OTTO HR DATA PROCESSING ADDENDUM

This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms of Service or other written or electronic agreement (the “Agreement”) between Ottohr Inc. (“Otto HR”) and the customer that is a party to the Agreement (“Customer”) governing Customer’s access to and use of the Platform and Services. This DPA applies to Otto HR’s Processing of Personal Data on behalf of Customer in connection with the Services. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

By executing the Agreement, or by accepting this DPA where it is presented for acceptance, Customer and Otto HR agree to this DPA. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls.

1. Definitions

For purposes of this DPA:

“Applicable Data Protection Laws” means all data protection and privacy laws and regulations applicable to the Processing of Personal Data under this DPA, including, as applicable: the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act and its implementing regulations (the “CCPA”); the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, and other U.S. state privacy laws (together with the CCPA, “U.S. State Privacy Laws”); the EU General Data Protection Regulation 2016/679 (“EU GDPR”) and the UK GDPR and Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection (“FADP”); and the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”).

“Business,” “Controller,” “Processor,” “Service Provider,” “Contractor,” “Consumer,” “Data Subject,” “Sell,” “Share,” “Sensitive Personal Information,” “Deidentified,” and “Process/Processing” have the meanings given to them (or their functional equivalents) under Applicable Data Protection Laws.

“Customer Personal Data” means Personal Data contained within Customer Data that Otto HR Processes on behalf of Customer under the Agreement, as further described in Annex 1.

“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, and includes “personal information” and “personal data” as defined under Applicable Data Protection Laws.

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Otto HR or its Sub-processors. Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, denial-of-service attacks, or unsuccessful log-in attempts.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.

“Sub-processor” means a third party engaged by Otto HR that Processes Customer Personal Data in connection with the Services.

2. Roles and Scope of Processing

2.1. Roles. As between the parties and with respect to Customer Personal Data, Customer is the Business and Controller, and Otto HR is the Service Provider and Processor acting on Customer’s behalf. Where Customer is itself a Processor acting on behalf of a third-party controller, Otto HR acts as a Sub-processor, and Customer represents that it has the authority and instructions of the relevant controller.

2.2. Scope. Otto HR will Process Customer Personal Data only as a Service Provider and Processor for the limited and specified purposes of providing, maintaining, securing, supporting, and improving the Services, performing the Agreement, and as otherwise instructed by Customer, and not for any other commercial purpose. The subject matter, duration, nature and purpose of Processing, categories of Data Subjects, and categories of Personal Data are described in Annex 1.

2.3. Instructions. Otto HR will Process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement, this DPA, and Customer’s configuration and use of the Services, unless required to Process by Applicable Data Protection Laws, in which case Otto HR will, to the extent legally permitted, inform Customer of that legal requirement before Processing. Otto HR will promptly notify Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws (without obligation to provide legal advice).

3. Customer Obligations

3.1. Customer is responsible for the lawfulness of its collection and Processing of Customer Personal Data and for its instructions to Otto HR. Customer represents and warrants that it has provided all required notices and obtained all rights, consents, and lawful bases necessary for Otto HR to Process Customer Personal Data as contemplated by the Agreement and this DPA, including for candidate, applicant, and employee data and for any Sensitive Personal Information.

3.2. Special categories. Customer will not submit to the Services, and will not instruct Otto HR to Process, (a) protected health information subject to the U.S. Health Insurance Portability and Accountability Act (“HIPAA”) unless the parties have executed a Business Associate Agreement, or (b) biometric identifiers or biometric information regulated by the Illinois Biometric Information Privacy Act or similar laws, in each case unless Customer has provided all legally required notices and obtained all legally required consents.

4. Otto HR Processing Obligations

4.1. Otto HR will (a) Process Customer Personal Data only as permitted by this DPA and Customer’s instructions; (b) ensure that personnel authorized to Process Customer Personal Data are subject to binding obligations of confidentiality; (c) implement and maintain the technical and organizational measures described in Section 10 and Annex 2; (d) assist Customer as described in Sections 7 and 8; and (e) delete or return Customer Personal Data as described in Section 14.

4.2. Otto HR will provide the same level of privacy protection with respect to Customer Personal Data as is required of Customer under Applicable Data Protection Laws to the extent Otto HR Processes such data on Customer’s behalf.

4.3. Otto HR will not use Customer Personal Data to train or fine-tune any foundation or general-purpose artificial intelligence models made available to other customers or third parties. Otto HR may use aggregated and Deidentified data only as permitted under Section 12 and Applicable Data Protection Laws.

