Chispa

Data Processing Agreement

Effective date: 2026-08-06, Version 2026-08-06.19ee66a908, Operated by JPAgency LLC

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Terms") and applies where JPAgency LLC ("Processor") Processes Personal Data on behalf of you ("Controller") in providing the Service. It reflects Article 28 of the EU/UK General Data Protection Regulation and comparable laws. Where this DPA conflicts with the Terms on data-protection matters, this DPA controls.

1. Definitions

"Applicable Data Protection Law" means all privacy and data-protection laws applicable to a party's Processing, including the EU GDPR, the UK GDPR and U.S. state privacy laws. "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings in Applicable Data Protection Law. "Sub-Processor" means a third party engaged by the Processor to Process Personal Data under this DPA. "SCCs" means the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (or any successor). "UK IDTA" means the UK International Data Transfer Agreement or Addendum issued by the UK Information Commissioner's Office. Capitalized terms not defined here have the meaning given in the Terms.

2. Roles

You are the Controller of the Personal Data Processed under this DPA, and the Processor Processes it only on your documented instructions. The Terms, the Privacy Policy, this DPA and any explicit written instructions you provide constitute your documented instructions. Each party will comply with its obligations under Applicable Data Protection Law. You represent that your instructions and your use of the Service comply with Applicable Data Protection Law and that you have provided all notices and obtained all consents required for the Personal Data you route through the Service, including Fan data.

3. Subject-matter, duration, nature and purpose

The subject-matter is the Processing of Personal Data to provide the Service under the Terms, for the term of the Terms plus the retention periods in the Privacy Policy and Section 12. The nature and purpose of Processing is the storage, retrieval, organization, structuring, transmission, adaptation and analysis of Personal Data to: (a) provide the CRM, dashboard, analytics, scheduling and the AI Copilot; (b) enable communication with Fans on behalf of Managed Creators; (c) compute Attributed Sales and billing; (d) develop, secure and improve the Service and its models through aggregated and de-identified data (see Section 5); and (e) fulfill your instructions. The categories of Data Subjects and Personal Data are described in Exhibit A.

4. Processor obligations

The Processor will: (a) Process Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by law (in which case it will inform you before Processing unless the law prohibits such notice); (b) ensure that persons authorized to Process are bound by confidentiality; (c) implement the technical and organizational measures in Exhibit B; (d) assist you, by appropriate measures and taking into account the nature of Processing, to respond to Data Subject requests and to meet your obligations under Articles 32–36 GDPR (security, breach notification, impact assessments, prior consultation); (e) notify you of a Personal Data Breach without undue delay after becoming aware; and (f) at your choice, delete or return Personal Data at the end of the Service, subject to Section 12.

5. Aggregated and de-identified data

Data that has been aggregated or de-identified so that it no longer identifies, and cannot reasonably be used to identify, a Data Subject is not Personal Data and is not subject to this DPA. As stated in Section 10.3 of the Terms, the Processor may use such data to operate, secure, evaluate and improve the Service and its models. The Processor will not attempt to re-identify such data and will maintain it in de-identified form.

6. Sub-processors

You give the Processor general authorization to engage Sub-Processors to Process Personal Data. Current Sub-Processor categories are described in Exhibit C and in the Privacy Policy. The Processor imposes on each Sub-Processor data-protection obligations substantially equivalent to this DPA and remains responsible for its Sub-Processors' performance. The Processor will make available the current Sub-Processor list on request and give reasonable notice of a new Sub-Processor, and you may object on reasonable data-protection grounds; if the parties cannot resolve the objection, you may terminate the affected part of the Service.

7. International transfers

The Processor operates from the United States and may Process Personal Data in other countries. Where Personal Data subject to EU or UK law is transferred to a country without an adequacy decision, the transfer is made under an appropriate mechanism, including the SCCs and, for UK data, the UK IDTA, which are incorporated by reference (see Exhibit D). The parties agree to the SCCs' module for controller-to-processor transfers, with the elections in Exhibit D.

8. Security

The Processor implements and maintains the technical and organizational measures in Exhibit B, appropriate to the risk. The Processor may update these measures and will not materially decrease overall security during the term.

