ORDER FORM

Issued under the Master Subscription Agreement

This Order Form (this “Order Form”) is entered into by and between Cakewalk Tech Inc., a Delaware corporation with its principal place of business at 345 California Avenue, Palo Alto, CA 94306 (“Cakewalk”), and the customer identified below (“Customer”), and is governed by the Master Subscription Agreement between the Parties (the “Agreement”). Capitalized terms not defined in this Order Form have the meanings set forth in the Agreement.

1. Parties

Customer Legal Name
Customer Address
Customer Billing Contact
Customer Technical Contact
Customer Notice Email

2. Subscription Details

Plan Human Access Management / Agent Access Management / Human & Agent Access Management
Included Users / Seats
Effective Date
Initial Term
Term End Date


3. Fees and Payment

Subscription Fee
Billing Cadence
Payment Method
Payment Terms
Currency
Discounts Granted
One-Time Setup & Onboarding

All Fees are exclusive of taxes; Customer is responsible for all sales, use, and similar taxes as set forth in Section 2 of the Agreement.

4. Service Level

  • Availability Target: 99.5% monthly availability, in accordance with Section 4 of the Agreement.

  • Support: Standard support requests responded to within 4 business hours; critical requests within 30 minutes, during Cakewalk’s standard business hours.

5. Special Terms

The customer agrees to submit up to three 5-star reviews on G2 and to participate in a joint LinkedIn post, in recognition of the discounts granted.

6. Acceptance

By signing below, each Party agrees to be bound by this Order Form and reaffirms its obligations under the Agreement.

CAKEWALK TECH INC. CUSTOMER

By: __________________________ By: __________________________

Name: Name:

Title: Title:

Date: Date:

MASTER SUBSCRIPTION AGREEMENT

Cakewalk Tech Inc.

This Master Subscription Agreement (the “Agreement”) is entered into as of the Effective Date set forth on the applicable Order Form by and between Cakewalk Tech Inc., a Delaware corporation with its principal place of business at 345 California Avenue, Palo Alto, CA 94306 (“Cakewalk”), and the customer identified on the Order Form (“Customer”). Cakewalk and Customer are each referred to as a “Party” and collectively as the “Parties.”

This Agreement governs Customer’s access to and use of the Application (defined below). Specific commercial terms (including pricing, term, and seat counts) are set forth in one or more order forms referencing this Agreement (each, an “Order Form”). In the event of a conflict between this Agreement and an Order Form, the Order Form controls solely with respect to the subject matter therein.

Services

  1. Cakewalk shall host and make available to Customer the Cakewalk application (the “Application”) as a software-as-a-service offering, in the plan and at the seat count specified on the applicable Order Form.

  2. Cakewalk may, in its sole discretion, develop and provide updates, upgrades, enhancements, or other improvements to the Application from time to time. Nothing in this Agreement obligates Cakewalk to develop, deliver, or make available any specific feature, functionality, update, or new version of the Application.

2. Fees, Taxes, and Payment

  1. Fees. Customer shall pay the fees set forth on the applicable Order Form (the “Fees”). All Fees are stated in U.S. Dollars and are non-cancelable and non-refundable except as expressly provided in this Agreement.

  2. Invoicing. The ongoing fees for the Application are billed upfront for the term specified on the Order Form. Cakewalk will invoice Customer via Stripe in accordance with the billing cadence set forth on the Order Form. Fees are due within fourteen (14) days of the invoice date unless otherwise stated on the Order Form. Overdue amounts accrue interest at the lesser of 1.5% per month or the maximum rate permitted by applicable law, from the due date until paid.

  3. Taxes. All Fees are exclusive of taxes, levies, and duties of any kind. Customer is responsible for all sales, use, value-added, excise, withholding, and similar taxes (other than taxes on Cakewalk’s net income). If Cakewalk is required to collect or pay any such taxes, they will be invoiced to and paid by Customer, unless Customer provides a valid tax exemption certificate.

  4. Suspension. Cakewalk may suspend access to the Application if any Fees remain unpaid more than thirty (30) days after the due date, following written notice and a ten (10) day cure period. Suspension does not relieve Customer of its payment obligations.

  5. Offset. Customer shall not withhold, offset, or deduct any amounts owed under this Agreement against any claims, counterclaims, or other obligations.

3. Term and Termination

  1. Term. This Agreement is effective on the Effective Date and continues for so long as any Order Form remains in effect. Each Order Form has the initial term and renewal terms specified therein.

  2. Termination for Cause. Either Party may terminate this Agreement or any Order Form for material breach if the breaching Party fails to cure such breach within thirty (30) days after written notice. To the extent permitted by applicable law, either Party may terminate immediately upon written notice if the other Party becomes insolvent, makes a general assignment for the benefit of creditors, or commences or has commenced against it proceedings under any bankruptcy or insolvency law that are not dismissed within sixty (60) days.

