// legal

Data Processing Agreement

Controller and Processor Terms

// Donna OS · Individual Entrepreneur Vladislav Verin (Georgia, ID 322783225)

Document informationDetails
Effective date17 September 2026
ProcessorUladzislau Veryn, Individual Entrepreneur
Identification number322783225
Registration and addressGeorgia; 18 Giorgi Guramishvili Street, Tbilisi
Applies withDonna OS Terms of Service and applicable Order Forms

This Data Processing Agreement governs Donna OS's processing of Personal Data on behalf of a business customer. It forms part of the Agreement for the Service and applies when Donna OS acts as a Processor or Subprocessor. The Customer determines the purposes and essential means of processing and remains responsible for the lawfulness of its instructions and use of the Service.

IMPORTANT NOTICE. The person accepting this DPA confirms authority to bind the Customer. This DPA includes processing details, realistic security commitments, Subprocessor terms, a Georgia mandatory-law addendum, international-transfer provisions, EU Standard Contractual Clauses completion terms, the United Kingdom Addendum completion terms, Swiss modifications, and United States state privacy provisions.

Contents

1 Parties Acceptance and Relationship to the Agreement

2 Definitions

3 Scope Priority and Regulatory Roles

4 Documented Instructions

5 Customer Obligations

6 Processor Obligations

7 Authorized Personnel and Confidentiality

8 Security Measures

9 Personal Data Breaches

10 Subprocessors

11 Data Subject Requests

12 Impact Assessments and Regulatory Cooperation

13 Records Audits and Demonstration of Compliance

14 Government and Legal Requests

15 International Data Transfers

16 Return Export Retention and Deletion

17 United States State Privacy Requirements

18 Artificial Intelligence Processing

19 Term Suspension and Termination

20 Liability and Governing Terms

21 General Terms

Contents Continued

Schedule 1 Details of Processing

Schedule 2 Technical and Organizational Measures

Schedule 3 Subprocessor Authorization and Register

Schedule 4 Georgia Mandatory Data Processing Terms

Schedule 5 European Union Standard Contractual Clauses

Schedule 6 United Kingdom International Transfer Addendum

Schedule 7 Switzerland Transfer Modifications

Schedule 8 United States State Privacy Addendum

1 Parties Acceptance and Relationship to the Agreement

1.1 Parties. This Data Processing Agreement is between the Customer identified in the applicable Order Form, checkout record, invoice, or account registration and Uladzislau Veryn, an Individual Entrepreneur registered under the laws of Georgia, identification number 322783225, with registered address at 18 Giorgi Guramishvili Street, Tbilisi, Georgia, trading as Donna OS. Each is a Party and together they are the Parties.

1.2 Incorporation. This DPA forms part of the Agreement governing the Customer's use of Donna OS. Capitalized terms not defined in this DPA have the meanings given in the Donna OS Terms of Service or the applicable Order Form.

1.3 Acceptance. The Customer accepts this DPA by signing it, accepting an Order Form that incorporates it, completing an electronic acceptance process, or using the Service after the DPA is made available. Electronic acceptance has the same effect as a signature to the extent permitted by Applicable Data Protection Law.

1.4 Authority. A person accepting this DPA for the Customer represents that the person has authority to bind the Customer and each participating Customer Affiliate. If that person lacks authority, the person must not accept this DPA.

1.5 Existing data processing agreements. A separately signed data processing agreement between the Parties remains effective for its stated term and scope. This DPA applies when no separate signed agreement governs the same processing or when the Parties expressly replace the earlier agreement.

1.6 Effective date. This DPA takes effect on the later of 17 September 2026, the date the Customer accepts it, or the date Donna OS first processes Customer Personal Data for the Customer.

2 Definitions

TermMeaning
Applicable Data Protection Lawa law or binding regulation governing privacy, data protection, or the processing of Personal Data that applies to a Party or the processing, including where applicable the GDPR, UK GDPR, Swiss FADP, Georgia Data Protection Law, and United States State Privacy Laws.
Controllerthe person that determines the purposes and essential means of processing Personal Data, including an equivalent term such as business where Applicable Data Protection Law uses that term.
Customer Personal DataPersonal Data contained in Customer Data that Donna OS processes on behalf of the Customer under the Agreement. It includes AI Input and AI Output to the extent they contain Personal Data.
Data Subjectan identified or identifiable natural person to whom Personal Data relates, including an employee, former employee, worker, contractor, candidate, customer, prospect, supplier contact, user, representative, or other individual recorded in the Service.
EEAthe European Economic Area.
EU SCCsthe standard contractual clauses for international transfers adopted by Commission Implementing Decision EU 2021 914, as amended, replaced, or superseded by a competent authority.
Georgia Data Protection Lawthe Law of Georgia on Personal Data Protection adopted on 14 June 2023, including amendments effective as of the DPA Effective Date, and binding subordinate acts.
GDPRRegulation EU 2016 679.
Personal Datainformation relating to an identified or identifiable natural person, and any information treated as personal data, personal information, or an equivalent concept under Applicable Data Protection Law.
Personal Data Breacha breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed.
Processingan operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
Processorthe person that processes Personal Data on behalf of a Controller, including an equivalent term such as service provider, contractor, or operator where Applicable Data Protection Law uses that term.
Restricted Transfera transfer of Personal Data that requires an adequacy decision, approved contractual clauses, certification, binding corporate rules, derogation, or another transfer mechanism under Applicable Data Protection Law.
Security Measuresthe technical and organizational measures described in Schedule 2 and any additional measures expressly agreed in an Order Form or security addendum.
Sell Share and Targeted Advertisinghave the meanings given under the applicable United States State Privacy Law, including analogous terms concerning cross context behavioral advertising.
Special Category DataPersonal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, data concerning sex life or sexual orientation, and comparable sensitive data under Applicable Data Protection Law.
Subprocessora third party appointed by Donna OS to process Customer Personal Data on behalf of the Customer in connection with the Service.
Supervisory Authorityan independent public authority responsible for monitoring compliance with Applicable Data Protection Law, including the State Audit Office of Georgia for processing within its statutory competence.
UK Addendumthe then current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018.
UK GDPRthe GDPR as incorporated into United Kingdom law and amended from time to time.
United States State Privacy LawsUnited States state privacy laws applicable to the processing, including laws that impose processor, service provider, contractor, or similar duties.

3 Scope Priority and Regulatory Roles

3.1 Scope. This DPA applies to Donna OS's processing of Customer Personal Data on behalf of the Customer in providing, securing, supporting, maintaining, and improving the Service as permitted by the Agreement and the Customer's documented instructions.

3.2 Controller and Processor roles. The Customer is the Controller and Donna OS is the Processor when the Customer determines the purposes and essential means of processing. If the Customer acts as a Processor for another Controller, Donna OS acts as the Customer's Subprocessor. The Customer is responsible for obtaining any authorization required from that Controller.

3.3 Independent Controller processing. Donna OS acts as an independent Controller for Personal Data it processes for account administration, business contact management, billing records, fraud prevention, security administration, legal compliance, establishment or defense of claims, and its own legitimate operational records. That processing is governed by the Donna OS privacy notice and is outside this DPA except where Applicable Data Protection Law requires otherwise.

3.4 Processing details. The subject matter, duration, nature, purposes, Data Subject categories, Personal Data categories, sensitive data safeguards, and retention framework are described in Schedule 1. The applicable Order Form and the Customer's configuration may further limit those details.

3.5 Priority. For processing of Customer Personal Data, this DPA prevails over conflicting provisions of the Terms of Service. The EU SCCs, UK Addendum, and mandatory provisions of Applicable Data Protection Law prevail over this DPA to the extent of a conflict. An Order Form changes this DPA only if it identifies the provision changed and expressly states the agreed replacement.

