Data Processing Agreement (DPA) – Annex to EBM Master Subscription and Services Agreement
Date: 08/12/2025
Between:
Customer (the “Controller”), and
EBM Software, LLC (the “Processor”), a company based in the United States (US), ISO 27001-certified, and provider of the “Compass”, “Catalyst”, and “Ontario” subscription software platforms and related services.
This Data Processing Agreement (“DPA”) is an addendum to the EBM Master Subscription and Services Agreement (MSSA) between Customer and Processor. It reflects the parties’ obligations under applicable data protection laws – including the EU General Data Protection Regulation (EU GDPR) and the UK GDPR (the EU GDPR as incorporated into UK law via the UK Data Protection Act 2018) – when Processor processes Personal Data on behalf of Customer.
This DPA is effective as of the MSSA effective date and for its duration, and in case of any conflict with the MSSA on data protection matters, this DPA shall prevail. The parties agree that nothing in this DPA relieves either party of its obligations under EU or UK data protection law.
- Scope of Processing
The subject matter and details of processing under this DPA are as follows:
- Subject Matter: Processor will process personal data on behalf of Customer solely for the purpose of providing the subscription software services and related professional services (the “EBM Solutions,” including the Compass, Catalyst, and Ontario platforms and any associated deliverables) under the MSSA. This includes the use of the Compass, Catalyst, and Ontario software platforms and any recurring or related professional services as set out in the parties’ order(s). The processing is integral to delivering the functionalities and services subscribed by Customer.
- Duration: Processor is authorized to process personal data for the duration of the MSSA and any Order(s) in effect (including any renewal terms), until all personal data is deleted or returned in accordance with this DPA.
- Nature & Purpose of Processing: The nature of processing includes the collection, hosting, storage, organization, analysis, and other use of personal data within Processor’s cloud-based software and systems, as needed to provide the EBM Solutions’ functionality and associated deliverables to Customer. The purpose of processing is to enable Customer to utilize the Compass, Catalyst, and Ontario solutions for its internal business operations (such as financial planning, analysis, reporting, data analytics, and related services), as well as to allow Processor’s team to perform any agreed professional services (e.g. data analysis support or fractional finance team support) for Customer. All processing shall be strictly limited to these purposes and performed in accordance with Customer’s documented instructions under the MSSA and this DPA.
- Types of Personal Data: The personal data processed may include identification and contact data (e.g. names, job titles, business contact information of Customer’s employees or contractors), user account credentials (for authorized users of the platforms), business or financial information relating to individuals (e.g. employee payroll or compensation data, customer order or payment details, vendor contact information contained in financial records), and any other personal data that Customer chooses to input into the Compass, Catalyst, or Ontario platform or provide to Processor as part of the services.
- Categories of Data Subjects: The personal data may concern the following categories of data subjects: Customer’s employees, staff, and contractors (whose information may be processed for finance, operations, or analytics purposes); Customer’s own customers (e.g. if customer-related financial transactions or records containing personal identifiers are processed); Customer’s business contacts or vendors (individuals at partner companies or suppliers, if their data is included in financial or payable records); and any other individuals whose data Customer stores in the EBM systems.
- Roles and Compliance with Data Protection Laws
For purposes of EU and UK data protection laws, Customer is the “data controller” (or “Controller”) and retains overall control of the purpose and means of processing of personal data, and Processor is the “data processor” (or “Processor”) that will process personal data on behalf of Customer only on Customer’s documented instructions and for the purposes specified in the MSSA and this DPA. Each party shall fulfill its respective obligations under applicable Data Protection Laws.
Customer is responsible for ensuring that it has a valid legal basis for processing the personal data and for instructing Processor in a lawful manner. Processor, as a service provider, will comply with Article 28 of the GDPR and equivalent provisions of the UK GDPR, and the terms of this DPA are intended to satisfy the requirements of GDPR Article 28(3).
Processor shall inform Customer if, in its opinion, an instruction from Customer infringes the EU or UK GDPR or other applicable data protection provisions. Both parties will cooperate in good faith to modify any instruction or agreement as needed to ensure compliance with the law. In the event that changes in law require additional safeguards or contractual terms, the parties agree to negotiate in good faith to amend this DPA accordingly.
