Data Processing Addendum

Mariontek · Effective version v1.1

Scope

This Data Processing Addendum (the “DPA”) supplements and forms part of the Master Service Agreement between MARIONTEK LLC, a Washington limited liability company (“Mariontek”), and the customer that has accepted the Master Service Agreement (the “Customer”). It governs Mariontek’s processing of personal data on Customer’s behalf in connection with the Services. Capitalized terms not defined here have the meaning given in the Master Service Agreement (the “Agreement”). This DPA is incorporated into the Agreement by reference under Section 7.1 of the Agreement and applies for so long as Mariontek processes Customer Personal Data.

1. Definitions

“Applicable Data Protection Laws” means all privacy and data-protection laws applicable to a Party’s processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, “CCPA”) and other comparable U.S. state privacy laws in effect during the term.

“Customer Personal Data” means the portion of Customer Data that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable individual, and that Mariontek processes on Customer’s behalf in providing the Services.

“Process” and “Processing” mean any operation performed on Customer Personal Data, including collection, recording, storage, transcription, organization, use, disclosure, transmission, and deletion.

“Security Incident” means a confirmed breach of Mariontek’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Mariontek. A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, denied login attempts, or denial-of-service attacks.

“Subprocessor” means a third party engaged by Mariontek to process Customer Personal Data in connection with the Services.

The terms “Customer Data,” “End Caller,” and “Services” have the meanings given in the Agreement. The terms “controller,” “processor,” “service provider,” “business,” “sell,” “share,” and “personal information” have the meanings given under Applicable Data Protection Laws.

2. Roles and Scope

2.1 Roles. As between the Parties, Customer is the controller (and, under the CCPA, the “business”) of Customer Personal Data, and Mariontek is the processor (and, under the CCPA, the “service provider”) acting on Customer’s behalf. Each Party is responsible for its own compliance with Applicable Data Protection Laws.

2.2 Scope and Details of Processing. Mariontek processes Customer Personal Data only to provide, maintain, secure, and support the Services. The subject matter, duration, nature and purpose of the processing, the categories of data subjects, and the categories of Customer Personal Data are described in Annex 1.

2.3 Customer Responsibility for Lawful Basis. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for having obtained all consents, notices, and authority required under Applicable Data Protection Laws to provide that data to Mariontek and to route, record, and have End Caller communications handled through the Services, consistent with Sections 5 and 6 of the Agreement.

3. Processing Instructions

3.1 Documented Instructions. Mariontek will process Customer Personal Data only on Customer’s documented instructions, which consist of the Agreement, this DPA, Customer’s use and configuration of the Services, and any further written instructions agreed by the Parties. Mariontek will not process Customer Personal Data for any other purpose.

3.2 No Sale or Sharing; Service-Provider Restrictions. Mariontek will not sell or share Customer Personal Data, will not retain, use, or disclose Customer Personal Data for any purpose other than providing the Services or as otherwise permitted by Applicable Data Protection Laws, and will not retain, use, or disclose Customer Personal Data outside the direct business relationship between the Parties or combine it with personal information obtained from other sources, except as permitted by the CCPA for a service provider. Mariontek certifies that it understands and will comply with these restrictions.

3.3 Unlawful Instructions. Mariontek will inform Customer if, in Mariontek’s reasonable opinion, an instruction violates Applicable Data Protection Laws, except where prohibited from doing so by law. Mariontek is not obligated to perform a legal review of Customer’s instructions.

4. Confidentiality of Personnel

Mariontek will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are made aware of the confidential nature of the data. Mariontek limits access to Customer Personal Data to personnel who require access to provide the Services.

5. Security Measures

5.1 Safeguards. Mariontek will implement and maintain the technical and organizational security measures described in Annex 2, designed to protect Customer Personal Data against a Security Incident, taking into account the nature of the Services and the risks to data subjects.

5.2 Customer Configuration. Customer is responsible for securing its own account credentials, access management, and configuration choices within the Services.

