DATA PROCESSING ADDENDUM

Data Processing Addendum (DPA)

Last updated: April 20, 2026 · Effective immediately

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written or electronic agreement between Vedric ("Vedric," "Processor") and the Customer organization ("Customer," "Controller") (collectively, the "Agreement") to reflect the parties' agreement regarding the processing of personal data subject to the General Data Protection Regulation 2016/679 ("GDPR"), the United Kingdom Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act as amended ("CCPA"), and other analogous data protection laws (collectively, "Data Protection Laws").

This DPA is incorporated into the Agreement by reference and applies to the extent Vedric processes personal data on behalf of Customer in providing the Services.

1. Definitions

Terms not defined here have the meaning given in Data Protection Laws or the Agreement. "Customer Personal Data" means personal data contained in Customer Data that Vedric processes on behalf of Customer in performing the Services.

2. Roles of the parties

For Customer Personal Data, Customer is the Controller (or Business under CCPA) and Vedric is the Processor (or Service Provider under CCPA). Each party will comply with its respective obligations under Data Protection Laws.

Vedric will process Customer Personal Data only (a) on the documented instructions of Customer (including those set forth in the Agreement and through configuration of the Services), (b) as necessary to provide and support the Services, or (c) as required by applicable law (in which case Vedric will, where lawful, inform Customer of the legal requirement before processing).

3. Subject matter and details of processing

Subject matter: Vedric's processing of Customer Personal Data in connection with delivering the Services.

Duration: The term of the Agreement, plus any post-termination period required to return or delete Customer Personal Data per Section 9 below.

Nature and purpose: Behavioral telemetry collection, processing, analysis, alerting, hunting, investigation, and response support, as configured by Customer.

Categories of data subjects: Personnel of Customer whose endpoints are monitored by the Vedric agent (including employees, contractors, and other authorized users).

Categories of personal data: Behavioral metadata about endpoint activity, including process activity, authentication events, network destination metadata, file system activity metadata, persistence mechanism inventory, and decoded script-block content where host logging is enabled. End-user identifiers are anonymized at the source. Vedric does not collect file contents, keystrokes, screenshots, browser content, message bodies, clipboard data, or audio/video input.

Special categories: Vedric does not intentionally process special categories of personal data (Article 9 GDPR). Customer should not configure the Services to process such data.

4. Confidentiality

Vedric will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and have received training in the protection of personal data.

5. Security measures

Vedric implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures include encryption of data in transit and at rest, multi-factor authentication for administrative access, role-based access controls, payload integrity verification on agent communications, append-only audit trails for sensitive actions, and tenant isolation enforced at the data access layer. Third-party security assessments are scheduled. Vedric may update these measures from time to time provided that the security level is not materially diminished.

6. Subprocessors

Customer authorizes Vedric to engage subprocessors to assist in providing the Services. Vedric will (a) maintain a current list of subprocessors at vedric.io/subprocessors; (b) provide at least thirty (30) days' prior notice before engaging a new subprocessor that processes Customer Personal Data, except where prevented by law or where the new subprocessor replaces an existing one performing the same function; (c) impose data protection obligations on each subprocessor that are no less protective than those in this DPA; and (d) remain liable for the acts and omissions of its subprocessors as if they were its own.

Customer may object on reasonable grounds to a new subprocessor by written notice within fifteen (15) days of Vedric's notification. The parties will discuss in good faith. If the parties cannot reach a resolution, Customer may terminate the affected portion of the Services as its exclusive remedy and receive a pro-rated refund of prepaid fees.

7. International data transfers

Where Customer Personal Data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country not deemed adequate by the relevant authority, the transfer will be governed by the Standard Contractual Clauses approved by the European Commission (Module 2: Controller to Processor) or the UK International Data Transfer Addendum, as applicable, which are incorporated into this DPA by reference. Customer is the data exporter; Vedric is the data importer. The parties agree to the optional clauses of the Standard Contractual Clauses to the extent applicable.

8. Data subject requests

Vedric will, taking into account the nature of the processing, provide reasonable assistance to Customer (by appropriate technical and organizational measures) in fulfilling Customer's obligations to respond to requests by data subjects exercising their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection). If Vedric receives a request directly from a data subject regarding Customer Personal Data, Vedric will direct the data subject to Customer.

9. Return or deletion of Customer Personal Data

Upon termination or expiration of the Agreement, Vedric will, at Customer's choice, delete or return Customer Personal Data to Customer, and delete existing copies, unless retention is required by applicable law. Upon Customer's written request, Vedric will provide written confirmation of deletion. Customer Personal Data may persist in routine backup copies for a limited operational window, after which it is overwritten in the ordinary course.

10. Personal data breach notification

Vedric will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Such notification will include, to the extent then known: the nature of the breach, the categories and approximate volume of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach. Vedric will provide reasonable cooperation and assistance to Customer in investigating, mitigating, and remedying the breach and in fulfilling Customer's notification obligations to supervisory authorities and data subjects.

11. Audit rights

Vedric will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. On Customer's reasonable written request and not more than once per calendar year, Vedric will provide a summary of the results of its third-party security assessment program, once such assessments have been completed, under non-disclosure obligations. To the extent the foregoing does not satisfy Customer's audit obligations under Article 28 GDPR, Customer may conduct or commission an audit (at Customer's cost) of Vedric's processing activities relevant to this DPA, on at least sixty (60) days' written notice, conducted in a manner that minimizes disruption to Vedric's operations and protects the confidentiality of other customers and third parties.

12. CCPA-specific terms

To the extent Vedric processes personal information of California residents on behalf of Customer, Vedric is a "Service Provider" as defined in the CCPA. Vedric (a) will not sell or share such personal information; (b) will not retain, use, or disclose such personal information for any purpose other than the specific purpose of performing the Services or as otherwise permitted by the CCPA; (c) will not retain, use, or disclose such personal information outside of the direct business relationship with Customer; and (d) will not combine such personal information with information received from other sources, except as permitted by the CCPA.

13. Conflicts

In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Customer Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.

14. Execution

By accepting the Terms of Service or by using the Services, Customer is deemed to have accepted this DPA. For Customers requiring a counter-signed copy or modifications to address specific regulatory requirements, contact legal@vedric.io.