  3. Effect of Termination. Upon termination or expiration, Customer’s right to access and use the Application immediately ceases. Termination does not relieve Customer of its obligation to pay Fees accrued or payable prior to the effective date of termination. Sections 2 (with respect to amounts accrued), 5.1 (Restrictions), 6 (Intellectual Property), 8 (Limitation of Liability), 9 (Confidentiality), 10 (Indemnification), 11 (Compliance), and 12 (General) survive termination.

4. Operation and Support

  1. Availability. Cakewalk will use commercially reasonable efforts to ensure that the actual monthly availability of the Application is at least 99.5% (the “Availability Target”), excluding Planned Maintenance Work and downtime caused by factors outside Cakewalk’s reasonable control. If monthly availability falls below the Availability Target, Customer’s sole and exclusive remedy is a service credit applied to the next invoice, calculated as follows: (i) 10% of the monthly-equivalent Fee (the total Fees under the applicable Order Form divided by the number of months in the term) if availability is below 99.5% but at or above 99.0%; (ii) 15% of the monthly-equivalent Fee if availability is below 99.0% but at or above 98.0%; and (iii) 25% of the monthly-equivalent Fee if availability is below 98.0%. Service credits may not exceed 25% of the monthly-equivalent Fee in any given month and may not be redeemed for cash.

  2. Measurement. Monthly availability is calculated as: ((total minutes in the applicable calendar month minus total minutes of Downtime) divided by total minutes in the applicable calendar month) multiplied by 100. "Downtime" means any period during which the Application is materially inaccessible or inoperable to Customer, excluding (i) Planned Maintenance Work, (ii) downtime caused by factors outside Cakewalk's reasonable control (including force majeure events, internet or telecommunications failures beyond Cakewalk's network, or acts or omissions of Customer), and (iii) downtime resulting from Customer's use of the Application in a manner not in accordance with this Agreement or the applicable documentation.

  3. Credit Claims. Service credits are not applied automatically. To receive a service credit, Customer must submit a written request to Cakewalk within thirty (30) days after the end of the calendar month in which the Downtime occurred, identifying the dates and times of the claimed Downtime. Cakewalk will evaluate the request against its monitoring records and respond within fifteen (15) business days. If Cakewalk confirms that the Availability Target was not met, the applicable service credit will be applied to Customer's next invoice.

  4. Planned Maintenance. Cakewalk may perform regular maintenance (“Planned Maintenance Work”) and will use reasonable efforts to minimize interruptions. Cakewalk will notify Customer at least seven (7) days in advance of Planned Maintenance Work. Planned Maintenance Work is excluded from availability calculations.

  5. Support. During Cakewalk’s standard business hours (as published in Cakewalk’s support documentation), Cakewalk will respond to standard support requests within four (4) business hours and to critical support requests within thirty (30) minutes. “Critical” means an issue that prevents Customer from materially using the Application.

  6. Modifications. Cakewalk may modify the functionality of the Application from time to time (“Modifications”) and will notify Customer of material Modifications within a reasonable period of time, by email, within the Application, or by other reasonable means. If a Modification materially and adversely affects Customer’s ability to use the Application for its agreed purposes, Customer has a special right of termination, exercisable within thirty (30) days of receiving notice of the Modification, with a pro-rata refund of prepaid Fees for the unused portion of the then-current subscription term.

5. Rights of Use

  1. Restrictions. Customer shall not, and shall not permit any third party to: (i) copy, modify, translate, adapt, or create derivative works of the Application; (ii) reverse engineer, decompile, or disassemble the Application, except to the extent expressly permitted by applicable law notwithstanding this restriction; (iii) rent, lease, lend, sell, or sublicense access to the Application; (iv) use the Application to develop a competing product or service; (v) perform or publish benchmarks, competitive analyses, or performance tests of the Application without Cakewalk's prior written consent; (vi) remove or alter any proprietary notices; (vii) share, transfer, or otherwise make available login credentials or access to the Application to any person beyond the number of seats specified on the applicable Order Form, or permit any single set of credentials to be used by more than one individual; (viii) use any robot, spider, scraper, automated script, or other automated means to access, monitor, or interact with the Application, except through interfaces expressly provided by Cakewalk for such purposes; (ix) circumvent, disable, or otherwise interfere with any security, authentication, rate-limiting, or usage-limiting features of the Application; or (x) frame, mirror, embed, or otherwise incorporate any portion of the Application into any other product, service, or website without Cakewalk's prior written consent.

