Business Terms

Data Processing Addendum

Version 2026-08-05-1 · Effective August 5, 2026

This Data Processing Addendum (“DPA”) forms part of the PrivateChief Service Agreement when PrivateChief processes Personal Data on behalf of a Business customer (“Customer”). Capitalized terms not defined here have the meanings in the Agreement.

1. Roles and instructions

Customer is the controller or business and PrivateChief is the processor or service provider for Personal Data submitted to Business service, except where each party independently controls account, billing, security, or legal-compliance records. PrivateChief will process Customer Personal Data only to provide, secure, support, and improve the reliability of the Service; follow documented Customer instructions; prevent fraud or harm; or comply with law.

2. Processing details

The subject matter is managed Business Chief service. Processing continues for the service term and offboarding period. Operations may include collection, organization, storage, retrieval, consultation, transmission to approved providers, analysis, generation, backup, deletion, and return. Data subjects may include Customer personnel, contractors, prospects, customers, vendors, and contacts. Data may include identifiers, contact information, communications, schedules, documents, transactions, account metadata, device information, and other content Customer chooses to process.

3. Customer obligations

Customer will provide lawful instructions, required notices, and a valid basis for processing; honor data-subject rights; configure appropriate member permissions; and avoid regulated or unusually sensitive data unless separately approved in writing. Customer will not direct PrivateChief to violate law or another person’s rights.

4. Confidentiality and security

PrivateChief will limit access to authorized people and service accounts subject to confidentiality obligations and will maintain reasonable safeguards appropriate to the risk, including access controls, encrypted network transport, protected credentials, monitoring, security updates, and encrypted recovery backups.

5. Subprocessors

Customer authorizes subprocessors needed for AI processing, hosting, storage, communications, monitoring, financial connections, payments, and support. Depending on enabled features, these may include OpenAI, Anthropic, Google, Plaid, Amazon Web Services, Stripe, application-platform providers, and communications providers. PrivateChief remains responsible for its obligations under this DPA and will provide notice before a material new category of processing where reasonably practicable.

6. Assistance and incidents

Taking into account the nature of processing, PrivateChief will reasonably assist Customer with verified data-subject requests, security inquiries, and legally required assessments. PrivateChief will notify Customer without undue delay after confirming a Personal Data breach affecting Customer-controlled data and will provide reasonably available information needed for Customer’s response.

7. Return and deletion

On request before completed offboarding, PrivateChief will provide a reasonably usable export of supported data. PrivateChief will delete or de-identify centrally held live Customer content within thirty days after completed offboarding unless law requires retention. Encrypted backups expire under the applicable retention cycle.

8. Transfers and conflicting law

PrivateChief presently provides service from the United States. Customer will not use Business service for international operations requiring transfer safeguards not established in the order summary. If applicable privacy law requires additional terms, the parties will cooperate in good faith to adopt them. If a lawful demand conflicts with Customer instructions, PrivateChief will notify Customer when legally permitted.

9. Audit information

On reasonable written request no more than annually, PrivateChief will provide information reasonably necessary to demonstrate compliance with this DPA. Any further audit must protect other customers, security, confidentiality, and system availability and may be subject to reasonable cost reimbursement.