Nothing in this DPA shall be construed to relieve either party of its direct responsibilities or liabilities under GDPR. In particular, Processor understands that it may be directly liable under GDPR for failing to meet its processing obligations or for acting outside of Customer’s lawful instructions.
- Obligations of the Processor (EBM Software)
Processor agrees to the following obligations, in addition to those set forth elsewhere in this DPA and the MSSA:
- Process Only on Instructions: Processor will process personal data only on the documented instructions of Customer (including those provided in the MSSA, this DPA, or in written orders), unless required otherwise by applicable law. In particular, Processor will not process the personal data for any purpose other than to fulfill its responsibilities under the MSSA and this DPA.
- Confidentiality: Processor shall ensure that all persons authorized to process the personal data are bound by appropriate confidentiality obligations (whether by contract or by statutory duty). Processor will restrict access to personal data to only those personnel (including employees and approved subcontractors) who need to access it for the fulfillment of Processor’s obligations. Such personnel will be trained in data protection and security and will be subject to strict duties to keep the data confidential. (The MSSA already imposes mutual confidentiality obligations; personal data is considered Customer’s Confidential Information, and Processor must protect it accordingly.)
- Technical and Organizational Measures: Processor shall implement and maintain appropriate technical and organizational measures (“TOMs”) to ensure a level of security appropriate to the risk of the personal data processing, as required by Article 32 GDPR. These measures are detailed in Section 5 (Data Security) below and in EBM’s Information Security Standard Policy (the “InfoSec Policy”), which is incorporated by reference as a description of Processor’s technical and organizational measures.
- Prohibition on Unauthorized Disclosure: Processor will not disclose or give access to any personal data to any unauthorized third party unless required by law. If a government, law enforcement, or other authority demands access to personal data, Processor shall (to the extent legally permissible) promptly notify Customer and cooperate with Customer’s efforts to intervene or object. Processor will not provide any data to the requesting party unless legally compelled (e.g. by court order or equivalent mandate). If disclosure is compelled, Processor will only release the minimum necessary data and will inform Customer after the fact, if prior notice is prohibited. Processor shall also, where possible, seek protective orders or confidential treatment for any data compelled to be disclosed. All such requests and Processor’s responses will be documented.
- Assistance with Customer Obligations: Taking into account the nature of processing and the information available, Processor shall assist Customer in fulfilling Customer’s obligations under GDPR. This includes providing assistance with: (i) responding to Data Subject Requests (as detailed in Section 7 below) – Processor will help supply, correct, or delete data or otherwise enable Customer to respond to individuals exercising their rights under GDPR; (ii) security and breach notification – Processor will assist Customer by maintaining adequate security measures and notifying Customer of personal data breaches (per Section 8) so that Customer can meet any reporting duties; (iii) Data Protection Impact Assessments (DPIAs) – Processor will provide relevant information about its processing activities and security measures to support Customer in conducting DPIAs and any required prior consultations with supervisory authorities; and (iv) regulatory compliance – Processor will, upon request, provide necessary information about its processing and compliance measures so Customer can ensure both parties meet their obligations.
- Data Accuracy and Minimization: Processor will follow Customer’s instructions regarding data accuracy, retention, and deletion. Processor will notify Customer if it becomes aware that personal data is inaccurate or has been provided in violation of law, and will correct or delete such data as directed by Customer. Processor will not retain personal data longer than instructed by Customer or longer than necessary for the permitted purposes. Processor will adhere to principles of data minimization and only process the personal data that is necessary for the performance of its duties.
- Liability and Indemnity: The allocation of liability for data protection matters is as set out in the MSSA, including any agreed exclusions or limitations of liability. Nothing in this DPA is intended to alter or expand the parties’ liability as established in the MSSA, except to ensure compliance with Data Protection Laws.
- Obligations of the Customer (Controller)
Customer, as Controller, agrees to:
- Lawful Data Provision: Only provide or make available to Processor personal data that has been collected and is provided in compliance with applicable laws. Customer represents that it has obtained all necessary permissions, notices, and (if required) consents from data subjects to lawfully transfer the personal data to Processor and to authorize the processing of the personal data by Processor as described in the MSSA and this DPA. Customer will not direct Processor to process any personal data in a manner that would violate applicable law.
