Terms & Privacy

Data Processing Agreement

Data Processing Agreement

Version 2.0. Last update: 09/16/2026

This Data Processing Agreement (the "DPA") forms part of the Software as a Service Agreement between Provider and Customer — the Software as a Service Agreement published at https://maestra.io/msa where Provider is Maestra.io LLC (the "US SSA"), or the Software as a Service Agreement published at https://maestra.io/eu/msa where Provider is Maestra B.V. (the "EU SSA") (in either case, the "SSA"). "Provider" or "Processor" means the Maestra entity identified as the Provider in the Order Form: Maestra.io LLC, a Delaware limited liability company, or Maestra B.V., a private company with limited liability organised under the laws of the Netherlands. "Customer" or "Controller" means the Customer identified in the Order Form. Provider and Customer are each a "Party" and together the "Parties". This DPA applies whenever Provider Processes Personal Data on behalf of Customer through the Services, wherever Customer is established.

This DPA takes effect on the Effective Date of the SSA. For SSAs in force before the "Last update" date above, this version takes effect on the date stated in Provider’s notice given under Provider’s right to update the Agreement by written notice in the Section of the SSA titled "Amendment and Waiver", and replaces the version of the DPA previously in force, as set out in Clause 29.

Capitalised terms not defined in this DPA have the meanings given in the SSA, including Exhibit C. In this DPA: "Personal Data" means any information relating to an identified or identifiable natural person, and includes "PII" as defined in the US SSA and "Personal Data" as defined in the EU SSA; "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the SSA, including, where applicable, the GDPR, the UK GDPR and the Data Protection Act 2018, and the privacy laws of the states of the United States; "GDPR" means Regulation (EU) 2016/679; "UK GDPR" has the meaning given in the Data Protection Act 2018; "Sub-processor" (referred to in Part A as "sub-processor") means any processor engaged by Provider or its Affiliates to Process Personal Data on behalf of Customer; "Sub-processor List" means the list published at https://maestra.io/legal/subprocessors, as updated in accordance with this DPA; "Exhibit C" means the Exhibit to the SSA titled "Information Security and Data Processing Policy", published at https://maestra.io/msa/exhibit-c. Where the terms used in this DPA are defined in the GDPR, those terms shall have the same meaning as in the GDPR.

In the event of a conflict, the order of precedence is: Part A and the Standard Contractual Clauses incorporated by Clause 12; then the rest of this DPA; then the SSA, in accordance with the Section of the SSA titled "Entire Agreement; Order of Precedence".

Part A — Standard contractual clauses between controllers and processors (Article 28(7) GDPR; Commission Implementing Decision (EU) 2021/915)

Section I — General

Clause 1 — Purpose and Scope

  1. The purpose of these standard contractual clauses (the "Clauses") is to ensure compliance with Article 28(3) and (4) of the GDPR for the Processing of Personal Data by the Processor on behalf of the Controller.

  2. The Parties have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of the GDPR.

  3. These Clauses apply to the Processing of Personal Data as specified in Annex II to this DPA.

  4. Annexes I to IV to this DPA are an integral part of these Clauses.

  5. These Clauses are without prejudice to obligations to which the Controller is subject by virtue of the GDPR.

  6. These Clauses do not by themselves ensure compliance with obligations related to international transfers in accordance with Chapter V of the GDPR.

Clause 2 — Invariability of the Clauses

  1. The Parties undertake not to modify the Clauses, except for adding information to the Annexes or updating information in them.

  2. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a broader contract, or from adding other clauses or additional safeguards provided that they do not directly or indirectly contradict the Clauses or detract from the fundamental rights or freedoms of data subjects.

Clause 3 — Interpretation

  1. Where these Clauses use the terms defined in the GDPR, those terms shall have the same meaning as in that Regulation.

  2. These Clauses shall be read and interpreted in the light of the provisions of the GDPR.

  3. These Clauses shall not be interpreted in a way that runs counter to the rights and obligations provided for in the GDPR or in a way that prejudices the fundamental rights or freedoms of the data subjects.

Clause 4 — Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties existing at the time when these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 5 — Docking Clause (Optional)

  1. Any entity that is not a Party to these Clauses may, with the agreement of all the Parties, accede to these Clauses at any time as a controller or a processor by completing the Annexes and signing Annex I.

  2. Once the Annexes referred to in paragraph (a) are completed and signed, the acceding entity shall be treated as a Party to these Clauses and have the rights and obligations of a controller or a processor, in accordance with its designation in Annex I.

  3. The acceding entity shall have no rights or obligations resulting from these Clauses from the period prior to becoming a Party.

Section II — Obligations of the Parties

Clause 6 — Description of Processing

The details of the Processing operations, in particular the categories of Personal Data and the purposes of Processing for which the Personal Data is Processed on behalf of the Controller, are specified in Annex II to this DPA.

Clause 7 — Obligations of the Parties

7.1 Instructions

  1. The Processor shall Process Personal Data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject. In this case, the Processor shall inform the Controller of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest. Subsequent instructions may also be given by the Controller throughout the duration of the Processing of Personal Data. These instructions shall always be documented.

  2. The Processor shall immediately inform the Controller if, in the Processor’s opinion, instructions given by the Controller infringe the GDPR or the applicable Union or Member State data protection provisions.

