DATA PROCESSING ADDENDUM

Version 1.0 — Effective 14 August 2026

This Data Processing Addendum forms part of the agreement between Infercloud, Inc. (doing business as Pipeshift) and the business customer using the Services.

This Data Processing Addendum (“DPA”) forms part of and is incorporated into the agreement betweenInfercloud, Inc., a Delaware corporation (doing business as “Pipeshift”) (“Company”) and the business customer that has entered into, or is otherwise bound by, the applicable terms of service or other written agreement governing the Customer’s use of the Services (the “Agreement”).

To the extent Company processes Personal Data on behalf of Customer in connection with the Services, this DPA sets forth the Parties’ respective rights and obligations regarding such processing. In the event of a conflict between this DPA and the Agreement, this DPA shall control with respect to the Processing of Covered Data.

1. DEFINITIONS

1.1Capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalized terms used in this DPA will be defined as follows:

Administration Data” means (a) contact details relating to, and the content of correspondence with, Customer’s main account holder or administrator; and (b) support enquiries submitted by Customer’s authorized users in relation to the Services.

Affiliate” means: (a) an entity of which a party directly or indirectly owns fifty percent (50%) or more of the stock or other equity interest; (b) an entity that owns at least fifty percent (50%) or more of the stock or other equity interest of a party; or (c) an entity which is under common control with a party by having at least fifty percent (50%) or more of the stock or other equity interest of such entity and a party owned by the same person, but such entity shall only be deemed to be an Affiliate so long as such ownership exists.

Applicable Data Protection Laws” means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, under the European Data Protection Laws, US Data Protection Laws, and Indian Data Protection Laws.

Controller Purposes” means: (a) administering Company’s relationship with Customer under the Agreement, including maintaining and servicing accounts on the Services; (b) monitoring, investigating, preventing and detecting fraud, security incidents and other misuse of the Services; (c) complying with legal or regulatory obligations applicable to the processing and retention of Personal Data to which Company is subject; (d) monitoring the performance and availability of the Services to identify and repair errors; and (e) undertaking internal research for technological development, including testing, improving, developing and altering the functionality of the Services and developing new products and services.For the avoidance of doubt, the Controller Purposes do not include training, fine-tuning, retraining, or otherwise developing or improving any machine learning or artificial intelligence model using Covered Data, Customer Code, or any data or materials derived from either of them in any form (see Section 4.4).

Covered Data” means Personal Data that is: (a) provided by or on behalf of Customer to Company in connection with the Services; or (b) obtained, developed, produced or otherwise Processed by Company, or its agents or Sub-processors, for the purposes of providing the Services, in each case as further described in Schedule 1. For clarity, Covered Data includes Customer prompts, model inputs, embeddings inputs and outputs, and model outputs generated for Customer. Covered Data doesnotinclude Usage Data or Administration Data, which (although they may constitute Personal Data) Company Processes as a controller for the Controller Purposes (see Section 3(b)).

Customer Code” means any proprietary software code, scripts, orchestration or application logic, and other materials and intellectual property that Customer or its authorized users submit to, store on, deploy to, or execute within the Services — together with any environment variables, secrets, or credentials that Customer provides to configure or run such code or containers — including any orchestration or chaining logic that Company hosts or runs on Customer’s behalf to sequence or combine calls across one or more models. For the avoidance of doubt, Customer Code does not include the Company-controlled model deployment configurations or inference settings of the Services. As between the Parties, Customer Code is the Confidential Information and exclusive property of Customer.

Data Subject” means a natural person whose Personal Data is Processed.

Deidentified Data” means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.

European Data Protection Laws” means data protection and privacy laws and regulations of Europe applicable to Company’s provision of the Services under the Agreement, including where applicable (a) the General Data Protection Regulation 2016/679 (“GDPR”); (b) the GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 and the Data Protection Act 2018 (together, “UK GDPR”); and (c) the Swiss Federal Data Protection Act and its implementing regulations (“Swiss Data Protection Act”); in each case, as amended, superseded or replaced from time to time.

Indian Data Protection Laws” means the Digital Personal Data Protection Act, 2023 and the rules issued thereunder, in each case as amended or replaced from time to time, and, to the extent applicable, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, in each case as they apply to Company’s provision of the Services under the Agreement.

Personal Data” means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise “personal data”, “personal information”, “personally identifiable information”, or similarly defined data or information under Applicable Data Protection Laws.

Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. “Process”, “Processes” and “Processed” will be interpreted accordingly.

