DPA
Version 1 — Effective June 25, 2026
This Data Processing Addendum ("Addendum") forms part of, and is incorporated into, the master services or subscription agreement between DealAdvisorHQ ("DealAdvisorHQ," "we," or "us") and the customer and its affiliates (collectively, "Customer") (the "Agreement"). Where DealAdvisorHQ's affiliates enter into order forms or statements of work with Customer, references to "DealAdvisorHQ" mean the affiliate entering into that document, including, where it is a data importer, its applicable contact details.
Terms used but not defined here have the meanings given in the Agreement. Except as modified by this Addendum, the Agreement remains in full force. This Addendum applies to the processing of Customer Personal Data by DealAdvisorHQ as a Processor, and does not apply to the extent DealAdvisorHQ processes Personal Data as a Controller.
1. Definitions
In this Addendum, the following terms have the meanings set out below. Terms such as "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," and "Supervisory Authority" carry the meanings given in the GDPR and, where relevant, are read to align with the equivalent terms in other applicable Data Protection Law.
- "Affiliate" — any entity that controls, is controlled by, or is under common control with a party, or that is a successor to such an entity or its business and assets.
- "Applicable Laws" — the laws of the European Union or its Member States and the laws applicable in the United Kingdom, the United States, Switzerland, or Singapore, in each case as applicable to the relevant Customer Personal Data.
- "Customer Personal Data" — any Personal Data that DealAdvisorHQ processes on the Customer's behalf as a Processor under or in connection with the Agreement, and in respect of which the Customer is subject to applicable Data Protection Law. Customer Personal Data excludes DealAdvisorHQ CRM Data.
- "Data Protection Law" — all privacy and data protection laws applicable to the processing under the Agreement, which may include the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), UK Data Protection Law, Swiss Data Protection Law, EEA Data Protection Law, and Singapore Data Protection Law, each as amended or superseded over time.
- "EEA Data Protection Law" — the GDPR and any EEA Member State laws implementing or supplementing it, as amended or superseded over time.
- "GDPR" — Regulation (EU) 2016/679 (the EU General Data Protection Regulation).
- "UK GDPR / UK Data Protection Law" — the UK GDPR (as defined in the UK Data Protection Act 2018), the UK Data Protection Act 2018, the UK Privacy and Electronic Communications Regulations 2003, and related laws, each as amended or superseded over time.
- "Swiss Data Protection Law" — the Swiss Federal Act on Data Protection and its ordinances, as amended or superseded over time.
- "Singapore Data Protection Law" — the Singapore Personal Data Protection Act 2012 ("PDPA"), as amended or superseded over time.
- "Standard Contractual Clauses" — as applicable, the EEA Standard Contractual Clauses, the UK Standard Contractual Clauses, and the Swiss Standard Contractual Clauses.
- "EEA Standard Contractual Clauses" — the controller-to-processor (Module 2), processor-to-controller (Module 4), and processor-to-processor (Module 3) modules of the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021. The Parties' selections for optional provisions are set out in Schedule 1.
- "UK Addendum" — the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under s119A(1) of the Data Protection Act 2018, in force from 21 March 2022.
- "UK Standard Contractual Clauses" — the EEA Standard Contractual Clauses as amended and incorporated by the UK Addendum and supplemented by the tables in Schedule 3.
- "Swiss Standard Contractual Clauses" — the EEA Standard Contractual Clauses as amended by Schedule 2 (Swiss Modification).
- "Restricted Transfer" — a transfer of Customer Personal Data that is only permitted under the GDPR, UK Data Protection Law, Swiss Data Protection Law, or Singapore Data Protection Law (as applicable) if a Transfer Mechanism is in place. A transfer from the EEA, UK, or Switzerland is not a Restricted Transfer where the destination is covered by an adequacy decision, a valid derogation applies, or the importer is otherwise within the territorial scope of the GDPR for that transfer.
- "Transfer Mechanism" — the Standard Contractual Clauses or any other valid safeguard that permits a transfer of Personal Data under the applicable Data Protection Law.