3.6 Customer Affiliates. A Customer Affiliate may rely on this DPA only while it is authorized to use the Service under the Agreement and is subject to the same obligations as the Customer. The Customer remains responsible for coordinating instructions, notices, and claims for participating Affiliates unless an Affiliate signs a separate Order Form.

4 Documented Instructions

4.1 Instructions. Donna OS will process Customer Personal Data only on documented instructions from the Customer, including instructions contained in the Agreement, Order Forms, account configuration, Authorized User actions, API calls, integration settings, support requests, and other written directions consistent with the Service.

4.2 Purpose limitation. Donna OS will process Customer Personal Data only to provide, secure, support, maintain, and improve the Service for the Customer; prevent fraud and abuse; comply with the Agreement; and carry out other documented instructions from the Customer.

4.3 Required processing. If law requires Donna OS to process Customer Personal Data beyond the Customer's instructions, Donna OS will inform the Customer before processing unless the law prohibits notice on important grounds of public interest.

4.4 Unlawful instructions. Donna OS will promptly inform the Customer if it reasonably believes an instruction violates Applicable Data Protection Law. Donna OS may suspend the affected processing while the Parties clarify or modify the instruction. Donna OS is not required to provide legal advice or independently verify the Customer's legal basis.

4.5 Changes to instructions. The Customer may change instructions through supported Service controls or a written request. If a requested change is technically infeasible, materially changes the Service, creates material risk, or requires professional services, the Parties will discuss a reasonable alternative, revised Order Form, or statement of work.

4.6 No sale or unrelated use. Donna OS will not sell Customer Personal Data, share it for cross-context behavioral advertising, use it for targeted advertising, or retain, use, or disclose it outside the direct business relationship except as permitted by this DPA, the Agreement, the Customer's instructions, or Applicable Data Protection Law.

5 Customer Obligations

5.1 Lawful basis and authority. The Customer must ensure that it has a valid legal basis and all necessary rights, notices, consents, authorizations, and permissions for Donna OS and its Subprocessors to process Customer Personal Data as contemplated by the Agreement.

5.2 Transparency. The Customer is responsible for providing legally sufficient privacy notices to Data Subjects, identifying Donna OS or categories of processors where required, and explaining the Customer's purposes, legal bases, retention periods, transfers, automated processing, and Data Subjects' rights.

5.3 Data minimization. The Customer must limit Customer Personal Data to information reasonably necessary for the configured Service. The Customer must not submit restricted data, government classified information, payment card authentication data, full payment card numbers, or specialized medical records unless the Agreement and Documentation expressly support that data and the Parties have agreed appropriate safeguards.

5.4 Accuracy. The Customer is responsible for the accuracy, quality, legality, and relevance of Customer Personal Data and for correcting or deleting inaccurate data using available Service controls.

5.5 Special Category Data. The Customer must not process Special Category Data or criminal conviction data through the Service unless the relevant feature supports it, the Customer has a lawful basis and required authorization, the Customer applies appropriate access restrictions, and any required impact assessment or consultation has been completed.

5.6 Children data. The Service is intended for business administration and is not directed to children. If the Customer processes information about dependants, beneficiaries, minors, or young workers, the Customer must determine that the processing is lawful and configure access and retention accordingly.

5.7 Controller instructions. If the Customer is a Processor, it represents that its instructions to Donna OS are authorized by the relevant Controller and consistent with the Customer's own processor obligations. The Customer will provide the Controller's identity and contact information when reasonably required for a Restricted Transfer or regulatory request.

5.8 Security responsibilities. The Customer must protect credentials, endpoints, exports, connected systems, integrations, administrator accounts, role assignments, and Customer-controlled encryption keys. The Customer must promptly disable unnecessary access and notify Donna OS of suspected account compromise.

5.9 Response duties. The Customer is responsible for responding to Data Subjects and Supervisory Authorities, making legally required breach notifications, determining whether an impact assessment is required, and obtaining professional advice concerning its own processing.

6 Processor Obligations

6.1 Compliance. Donna OS will comply with obligations directly applicable to it as a Processor under Applicable Data Protection Law and will process Customer Personal Data in accordance with this DPA.

6.2 Assistance. Taking into account the nature of processing and information available to Donna OS, Donna OS will provide reasonable assistance with Data Subject requests, security obligations, Personal Data Breach notifications, impact assessments, and prior consultations as described in this DPA.

6.3 Processing records. Donna OS will maintain records of processing activities required of a Processor and make them available to a competent Supervisory Authority on lawful request.

6.4 Data protection contact. Questions and notices concerning this DPA may be sent to info@donna-os.com with the subject Data Protection Notice, unless an Order Form or the Donna OS legal page identifies a dedicated privacy contact.

6.5 Inability to comply. Donna OS will notify the Customer if it determines that it can no longer meet a material obligation under this DPA. The Parties will cooperate in good faith to stop, suspend, or remediate the affected processing. If remediation is not reasonably possible, either Party may terminate the affected processing or Service as permitted by the Agreement and Applicable Data Protection Law.

6.6 No direct relationship with Data Subjects. Donna OS does not determine the Customer's purposes for processing and does not assume the Customer's notice, consent, employment, or regulatory duties. Donna OS will not respond substantively to a Data Subject request concerning Customer Personal Data unless authorized by the Customer or required by law.

7 Authorized Personnel and Confidentiality

7.1 Need to know access. Donna OS will limit access to Customer Personal Data to personnel who need access to provide, secure, support, or maintain the Service or to comply with law.

7.2 Confidentiality. Donna OS will ensure that personnel authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations that continue after their engagement ends.

7.3 Training. Donna OS will provide personnel with privacy and security awareness appropriate to their roles and access. Personnel with elevated access or security responsibilities will receive additional role based instruction where appropriate.

7.4 Access lifecycle. Donna OS will use reasonable processes to authorize, review, modify, and revoke personnel access. Access will be based on role, least privilege, and operational need, and will be removed or adjusted after a role change or termination.

7.5 Support access. Support personnel may access Customer Personal Data only when reasonably necessary to investigate a request, troubleshoot an issue, respond to an incident, or perform an authorized service. Donna OS will use available access controls and logging appropriate to the support method.

8 Security Measures

8.1 Security program. Donna OS will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. The measures will take account of the state of the art, implementation cost, processing context, and risks to Data Subjects.

8.2 Minimum measures. The Security Measures in Schedule 2 apply to the Service. Donna OS may update them to address changing risks, technology, and industry practice, provided an update does not materially reduce the overall protection of Customer Personal Data during a paid Subscription Term.

8.3 Shared responsibility. Security is a shared responsibility. Donna OS secures systems under its control. The Customer secures its users, endpoints, credentials, integrations, exports, connected systems, permissions, and configurations. A control offered by Donna OS does not relieve the Customer from enabling and using it appropriately.

8.4 Risk review. Donna OS will periodically review material security risks and the continued appropriateness of the Security Measures. Reviews may consider threat information, incidents, vulnerability findings, architectural changes, Subprocessor changes, and applicable legal requirements.

8.5 Evidence. Subject to confidentiality, security, and third party restrictions, Donna OS will make available information reasonably necessary to demonstrate the Security Measures, which may include security summaries, questionnaire responses, independent assessment summaries, penetration test summaries, or certifications if and when available. This clause does not represent that Donna OS currently holds a particular certification.

8.6 Customer testing. The Customer must not conduct penetration testing, vulnerability scanning, or other intrusive security testing without Donna OS's prior written authorization. Any authorized testing must follow agreed scope, timing, confidentiality, safety, and reporting requirements and must not access another customer's environment.