- Instruction Authority: Ensure that its instructions for the processing of personal data are lawful, clear, and documented. Customer is responsible for the accuracy, quality, and legality of the personal data provided to Processor, and for the means by which Customer acquired such data. If Customer requires any change in the processing of personal data, it will communicate this in writing to Processor. Customer is responsible for determining the categories of data and data subjects included in Customer Data, and will not upload personal data outside the agreed scope.
- Assessments and Notifications: Conduct any required data protection impact assessments (DPIAs) and make any required regulatory notifications (e.g. to supervisory authorities or data subjects) with assistance from Processor as needed. Customer shall be responsible for communications with data protection authorities or individuals regarding the processing, except as otherwise agreed or required by law. In the event of a Personal Data Breach (as defined in Section 8 below), Customer is responsible for determining whether to notify supervisory authorities or affected data subjects, unless Processor is expressly required by law to do so (in which case Processor will coordinate with Customer).
- Account and Access Management: Use the Processor’s services in accordance with the MSSA and any applicable user policies. Customer is responsible for managing its user accounts, passwords, and other access credentials for the EBM software platforms. Customer shall maintain the confidentiality of its authentication credentials and promptly notify Processor of any unauthorized access to, or suspected breach of, its accounts or credentials.
- Data Security Measures
Processor shall implement and maintain appropriate technical and organizational security measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or alteration. In assessing the appropriate level of security, Processor shall take into account the risks presented by the processing, in particular those arising from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. EBM’s Information Security Standard Policy (the “InfoSec Policy”) is expressly incorporated into this DPA by reference as a description of the technical and organizational measures in place. The InfoSec Policy (as updated from time to time) outlines EBM’s information security program.
- Use of Sub-processors
Customer authorizes Processor to engage sub-processors (subcontractors) to carry out specific processing activities on behalf of Customer, provided that Processor meets the requirements set forth in GDPR Article 28(2) and 28(4). Processor must ensure any sub-processor is bound by contractual terms that provide at least the same level of protection for personal data as this DPA. Processor remains fully liable to Customer for the performance of any sub-processor that processes personal data under this DPA, and will bear responsibility for any acts or omissions of its sub-processors that cause Processor to breach any of its obligations under this DPA.
Processor shall inform Customer of any intended addition or replacement of sub-processors by providing prior notice (e.g. via email or an online portal) at least thirty (30) days in advance. If Customer objects to a new sub-processor on reasonable grounds relating to data protection, Customer must notify Processor within that notice period. The parties will work together in good faith to find a mutually acceptable solution to address the objection. If no such solution can be reached, Customer may have the right to terminate the affected service(s) under the MSSA (with a pro-rated refund of any prepaid fees for the terminated portion, if applicable) without penalty, to the extent the use of the new sub-processor would materially compromise Customer’s data protection expectations. In all cases, Processor shall notify Customer of the engagement of any new sub-processor and provide an updated list of sub-processors upon request.
- Data Subject Rights and Cooperation
Taking into account the nature of the processing, Processor shall assist Customer by appropriate technical and organizational measures, insofar as possible, in the fulfillment of Customer’s obligation to respond to requests from individuals (data subjects) to exercise their rights under the GDPR/UK GDPR. If Processor receives a request directly from an individual, Processor will promptly inform the Customer and will not respond to the request directly (unless legally compelled to do so) so that Customer can assume responsibility for handling the request.
- Personal Data Breach Notification
In the event of a Personal Data Breach (as defined in the GDPR) involving Customer’s personal data, Processor shall notify Customer without undue delay after becoming aware of the breach. For purposes of this DPA, a “Personal Data Breach” means a confirmed security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed by Processor.
Processor’s notification of a Personal Data Breach will include, to the extent known at the time, the following information:
- Description of the breach: The nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned.
- Impact: The likely consequences of the personal data breach, particularly any risks to data subject rights and freedoms.
- Measures taken: The measures that have been taken or are proposed by Processor to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
- Contact point: Contact information for a Processor representative (such as Processor’s incident response manager or data protection officer) who can provide further information to Customer.