Prohibited Personal Data” means: (a) Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, criminal convictions and any other special categories of Personal Data identified in Article 9 of the GDPR or Personal Data that is otherwise sensitive Personal Data under Applicable Data Protection Laws; (b) biometric identifiers or templates; (c) financial information (including, without limitation, billing information and cardholder or sensitive authentication data, as those terms are defined under the Payment Card Industry Data Security Standard); (d) personally identifiable financial information, as defined by and subject to the Gramm-Leach-Bliley Financial Modernization Act of 1999; (e) national identification numbers (including, without limitation, Social Security Numbers, Social Insurance Numbers, driver’s license or passport numbers or other governmentally-issued identification numbers); (f) information relating to individuals under the age of 13 (or the applicable age of digital consent); (g) education records, as defined under the Family Educational Rights and Privacy Act of 1974; and (h) protected health information as defined by, and subject to, the Health Insurance Portability and Accountability Act (“HIPAA”).

Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Covered Data.

Services” means the services to be provided by the Company to the Customer under the Agreement, including the hosted (Company-managed) generative AI inference and model deployment platform, comprising dedicated single-tenant deployments, a multi-tenant serverless inference API, and the execution of Customer-provided orchestration or application logic in connection with such inference.

Standard Contractual Clauses” or “SCCs” means the Standard Contractual Clauses annexed to the Commission Implementing Decision (EU) 2021/914.

Sub-processor” means, with respect to any Processing performed by Company as a processor or service provider, an entity appointed by Company to Process Covered Data on its behalf.

Swiss Data Protection Laws” means the Swiss Federal Act on Data Protection of 25 September 2020 (“FADP”) and the Swiss Data Protection Ordinance of 31 August 2022 (the “Ordinance”), and any new or revised version of these laws that may enter into force from time to time.

US Data Protection Laws” means all applicable federal and state laws, rules, regulations, and governmental requirements relating to data protection, the Processing of Personal Data, privacy and/or data security in force from time to time in the United States, including (without limitation): the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”); the Virginia Consumer Data Protection Act; the Colorado Privacy Act; the Connecticut Data Privacy Act; the Utah Consumer Privacy Act; and the Texas Data Privacy and Security Act, in each case as amended from time to time.

Usage Data” means diagnostic, usage and performance information collected by the Company in relation to Customer’s and its authorized users’ use of the Services. For the sake of clarity, the definition of Usage Datadoes notinclude Customer prompts, model inputs, embeddings, or outputs (each of which is considered Covered Data hereunder).

1.2The terms “controller”, “processor”, “business” and “service provider” have the meanings given to them in the Applicable Data Protection Laws. For the purposes of Indian Data Protection Laws, Customer is the “Data Fiduciary”, Company is the “Data Processor”, and a Data Subject is a “Data Principal”.

2. INTERACTION WITH THE AGREEMENT

This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data.

3. ROLE OF THE PARTIES

The Parties acknowledge and agree that:

(a) save as set out in paragraph 3(b), Company acts as a processor or service provider in the performance of its obligations under the Agreement and this DPA, and Customer acts as a controller or business; and

(b) Company acts as a controller with respect to the Processing of Administration Data and Usage Data for the Controller Purposes.

4. DETAILS OF DATA PROCESSING

4.1The details of the Processing of Personal Data under the Agreement and this DPA (including subject matter, nature and purpose of the Processing, categories of Personal Data and Data Subjects) are described in the Agreement and in Schedule 1 to this DPA.

4.2Company shall comply with its obligations under Applicable Data Protection Laws. Save with respect to any Processing of Administration Data and Usage Data for the Controller Purposes, Company will only Process Covered Data on behalf of and under the documented instructions of Customer and in accordance with Applicable Data Protection Laws, unless Company is required to Process Covered Data by applicable law to which Company is subject, in which case Company will inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.

4.3The Agreement and this DPA shall constitute Customer’s instructions for the Processing of Covered Data. Customer may issue further written instructions in accordance with this DPA. Without limiting the foregoing, Company is prohibited from:

(a) selling Covered Data or otherwise making Covered Data available to any third party for monetary or other valuable consideration;

(b) sharing Covered Data with any third party for cross-context behavioural advertising;

(c) retaining, using, or disclosing Covered Data for any purpose other than for the business purposes specified in the Agreement or as otherwise permitted by Applicable Data Protection Laws;

(d) retaining, using, or disclosing Covered Data outside of the direct business relationship between the Parties; and

(e) except as otherwise permitted by Applicable Data Protection Laws, combining Covered Data with Personal Data that Company receives from or on behalf of another person or persons, or collects from its own interaction with the Data Subject.

4.4 No model training on Covered Data or Customer Code.Company willnot, and will not permit any Sub-processor or other third party to, use Covered Data, Customer Code, or any data or materials derived from either of them — whether in identifiable, pseudonymized, deidentified, anonymized, aggregated, or any other form — to train, fine-tune, retrain, evaluate, benchmark, or otherwise develop or improve any machine learning or artificial intelligence model, whether for Company’s own benefit or for the benefit of any third party.This prohibition applies regardless of whether the data or materials have been deidentified, anonymized, pseudonymized, or aggregated: Company does not create, derive, or use Deidentified Data, or any anonymized or aggregated data drawn from Covered Data or Customer Code, for any model training, fine-tuning, retraining, or development purpose.Covered Data and Customer Code are Processed and executed solely to provide and maintain the Services for Customer.

