This Data Processing Addendum (“DPA”) forms part of the agreement between Weesp AI, Inc. (“Company” or “Processor”) and the customer identified in the applicable Services Order Form (“Customer” or “Controller”), consisting of that Order Form and the Bracket Standard Terms incorporated into it (collectively, the “Agreement”). This DPA is effective as of the Effective Date of the Agreement and is incorporated into and governed by the Agreement. Capitalized terms used but not defined herein have the meanings ascribed to them in the Agreement.

1. Definitions

1.1 “Applicable Data Protection Law” means all applicable laws and regulations relating to the processing of Personal Data, including without limitation the Israeli Protection of Privacy Law, 5741-1981, and the regulations promulgated thereunder (including the Protection of Privacy Regulations (Data Security), 5777-2017 (the “Data Security Regulations”), the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001, and, to the extent applicable, the Privacy Protection Regulations (Instructions for Data that was Transferred to Israel from the European Economic Area), 5783-2023), in each case as amended from time to time, and directives and guidelines of the Israeli Privacy Protection Authority to the extent legally binding, and, to the extent applicable, the EU General Data Protection Regulation (EU 2016/679) (“GDPR”), the UK GDPR, and any other applicable data protection, privacy, or data security laws.

1.2 “Controller” means the entity that determines the purposes and means of the processing of Personal Data.

1.3 “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.

1.4 “Personal Data” means any information relating to an identified or identifiable natural person that is processed by Company on behalf of Customer in connection with the Services, including Customer Data as defined in the Agreement that constitutes personal data under Applicable Data Protection Law.

1.5 “Personal Data Breach” means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

1.6 “Processing” (and “Process” and “Processed”) means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.

1.7 “Processor” means the entity that processes Personal Data on behalf of the Controller. References in this DPA to “Controller” and “Processor” include, respectively, the controller of a database and the holder (מחזיק) of a database within the meaning of the Protection of Privacy Law, 5741-1981.

1.8 “Subprocessor” means any third party engaged by Company to process Personal Data on behalf of Customer.

2. Roles and Processing Instructions

2.1 The parties acknowledge that: (a) Customer is the Controller of Personal Data; (b) Company is the Processor of Personal Data; and (c) Company shall process Personal Data only on documented instructions from Customer, including the instructions set forth in the Agreement and this DPA, unless required to do otherwise by Applicable Data Protection Law.

2.2 Company shall promptly inform Customer if, in Company’s reasonable opinion, an instruction from Customer infringes Applicable Data Protection Law.

2.3 Company shall process Personal Data only for the purpose of providing the Services and as otherwise instructed by Customer in writing. Company shall not process Personal Data for any other purpose, including without limitation for model training, algorithm development, or product improvement, without Customer’s prior written consent.

3. Security Controls

3.1 Company shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against Personal Data Breaches and to ensure a level of security appropriate to the risk, including at a minimum:

3.2 Company shall review and, where necessary, update its security measures at least annually and in response to any changes in the risk landscape.

3.3 Customer shall notify Company in writing of the security level applicable under the Data Security Regulations to the database(s) containing the Personal Data and of any change thereto, and Company shall implement the measures required of it as a holder of such database(s) under the Data Security Regulations for that level.

3.4 Upon Customer’s written request, no more than once per calendar year, Company shall provide Customer with written confirmation of its implementation of its data security obligations under this DPA. The parties intend this DPA to satisfy the requirements applicable to their engagement under Regulation 15 of the Data Security Regulations.

4. Personal Data Breach Notification

4.1 Company shall notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Customer’s Personal Data. Such notification shall include, to the extent then known and as information becomes available:

4.2 Company shall provide Customer with timely updates as additional information about the Personal Data Breach becomes available. Company shall cooperate fully with Customer in any investigation of the Personal Data Breach and shall take all reasonable steps to mitigate the effects of the breach and prevent its recurrence.

