Effective Date: July 17, 2026

This Data Processing Addendum (“DPA”) is entered into between Thrum, Inc., doing business as QuarqAI (“QuarqAI”, “Processor”, “we”, “us”, or “our”), and the customer identified in the applicable Order Form or Statement of Work (“Customer”, “Controller”, or “you”). This DPA supplements and is incorporated by reference into the Master Service Agreement or other written agreement between QuarqAI and Customer governing Customer’s use of the QuarqAI Services (the “Agreement”). Capitalized terms not defined here have the meaning given in the Agreement or our Privacy Policy.

1. Definitions

2. Roles of the parties

2.1 Scope. This DPA applies only to the Processing of Customer Personal Data by QuarqAI on behalf of Customer in the course of providing the Services. It does not apply to information QuarqAI collects as an independent controller in its own right (for example, billing contact information or Site analytics), which is addressed in our Privacy Policy.

2.2 Roles. As between the parties, Customer is the Controller (or, for CCPA purposes, the Business) of Customer Personal Data, and QuarqAI is the Processor (or Service Provider) acting on Customer’s documented instructions as set out in the Agreement, this DPA, and Customer’s ordinary use of the Services’ configurable functionality.

2.3 Customer responsibilities. Customer is responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which Customer acquired it; (b) ensuring it has a valid legal basis to disclose Customer Personal Data (including data about Customer’s own partners, contacts, and personnel) to QuarqAI for Processing as contemplated by the Agreement; and (c) any instructions it issues to QuarqAI regarding the Processing of Customer Personal Data.

3. Processing of Customer Personal Data

3.1 Instructions. QuarqAI will Process Customer Personal Data only on documented instructions from Customer, including regarding transfers of Customer Personal Data to a third country, unless required to do so by law, in which case QuarqAI will inform Customer of that legal requirement before Processing unless the law prohibits this on important grounds of public interest. The Agreement, this DPA, and Customer’s configuration and use of the Services constitute Customer’s complete and documented instructions to QuarqAI.

3.2 Details of Processing. The subject matter, duration, nature and purpose of Processing, types of Customer Personal Data, and categories of Data Subjects are described in Annex 1 below.

3.3 Confidentiality. QuarqAI ensures that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.4 AI-assisted Processing. Where Customer elects to use QuarqAI features that invoke third-party large language model providers (“AI Sub-processors”) to analyze Customer Personal Data, QuarqAI will (a) engage only AI Sub-processors that are contractually prohibited from using Customer Personal Data to train their own general-purpose or foundation models and from retaining Customer Personal Data beyond the period needed to return a result, and (b) apply data-minimization and redaction measures designed to limit the Customer Personal Data transmitted to what is reasonably necessary to generate the requested output. QuarqAI will not itself use Customer Personal Data to train any foundation or generalized model without Customer’s prior written consent.

4. Sub-processors

4.1 General authorization. Customer provides QuarqAI a general authorization to engage Sub-processors to Process Customer Personal Data, provided QuarqAI: (a) maintains a list of current Sub-processors as set out in Annex 3 below; (b) imposes data protection terms on each Sub-processor substantially no less protective than this DPA; and (c) remains liable to Customer for each Sub-processor’s performance.

4.2 Notice of new Sub-processors. QuarqAI will provide reasonable advance notice, by updating Annex 3 and, where practicable, by email to Customer’s designated contact, before authorizing a new Sub-processor to Process Customer Personal Data. If Customer objects on reasonable data-protection grounds within fifteen (15) days of notice, the parties will work in good faith to resolve the objection. If no resolution is reached, Customer may terminate the affected Services as its sole remedy.

5. Security measures

5.1 Technical and organizational measures. QuarqAI implements and maintains the technical and organizational security measures described in Annex 2 below and on our Security page, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

5.2 Certifications. As of the Effective Date, QuarqAI aligns its security program with SOC 2 and ISO 27001 control frameworks but has not obtained formal certification under either framework. QuarqAI will notify Customer of any material change in this status. A current security overview is available on written request to contact@quarq.ai, subject to confidentiality obligations.

6. Personal Data Breach notification

QuarqAI will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, including, to the extent then known, the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed. QuarqAI will cooperate with Customer to help it meet its own notification obligations under Applicable Data Protection Laws.