9 Personal Data Breaches

9.1 Notification. Donna OS will notify the Customer immediately after becoming aware of a Personal Data Breach affecting Customer Personal Data and, in all cases, without undue delay. Donna OS will not delay the initial notice solely because the investigation is incomplete or the breach has not yet been fully confirmed. The initial notice may be preliminary and will be sent to the Customer's administrator, security contact, privacy contact, or other contact identified in the Order Form or account.

9.2 Notification contents. To the extent reasonably available, the notice will describe the circumstances, type, and time of the breach; the categories and approximate numbers of affected Data Subjects and records; the categories and volume of data disclosed, damaged, deleted, destroyed, obtained, lost, or altered without authorization; likely consequences; measures taken or proposed; mitigation steps; and a contact point for further information.

9.3 Updates. If complete information is not available at the time of initial notice, Donna OS will provide information in phases without undue further delay as the investigation develops. Donna OS may withhold information that would compromise security, violate law, expose another customer, or prejudice a legitimate investigation.

9.4 Containment and remediation. Donna OS will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach within its responsibility and will document material facts, effects, and remedial action as required by Applicable Data Protection Law.

9.5 Customer cooperation. The Customer will provide timely information and cooperation needed to investigate account activity, connected systems, user actions, or environments controlled by the Customer. The Customer remains responsible for notifications to Data Subjects, Supervisory Authorities, customers, employees, or other persons unless law assigns that duty to Donna OS.

9.6 Communications. Neither Party will identify the other in a public statement about a Personal Data Breach without prior consultation where practicable, except where required by law. Donna OS may review a proposed reference to it for factual accuracy. Notification or cooperation is not an admission of fault or liability.

9.7 Excluded events. A failed login, unsuccessful attack, blocked scan, routine security event, Customer-caused disclosure, or incident that does not compromise Customer Personal Data is not a Personal Data Breach under this DPA. Donna OS may nevertheless provide notice when it reasonably considers the event relevant to the Customer's security.

9.8 Controller notification deadlines. The Customer remains responsible for determining whether notice to a Supervisory Authority or affected Data Subjects is required. Donna OS will provide available information promptly so that the Customer can meet applicable deadlines, including the seventy-two-hour controller notification period under the Georgia Data Protection Law where that period applies.

10 Subprocessors

10.1 General authorization. The Customer gives Donna OS general written authorization to appoint Subprocessors for the processing described in this DPA, subject to this Section and Schedule 3.

10.2 Subprocessor register. Donna OS will maintain a current Subprocessor register identifying the Subprocessor name, processing purpose, and processing location or region where reasonably available. The register may be published at donna-os.com/legal/subprocessors or another URL identified on the Donna OS legal page.

10.3 Advance notice. Donna OS will provide at least thirty days advance notice before a new Subprocessor begins processing Customer Personal Data, unless an urgent change is reasonably necessary to address a security incident, prevent service interruption, comply with law, or replace a Subprocessor that unexpectedly ceases service. For an urgent change, Donna OS will provide notice as soon as reasonably practicable.

10.4 Contractual protection. Donna OS will enter into a written agreement with each Subprocessor that imposes data protection obligations materially consistent with the obligations applicable to Donna OS for the relevant processing, including confidentiality, security, breach notification, deletion or return, assistance, and Restricted Transfer safeguards where required.

10.5 Responsibility. Donna OS remains responsible to the Customer for performance of its Subprocessors' data protection obligations to the extent required by Applicable Data Protection Law and the Agreement.

10.6 Objection. The Customer may object to a new Subprocessor on reasonable and documented data protection grounds by notifying Donna OS within fifteen days after notice. The objection must explain the specific risk and any reasonable requested mitigation.

10.7 Resolution. The Parties will work in good faith to address a valid objection. Donna OS may use a commercially reasonable alternative, apply additional safeguards, avoid use of the Subprocessor for that Customer where technically feasible, or permit termination of the materially affected Service. If no reasonable resolution is available, the Customer may terminate the affected Service before the Subprocessor begins processing and receive a refund of prepaid Fees allocable to the unused period of that affected Service. This is the Customer's exclusive remedy for an unresolved objection, without limiting mandatory rights.

10.8 Copies of terms. On reasonable request, Donna OS will provide information concerning a Subprocessor agreement sufficient to demonstrate compliance. Donna OS may redact commercial terms, security sensitive information, Personal Data, and information concerning other customers.

11 Data Subject Requests

11.1 Customer responsibility. The Customer is responsible for receiving, authenticating, evaluating, and responding to Data Subject requests concerning Customer Personal Data.

11.2 Forwarding requests. If Donna OS receives a request that reasonably appears to concern Customer Personal Data, Donna OS will forward it to the Customer without undue delay unless prohibited by law. Donna OS will not respond substantively except on documented Customer instructions or as required by law.

11.3 Service functionality. Taking into account the nature of processing, Donna OS will provide available self service functionality that enables the Customer to access, correct, export, restrict, or delete Customer Personal Data where supported by the Service.

11.4 Additional assistance. If a request cannot reasonably be completed using standard Service functionality, Donna OS will provide reasonable assistance appropriate to the request and information available. Donna OS may charge reasonable Fees for assistance that requires custom development, extensive retrieval, or professional services, unless Applicable Data Protection Law prohibits the charge.

11.5 Identity and authority. Donna OS may require the Customer to verify the identity and authority of the requester, identify the relevant account and records, narrow an overbroad request, or confirm that the requested action is lawful before Donna OS acts on the request.

11.6 Legal holds and exceptions. Donna OS may decline or limit an action where retention is required by law, a legal hold applies, the request would adversely affect another person's rights, the data cannot reasonably be identified, or Applicable Data Protection Law permits an exception. Donna OS will inform the Customer of the basis where legally permitted.

12 Impact Assessments and Regulatory Cooperation

12.1 Impact assessments. Taking into account the nature of processing and information available, Donna OS will provide reasonable information and assistance for a data protection impact assessment concerning the Customer's use of the Service where Applicable Data Protection Law requires one.

12.2 Prior consultation. Donna OS will reasonably assist with a prior consultation with a Supervisory Authority when required for processing through the Service, provided the Customer first supplies the assessment, identifies the unresolved high risk, and explains the requested assistance.

12.3 Regulatory inquiries. Donna OS will reasonably cooperate with the Customer in responding to a lawful inquiry from a Supervisory Authority concerning Donna OS's processing of Customer Personal Data. Each Party remains responsible for its own communications, submissions, and legal advice.

12.4 Limits. Assistance is limited to matters concerning Donna OS's processing and information available to Donna OS. Donna OS is not required to assess the Customer's business processes, determine the Customer's legal basis, evaluate systems not controlled by Donna OS, or provide privileged legal analysis.

12.5 Costs. The Customer will reimburse reasonable costs of unusual or extensive assistance unless the assistance is required because Donna OS breached this DPA, a Personal Data Breach arose from Donna OS's failure to comply with its obligations, or Applicable Data Protection Law prohibits reimbursement.

13 Records Audits and Demonstration of Compliance

13.1 Information rights. Donna OS will make available information reasonably necessary to demonstrate compliance with Processor obligations under Applicable Data Protection Law and this DPA.

13.2 Audit sequence. The Customer will first review available documentation, security materials, independent reports, certifications if any, and written responses. If those materials do not reasonably demonstrate compliance, the Customer may request a remote audit. An onsite inspection is permitted only where required by law, requested by a Supervisory Authority, or reasonably necessary after a material Personal Data Breach or credible evidence of material noncompliance.

13.3 Frequency and notice. Unless a Personal Data Breach, binding regulatory request, or credible material noncompliance justifies another audit, the Customer may audit no more than once in any twelve month period and must provide at least thirty days written notice.

