Data Processing Addendum

Legal Navigation

Participants

Customers

Effective Date: 08/21/2026

BACKGROUND

This Data Processing Addendum (this “DPA”) is incorporated into and forms part of the Master Services Agreement between the Service Provider entity identified in the applicable Order Form (“Service Provider”) and the customer identified in the applicable Order Form (“Customer”) (the “Agreement”). Service Provider entities include Discuss.io Inc., Groupe Voxco Inc., Language Logic LLC, Voxco GmbH, and Voxco SARL, together with their respective Affiliates, as applicable to the Services purchased by Customer. Capitalized terms used but not defined in this DPA have the meanings given in Annex B or, if not defined there, in the Agreement.

This DPA applies where Customer’s use of the Services involves the Processing of Personal Data subject to Data Protection Laws. It is available at the DPA URL identified in Section 5.4 of the Agreement and is incorporated into the Agreement by reference. By accepting the Agreement, the Parties are deemed to have accepted this DPA. This DPA is also available in printable form, and either Party may request that it be executed as a stand-alone document.

Order of precedence. This DPA supplements and amends the Agreement with respect to the Processing of Customer Personal Data. In the event of any conflict between this DPA and the body of the Agreement concerning the Processing of Personal Data, this DPA prevails. On all other matters, including the limitations and exclusions of liability, this DPA is subject to the Agreement. Nothing in this DPA is construed to prevail over a conflicting term of any applicable Standard Contractual Clauses.

Supersession. This DPA supersedes and replaces any prior data processing agreement or data processing terms between the Parties with respect to the Services, including the standalone Discuss and Voxco data processing agreements previously made available at their respective URLs. A signed customer-specific data processing agreement that remains in effect continues to apply on its own terms until it expires or is replaced.

STRUCTURE OF THIS ADDENDUM

For ease of reference, this DPA is structured as follows. The General Terms set out the obligations of the Parties with respect to the Processing of Customer Personal Data. Annex A sets out the subject matter and details of Processing. Annex B contains the definitions used in this DPA. Annex C sets out the technical and organizational security measures. Annex D contains the additional regional provisions, which apply only where Customer Personal Data subject to the relevant laws is Processed.

GENERAL TERMS

1.  PROCESSING OF CUSTOMER PERSONAL DATA

1.1  Roles of the Parties.

With respect to the Processing of Customer Personal Data, Customer is the Controller and Service Provider is the Processor. Service Provider Processes Customer Personal Data on behalf of Customer in accordance with Customer’s documented lawful instructions, including as set out in the Agreement, this DPA, and the applicable Order Form, and as described in Annex A. Service Provider will inform Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws. If Data Protection Laws require other Processing, Service Provider will, to the extent permitted by law, inform Customer of that requirement before Processing.

1.2  Permitted Purposes.

Service Provider Processes Customer Personal Data only as necessary to provide, maintain, support, secure, and improve the Services for Customer, to comply with its legal obligations, and to exercise its rights under the Agreement, consistent with the license in Section 5.2 of the Agreement. Service Provider will not sell or share Customer Personal Data, will not Process it for cross-context behavioral advertising, and will not Process it for any commercial purpose other than providing the Services or as permitted by Data Protection Laws.

1.3  Aggregated and Anonymized Data.

As permitted by Section 5.3 of the Agreement, Service Provider may generate and use anonymized and aggregated data derived from Customer Data. Once data has been anonymized so that it can no longer reasonably be used to identify any individual, Customer, or specific Customer Data, it is no longer Personal Data and falls outside this DPA. Service Provider will not attempt to re-identify such data and will maintain commercially reasonable measures to prevent re-identification.

