Data Processing Addendum

Last updated: August 11, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between WarmGTM ("Processor") and the customer ("Controller") and applies where WarmGTM processes personal data on the Controller's behalf in the course of providing the Service.

1. Definitions

"Personal Data," "Processing," "Data Subject," "Controller," and "Processor" have the meanings given under applicable data protection law, including the GDPR where relevant.

2. Roles of the Parties

As between the parties, the Controller determines the purposes and means of processing personal data submitted to the Service. WarmGTM acts as a Processor, processing personal data solely on documented instructions from the Controller, including as set out in the underlying agreement and this DPA.

3. Processing Instructions

WarmGTM will process personal data only to provide, maintain, and support the Service, and will not use personal data for its own independent purposes, except as permitted by applicable law.

4. Confidentiality

WarmGTM ensures that personnel authorized to process personal data are subject to confidentiality obligations.

5. Security Measures

WarmGTM implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure, consistent with the risk presented by the processing.

6. Subprocessors

WarmGTM may engage subprocessors to support the Service (for example, hosting and infrastructure providers). WarmGTM remains responsible for subprocessors' compliance with data protection obligations equivalent to those in this DPA, and will make reasonable efforts to notify Controllers of material changes to its subprocessor list.

7. Assistance with Data Subject Rights

WarmGTM will provide reasonable assistance to the Controller in responding to requests from data subjects to exercise their rights under applicable data protection law.

8. International Transfers

Where personal data is transferred outside the jurisdiction in which it was collected, WarmGTM relies on appropriate safeguards, such as standard contractual clauses, to the extent required by applicable law.

9. Data Breach Notification

WarmGTM will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably necessary for the Controller to meet its own notification obligations.

10. Audit Rights

Upon reasonable request, WarmGTM will make available information reasonably necessary to demonstrate compliance with this DPA.

11. Term & Deletion

Upon termination of the Service, WarmGTM will delete or return personal data processed on the Controller's behalf, except where retention is required by law.

12. Contact Us

Questions about this DPA, or requests for an executed copy referencing your organization, can be sent to legal@warmgtm.com.