13.4 Audit conditions. An audit must occur during normal business hours, minimize disruption, follow reasonable security and confidentiality requirements, avoid access to another customer's data, and use an independent qualified auditor that is not a competitor of Donna OS. The scope must be limited to processing covered by this DPA.

13.5 Costs. The Customer bears its audit costs and will reimburse Donna OS's reasonable costs of supporting an audit, unless the audit identifies a material breach by Donna OS. Donna OS will bear reasonable remediation costs for a confirmed breach within its responsibility.

13.6 Findings. The Customer will provide Donna OS with a confidential copy of material findings. Donna OS will address verified material noncompliance within a reasonable period proportionate to risk. Audit results, security materials, and remediation plans are Donna OS's Confidential Information.

13.7 Supervisory Authorities. This Section does not restrict the powers of a competent Supervisory Authority. Donna OS will maintain processor records and security logs required by Applicable Data Protection Law and provide legally required information within applicable statutory deadlines, including to the State Audit Office of Georgia. Nothing in this DPA authorizes an audit to expose another customer's data or compromise Service security.

14 Government and Legal Requests

14.1 Review. Donna OS will review a governmental, judicial, or law enforcement request for Customer Personal Data to determine whether the request is valid, binding, properly addressed, and proportionate under applicable law.

14.2 Customer notice. Donna OS will notify the Customer before disclosure unless law prohibits notice, an emergency involving risk of serious harm makes prior notice impracticable, or the request terms require confidentiality. If notice is delayed, Donna OS will provide it when the restriction ends where legally permitted.

14.3 Challenge and minimization. Where there are reasonable grounds and lawful means, Donna OS will seek clarification, narrow an overbroad request, object to an unlawful request, or direct the authority to the Customer. Donna OS will disclose only the information legally required.

14.4 Transparency. Donna OS may publish aggregate information about governmental requests where legally permitted. Donna OS will not voluntarily provide bulk or indiscriminate access to Customer Personal Data.

14.5 International transfer assessment. For transfers subject to the EU SCCs or UK Addendum, Donna OS will provide information reasonably necessary for the Customer's transfer risk assessment and will notify the Customer if it has reason to believe that applicable laws or practices prevent compliance with the relevant transfer terms.

15 International Data Transfers

15.1 Transfer compliance. Each Party will comply with Applicable Data Protection Law governing Restricted Transfers. The Customer authorizes processing in the countries and regions identified in the applicable Order Form, Documentation, or Subprocessor register, subject to a valid transfer mechanism where required.

15.2 Order of mechanisms. A Restricted Transfer may rely on an applicable adequacy decision, approved certification or framework, binding corporate rules, the EU SCCs, the UK Addendum, another approved contractual mechanism, or a lawful derogation. A mechanism applies only while it remains valid for the transfer.

15.3 Transfers governed by Georgian law. A transfer from Georgia to another state or international organization will be made only where the requirements of the Georgia Data Protection Law are met. Donna OS will use an applicable adequacy basis, binding contractual safeguards, another statutory ground, or a permit from the State Audit Office of Georgia where Article 37 or a successor provision requires that permit. Donna OS will apply appropriate organizational and technical safeguards to the transfer and will not authorize an onward transfer unless it remains compatible with the initial purpose and is supported by a lawful basis and adequate safeguards.

15.4 EU transfers. For a Restricted Transfer governed by the GDPR, the EU SCCs are incorporated through Schedule 5. Module Two applies when the Customer is a Controller and Donna OS is a Processor. Module Three applies when the Customer is a Processor and Donna OS is a Subprocessor.

15.5 United Kingdom transfers. For a Restricted Transfer governed by the UK GDPR, the UK Addendum and the EU SCCs completed through Schedules 5 and 6 are incorporated into this DPA.

15.6 Switzerland transfers. For a Restricted Transfer governed by the Swiss FADP, the EU SCCs apply with the modifications in Schedule 7 to the extent required by Swiss law.

15.7 Supplementary measures. The Security Measures, government request commitments, data minimization controls, encryption, access restrictions, and other measures described in this DPA apply as supplementary safeguards where relevant to a Restricted Transfer.

15.8 Conflicting transfer terms. The applicable transfer mechanism prevails over inconsistent provisions of the Agreement. Nothing in the Agreement reduces Data Subjects' rights or Supervisory Authorities' powers under a mandatory transfer mechanism.

15.9 Alternative mechanism. If a transfer mechanism is invalidated, amended, or no longer sufficient, the Parties will cooperate in good faith to implement a valid replacement. Donna OS may suspend the affected transfer if no lawful mechanism is reasonably available.

16 Return Export Retention and Deletion

16.1 During the Subscription Term. The Customer may access and export Customer Personal Data using supported Service functionality, subject to permissions, plan limits, security controls, and the Agreement.

16.2 Termination export period. For thirty days after ordinary expiration or termination, the Customer may request or perform a standard export of available Customer Personal Data as described in the Terms of Service, unless access is prohibited by law, creates a material security risk, or the Customer has not paid undisputed amounts.

16.3 Customer election and mandatory return. The Customer may instruct Donna OS to return or delete Customer Personal Data after the Service ends. A supported export before deletion constitutes return. Where the Georgia Data Protection Law requires immediate transfer following termination, invalidity, cancellation, or a processing dispute, Donna OS will suspend the affected processing and initiate the legally required transfer without undue delay. Donna OS is not required to recreate data already lawfully deleted or build a custom export unless separately agreed.

16.4 Production deletion. After the applicable return or export step, Donna OS will disable the tenant and begin deleting Customer Personal Data from active production systems. Unless mandatory law, an Order Form, a documented retention setting, or this DPA requires an earlier period, Donna OS will complete production deletion within ninety days after the export period ends. Data awaiting deletion will remain protected and unavailable for ordinary processing.

16.5 Backups. Residual copies may remain in encrypted backups until overwritten or deleted under ordinary backup rotation. Backup copies remain protected by this DPA and will not be restored for ordinary business use. If restored for disaster recovery, applicable deletion instructions will be reapplied.

16.6 Required retention. Donna OS may retain Customer Personal Data to the extent required by law, a binding legal hold, or establishment, exercise, or defense of legal claims. Retained data will be isolated where reasonably practicable, protected under this DPA, and processed only for the retention purpose.

16.7 Deletion confirmation. On written request after the applicable deletion period, Donna OS will provide reasonable written confirmation of deletion. Confirmation may describe the deletion process and exclusions and does not require disclosure of security sensitive system details.

16.8 Deidentified data. This Section does not require deletion of Usage Data or information that has been deidentified so that it no longer constitutes Personal Data under Applicable Data Protection Law. Donna OS will not attempt to reidentify deidentified data except to test deidentification or as required by law.

17 United States State Privacy Requirements

17.1 Applicability. This Section and Schedule 8 apply when a United States State Privacy Law governs Donna OS's processing of Customer Personal Data on behalf of the Customer.

17.2 Service provider relationship. Donna OS acts as a processor, service provider, contractor, or equivalent recipient for Customer Personal Data. The Customer discloses Customer Personal Data to Donna OS only for the limited and specified business purposes described in the Agreement and Schedule 1.

17.3 Restricted activities. Donna OS will not Sell or Share Customer Personal Data, use it for targeted advertising, retain, use, or disclose it outside the direct business relationship, or combine it with Personal Data received from another person or collected from Donna OS's own consumer interactions, except as permitted by applicable law to provide the Service, protect security, prevent fraud, or perform a permitted business purpose.

17.4 Level of protection. Donna OS will provide the same level of privacy protection required of the Customer for the relevant delegated processing and will notify the Customer if Donna OS determines that it can no longer meet an applicable obligation.