1.4  Artificial Intelligence Features.

Where Customer enables AI Features under Section 6.3 of the Agreement, Service Provider Processes Customer Personal Data through those features only to the extent Customer enables them, using inference-mode methods such as Retrieval-Augmented Generation. Service Provider will not use Customer Personal Data to train, fine-tune, or otherwise improve any generalized or third-party artificial intelligence or machine learning model. The underlying AI model provider (OpenAI or any replacement or additional AI model provider used to support the Services in the future) and the product analytics provider (Pendo or any replacement or additional product analytics provider used to support the Services in the future) are engaged as Sub-processors under Section 4. Transparency and disclosure obligations under the EU AI Act are addressed in the Country-Specific Terms and the Product-Specific Terms.

1.5  Customer Warranties.

Customer warrants that it has complied and will comply with Data Protection Laws; that its Processing instructions are lawful; that it has the right to transfer Customer Personal Data to Service Provider and the Sub-processors for the permitted purposes; and that it has provided all notices and obtained all consents required for the Processing contemplated by the Agreement. Where Customer’s use of the Services involves the Personal Data of minors, Customer is responsible for obtaining any parental or guardian consent required by Data Protection Laws.

1.6  Special Categories of Personal Data.

Where Customer configures the Services to collect or Process special categories of Personal Data (such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation) or other sensitive data, Service Provider Processes such data only on Customer’s documented instructions and as necessary to provide the Services. Customer is responsible for determining the lawful basis for the Processing and for obtaining any explicit consent required from data subjects. This includes research involving healthcare professionals or health-related topics and any video or audio recordings of participants.

1.7  Health Studies and Adverse-Event Reporting.

Where the Services are used for health-related research, Customer instructs and authorizes Service Provider to disclose to Customer any adverse experience or safety information that a participant reports, in anonymized form and, where the participant volunteers identifying details with the report, together with those details, so that Customer can meet its pharmacovigilance and other legal obligations. Such disclosures are a permitted part of the Services and are not a breach of Service Provider’s confidentiality or instruction obligations under this DPA.

1.8  On-Premise Deployments.

Where an Order Form designates a Service for on-premise deployment, Customer hosts and controls the Customer Personal Data within its own or its hosting provider’s environment. In that case, Service Provider Processes Customer Personal Data only when Customer grants access to install, support, maintain, or troubleshoot the Software, and the security measures in Annex C apply to that access. Customer is responsible for the security of the environment in which it hosts the Software and the Customer Personal Data.

2.  CONFIDENTIALITY OF PROCESSING

Service Provider ensures that personnel authorized to Process Customer Personal Data are subject to a duty of confidentiality (whether contractual or statutory), receive appropriate training in the care and handling of Personal Data, and are granted access to Customer Personal Data only to the extent necessary to provide the Services. Access is role-based, limited to the minimum necessary, and monitored in accordance with Service Provider’s access-control policies, consistent with Section 2.4 of the Agreement.

3.  SECURITY MEASURES

Service Provider implements and maintains the technical and organizational measures set out in Annex C, designed to ensure a level of security appropriate to the risk, including protection against unauthorized or unlawful Processing and accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. Service Provider regularly monitors compliance with these measures and may update them from time to time provided that the updates do not materially reduce the overall level of security.

4.  SUB-PROCESSORS

4.1  General Authorization.

Customer grants Service Provider general written authorization to engage Service Provider Affiliates and third-party Sub-processors to Process Customer Personal Data in connection with the Services. Service Provider’s current Sub-processors are listed online: for the Voxco and Ascribe Services at https://www.voxco.com/data-processing-agreement, and for the Discuss Services at trust.discuss.io. Service Provider’s intra-group Affiliates Process Customer Personal Data under this authorization.

4.2  Notice and Objection.

Service Provider will provide notice by email at least thirty (30) days before engaging a new Sub-processor. If Customer reasonably objects within the thirty (30) day period, the Parties will work in good faith to find a suitable alternative; if no resolution is reached, Customer may terminate the affected portion of the Services.