7.2 Purpose Limitation

The Processor shall Process the Personal Data only for the specific purpose(s) of the Processing, as set out in Annex II to this DPA, unless it receives further instructions from the Controller.

7.3 Duration of the Processing of Personal Data

Processing by the Processor shall only take place for the duration specified in Annex II to this DPA.

7.4 Security of Processing

  1. The Processor shall at least implement the technical and organisational measures specified in Annex III to this DPA to ensure the security of the Personal Data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (personal data breach). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing and the risks involved for the data subjects.

  2. The Processor shall grant access to the Personal Data undergoing Processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of the contract. The Processor shall ensure that persons authorised to Process the Personal Data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7.5 Sensitive Data

If the Processing involves Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences ("sensitive data"), the Processor shall apply specific restrictions and/or additional safeguards.

7.6 Documentation and Compliance

  1. The Parties shall be able to demonstrate compliance with these Clauses.

  2. The Processor shall deal promptly and adequately with inquiries from the Controller about the Processing of data in accordance with these Clauses.

  3. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations that are set out in these Clauses and stem directly from the GDPR. At the Controller’s request, the Processor shall also permit and contribute to audits of the Processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or an audit, the Controller may take into account relevant certifications held by the Processor.

  4. The Controller may choose to conduct the audit by itself or mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the Processor and shall, where appropriate, be carried out with reasonable notice.

  5. The Parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority/ies on request.

7.7 Use of Sub-Processors

  1. GENERAL WRITTEN AUTHORISATION: The Processor has the Controller’s general authorisation for the engagement of sub-processors from an agreed list. The Processor shall specifically inform in writing the Controller of any intended changes of that list through the addition or replacement of sub-processors at least thirty (30) calendar days in advance, thereby giving the Controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s). The Processor shall provide the Controller with the information necessary to enable the Controller to exercise the right to object. Notwithstanding the foregoing, where the Processor needs to add or replace a sub-processor on shorter notice due to (i) the sub-processor’s insolvency, (ii) a material security incident affecting the sub-processor, (iii) the sub-processor’s material breach of its data protection obligations, or (iv) any other circumstance requiring immediate action to protect the security or integrity of the Services or the Personal Data, the Processor may make such addition or replacement on as much advance notice as is reasonably practicable (and in any event with not less than five (5) working days' notice where reasonably possible), with prompt notice to the Controller of the circumstances justifying the shortened notice period.

  2. Where the Processor engages a sub-processor for carrying out specific Processing activities (on behalf of the Controller), it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as the ones imposed on the Processor in accordance with these Clauses. The Processor shall ensure that the sub-processor complies with the obligations to which the Processor is subject pursuant to these Clauses and to the GDPR.

  3. At the Controller’s request, the Processor shall provide a copy of such a sub-processor agreement and any subsequent amendments to the Controller. To the extent necessary to protect business secret or other confidential information, including Personal Data, the Processor may redact the text of the agreement prior to sharing the copy.

  4. The Processor shall remain fully responsible to the Controller for the performance of the sub-processor’s obligations in accordance with its contract with the Processor. The Processor shall notify the Controller of any failure by the sub-processor to fulfil its contractual obligations.

  5. The Processor shall agree a third party beneficiary clause with the sub-processor whereby — in the event the Processor has factually disappeared, ceased to exist in law or has become insolvent — the Controller shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the Personal Data.

7.8 International Transfers

  1. Any transfer of data to a third country or an international organisation by the Processor shall be done only on the basis of documented instructions from the Controller or in order to fulfil a specific requirement under Union or Member State law to which the Processor is subject and shall take place in compliance with Chapter V of the GDPR.

  2. The Controller agrees that where the Processor engages a sub-processor in accordance with Clause 7.7 for carrying out specific Processing activities (on behalf of the Controller) and those Processing activities involve a transfer of Personal Data within the meaning of Chapter V of the GDPR, the Processor and the sub-processor can ensure compliance with Chapter V of the GDPR by using standard contractual clauses adopted by the Commission in accordance with Article 46(2) of the GDPR, provided the conditions for the use of those standard contractual clauses are met.

Clause 8 — Assistance to the Controller

  1. The Processor shall promptly notify the Controller of any request it has received from the data subject. It shall not respond to the request itself, unless authorised to do so by the Controller.

  2. The Processor shall assist the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights, taking into account the nature of the Processing. In fulfilling its obligations in accordance with paragraphs (a) and (b), the Processor shall comply with the Controller’s instructions.

  3. In addition to the Processor’s obligation to assist the Controller pursuant to Clause 8(b), the Processor shall furthermore assist the Controller in ensuring compliance with the following obligations, taking into account the nature of the data Processing and the information available to the Processor: (i) the obligation to carry out a data protection impact assessment where a type of Processing is likely to result in a high risk to the rights and freedoms of natural persons; (ii) the obligation to consult the competent supervisory authority/ies prior to Processing where a data protection impact assessment indicates that the Processing would result in a high risk in the absence of measures taken by the Controller to mitigate the risk; (iii) the obligation to ensure that Personal Data is accurate and up to date, by informing the Controller without delay if the Processor becomes aware that the Personal Data it is Processing is inaccurate or has become outdated; (iv) the obligations in Article 32 of the GDPR.