- "Subprocessor" — any third party (including a DealAdvisorHQ Affiliate) engaged by or on behalf of DealAdvisorHQ to process Customer Personal Data.
- "Services" — the services provided under the Agreement, including any support and cloud or hosted services, as applicable.
- "DealAdvisorHQ CRM Data" — data (including contact information such as names, email addresses, and telephone numbers) provided by the Customer that DealAdvisorHQ needs to manage its own relationship with the Customer, which DealAdvisorHQ processes as an independent Controller.
2. Application of These Terms
- These terms apply only where Data Protection Law governs the processing of Personal Data under the Agreement, and then only to the extent applicable.
- Where capitalized data-protection terms are used, they carry the meaning given in the GDPR and are construed to align with equivalent terms under other applicable Data Protection Law. "Data exporter" and "data importer" have the meanings given in the applicable Standard Contractual Clauses.
3. Processing of Customer Personal Data
- This Addendum applies to DealAdvisorHQ's processing of Customer Personal Data while providing the Services as a Processor. For the purposes of the GDPR and UK GDPR, DealAdvisorHQ is the Processor and the Customer is the Controller.
- DealAdvisorHQ will process Customer Personal Data only on the Customer's documented instructions, unless processing is required by Applicable Laws to which DealAdvisorHQ is subject (or by a court or authority), in which case DealAdvisorHQ will, where permitted, inform the Customer of that requirement before processing.
- The Customer instructs DealAdvisorHQ (and authorizes it to instruct each Subprocessor) to process and transfer Customer Personal Data as reasonably necessary to provide the Services consistent with the Agreement. The Customer represents that it is authorized to give these instructions and that they comply with Applicable Laws. If DealAdvisorHQ believes an instruction violates Applicable Laws, it will not act on it and will notify the Customer.
- Schedule 4 sets out the information about DealAdvisorHQ's processing required by Article 28(3) of the GDPR (and equivalent provisions of other Data Protection Law). The Customer may make reasonable written amendments to Schedule 4 as needed to meet those requirements, consistent with the scope of the Services.
- Nothing in this Addendum prevents DealAdvisorHQ from processing DealAdvisorHQ CRM Data for its own purposes as an independent Controller, subject to its compliance with Data Protection Law.
4. Personnel
DealAdvisorHQ will ensure that any employee, agent, or contractor who may access Customer Personal Data is bound by appropriate confidentiality obligations in respect of that data.
5. Security
- Taking into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, and the risks to data subjects, DealAdvisorHQ will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which may include the measures described in Article 32(1) of the GDPR (or equivalent provisions of other Data Protection Law).
- In assessing the appropriate level of security, DealAdvisorHQ may take account of the risks presented by the processing, in particular from a Personal Data Breach. A summary of the current measures is set out in Annex II to Schedule 1.
6. Subprocessing
- The Customer authorizes DealAdvisorHQ (and each Subprocessor) to appoint Subprocessors in accordance with this Section and any restrictions in the Agreement.
- DealAdvisorHQ may continue to use the Subprocessors it has engaged as of the date of this Addendum.
- DealAdvisorHQ will maintain a list of Subprocessors and post notice of any new Subprocessor, with details of the processing involved. Customers who subscribe to notifications (by emailing dpa@dealadvisorhq.com) will receive notice of such postings. If, within 14 days of notice, the Customer raises reasonable written objections, DealAdvisorHQ will not appoint that Subprocessor (or disclose Customer Personal Data to it) until it has taken reasonable steps to address the objection and explained those steps in writing.
- DealAdvisorHQ will ensure each Subprocessor is bound by a written contract providing at least the same level of protection for Customer Personal Data as this Addendum.
- DealAdvisorHQ remains responsible for its obligations under this Addendum and for any acts or omissions of a Subprocessor that cause DealAdvisorHQ to breach this Addendum.
