Data Processing Addendum

Last Updated: September 18, 2026

This DPA is incorporated into the Terms of Service or other written services agreement (the “Agreement”) between the entity or person agreeing to these terms (“Customer”) and Esper.io, Inc. (“Esper”). By using the Services, Customer agrees to be bound by this DPA. The DPA applies to all Processing of Customer Personal Data by Esper under the Agreement. Should there be a conflict between this DPA, and the Agreement, this DPA will govern.

  1. Definitions

In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:

  1. 1.1.“Confidential Information” is defined in the Agreement.
  2. 1.2.“Customer Personal Data” means any Personal Data provided by or made available by Customer to Esper on behalf of Customer, which Esper Processes to perform the Services.
  3. 1.3.“Data Breach” means (i) any unauthorized or unlawful processing of Customer Personal Data that may adversely affect the privacy or security of individuals; or (ii) as otherwise defined under applicable Data Protection Laws. Data Breach does not include unsuccessful attempts or activities that do not compromise the confidentiality, availability, or integrity of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other similar incidents.
  4. 1.4.“Data Protection Laws” means (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“GDPR”), (ii) Directive 2002/58/EC concerning the processing of Personal Data and the protection of privacy in the electronic communications sector and applicable national implementations of it (“ePrivacy Directive”); (iii) Swiss Federal Data Protection Act (“Swiss DPA”), (iv) United Kingdom General Data Protection Regulation (“UK GDPR”) and United Kingdom (“UK”) Data Protection Act 2018, (v) regulations and official guidance adopted thereunder, and (vi) any subsequent supplements, amendments, or replacements to (i) - (v).
  5. 1.5.“Personal Data” means data that relates to an identified or identifiable natural person or as otherwise defined under Data Protection Laws.
  6. 1.6.“Services” means services provided by Esper under the Agreement and all schedules, order forms, and statements of work thereunder.
  7. 1.7.“Sub-processor” means any person or entity engaged by Esper that Processes Customer Personal Data.
  8. 1.8.The terms “Controller,” “Data Subject,” “Process/process,” “Processor,” “Data Processor,” and “Business,” shall have the same meaning as in Data Protection Laws.
  1. Scope of Processing
  1. 2.1.Roles of Parties. The parties acknowledge and agree that with respect to processing of Customer Personal Data, Esper is a Processor and Customer is a Controller, except that if Customer is a Processor in which case Esper is a Sub-processor. If Customer is a Processor of Customer Personal Data, Customer represents and warrants that Customer’s instructions and Processing of Customer Personal Data, including its appointment of Esper as a Sub-processor, have been authorized by the respective Controller.
  2. 2.2.Details of Processing. Exhibit 1 to this DPA (Description of Processing and Transfer Details) provides information about the subject matter and details of the Processing of Personal Data.
  3. 2.3.Customer Instructions and Restrictions on Processing
  1. 2.3.1.Instructions. Esper will process Customer Personal Data for the purpose of providing, maintaining, and improving its Services and at all times in accordance with Customer’s instructions which are as set forth in the Agreement and DPA. Esper will inform Customer if any of Customer’s instructions infringes any Data Protection Laws.
  2. 2.3.2.Employees and Agents. Esper will take commercially reasonable steps so that all Esper employees, contractors, and Sub-processors that Process Customer Personal Data are subject to written confidentiality agreements (or subject to statutory duties of confidentiality) that provide substantially the same level of protection for Customer Personal Data as provided in this DPA and as required by Data Protection Laws.
  1. Data Security
  1. 3.1.Data Security Obligations. Esper will implement and maintain commercially reasonable administrative, technical, and physical safeguards, which shall be no less protective of the Customer Personal Data than the measures described in Exhibit 2.
  2. 3.2.Data Breach.
  1. 3.2.1.If Esper confirms a Data Breach affecting Customer Personal Data, Esper shall take reasonable and appropriate steps, given the nature of the processing and the information available to Esper, to: (1) notify Customer without undue delay (and in any event within seventy-two hours) of confirmation of the Data Breach and (2) provide information to and assist Customer, as needed in meeting Customer’s obligations to notify individuals affected by the Data Breach.
  2. 3.2.2.Esper’s cooperation or obligation to report or respond to Data Breaches under this DPA shall not be deemed an acknowledgment by Esper of any fault or liability of Esper with respect to a Data Breach.
  3. 3.2.3.Esper shall not be identified in any notifications provided publicly or to third parties (such as to government entities or Data Subjects) unless the contents of the notifications are approved by Esper. Esper agrees to cooperate in promptly reviewing any notifications and will not unreasonably withhold approval. If such reviews and approvals are expressly prohibited by applicable law, Customer can provide them without review and approval.
  1. 3.3.Security Audit. If and to the extent Esper processes, handles, distributes or otherwise makes available, or stores Customer Personal Data as part of the Services, then Esper will make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in the GDPR including responding in writing to a security questionnaire as requested by Customer no more than once annually.
  2. 3.4.Customer agrees to treat such information provided by Esper in response to a request under this Section 3 as Esper’s Confidential Information.
  1. Data Protection Audits and Assistance