  4. The Parties shall set out in Annex III to this DPA the appropriate technical and organisational measures by which the Processor is required to assist the Controller in the application of this Clause as well as the scope and the extent of the assistance required.

Clause 9 — Notification of Personal Data Breach

In the event of a personal data breach, the Processor shall cooperate with and assist the Controller for the Controller to comply with its obligations under Articles 33 and 34 of the GDPR, taking into account the nature of Processing and the information available to the Processor.

9.1 Data Breach Concerning Data Processed by the Controller

In the event of a personal data breach concerning data Processed by the Controller, the Processor shall assist the Controller:

  1. in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the Controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);

  2. in obtaining the following information which, pursuant to Article 33(3) of the GDPR, shall be stated in the Controller’s notification, and must at least include: (1) the nature of the Personal Data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned; (2) the likely consequences of the personal data breach; (3) the measures taken or proposed to be taken by the Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects;

  3. in complying, pursuant to Article 34 of the GDPR, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.

Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

9.2 Data Breach Concerning Data Processed by the Processor

In the event of a personal data breach concerning data Processed by the Processor, the Processor shall notify the Controller without undue delay after the Processor having become aware of the breach. Such notification shall contain, at least:

  1. a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned);

  2. the details of a contact point where more information concerning the personal data breach can be obtained;

  3. its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects.

Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

Section III — Final Provisions

Clause 10 — Non-compliance with the Clauses and Termination

  1. Without prejudice to any provisions of the GDPR, in the event that the Processor is in breach of its obligations under these Clauses, the Controller may instruct the Processor to suspend the Processing of Personal Data until the latter complies with these Clauses or the contract is terminated. The Processor shall promptly inform the Controller in case it is unable to comply with these Clauses, for whatever reason.

  2. The Controller shall be entitled to terminate the contract insofar as it concerns Processing of Personal Data in accordance with these Clauses if: (1) the Processing of Personal Data by the Processor has been suspended by the Controller pursuant to point (a) and if compliance with these Clauses is not restored within a reasonable time and in any event within one month following suspension; (2) the Processor is in substantial or persistent breach of these Clauses or its obligations under the GDPR; (3) the Processor fails to comply with a binding decision of a competent court or the competent supervisory authority/ies regarding its obligations pursuant to these Clauses or to the GDPR.

  3. The Processor shall be entitled to terminate the contract insofar as it concerns Processing of Personal Data under these Clauses where, after having informed the Controller that its instructions infringe applicable legal requirements in accordance with Clause 7.1(b), the Controller insists on compliance with the instructions.

  4. Following termination of the contract, the Processor shall, at the choice of the Controller, delete all Personal Data Processed on behalf of the Controller and certify to the Controller that it has done so, or return all the Personal Data to the Controller and delete existing copies unless Union or Member State law requires storage of the Personal Data. Until the data is deleted or returned, the Processor shall continue to ensure compliance with these Clauses. For the avoidance of doubt, this Clause 10(d) does not apply to Resultant Data, which is governed by the Section of the SSA titled "Provider Materials and Resultant Data".

  5. Without modifying the Clauses themselves (consistent with Clause 2 of this DPA), the Processor may update the Annexes to this DPA from time to time to reflect changes in the Services, sub-processors, technical and organisational measures, or business processes, or for legal, regulatory, or security reasons. The Processor shall provide the Controller with ten (10) days' advance written notice of any such update before it becomes effective. If the Controller does not agree to the updated Annex, the Controller may terminate the SSA with respect to the affected Processing on one (1) day’s written notice given within that ten (10)-day period. If the Controller does not give such notice within the ten (10)-day period, the updated Annex is deemed accepted and becomes effective at the end of the period. This Clause 10(e) does not displace the sub-processor change-notice procedure set forth in Clause 7.7 of this DPA, which continues to apply to additions or replacements of sub-processors.

Part B — Cross-border transfers

Clause 11 — Scope

This Part B applies to any transfer of Personal Data Processed under this DPA that is subject to Chapter V of the GDPR or Chapter V of the UK GDPR, including (a) a transfer by Customer to Provider where Provider is established outside the European Economic Area or the United Kingdom, and (b) any onward transfer by Provider to a Sub-processor in a third country. Where the Data Protection Laws of another jurisdiction require a transfer mechanism for the export of Personal Data to Provider or a Sub-processor, permit reliance on contractual clauses for that purpose and do not prescribe a different form of contractual clauses, the Standard Contractual Clauses incorporated by Clause 12 apply to that transfer mutatis mutandis, with references to the GDPR read as references to those laws to the extent necessary. Where this Part B applies, its provisions operate in addition to, and not in derogation of, Part A.

Clause 12 — Incorporation of the Standard Contractual Clauses

  1. The Parties incorporate by reference into this DPA the Standard Contractual Clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (the "SCCs"). The SCCs as incorporated into this DPA shall be deemed executed between the Parties as of the Effective Date of the SSA. The authoritative text of the SCCs is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.

  2. The Parties acknowledge that the SCCs constitute appropriate safeguards within the meaning of Article 46(2)(c) of the GDPR for the transfer of Personal Data to a third country.

  3. If there is any discrepancy between any copy of the SCCs and the authoritative text published by the European Commission, the authoritative text shall prevail.