Processor will cooperate with Customer in investigating the breach and in providing information to enable Customer to meet any obligations to notify authorities or data subjects, as required by law.
Processor’s notification of or response to a Personal Data Breach under this Section 8 will not be construed as an acknowledgment by Processor of any fault or liability with respect to the incident.
- Audit and Compliance Rights
Processor shall make available to Customer all information necessary to demonstrate compliance with Processor’s obligations under this DPA and to satisfy the requirements of GDPR Article 28. This includes maintaining up-to-date records of processing activities, documentation describing Processor’s security measures, evidence of data protection compliance, and third-party audit certifications or reports. Upon Customer’s written request, Processor will provide copies of such documentation (subject to reasonable confidentiality measures) to help Customer assess Processor’s compliance with this DPA.
As part of demonstrating compliance, Processor may provide Customer with relevant third-party security certifications or audit reports in lieu of a direct audit. For example, Processor can furnish its ISO 27001 certification, SOC 1 Type II / SOC 2 audit reports, or similar attestations which evaluate and attest to the effectiveness of Processor’s information security controls.
Customer (itself or through an independent auditor mandated by Customer, provided such auditor is not a competitor of Processor and is bound by appropriate confidentiality obligations) is entitled to conduct audits and inspections of Processor’s processing of personal data, in order to verify that Processor is complying with this DPA and applicable data protection law. Any such audit shall be conducted on reasonable advance notice and in a manner that minimizes disruption to Processor’s business and other customers. Processor will provide reasonable cooperation and access to relevant information, personnel, and systems during an audit. Audits will be conducted during normal business hours and under mutually agreed conditions, and will be subject to Processor’s security and operational policies (including policies designed to protect the information of other customers). Customer shall have no right to access any data of other customers or to any information that would violate Processor’s confidentiality obligations to its other clients. Processor may require auditors to execute a standard non-disclosure agreement as a condition of their participation. Customer is responsible for its costs and expenses of any audit.
- International Data Transfers
10.1 EU International Data Transfer Addendum
Customer acknowledges that Processor is based in the United States, a country outside the European Economic Area (EEA) and the UK, and that Processor may access or process personal data in the US. In addition, Processor and its authorized sub-processors may, in the course of providing the services, transfer or access personal data from other countries (e.g. where Processor’s support or infrastructure providers are located). All such transfers shall be made in compliance with applicable data transfer restrictions under EU and UK data protection laws.
For personal data that is subject to the EU GDPR and is transferred from the EEA (or Switzerland) to Processor in a country outside the EEA that the European Commission has not recognized as providing an adequate level of data protection, the parties hereby incorporate the EU Standard Contractual Clauses pursuant to European Commission Decision 2021/914 of 4 June 2021 (the “EU SCCs”) into this DPA. The EU SCCs are incorporated in their entirety as if set forth herein and will apply to such transfers, with the following specifications and clarifications:
- Module and Roles: The EU SCCs Module Two (Controller-to-Processor) shall apply to the extent the Customer is transferring personal data as a controller to Processor acting as a processor. Customer is the data exporter (controller) and EBM Software, LLC is the data importer (processor). (If in a specific situation Customer acts as a processor for certain data and is engaging EBM as a sub-processor, then the Module Three (Processor-to-Sub-processor) SCCs would apply between Customer and Processor. The default assumption, however, is that Customer is a controller and Module Two applies.) If in the future an EBM affiliate or a Customer affiliate needs to join the SCCs (for example, to cover additional parties), the optional Docking Clause (Clause 7) of the SCCs is deemed enabled, allowing additional parties to accede to the SCCs as needed.
- Clause 9 (Use of Sub-processors): For the purposes of Clause 9 of the SCCs, the parties select Option 2 (General Written Authorization). The data exporter (Customer) authorizes Processor’s use of sub-processors as described in Section 6 of this DPA. Processor has provided the data exporter with a list of current sub-processors, and shall notify the exporter of any intended addition of sub-processors by the process set forth in Section 6. The exporter may object to new sub-processors pursuant to the mechanism in Section 6. The time period for objection shall be the thirty (30) days noted in this DPA (unless a different period is agreed in writing for a particular notice).
