitted, Subscriber shall be responsible for any costs arising from Siro’s assistance.

3.2 Data Protection Impact Assessments. To the extent required by Applicable Privacy Laws, Siro shall, upon receipt of written request by Subscriber, (a) make available to Subscriber such information as is reasonably necessary to demonstrate Subscriber’s compliance with Applicable Privacy Laws to the extent applicable to the Services, and (b) reasonably assist Subscriber in carrying out any privacy impact assessment.

3.3 Privacy Authorities. Siro shall provide to Subscriber such co-operation, assistance and information as Subscriber may reasonably request to enable it to comply with its obligations under Applicable Privacy Law and co-operate and comply with the directions or decisions of a relevant Privacy Authority, in each case (a) solely to the extent applicable to Subscriber’s provision of the Services, and (b) within such reasonable time as would enable Subscriber to meet any time limit imposed by the Privacy Authority.

4. Security of Personal Data.  Siro shall maintain, during the term of the Agreement, appropriate technical and organizational security measures designed to protect Personal Data against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorized disclosure or access, as set forth in the Trust Center. Siro shall ensure the reliability of any employees who Process Personal Data. Subscriber is responsible for secure and appropriate use of the Services, to ensure a level of security appropriate to the risk in respect of the Personal Data.

5. Subscriber Obligations. Subscriber shall (a) comply with all applicable laws, including Applicable Privacy Laws, in respect of its use of the Services; (b) ensure that any instructions provided to Siro are at all times in accordance with Applicable Privacy Laws; (c) collect all Personal Data in accordance with Applicable Privacy Laws and obtain all consents and rights necessary for the Processing of Personal Data; (d) maintain at all times the accuracy, quality, and legality of Personal Data; and (e) provide to Siro the minimum amount of Personal Data necessary for the provision of the Services.

6. Subprocessors.

6.1 As part of the provision of the Services, Siro may engage Subprocessors to Process Personal Data on Subscriber’s behalf. Subscriber hereby grants Siro a general authorization to appoint and use the Subprocessors currently listed on the “List of Subprocessors” which is available in the Trust Center. Siro shall provide Subscriber prior notice of any additional or replacement Subprocessors. After being notified, Subscriber must notify Siro within fourteen (14) business days of any reasonable objection it has to such Subprocessors. In the event Subscriber provides a reasonable objection, Siro will use commercially reasonable efforts to make a change in processing under the Agreement to avoid Processing of Personal Data by such Subprocessor. If Siro is unable to make available such change within a reasonable period of time, Subscriber may terminate the Services provided under the Agreement in respect only to those services which cannot be provided by Siro without the use of the objected-to Subprocessor, by providing written notice to Siro. The Parties agree that Subscriber’s non-response to a notification of any additional or replacement Subprocessors will be taken as the Subscriber’s approval of such additional or replacement Subprocessor. 

6.2 Siro shall remain liable for any Processing of Personal Data by each such Subprocessor as if it had undertaken such Processing itself.

6.3 Siro will contractually impose data protection obligations on its Subprocessors that are no less onerous than those imposed on Siro under this Addendum.

7. Breach Notification.

7.1 Notification to Subscriber.  Unless otherwise prohibited by applicable law, Siro shall notify Subscriber without undue delay after Siro confirms a Security Breach.  Such notification shall include, to the extent such information is available, (a) a detailed description of the Security Breach, (b) the type of data that was the subject of the Security Breach and (c) the identity of each affected person (or, where not possible, the approximate number of Data Subjects and of Personal Data records concerned).  In addition, Siro shall communicate to Subscriber (d) the name and contact details of Siro’s data protection officer or other point of contact where more information can be obtained, (e) a description of the likely consequences of the Security Breach, (f) a description of the measures taken or proposed to be taken by Siro to address the Security Breach, including, where appropriate, measures to mitigate its possible adverse effects.  

7.2 Investigation. Siro shall take prompt action to investigate the Security Breach and shall use industry standard, commercially reasonable efforts to mitigate the effects of any such Security Breach in accordance with its obligations hereunder.    