4.5Company will:

(a) provide Customer with reasonable and appropriate information to enable Customer to conduct and document any data protection impact assessments and prior consultations required under Applicable Data Protection Laws;

(b) promptly inform Customer if, in its opinion, an instruction from Customer infringes the Applicable Data Protection Laws; and

(c) limit access to Covered Data to personnel who have a business need to access such Covered Data, and ensure that such personnel are subject to obligations of confidentiality at least as protective of the Covered Data as the terms of this DPA and the Agreement.

4.6 Customer Code and intellectual property.As between the Parties, Customer retains all right, title, and interest in and to Customer Code, including all intellectual property rights therein. Company acquires no right, title, or interest in or to Customer Code, except a limited, non-exclusive, non-transferable right to host, store, execute, and Process Customer Code solely as necessary to provide and maintain the Services for Customer in accordance with the Agreement. Company will treat Customer Code as Customer’s Confidential Information, will not reverse engineer, decompile, or disassemble Customer Code except to the extent expressly authorized by Customer or required by applicable law, and will not access, use, reproduce, modify, or disclose Customer Code for any purpose other than providing the Services. The restrictions in Section 4.3, the prohibition in Section 4.4, the security measures in Section 8 and Schedule 2, and the deletion and return obligations in Section 11 apply to Customer Code to the same extent they apply to Covered Data. This Section 4.6 supplements, and does not limit, any intellectual property or confidentiality provisions of the Agreement.

5. COMPLIANCE

5.1Customer shall comply with its obligations as a controller, business or equivalent term under the Applicable Data Protection Laws, and shall:

(a) provide such information to Data Subjects regarding the Processing of their Covered Data in connection with the Customer’s use of the Services as required under Applicable Data Protection Laws;

(b) provide Data Subjects with any information made available to the Customer by Company in respect of Company’s Processing of Administration Data and Usage Data for the Controller Purposes;

(c) ensure that any Covered Data provided by Customer to Company does not contain any Prohibited Personal Data, unless the Parties have explicitly agreed in writing to the submission of such data prior to its provision to Company;

(d) to the extent required for the lawful Processing of Covered Data under Applicable Data Protection Laws, including Company’s collection and Processing of Usage Data for the Controller Purposes, obtain any required consents or provide any required notices to Data Subjects in accordance with Applicable Data Protection Laws; and

(e) implement appropriate technical and organisational measures to give effect to Data Subject rights under Applicable Data Protection Laws, and comply with requests from Data Subjects to exercise their rights within the timeframe and subject to any exemptions prescribed in the Applicable Data Protection Laws.

6. SUB-PROCESSORS

6.1Company may Process Covered Data anywhere that Company, its Affiliates or its Sub-processors maintain facilities, subject to the remainder of this clause 6 and clause 12 (international transfers).

6.2Customer grants Company general authorisation to engage the Affiliates and/or Sub-processors listed in Schedule 1, as amended in accordance with clause 6.4 (the “Authorised Sub-processors”), to Process Covered Data.

6.3Company shall:

(a) enter into a written agreement with each Authorised Sub-processor imposing data protection obligations that, in substance, are no less protective of Covered Data than Company’s obligations under this DPA; and

(b) remain liable for each Authorised Sub-processor’s compliance with the obligations under this DPA.

6.4Company will provide Customer with at least fourteen (14) days’ prior written notice — by email or, once Company makes one available, via Company’s Trust Center or sub-processor page (to which Customer may subscribe for such notifications) — of any proposed addition or replacement of an Authorised Sub-processor. If Customer wishes to object to a proposed change to the Authorised Sub-processors (including, where applicable, when exercising its right to object under clause 9(a) of the SCCs), Customer must provide Company with written notice of such objection, on reasonable data-protection grounds, within ten (10) days after Company has provided notice of the proposed change (an “Objection”).

6.5In the event Customer submits an Objection to Company, Company and Customer shall work together in good faith to find a mutually acceptable resolution to address such Objection. If the Parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, which shall not exceed thirty (30) days, Customer may terminate the portion of the Agreement relating to the Services that cannot be provided without the objected-to Sub-processor by providing written notice to Company.

6.6Company shall notify the Customer of any material failure by an Authorised Sub-processor to fulfil its data protection obligations of which Company becomes aware.

7. DATA SUBJECT RIGHTS REQUESTS

7.1Company will notify Customer without undue delay of any request received by Company or any Authorised Sub-processor from a Data Subject to assert their rights in relation to Covered Data under Applicable Data Protection Laws (a “Data Subject Request”).