  4. Provider shall not modify the SCCs. The Parties may add information to the Appendix tables set forth in this DPA, and may add other clauses or additional safeguards in this DPA or in the SSA, provided that they do not contradict, directly or indirectly, the SCCs or prejudice the fundamental rights or freedoms of data subjects.

Clause 13 — Module and Option Selections

The Parties select the following modules and options under the SCCs:

  1. Module: Module Two (Controller to Processor) applies where Customer Processes Personal Data as a controller; Customer acts as the controller and data exporter, and Provider as the processor and data importer. Where Customer Processes Personal Data as a processor on behalf of its own customers, Module Three (Processor to Processor) applies to those transfers; Customer acts as data exporter and Provider as data importer, and the Annexes apply with the roles read accordingly.

  2. SCC Clause 7 (Docking Clause): the optional Docking Clause does NOT apply. Additional parties may not accede to the SCCs without the written consent of both Parties.

  3. SCC Clause 9 (Use of sub-processors): the Parties select Option 2 — General Written Authorisation. Provider shall give notice of any intended changes to the Sub-processor List at least thirty (30) calendar days in advance, or the shorter notice permitted by Clause 7.7(a) in the circumstances stated there.

  4. SCC Clause 11 (Redress): the optional independent dispute resolution language does NOT apply. The standard redress mechanisms set forth in SCC Clause 11 apply without modification.

  5. SCC Clause 17 (Governing law): the Parties select the law of the Kingdom of the Netherlands as the governing law of the SCCs.

  6. SCC Clause 18(b) (Choice of forum and jurisdiction): the Parties select the competent courts of Amsterdam, the Netherlands, as the courts having jurisdiction over disputes arising from the SCCs, without prejudice to the data subject’s right to bring proceedings in the Member State of his or her habitual residence.

  7. Annexes: Annex I of the SCCs (List of Parties; Description of the Transfer; Competent Supervisory Authority) is completed by Annex I and Annex II to this DPA; Annex II of the SCCs (Technical and Organisational Measures) by Annex III to this DPA; Annex III of the SCCs (List of Sub-processors) by Annex IV to this DPA.

Clause 14 — Future Updates to the SCCs

  1. If the European Commission adopts a successor decision that materially amends, replaces, or repeals the SCCs, or if a competent supervisory authority issues binding guidance that materially affects the operation of the SCCs as incorporated in this DPA, the Parties shall negotiate in good faith any amendments to this DPA required to implement such successor decision or guidance.

  2. If the Parties do not reach mutual agreement on the required amendments within sixty (60) days from the date the successor decision or guidance enters into force, either Party may terminate the SSA in respect of the Processing of Personal Data under this DPA upon thirty (30) days' written notice to the other Party. Customer shall pay all Fees accrued through the effective date of such termination, and Provider shall refund any Fees prepaid for periods after that date on a pro rata basis.

  3. Where the successor decision provides clauses that replace the SCCs for the transfers covered by this DPA, those clauses replace the SCCs as incorporated by Clause 12 from the date on which they must be used, and Provider publishes the corresponding update to this DPA under Clause 21(c); paragraphs (a) and (b) then do not apply.

Clause 15 — United Kingdom

  1. Where the Processing of Personal Data of data subjects in the United Kingdom by Provider or by a Sub-processor involves a transfer of Personal Data from the United Kingdom to a third country that does not benefit from adequacy regulations under Article 45 of the UK GDPR, the Parties incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner’s Office (Version B1.0, in force 21 March 2022, the "UK Addendum"), the authoritative text of which is available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/. The UK Addendum operates as an addendum to the SCCs incorporated by Clause 12, which are deemed to apply, with the modifications set forth in the UK Addendum, to such transfers. The tables of the UK Addendum are completed in Annex V to this DPA.

  2. For the purposes of such Processing, references in Part A to the GDPR are read as references to the UK GDPR and the Data Protection Act 2018, references to a Member State or the European Economic Area as references to the United Kingdom, and references to the competent supervisory authority as references to the Information Commissioner’s Office (or its successor).

  3. If the Information Commissioner’s Office (or its successor) issues a successor to the UK Addendum that materially affects its operation, Clause 14 applies mutatis mutandis.

Part C — Personal Data subject to United States state privacy laws

Clause 16 — Scope and roles

  1. This Part C applies to the extent the Processing of Personal Data under the SSA is subject to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (the "CCPA"), or to another state privacy law of the United States of general application that distinguishes the roles of "business" or "controller" and "service provider", "contractor" or "processor" (together, "US State Privacy Laws"). Terms used in this Part C have the meanings given in the applicable US State Privacy Law.

  2. Customer is the "business" (or "controller") and Provider is the "service provider" (or "processor") with respect to Personal Data Processed on Customer’s behalf, as set out in the Section of the US SSA titled "Privacy and Data Protection Roles" and, for Customers contracting with Maestra B.V., in this DPA as a whole.

Clause 17 — Provider’s obligations

  1. Provider Processes Personal Data on Customer’s behalf for the business purpose of providing the Services under the SSA, as described in the SSA, Exhibit C (including its Annex 1) and the Documentation, and for no other purpose.

