Shipping Container - Altana

September 2026

Data Processing Addendum

Company Address

Altana Technologies, Inc.
25 Kent Ave
Suite 501
Brooklyn, NY 11249-1060
USA

THIS DATA PROCESSING ADDENDUM (“DPA”) GOVERNS THE PROCESSING BY ALTANA OF CUSTOMER PI (AS DEFINED BELOW) PROVIDED BY YOU. THE “EFFECTIVE DATE” OF THIS AGREEMENT IS THE DATE IDENTIFIED IN ANY APPLICABLE ORDER FORM ISSUED BY US (“ALTANA”) TO YOU (“YOU” OR “CUSTOMER”). IF YOU HAVE EXECUTED A SEPARATE DPA WITH ALTANA, THE TERMS AND CONDITIONS OF THAT SEPARATE DPA WILL TAKE PRECEDENCE AS TO YOUR TRANSACTION. THIS DPA APPLIES SOLELY TO THE EXTENT YOU SHARE CUSTOMER PI WITH ALTANA PURSUANT TO THE PLATFORM ACCESS AGREEMENT (THE “AGREEMENT”). ALTANA AND CUSTOMER ARE EACH A “PARTY” AND TOGETHER THE “PARTIES”.

1. Definitions

All capitalized terms not defined herein shall have the meaning given to them in the Agreement.
Customer PI” means Personal Information contained in Customer Data that is Processed by Altana on behalf of Customer. For clarity, Customer PI is limited to PI contained in Customer Data that is uploaded or otherwise submitted to Altana through use of the Platform. Customer PI excludes any information related to users of the Altana Platform or collected for administrative, account, support, security, compliance, or other operational purposes.
Data Protection Laws” means applicable data protection or privacy laws.
Personal Information” (“PI”) means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked (directly or indirectly) with a particular individual or household, or is otherwise defined as “personal information” or “personal data” under relevant Data Protection Laws.
PI Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer PI in the possession, custody or control of Altana.
Sub-Processor” means an entity engaged by Altana to Process Customer PI on behalf of Customer in connection with the Services performed pursuant to the Agreement.
The terms “Controller,” “Data Subject,” “Processing,” “Processor” and “Sell” will each have the meanings given to them under relevant Data Protection Laws.

2. Processing Description

2.1. Subject-Matter, Nature and Purpose of the Processing. The purpose of Processing of Customer PI is to enable Altana to perform the Services described in the Agreement. Customer PI will be collected, analyzed, shared and stored by Altana for purposes of providing the Services. Additional information regarding the subject-matter, nature and purpose of the Processing may be set out in applicable Order Forms.
2.2. Duration of the Processing. Customer PI will be Processed to perform the Services for the duration of the Agreement.
2.3. Types of Customer PI and Categories of Data Subjects. The types of Customer PI Processed and categories of Data Subjects are described in the Summary of Services in the Order Forms.