7.2Other than in respect of any Processing of Administration Data and Usage Data for the Controller Purposes, Customer will have sole discretion in responding to the Data Subject Request, and Company shall not respond to the Data Subject Request, save that Company may advise the Data Subject that their request has been forwarded to Customer.

7.3Taking into account the nature of the Processing, Company will provide Customer with reasonable assistance, including by appropriate technical and organisational measures and through self-service functionality in the Services where available, as necessary for Customer to fulfil its obligation under Applicable Data Protection Laws to respond to Data Subject Requests.

8. SECURITY

8.1Company will implement and maintain appropriate technical and organisational data protection and security measures designed to ensure the security of Covered Data, including, without limitation, protection against unauthorised or unlawful Processing and against accidental loss, destruction, or damage of or to Covered Data.

8.2When assessing the appropriate level of security, Company shall take into account the nature, scope, context and purpose of the Processing as well as the risks that are presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Covered Data.

8.3Company will implement and maintain as a minimum standard the measures set out in Schedule 2.

9. INFORMATION AND AUDITS

9.1Company shall notify Customer promptly if Company determines that it can no longer meet its obligations under Applicable Data Protection Laws.

9.2Customer may take reasonable and appropriate steps to: (a) ensure that Company uses Covered Data in a manner consistent with Customer’s obligations under Applicable Data Protection Laws; and (b) upon reasonable notice, stop and remediate unauthorized use of Covered Data.

9.3Company shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. Customer may engage an independent third party auditor, at Customer’s expense, to audit Company’s compliance with this DPA (no more often than once annually, except in the event of a Security Incident or where required by a supervisory authority). The Parties agree that all such audits will be conducted: (a) upon reasonable prior written notice to Company; (b) only during Company’s normal business hours; and (c) in a manner that does not materially disrupt Company’s business or operations.

9.4With respect to any audits conducted in accordance with clause 9.3: (a) Company shall not be required to facilitate any such audit unless and until the Parties have agreed in writing the scope and timing of such audit; and (b) Company shall not be required to give Customer access to information, facilities or systems to the extent doing so would cause Company to be in violation of confidentiality obligations owed to other customers or its legal obligations, or would compromise the security of other customers’ data.

9.5Customer shall promptly notify Company of any non-compliance discovered during an audit. The results of the audit shall be the confidential information of both Parties.

9.6Company shall provide to Customer upon reasonable request such documentation reasonably evidencing the implementation of the technical and organisational data security measures described in Schedule 2 (for example, summaries of penetration test results, security policies, or — where and when available — third-party audit reports or certifications).

10. SECURITY INCIDENTS

10.1Company shall notify Customer in writing without undue delay, and in any event within forty-eight (48) hours after confirmation of any Security Incident.

10.2Company shall take reasonable steps to contain, investigate, and mitigate any Security Incident, and shall send Customer timely information about the Security Incident, to the extent known to Company or as the information becomes available, including, but not limited to, the nature of the Security Incident, the categories and approximate number of Data Subjects and records affected, the measures taken to mitigate or contain the Security Incident, and the status of the investigation.

10.3Company shall provide reasonable assistance with Customer’s investigation of any Security Incident and any of Customer’s obligations in relation to the Security Incident under Applicable Data Protection Laws, including any notification to Data Subjects or supervisory authorities.

10.4Company’s notification of or response to a Security Incident under this paragraph 10 shall not be construed as an acknowledgement by Company of any fault or liability with respect to the Security Incident.

11. TERM, DELETION AND RETURN

11.1This DPA shall commence on the effective date of the Agreement and, notwithstanding any termination of the Agreement, will remain in effect until, and automatically expire upon, Company’s deletion of all Covered Data as described in this DPA.

11.2Company shall:

(a) if requested to do so by Customer within thirty (30) days of expiry or termination of the Agreement (the “Retention Period”), provide a copy of all Covered Data in such commonly used format as requested by Customer, or provide self-service functionality allowing Customer to download such Covered Data; and

(b) on expiry of the Retention Period, delete all copies of Covered Data Processed by Company or any Authorised Sub-processors, other than any Administration Data and Usage Data Processed for the Controller Purposes, and other than copies required to be retained by applicable law (which Company shall continue to protect in accordance with this DPA).

12. STANDARD CONTRACTUAL CLAUSES

12.1The Standard Contractual Clauses shall, as further set out in Schedule 3, apply to the transfer of any Covered Data from Customer to Company, and form part of this DPA, to the extent that:

(a) the European Data Protection Laws apply to Customer when making that transfer; or

(b) the European Data Protection Laws that apply to Customer when making that transfer (the “Exporter Data Protection Laws”) prohibit the transfer of Covered Data to Company under this DPA in the absence of a transfer mechanism implementing adequate safeguards, and any one or more of the following applies: (i) the relevant authority with jurisdiction over Customer’s transfer has not formally adopted standard data protection clauses or another transfer mechanism under the Exporter Data Protection Laws; or (ii) entering into standard contractual clauses approved by the European Commission would reasonably satisfy any requirement under the Exporter Data Protection Laws to implement adequate safeguards in respect of that transfer; or

(c) the transfer is an “onward transfer” (as defined in the applicable module of the SCCs).