4.3  Sub-processor Terms and Liability.

Service Provider imposes on each Sub-processor data protection obligations that are, in substance, no less protective than those in this DPA, and ensures that any Restricted Transfer to a Sub-processor is covered by an appropriate transfer mechanism. Service Provider remains fully liable to Customer for the performance of each Sub-processor’s obligations, subject to Section 11 (Liability).

5.  DATA SUBJECT REQUESTS

Taking into account the nature of the Processing, Service Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights under Data Protection Laws, including access, rectification, erasure, restriction, portability, and objection. Where Service Provider receives such a request directly, it will, to the extent legally permitted, notify Customer and direct the data subject to Customer rather than respond itself. Service Provider provides self-service functionality within the Services that enables Customer to address many such requests directly. Customer is responsible for the reasonable costs of assistance under this Section.

Service Provider’s self-service functionality and data subject request workflow are designed to help Customer respond within the timeframes required by Data Protection Laws (for example, within thirty (30) days under several regimes). For enterprise accounts, Service Provider may direct a data subject who contacts it directly to the Customer that administers the account.

6.  SECURITY INCIDENT NOTIFICATION

6.1  Notification.

Service Provider will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Security Incident affecting Customer Personal Data. Service Provider will provide Customer with information reasonably available to it to allow Customer to meet its own obligations to assess and report the Security Incident, which may be provided in phases as it becomes available, including: (a) the nature of the Security Incident, including the categories and approximate number of data subjects and records concerned and any Sub-processors involved; (b) the name and contact details of Service Provider’s relevant contact; (c) the likely consequences of the Security Incident; and (d) the measures taken or proposed to address it.

6.2  Remediation and Cooperation.

Service Provider will make reasonable efforts to identify the cause of the Security Incident and take the steps it deems necessary and reasonable to remediate the cause, to the extent within its reasonable control, and will cooperate with Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the Security Incident.

6.3  Notifications to Authorities and Individuals.

As between the Parties, Customer is responsible for notifying supervisory authorities and affected data subjects of a Security Incident, unless Customer instructs Service Provider to do so or Data Protection Laws require Service Provider to do so. Service Provider will not notify any supervisory authority or data subject on Customer’s behalf without first obtaining Customer’s consent, except where required by Data Protection Laws. Service Provider’s notification under Section 6.1 is not an acknowledgment of fault or liability.

7.  DATA PROTECTION IMPACT ASSESSMENTS

Taking into account the nature of the Processing and the information available to Service Provider, Service Provider will provide Customer with reasonable assistance, at Customer’s cost, with data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Data Protection Laws, to the extent Customer does not otherwise have access to the relevant information.

8.  INTERNATIONAL DATA TRANSFERS

8.1  General.

Customer acknowledges that Service Provider may Process Customer Personal Data on a global basis as necessary to provide the Services, including in the United States, Canada, the European Economic Area, the United Kingdom, and Australia. Where a transfer of Customer Personal Data constitutes a Restricted Transfer, the Parties will ensure that an appropriate transfer mechanism applies as set out in this Section and in Annex D.

8.2  Standard Contractual Clauses.

Where the SCCs apply, they are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where Customer is a Controller and data exporter; Module Three (Processor to Processor) applies where Customer is a Processor acting on behalf of a third-party Controller; and Module Four (Processor to Controller) applies only to the limited return of Customer Personal Data from Service Provider to Customer. For all entities, the SCCs are governed by the law of Ireland, and the courts of Ireland have jurisdiction over disputes arising from the SCCs, except where the relevant Module or Data Protection Laws require otherwise. The information required by the Annexes to the SCCs is set out in Annex A and Annex C. Where a Service Provider entity established in the European Economic Area, including Voxco SARL and Voxco GmbH, transfers Customer Personal Data to a Service Provider entity in the United States (Discuss.io Inc. or Language Logic LLC) or in Canada (Groupe Voxco Inc.), that entity acts as data exporter and the Standard Contractual Clauses incorporated under this Section 8.2, governed by the law of Ireland, apply to the transfer.

