PAIRITY ABA

Data Processing Addendum

Last updated: July 13, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between R2 Technologies LLC, a California limited liability company operating the Pairity platform (“Pairity,” “we,” “us”), and the customer organization named on the applicable Order Form or Master Subscription Agreement (“Customer,” and together the “Agreement”). It describes how we process personal information on Customer's behalf in the course of providing the Pairity platform.

Where we process protected health information (“PHI”) for Customer, the Business Associate Agreement (“BAA”) between the parties governs that PHI, and the BAA controls over this DPA to the extent of any conflict.

1. Roles

Customer determines the purposes and means of processing the personal information it enters into the platform, and we process it only on Customer's behalf and under Customer's instructions. Under U.S. state privacy laws, we act as Customer's “service provider” or “processor”; under HIPAA, we act as Customer's business associate.

2. Scope and details of processing

3. Our obligations

We will:

4. Security

We maintain administrative, technical, and physical safeguards designed to protect Customer Data, including:

5. Subprocessors

Customer authorizes us to engage subprocessors to help provide the service — currently cloud hosting (Amazon Web Services) and transactional email delivery. We contractually require subprocessors to protect Customer Data to a standard no less protective than this DPA, and we remain responsible for their performance. We will give Customer notice of any new subprocessor that will process Customer Data, and Customer may object on reasonable data-protection grounds; if we cannot resolve the objection, Customer may terminate the affected service.

6. Security incidents

If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, we will notify Customer without undue delay, provide information reasonably available to us about the incident, and take reasonable steps to contain and remediate it. Notification of incidents involving PHI follows the timelines in the BAA.

7. Assistance

Taking into account the nature of the processing, we will reasonably assist Customer in responding to requests from individuals to exercise their privacy rights (access, correction, deletion), and in meeting Customer's obligations regarding security, incident notification, and privacy assessments. If we receive a request directly from an individual whose data Customer controls, we will direct them to Customer, as described in our Privacy Policy.

8. Return and deletion

During the term, Customer can export its data from the platform. Upon termination or expiration of the Agreement, we will make Customer Data available for export for thirty (30) days, then delete it from active systems, except where retention is required by law. Data governed by the BAA is returned or destroyed as the BAA provides.

9. Audits

Upon reasonable written request, no more than once per year, we will make available information reasonably necessary to demonstrate compliance with this DPA — such as security documentation and summaries of third-party assessments — and will reasonably cooperate with audits required of Customer by law or regulators, subject to confidentiality and reasonable scheduling.

10. Data location

Customer Data is hosted in the United States. We will not transfer Customer Data outside the United States without Customer's prior consent.

11. Precedence and term

This DPA takes effect on the effective date of the Agreement and remains in force for as long as we process Customer Data. If this DPA conflicts with the Agreement, this DPA controls as to the processing of personal information; the BAA controls as to PHI.

12. Contact

Questions about this DPA or to request a signed copy: info@pairityaba.com.