6. Subprocessors

6.1 Authorization. Customer provides general authorization for Mariontek to engage Subprocessors to process Customer Personal Data. The Subprocessors Mariontek currently engages are named in Annex 3. Mariontek will update Annex 3 when it adds or replaces a Subprocessor and will make the updated list available on request to privacy@mariontek.com.

6.2 Subprocessor Obligations. Mariontek will impose on each Subprocessor data-protection obligations that are substantially the same as those in this DPA to the extent applicable to the Subprocessor’s processing. Mariontek remains responsible for each Subprocessor’s performance of its obligations.

6.3 Changes. When Mariontek adds or replaces a Subprocessor that processes Customer Personal Data, Mariontek will make the updated list available on request. Customer may object to a new Subprocessor on reasonable data-protection grounds by written notice to privacy@mariontek.com within thirty (30) days, in which case the Parties will work in good faith to resolve the objection. If the Parties cannot resolve it, Customer’s sole remedy is to terminate the Agreement for the affected Services.

7. Data Subject and Consumer Requests

Taking into account the nature of the processing, Mariontek will provide reasonable assistance, through appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from individuals to exercise their rights under Applicable Data Protection Laws, including rights to access, correct, delete, or obtain a copy of their personal data. If Mariontek receives such a request directly from an individual relating to Customer Personal Data, Mariontek will, where permitted by law, direct the individual to Customer rather than responding substantively.

8. Assistance

Taking into account the nature of the processing and the information available to Mariontek, Mariontek will provide reasonable assistance to Customer with: (a) Customer’s obligations to keep Customer Personal Data secure; (b) Security Incident notification and remediation; and (c) any data-protection assessment Customer is required to conduct under Applicable Data Protection Laws.

9. Security Incident Notification

9.1 Notice. Mariontek will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

9.2 Contents. The notice will describe, to the extent then known and as it becomes available, the nature of the Security Incident, the categories and approximate volume of data and records affected, the likely consequences, and the measures taken or proposed to address it.

9.3 No Admission. Mariontek’s notification of or response to a Security Incident is not an acknowledgment of fault or liability.

10. Return and Deletion

On termination or expiration of the Agreement, Mariontek will, in accordance with its standard retention practices and the Privacy Policy, make Customer Personal Data available for export for ninety (90) days following termination and will thereafter delete or anonymize Customer Personal Data, except for copies required to be retained by law or held in routine backups that are overwritten on a rolling basis and remain subject to the confidentiality and security obligations of this DPA. On Customer’s written request following deletion, Mariontek will provide written certification that it has deleted or anonymized Customer Personal Data in accordance with this Section.

11. Audit and Compliance Information

Mariontek will make available to Customer, on reasonable written request and no more than once in any twelve (12) month period, information reasonably necessary to demonstrate Mariontek’s compliance with this DPA, which may be provided in the form of policy summaries, security documentation, or third-party reports where available. Any on-site audit, where reasonably required, is subject to reasonable advance notice, Mariontek’s security and confidentiality requirements, and the auditing Party bearing its own costs.

12. International Transfers

The Services are operated from and store Customer Personal Data within the United States. Customer will not provide Mariontek with personal data that is subject to data-transfer restrictions of a jurisdiction outside the United States unless the Parties have agreed in writing to additional terms governing such transfers.

13. CCPA Service-Provider Terms

13.1 Service-Provider Status. The Parties acknowledge that Mariontek receives Customer Personal Data from Customer solely to perform the Services and acts as a service provider under the CCPA. Mariontek is prohibited from, and will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, including retaining, using, or disclosing it for a commercial purpose other than providing the Services; or (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the Parties. The Parties further agree that the restrictions in this Section and in Section 3.2 form the data-protection terms required of a service provider under the CCPA.

13.2 Notice of Inability to Comply. Mariontek will notify Customer without undue delay if it determines that it can no longer meet its obligations as a service provider under the CCPA or this DPA.