8.3  Data Privacy Framework.

Discuss.io Inc. participates in and certifies compliance with the Data Privacy Framework. Where Discuss.io Inc. is the data importer and the Data Privacy Framework applies to a Restricted Transfer, Discuss.io Inc. will provide at least the level of protection required by the Data Privacy Framework Principles and will promptly notify Customer if it can no longer do so, in which case the SCCs apply. Where any Service Provider entity other than Discuss.io Inc. is the data importer, the SCCs (and, for transfers from the United Kingdom, the UK Addendum) apply.

8.4  United Kingdom.

For Restricted Transfers from the United Kingdom, the UK Addendum issued by the UK Information Commissioner applies to and amends the SCCs. The information required by Tables 1 to 4 of the UK Addendum is provided as follows: the parties and their signatures are as set out in the Agreement and the applicable Order Form (Table 1); the version of the EU SCCs is Module Two as set out in Section 8.2, used for both EU and UK transfers (Table 2); the appendix information, including the description of the transfer and the security measures, is set out in Annex A and Annex C (Table 3); and either Party may end the UK Addendum as permitted by the Approved Addendum (Table 4). The UK Addendum is governed by the laws of England and Wales.

8.5  Switzerland.

For Restricted Transfers from Switzerland, the SCCs apply with the following adjustments required by Swiss data protection law: (a) the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority in respect of transfers governed by the Swiss Federal Act on Data Protection (FADP), acting in parallel with any competent EU authority where the transfer is also subject to the EU GDPR; (b) references to the GDPR are read as references to the FADP to the extent the transfer is subject to Swiss law; and (c) the SCCs also protect the data of natural persons in Switzerland. The Parties will, where required, carry out transfer impact assessments and put in place supplementary measures.

9.  RETURN AND DELETION OF CUSTOMER PERSONAL DATA

Customer’s access to the Services and to Customer Personal Data through the Services terminates immediately on expiration or termination of the applicable Order Form, as provided in Section 4.7 of the Agreement. On Customer’s request, and in any event within thirty (30) days after termination, Service Provider will delete or, at Customer’s option, return Customer Personal Data in a standard, commercially reasonable format, except to the extent (a) retention is required by applicable law, (b) Customer Personal Data is held in routine back-up systems that are deleted in the ordinary course in accordance with Service Provider’s retention schedules, or (c) a longer retention period is agreed by the Parties (including any customer-specific retention schedule set out in an Order Form). Where a customer is entitled to a post-termination data-retrieval window under the Country-Specific Terms (including the EU Data Act), the thirty (30) day deletion period begins only after that retrieval window closes. Retained Customer Personal Data remains subject to this DPA.

10.  AUDIT

10.1  Reports in Lieu of Audit.

On Customer’s reasonable request and no more than once per calendar year, Service Provider will make available, under obligations of confidentiality, a summary of its then-current third-party audit reports and certifications (such as SOC 2 Type II or ISO 27001), which may be accessed through Service Provider’s trust center, to demonstrate compliance with this DPA. The Parties intend that such reports and certifications ordinarily satisfy Customer’s audit rights.

10.2  On-Site Audits.

Where the reports under Section 10.1 are insufficient to demonstrate compliance, or where required by Data Protection Laws or by a supervisory authority, or where Customer has reasonable grounds to suspect a material breach of this DPA or a Personal Data Breach has occurred, Customer (or an independent, suitably qualified auditor appointed by Customer and bound by confidentiality, who is not a competitor of Service Provider) may audit Service Provider on at least thirty (30) days’ written notice. Audits take place during business hours, no more than once per calendar year (unless a material breach is suspected), are conducted on a risk-based basis so as to minimize disruption, and do not include access to other customers’ data, Service Provider’s personnel files, trade secrets, or its servers or systems by way of penetration testing or vulnerability scanning. Customer bears the costs of the audit.