Upon Customer request, but no more than once per year, Esper will provide reasonable assistance and information to Customer regarding its Processing of Customer Personal Data to demonstrate its compliance with its obligations under Data Protection Laws and to support Customer with its data protection impact assessments, where the information sought is not provided in the Agreement or this DPA or otherwise accessible to Customer through product documentation. Where and to the extent so required by Data Protection Law and where such need is not met by the foregoing rights, Esper will allow for, contribute to, and cooperate with reasonable audits, assessments, and inspections conducted by or on behalf of Customer.

  1. Notice Regarding Third Party Requests and Inquiries

Esper will take reasonable steps to notify Customer if Esper receives any request from a government entity or regulator that pertains directly to its Processing of Customer Personal Data, provided such notice is not prohibited by law or court order. If Esper receives any requests from a Data Subject, including individual opt-out requests, requests for access and/or deletion and all similar individual rights requests, it will inform that Data Subjects that they should direct Data Subject requests to their Controller.

  1. Sub-processors
  1. 6.1.Approved Sub-Processors. Customer authorizes access or transfer to Esper’s Sub-processors. At present, the Sub-processors Esper uses are listed in Exhibit 3. Esper will provide thirty (30) calendar days’ notice before engaging a new Sub-processor by sending notice to the email address designated by Customer for such purpose, or, if no email address has been designated, by posting the update to Esper’s Sub-processor notification page (found here: https://trust.esper.io/subprocessors ). Customer authorizes Esper to use any such Sub-processor to process Customer Personal Data unless Customer objects within ten (10) calendar days of such notification. Any such objection must be based on reasonable grounds that any such Sub-processor is unable to adequately protect the Customer Personal Data in accordance with the Agreement. If such objection is justified, Customer and Esper will work together to find a mutually acceptable resolution to such objection, and if unsuccessful, Customer’s sole remedy is termination of the relevant Services under the terms of the Agreement.
  2. 6.2.Responsibility. Esper will have a written agreement in place with each Sub-processor that obligates the Sub-processor to Process Customer Personal Data in a manner that is no less protective than the obligations on Esper under this DPA. Where Sub-processor fails to fulfil its obligations under any sub-processing agreement or Data Protection Laws, Esper will remain liable to Customer for the fulfilment of its obligations under this DPA and the Agreement.
  1. Cross-Border Data Transfers
  1. 7.1.Customer instructs Esper to process Customer Personal Data in the countries and regions in which Esper or its Sub-Processors maintain data processing operations, including in the United States.
  2. 7.2.With regard to countries, regions, or territories with Data Protection Laws requiring a mechanism for valid export of Customer Personal Data (such countries, regions, or territories, are “Limited Transfer Region(s)” and such data is “Limited Transfer Data”), Esper may not transfer, export, receive, or Process such Limited Transfer Data outside of such Limited Transfer Regions unless it or its Sub-processors take measures to adequately protect such data consistent with applicable Data Protection Laws. Such measures may include (to the extent consistent with Data Protection Laws):
  1. 7.2.1.Processing Customer Personal Data in a country, a territory, or one or more specified jurisdictions that are considered under Data Protection Laws as providing an adequate level of data protection);
  2. 7.2.2.The parties’ agreement to enter into and comply with the EU Standard Contractual Clauses incorporated by reference into Exhibit 4 (“Standard Contractual Clauses”) and any successors or amendments to such clauses or such other applicable contractual terms adopted and approved under Data Protection Laws. For the avoidance of doubt, the Parties agree that the SCCs are incorporated into this DPA without further need for reference, incorporation, or attachment and that by executing this DPA, each party is deemed to have executed the SCCs;
  3. 7.2.3.Processing in compliance with Binding Corporate Rules in accordance with Data Protection Laws;
  4. 7.2.4.Implementing any other data transfer mechanisms or certifications approved under Data Protection Laws, including, as applicable, the Data Privacy Framework (and any approved successor or replacements thereto); or
  5. 7.2.5.To the extent that any substitute or additional appropriate safeguards or mechanisms under any Data Protection Laws of Limited Transfer Regions are required to transfer Customer Personal Data from a Limited Transfer Region, as applicable, to any third country, the parties agree to implement the same as soon as practicable and document such requirements for implementation in an attachment to this DPA governing the parties' Processing of Limited Transfer Data.
  1. Retention and Deletion of Customer Personal Data

