DATA PROCESSING AGREEMENT (DPA)

Annex 1 to the CLAI Services Agreement

 Updated: 12 August 2026

 This Data Processing Agreement (“DPA”) forms part of the CLAI Services Agreement between Customer and Dr. Nørby & Partners ApS. It applies where CLAI processes Customer Personal Data on behalf of Customer in providing the Services. Capitalized terms not defined in this DPA have the meaning given in the Services Agreement. “Data Protection Law” means the GDPR and other applicable laws governing the processing of Personal Data. “Personal Data”, “controller” and “processor” have the meanings given in applicable Data Protection Law.

 1. Roles and Processing Instructions

1.1. Customer is the controller and CLAI is the processor of Customer Personal Data, except where applicable Data Protection Law requires a different characterization for a particular processing activity.

1.2. CLAI shall process Customer Personal Data only on documented instructions from Customer and only as necessary to provide, secure, support and operate the Services. The Services Agreement, this DPA, any applicable Order Form, and Customer’s and its End Users’ use and configuration of the Services constitute Customer’s documented instructions.

1.3. CLAI shall inform Customer if, in its opinion, a documented instruction infringes applicable Data Protection Law.

 2. Details of Processing

2.1. Subject matter and purpose. CLAI processes Customer Personal Data as necessary to provide, secure, support and operate the CLAI Services in accordance with Customer’s documented instructions.

2.2. Nature of processing. Processing may include collection, storage, organization, retrieval, use, transmission to authorized Subprocessors, generation of CLAI Output, deletion and other processing necessary to provide the Services.

2.3. Duration. Processing continues for the term of the Agreement and thereafter only for the limited retention periods expressly provided in this DPA or required by applicable law.

2.4. Categories of Data Subjects. Any identified or identifiable natural person whose Personal Data is contained in Customer Input submitted, uploaded, provided or otherwise made available to the Services by or on behalf of Customer or an End User, or in CLAI Output generated from that Customer Input.

2.5. Types of Personal Data. Any Personal Data contained in Customer Input or CLAI Output, the categories and extent of which are determined by Customer and End Users through their use of the Services. The Services are not designed specifically to collect special categories of Personal Data, but such data may be included in unstructured Customer Input where Customer or an End User chooses to provide it.

 3. Confidentiality and Security

3.1. CLAI shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, taking into account the nature and risks of the processing.

3.2. Hosting and processing location. CLAI’s primary application infrastructure, storage and AI model inference are hosted or configured for processing within the European Union, including Microsoft Azure’s EU Data Zone where applicable.

3.3. Encryption. Customer Personal Data is protected using encryption in transit and at rest.

3.4. Access controls. Access to production systems and Customer Personal Data is restricted on a need-to-know and least-privilege basis. Administrative and privileged access is protected by multi-factor authentication. Access rights are reviewed and revoked when no longer required.

3.5. Human access. CLAI personnel do not routinely access or read End User conversations. Authorized CLAI personnel may access Customer Personal Data only where necessary to provide requested support or troubleshooting, investigate or mitigate a security incident, prevent or investigate material misuse of the Services, or comply with a binding legal obligation. Such access is restricted to authorized personnel and logged.

3.6. Logging. Administrative and privileged access to production systems, databases and Customer Personal Data is logged to support security monitoring and accountability.

3.7. Customer segregation. CLAI maintains logical segregation controls designed to prevent one Customer or its End Users from accessing another Customer’s Customer Input, conversations, Knowledge Layers or Customer Personal Data.

3.8. Development and production. Development and test environments are separated from production, and development and testing are not performed directly against production Customer Personal Data as a normal practice.

3.9. Vulnerability and patch management. CLAI maintains processes for applying relevant security updates and patches and for assessing and addressing identified material vulnerabilities.

3.10. Backup and recovery. CLAI maintains backup and recovery procedures designed to support restoration following system failure or data loss. Backup copies are protected against unauthorized access and are subject to the retention principles in this DPA.

3.11. Personnel confidentiality. Personnel and developers who may access production systems or Customer Personal Data are subject to contractual confidentiality obligations appropriate to their role.

3.12. Incident response. CLAI maintains procedures to identify, investigate, contain and respond to security incidents, including escalation where Customer Personal Data may be affected.

3.13. Review. CLAI may update its security measures as technology, threats and the Services evolve, provided the overall level of protection of Customer Personal Data is not materially reduced during the Subscription Term.