12.2The Parties agree that execution or acceptance of the Agreement (whether signed, accepted online, or otherwise agreed) shall have the same effect as signing the SCCs.

12.3 Transfers subject to Indian Data Protection Laws.With respect to any Covered Data transferred by Customer to Company that is subject to Indian Data Protection Laws, the Parties acknowledge that: (a) Customer acts as Data Fiduciary and Company as Data Processor, and the terms of this DPA constitute the valid contract required under the Digital Personal Data Protection Act, 2023 for such Processing; and (b) transfers of such Covered Data outside India are permitted except to any territory restricted by the Central Government of India by notification. Customer remains responsible for complying with any sector-specific data localisation or transfer requirements (for example, those of the Reserve Bank of India) applicable to its Covered Data. No Standard Contractual Clauses are required for such transfers unless and to the extent required by Indian Data Protection Laws.

13. DEIDENTIFIED DATA

If Company creates or receives Deidentified Data from or on behalf of Customer, Company shall: (a) take reasonable measures to ensure the information cannot be associated with a Data Subject; (b) publicly commit to Process the Deidentified Data solely in deidentified form and not to attempt to reidentify the information; and (c) contractually obligate any recipients of the Deidentified Data to comply with the foregoing requirements and Applicable Data Protection Laws. For the avoidance of doubt, and notwithstanding the creation of any Deidentified Data, Company will not use Deidentified Data, or any aggregated or derived data, to train, fine-tune, retrain, or otherwise develop or improve any machine learning or artificial intelligence model, consistent with Section 4.4.

14. GENERAL

14.1The Parties hereby certify that they understand the requirements in this DPA and will comply with them.

14.2The Parties agree that any limitations on either Party’s liability under the Agreement shall apply to any claims, losses or damages arising in respect of a breach of this DPA and the SCCs.

14.3The Parties agree to negotiate in good faith any amendments to this DPA as may be required in connection with changes in Applicable Data Protection Laws.

15. MODIFICATIONS

Company may update this DPA from time to time, including to reflect changes in the Services, its Sub-processors, or Applicable Data Protection Laws. Company will give Customer at least fourteen (14) days’ prior notice of any material change (by email or, once Company makes one available, via Company’s Trust Center or sub-processor page).No update will materially reduce the protections afforded to Covered Data under this DPA.Customer’s continued use of the Services after the effective date of an update constitutes acceptance of the updated DPA. If Customer objects to a material change on reasonable data-protection grounds, the objection and resolution process in clauses 6.4–6.5 applies by analogy, including Customer’s right to terminate the affected Services if the Parties cannot reach a mutually acceptable resolution. Amendments required by Applicable Data Protection Laws are addressed in clause 14.3.

A. List of Parties

B. Description of Processing

Categories of Data Subjects- Customer’s employees, consultants, contractors and/or agents; - Employees, consultants, contractors and/or agents of Customer’s Affiliates; and - Any natural persons whose Personal Data is contained in the prompts and inputs submitted to the Services by Customer’s authorized users (as determined solely by Customer).

Categories of Personal Data- Contact information: name, title, phone number, email address. - Account information: business email address, account credentials, API key identifier (not the secret), and account / organization identifier. -Inputs: information and content inputted into the Services by Customer’s authorized users, including prompts, model inputs, and embeddings inputs. -Outputs: content generated by the models in response to Customer inputs. - Connection and operational metadata (this is Usage Data, which Company Processes as a controller for the Controller Purposes — see Section 3(b)): source IP address, request timestamps, endpoint accessed and HTTP status code, and performance/timing telemetry.

Special categories of Personal Data- N/A unless otherwise agreed in writing by the Parties in accordance with Section 5.1(c). Customer is responsible for not submitting Prohibited Personal Data.

Frequency of the transfer- Continuous.

Nature of the Processing- Receiving data, including collection, accessing, retrieval, recording, and data entry. - Protecting data, including restricting, encrypting, and security testing. - Holding data, including storage, organization, and structuring. - Computing on data, including running model inference and, where enabled, executing Customer’s orchestration or application logic on Customer’s behalf to sequence or combine calls across models. - Erasing data, including destruction and deletion. - Analyzing data, including product usage assessment (Usage Data only). - Sharing data, including disclosure to Authorised Sub-processors as permitted in this DPA.