8. Audit Rights. Subscriber may audit Siro’s compliance with its obligations under this Addendum up to once per year and on such other occasions as may be required by Applicable Data Privacy Laws, including where mandated by Subscriber’s Privacy Authority.  Siro will contribute to such audits by providing Subscriber or Subscriber’s Privacy Authority with the information and assistance that Siro considers appropriate in the circumstances and reasonably necessary to conduct the audit. To request an audit, Subscriber must submit a proposed audit plan to Siro at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof.  The proposed audit plan must describe the proposed scope, duration, and start date of the audit.  Siro will review the proposed audit plan and provide Subscriber with any concerns or questions (for example, any request for information that could compromise Siro security, privacy, employment or other relevant policies).  Siro will work cooperatively with Subscriber to agree on a final audit plan.  Nothing in this Section 8 shall require Siro to breach any duties of confidentiality.  If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Subscriber’s audit request and Siro has confirmed there have been no known material changes in the controls audited since the date of such report, Subscriber agrees to accept such report in lieu of requesting an audit of such controls or measures.  The audit must be conducted during regular business hours, subject to the agreed final audit plan and Siro’s safety, security or other relevant policies, and may not unreasonably interfere with Siro business activities. Any audits are at Subscriber’s sole expense.  Subscriber shall reimburse Siro for any time expended by Siro and any third parties in connection with any audits or inspections under this Section 8 at Siro then-current professional services rates, which shall be made available to Subscriber upon request.  Subscriber will be responsible for any fees charged by any auditor appointed by Subscriber to execute any such audit.  

9. Deletion of Personal Data.  Siro shall return and/or delete Personal Data in accordance with the applicable provisions in the Agreement. If Siro determines that continued retention is required and/or permitted by Applicable Privacy Laws and/or mandatory applicable law, Siro shall ensure the confidentiality of such Personal Data and shall extend the protections of this Addendum to such Personal Data.

10. Transfers Out of the EEA. If Subscriber transfers Personal Data out of the EEA to Siro in a country not deemed by the European Commission to have adequate data protection, such transfer will be governed by the EU SCCs, the terms of which are hereby incorporated into this Addendum.  In furtherance of the foregoing, the Parties agree that:

10.1 Subscriber will act as the data exporter and Siro will act as the data importer under the EU SCCs;

10.2 for purposes of Annex I to the EU SCCs, the categories of data subjects, data, special categories of data (if appropriate), and the Processing operations shall be as set out in Section B to Exhibit A; 

10.3 for purposes of Annex II to the EU SCCs, the technical and organizational measures shall be as set out in the Trust Center;

10.4 The optional docking clause in Clause 7 of the EU SCCs shall be included;

10.5 the audits described in Clause 8.9 of the EU SCCs shall be performed in accordance with Section 8 of this Addendum; 

10.6 Section 6 (Subprocessors) of this Addendum shall constitute the procedures for Siro to request general authorization for Subprocessors under Clause 9(a)(Option 2) of the EU SCCs; 

10.7 the optional language in Section 11(a) of the EU SCCs shall not be included;

10.8 for Clause 13, the following language shall apply: The supervisory authority with responsibility for ensuring compliance by the data exporter with the GDPR shall act as competent supervisory authority; 

10.9 Option 1 of Clause 17 shall apply, and the EU SCCs will be governed by the law of the Member State of the supervisory authority with responsibility for ensuring compliance by the data exporter with the GDPR; and

10.10 For Clause 18, any dispute arising from the EU SCCs shall be resolved by the courts of the Member State of the supervisory authority with responsibility for ensuring compliance by the data exporter with the GDPR.