7. Data Subject Rights
- The Services provide the Customer with means to retrieve, correct, delete, or restrict Customer Personal Data, which the Customer may use to assist with its obligations under Data Protection Law, including responding to data subject requests.
- DealAdvisorHQ will promptly notify the Customer if it receives a data subject request relating to Customer Personal Data and will not respond except as required by Applicable Laws, in which case it will, where permitted, inform the Customer of that requirement first.
- On request, the Customer will reimburse DealAdvisorHQ's actual, documented costs of assisting under this Section.
8. Personal Data Breach
- DealAdvisorHQ will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing enough information to enable the Customer to meet its own notification obligations.
- DealAdvisorHQ will cooperate with the Customer and take reasonable steps appropriate to the circumstances to investigate, mitigate, and remediate the breach.
9. Deletion or Return of Customer Personal Data
- Subject to Section 9.2, within 120 days after the end of the applicable retention period following expiration or termination of the Agreement, DealAdvisorHQ will permanently delete Customer Personal Data, unless the Customer has already deleted it.
- DealAdvisorHQ may retain Customer Personal Data to the extent and for the period required by Applicable Laws (and may retain Customer staff business-contact information), provided it keeps the data confidential and processes it only for the purpose requiring its retention.
10. Impact Assessments and Audits
- DealAdvisorHQ will provide reasonable assistance with data protection impact assessments and prior consultations with authorities that the Customer reasonably considers required under Articles 35–36 of the GDPR (or equivalents), taking into account the nature of the processing and the information available to DealAdvisorHQ. On request, the Customer will reimburse DealAdvisorHQ's actual, documented costs.
- DealAdvisorHQ maintains an information security program for the Services aligned to recognized industry standards.
- Where DealAdvisorHQ obtains third-party security audit or assessment reports for the Services, it will, on the Customer's reasonable request, make available a copy (or a summary) so the Customer can verify DealAdvisorHQ's compliance. Such reports are DealAdvisorHQ's confidential information.
- The Customer agrees to exercise any audit or inspection right it may have (including under the Standard Contractual Clauses, where they apply) by instructing DealAdvisorHQ to facilitate the process described above. Where the Standard Contractual Clauses apply, nothing in this Section varies them or affects any authority's or data subject's rights under them.
11. Restricted Transfers
- The Parties will ensure a valid Transfer Mechanism is in place for any Restricted Transfer.
- For an EEA or Swiss Restricted Transfer from a controller (exporter) to DealAdvisorHQ as processor (importer), the EEA Controller-to-Processor SCCs (Module 2) are incorporated as supplemented by Schedule 1, and, for Swiss transfers, as amended by Schedule 2.
- For an EEA or Swiss Restricted Transfer from DealAdvisorHQ as processor (exporter) to a controller (importer), the EEA Processor-to-Controller SCCs (Module 4) are incorporated as supplemented by Schedule 1, and, for Swiss transfers, as amended by Schedule 2.
- For a UK Restricted Transfer from a controller (exporter) to DealAdvisorHQ as processor (importer), the UK Controller-to-Processor SCCs are incorporated as supplemented by Schedule 3.
- For a UK Restricted Transfer from DealAdvisorHQ as processor (exporter) to a controller (importer), the UK Processor-to-Controller SCCs are incorporated as supplemented by Schedule 3.
- Where DealAdvisorHQ engages a Subprocessor for processing that involves a transfer within the meaning of Chapter V of the GDPR or UK GDPR, the Parties agree that the EEA Processor-to-Processor SCCs (Module 3) or the applicable module of the UK Addendum may be used to ensure compliance, provided the conditions for their use are met.
- If a competent authority approves an updated or replacement Transfer Mechanism during the term, that new mechanism will replace the applicable one under this Addendum from the date stated in DealAdvisorHQ's notice to the Customer.
12. CCPA Terms
- Sections 4, 5, 7, 8, 9, 12, and 14 apply where the CCPA governs the processing, and for those purposes the CCPA is the applicable Data Protection Law.