7. Assistance with data subject rights and compliance

7.1 Data subject requests. QuarqAI will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to enable Customer to respond to Data Subject requests under Applicable Data Protection Laws (including access, rectification, erasure, restriction, portability, and objection). If QuarqAI receives such a request directly, it will promptly redirect it to Customer and will not respond directly except to confirm receipt or as required by law.

7.2 Data protection impact assessments. QuarqAI will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that Customer reasonably considers necessary.

8. International transfers

QuarqAI is based in the United States. To the extent QuarqAI’s Processing of Customer Personal Data involves a transfer of Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland to the United States or another country not recognized as providing an adequate level of data protection, the parties agree such transfer is governed by the Standard Contractual Clauses (Module Two: Controller to Processor), incorporated by reference into this DPA, with Customer as “data exporter” and QuarqAI as “data importer”. For UK GDPR transfers, the parties adopt the UK Addendum to the SCCs. Where a Sub-processor Processes Customer Personal Data outside the country of origin, QuarqAI ensures an appropriate transfer mechanism is in place with that Sub-processor.

9. Audit rights

On Customer’s written request, no more than once per twelve (12)-month period (except following a confirmed Personal Data Breach or as required by a supervisory authority), QuarqAI will make available information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through QuarqAI’s security documentation, a written questionnaire response, or, if those are insufficient, a mutually scheduled audit by an independent third-party auditor bound by confidentiality, at Customer’s expense.

10. Return and deletion of Customer Personal Data

Upon expiration or termination of the Agreement, or earlier upon Customer’s written request, QuarqAI will, within thirty (30) days, delete or return (at Customer’s election) all Customer Personal Data in its possession, including copies held by Sub-processors, except to the extent applicable law requires longer retention, in which case QuarqAI will isolate and protect that data until the retention requirement lapses.

11. Liability

Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA relieves either party of its own direct responsibilities and liabilities under Applicable Data Protection Laws.

12. Term; order of precedence

This DPA takes effect on the Effective Date and remains in force for as long as QuarqAI Processes Customer Personal Data on behalf of Customer under the Agreement. In the event of a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls. In the event of a conflict between this DPA and the Standard Contractual Clauses incorporated herein, the Standard Contractual Clauses control.

13. Incorporation and contact

This DPA is incorporated by reference into the Agreement between QuarqAI and Customer. If Customer requires a countersigned copy for its own records, contact contact@quarq.ai.

Annex 1: Details of Processing

Subject matter: Provision of the QuarqAI partnership-intelligence platform, including data ingestion, normalization, analytics, dashboards, and related support services described in the Agreement and applicable Order Form.

Duration: For the term of the Agreement, plus any post-termination retention or export period specified in the Agreement or Section 10 above.

Nature and purpose: Collection, storage, organization, analysis, and reporting of Customer’s partner-ecosystem data in order to calculate partnership metrics (e.g., Total Partner Value, Shared Value Index, Capital Efficiency Ratio, Value Exchange Pathways) and to provide dashboards, alerts, and integrations requested by Customer.

Categories of Data Subjects: Customer’s personnel and authorized users; personnel and representatives of Customer’s business partners, resellers, and channel contacts; and, where included in Customer Data, personnel of Customer’s end customers or leads referenced in partner-sourced deal records.

Types of Personal Data: Business contact information (name, business email, phone, title, employer); account and authentication data for Customer’s users; deal, opportunity, and revenue-attribution records associated with named individuals; and any other Personal Data Customer elects to include in Customer Data. Special categories of data are not intended to be Processed, and Customer should not submit special-category data to the Services.

Frequency of transfer: Continuous, for as long as Customer uses the Services.

Annex 2: Technical and organizational security measures

A full description of QuarqAI’s security measures, including encryption, access control, tenant isolation, and monitoring, is maintained on our Security page and summarized below:

Annex 3: Authorized Sub-processors

Google Cloud Platform (GCP) — cloud hosting and infrastructure for the Services (United States).

Syncari — data integration and synchronization pipeline.

Anthropic and other AI providers — AI inference for partner-ecosystem analysis, invoked only when explicitly used by Customer (United States).

HubSpot — customer relationship management and customer communications (United States).

This list may be updated from time to time in accordance with Section 4.2 above. Questions about this DPA can be directed to contact@quarq.ai.