11. Transfers Out of the UK. If Subscriber transfers Personal Data out of the UK to Siro in a country not deemed by the UK Government to have adequate data protection, such transfer will be governed by the UK SCCs, the terms of which are hereby incorporated into this Addendum. Siro shall provide a copy of the signed version of the UK SCCs to Subscriber upon request.  In furtherance of the foregoing, the Parties agree that Tables 1 through 4 of the UK SCCs shall be satisfied by the following information:

11.1 Table 1: Reference to Table 1 shall be satisfied by the information in Section A of Exhibit A.

11.2 Table 2: For Table 2, the version of the Approved EU SCCs shall be the EU SCCs, Controller to Processor module.

11.3 Table 3: Reference to Table 3 shall be satisfied by the information in Exhibit A and the Trust Center.

11.4 Table 4: For Table 4, the Exporter and Importer shall have the rights outlined in Section 19 of the UK SCCs

12. Transfers Out of Switzerland. For transfers from Switzerland, references in the EU SCCs shall be interpreted to include the following applicable terminology and statutory terms: (a) the Federal Data Protection and Information Commissioner is the competent supervisory authority; (b) Swiss law (or the law of a country that allows and grants rights as a third party beneficiary for contractual claims regarding data transfers pursuant to the FADP shall be the applicable law for contractual claims under Clause 17 of the EU SCCs; (c) Switzerland is to be considered as a Member State within the meaning of the EU SCCs; (d) data subjects with their regular place of residence in Switzerland are allowed to bring a lawsuit in Switzerland against either the data exporter or the data importer in accordance with Clause 18(c) of the EU SCCs; and (e) references to the GDPR are to be understood as references to the FADP

13. Limitation of Liability.  The liability of each Party and each Party’s Affiliates under this Addendum shall be subject to the exclusions and limitations of liability set out in the Agreement and shall not be modified by this Addendum. Any claims brought by a party or its Affiliates under this Addendum, whether in contract, tort or under any other theory of liability, shall be subject to the exclusions and limitations set forth in the Agreement, as permitted by applicable law.

14. Amendments. The Parties acknowledge and agree that, to the extent the Services contemplate the processing of Personal Data that is subject to Applicable Privacy Laws that require additional terms in this Addendum, the Parties shall enter into an amendment to this Addendum that addresses such additional terms.



EXHIBIT A

A. LIST OF PARTIES


Data exporter(s):

Name:


As set forth in the Agreement.

Address:


As set forth in the Agreement.

Contact person’s name, position and contact details:


As set forth in the Agreement.

Activities relevant to the data transferred under these Clauses:


Receipt of the Services under the Agreement. 

Signature and Date:

The signature in the Addendum shall satisfy this signature requirement. 

Role (Controller or Processor):

Controller

Data importer(s):

Name:


Siro Technologies Inc. 

Address:


50 W 23rd St, Suite 500, New York, NY 10010

Contact person’s name, position and contact details:


Paul Sanwald, VP of Engineering at security@siro.ai 

Activities relevant to the data transferred under these Clauses:


Provision of the Services under the Agreement.

Signature and Date:

The signature in the Addendum shall satisfy this signature requirement. 

Role (Controller or Processor):

Processor


B. DESCRIPTION OF PROCESSING

The competent supervisory authority shall be the supervisory authority that has jurisdiction over the data exporter.


Categories of data subjects and personal data processed/transferred


Subscriber and Permitted Users (as defined in the Agreement) determine the identity of the persons which are part of the conversations and content analyzed by the Services, and the type and nature of any Personal Data (if any) exchanged in such conversations or included in such content. Siro has no control over the identity of the Data Subjects whose Personal Data is processed on behalf of Subscriber and over the types of Personal Data Processed. 

Sensitive data processed/transferred


See above

The frequency of processing/transfer


On a continuous basis during the term of the Agreement

Nature of the processing/transfer


As described in the Agreement

Purpose(s) of the processing/transfer

As described in the Agreement

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

Duration of performance of the Services or as otherwise contemplated by the Agreement

C. COMPETENT SUPERVISORY AUTHORITY

The competent supervisory authority shall be the supervisory authority that has jurisdiction over the data exporter.



Ready to grow
faster with Siro?