Upon Customer’s written request, or upon thirty (30) days following termination or expiration of the Agreement, Esper will delete all Customer Personal Data under Esper’s possession or control or provide Customer ability to delete such Customer Personal Data directly through tools or functionality made available by Esper. Esper will not delete Customer Personal Data to the extent that: (a) deletion is not permitted under applicable laws or the order of a governmental or regulatory body; (b) where Esper retains such data for internal record keeping, compliance with any legal obligations, and other lawfully permitted purposes; or (c) while Esper’s then-current data retention or similar back-up system stores Customer Personal Data provided such data will remain protected in accordance with the measures described in the Agreement and this DPA.

  1. General Terms
  1. 9.1.Limitation of Liability. Esper’s entire liability arising out of or related to this DPA (including under the SCCs), whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability contained in the Agreement. For the avoidance of doubt, Esper’s total liability for all claims from Customer and all its users arising out of or related to the Agreement and this DPA will apply in aggregate for all claims under both the Agreement and this DPA.
  2. 9.2.Notices. Unless expressly stated otherwise in the Agreement, all notices under this DPA will be in writing and delivered by electronic mail.
  3. 9.3.Termination and Survival. This DPA can be terminated as set forth in the Agreement. The provisions of this DPA that, by their terms, require performance after the termination or expiration of this DPA, or have application to events that may occur after the termination or expiration of this DPA, will survive the termination or expiration of this DPA..
  4. 9.4.Governing Law; Conflicts of Law; Severance. The parties to this DPA agree to the choice of jurisdiction stipulated in the Agreement with respect to any disputes or claims relating to or arising under this DPA; and this DPA and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Agreement (without reference to its conflict of laws requirements), unless otherwise required by Data Protection Laws. To the extent any court or governmental entity with competent jurisdiction determines that a provision of this DPA is invalid or unenforceable, the parties agree and intend that such provision should be (a) amended solely as necessary to bring it back into force in a manner consistent with the parties’ manifest intent, or if that is not possible (b) severed from the DPA in a manner to give maximum legal force and effect to the remaining provisions.

EXHIBIT 1

DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA

This Exhibit 1 supplements the Agreement and DPA, and together, provide details about Customer Personal Data processing by Esper.

Describe the nature and purpose of the Processing of Customer Personal Data.

The processing of Customer Personal Data in connection with providing the Services to Customer, as further described in the Agreement and the DPA.

The types of Customer Personal Data to be Processed

Name and Contact Information (such as name, email and phone number); identifiers and device information (such as IP address, MAC address, diagnostic data, device IP address, device name, etc.).

While the Services do not generally process Sensitive Customer Personal Data, the precise geolocation data of managed devices may be processed by Esper solely as necessary to support geolocation-dependent features, such as geofencing and location telemetry, on behalf of Customer. Geofencing is configured and enabled by the Customer’s enterprise administrator. Location telemetry is not enabled by default and, when activated by Esper via remote configuration to support the Services, collects and reports device location to the Customer’s management dashboard. The Services do not process precise geolocation data of managed devices by default. Esper does not access or use this data for the purpose of inferring the precise geolocation of an individual.