 4. Subprocessors

4.1. Customer gives CLAI general authorization to engage Subprocessors to process Customer Personal Data in accordance with this DPA. CLAI will impose data-protection obligations on each Subprocessor that are appropriate to the processing and consistent with applicable Data Protection Law, and CLAI remains responsible for its Subprocessors to the extent required by applicable law.

4.2. Current Subprocessor: Microsoft Azure (Microsoft) – cloud hosting, data storage and AI model inference for the Services, configured for processing within the European Union / EU Data Zone.

4.3. CLAI may appoint or replace a Subprocessor by giving Customer at least 30 days’ prior notice. Customer may object during that period on reasonable data-protection grounds. The Parties will seek in good faith to resolve the objection. If no reasonable resolution is available, CLAI may discontinue the affected processing or Customer may terminate the affected Service, in which case CLAI will refund any prepaid fees allocable to the unused portion of the affected Service.

 5. International Data Transfers

5.1. CLAI’s primary processing is configured within the European Union as described in Section 3.2. If Customer Personal Data is transferred outside the European Economic Area through an authorized Subprocessor or otherwise in providing the Services, CLAI will ensure that the transfer is made in accordance with Chapter V of the GDPR and applicable Data Protection Law.

5.2. Where required, CLAI will rely on an applicable adequacy decision, the European Commission’s Standard Contractual Clauses or another valid transfer mechanism and will implement supplementary measures where reasonably necessary to provide an essentially equivalent level of protection. Applicable Standard Contractual Clauses prevail over conflicting terms of this DPA to the extent required by those clauses.

 6. Data Subject Requests

Taking into account the nature of the Processing, CLAI shall reasonably assist Customer in responding to requests from Data Subjects concerning Customer Personal Data. If CLAI receives such a request directly in relation to Customer Personal Data, CLAI may direct the requester to Customer and will not respond substantively except on Customer’s instructions or as required by law.

 7. Personal Data Breaches

CLAI shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and shall provide information reasonably available to CLAI regarding the nature of the breach, its likely consequences and the measures taken or proposed to address it. Information may be provided in phases as it becomes available.

 8. Compliance Assistance

Taking into account the nature of the Processing and the information available to CLAI, CLAI shall provide reasonable assistance to Customer where needed for a data protection impact assessment or prior consultation with a competent supervisory authority relating to CLAI’s Processing of Customer Personal Data.

 9. Information and Audit Rights

9.1. On reasonable written request, CLAI will provide Customer with information reasonably necessary to demonstrate compliance with this DPA, including relevant information about its privacy and security measures.

9.2. If the information provided is not reasonably sufficient for Customer to meet its obligations under applicable Data Protection Law, Customer may request an audit of CLAI’s relevant processing. Audits will normally be limited to once in any 12-month period, conducted on reasonable prior notice, during normal business hours, at Customer’s expense and in a manner that minimizes disruption. The annual limit does not apply where an audit is required by a supervisory authority, follows a Personal Data Breach materially affecting Customer Personal Data, or is reasonably necessary due to credible evidence of material non-compliance.

9.3. Audits may be performed by Customer or an independent auditor bound by appropriate confidentiality obligations and may not provide access to other customers’ data, CLAI source code, or information whose disclosure would materially compromise the security of the Services.

 10. Return, Deletion and End of Processing

10.1. During the Subscription Term, Customer and End Users may delete Customer Input through the functionality made available in the Services. End Users can delete individual conversations, their conversation history and content in their Individual Knowledge Layer. Such deletion is processed as described in the Services Agreement.

10.2. On termination or expiry of the affected Services, Customer may request return of Customer Personal Data that Customer is entitled to access under the Services Agreement. Customer Administrator access rights are not expanded by termination and do not include End User conversations or Individual Knowledge Layer content. Unless returned or deleted earlier, Customer Personal Data will be deleted from active systems within 30 days after termination or expiry of the affected Services, subject to Section 10.3.

10.3. Deleted Customer Personal Data may remain in protected backup copies for a limited period under CLAI’s normal backup-retention process and will not be restored for ordinary processing. CLAI may retain information where and for so long as required by applicable law, in which case the retained information will remain protected and will be processed only for the legally required purpose.

 11. Term and Precedence

This DPA remains in effect for as long as CLAI processes Customer Personal Data on Customer’s behalf. If this DPA conflicts with the Services Agreement on a matter concerning Customer Personal Data, this DPA prevails. The governing law and jurisdiction provisions of the Services Agreement apply to this DPA, except to the extent mandatory Data Protection Law or applicable Standard Contractual Clauses require otherwise.

 End.