4.3 Company shall maintain records of all Personal Data Breaches affecting Customer’s Personal Data, including those for which notification to an authority or Data Subjects is not required under Applicable Data Protection Law, and shall make such records available to Customer upon request.

4.4 As between the parties, Customer is responsible for any notification of a Personal Data Breach to the Israeli Privacy Protection Authority, any other competent authority, or Data Subjects, except where Applicable Data Protection Law requires such notification directly by Company. Company shall not notify any authority or Data Subject of a Personal Data Breach affecting Customer’s Personal Data unless required by Applicable Data Protection Law, and shall provide reasonable cooperation and information to support Customer’s notifications.

5. Subprocessor Disclosure and Management

5.1 Customer hereby provides general written authorization for Company to engage Subprocessors listed in Schedule 1 to this DPA (the “Authorized Subprocessors”). Company shall not engage any new Subprocessor or replace any existing Subprocessor without providing Customer with at least thirty (30) days’ prior written notice (“Subprocessor Notice”). Subprocessor Notices may be given by email to Customer’s designated contact or by updating the Subprocessor list published at getbracket.io/legal/dpa, provided Company offers a mechanism for Customer to receive notice of such updates. Where a Subprocessor must be replaced urgently for reasons outside Company’s reasonable control (including security, insolvency, or discontinuation of service), Company may effect the replacement and shall notify Customer as soon as reasonably practicable, and Customer’s objection rights under Section 5.2 shall apply following such notice.

5.2 If Customer reasonably objects to the engagement or replacement of a Subprocessor based on a legitimate data protection or security concern, Customer must notify Company in writing within fifteen (15) days of receiving the Subprocessor Notice. The parties shall work in good faith to resolve Customer’s objection. If the parties are unable to resolve the objection within thirty (30) days of Customer’s notice, Customer may terminate the Agreement or the affected Services by providing written notice to Company without incurring any early termination fees.

5.3 Company shall impose on each Subprocessor, by way of a written contract, data protection obligations that are no less protective in all material respects than those set out in this DPA, to the extent applicable to the nature of the services provided by such Subprocessor. Company shall remain fully liable to Customer for the performance of each Subprocessor’s obligations under such contract.

5.4 Company shall maintain a current and complete list of all Subprocessors engaged in connection with the Services and shall make such list available to Customer upon request. Company shall promptly update Schedule 1 to reflect any changes to its Subprocessor roster.

6. Data Residency

6.1 Unless otherwise agreed in writing by the parties, Company shall store Personal Data at rest, and shall process Personal Data, only in Israel, the United States, and/or the European Economic Area, and only with the Authorized Subprocessors listed in Schedule 1 (as updated in accordance with Section 5), provided that limited remote access for support, maintenance, or security purposes may occur from other locations where such access is protected by safeguards consistent with this DPA and Applicable Data Protection Law. Without limiting the foregoing: (a) any transfer of Personal Data outside of Israel shall be made in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001, by satisfying a condition for lawful transfer set out therein and by obtaining from the recipient a binding written undertaking to take adequate measures to ensure the privacy of the Data Subjects and to protect the Personal Data at a level no less protective than that required by this DPA and applicable requirements of Israeli law; and (b) Company shall not transfer Personal Data to any other jurisdiction without (i) Customer’s prior written consent and (ii) appropriate safeguards in place.

6.2 Company shall, upon Customer’s request, provide Customer with written confirmation of the countries or regions in which Personal Data is stored or processed.

7. Data Subject Rights

7.1 Company shall assist Customer, by appropriate technical and organizational measures, in fulfilling Customer’s obligation to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction of processing, data portability, and objection.

7.2 Company shall promptly notify Customer (and in any event within five (5) business days) upon receiving any request from a Data Subject relating to Personal Data processed under this DPA, and shall not respond to any such request except on the documented instructions of Customer or as required by Applicable Data Protection Law.