The types of Sensitive Customer Personal Data to be Processed

n/a – see note above.

The categories of Data Subjects to whom the Customer Personal Data relates

Customer’s clients, employees, contractors and representatives

The frequency of the transfer of Customer Personal Data from Customer to Esper

Continuous

Duration of the Processing of Customer Personal Data

As set forth in the Agreement and this DPA.

Location of Processing of Customer Personal Data by Esper

As set forth in the Agreement and this DPA.

The obligations and rights of Customer

The obligations and rights of Customer are as set out in the Agreement and this DPA.

EXHIBIT 2

TECHNICAL AND ORGANIZATIONAL MEASURES

Esper’s personnel will not process Customer Personal Data without authorization. Personnel are obligated to maintain the confidentiality of any Customer Personal Data and this obligation continues even after their engagement ends.

Esper will implement and maintain commercially reasonable administrative, technical, and physical safeguards, including procedures and practices commensurate with the level of sensitivity of Customer Personal Data and the nature of its activities under the applicable Agreement, to protect the security, confidentiality, and integrity of Customer Personal Data processed by Esper or in its possession and control including such safeguards (a) to protect the security of systems upon which such data is processed; and (b) designed to prevent a Data Breach.

Such technical and organizational measures shall include, at a minimum and without limitation:

Measures for:Description

pseudonymisation and encryption of Customer Personal Data

Implement and maintain modern and industry standard encryption mechanism and pseudonymize data as applicable to the Services provided.

ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services

Implement and maintain a formal information security program that considers the ongoing confidentiality, integrity, availability, and processing of systems.

ensuring the ability to restore the availability of and access to Customer Personal Data in a timely manner in the event of a physical or technical incident

Implement and maintain measures to ensure the availability of data according to agreed-upon RTO and RPO. Measures should include backup procedures, geographical separation, and redundancy.

regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing

Implement a review program for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures using a risk-based approach (risk assessment and internal audit) and periodically by a qualified third party (external and penetration test). Mitigation and remediation actions required based on the results of such testing should be documented and executed in a timely manner.

user identification and authorization

Esper’s personnel will not process Customer Personal Data without authorization. Esper shall, additionally, implement and maintain mechanisms for establishing identity and accountability including unique ID, strong password, and multifactor authentication.

the protection of data during transmission

Implement and maintain industry standard encryption protocols for encrypting data in transit, including but not limited to logins and sensitive data transfers.

the protection of data during storage

Implement and maintain industry standard encryption protocols for encrypting data at rest.

ensuring physical security of locations at which Customer Personal Data are processed

Implement and maintain physical security measures for locations used for data processing and storage.

ensuring events logging

Implement and maintain controls around logging, monitoring, and alerting based on pre-defined thresholds.

ensuring system configuration, including default configuration

Implement and maintain a formal hardening standard to ensure that configurations of system align with NIST, ISO, or equivalent guidance.

internal IT and IT security governance and management

Implement and maintain measures to ensure that IT policy and control are established and communicated, understood, and acknowledged throughout the organization.

certification/assurance of processes and products

Implement and maintain external certification and attestation of systems and controls used to secure the process information relevant to the services provided (SSAE 18/SOC 2, ISO 27701, ISO 27001, External Pen test, etc.)

ensuring data minimization

Implement and maintain controls to limit data collected through the Services provided and limit the use of data to the agreed upon uses or for providing the Services.

ensuring data quality

Implement and maintain controls to maintain the accuracy, completeness, and consistency of data over its life cycle.

ensuring limited data retention

Implement and maintain controls for deleting data according to request or agreed upon terms of retention post termination of the applicable Agreement.

ensuring accountability

Implement and maintain measures to ensure accountability and responsibility for security, privacy, and breach notification.

allowing data portability and ensuring erasure

Implement and maintain measures to allow for portability of data and ensure complete erasure upon request or contract term.

transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter:

Esper shall remain committed to providing commercially reasonable cooperation and assistance to controllers. As set forth in this DPA, Esper will delete or return Customer Personal Data in accordance with the prior written instructions of Customer. In addition, upon request, Esper will, to the extent not prohibited by law, reasonably assist Customer in responding to any Data Subject request. Further, when Esper engages a sub-processor pursuant to this DPA, Esper is required to first enter into an agreement with such a sub-processor that contains data processing obligations substantially similar to those contained in this DPA.