17.5 Monitoring and remediation. The Customer may take reasonable and appropriate steps to help ensure Donna OS uses Customer Personal Data consistently with the Customer's obligations and may require Donna OS to stop and remediate unauthorized processing, subject to the audit procedures in Section 13.

17.6 Consumer requests. Donna OS will provide reasonable assistance with authenticated consumer requests as described in Section 11 and will comply with legally required deletion, correction, access, portability, and opt out instructions from the Customer.

17.7 Deidentified data. If Donna OS receives or creates deidentified data subject to a United States State Privacy Law, Donna OS will take reasonable measures to ensure the data cannot be associated with an individual, publicly commit to maintain and use it in deidentified form where required, and not attempt to reidentify it except as permitted by law.

18 Artificial Intelligence Processing

18.1 Scope. This Section applies when an AI Feature processes Customer Personal Data, including Personal Data in prompts, files, retrieved context, summaries, classifications, recommendations, generated documents, predictions, or other AI Input and AI Output.

18.2 Instructions and purpose. Donna OS will process Customer Personal Data through AI Features only to provide, secure, support, and evaluate the feature for the Customer, follow documented instructions, detect misuse, and comply with law. The Customer controls whether and how to enable supported AI Features.

18.3 No cross customer training. Donna OS will not use identifiable Customer Personal Data, AI Input, or AI Output to train a general purpose model for the benefit of other customers without the Customer's express agreement. This restriction does not prevent processing needed to provide the feature, evaluate performance using appropriately protected data, or improve a model dedicated to the Customer where agreed.

18.4 AI providers. An external model, infrastructure, or evaluation provider that processes Customer Personal Data on behalf of Donna OS will be treated as a Subprocessor and subject to Section 10. If a feature connects directly to a Customer-selected AI provider under the Customer's account, that provider may be a Third Party Service governed by the Customer's agreement with it.

18.5 Data minimization. The Customer must avoid submitting unnecessary Personal Data, secrets, Special Category Data, criminal conviction data, or regulated records to AI Features. The Customer must configure permissions and retrieval sources so an AI Feature can access only information appropriate to the user and purpose.

18.6 Automated decisions. Donna OS does not make employment, credit, eligibility, legal, financial, safety, or similarly consequential decisions for the Customer. The Customer must provide qualified human review and must not use AI Output as the sole basis for a decision producing legal or similarly significant effects unless Applicable Data Protection Law permits the use and the Customer has implemented required safeguards.

18.7 Accuracy and rights. AI Output may be inaccurate, incomplete, biased, outdated, or nonunique. The Customer must verify material output, correct source records, provide legally required notices and explanations, and support applicable objection, review, and appeal rights.

18.8 AI impact assessment. The Customer is responsible for determining whether an AI or data protection impact assessment is required for its intended use. Donna OS will provide reasonable information concerning the AI Feature processing, Subprocessors, and safeguards as described in Section 12.

19 Term Suspension and Termination

19.1 Duration. This DPA continues for as long as Donna OS processes Customer Personal Data on behalf of the Customer, including any export, retention, backup, or deletion period after the Service ends.

19.2 Suspension. Donna OS may suspend affected processing if an instruction is unlawful, the processing creates a material security risk, the Customer breaches this DPA, a Restricted Transfer lacks a lawful mechanism, or a competent authority requires suspension. Donna OS will limit suspension to the affected processing where reasonably possible.

19.3 Termination for material breach. A Party may terminate the affected processing or Service if the other Party materially breaches this DPA and does not cure the breach within thirty days after detailed written notice, or if the breach cannot reasonably be cured. Mandatory termination rights under Applicable Data Protection Law remain unaffected.

19.4 Effect. Termination of this DPA does not by itself erase accrued rights or payment obligations. Sections concerning confidentiality, audits, government requests, transfers, deletion, liability, and interpretation survive for as long as relevant to retained Customer Personal Data or an accrued claim.

20 Liability and Governing Terms

20.1 Liability framework. Each Party's liability arising from this DPA is subject to the exclusions, limitations, indemnities, and claim procedures in the Agreement unless an Order Form expressly states a separate data protection liability cap or Applicable Data Protection Law prohibits the limitation.

20.2 No reduction of mandatory rights. Nothing in the Agreement or this DPA limits a Data Subject's right, a Supervisory Authority's power, or liability that cannot lawfully be limited. The EU SCCs and UK Addendum govern liability for claims within their scope to the extent they require different treatment.

20.3 Governing law. Except for the EU SCCs, UK Addendum, Swiss modifications, or another mandatory transfer mechanism, this DPA is governed by the governing law and dispute terms stated in the Agreement. The current Donna OS Terms of Service select the laws of Georgia and the courts of Tbilisi, Georgia, subject to mandatory jurisdiction rules.

20.4 Allocation between Parties. The Customer is responsible for its processing purposes, legal bases, notices, instructions, configurations, Data Subject decisions, and systems under its control. Donna OS is responsible for complying with its Processor obligations and protecting systems under its control. This allocation does not affect rights of Data Subjects or authorities.

21 General Terms

21.1 Changes required by law. Donna OS may update this DPA to reflect a change in Applicable Data Protection Law, an approved transfer mechanism, or binding regulatory guidance. For a material change adversely affecting an existing paid Customer, Donna OS will provide at least thirty days notice unless an earlier change is required by law or a competent authority.

21.2 Other amendments. Except for updates permitted by Section 21.1, an amendment must be in writing and accepted by authorized representatives of both Parties. An Order Form may serve as that amendment if it identifies the changed provision and agreed replacement.

21.3 Notices. Data protection notices must be sent through the contact method in Section 6.4 and to the Customer's privacy, security, legal, administrator, or billing contact identified in the Order Form or account. Each Party must keep its contacts current.

21.4 Assignment. An assignment of the Agreement includes this DPA. Neither Party may assign this DPA separately from the Agreement. A permitted assignee must assume the assigning Party's obligations for Customer Personal Data.

21.5 Severability. If a provision is invalid or unenforceable, it will be enforced to the maximum lawful extent and modified only as necessary. The remaining provisions remain effective. A mandatory transfer mechanism will not be modified beyond selections and additions it permits.

21.6 No waiver. A waiver must be express and in writing. Failure or delay to exercise a right does not waive it, and a waiver for one event does not waive a later event.

21.7 Electronic records. This DPA may be executed or accepted electronically and in counterparts. Electronic records and copies are admissible to the same extent as originals, subject to Applicable Law.

21.8 Language. The English version controls. A translation is provided only for convenience unless the Parties expressly agree that another language version controls.

Schedule 1 Details of Processing

This Schedule describes the processing authorized by the Customer. The Order Form, subscribed modules, account configuration, Authorized User actions, and documented support requests may narrow the processing. They do not expand it beyond the Agreement without a lawful instruction.

Processing elementDescription
Subject matterOperation of Donna OS as a modular business management platform, including subscribed HR, CRM, finance, legal, document, analytics, forecasting, attendance, employee workspace, integration, notification, and AI functionality.
DurationThe Subscription Term, any supported export period, and the period required to complete deletion or legally required retention.
Nature of processingCollection, recording, organization, structuring, storage, retrieval, consultation, use, calculation, classification, analysis, summarization, generation, transmission, disclosure to authorized recipients, restriction, export, backup, erasure, and destruction.
PurposesProviding, securing, supporting, maintaining, configuring, and improving the Service for the Customer; executing workflows and integrations; preventing fraud and abuse; responding to support requests; and complying with documented instructions and law.
Processing frequencyContinuous or event driven during use of the Service, with periodic backups, maintenance, monitoring, and deletion processes.
Geographic scopeCountries and regions identified in the Order Form, Documentation, or Subprocessor register, subject to Section 15.