  2. Provider shall not: (i) sell or share Personal Data; (ii) retain, use or disclose Personal Data for any purpose, including any commercial purpose, other than the business purpose specified in paragraph (a), or outside the direct business relationship between Provider and Customer, except as permitted by the applicable US State Privacy Law; (iii) combine Personal Data received from or on behalf of Customer with personal information received from or on behalf of another person, or collected from Provider’s own interaction with a consumer, except as permitted by the applicable US State Privacy Law for service providers or processors. Provider’s rights with respect to Resultant Data and Anonymized Data under the Section of the SSA titled "Provider Materials and Resultant Data" are not affected.

  3. Provider shall comply with the obligations applicable to service providers and processors under the applicable US State Privacy Laws and shall provide the level of privacy protection they require.

  4. Provider shall notify Customer if Provider determines that it can no longer meet its obligations under the applicable US State Privacy Laws.

  5. Customer may take reasonable and appropriate steps to ensure that Provider uses Personal Data in a manner consistent with Customer’s obligations under the applicable US State Privacy Laws, in accordance with Clause 22, and, upon notice, to stop and remediate unauthorised use of Personal Data.

  6. Provider engages Sub-processors under written contracts that bind them to the obligations of this Part C to the extent applicable to the services they provide, and notifies Customer of Sub-processors in accordance with Clause 7.7 and Clause 20.

  7. Provider shall assist Customer, taking into account the nature of the Processing, in responding to verifiable consumer requests under the applicable US State Privacy Laws by making available the functions of the Services for that purpose and, where those functions do not suffice, on Customer’s instruction through the Means of Communication.

  8. Provider certifies that it understands the restrictions in this Part C and will comply with them.

Part D — Additional terms

Clause 18 — Provider and Affiliates

Provider is the Maestra entity identified in the Order Form. The other Maestra entity — Maestra B.V. where Provider is Maestra.io LLC, and Maestra.io LLC where Provider is Maestra B.V. — Processes Personal Data as a Sub-processor and is listed as such on the Sub-processor List.

Clause 19 — Instructions

The SSA, this DPA, the Order Form and Customer’s configuration of the Services — including the attributes, forms, integrations, Tracking Technologies, audiences and campaigns Customer creates, installs, connects or enables, and the instructions Customer gives Provider Personnel through the Means of Communication — constitute Customer’s complete documented instructions for the purposes of Clause 7.1. Customer may give further instructions through the Means of Communication; Provider is not required to act on instructions given in any other way, and may decline an instruction that it reasonably believes infringes Data Protection Laws, as provided in Clause 7.1(b).

Clause 20 — Sub-processor changes: notice, self-service and objection

  1. The agreed list of Sub-processors for the purposes of Clause 7.7 is the Sub-processor List as in force on the date this DPA takes effect for Customer under the preamble, as subsequently updated in accordance with Clause 7.7 and this Clause 20.

  2. Provider gives the notice required by Clause 7.7(a) by (i) publishing the intended change on the Sub-processor List, with the date on which it takes effect, and (ii) sending the notice by email to the address for legal notices in Customer’s Order Form and to any additional address Customer has registered for that purpose with Provider (registration is made by email to dpo@maestra.io or, where available, through the form on the Sub-processor List). Such an email is written notice under the Section of the SSA titled "Notices". Customer may add or change its additional addresses at any time in the same way; the Order Form address cannot be removed except by a change to the Order Form. Customer keeps the address for legal notices in its Order Form current through the Means of Communication.

  3. Customer may object to an intended addition or replacement on reasonable grounds relating to the protection of Personal Data by written notice to Provider, stating those grounds, before the date on which the change takes effect. An objection that states no such grounds does not have the effects of this paragraph. The Parties shall discuss the objection in good faith. If the Parties do not resolve it before the date on which the change takes effect, either Party may, as its sole and exclusive remedy, terminate the SSA by written notice to the other Party given before that date, with effect from that date or a later date stated in the notice. Fees accrue to the effective date of termination, and the Section of the SSA titled "Effect of Termination or Expiration" applies to the Personal Data. Provider does not undertake to maintain alternative hosting or infrastructure for an objecting Customer, or to exclude Customer’s Personal Data from Processing through the Sub-processor concerned.

  4. If Customer does not object before the date on which the change takes effect, Customer is deemed to have authorised the engagement.

  5. The removal of a Sub-processor from the Sub-processor List and corrections to the description of an existing Sub-processor’s location or purpose are published on the Sub-processor List and do not require the notice in paragraph (b).

  6. This Clause 20 applies to every Customer on both the US SSA and the EU SSA. Nothing in this Clause 20 reduces the rights in Clause 7.7.

Clause 21 — Updates to this DPA and to the documents it incorporates

  1. Part A reproduces the standard contractual clauses of Commission Implementing Decision (EU) 2021/915 with the options selected, together with the additions in Clause 7.7(a) (shorter notice in the circumstances stated there), Clause 10(d) (Resultant Data) and Clause 10(e) (updates to the Annexes), which the Parties agree under Clause 2(b); Part A is not otherwise modified.

  2. The Annexes to this DPA are updated in accordance with Clause 10(e), except that additions or replacements of Sub-processors follow Clause 7.7 and Clause 20.