EXHIBIT 3

SUB-PROCESSORS

This list identifies the Sub-processors authorized to Process Customer Personal Data.

Sub-processor NameSub-processor location (location(s) of processing)Sub-processor services provided (description of subject matter, nature of Processing of Customer Personal Data)
Amazon Web ServicesUnited StatesPrimary Cloud Infrastructure Provider
Okta/Auth0United StatesUser Authentication and Authorization Systems
Ascend.ioUnited StatesAudits
DatabricksUnited StatesData Platform
SendGridUnited StatesEmail Service
ImplyDataUnited StatesData Platform
PendoUnited StatesUser Behavior Analysis
ZendeskUnited StatesCustomer Support Platform

EXHIBIT 4

STANDARD CONTRACTUAL CLAUSES

The Parties agree that by entering into this DPA, each party is deemed to have executed the of the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as issued by the European Commission on June 4, 2021 (the “SCCs”), and as also adopted by the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) (collectively “EU SCCs”), as applicable. Limited Transfer Data subject to the UK GDPR and UK Data Protection Act 2018 that Customer transfers to Esper will be governed by the EU SCCs and UK Transfer Addendum Version B1.0 (in force 21 March 2022) adopted by the UK Information Commissioner’s Office. The elections and information required for the purposes of the EU SCCs and the UK Transfer Addendum is provided in Table 1 below.

Table 1: EU SCC and UK Transfer Addendum Information.

SCC ClauseGDPRSwiss DPAUK Data Protection Law
Module in Operation

Module Two (Controller to Processor) and Module Three (Processor to Processor)

Clause 7- Docking Clause

Does not apply

Clause 9(a)- Use of Sub-processors

GENERAL WRITTEN AUTHORISATION: The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the data exporter with the information necessary to enable the data exporter to exercise its right to object.

Clause 11 (Redress)

Optional language in Clause 11 shall not apply.

Clause 17- Governing Law

These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Ireland.

These Clauses shall be governed by the law of Switzerland, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Switzerland.

These Clauses shall be governed by the law of the United Kingdom, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of England and Wales.

Clause 18 – Choice of Forum and Jurisdiction

The parties agree that those shall be the courts of Ireland.

The parties agree that those shall be the competent courts of Switzerland.

The parties agree that those shall be the competent courts of England and Wales.

Appendix, Annex I.A- List of Parties

The name, address, and contact person’s name, position, and contact details, and each party’s role in Processing Personal Data are as set forth in the DPA to which this Exhibit 4 is attached.

Annex I.B – Description of Transfer

This information can be found in Exhibit 1 to the DPA to which this Exhibit 4 is attached.

To the extent applicable, the descriptions of safeguards applied to the special categories of Personal Data can be found Exhibit 2 to the DPA to which this Exhibit 4 is attached.

Clause 13 and Annex I.C – Competent Supervisory Authority

Identify the competent supervisory authority/ies in accordance with Clause 13: The Data Protection Commission

Identify the competent supervisory authority/ies in accordance with Clause 13:

FDPIC

Identify the competent supervisory authority/ies in accordance with Clause 13:

UK Information Commissioner

Annex II – Technical and Organizational Measures – Subprocessors

The description of technical and organization measures designed to ensure the security of Personal Data are described in Exhibit 2 to the DPA to which this Exhibit 4 is attached.

Annex III – List of Subprocessors

As described in Exhibit 3 to the DPA to which this Exhibit 4 is attached.

Ending the UK Transfer Addendum when the Approved Addendum changes

N/A

Which Parties may end this Addendum as set out in Section ‎19:

☒ Importer

☐ Exporter

☐ neither Party


Revision Date
Last revised September 18, 2026
© Esper.io, Inc. All Rights Reserved.