Purposes of the data transfer and further Processing- The delivery of a hosted generative AI inference and model deployment platform, including: providing Customer’s authorized users with access to the Services; generating outputs (model inference) based on inputs provided by Customer’s users; and resolving queries and support requests submitted by Customer.

Retention period- For the duration of the Agreement and the Retention Period, after which Covered Data is deleted in accordance with Section 11, unless earlier deletion is requested by Customer or required by law.

Sub-processors- As set out in Section C below.

C. Authorised Sub-processors

For clarity, this list includes both Sub-processors that Process Covered Data and other vendors that support the provision of the Services or Process Administration Data on Company’s behalf (for example, billing, communications, and network-access tools); the latter are included for transparency. Company procures GPU compute capacity on certain of the providers listed above through the Shadeform marketplace.

D. Competent Supervisory Authority

The competent supervisory authority is identified in accordance with Clause 13 of the SCCs, by reference to Customer as data exporter:

(a) where Customer is established in an EU Member State, the supervisory authority responsible for ensuring Customer’s compliance with the GDPR in respect of the transfer;

(b) where Customer is not established in an EU Member State but is subject to the GDPR in accordance with Article 3(2) of the GDPR and has appointed a representative pursuant to Article 27(1) of the GDPR, the supervisory authority of the EU Member State in which that representative is established; and

(c) where Customer is not established in an EU Member State, is subject to the GDPR in accordance with Article 3(2) of the GDPR and is not required to appoint such a representative, the supervisory authority of one of the EU Member States in which the Data Subjects whose Covered Data is transferred are located.

Customer will notify Company of the competent supervisory authority so identified.Unless and until Customer does so, the Parties will treat the Irish Data Protection Commission as the competent supervisory authority for the purposes of Part C of Annex I to the SCCs.

This paragraph D applies for the purposes of the SCCs. For transfers subject to UK Data Protection Laws, the competent supervisory authority is the Information Commissioner in accordance with the Approved Addendum (paragraph 2 of Schedule 3). For Processing subject to Swiss Data Protection Laws, the competent supervisory authority is determined in accordance with paragraph 3 of Schedule 3.

1. EU SCCs

With respect to any transfers referred to in clause 12, the Standard Contractual Clauses shall be completed as follows:

1.1Module Two (controller to processor) of the SCCs will apply.

1.2Clause 7 of the SCCs (Docking Clause) does not apply.

1.3Option 2 of Clause 9(a) (General written authorisation) shall apply, and the time period to be specified is determined in clause 6.4 of the DPA.

1.4The option in Clause 11(a) of the SCCs (Independent dispute resolution body) does not apply.

1.5With regard to Clause 17 of the SCCs (Governing law), the Parties agree that Option 1 will apply and the governing law will be the law of Ireland.

1.6In Clause 18 of the SCCs (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of Ireland.

1.7For the purpose of Annex I of the SCCs, Schedule 1 of the DPA contains the specifications regarding the parties, the description of transfer, and the competent supervisory authority.

1.8For the purpose of Annex II of the SCCs, Schedule 2 of the DPA contains the technical and organisational measures.

2. UK Addendum

2.1This paragraph 2 (UK Addendum) shall apply to any transfer of Covered Data from Customer (as data exporter) to Company (as data importer), to the extent that: (a) the UK Data Protection Laws apply to Customer when making that transfer; or (b) the transfer is an “onward transfer” as defined in the Approved Addendum.

2.2As used in this paragraph 2: - “Approved Addendum” means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before the UK Parliament on 2 February 2022, as it may be revised under Section 18 of the Approved Addendum. - “UK Data Protection Laws” means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.

2.3The Approved Addendum will form part of this DPA with respect to any transfers referred to in paragraph 2.1, and execution or acceptance of the Agreement (whether signed, accepted online, or otherwise agreed) shall have the same effect as signing the Approved Addendum.

2.4The Approved Addendum shall be deemed completed as follows: (a) the “Addendum EU SCCs” shall refer to the SCCs as incorporated into this DPA in accordance with clause 12 and this Schedule 3; (b) Table 1 of the Approved Addendum shall be completed with the details in paragraph A of Schedule 1; (c) the “Appendix Information” shall refer to the information set out in Schedule 1 and Schedule 2; (d) for the purposes of Table 4 of the Approved Addendum, Company (as data importer) may end this DPA, to the extent the Approved Addendum applies, in accordance with Section 19 of the Approved Addendum; and (e) Section 16 of the Approved Addendum does not apply.

3. Swiss Addendum

3.1This Swiss Addendum will apply to any Processing of Covered Data that is subject to Swiss Data Protection Laws or to both Swiss Data Protection Laws and the EU GDPR.

3.2Interpretation: where this Addendum uses terms defined in the SCCs, those terms will have the same meaning as in the SCCs. In addition, “FDPIC” means the Swiss Federal Data Protection and Information Commissioner. This Addendum shall be read and interpreted consistently with, and shall not conflict with rights and obligations provided for in, Swiss Data Protection Laws. References to legislation mean that legislation as amended over time.