5. CCPA and CPRA Service Provider Terms

This Section applies to the extent Otto HR Processes Personal Information (as defined under the CCPA) on behalf of Customer as a Service Provider. Otto HR:

5.1. will Process the Personal Information only for the limited and specified “business purposes” of performing the Services and the Agreement and as otherwise permitted under the CCPA, and will not Process it for any other purpose;

5.2. will not Sell or Share the Personal Information;

5.3. will not retain, use, or disclose the Personal Information (a) for any purpose other than the business purposes specified in this DPA and the Agreement, including any commercial purpose other than the business purposes specified, or (b) outside the direct business relationship between Otto HR and Customer, except in each case as permitted by the CCPA;

5.4. will not combine the Personal Information with Personal Information that Otto HR receives from, or on behalf of, another person, or that it collects from its own interactions with the Consumer, except as permitted under the CCPA and its implementing regulations;

5.5. certifies that it understands the restrictions in this Section 5 and Section 2, and will comply with them;

5.6. will comply with applicable obligations under the CCPA and provide the same level of privacy protection as required of businesses by the CCPA;

5.7. will notify Customer promptly, and in any event without undue delay, if it determines that it can no longer meet its obligations under the CCPA; and

5.8. grants Customer the right, upon notice, to take reasonable and appropriate steps to help ensure that Otto HR uses the Personal Information in a manner consistent with Customer’s obligations under the CCPA, and to stop and remediate any unauthorized use of Personal Information.

Otto HR does not receive the Personal Information as consideration for the Services or for any other services provided to Customer.

6. Other U.S. State Privacy Laws — Processor Terms

To the extent U.S. State Privacy Laws other than the CCPA apply, Otto HR, as Processor, will: (a) adhere to Customer’s instructions and assist Customer in meeting its obligations; (b) ensure that persons Processing Customer Personal Data are subject to a duty of confidentiality; (c) at Customer’s direction, delete or return Customer Personal Data upon termination of the Services, unless retention is required by law; (d) upon Customer’s reasonable request, make available to Customer information reasonably necessary to demonstrate Otto HR’s compliance with its obligations; (e) engage Sub-processors only pursuant to a written contract that imposes obligations substantially similar to those in this DPA; and (f) provide the assistance described in Sections 7 and 8, including reasonable assistance with data protection assessments and Security Incident obligations.

7. Automated Decisionmaking, Risk Assessments, and Audit Assistance

7.1. ADMT. To the extent Customer uses the Services to carry out profiling or automated decisionmaking technology (“ADMT”) that is subject to Applicable Data Protection Laws, including the CCPA’s ADMT regulations, Customer is the Business and Controller responsible for compliance, including any required pre-use notice, access, opt-out, appeal, and human-review obligations. Otto HR will provide reasonable assistance and information within its possession or control to enable Customer to comply with such obligations and to respond to related Consumer or Data Subject requests.

7.2. Risk assessments and data protection assessments. Otto HR will provide reasonable assistance and make available information reasonably necessary to enable Customer to conduct and document risk assessments, data protection assessments, and data protection impact assessments required under Applicable Data Protection Laws (including the CCPA risk-assessment regulations and comparable state and GDPR requirements) in connection with Customer’s use of the Services.

7.3. Cybersecurity audits. Where Customer is required under Applicable Data Protection Laws to conduct or certify a cybersecurity audit, Otto HR will, upon reasonable request, provide information and reasonable assistance regarding the technical and organizational measures applicable to the Services to enable Customer to complete such audit.

8. Data Subject and Consumer Requests

8.1. Taking into account the nature of the Processing, Otto HR will provide reasonable assistance, including through appropriate technical and organizational measures and functionality within the Services, to enable Customer to respond to requests from Data Subjects and Consumers to exercise their rights under Applicable Data Protection Laws, including rights of access, deletion, correction, portability, opt-out, and restriction.

8.2. If Otto HR receives a request from a Data Subject or Consumer relating to Customer Personal Data, Otto HR will, to the extent legally permitted, promptly forward the request to Customer and will not respond to the request except on Customer’s documented instructions or as required by Applicable Data Protection Laws.

9. Sub-processors

9.1. Authorization. Customer provides general written authorization for Otto HR to engage Sub-processors to Process Customer Personal Data in connection with the Services. A current list of Sub-processors is made available to Customer as described in Annex 3.

9.2. New Sub-processors. Otto HR will inform Customer of any intended addition or replacement of a Sub-processor with a reasonable opportunity, of at least ten (10) days before the Sub-processor begins Processing, to object on reasonable data-protection grounds. If Customer reasonably objects and the parties cannot resolve the objection, Customer may, as its sole and exclusive remedy, terminate the affected portion of the Services.

9.3. Flow-down and liability. Otto HR will impose on each Sub-processor, by written contract, data-protection obligations substantially similar to and no less protective than those in this DPA. Otto HR remains responsible for the performance of each Sub-processor’s obligations under this DPA.