  3. The preamble, Parts B, C and D of this DPA are updated by Provider in the same way as the SSA, under Provider’s right to update the Agreement in the Section of the SSA titled "Amendment and Waiver": written notice not less than thirty (30) calendar days before the effective date, publication of the updated version at the URL of this DPA, prospective effect only, and Customer’s right to terminate for convenience before the effective date. Provider shall not use such an update to modify the SCCs (Clause 12(d)) or to detract from the rights of data subjects.

  4. Exhibit C, the Sub-processor List and the Documentation are incorporated by reference and change in accordance with their own terms — the Section of Exhibit C titled "Updates" (including the notice it requires for changes to Default Collection), the section of the Sub-processor List titled "Updates to this list" and Clause 20, and the Documentation as released. A change to a document incorporated by reference is not an update to an Annex under Clause 10(e).

  5. Prior versions of this DPA remain available at the archive link at the foot of this DPA.

Clause 22 — Audits and security information

  1. Provider makes the following available to demonstrate compliance with this DPA: its current SOC 2 Type II report, on reasonable written request and subject to a customary non-disclosure agreement (the Section of Exhibit C titled "Security Programme"); Exhibit C; the Sub-processor List; and written responses, on a confidential basis, to reasonable requests for information that Customer needs to confirm Provider’s compliance with this DPA, including information-security, due-diligence and audit questionnaires, not more than once in any calendar year.

  2. Customer exercises its rights under Clause 7.6(c) and (d) and Clause 17(e) first through the information in paragraph (a). Where that information does not demonstrate compliance on a point, or where there are indications of non-compliance, Customer or an independent auditor mandated by Customer and bound by confidentiality may audit the Processing activities covered by this DPA, on-site or remotely, not more than once in any calendar year unless Data Protection Laws or a competent supervisory authority require otherwise, on at least thirty (30) days' written notice with a proposed scope and plan. The Parties agree the scope, timing and duration of the audit before it starts; the audit is conducted during Provider’s normal business hours and in a manner that does not unreasonably interfere with Provider’s operations or the security of other customers' data. Provider may object to an auditor that is not suitably qualified or independent, is a competitor of Provider or is otherwise manifestly unsuitable, in which case Customer appoints another auditor. An audit report is Confidential Information of Provider under the Section of the SSA titled "Confidentiality".

  3. An audit under paragraph (b) is at Customer’s expense. Customer bears its own costs and reimburses Provider for the time and expenses Provider reasonably incurs in preparing for and supporting the audit, at Provider’s then-current professional services rates notified in advance, unless the audit reveals a material breach of this DPA by Provider, in which case Provider bears its own costs. Provider’s cooperation under paragraph (a) is at no charge.

Clause 23 — AI Features and third-party AI tools

  1. The Processing of Personal Data by the AI Features is governed by the Section of the SSA titled "AI Features" and by this DPA. Provider does not use Personal Data to train its own artificial-intelligence or machine-learning models, as stated in that Section.

  2. Provider Personnel may use third-party artificial-intelligence tools and services to service Customer’s account and to operate and support the Services, including to configure the Services on Customer’s instructions. Any such tool or service that Processes Personal Data is a Sub-processor, is listed on the Sub-processor List and is engaged under Clause 7.7(b) on terms that prohibit the use of Personal Data for the tool provider’s own purposes, including the training of its models.

Clause 24 — Resultant Data and Anonymized Data

The Processing of Resultant Data and Anonymized Data is not Processing on behalf of Customer under this DPA. Resultant Data and Anonymized Data are governed exclusively by the Section of the SSA titled "Provider Materials and Resultant Data", and Provider may retain and use them indefinitely in accordance with that Section. The licence Customer grants to Provider in that Section is Customer’s documented instruction under Clause 7.1 for the derivation of Resultant Data and Anonymized Data. Nothing in this Clause 24 limits the rights of data subjects under Data Protection Laws, which apply to Personal Data before irreversible anonymisation.

Clause 25 — Allocation of responsibility under Data Protection Laws

Each Party is responsible for its own compliance with the Data Protection Laws that apply to it in its role. Customer is responsible for the lawfulness of the Personal Data it makes available to the Services, for the notices to and consents of data subjects that its use of the Services requires, and for its assessment of whether the Services and this DPA meet the requirements of the Data Protection Laws of the jurisdictions in which Customer operates. Provider makes no representation regarding, and gives no warranty of compliance with, any law other than as expressly stated in this DPA and the SSA.

Clause 26 — Customer Affiliates

  1. Where Customer’s Affiliates use the Services under Customer’s Order Form, Customer enters into this DPA on behalf of itself and those Affiliates, which are "Customer" for the purposes of this DPA in respect of the Personal Data Processed on their behalf.

  2. Customer alone exercises the rights and remedies under this DPA for itself and its Affiliates, and Provider’s notices and communications to Customer discharge any obligation to notify or communicate with a Customer Affiliate. A Customer Affiliate that is entitled under Data Protection Laws to enforce this DPA directly does so through Customer, unless Data Protection Laws require otherwise.