11.  LIABILITY

Each Party’s liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to, and counts toward, the limitations and exclusions of liability set out in the Agreement, including Section 10 (Limitation of Liability) and the super-cap in Section 10.2. This DPA does not create any separate or additional liability cap or any independent liability regime. Any reference to the liability of a Party means the aggregate liability of that Party and its Affiliates under the Agreement and this DPA taken together.

12.  GOVERNING LAW

This DPA is governed by, and the Parties submit to the jurisdiction stipulated in, the Agreement (Section 11), except that the SCCs are governed by, and subject to the jurisdiction of, the law and courts identified in Section 8.2. Nothing in this DPA overrides a conflicting term of any applicable SCCs.

13.  CHANGES TO THIS DPA

Notwithstanding the amendment provisions of the Agreement, Service Provider may update this DPA on at least thirty (30) days’ written notice to the extent reasonably required to reflect changes in, or to maintain compliance with, applicable Data Protection Laws, provided that no such update materially reduces the protections for Customer Personal Data. Customer may object to a material change within the notice period, in which case the Parties will work in good faith to address the objection. All other amendments require a written instrument in accordance with the Agreement.

ANNEX A: SUBJECT MATTER AND DETAILS OF PROCESSING

This Annex sets out the particulars required by Article 28(3) of the EU GDPR and equivalent provisions of other Data Protection Laws, and the information required by the Annexes to the SCCs.

Subject matter and duration. Service Provider’s provision of the Services to Customer under the Agreement, for the duration of the Agreement and any period during which Customer Personal Data is retained under Section 9.

Nature and purpose of the Processing. Hosting, collection, storage, analysis, and related Processing of Customer Personal Data as necessary to provide the survey, research, panel, text-analytics, and related Services configured by Customer, including AI Features that Customer enables.

Categories of data subjects. Survey and research respondents, panelists, Customer’s personnel and Authorized Users, and any other individuals whose Personal Data Customer submits to or generates through the Services.

Categories of Customer Personal Data. Contact and profile data; survey, interview, and panel responses; video and audio recordings of participants and their transcripts; usage and device data; and any other Personal Data Customer determines to submit. The data may include special categories of Personal Data (including health-related data and data concerning healthcare professionals) where Customer configures the Services to collect them (see Section 1.6).

Sub-processors. As set out in the online Sub-processor lists referenced in Section 4.1.

Competent supervisory authority. Determined in accordance with the SCCs based on Customer’s place of establishment or its EU representative.

ANNEX B: DEFINITIONS

Capitalized terms not otherwise defined in this DPA have the meanings given in the Agreement. In this DPA, the following terms have the meanings set out below. Terms defined by reference to a statutory cognate take the meaning given under the applicable Data Protection Laws.

“Affiliate” means with respect to any entity, any other entity that directly or indirectly controls, is controlled by, or is under common control with that entity, as further defined in the Agreement.

“Biometric Data” means biometric identifiers (such as a voiceprint, an iris or retina scan, a fingerprint, or a scan of face or hand geometry) and information based on such identifiers that is used to identify an individual, in each case as defined under applicable US biometric privacy laws. Photographs and audio or video recordings are not Biometric Data unless a biometric identifier is extracted from them.

“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.

“Controller” means the Party that alone or jointly with others determines the purposes and means of the Processing of Personal Data, and includes a “business” under the CCPA and any cognate term under Data Protection Laws.

“Customer Personal Data” means any Personal Data that Service Provider or a Sub-processor Processes on behalf of Customer (as Controller) under the Agreement.

“Data Protection Laws” means all applicable laws, rules, and regulations relating to the Processing of Personal Data and privacy, as in effect from time to time, including the EU GDPR, the UK GDPR, Swiss data protection law, the CCPA and other US state privacy laws, Quebec’s Law 25, and other applicable data protection laws.

“Data Privacy Framework” means the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, and the Swiss-US Data Privacy Framework, in each case as administered by the US Department of Commerce.

“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council.