9. Personal Data Breach

The Processor will notify you without undue delay after becoming aware of a Personal Data Breach affecting your Personal Data, and will provide information reasonably available to help you meet your own notification obligations. Notification is not an acknowledgment of fault.

10. Data Subject rights

Taking into account the nature of Processing, the Processor will assist you by appropriate measures to respond to Data Subject requests to exercise rights of access, rectification, erasure, restriction, portability and objection. Where a Data Subject contacts the Processor directly regarding your data, the Processor will refer them to you.

11. Audits

The Processor will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior written notice, subject to confidentiality, no more than once per year unless required by a Supervisory Authority or following a Personal Data Breach.

12. Return and deletion

At the end of the Service, the Processor will, at your choice, delete or return your Personal Data within a reasonable period, and delete existing copies unless retention is required by law. Certain compliance and financial records, and immutable message/audit archives, may be retained for the periods described in the Privacy Policy.

13. Liability, priority and governing law

Each party's liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the law that governs the Terms, except where Applicable Data Protection Law or the SCCs require otherwise. In case of conflict, the order of precedence is: the SCCs, then this DPA, then the Terms.

14. Contact

Data-protection contact: [email protected].

Exhibit A, Description of processing

Data Subjects: your team members, managers and chatters; the Managed Creators whose accounts you connect; and the Fans/subscribers who interact with those accounts. Categories of Personal Data: account identifiers and public handles; message content and metadata; Fan names, notes, tags and spending patterns; connection and session credentials (encrypted); billing and usage records; and IP address and the country derived from it (via our edge/CDN provider) for security and abuse prevention. Sensitive data: you must not use the Service to Process special-category data beyond what is inherent to the connected platforms. Nature/purpose and duration: as in Sections 3 and 12.

Exhibit B, Technical and organizational measures

The Processor maintains at least the following measures, which may evolve without materially decreasing overall security:

Access control: role-based access with least privilege; optional two-factor authentication for user accounts; server-to-server administrative operations gated by a secret and, where configured, an IP allowlist; production access limited to authorized personnel with a business need; the ability to sign out of all sessions.

Encryption and credentials: TLS for data in transit; sensitive connection and session credentials encrypted at rest; account passwords stored using industry-standard salted hashing; session tokens stored hashed server-side with sliding expiry and revocation; authentication cookies set HttpOnly and, under HTTPS, Secure.

Request integrity: HMAC-based signing of API requests to resist tampering and replay.

Network and platform: served behind a CDN/edge and reverse proxy with HTTPS, HSTS and a content-security policy; rate limiting on sensitive endpoints (persisted across restarts); restricted inbound/outbound traffic.

Tenant isolation: per-organization scoping of data and access.

Logging, resilience and governance: audit logging of sensitive actions; automated database backups with rotation and a documented retention/pruning policy; security reviews and periodic penetration testing.

Exhibit C, Sub-processors

The Processor engages Sub-Processors in the following categories to provide the Service. The current specific list is available on request.

· Cloud and hosting infrastructure, application hosting, database, storage and compute.
· Edge, CDN and network security, content delivery, TLS, DDoS and bot mitigation.
· AI inference providers, language and vision model inference for the AI Copilot (data minimized; used to generate drafts and content descriptions).
· Cryptocurrency payment processor, processing of prepaid top-ups.
· Transactional email provider, delivery of Service-related emails.

Exhibit D, Standard Contractual Clauses

Where the SCCs apply (Section 7): the controller-to-processor module applies; you are the data exporter and the Processor the data importer; the optional docking clause applies; the governing law and forum are those of an EU Member State with jurisdiction, as required by the SCCs; the technical and organizational measures are those in Exhibit B; and the Sub-Processors are those in Exhibit C. For transfers of UK data, the UK IDTA/Addendum applies and amends the SCCs accordingly. Signing the Terms and accepting this DPA constitutes signature of the SCCs where they apply.

© 2026 JPAgency LLC. [[REGISTERED ADDRESS]]. Contact: [email protected].