10. Security Measures

10.1. Otto HR will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against a Security Incident, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risk to Data Subjects. Such measures are described in Annex 2 and include, at a minimum, tenant isolation, role-based access controls, multi-factor authentication support, encryption of Customer Personal Data in transit, logging and monitoring, and access restriction.

10.2. Otto HR will take reasonable steps to ensure that personnel with access to Customer Personal Data are subject to confidentiality obligations and Process the data only as instructed.

11. Security Incident Notification

11.1. Otto HR will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

11.2. Otto HR’s notification will describe, to the extent known and available, the nature of the Security Incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where information is not available at the time of the initial notification, Otto HR will provide it in phases as it becomes available.

11.3. Otto HR will take reasonable steps to mitigate and remediate the Security Incident and will provide Customer with reasonable cooperation and assistance to enable Customer to meet its own notification and other obligations under Applicable Data Protection Laws. Otto HR’s notification is not an acknowledgment of fault or liability.

12. Deidentified Data

If Otto HR creates Deidentified data from Customer Personal Data, Otto HR will (a) take reasonable measures to ensure the information cannot be associated with a Data Subject or household; (b) publicly commit to maintain and use the information in Deidentified form and not to attempt to reidentify it, except as permitted by Applicable Data Protection Laws to determine whether its deidentification processes satisfy applicable requirements; and (c) contractually obligate any recipients to comply with these requirements.

13. International Data Transfers

13.1. EU/EEA transfers. Where Otto HR Processes Customer Personal Data subject to the EU GDPR and transfers it to a country that does not benefit from an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows: (a) Module Two (Controller-to-Processor) applies where Customer is a controller, and Module Three (Processor-to-Processor) applies where Customer is a processor; (b) in Clause 7, the optional docking clause does not apply; (c) in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 9.2; (d) in Clause 11, the optional independent dispute resolution language does not apply; (e) in Clause 17, the SCCs are governed by the law of Ireland; (f) in Clause 18, disputes will be resolved before the courts of Ireland; and (g) Annexes I, II, and III of the SCCs are populated by Annexes 1, 2, and 3 of this DPA, and the competent supervisory authority is as identified in Annex 1.

13.2. UK transfers. Where the UK GDPR applies, the SCCs as implemented above apply as varied by the UK International Data Transfer Addendum issued by the Information Commissioner’s Office (the “UK Addendum”), which is incorporated by reference; the information required by Part 1 of the UK Addendum is set out in Annexes 1–3, and Tables are completed accordingly.

13.3. Swiss transfers. Where the FADP applies, the SCCs apply with the following modifications: references to the GDPR are interpreted as references to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” does not prevent Data Subjects in Switzerland from exercising rights in their place of habitual residence.

13.4. Türkiye. Where the KVKK applies, transfers of Personal Data outside Türkiye will be carried out in accordance with the KVKK’s cross-border transfer regime, including on the basis of an adequacy determination, appropriate safeguards (such as standard contracts or binding corporate rules), an undertaking with authority approval, explicit consent, or another mechanism permitted under the KVKK, and Otto HR acts as a data processor (veri işleyen) on Customer’s behalf.

13.5. Conflict. In the event of a conflict between the SCCs and this DPA or the Agreement, the SCCs prevail with respect to transfers governed by them.

14. Return and Deletion of Personal Data

14.1. Upon termination or expiration of the Agreement, Otto HR will, in accordance with the Agreement, make Customer Personal Data available for export for the period specified in the Agreement, after which Otto HR will delete or anonymize Customer Personal Data, except to the extent retention is required by Applicable Data Protection Laws or other applicable law or is retained in routine backups that are securely isolated and deleted in the ordinary course.

14.2. Upon Customer’s written request, Otto HR will certify in writing that it has deleted Customer Personal Data in accordance with this Section.

15. Audits and Demonstrating Compliance

15.1. Otto HR will make available to Customer information reasonably necessary to demonstrate its compliance with this DPA, which may be satisfied by providing then-current third-party audit reports, certifications, or security documentation (such as SOC 2 reports or a security questionnaire response).

15.2. To the extent the information described in Section 15.1 is insufficient to demonstrate compliance with Applicable Data Protection Laws, and subject to appropriate confidentiality obligations, Customer (or an independent auditor mandated by Customer that is not a competitor of Otto HR) may, no more than once per year and upon reasonable prior written notice, conduct an audit limited in scope to Otto HR’s Processing of Customer Personal Data, conducted during business hours in a manner that does not disrupt Otto HR’s operations or compromise the security of other customers’ data. This Section is without prejudice to the audit and inspection rights under the SCCs where they apply.

16. Liability

Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this DPA together. This Section does not limit either party’s liability to Data Subjects under the SCCs where they apply.