S1.1 Categories of Data Subjects

• Customer employees, former employees, directors, officers, workers, consultants, contractors, agency workers, interns, volunteers, dependants, beneficiaries, and emergency contacts.

• Job applicants, candidates, referees, recruiting contacts, talent pool members, and prospective workers.

• Customer customers, prospects, leads, suppliers, vendors, partners, investors, representatives, professional advisers, and other business contacts.

• Authorized Users, administrators, account owners, support requesters, integration users, and persons appearing in audit or security records.

• Persons identified in contracts, legal matters, corporate records, documents, communications, tasks, requests, invoices, payments, forecasts, or other Customer records.

S1.2 Categories of Personal Data

CategoryExamples
Identity and contactName, preferred name, signature, photo, date of birth, age, nationality, identifiers, address, email, phone number, emergency contact, and related profile information.
Employment and organizationEmployer, position, department, reporting line, employment status, start and end dates, location, work eligibility, contract details, grade, schedule, leave, attendance, objectives, performance, training, disciplinary records, and workforce planning information.
RecruitmentCV, application, qualifications, employment history, interview notes, assessments, references, availability, compensation expectations, and hiring decisions.
Compensation benefits and taxSalary, bonus, commission, equity, benefits, deductions, expense, payroll, tax identifier, tax status, bank or payment details where supported, and compensation history.
Customer and commercialCRM profiles, business contact details, communications, notes, opportunities, proposals, contracts, orders, support records, invoices, payments, and relationship history.
Finance and operationsBudgets, forecasts, transactions, categories, cost centers, approvals, business metrics, project records, and operational assumptions that may relate to individuals.
Legal and documentContracts, legal matter records, obligations, claims, deadlines, correspondence, signatures, approvals, generated documents, and document metadata.
Communications and contentMessages, comments, tasks, requests, attachments, recordings where supported, notes, surveys, feedback, and user generated content.
Technical and securityAccount identifiers, roles, permissions, login events, IP address, device and browser information, session records, API activity, audit logs, error logs, and security events.
AI Input and AI OutputPrompts, retrieved context, source records, files, questions, summaries, classifications, recommendations, predictions, generated documents, and feedback to the extent they contain Personal Data.

S1.3 Sensitive Data and Safeguards

Depending on the Customer's configuration, Customer Personal Data may include Special Category Data, criminal conviction data, government identifiers, financial account information, precise location information, or other data treated as sensitive under Applicable Data Protection Law. The Customer must use only supported features and apply the safeguards required by Section 5.5.

• Role based and least privilege access, with elevated permissions limited to authorized administrators.

• Data minimization, field level configuration where available, restricted exports, and segregation of duties.

• Encryption in transit and at rest where described in Schedule 2, together with secure key and credential management.

• Human review and access controls for AI Features and consequential workflows.

• Documented retention periods and prompt removal when sensitive data is no longer required.

S1.4 Customer Instructions and Retention

The Agreement, this DPA, Order Forms, account configuration, Authorized User actions, integrations, API calls, and written support requests constitute the Customer's documented instructions. The default termination lifecycle is thirty days for supported export followed by commercially reasonable deletion from active production systems within ninety additional days, subject to backups, legal retention, and agreed settings.

Schedule 2 Technical and Organizational Measures

Donna OS will maintain the following measures as appropriate to the Service, processing, and risk. A measure may be implemented through Donna OS's systems or an authorized infrastructure Subprocessor. Specific implementation details may change without materially reducing the overall level of protection.

S2.1 Security governance

• Documented allocation of security responsibilities and periodic review of material technical and organizational risks.

• Policies and procedures appropriate to access control, incident response, vulnerability management, change management, backup, vendor risk, and business continuity.

• Privacy and security considerations incorporated into material system and feature changes proportionate to risk.

S2.2 Identity and access management

• Unique user identities, role based access, least privilege, and authorization controls for production and administrative systems.

• Multi factor authentication for privileged administrative access where supported and appropriate.

• Processes for access approval, periodic review, role changes, and prompt revocation following termination or loss of need.

• Protection of passwords, tokens, API keys, secrets, and recovery mechanisms using appropriate technical controls.

S2.3 Encryption and communications

• Encryption of network communications using current industry accepted transport encryption where supported.

• Encryption of Customer Personal Data at rest in production storage and backups where supported by the relevant infrastructure.

• Management of encryption keys and secrets using access restricted systems and rotation or replacement processes appropriate to risk.

S2.4 Application and infrastructure security

• Logical tenant separation and authorization checks designed to prevent one customer from accessing another customer data.

• Secure configuration, change control, code review, dependency management, and testing practices appropriate to the development process.

• Network, platform, and cloud security controls appropriate to the hosted architecture, including restrictions on administrative interfaces.

• Production changes performed by authorized personnel using controlled deployment processes and rollback capabilities where appropriate.

S2.5 Vulnerability management

• Processes to identify, assess, prioritize, and remediate vulnerabilities based on severity, exploitability, and system exposure.

• Use of automated dependency, code, configuration, or infrastructure scanning where appropriate to the technology.

• Independent penetration testing or comparable technical assessment periodically where proportionate to Service maturity and risk, with material findings tracked to remediation.

S2.6 Logging and monitoring

• Logging of relevant authentication, administrative, application, security, and infrastructure events with access restricted to authorized personnel.

• Monitoring and alerting designed to identify anomalous activity, service failures, and material security events.

• Protection of security logs against unauthorized access and alteration, with retention determined by operational, security, legal, and plan requirements.

S2.7 Availability and resilience

• Backups, replication, redundancy, or recovery mechanisms appropriate to the architecture and subscribed Service.

• Documented incident response and business continuity processes, with periodic exercises or reviews proportionate to risk.

• Capacity, health, and availability monitoring for material production components.

S2.8 Incident response

• Defined processes for detection, triage, containment, investigation, evidence preservation, remediation, recovery, and post incident review.

• Escalation paths and assigned responsibilities for material incidents and Personal Data Breaches.

• Customer notification and cooperation in accordance with Section 9.

S2.9 Data lifecycle controls

• Customer-controlled access, correction, export, and deletion features where supported.

• Retention and deletion processes for active systems, backups, logs, support materials, and legally retained records.

• Secure disposal or sanitization of storage media and system resources using cloud provider or industry appropriate processes.

S2.10 Personnel security

• Confidentiality obligations, privacy and security awareness, and role appropriate training for personnel with access to Customer Personal Data.

• Background or reference checks where lawful, appropriate to role, and proportionate to access and risk.

• Disciplinary and offboarding processes addressing misuse, policy violations, and access removal.

S2.11 Subprocessor and supplier security

• Risk based review of material Subprocessors before engagement and contractual obligations appropriate to their processing.

• Ongoing review of material changes, security information, incidents, and continued suitability proportionate to risk.

• Restricted Transfer mechanisms and supplementary measures where required.

S2.12 Physical security

• Donna OS relies primarily on professionally managed cloud infrastructure. Physical data center safeguards are maintained by the relevant infrastructure providers.

• Access to Donna OS's offices, devices, and local work environments is restricted using measures appropriate to the location and risk.

• Customer Personal Data will not be intentionally stored on portable media unless authorized and protected with appropriate encryption and access controls.

Schedule 3 Subprocessor Authorization and Register

The Customer gives prior general written authorization for the current Subprocessors identified below and for future additions made in accordance with Section 10. Donna OS will not permit a Subprocessor to process Customer Personal Data for purposes unrelated to the Service.