13.3 Customer Remediation Right. On reasonable notice of unauthorized use of Customer Personal Data, Customer may take reasonable and appropriate steps to stop and remediate the unauthorized use.

14. Liability

Each Party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a Party’s liability in the Agreement means the aggregate liability of that Party under the Agreement and this DPA combined.

15. General

15.1 Term. This DPA takes effect on the effective date of the Agreement and continues until Mariontek has deleted or returned all Customer Personal Data in accordance with Section 10.

15.2 Order of Precedence. This DPA forms part of the Agreement. In the event of a conflict between this DPA and the body of the Agreement with respect to the processing of Customer Personal Data, this DPA controls. In all other respects, the Agreement controls.

15.3 Governing Law. This DPA is governed by the laws of the State of Washington, without regard to its conflict-of-law principles, and is subject to the dispute-resolution provisions of the Agreement.

15.4 Changes. Mariontek may update this DPA on reasonable notice to reflect changes in the Services or Applicable Data Protection Laws, provided no update materially reduces the protections afforded to Customer Personal Data during the then-current term.

Annex 1 — Details of Processing

Subject matter. Provision of Mariontek’s AI-assisted missed-call recovery, call-handling, and lead-capture Services.

Duration. The term of the Agreement, plus the post-termination retention and deletion period described in Section 10.

Nature and purpose. Receiving, routing, recording, and transcribing inbound and recovery calls; generating structured notes, summaries, and lead classifications; storing and presenting lead and account records; and supporting, securing, and improving the Services.

Categories of data subjects. Customer’s personnel and authorized users; End Callers (the individuals who call Customer’s business or are contacted by the recovery callback).

Categories of Customer Personal Data. Account and billing contact details of Customer’s authorized users; End Caller telephone numbers; call timestamps, duration, and metadata; spoken content captured during calls and the transcripts, structured notes, summaries, and lead classifications generated from it; and follow-up activity records. Customer controls what additional information End Callers may disclose during a call.

Sensitive data. The Services are not designed to collect special categories of data. Customer is responsible for not configuring the Services to solicit, and for not directing through the Services, categories of sensitive personal data beyond what is necessary for routine intake by a trades or home-services business.

Annex 2 — Technical and Organizational Security Measures

Mariontek maintains the following measures, which may evolve as the Services develop provided overall protection is not materially reduced:

Encryption. Encryption of Customer Personal Data in transit, and encryption at rest for sensitive fields.

Access control. Role-based access controls, row-level data isolation between customer accounts, hashed (not plaintext) storage of passwords, and access limited to personnel who require it to provide the Services.

Authentication. Session-based authentication with access logging.

Network and application security. Use of reputable infrastructure providers, signature verification on inbound integration callbacks, and protections against common application vulnerabilities.

Monitoring. Logging of system events, error and API request logs, and monitoring for anomalous activity, retained on a rolling basis for operational and security purposes.

Subprocessor diligence. Engagement of infrastructure, telephony, payment, and AI processing providers that maintain their own data-protection and security commitments.

Incident response. Internal procedures for identifying, assessing, and responding to Security Incidents and for notifying Customer in accordance with Section 9.

Annex 3 — Subprocessors

Mariontek engages the following Subprocessors to deliver the Services: Supabase (cloud database, authentication, edge functions, and file storage — application infrastructure); Retell AI (real-time AI voice call handling and transcription); Twilio (telephony — phone-number provisioning, call routing, and SMS); OpenAI (classification of call transcripts into structured leads; text only); Stripe (subscription billing and payment-method processing, with raw card data held by Stripe and not by Mariontek); Resend (transactional email — lead alerts and service and billing notices); and Vercel (application hosting and content delivery). Each processes Customer Personal Data in the United States.

A current list of the specific named Subprocessors within these categories is available to Customer on request to privacy@mariontek.com.