3.3In relation to any Processing of Personal Data subject to Swiss Data Protection Laws, the SCCs are amended so they operate as standard data protection clauses recognised by the FDPIC for the purposes of Article 16(2)(d) of the FADP, including the following amendments where the transfer is exclusively subject to Swiss Data Protection Laws: - (a) references to the “GDPR” / “Regulation (EU) 2016/679” are replaced by “Swiss Data Protection Laws” and references to specific Articles are replaced with the equivalent provision of Swiss Data Protection Laws; - (b) references to “Regulation (EU) 2018/1725” are removed; - (c) references to the “European Union”, “Union”, “EU” and “EU Member State” are replaced with “Switzerland”; - (d) the “competent supervisory authority” is the FDPIC; Clause 13(a) and Part C of Annex I are not used; - (e) Clause 17 is replaced to state: “These Clauses are governed by the laws of Switzerland”; and - (f) Clause 18 is replaced to state: “Any dispute arising from these Clauses relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland. A Data Subject may also bring legal proceedings against the data exporter and/or data importer before the courts of Switzerland in which he/she has his/her habitual residence. The Parties agree to submit themselves to the jurisdiction of such courts.”

3.4Where the Processing is subject tobothSwiss Data Protection Laws and the GDPR, the FDPIC acts as competent supervisory authority to the extent Swiss Data Protection Laws apply, and the supervisory authority identified in Schedule 1 acts as competent supervisory authority to the extent the GDPR applies; and the terms “European Union”, “Union”, “EU”, and “EU Member State” shall not be interpreted so as to exclude Data Subjects in Switzerland from bringing a claim in their place of habitual residence in accordance with Clause 18(c) of the SCCs.

4. Transfers under the laws of other jurisdictions

4.1With respect to any transfers of Personal Data referred to in clause 12.1(b) (each a “Global Transfer”), the SCCs shall not be interpreted in a way that conflicts with rights and obligations provided for in the Exporter Data Protection Laws.

4.2For the purposes of any Global Transfers, the SCCs shall be deemed amended to the extent necessary so that they operate: (a) for transfers made by the applicable data exporter to the data importer, to the extent the Exporter Data Protection Laws apply to that data exporter’s Processing; and (b) to provide appropriate safeguards for the transfers in accordance with the Exporter Data Protection Laws.

4.3The amendments referred to in paragraph 4.2 include (without limitation): (a) references to the “GDPR” and specific Articles are replaced with the equivalent provisions under the Exporter Data Protection Laws; (b) references to the “Union”, “EU” and “EU Member State” are replaced with the jurisdiction in which the Exporter Data Protection Laws were issued (the “Exporter Jurisdiction”); (c) the “competent supervisory authority” shall be the applicable supervisory authority in the Exporter Jurisdiction; and (d) Clauses 17 and 18 of the SCCs shall refer to the laws and courts of the Exporter Jurisdiction respectively.

4.4Where, at any time during Company’s Processing of Covered Data under this DPA, a transfer mechanism other than the SCCs is approved under the Exporter Data Protection Laws with respect to transfers of Covered Data by Customer to Company, the Parties shall promptly enter into a supplementary agreement that: (a) incorporates any standard data protection clauses or another transfer mechanism formally adopted by the relevant authority in the Exporter Jurisdiction; (b) incorporates the details of Processing set out in Schedule 1; and (c) shall, with respect to the transfer of Personal Data subject to the Exporter Data Protection Laws, take precedence over this DPA in the event of any conflict.

4.5Where required under the Exporter Data Protection Laws, the relevant data exporter shall file a copy of the agreement entered into in accordance with paragraph 4.4 with the relevant national authority.

SCHEDULE TABLES

Customer — Company

Role — Data exporter / controller — Data importer / processor

Contact — As specified in the Agreement or in Customer’s Administration Data associated with its use of the Services. — Pipeshift Privacy / Security Team — [email protected]

Activities relevant to the transfer — The receipt of the Services under the Agreement. — The performance of the Services under the Agreement.