- Clause 11 (Redress): The optional language in Clause 11 of the SCCs (independent dispute resolution for data subjects) is not included, as data subjects are already entitled to enforce the SCCs as third-party beneficiaries.
- Clause 17 (Governing law): For Clause 17, the parties select Option 1. The SCCs shall be governed by the law of Ireland, being an EU Member State that allows for third-party beneficiary rights. This choice of governing law is made solely for the SCCs (as required by the SCCs themselves).
- Clause 18 (Choice of forum and jurisdiction): The parties choose the courts of Ireland as the forum for disputes arising from the SCCs. In other words, data subjects may bring legal proceedings under the SCCs in the Irish courts.
- Annexes of SCCs: The Annexes of the EU SCCs shall be populated with the relevant information from this DPA, as follows: Annex I.A (List of Parties): The data exporter is Customer (the Controller), and the data importer is EBM Software, LLC (the Processor). Contact details and a description of activities for each party are as set forth in the MSSA (e.g. the exporter is an enterprise customer using EBM’s services, and the importer is a SaaS provider). Annex I.B (Description of Transfer): This corresponds to the categories of data subjects, types of personal data, and purposes of processing and transfer as described in Section 1 of this DPA (Scope of Processing). The frequency of transfer is continuous (on-demand, as Customer uses the services), and the retention period is for the duration of the MSSA, with deletion or return as provided in this DPA. Annex I.C (Competent Supervisory Authority): If Customer is established in an EU Member State, the competent supervisory authority will be the authority of that Member State. If Customer is not established in the EU (for example, if Customer is only established in the UK or elsewhere), then the competent authority shall be determined in accordance with Clause 13 of the SCCs (for instance, it may default to the Irish Data Protection Commission given the choice of Irish law, or to any EU Member State in which an EU representative of Customer is appointed, if applicable). Annex II (Technical and Organizational Measures): This is deemed to be fulfilled by the security measures outlined in Section 5 of this DPA, as well as those described in EBM’s InfoSec Policy, which together correspond to the requirements of Annex II of the SCCs. Annex III (List of Sub-processors): This will include the sub-processors authorized under Section 6 of this DPA.
- Priority: In the event of any conflict or inconsistency between the SCCs and this DPA or any other agreement between the parties, the provisions of the SCCs shall prevail with regard to the protection of EU personal data transferred under the SCCs. Any provisions of the MSSA or this DPA that are more protective of data subjects and do not conflict with the SCCs will continue to apply to such data transfers.
10.2 UK International Data Transfer Addendum
For personal data that is subject to the UK GDPR (i.e. transferred from the UK to Processor in the US or any other third country not deemed “adequate” by the UK), the parties agree to implement the UK Information Commissioner’s Office (ICO) International Data Transfer Addendum (IDTA) to the EU SCCs (issued under s.119A of the UK Data Protection Act 2018, Version B1.0, in force 21 March 2022) as the applicable transfer mechanism. The UK Addendum is hereby incorporated into this DPA and is deemed executed by the parties as of the effective date of this DPA, thereby modifying the above EU SCCs as needed to comply with UK law. In the UK Addendum:
- Tables: The IDTA’s Tables are completed as follows: Table 1 (Parties and Signature): identifies Customer as the Exporter and EBM Software, LLC as the Importer. The parties’ contact details are as provided in the MSSA (e.g. the Customer’s registered address and contact, and EBM’s address and contact). If the Customer has an ICO registration number, it should be specified. The DPA’s effective date is the commencement date of the Addendum. Table 2 (Selected SCCs): indicates that the “Approved EU SCCs” appended to the Addendum are the EU SCCs (Controller-to-Processor, 2021) as detailed above. Table 3 (Appendix Information): refers to the information in Annex I and Annex II of the EU SCCs (which is provided by the corresponding details in this DPA, per the above descriptions in Section 10 and Section 5). Table 4 (Importer’s redress): the parties select the option that neither party may terminate the UK Addendum in accordance with Section 19 of that Addendum (i.e. “neither party” is checked).