Clause 27 — Liability

The limitations and exclusions of liability in the Section of the SSA titled "Limitations of Liability" apply to the Parties' liability as between themselves under this DPA, including the SCCs, to the maximum extent permitted by the SCCs and Data Protection Laws, and any reference in that Section to the liability of a Party means the aggregate liability of that Party and its Affiliates under the SSA and this DPA together. For the avoidance of doubt: (i) the liability of either Party to a data subject for material or non-material damages under Article 82 of the GDPR, the UK GDPR or the SCCs is governed exclusively by those instruments and cannot be limited by this Clause 27 as between the Parties and the data subject; and (ii) this Clause 27 applies to liability under the SCCs only to the extent the SCCs permit the Parties to limit their liability to each other, and the SCCs otherwise continue to operate as drafted.

Clause 28 — Governing law and forum

This DPA is governed by the law that governs the SSA, and disputes are resolved as provided in the SSA, except that the SCCs are governed by the law and subject to the courts selected in Clause 13(e) and (f), and the UK Addendum as provided in it.

Clause 29 — Relationship to the SSA; prior data-processing terms

  1. This DPA forms part of the SSA and is incorporated by reference into it, and forms part of the Agreement between the Parties.

  2. This DPA replaces any data-processing terms previously in force between the Parties for the same Processing, including Annex 1 (EU) — Data Processing Agreement version 1.1 and earlier versions and Annex 2 (UK) — UK Addendum to the Data Processing Agreement version B1.0, from the date this DPA takes effect for Customer under the preamble. It does not modify any term expressly negotiated by the Parties and recorded in a signed Order Form or addendum, which continues to apply in accordance with the provision of the Section of the SSA titled "Amendment and Waiver" that preserves terms expressly negotiated by the Parties and recorded in a signed Order Form or addendum.

  3. Where this DPA replaces version 1.1, the Clauses of Part A are the same standard contractual clauses, with the same selections, as in version 1.1; the Annexes are updated under Clause 10(e); and Parts B, C and D take effect under Clause 21(c). Where the SSA is amended in the same notice, the amendment of the SSA takes effect immediately before this DPA.

Clause 30 — Contact

Notices to Provider under this DPA are given as provided in the Section of the SSA titled "Notices". Provider’s contact for data-protection matters is dpo@maestra.io.

Annex I — List of Parties

A. Controller (data exporter)

Name and address: Customer, as identified in the Order Form. Contact person’s name, position and contact details: as set forth in the Order Form. Activities relevant to the data transferred under these Clauses: the Processing described in Annex II. Role: controller or, where Clause 13(a) so provides, processor.

B. Processor (data importer)

Name and address: the Maestra entity identified as the Provider in the Order Form — Maestra.io LLC, 1167 Massachusetts Ave, Arlington, MA 02476, United States, or Maestra B.V., Haarlemmerweg 331A, 1051 LH Amsterdam, the Netherlands. Contact person’s name, position and contact details: Data Protection Person, dpo@maestra.io. Activities relevant to the data transferred under these Clauses: provider of the Maestra Platform, a software platform for customer data management and marketing automation distributed as software-as-a-service, in the course of which Provider Processes Personal Data as a processor. Role: processor.

C. Competent supervisory authority

Where Provider is Maestra B.V.: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands, https://autoriteitpersoonsgegevens.nl/en. Where Provider is Maestra.io LLC: the supervisory authority determined in accordance with SCC Clause 13. For Personal Data of data subjects in the United Kingdom: the Information Commissioner’s Office (or its successor) (Annex V).

Annex II — Description of the Processing

  1. Categories of data subjects: End Customers (Customer’s customers, subscribers and prospects, and visitors to Customer’s websites, online stores and mobile applications) and Authorized Users, as described in the Section of Annex 1 to Exhibit C titled "Data subjects".
  2. Categories of Personal Data: the categories described in the Section of Annex 1 to Exhibit C titled "Categories of PII, by Data Type" — identifiers; internet or other electronic network activity information; commercial information; characteristics of protected classifications where Customer configures the Services to collect them; geographic area; inferences — and the data collected by Provider’s Tracking Technologies as described in the Section of Annex 1 to Exhibit C titled "Default Collection by Tracking Technologies". The scope of Personal Data Processed for a given Customer is determined by Customer as described in the Section of Annex 1 to Exhibit C titled "Scope determined by Customer".
  3. Sensitive data: the Services are not intended for, and the Acceptable Use Policy prohibits, the Processing of sensitive data within the meaning of Clause 7.5 and of sensitive personal information within the meaning of US State Privacy Laws. Sensitive data is not part of Default Collection. Where Customer nonetheless configures the Services to Process such data, the measures in Exhibit C apply to it, and Customer is responsible, as stated in the Section of Annex 1 to Exhibit C titled "Categories of PII, by Data Type" and in the Sections of the SSA titled "Customer Control and Responsibility" and "Access and Security", for the lawful basis, notices and consents such Processing requires.
  4. Frequency of the transfer: continuous, for the duration of the SSA.
  5. Nature of the Processing: hosting, storage, organisation, analysis, segmentation, transmission of communications, personalisation, reporting and the other operations described in the SSA, Exhibit C (the Sections of Annex 1 titled "Roles and purpose", "Sources" and "Scope determined by Customer") and the Documentation, performed through the Services on Customer’s instructions.
  6. Purpose of the Processing: the provision of the Services to Customer under the SSA and on Customer’s documented instructions (Clause 19; the Section of the US SSA titled "Privacy and Data Protection Roles"), and for no other purpose.
  7. Duration of the Processing and retention: the Term of the SSA. Retention during the Term is set by Customer in accordance with the paragraph of Exhibit C headed "Retention". On termination or expiration, Personal Data is returned or deleted in accordance with Clause 10(d) and within the period stated in the Section of the SSA titled "Effect of Termination or Expiration". Return is effected by export of the Personal Data in the standard formats of the Services: through the export functions of the Services, which are available to Customer until the effective date of termination or expiration, and after that date by Provider Personnel on Customer’s written request made within thirty (30) days after termination or expiration (the period stated in that Section); Provider may effect return by other means at its discretion. If Customer makes no request within those thirty (30) days, Provider deletes the Personal Data within ninety (90) days after termination or expiration. Backups are deleted within the period stated in the paragraph of Exhibit C headed "Backup".
  8. Transfers to Sub-processors: the subject matter, nature and duration of the Processing by each Sub-processor are those stated for it on the Sub-processor List (purpose column) and in this Annex II; each Sub-processor Processes Personal Data only for the duration of its engagement and deletes or returns it in accordance with Clause 7.7(b).