SubprocessorService and purposeData and processing locations
Supabase, Inc.Database, authentication, object storage, backend infrastructure, backups, and related platform services.Account, identity, Customer Personal Data, uploaded files, and technical logs. Primary hosting region follows the Donna OS project configuration; limited support and ancillary processing may occur where Supabase and its authorized subprocessors operate.
Vercel Inc.Application hosting, deployment, serverless execution, content delivery, networking, and platform security.Request data, IP and device information, logs, and Customer Personal Data processed through hosted application functions. Vercel operates distributed and global infrastructure, subject to configured regions and transfer safeguards.
Resend, Inc.Transactional email delivery, including account verification, invitations, password reset, security, and service notices.Recipient name and email address, message or template content, and delivery metadata. Processing may occur in the United States and other locations used by Resend and its authorized subprocessors.

S3.1 Register Requirements

The table above is the current register as of the Effective Date. Donna OS will maintain an up-to-date register identifying each Subprocessor's legal name, service purpose, processing country or region where reasonably available, and effective date. If donna-os.com/legal/subprocessors is not available, the Customer may request the current register through the contact in Section 6.4.

S3.2 Notice Method

Donna OS may provide Subprocessor notices by email to the Customer's account, privacy, security, legal, administrator, or billing contact; through an in-product notice; or through a subscription mechanism on the Subprocessor register. The Customer is responsible for maintaining a monitored contact and, where offered, subscribing to updates.

S3.3 Providers with independent-controller roles

Paddle and its applicable affiliates act as merchant of record and may act as independent controllers for checkout, payment, invoicing, tax, fraud-prevention, refund, and legally required records. They are not treated as Subprocessors for those independent-controller activities. If Donna OS later uses Paddle for processing performed solely on Donna OS's instructions, that processing will be governed by Section 10.

S3.4 AI providers

No external AI model provider is authorized to receive Customer Personal Data merely because an AI feature appears in the Service. Before an external AI provider processes Customer Personal Data, Donna OS will identify that provider in the current Subprocessor register or applicable Order Form, apply Section 10, and ensure that the provider does not use identifiable Customer Personal Data to train a general-purpose model for unrelated customers without the Customer's express agreement.

Schedule 4 Georgia Mandatory Data Processing Terms

This Schedule applies whenever the Georgia Data Protection Law governs Donna OS's processing. It is intended to satisfy the written processor-agreement requirements of Article 36 and must be interpreted consistently with mandatory Georgian law. The official English text is available through the Legislative Herald of Georgia at https://matsne.gov.ge/en/document/view/5827307.

S4.1 Written agreement and processing particulars

The legal ground for Donna OS's processing is the Customer's written engagement of Donna OS under the Agreement and the Customer's lawful instructions. The processing purposes, categories of Personal Data, categories of Data Subjects, nature, frequency, duration, and retention are set out in the Agreement and Schedule 1. The Customer determines the purposes and essential means of processing; Donna OS processes the data on the Customer's behalf.

S4.2 Instructions and purpose limitation

Donna OS will process Customer Personal Data only under the Customer's written instructions and will not carry out further processing for a purpose other than the purposes established by the Agreement, unless Georgian law requires it. Where law permits, Donna OS will inform the Customer before carrying out legally required processing outside the instructions.

S4.3 Confidentiality and authorized persons

Donna OS will ensure that each natural person directly participating in processing is authorized on a need-to-know basis, acts within assigned powers, and is bound by a written, contractual, or statutory confidentiality obligation that continues after the person's authority or engagement ends.

S4.4 Security, logging, and records

Donna OS will maintain technical and organizational measures appropriate to the categories and volume of data, the purpose, form, and means of processing, and reasonably foreseeable threats to Data Subjects. Measures include confidentiality, integrity, availability, access restrictions, and registration of relevant electronic-data operations and incidents to the extent required by Articles 27 and 28. Donna OS will periodically assess the effectiveness of those measures and update them where necessary.

S4.5 Incidents

Donna OS will notify the Customer immediately after becoming aware of an incident affecting Customer Personal Data and will provide information and updates described in Section 9. The Customer remains responsible for notification to the State Audit Office of Georgia and Data Subjects unless mandatory law places a direct obligation on Donna OS for the relevant processing.

S4.6 Subprocessors

Acceptance of this DPA constitutes the Customer's prior general written consent for the Subprocessors identified in Schedule 3 and future changes made under Section 10. Donna OS remains responsible for its own obligations and will impose appropriate written data-protection duties on each Subprocessor. The Customer's consent does not release Donna OS from obligations or responsibility imposed by law.

S4.7 Assistance and monitoring

Donna OS will use appropriate organizational and technical measures to assist the Customer with Data Subject rights and will make available information reasonably necessary for the Customer to monitor Donna OS's processing and compliance. The Customer may use the audit process in Section 13 without limiting the statutory powers of the State Audit Office of Georgia.

S4.8 Regulatory records and cooperation

Donna OS will maintain processor records required by Georgian law, including its identity and contact details, controllers on whose behalf it acts, types of processing, relevant international transfers and safeguards, a general description of security measures, and incident information. Donna OS will cooperate with lawful requests of the State Audit Office of Georgia within applicable statutory deadlines.

S4.9 International transfers

A transfer governed by Article 37 will occur only where the statutory requirements and appropriate safeguards are satisfied. Where Donna OS relies on legally binding contractual safeguards and Georgian law requires a permit, the transfer will not begin until the required permit is obtained. Onward transfers must remain compatible with the initial purpose and be supported by a lawful ground and adequate safeguards.

S4.10 Termination, invalidity, and processing disputes

On cancellation, invalidity, or termination of the processing agreement, Donna OS will stop the affected processing and return or delete Customer Personal Data and copies as required by the Customer's lawful instruction and mandatory Georgian law. If Article 36 requires immediate suspension and transfer because of a processing dispute, that mandatory rule prevails over an inconsistent export or deletion period in the Agreement. Data that Georgian law requires Donna OS to retain will remain protected and will be processed only for the legally required purpose.

Schedule 5 European Union Standard Contractual Clauses

The standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 are incorporated by reference for each Restricted Transfer governed by the GDPR. The authoritative text is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. The clauses are completed as follows. The Parties do not modify them beyond the selections and additional safeguards they permit.

S5.1 Modules and Options

EU SCC itemSelection
Applicable moduleModule Two Controller to Processor when the Customer is a Controller. Module Three Processor to Processor when the Customer is a Processor. Module Four applies only if expressly stated in an Order Form.
Clause 7 dockingThe optional docking clause applies.
Clause 9 subprocessorsOption 2 general written authorization applies. The notice period is thirty days, subject to the urgent change procedure in Section 10.3.
Clause 11 redressThe optional independent dispute resolution language does not apply unless an Order Form expressly states otherwise.
Clause 17 governing lawFor Module Two and Module Three, the law of Ireland governs the EU SCCs.
Clause 18 courtsThe courts of Dublin, Ireland have jurisdiction for proceedings under the EU SCCs, without limiting Data Subjects' rights under Clause 18(c).

S5.2 Annex I Parties

PartyDetails
Data exporterThe Customer and any participating Customer Affiliate transferring Personal Data under the EU SCCs. Address and contact details are stated in the Order Form, checkout record, account, or written notice. Activities relate to the Customer's use of Donna OS. Role is Controller for Module Two or Processor for Module Three.
Data importerUladzislau Veryn, Individual Entrepreneur, identification number 322783225, registered under the laws of Georgia, registered address 18 Giorgi Guramishvili Street, Tbilisi, Georgia, trading as Donna OS. Contact: info@donna-os.com. Activities are the provision of Donna OS under the Agreement. Role is Processor for Module Two or Subprocessor for Module Three.
Signature and accessionAcceptance of the Agreement and this DPA constitutes signature of the EU SCCs on the DPA Effective Date. An eligible Customer Affiliate may accede through Clause 7 and a written Order Form or accession notice.