“Personal Data” means any information relating to an identified or identifiable natural person, and includes “personal information” and any cognate term under Data Protection Laws.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

“Processing” means any operation performed on Personal Data, whether or not by automated means, and “Process” and “Processed” are construed accordingly.

“Processor” means a natural or legal person that Processes Personal Data on behalf of the Controller, and includes a “service provider” under the CCPA and any cognate term under Data Protection Laws.

“Restricted Transfer” means a transfer of Customer Personal Data that would be prohibited by Data Protection Laws in the absence of a transfer mechanism such as the SCCs, the UK Addendum, or the Data Privacy Framework.

“SCCs” means the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.

“Security Incident” means (i) any Personal Data Breach affecting Customer Personal Data, or (ii) any other event resulting in the unauthorized or unlawful access to, use, disclosure, loss, alteration, or destruction of Customer Personal Data. A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems.

“Sub-processor” means any Processor engaged by Service Provider or a Service Provider Affiliate to Process Customer Personal Data on behalf of Customer.

“UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, as amended or replaced from time to time.

“UK GDPR” means the EU GDPR as transposed into United Kingdom law by the Data Protection Act 2018.

ANNEX C: TECHNICAL AND ORGANIZATIONAL MEASURES

Service Provider maintains the following technical and organizational measures to protect Customer Personal Data. Where this DPA covers more than one Service Provider entity or platform, the measures below represent the common baseline; current certifications and audit reports for each entity or platform are available through Service Provider’s trust center.

Encryption. Customer Personal Data is encrypted in transit using TLS and at rest using AES-256 or equivalent.

Access control and confidentiality. Role-based access on a least-privilege, need-to-know basis; strong authentication; personnel bound by confidentiality obligations; logical separation of customer data.

Infrastructure security. Use of hosting providers that maintain recognized security certifications; logical separation of customer data; security logging, monitoring, and intrusion detection and prevention to detect and respond to unauthorized access.

Resilience. Redundant storage and back-up processes designed to restore availability and access to Customer Personal Data in a timely manner following an incident.

Testing and assessment. Regular review, testing, and assessment of the effectiveness of the measures, including third-party audits and penetration testing.

Incident response. A documented incident-response plan to address Security Incidents without undue delay.

Personnel training. Security and privacy training on hire and at least annually.

Certifications. Discuss.io Inc. is ISO/IEC 27001 certified. Groupe Voxco Inc., Language Logic, LLC, Voxco GmbH, and Voxco SARL have completed a SOC 2 Type II audit.

ANNEX D: ADDITIONAL REGIONAL PROVISIONS

A.  European Economic Area, United Kingdom, and Switzerland

This Part applies to Customer Personal Data protected by the EU GDPR, the UK GDPR, or Swiss data protection law. When Processing such data on Customer’s instructions, Customer acts as Controller (or as Processor on behalf of a Controller) and Service Provider acts as Processor. Service Provider will notify Customer if it believes Customer’s instructions infringe the applicable law, and will provide the assistance described in Sections 5, 6, and 7. The transfer mechanisms in Section 8 (SCCs governed by Irish law, the Data Privacy Framework for Discuss.io, Inc., and the UK Addendum) apply to Restricted Transfers. European data protection inquiries may be directed to dpo@discuss.io.

B.  California

This Part applies to Personal Data subject to the CCPA. Customer is a “business” and Service Provider is a “service provider.” Service Provider will Process such Personal Data only to perform the Services and for the business purposes specified in the Agreement, or as otherwise permitted by the CCPA, and will not: (a) sell or share it; (b) retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between the Parties; or (c) combine it with Personal Data received from other sources, except as permitted by the CCPA for a service provider. Service Provider certifies that it understands and will comply with these restrictions, and will provide the same level of privacy protection as is required of a business by the CCPA. The disclosure of Personal Data to Service Provider is not a sale. If Service Provider determines it can no longer meet its obligations under the CCPA, it will notify Customer, and Customer may take reasonable steps to stop and remediate unauthorized Processing. Where Customer provides or Service Provider creates deidentified data, Service Provider will not attempt to re-identify it and will maintain it as deidentified. The no-sale and no-share commitments in this Part concern Customer Personal Data that Service Provider Processes as a service provider; they do not address Service Provider’s own website cookies or tags, which are governed by Service Provider’s public privacy notices.