3. Altana Obligations

3.1. Processing Role. Unless otherwise required by applicable law, Altana will Process Customer PI as a Processor on behalf of and in accordance with Customer’s written instructions as set forth in this DPA and the Agreement. Altana is hereby instructed to Process Customer PI to the extent necessary to enable Altana to perform the services under the Agreement, this DPA and any applicable written agreement between the Parties, or as otherwise permitted by relevant Data Protection Laws. A description of the Processing of Customer PI is provided in Exhibit 1 hereto. Unless prohibited by applicable law, Altana will inform Customer if, in Altana’s opinion, an instruction infringes applicable law.
3.2. Processing Restrictions. Altana will not (1) Sell Customer PI or share Customer PI for cross-context behavioral advertising purposes; (2) retain, use or disclose Customer PI (i) for any purpose other than for the specific business purpose of providing the Services, or as otherwise required or permitted by applicable law, or (ii) outside of the direct business relationship between the Parties; or (3) combine Customer PI with Personal Information received from or on behalf of another person, or collected from Altana’s own interactions with individuals, unless permitted by Data Protection Laws. Each Party may take reasonable and appropriate steps to (1) ensure that the other Party uses Customer PI in a manner consistent with its obligations under Data Protection Laws and (2) upon notice to the other Party, stop and remediate the unauthorized use of Customer PI. Each Party shall promptly notify the other Party if at any time the Party determines that it can no longer meet its obligations under Data Protection Laws.
3.3. Compliance. Altana will comply with relevant provisions of Data Protection Law applicable to Processors and provide the level of privacy protection for Customer PI as required by relevant Data Protection Law. Altana may deidentify or aggregate Customer PI as part of providing the Services. If Altana deidentifies or aggregates Customer PI or receives deidentified data from Customer, Altana will, to the extent required by applicable law, take (1) reasonable measures to ensure that the deidentified data cannot be associated with a natural person or household and (2) other steps necessary to Process de-identified data as required by Data Protection Law. Except for the foregoing, no other obligation or restriction in this DPA will apply to any deidentified information Processed pursuant to this DPA.
3.4. Assistance. At Customer’s request, Altana will provide Customer with commercially reasonable assistance as necessary for the fulfilment of Customer’s obligations under Data Protection Laws, including Customer’s obligations to (i) respond to requests from Data Subjects to exercise rights with respect to Altana’s Processing of Customer PI, (ii) implement appropriate data security measures, (iii) carry out data protection impact assessments, and (iv) consult competent supervisory authorities under Data Protection Laws. Altana will provide such assistance only to the extent that the assistance is necessary for the fulfilment of Customer’s obligations under Data Protection Laws and concerns Altana’s Processing of Customer PI. Customer will be responsible for any costs and expenses arising from such assistance.
3.5. Data Security. Altana will implement commercially reasonable technical and organizational measures designed to maintain a level of security for Customer PI appropriate to the level of risk associated with the relevant Processing of Customer PI. Altana will take commercially reasonable steps to ensure that Altana personnel who Process Customer PI are subject to confidentiality obligations with respect to Customer PI. Altana will notify Customer and provide reasonable information regarding any PI Breach that occurs in the course of Processing Customer PI as a Processor and will act reasonably in cooperating with Customer in the context of any notifications required by Data Protection Law.
3.6. Data Return. Upon the expiration or earlier termination of the Agreement, Altana will delete (or return, at Customer’s election) all Customer PI in the possession or control of Altana, unless the continued retention of such Customer PI is permitted by applicable law. Customer will be responsible for all fees and expenses associated with the return or deletion of Customer PI. Notwithstanding the foregoing, Altana may retain (i) Customer PI as required by law or expressly agreed by Customer or (ii) Customer PI that is stored in accordance with regular computer back-up operations. Altana will not actively use such Customer PI after termination of the Agreement, unless required to do so by applicable law.
3.7. Information Requests. Altana will make available to Customer all reasonable information necessary to demonstrate compliance with the obligations set forth in this DPA and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer. Altana will provide information pursuant to this Section only to the extent that the information concerns Altana’s Processing of Customer PI and will not violate Altana’s confidentiality obligations or legal protections. Any inspection pursuant to this Section will (i) be performed only once annually with reasonable prior written notice to Altana, (ii) be mutually agreed upon by the Parties, and (iii) not unreasonably interfere with the normal conduct of Altana’s business. Altana may, in its sole discretion, restrict access to information or facilities to avoid compromising the security confidentiality or integrity of Altana’s business information or systems. All audits performed pursuant to this Section will consist solely of: (1) a summary of its information security and privacy policies applicable to the Services; (2) to the extent available, a SOC 2 report relevant to the Services that has been performed by a qualified third-party auditor on behalf of Altana within twelve (12) months of Customer’s audit request; and (3) cooperation in responding to reasonable inquiries from Customer related to the results of such summary information. Customer will be responsible for any costs and expenses incurred by Altana in complying with a request made pursuant to this Section.

4. Customer Obligations

4.1. Compliance. Customer will use the Services and disclose Customer PI to Altana in compliance with Data Protection Laws. Customer represents and warrants that Customer has all rights and permissions necessary to lawfully share Customer PI with Altana for the purposes contemplated by the Services. Where required by Data Protection Laws, Customer will be responsible for providing notice to individuals and obtaining and maintaining all necessary consents, to use and disclose Customer PI to Altana for the performance of the Services. Should an individual withdraw such consent, Customer is responsible for promptly communicating such withdrawal to Altana in writing. Customer will take all reasonable steps to ensure that Customer PI is accurate, complete and up-to-date.

