BURDENOFF DATA PROCESSING ADDENDUM (DPA) Version 2026-08-01 (template) This Data Processing Addendum ("DPA") forms part of the Terms of Service (or a separately signed Master SaaS Agreement / Order Form) between the customer identified in the applicable Order Form ("Customer," acting as data controller or, where applicable, data processor on behalf of its own customers) and Burdenoff Consultancy Services Pvt. Ltd. ("Burdenoff," acting as data processor / sub-processor), governing Burdenoff's processing of personal data submitted to the Service on Customer's behalf. 1. DEFINITIONS "Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Sub-processor" have the meanings given in the GDPR, or the closest equivalent term under other applicable data protection law (including the DPDP Act 2023 and the CCPA/CPRA), as context requires. "Customer Data" means personal data that Customer or its authorized users submit to the Service. 2. ROLES Customer is the controller (or processor, if Customer itself processes personal data on behalf of a third party) of Customer Data. Burdenoff is a processor / sub-processor that processes Customer Data solely to provide, secure, and support the Service, on Customer's documented instructions as set out in the Agreement and this DPA. 3. PROCESSING ACTIVITIES (ANNEX 1) | Activity | Service | Data processed | |----------------------------------|-----------------------------------------------------|------------------------------------------| | Identity & authentication | global-auth-svc | Credentials, sessions, MFA state | | Tenant / organization management | global-tenant-svc | Tenant metadata, member roles | | Billing | global-billing-svc | Payment tokens, invoices, subscriptions | | Communications | global-notification-svc, global-channel-svc, global-newsletter-svc | Contact info, message content | | Audit | global-activity-svc | Activity logs, actor metadata | | Support | global-support-svc | Tickets, messages, attachments | | Developer portal / marketplace | global-devportal-svc, global-store-svc | Publisher/app metadata, order records | 4. SECURITY MEASURES (ANNEX 2) - Encryption in transit (TLS) for all Service traffic. - Encryption at rest for databases and object storage. - Field-level AES-256 encryption for MFA secrets, API/HMAC signing keys, OAuth tokens, and OIDC client secrets. - Tenant isolation via row-level scoping and opaque cross-service IDs. - Centrally enforced role-based access control (RBAC) at the API gateway; no service re-implements its own authorization. - Immutable activity/audit logging with a mandatory 7-year retention floor and no admin-triggered early deletion path. - CI-gated CVE, IaC, and SBOM scanning before any production deployment; commit-time secret scanning. - Access to production infrastructure restricted to authenticated operators via a managed Zero Trust access broker; no public SSH. 5. SUB-PROCESSORS (ANNEX 3) The current authoritative sub-processor list, including each party's purpose and processing region, is published and kept up to date at https://burdenoff.com/subprocessors. Burdenoff will provide at least 30 days' advance notice via that page before a new sub-processor with access to Customer Data begins processing. Customer may object to a new sub-processor on reasonable data-protection grounds by contacting privacy@burdenoff.com within that notice period; the parties will work in good faith to resolve the objection, which may include Customer terminating the affected part of the Service without penalty if no resolution is reached. 6. INTERNATIONAL TRANSFERS Where Burdenoff transfers Customer Data out of the European Economic Area, the United Kingdom, or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable), incorporated into this DPA by reference, or another legally recognized transfer mechanism then available. 7. DATA SUBJECT REQUESTS Burdenoff will provide reasonable assistance to Customer, to the extent Customer cannot reasonably fulfil a data subject request itself using the Service's available functionality, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection) known to relate to Customer Data. 8. DATA DELETION On termination of the Agreement, Burdenoff will delete or return Customer Data within the period set out in the Agreement (absent a legal requirement to retain it), consistent with Burdenoff's published data retention practices at https://burdenoff.com/privacy. 9. SUB-PROCESSOR FLOW-DOWN Burdenoff imposes data protection obligations on each sub-processor that are substantially similar to those in this DPA and remains liable to Customer for a sub-processor's performance of its data protection obligations. 10. AUDIT Burdenoff will make available information reasonably necessary to demonstrate compliance with this DPA (such as this document, our Security page at https://burdenoff.com/security, and applicable third-party audit reports once available), and will allow for an audit, including inspections, by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality, and no more than once per 12-month period absent a security incident or regulator requirement. 11. LIABILITY Liability under this DPA is subject to the limitation of liability set out in the Agreement. 12. EXECUTION This DPA becomes legally binding on the Customer identified below once counter-signed by an authorized Burdenoff representative and returned per the execution process described at https://burdenoff.com/dpa. Annex 1 (processing activities) may be supplemented with customer-specific detail in the signed version where Customer's use of the Service differs from the default description above. SIGNATURE BLOCK For Customer: For Burdenoff Consultancy Services Pvt. Ltd.: Name: ______________________ Name: ______________________ Title: ______________________ Title: ______________________ Date: ______________________ Date: ______________________ Signature: __________________ Signature: __________________ Questions: privacy@burdenoff.com