17. Term; Precedence; Miscellaneous

17.1. This DPA is effective as of the effective date of the Agreement and continues for as long as Otto HR Processes Customer Personal Data on Customer’s behalf. Provisions that by their nature should survive will survive termination.

17.2. This DPA supplements and forms part of the Agreement. In the event of a conflict, this DPA controls over the Agreement with respect to the Processing of Personal Data, and the SCCs control over this DPA with respect to transfers governed by them.

17.3. Except as required by the SCCs or by mandatory provisions of Applicable Data Protection Laws (which apply notwithstanding the governing law of the Agreement), this DPA is governed by the governing law of the Agreement, and disputes are resolved as provided in the Agreement.

17.4. If any provision of this DPA is held invalid or unenforceable, the remainder of this DPA remains in effect, and the parties will replace the invalid provision with a valid one that most closely reflects its intent.

17.5. References in this DPA to "Customer" include a customer that has accepted a localized (including Turkish-language) version of the Agreement under the term "Üye" or an equivalent term.


Annex 1 — Details of Processing

Parties. Data exporter/Business/Controller: Customer, as identified in the Agreement. Data importer/Service Provider/Processor: Ottohr Inc., 251 Little Falls Drive, Wilmington, New Castle County, DE 19808, USA.

Subject matter and duration. Processing of Customer Personal Data for the provision of the Services under the Agreement, for the term of the Agreement and any post-termination export or retention period described therein.

Nature and purpose of Processing. Hosting, storage, transmission, access management, analysis, workflow automation, and AI-assisted processing of Customer Personal Data to provide, secure, support, and improve the human-resources, applicant-tracking, employee-portal, workflow, candidate-sourcing, and AI-enabled features of the Platform, in accordance with Customer’s instructions.

Categories of Data Subjects. Customer’s administrators and Authorized Users; employees and contractors; job applicants and candidates, including individuals identified through candidate-sourcing features; and other individuals whose Personal Data Customer submits to or processes through the Services.

Categories of Personal Data. Identification and contact data; professional and employment data (job titles, roles, departments, employment status, work history, education, skills); applicant and candidate data (résumés, application materials, assessments, interview notes, sourcing data); account and authentication data; usage, device, log, and security data; communications and support data; document and workflow data; and AI input and output data. To the extent submitted by Customer, Personal Data may include Sensitive Personal Information.

Sensitive Personal Information. Only to the extent Customer chooses to submit it and subject to Section 3. May include, where applicable, government identifiers, precise geolocation, or data revealing characteristics protected under applicable law, as determined and controlled by Customer.

Frequency of transfer. Continuous, for the duration of the Agreement.

Competent supervisory authority (SCCs). The supervisory authority of the EEA member state in which the data exporter is established or, where applicable, of the exporter’s Article 27 representative; where the exporter is not established in the EEA, the supervisory authority as determined under Clause 13 of the SCCs. [To be specified: ●]

Annex 2 — Technical and Organizational Measures

Otto HR maintains the following measures, which may be updated to reflect evolving security practices provided that the level of protection is not materially reduced:

• Access control: role-based access controls; least-privilege access; multi-factor authentication support; unique credentials; timely revocation of access.

• Tenant isolation: logical separation of Customer data at the application and database layers.

• Encryption: encryption of Customer Personal Data in transit using industry-standard protocols; encryption at rest where applicable.

• Network and application security: firewalls; rate limiting; vulnerability management; secure development practices.

• Logging and monitoring: audit logging of access and security events; monitoring and alerting.

• Resilience and recovery: backup and restoration procedures; business continuity measures.

• Personnel: confidentiality obligations; security awareness practices; background screening where legally permitted.

• Vendor management: security and confidentiality obligations imposed on Sub-processors.

• Incident response: documented procedures for detecting, assessing, and responding to Security Incidents.

Annex 3 — Approved Sub-processors

Otto HR uses Sub-processors to provide the Services, which may include providers of cloud hosting and infrastructure, analytics, communications and email delivery, customer support, security, payment processing, and AI infrastructure. A current list of Sub-processors, including name, function, and location, is made available to Customer upon request at legal@ottohr.com or through a designated Sub-processor page, and is updated in accordance with Section 9.

Annex 4 — Standard Contractual Clauses

Where the SCCs apply under Section 13, the module and clause selections in Section 13.1 apply, and the appendices to the SCCs are populated as follows: Annex I (List of Parties; Description of Transfer; Competent Supervisory Authority) by Annex 1 of this DPA; Annex II (Technical and Organizational Measures) by Annex 2 of this DPA; and the list of Sub-processors by Annex 3 of this DPA. By entering into this DPA, each party is deemed to have signed the SCCs, including their appendices.