8. Confidentiality of Processing

8.1 Company shall ensure that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations with respect to such Personal Data, whether under contract or by operation of law.

8.2 Company shall limit access to Personal Data to personnel who require such access for the purposes of providing the Services.

9. Audit Rights

9.1 Company shall make available to Customer all information reasonably necessary to demonstrate Company’s compliance with this DPA and shall, upon reasonable notice (not less than thirty (30) days’ notice except in the case of a Personal Data Breach or a regulatory investigation), permit Customer or Customer’s designated third-party auditor to conduct an audit of Company’s data processing activities relevant to this DPA, no more than once per calendar year unless required more frequently by Applicable Data Protection Law or a regulatory authority. Audits shall be conducted during normal business hours, in a manner that does not unreasonably disrupt Company’s operations, subject to reasonable confidentiality obligations, and shall not extend to data or systems of Company’s other customers; the auditor shall not be a competitor of Company. Customer shall bear the costs of the audit. Company may first satisfy an audit request by providing written responses, certifications, third-party assessment reports, and other documentation reasonably demonstrating compliance, and an on-site audit shall be conducted only to the extent such materials do not reasonably do so.

9.2 Company shall cooperate with any inspection or inquiry by a data protection supervisory authority relating to Company’s processing of Personal Data under this DPA.

10. Return and Deletion of Personal Data

10.1 Upon termination or expiry of the Agreement for any reason, Company shall, at Customer’s election:

and in either case Company shall provide Customer with written certification of the return or deletion, as applicable, within five (5) business days of completion. If Customer does not notify Company of its election within thirty (30) days after termination or expiry, Company shall proceed under clause (b).

10.2 Company may retain Personal Data beyond the thirty (30) day period only to the extent and for as long as required by applicable law or regulation, in which case Company shall notify Customer of such requirement, shall continue to protect such Personal Data in accordance with this DPA, and shall Process it only as necessary to comply with such law.

11. General

11.1 In the event of any conflict or inconsistency between this DPA and the Agreement with respect to the subject matter of this DPA, this DPA shall prevail as between the incorporated documents; the Order Form controls over this DPA in all matters.

11.2 This DPA shall be governed by the same governing law as the Agreement.

11.3 If any provision of this DPA is held to be invalid, illegal, or unenforceable, the remaining provisions shall remain in full force and effect.

11.4 Each party’s aggregate liability arising out of or relating to this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set forth in the Agreement, and any amounts payable under this DPA count toward the liability cap in the Agreement, except to the extent Applicable Data Protection Law provides otherwise.

Schedule 1 to Annex C — Authorized Subprocessors

The following is a list of Subprocessors authorized by Customer as of the Effective Date. Each entry identifies the Subprocessor, the processing activity, the primary processing locations, and the safeguards in place. Company shall update this Schedule and provide notice in accordance with Section 5 of this DPA before adding or replacing any Subprocessor.

SubprocessorProcessing activityLocationsSafeguards
Google LLC (Google Cloud Platform)Cloud hosting and infrastructure; Gemini model APIsUnited States / EEAGoogle Cloud Data Processing Addendum, including transfer safeguards
Google LLC (Google Workspace / Gmail)Email processing for order-package intake and delivery of findings reportsUnited States / EEAGoogle Workspace Data Processing Amendment, including transfer safeguards
Anthropic, PBCClaude model APIs (where Customer elects to run tasks on Claude models)United StatesAnthropic Commercial Terms and Data Processing Addendum (no training on Customer Data), including transfer safeguards
Twilio Inc. (SendGrid)Transactional email deliveryUnited StatesTwilio Data Protection Addendum, including transfer safeguards
Neon, Inc.Managed database servicesUnited States / EEAProvider Data Processing Agreement, including transfer safeguards
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsUnited States / EEASentry Data Processing Addendum, including transfer safeguards
Descope Inc.Authentication and identity managementUnited States / IsraelProvider Data Processing Addendum, including transfer safeguards