5. Data Transfers

5.1. Jurisdictional Transfers. Customer authorizes Altana to transfer Customer PI to any jurisdiction in which Altana or its Sub-Processors are located, including, but not limited to, the United States.
5.2. EEA, UK and Switzerland Data Transfers. To the extent Customer transfers Customer PI to Altana from the European Economic Area (“EEA”), UK and/or Switzerland, the Data Transfer Appendix (as appended) will apply.
5.3. Sub-Processors. Customer authorizes Altana to appoint Sub-Processors to perform specific Processing activities on its behalf. Where Altana engages a Sub-Processor to Process Customer PI, Altana will enter into written agreements with the Sub-Processor that imposes obligations on the Sub-Processor that are substantially similar to those imposed on Altana under this DPA. Altana will inform Customer of intended changes concerning the addition or replacement of its Sub-Processors, and Customer will have an opportunity to object to such changes on reasonably justifiable grounds related to the inability of such Sub-Processors to protect Customer PI in accordance with the relevant obligations of this DPA. If Customer objects within fourteen (14) calendar days after being notified, Altana will use reasonable efforts to find an alternative. If a suitable alternative or other solution cannot be found, then Customer may terminate the relevant services without fault to either Party.

6. Miscellaneous

6.1. Term. This DPA is effective for the term of the Agreement.
6.2. Governing Law; Venue. This DPA and any non-contractual obligations arising in connection with it will be governed by and construed under the laws of the jurisdiction specified in the Agreement, notwithstanding any governing law identified under Clause 17 of the SCC. Notwithstanding any choice of forum and jurisdiction identified under Clause 18 of the SCCs, jurisdiction and venue specified in the Agreement will have exclusive jurisdiction to determine any dispute arising in connection with this DPA.
6.3. Waiver. The failure of any Party to insist upon strict performance of any provision of this Agreement will not be construed as a waiver of any subsequent breach of the same or similar nature. If any provision of this Agreement is determined to be invalid, unenforceable or illegal, then such determination does not affect the validity, enforceability, or legality of the other provisions contained herein, all of which remain in full force and effect.
[End of Addendum]

Data Transfer Appendix

1. Definitions

All capitalized terms not defined herein shall have the meaning given to them in the DPA or the Agreement.
EU SCCs” means the EU Standard Contractual Clauses pursuant to EU Commission Decision 2021/914/EU.
FADP” Swiss Federal Act on Data Protection.
GDPR” means the EU General Data Protection Regulation 2016/679.
UK Addendum” means the UK ICO’s International Data Transfer Addendum to the EU SCCs, Version B1.0, in force March 21, 2022.
UK GDPR” means the GDPR as incorporated into UK law by the Data Protection Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments Etc.) (EU Exit) Regulations 2019.

2. EU Data Transfers

2.1. To the extent that Customer PI subject to the GDPR is transferred to Altana in a country that has not been deemed to provide an adequate level of data protection by the EU Commission, and the transfer of Customer PI is not covered by an alternative transfer mechanism that is recognized by the EU Commission as providing an adequate level of protection, then the Parties agree to incorporate the EU SCCs by reference into the DPA, in accordance with the terms below:
2.1.1. Module 2 shall apply;
2.1.2. Clause 7 of the EU SCCs does not apply;
2.1.3. Option 2 in Clause 9(a) of the EU SCCs shall apply;
2.1.4. The option in Clause 11(a) of the EU SCCs does not apply;
2.1.5. For the purposes of Clause 13(a) of the EU SCCs, the competent supervisory authority shall be the supervisory authority of the Netherlands, unless determined otherwise by the nature of the transfer;
2.1.6. For the purposes of Clause 17 of the EU SCCs, the EU SCCs shall be governed by the laws of Ireland;
2.1.7. For the purposes of Clause 18(b) of the EU SCCs, disputes arising under the EU SCCs shall be resolved in the courts of Ireland; and
2.1.8. Annexes I, II and III to the EU SCCs are completed through Section 5 of this Data Transfer Appendix.