- Terms such as "Business," "Business Purpose," "Consumer," "Personal Information," "Sell," "Share," and "Service Provider" have the meanings given in the CCPA. For CCPA purposes, the Customer is the Business and DealAdvisorHQ is the Service Provider.
- For Customer Personal Information subject to the CCPA, DealAdvisorHQ is prohibited from: (i) selling or sharing it; (ii) retaining, using, or disclosing it for any purpose other than performing the Services or as otherwise permitted by the CCPA; (iii) retaining, using, or disclosing it outside the direct business relationship with the Customer; and (iv) combining it with personal information from other sources except as permitted by the CCPA. This does not restrict DealAdvisorHQ's permitted use of subprocessors, or its processing of DealAdvisorHQ CRM Data as a Business.
- DealAdvisorHQ will notify the Customer without undue delay if it determines it can no longer meet its obligations under this Section, and will allow the Customer to take reasonable steps to stop and remediate any unauthorized processing.
13. Singapore (PDPA) Terms
- Where Singapore Data Protection Law governs the processing, it is the applicable Data Protection Law for the relevant clauses. For these purposes the Customer is the Organisation and DealAdvisorHQ is the Data Intermediary; references to a Personal Data Breach mean a "Data Breach," and references to a Data Subject mean an "Individual," each as defined in the PDPA.
- For a Singapore Restricted Transfer, DealAdvisorHQ will (a) keep its Subprocessor list current so the Customer can see the countries to which data may be transferred, and (b) ensure recipients are bound by enforceable obligations providing a standard of protection comparable to the PDPA.
14. General Terms
- Without prejudice to the governing-law and jurisdiction clauses of the Standard Contractual Clauses, the Parties submit to the jurisdiction stated in the Agreement for disputes arising under this Addendum, and this Addendum is governed by the law stated in the Agreement.
- If there is any conflict between this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. If there is any conflict between this Addendum and the Agreement or other agreements between the Parties, this Addendum prevails as to its subject matter.
- This Addendum remains in effect until the Agreement expires or terminates.
- The limitations and exclusions of liability in the Agreement apply to this Addendum (including the Standard Contractual Clauses), so that the Parties' total aggregate liability under the Agreement and this Addendum together is subject to those limits.
- If any provision of this Addendum is invalid or unenforceable, the rest remains in effect, and the provision will be amended to the minimum extent needed to make it valid while preserving the Parties' intent.
Schedule 1 — EEA Standard Contractual Clauses
Table A — Module Options
| Provision | Module 2 (Controller to Processor) | Module 4 (Processor to Controller) |
|---|---|---|
| Clause 7 (Docking Clause) | Applies | Applies |
| Clause 9(a) (Subprocessors) | Option 2: General written authorization. Notice period: 2 weeks. Current Subprocessor list available at dealadvisorhq.com/subprocessors. | N/A |
| Clause 11(a) (Optional redress) | Does not apply | Does not apply |
| Clause 13(a) (Competent Supervisory Authority) | The authority responsible for the data exporter's GDPR compliance for the transfer. | N/A |
| Clause 17 (Governing law) | Option 1 — the law of the applicable EU Member State. | The law of the applicable EU Member State. |
| Clause 18 (Courts) | The courts of the applicable EU Member State. | The courts of the applicable EU Member State. |
| Combined with exporter data? | N/A | No |
Annex I — List of Parties and Description of Transfer
| Item | Details |
|---|---|
| Data exporter | The Customer, as identified in the Agreement / order form. Role: Controller. |
| Data importer | DealAdvisorHQ, the applicable legal entity, at its registered address and using its applicable privacy contact (e.g., privacy@dealadvisorhq.com). Role: Processor. |
| Categories of data subjects | The Customer's personnel, contractors, and agents; the Customer's clients and prospective clients; and buyers, sellers, and other counterparties to potential transactions, and their representatives. |
| Categories of personal data | Names, contact details, and other identification information; business, professional, and occupational information; and business and financial information relating to potential transactions. |
| Sensitive data | None expected. The Services are not intended for special-category data; if any is provided, the Customer must apply appropriate safeguards. |
| Frequency of transfer | On a continuous basis for the duration of the Services, and as needed for support and to meet security and availability commitments. |
| Nature and purpose | Hosting, storage, and related processing necessary to provide the Services described in the Agreement. |
| Retention period | Until expiration or termination of the applicable order, plus the applicable wind-down period, subject to Section 9. |
| Competent Supervisory Authority | The authority with supervision over the relevant data exporter. |
Annex II — Technical and Organizational Measures
DealAdvisorHQ maintains technical and organizational measures appropriate to the risk, which include the following:
- Encryption of Customer Personal Data in transit and, where appropriate, at rest;
- Role-based access controls and the principle of least privilege;
- Authentication controls, including multi-factor authentication for administrative access;
- Network security, logging, and monitoring of access to Customer Personal Data;
- Personnel confidentiality obligations and security awareness training;
- Vendor/Subprocessor due diligence and contractual security obligations;
- Backup, business-continuity, and incident-response procedures; and
- Secure development and change-management practices.