- Governing Law (for UK Addendum): For purposes of the UK Addendum and disputes arising from it, the parties select the law of England and Wales to govern the Addendum, and the courts of England and Wales as the forum for disputes. (This choice is distinct from the Irish law chosen for the EU SCCs, recognizing that the UK is outside the EU.) This ensures the Addendum is interpreted under UK law.
- Interpretation: The UK Addendum shall be interpreted to give effect to the incorporated EU SCCs for UK transfers. In particular, references in the EU SCCs to “Member State” or “EU/EEA” shall be read as references to the “UK”, references to the “GDPR” shall refer to the UK GDPR, and “Supervisory Authority” shall refer to the UK Information Commissioner’s Office, etc., as set out in the Addendum’s provisions. In case of any conflict between the EU SCCs and the UK Addendum, the terms of the UK Addendum will prevail for the purposes of UK data transfers.
By implementing the UK Addendum, the EU SCCs (as modified by the Addendum for UK purposes) become the mechanism for lawful transfer of UK personal data to Processor. The combination of the EU SCCs and the UK Addendum thereby constitutes the “UK Standard Contractual Clauses” under UK law for the transfer.
Additional Safeguards: The parties acknowledge that the SCCs (and UK Addendum) impose obligations to ensure that data subjects’ personal data receives an adequate level of protection when transferred internationally. Processor commits to implement additional technical, contractual, and organizational measures as needed to supplement these transfer mechanisms, particularly in light of the Schrems II decision. Such measures include (without limitation): encryption of personal data in transit and (where possible) at rest; strict access controls and logging to limit access to personal data; corporate policies not to disclose personal data to government authorities without a lawful basis; and transparency reporting or notifications to Customer about government requests for data. Processor will, upon request, provide Customer with information about any government access requests it has received and the steps taken to handle them, to the extent legally permitted, so that Customer can assess any risks to data subjects.
- Return and Deletion of Data
Upon termination or expiration of the MSSA (or at such earlier time that processing of personal data is no longer required for the agreed purposes), Processor shall, at Customer’s choice, either return or delete all personal data (including all copies) that it has processed on behalf of Customer. If Customer requests deletion of data (or fails to give any instruction within a reasonable time after termination), Processor will securely and permanently delete all personal data from its systems. In all cases, such deletion will include the shredding or secure erasure of storage media and the overwriting of backup systems, to the extent feasible, such that the personal data cannot be practicably recovered.
Notwithstanding the foregoing, the parties agree that Processor may retain personal data to the limited extent and for the period required by applicable law (for example, to comply with legal record-keeping requirements or law enforcement requests), or as strictly necessary for legitimate business purposes consistent with the GDPR (such as for internal audit or compliance purposes, or fraud detection), but only if such retention is after termination of the services, in a read-only, secure format, with access limited to what is necessary for the purpose. In addition, Processor is permitted to retain personal data in archival backups for up to twelve (12) months following termination of the MSSA, solely for the purpose of enabling restoration of data in the event of a disaster or system failure. Any personal data retained in backups will remain subject to the protections of this DPA, and Processor will not actively process such data except as needed for data restoration or other legally required purposes. Processor will ensure that any retained backup data is securely isolated and protected, and will delete or overwrite it in the normal course of its backup rotation after the retention period elapses.
- General Provisions
This DPA is incorporated into and supplements the MSSA. In the event of any conflict between the terms of this DPA and the terms of the MSSA or any other agreement between the parties, the provisions which provide the most protection to personal data and data subjects shall prevail. However, solely with respect to transfers of personal data from the EEA or UK, the Standard Contractual Clauses (and UK Addendum) described in Section 10 shall prevail over any conflicting term in this DPA or the MSSA. Except as specifically modified by this DPA, the MSSA remains in full force and effect.
Except to the extent that the EU SCCs or UK Addendum mandate a particular governing law for themselves (see Section 10 above), this DPA shall be governed by and construed in accordance with the same law that governs the MSSA between Customer and Processor.
If any provision of this DPA is found to be invalid or unenforceable by a court of competent jurisdiction or supervisory authority, the remainder of this DPA shall remain valid and in force.
In case of changes to Data Protection Laws or the issuance of new regulatory guidance that materially affect the obligations of either party under this DPA, the parties will negotiate in good faith to amend this DPA as necessary to ensure continued compliance.