Annex III — Technical and Organisational Measures

The technical and organisational measures implemented by Provider and its Sub-processors to ensure the security of Personal Data, including the measures by which Provider assists Customer under Clause 8, are those described in Exhibit C, as updated from time to time in accordance with the Section of Exhibit C titled "Updates". Provider’s information security programme is audited annually against the SOC 2 Type II standard, and the report is available as provided in Clause 22(a) and in the Section of Exhibit C titled "Security Programme". Assistance under Clause 8 is provided first through the functions of the Services for the access, export, correction and deletion of End Customer records described in the Documentation.

Annex IV — Sub-processors

  1. Provider engages the Sub-processors published on the Sub-processor List at https://maestra.io/legal/subprocessors, which is incorporated into this DPA by reference. The list states each Sub-processor’s name, location and purpose. The list as in force on the date this DPA takes effect for Customer is the agreed list for the purposes of Clause 7.7 and Clause 20; changes are notified in accordance with those Clauses.
  2. Maestra.io LLC (United States) is a Sub-processor for Customers contracting with Maestra B.V., and Maestra B.V. (the Netherlands) is a Sub-processor for Customers contracting with Maestra.io LLC, in each case for the operation, support and technical maintenance of the Services. Transfers of Personal Data between Maestra B.V. and Maestra.io LLC that are subject to Chapter V of the GDPR are covered by standard contractual clauses (Module Three) between the two entities, as provided in Clause 7.8(b). Provider shall ensure that the agreement between Maestra B.V. and Maestra.io LLC under which the other Maestra entity acts as Sub-processor provides that, if Provider has factually disappeared, ceased to exist in law or become insolvent, the other Maestra entity will act on Customer’s instruction to delete or return the Personal Data held by any Sub-processor engaged for the Services.
  3. Transfers of Personal Data to any other Sub-processor established in a third country are covered by standard contractual clauses between Provider (or its Affiliate) and the Sub-processor or by an adequacy decision applicable to the Sub-processor, as provided in Clause 7.8(b). Information on the mechanism applicable to a particular Sub-processor, on the further sub-processors engaged by a Sub-processor as disclosed by that Sub-processor, and a copy of the sub-processor agreement, are available on request in accordance with Clause 7.7(c).

Annex V — UK Addendum tables

Table 1: Parties. Exporter: Customer; Importer: Provider, as identified in Annex I; start date: the date this DPA takes effect for Customer.

Table 2: Selected SCCs, Modules and Selected Clauses. The SCCs incorporated by Clause 12 — Commission Implementing Decision (EU) 2021/914; Module Two (Controller to Processor) or, where Clause 13(a) so provides, Module Three (Processor to Processor); Docking Clause not applied; general written authorisation for Sub-processors with thirty (30) calendar days' advance notice of changes, or shorter notice in the circumstances set out in Clause 7.7(a); independent dispute resolution not applied; Annexes as set out in Clause 13(g).

Table 3: Appendix Information. Annex I (List of Parties; competent supervisory authority — for UK Personal Data, the Information Commissioner’s Office (or its successor), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, +44 (0) 303 123 1113, https://ico.org.uk), Annex II (Description of the Processing), Annex III (Technical and Organisational Measures) and Annex IV (Sub-processors) to this DPA.

Table 4: Ending this Addendum when the Approved Addendum changes. Neither Party may end the UK Addendum solely because the Information Commissioner’s Office has issued a revised Approved Addendum (as defined in the UK Addendum) that changes the Mandatory Clauses (as so defined), provided that the revised Approved Addendum can reasonably be operated by Provider in the ordinary course of business; if the revised Approved Addendum materially affects the Processing and the Parties cannot reasonably operate under it, either Party may end the UK Addendum on thirty (30) days' prior written notice to the other Party.

Archived versions:

Annex 1 (EU) — Data Processing Agreement, Version 1.1, published until 09/16/2026 (for Agreements in effect before that date, in force until 10/23/2026)

Version 1.0, in force until 07/23/2026

Annex 2 (UK) — UK Addendum to the Data Processing Agreement, Version B1.0, published until 09/16/2026 (for Agreements in effect before that date, in force until 10/23/2026)