Schedule 2 — Swiss Modification
Where Swiss Data Protection Law applies, the EEA Standard Contractual Clauses apply as modified below:
- The term "Member State" is read to include Switzerland, so that data subjects may enforce their rights in their place of habitual residence;
- References to the GDPR are read as references to the Swiss Federal Act on Data Protection (in the version applicable at the start of any dispute);
- Until the revised Swiss Federal Act on Data Protection takes effect, "personal data" also protects the data of legal entities;
- Clause 17 (Governing law): the Clauses are governed by the substantive laws of Switzerland; and
- Clause 18 (Courts): disputes are resolved by the courts of Geneva, Switzerland; a data subject may also bring proceedings in the place of his or her habitual residence, and the Parties submit to those courts.
Schedule 3 — UK Standard Contractual Clauses
UK International Data Transfer Addendum to the EEA Standard Contractual Clauses.
Table 1 — Parties
| Item | Exporter | Importer |
|---|---|---|
| Start date | Effective date of the Agreement | Effective date of the Agreement |
| Parties' details | See Annex I of Schedule 1 | See Annex I of Schedule 1 |
| Key contact | See Annex I of Schedule 1 | See Annex I of Schedule 1 |
| Signature | Signature blocks of the Agreement / order | Signature blocks of the Agreement / order |
Table 2 — Selected Modules
| Module | In operation | Clause 7 (Docking) | Clause 9(a) authorization | Clause 9(a) period |
|---|---|---|---|---|
| 2 (C2P) | Yes | Applies | General | 14 days |
| 4 (P2C) | Yes | Applies | N/A | N/A |
Table 3 — Appendix Information
The Appendix Information for the selected modules is as follows: List of Parties — see Annex I of Schedule 1; Description of Transfer — see Annex I of Schedule 1; Technical and Organizational Measures — see Annex II of Schedule 1; List of Subprocessors — see DealAdvisorHQ's Subprocessor list.
Table 4 — Ending this Addendum on Changes to the Approved Addendum
Either the Importer or the Exporter may end the UK Addendum as permitted by Section 19 of the UK Addendum when the Approved Addendum changes.
Schedule 4 — Details of Processing of Customer Personal Data
This Schedule sets out the details required by Article 28(3) of the GDPR and UK GDPR (and equivalent provisions of other Data Protection Law).
| Item | Details |
|---|---|
| Subject matter and duration | As set out in the Agreement and this Addendum. |
| Nature and purpose | DealAdvisorHQ provides software and/or services that support the Customer's management and execution of its business operations, including connecting buyers and sellers of businesses where applicable. |
| Types of personal data | Names, contact details, and other identification information; business, professional, and occupational information; and business and financial information relating to potential transactions. |
| Categories of data subjects | The Customer's personnel, clients, and prospective clients; and buyers, sellers, and other counterparties to potential transactions, and their representatives. |
| Obligations and rights of the Customer | As set out in the Agreement and this Addendum. |