Exhibit A
Data Processing Addendum (DPA)
Effective Date: January 13, 2026
This Data Processing Addendum ("DPA") forms part of the Plumloom Terms of Service (the "Agreement") between Plumloom LLC ("Company" or "Processor") and the customer entity or individual ("Customer" or "Controller").
This DPA applies only to the extent Company processes Personal Data on Customer's behalf in connection with the Services.
1. Incorporation; Precedence
This DPA is incorporated into and forms part of the Agreement.
If there is a conflict between this DPA and the Terms of Service on data-protection matters, this DPA controls.
All other matters are governed by the Terms of Service.
2. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
- "Personal Data" has the meaning given under Applicable Data Protection Laws.
- "Customer Data" has the meaning set forth in the Terms of Service.
- "Service Data" and "Aggregated Data" have the meanings set forth in the Terms of Service.
- "Applicable Data Protection Laws" means laws applicable to the Processing of Personal Data, including (where applicable) GDPR, UK GDPR, and CCPA/CPRA.
3. Roles of the Parties
Customer is the Controller of Customer Data that constitutes Personal Data.
Company acts as a Processor (or service provider) on Customer's behalf.
Nothing in this DPA limits Customer's responsibility to comply with Applicable Data Protection Laws.
For purposes of the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"), Company acts as a "service provider" or "processor" and shall not:
- (a) sell or share Personal Data;
- (b) retain, use, or disclose Personal Data for any purpose other than providing the Services as specified in the Agreement; or
- (c) combine Personal Data received from Customer with Personal Data obtained from other sources except as permitted by CCPA/CPRA.
4. Scope and Purpose of Processing
Company will Process Personal Data only to:
- provide, operate, secure, maintain, and support the Services;
- comply with Customer's documented instructions as reflected in Customer's use and configuration of the Services; and
- comply with applicable law.
Company will not use Customer Data or Outputs to train Company-owned AI systems.
Company may use Service Data and Aggregated Data as described in the Agreement.
5. Customer Instructions and Responsibilities
Customer represents and warrants that:
- it has a lawful basis to Process Personal Data;
- its instructions comply with Applicable Data Protection Laws; and
- it will not submit Prohibited Data except as expressly permitted under the Agreement.
Customer is solely responsible for the accuracy, quality, and legality of Customer Data.
6. Sub-Processors
Company may engage sub-processors to Process Personal Data for the Services, subject to written obligations consistent with this DPA.
Company will maintain a current list of sub-processors on its trust page and provide reasonable advance notice of material changes.
If Customer reasonably objects to a new sub-processor on data-protection grounds and the parties cannot resolve the objection, Customer's sole remedy is to terminate the affected Order in accordance with the Agreement.
Customer may audit Company's compliance with this DPA no more than once per twelve (12) month period, upon reasonable advance written notice and subject to confidentiality obligations. Company may satisfy audit requests by providing third-party security reports or certifications (by way of example SOC 2) where available. Audits shall not unreasonably interfere with Company's operations.
7. Security Measures
Company will implement and maintain administrative, technical, and physical safeguards appropriate to the nature of the Services.
A summary of Company's security measures is described in Exhibit B (Security Measures).
Company may update its security measures provided such updates do not materially reduce overall protection.
8. Security Incidents
Company will notify Customer without undue delay, and in any event no later than seventy-two (72) hours after confirmation of a Security Incident involving Personal Data, unless a shorter period is required by Applicable Data Protection Laws.
Company will provide reasonable information to allow Customer to meet its regulatory obligations.
9. Data Subject Rights Assistance
Taking into account the nature of the Processing, Company will provide reasonable assistance to Customer in responding to data-subject requests and regulatory inquiries, where required by Applicable Data Protection Laws.
Assistance beyond self-service features may be provided on a reasonable, time-and-materials basis and does not include legal advice.
10. Deletion and Return of Data
10.1 Data Export
During the Order Term, Customer may request export of Customer Data reasonably available through the Services. At this time, exportable data is limited to account information (such as name and login email) and user-provided content, including evaluator instructions, input prompts, and test data. Evaluation results, scores, and system-generated analytics may not be exportable at this time. Company may expand export capabilities over time at its discretion.
10.2 Deletion
Following termination or expiration of the Agreement, Company will delete or return Customer Data within 30 days, unless retention is required by law or permitted under the Agreement. Archived backups may be retained in accordance with standard retention practices and remain subject to confidentiality obligations.
11. International Data Transfers
Where Applicable Data Protection Laws require a transfer mechanism, the parties incorporate by reference the EU Standard Contractual Clauses (Decision (EU) 2021/914) and applicable UK or Swiss addenda, which are deemed executed upon acceptance of the Agreement.
12. Liability; Indemnity
Liability and indemnification obligations arising from Processing under this DPA are subject to the limitations, exclusions, and caps set forth in the Agreement.
Nothing in this DPA expands Company's liability beyond what is expressly stated in the Agreement.
13. Term; Survival
This DPA remains in effect for the duration of the Agreement and terminates automatically upon deletion of Customer Data.
Sections intended to survive (including security, deletion, and liability provisions) survive termination to the extent applicable.
Annex 1 — Details of Processing (Summary)
| Item | Description |
|---|---|
| Purpose | Provision, operation, security, and support of the Services |
| Categories of Data Subjects | Customer's users and individuals referenced in Customer Data |
| Categories of Personal Data | Names, email addresses, identifiers, prompts, configurations, evaluation inputs/outputs |
| Processing Activities | Hosting, storage, evaluation runs, reporting, support, security |
| Retention | As set forth in the Agreement |
| Subprocessor List | Company will maintain a current list of subprocessors upon request or on its trust page. |