Sub-processor — Purpose — Primary location

Amazon Web Services, Inc. (AWS) — Cloud hosting, compute, and storage — India, EU, and US

Cloudflare, Inc. — CDN, DNS, network security / DDoS protection — Global anycast edge — served from the point of presence nearest the requesting user

Tailscale Inc. — Zero-trust network access (WireGuard VPN) for administrative access to production — connection and identity metadata only; no customer inference data — Canada (control plane)

Stripe, Inc. — Payment processing (billing) — Administration Data only — United States

Google LLC (Google Workspace) — Business email, document storage, and customer support communications — Administration / support data only; no customer inference data — United States

Slack Technologies, LLC — Customer support and internal communications — support / communications data only; no customer inference data — United States

Microsoft Corporation (Microsoft Teams) — Customer support communications (for customers not on Slack) — support data only; no customer inference data — United States

Linear Orbit, Inc. (Linear) — Issue and project tracking — internal engineering / support data only; no customer inference data — United States

Plus Five Five, Inc. (Resend) — Transactional email delivery (account invitations, magic-link sign-in) — recipient email addresses / Administration Data; no customer inference data — United States

PostHog, Inc. — Product analytics — usage / behavioural telemetry tied to user identifiers (Administration / Usage Data); no customer inference data — United States

ClickHouse, Inc. (ClickHouse Cloud) — Analytics datastore for operational and usage telemetry — request counts, token counts, latency and similar performance metrics (Usage Data); no customer inference data. Company operates a separate instance per region, and telemetry for a given deployment is held in the instance for that deployment’s region. — EU, India, and United States

Denvr Dataworks Corp. (Canadian entity, Calgary) — GPU cloud compute — United States

Neysa Networks Private Limited — GPU cloud compute — India

E2E Networks Limited — GPU cloud compute — India

Massed Compute, Inc. — GPU cloud compute — United States

NexGen Cloud Limited (trading as Hyperstack), UK — GPU cloud compute — United States and Canada

Nebius B.V. (Netherlands) — GPU cloud compute — EU and US

Shadeform, Inc. — GPU compute marketplace / provisioning layer — procures and provides access to GPU instances on underlying providers — United States

Verda Cloud Oy (formerly DataCrunch Oy), Finland — GPU cloud compute — EEA (Finland and Iceland)

Crusoe Energy Systems LLC — GPU cloud compute — United States and EEA (Iceland)

Ubicloud Inc. — GPU cloud compute — United States and EU

Measure — Details

Encryption of Personal Data (in transit and at rest) — Customer Data is encrypted in transit using TLS 1.2 or higher. Data at rest in Company datastores is encrypted using AES-256 via the underlying cloud provider’s storage encryption (e.g. AWS).

Confidentiality of processing systems and personnel — Company’s customer agreements and its personnel and contractor arrangements include confidentiality obligations. Company will ensure that each Authorised Sub-processor is bound by confidentiality and data protection obligations substantially similar to those in this DPA.

Resilience and restoration of availability after an incident — Automated daily backups of production databases are taken via Amazon RDS, with point-in-time recovery within a 10-day retention window.

User identification and authorisation — Access to production systems and customer data is restricted to authorised personnel with individual accounts, granted on a least-privilege, business-need basis. Multi-factor authentication (MFA) is enforced across access paths: the cloud-provider and administrative consoles used to operate the Services (including AWS and Cloudflare) and billing systems (Stripe) require MFA; and production systems and instances — which are not exposed to the public internet — are reachable only through a Tailscale (WireGuard-based) zero-trust network that requires Google single sign-on with MFA enforced, governed by identity-based access controls.

Protection of data during transmission — All traffic to and from the Services is encrypted in transit using current secure protocols (TLS 1.2 or higher). Administrative connections to production instances are additionally tunnelled over an encrypted Tailscale (WireGuard) overlay network.

Protection of data during storage — Encryption at rest using industry-standard AES-256; encryption keys are managed by the underlying cloud provider (e.g. AWS KMS).

Physical security of processing locations — All production Processing occurs in cloud data centers operated by Company’s infrastructure Sub-processors (e.g. AWS and the GPU cloud providers listed in Schedule 1), which maintain their own physical security controls. Company operates no physical data centers of its own.

Events logging and monitoring — Company logs and monitors access to systems and resources that Process or store Covered Data, and reviews and escalates security-relevant events as appropriate.

System configuration and deployment — Changes to the production environment are deployed through CI/CD tooling to promote consistent and repeatable configuration.

Data minimisation — Customer unilaterally determines what data it routes through the Services (a shared-responsibility model). Company provides functionality enabling Customer to control and delete the data that enters the platform.

Limited data retention — Covered Data is retained only for the period described in Schedule 1 and Section 11 and is deleted on Customer request or at the end of the Retention Period.

Data portability and erasure — Personal Data submitted to the Services may be deleted by Customer or at Customer’s request; Company will respond to reasonable data portability requests to address Customer needs.

Governance and accountability — Company assigns responsibility for information security and data privacy matters and records and reports Security Incidents in accordance with Section 10 of this DPA. Company uses Oneleet for continuous security and compliance monitoring.

Measures applied by Sub-processors — Company will ensure that each Authorised Sub-processor is engaged under written data protection terms that are, in substance, no less protective of Covered Data than this DPA — in most cases the sub-processor’s standard data processing agreement, incorporated into its terms of service.

Copyright © 2026 Infercloud Inc. All rights reserved.