C.  Other US State Privacy Laws

This Part applies to Personal Data subject to the comprehensive privacy laws of other US states, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comparable laws then in effect. With respect to such Personal Data, Service Provider acts as a “processor” (or equivalent) and will: (a) Process it only on Customer’s documented instructions for the purposes set out in the Agreement; (b) ensure persons authorized to Process it are bound by a duty of confidentiality; (c) assist Customer with data subject requests, security, and data protection assessments as required by the applicable law; (d) engage Sub-processors under Section 4 with flow-down obligations; (e) on Customer’s direction, delete or return Personal Data; and (f) make available information reasonably necessary to demonstrate compliance and allow reasonable assessments as required by the applicable law.

D.  Biometric Data (United States)

This Part applies where the Services Process Biometric Data of individuals in the United States, including under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington biometric privacy law, and the biometric and sensitive-data provisions of US state comprehensive privacy laws. Recordings are not Biometric Data unless a biometric identifier, such as a faceprint or voiceprint, is extracted from them; where the Services do not generate biometric identifiers, this Part is precautionary.

Customer responsibilities. As the entity that interacts with participants, Customer is responsible, before any Biometric Data is collected, for providing the notices and obtaining the written consent, release, or opt-in required by applicable law, including the written notice and release required by BIPA and the consent required by CUBI, the Washington law, and applicable sensitive-data provisions.

Service Provider commitments. With respect to Biometric Data it Processes on Customer’s behalf, Service Provider will: (a) Process it only on Customer’s documented instructions and to provide the Services; (b) not sell, lease, trade, or otherwise profit from it; (c) maintain a written retention and destruction schedule and destroy Biometric Data when the purpose for which it was collected has been satisfied or within three (3) years of the individual’s last interaction with the Services, whichever occurs first, or sooner on Customer’s instruction; (d) protect it using a reasonable standard of care; (e) impose materially equivalent obligations on Sub-processors; and (f) provide Customer with reasonable assistance with any data protection assessment required for Biometric Data under applicable law. Where the Services themselves generate biometric identifiers, the Parties will cooperate to determine each Party’s direct obligations under the applicable biometric laws.

E.  Quebec (Law 25)

This Part applies where Customer Personal Data is subject to An Act respecting the protection of personal information in the private sector (Quebec), as amended (“Law 25”). Service Provider acknowledges its obligations as a service provider under Law 25. Where Service Provider becomes aware of a confidentiality incident affecting Customer Personal Data, it will notify Customer in accordance with Section 6, with information sufficient to enable Customer to assess whether the incident presents a risk of serious injury and to make any notifications to the Commission d’acces a l’information du Quebec and affected individuals that Customer, as the enterprise holding the information, is required to make with diligence under Law 25. Service Provider will provide reasonable assistance with cross-border transfer assessments and with requests by individuals to exercise their rights under Law 25. Where Service Provider communicates Customer Personal Data subject to Law 25 to a Sub-processor located outside Quebec, it will ensure the Personal Data benefits from protection that is adequate in light of generally recognized privacy principles, through the transfer mechanisms and Sub-processor obligations set out in this DPA. Service Provider’s person in charge of the protection of personal information, the Data Protection Officer (DPO) is contactable at privacy@discuss.io.

F.  Other Jurisdictions

Where Customer Personal Data is subject to the data protection law of another jurisdiction (including China’s Personal Information Protection Law), Service Provider will comply with the obligations applicable to it as a Processor under that law. Operative jurisdiction-specific provisions will be added where Customer’s use of the Services involves a material volume of Personal Data subject to such a law.