S5.3 Annex I Description of Transfer

The categories of Data Subjects, Personal Data, Special Category Data, frequency, nature, purpose, duration, and retention are described in Schedule 1. Transfers may occur continuously or when initiated by Authorized Users, integrations, support events, maintenance, security operations, or enabled AI Features. The competent Supervisory Authority is determined under Clause 13 and the GDPR based on the data exporter establishment, representative, or the affected Data Subjects.

S5.4 Annex II Security Measures

The technical and organizational measures are described in Schedule 2. For transfers involving Special Category Data, additional safeguards include role based access, data minimization, encryption, restricted exports, confidentiality, logging, retention controls, and human review where appropriate.

S5.5 Annex III Subprocessors

The authorized Subprocessors are identified in the Donna OS Subprocessor register described in Schedule 3. The Customer's general authorization, notice rights, objection process, contractual protections, and Donna OS's responsibility are governed by Section 10 and Clause 9 of the EU SCCs.

S5.6 Module Three Controller Information

For Module Three, the Customer will provide Donna OS with the identity and contact details of the relevant Controller when required by the EU SCCs, a Supervisory Authority, or the nature of the Restricted Transfer. The Customer confirms that the Controller authorized Donna OS as a Subprocessor or that the Customer otherwise has authority to appoint Donna OS.

S5.7 Transfer Assessment and Supplementary Measures

The Parties will consider the circumstances of the transfer, the nature of Customer Personal Data, destination laws and practices, available contractual protections, and the Security Measures. Donna OS will provide information reasonably necessary for the Customer's assessment. If a Party concludes that supplementary measures are required, the Parties will cooperate to implement reasonable measures or suspend the affected transfer.

Schedule 6 United Kingdom International Transfer Addendum

For a Restricted Transfer governed by the UK GDPR, the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office is incorporated and completed through this Schedule. The official addendum is available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/. Defined terms in the UK Addendum have the meanings given there.

UK Addendum tableCompletion information
Table 1 PartiesThe exporter is the Customer and eligible Customer Affiliates. The importer is Uladzislau Veryn, Individual Entrepreneur, identification number 322783225, registered in Georgia, trading as Donna OS. Contact information is in the Order Form, account, Section 6.4, and Schedule 5.
Table 2 Approved EU SCCsThe version adopted by Commission Implementing Decision EU 2021 914 applies. Module Two or Module Three applies as selected in Schedule 5. Clause 7 applies. Clause 9 Option 2 applies with thirty days notice. Clause 11 optional language does not apply.
Table 3 Appendix InformationThe parties are described in Schedule 5. The transfer description is in Schedule 1 and Schedule 5. The Security Measures are in Schedule 2. Subprocessors are in the register described in Schedule 3.
Table 4 Ending the AddendumEither Party may end the UK Addendum as permitted by the mandatory clauses when the Information Commissioner issues a revised approved addendum.
Effective date and signatureThe UK Addendum takes effect when a Restricted Transfer governed by the UK GDPR begins. Acceptance of this DPA constitutes execution of the UK Addendum.

S6.1 Mandatory Clauses

Part 2 Mandatory Clauses of the UK Addendum apply without amendment. If this DPA conflicts with those Mandatory Clauses, the Mandatory Clauses prevail for the relevant Restricted Transfer.

S6.2 United Kingdom Authority and Courts

The Information Commissioner is the competent Supervisory Authority for the UK Addendum. The governing law and courts for rights under the UK Addendum are determined by its Mandatory Clauses and applicable United Kingdom law.

Schedule 7 Switzerland Transfer Modifications

For a Restricted Transfer governed by the Swiss FADP, the EU SCCs apply with the following modifications to the extent required for their use under Swiss law.

ItemSwiss modification
AuthorityReferences to the competent Supervisory Authority include the Swiss Federal Data Protection and Information Commissioner for transfers governed by the Swiss FADP.
Protected personsReferences to Data Subjects include persons protected under the Swiss FADP. The EU SCCs will not be interpreted to exclude a person in Switzerland from exercising applicable rights.
Law referencesReferences to the GDPR are understood to include the corresponding provisions of the Swiss FADP where the transfer is governed by Swiss law.
Member StateReferences to a Member State are interpreted to include Switzerland where necessary to give effect to rights under the Swiss FADP.
Governing lawThe selections in Schedule 5 apply unless Swiss law requires Swiss law or another law that permits third party beneficiary rights for the relevant claim.
JurisdictionThe selections in Schedule 5 apply without limiting the right of a protected person to bring a claim in Switzerland where the Swiss FADP or EU SCCs as adapted permit it.
Dual applicationIf both the GDPR and Swiss FADP apply, the EU SCCs operate for both regimes with these modifications applying only to the Swiss law aspects.

Schedule 8 United States State Privacy Addendum

This Schedule supplements Section 17 for processing governed by a United States State Privacy Law. It applies only to the extent the relevant law treats Donna OS as a processor, service provider, contractor, or comparable recipient acting on behalf of the Customer.

RequirementCommitment
Limited purposesDonna OS may process Customer Personal Data only for the limited and specified purposes in the Agreement, this DPA, Schedule 1, and the Customer's documented instructions.
No sale or sharingDonna OS will not Sell or Share Customer Personal Data or use it for targeted advertising, except to the extent the Customer expressly instructs an activity that Applicable Data Protection Law permits and the Parties document required terms.
No unrelated useDonna OS will not retain, use, or disclose Customer Personal Data outside the direct business relationship or for its own commercial purposes except as permitted by law for security, fraud prevention, internal operations, legal compliance, or a permitted business purpose.
No prohibited combinationDonna OS will not combine Customer Personal Data with Personal Data received from another person or collected from Donna OS's direct consumer interactions except as permitted by the applicable law to provide the Service or perform a permitted business purpose.
ConfidentialityPersons processing Customer Personal Data are subject to confidentiality obligations and access restrictions.
SubcontractingSubprocessors are appointed under Section 10 and must be bound by appropriate processing restrictions.
Consumer rightsDonna OS will assist with access, correction, deletion, portability, opt out, and appeal related obligations as described in Section 11.
Assessment supportDonna OS will provide information reasonably necessary for a legally required data protection assessment concerning the delegated processing.
MonitoringThe Customer may monitor compliance using Section 13 and may require reasonable remediation of unauthorized processing.
CertificationAcceptance of this DPA constitutes Donna OS's certification that it understands and will comply with the restrictions applicable to it under this Schedule.

S8.1 California Specific Terms

For processing subject to the California Consumer Privacy Act as amended, the business purposes and services are those described in Schedule 1. Donna OS will provide the same level of privacy protection required by the CCPA for the delegated processing, will notify the Customer if it determines it can no longer meet its obligations, and will permit reasonable steps to stop and remediate unauthorized use. The Customer makes Customer Personal Data available to Donna OS for a business purpose and not for monetary or other valuable consideration.

S8.2 Other State Laws

For another United States State Privacy Law, references in this DPA to Controller, Processor, Personal Data, Data Subject, Sale, Share, targeted advertising, sensitive data, and consumer rights include the corresponding terms under that law. A mandatory state specific requirement applies automatically to the extent it cannot be waived and concerns the delegated processing.

Contact Information

Questions about this DPA or Donna OS's processing of Customer Personal Data may be sent to info@donna-os.com with the subject Data Protection Notice. Legal notices must also follow the notice requirements in the Agreement. Donna OS may publish updated contact information on the Donna OS legal page or in an applicable Order Form.