The Prompt Group Data Processing Addendum

The Prompt Group Ltd.

Data Processing Addendum

In effect from August 24, 2026

This Data Processing Addendum (this “DPA”) is incorporated into the agreement between Provider and Customer referencing this DPA (the “Agreement”). Capitalized terms used but not defined in this DPA will be understood to have the meanings given to them in the Agreement.

1Privacy

1.1Definitions

Any capitalized terms used but not defined herein shall have the meaning given to such term in the Agreement. For the purposes of this DPA, the following terms will have the meanings set forth below:

  1. “Provider Personnel” means all employees, officers, personnel, agents, representatives, sub-contractors, vendors, independent contractors or other third party contractors of Provider.

  1. “Personal Information” means information that can identify an individual directly or indirectly and that is provided or made available to Provider by or on behalf of Customer, or that Provider accesses, collects, retrieves, receives or otherwise Processes from Customer-authorized systems, data sources or Third-Party Platforms pursuant to the Agreement.

  2. PIPEDA” means the Personal Information Protection and Electronic Documents Act (Canada) and any regulations thereunder.

  3. Privacy Laws” means PIPEDA, provincial privacy legislation, and any other applicable statute or regulation applicable to the Processing of Personal Information, as such legislation may be amended from time to time.

    1.2This DPA is subject to the terms of the Agreement and is incorporated into the Agreement by reference

    In the case of conflict or ambiguity between any provision contained in the Agreement and any provision contained in this DPA, the provision contained in this DPA will prevail.

    1.3As between Customer and Provider, all Personal Information is and will be deemed to be and remain the exclusive property of Customer

    Customer retains control of the Personal Information and remains responsible for its compliance obligations under the applicable Privacy Laws, providing any required notices and obtaining any required consents, and for the Processing instructions it gives to Provider. Customer acknowledges that Provider is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions or the Personal Information other than as required under applicable Privacy Laws.

    1.4Without limiting the foregoing, in the course of rendering the Services contemplated in the Agreement, and to the extent that Provider Processes any Personal Information in connection with the Services contemplated in the Agreement, Provider shall comply with the information privacy and security requirements set out in this DPA (“Requirements”)

    1.5. Privacy Requirements. Provider confirms that it will comply with applicable Privacy Laws in the course of Processing any Personal Information in connection with the Services contemplated in the Agreement. Further, Personal Information shall be maintained by Provider in accordance with its privacy policy, a copy of which can be found at https://agreement.thepromptgroup.com/privacy (“Privacy Policy”). The Privacy Policy is hereby incorporated into and forms a part of this DPA and the Agreement, by reference.

Without limiting the foregoing, Provider shall:

For clarity, Provider may use data derived from Personal Information for model training or fine-tuning only after such data has been de-identified so that it cannot reasonably identify Customer or any individual, and Provider will not attempt to re-identify such data.

  1. only Process Personal Information for the purposes of rendering the Services in accordance with the Agreement, including accessing authorized Customer systems and data sources, building and maintaining Customer knowledge bases and related data stores, and as otherwise instructed by Customer from time to time;

  2. not disclose Personal Information to any third party without the prior consent of Customer except to the extent that a disclosure or transfer is permitted by the Agreement or required by Law;

  3. to the extent permitted by Law, promptly notify Customer of any (i) enquiry received from an individual relating to, among other things, the individual’s right to access, modify or correct Personal Information, (ii) complaint received by Provider relating to the Processing of Personal Information, and (iii) order, demand, warrant or any other document purporting to compel the production of any Personal Information, and to promptly comply and fully co-operate with all reasonable instructions of Customer with respect to any action taken with respect to such enquiry or complaint;

  4. establish and maintain written security (including the security requirements set forth in Section 2 of this DPA), back-up and disaster recovery policies and procedures as necessary for Provider to comply with the obligations set out in this Section 1.5, and provide information regarding such policies and procedures to Customer at Customer’s request;

  5. reasonably assist Customer, at Customer’s cost, with meeting Customer's compliance obligations under applicable Privacy Laws in relation to Personal Information, considering the nature of Provider’s Processing and the Personal Information available to Provider;

  6. provide Customer (or its representatives), upon reasonable advance notice and legal grounds, with reasonable access to the records and information on Provider for the purposes of Customer fulfilling any legally required audit requirements to verify Provider’s compliance with this Section 1.5; and

  7. upon the termination or expiration of the Agreement, return or securely dispose of Personal Information in Provider’s possession or control, including copies maintained in Customer-specific knowledge bases, data warehouses, indexes, embeddings or similar derived representations, subject to any retention expressly permitted by the Agreement or required by Law.

    1.6. Third Party Sub-Processors. Customer acknowledges and agrees that Provider may engage third parties, including affiliates of Provider and other service providers, to Process Personal Information in connection with the services provided under the Agreement. Provider has entered into a written agreement with each such third party containing, in substance, data protection obligations no less protective than those in this DPA with respect to the protection of Personal Information to the extent applicable to the nature of the Services provided by such third party.

2Security Requirements

2.1Security Requirements

Provider will use commercially reasonable security measures for its computer systems and information storage facilities which are designed to safeguard against the unauthorized destruction, loss, alteration of, Processing or access to Personal Information, whether such information is: (a) on Provider’s systems or stored in Provider’s facilities; (b) in transit or being disposed of; or (c) in hard copy or electronic format.

2.2Security Incident

If Provider discovers any (1) theft or unauthorized loss or access to Personal Information or other illegal Processing of Personal Information (each a “Security Incident”), Provider will as soon as reasonably possible: (a) notify Customer of such Security Incident; and (b) if the applicable Personal Information was in the possession of Provider at the time of such Security Incident, Provider shall: (i) start an investigation of the Security Incident and (ii) provide Customer with a written report on the outcome of its investigation.

2.3Information Security Guidelines

Provider has adopted, documented, implemented and shall adhere to commercially reasonable written information security guidelines for maintaining security controls designed to protect Personal Information against accidental, unauthorized or unlawful destruction, loss, alteration, disclosure, and access, and against all other unlawful activities and shall reasonably discuss such guidelines with Customer. Provider’s information security guidelines shall include physical, organizational, administrative and technical controls. The controls shall relate to the collection, maintenance (including access rights), transmittal and disposal of Personal Information.

2.4Provider Personnel

With respect to any Provider Personnel who at any time have access rights to Personal Information, Provider will: (a) limit such access to only those Provider Personnel with a need for such access in order to perform Provider’s obligations under the Agreement; and (b) advise such Provider Personnel (via training or other processes designed to acquaint such person with the security guidelines/programs instituted by Provider and the Requirements under this DPA and applicable Laws, prior to providing them with such access rights and obligate such Provider Personnel to abide by the security guidelines/programs instituted by Provider.