3. UK Data Transfers

3.1. To the extent that Customer PI subject to the UK GDPR is transferred to Altana in a country that has not been deemed to provide an adequate level of data protection by the UK Secretary of State, and the transfer of Customer PI is not covered by an alternative transfer mechanism that is recognized by the UK Secretary of State as providing an adequate level of protection, then the Parties agree to incorporate the UK Addendum by reference into the DPA, in accordance with the terms below:
3.1.1. The UK Addendum is appended to the EU SCCs (as incorporated under Section 2 of this Data Transfer Appendix);
3.1.2. In Table 1 of the UK Addendum, the Start Date shall be the Effective Date, and the details of the Parties and the Parties’ contact information shall be as set out in Section 5 of this Data Transfer Appendix;
3.1.3. In Table 2 of the UK Addendum, the second option shall be selected and the clauses of the EU SCCs shall apply as set out in Section 2 of this Data Transfer Appendix;
3.1.4. Table 3 of the UK Addendum shall be completed as follows:
  • Annex IA: List of Parties: As set out in Section 5 of this Data Transfer Appendix;
  • Annex IB: Description of Transfer: As set out in Section 5 of this Data Transfer Appendix;
  • Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data: As set out in Section 5 of this Data Transfer Appendix;
  • Annex III: List of Sub processors (Modules 2 and 3 only): As set out in Section 5 of this Data Transfer Appendix.
3.1.5. In Table 4 of the UK Addendum, the “data importer” option shall be selected.

4. Swiss Data Transfers

4.1. To the extent that Customer PI subject to the FADP is transferred to Altana in a country that has not been deemed to provide an adequate level of data protection by the Swiss Federal Council, and the transfer of Customer PI is not covered by an alternative transfer mechanism that is recognized by the Swiss Federal Council as providing an adequate level of protection, then the Parties agree that the EU SCCs (as incorporated under Section 2 of this Data Transfer Appendix) shall apply to such transfer of Customer PI, subject to the following:
4.1.1. References to the EU GDPR in the EU SCCs shall be understood as references to the equivalent provisions of the FADP;
4.1.2. For the purposes of Clause 13 and Annex I.C. of the EU SCCs, the Swiss Federal Data Protection and Information Commissioner shall act as the “competent supervisory authority” insofar as the relevant data transfer is governed by the FADP;
4.1.3. Clause 17 of the EU SCCs shall include Swiss law as the governing law in case the transfer is subject to the FADP; and
4.1.4. Clause 18 of the EU SCCs shall include Switzerland as the jurisdiction for the purpose of allowing Swiss data subjects to pursue their rights in their place of habitual residence.

5. Scope of the Data Transfers

5.1. Data exporter(s):
Name: Customer
Address: As defined in the Agreement
Contact person’s name, position and contact details: As shown on the Order Form, or otherwise provided to Altana
Activities relevant to the data transferred under these Clauses: Services performed under the Agreement.
Role: Controller
5.2. Data importer(s):
Name: Altana Technologies, Inc.
Address: 25 Kent Avenue, Suite 501, Brooklyn, NY 11249
Contact person’s name, position and contact details: The Security Team and Legal Department may be reached at dataprivacy@altana.ai and legal@altana.ai.
Activities relevant to the data transferred under these Clauses: Services performed under the Agreement.
Role: Processor
5.3. Description, Purposes and Nature of Processing. Customer PI will be Processed as described in Section 2 of the DPA.
5.4. Frequency of Transfer. Customer PI will be transferred on a continuous basis.
5.5. Data Retention. Customer PI will be retained by Altana for the duration of the Agreement and such longer period as required or permitted by applicable law.
5.6. Sub-Processors. A list is available at https://trust.altana.ai/subprocessors.
5.7. Technical and Organizational Measures. Altana will, and require its Sub-Processors to, implement commercially reasonable technical and organizational measures designed to maintain a level of security for Customer PI appropriate to the level of risk associated with the relevant Processing of Customer PI. Such measures may include, as deemed appropriate by Altana in the context of the Services, those for:
  • the protection of personal data during transmission and storage, such as pseudonymisation and encryption;
  • the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  • regularly testing, assessing and evaluating the effectiveness of technical and organizational measures to help protect the security of the processing;
  • access and authentication controls, including account passwords and unique account identifiers;
  • the physical security of locations at which personal data are processed;
  • events logging; and
  • internal IT and IT security governance and management.