  2. Acceptable Use. Customer shall not use the Application in any manner that: (i) violates applicable law or regulation; (ii) infringes, misappropriates, or otherwise violates any third-party intellectual property, privacy, or other rights; (iii) transmits, uploads, or distributes any viruses, malware, or other malicious code; (iv) attempts to gain unauthorized access to any system, network, or data; (v) transmits unsolicited or unauthorized advertising, promotional materials, spam, or any other form of solicitation; (vi) stores, transmits, or distributes any content that is unlawful, defamatory, obscene, or otherwise objectionable; (vii) interferes with or disrupts the integrity, performance, or availability of the Application or the experience of other users; or (viii) intentionally imposes an unreasonable or disproportionate load on the Application's infrastructure, including through stress testing, load testing, or similar activities, without Cakewalk's prior written consent.

6. Intellectual Property

  1. Cakewalk IP. As between the Parties, Cakewalk retains all right, title, and interest in and to the Application, including all intellectual property rights therein and all improvements, modifications, derivative works, and other developments thereof (collectively, "Cakewalk IP"). Without limiting the foregoing, any intellectual property rights arising from or in connection with the Application shall vest exclusively in Cakewalk, regardless of whether such rights are based on or derived from any suggestions, feedback, requirements, ideas, contributions, comments, or other input provided by Customer, its users, or any third party. For the avoidance of doubt, Cakewalk IP does not include Customer Data.

  2. Customer Data. As between the Parties, Customer retains all right, title, and interest in and to Customer Data. Customer grants Cakewalk a limited, non-exclusive license to use, process, and transmit Customer Data solely to provide the Application and perform its obligations under this Agreement. “Customer Data” means any proprietary data, information, or content of Customer submitted through the Application by or on behalf of Customer.

  3. Usage Data. Cakewalk may collect and process usage data and technical metadata generated through Customer’s and its users’ interaction with the Application (“Usage Data”), including information about user interactions, technical events, and other data generated during use. Cakewalk uses Usage Data to improve the performance, security, and usability of the Application and to provide customer support. Cakewalk may also use Usage Data in aggregated and de-identified form (such that it does not identify Customer or any individual) for analytics, benchmarking, product development, and other lawful business purposes, and such aggregated and de-identified data shall not be considered Customer Data or Confidential Information. All Usage Data is processed in accordance with applicable data protection laws and subject to appropriate technical and organizational measures. For the avoidance of doubt: no personal data is used for AI training purposes.

  4. Feedback. Customer grants Cakewalk a perpetual, irrevocable, royalty-free, worldwide license to use any feedback, comments, or suggestions provided by Customer for any purpose, without obligation.

7. Warranties and Disclaimers

  1. Mutual. Each Party represents and warrants that it has the legal power and authority to enter into this Agreement.

  2. Cakewalk Warranty. Cakewalk warrants that, during the applicable subscription term, the Application will perform materially in accordance with its then-current documentation. To receive warranty remedies, Customer must notify Cakewalk in writing of any claimed non-conformance within thirty (30) days of first discovering such non-conformance, providing reasonable detail sufficient to allow Cakewalk to reproduce the issue. Upon receipt of a valid warranty claim, Cakewalk shall use commercially reasonable efforts to correct the non-conformance within thirty (30) days. If Cakewalk fails to correct the non-conformance within such period, Customer may, as its sole and exclusive remedy, terminate the affected Order Form upon written notice and receive a pro-rata refund of any prepaid Fees for the unused portion of the then-current subscription term. The foregoing warranty does not apply to any non-conformance resulting from: (i) use of the Application other than in accordance with this Agreement or the applicable documentation; (ii) modifications to the Application not made or authorized by Cakewalk; (iii) combination of the Application with any third-party products, services, hardware, or software not provided or specified by Cakewalk, where the non-conformance would not have occurred absent such combination; (iv) Customer's failure to implement updates or corrections made available by Cakewalk; or (v) any force majeure event or other cause beyond Cakewalk's reasonable control.

  3. Beta Features. Customer may be given access to beta or preview features, which are provided “AS IS” and without any warranty. Cakewalk shall not be liable for any damages or issues arising from features labeled as beta or preview.

  4. Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT, THE APPLICATION IS PROVIDED “AS IS” AND CAKEWALK DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. CAKEWALK DOES NOT WARRANT THAT THE APPLICATION WILL BE UNINTERRUPTED OR ERROR-FREE. CAKEWALK MAKES NO REPRESENTATION OR WARRANTY REGARDING (I) ANY THIRD-PARTY SERVICES, PLATFORMS, INTEGRATIONS, OR APIS THAT INTERACT WITH OR ARE ACCESSIBLE THROUGH THE APPLICATION, INCLUDING THEIR AVAILABILITY, ACCURACY, OR PERFORMANCE; (II) THE ACCURACY, COMPLETENESS, OR RELIABILITY OF ANY DATA, REPORTS, OUTPUTS, OR OTHER RESULTS GENERATED BY OR THROUGH THE APPLICATION; (III) THE SUITABILITY OF THE APPLICATION FOR COMPLIANCE WITH ANY SPECIFIC LEGAL, REGULATORY, OR INDUSTRY REQUIREMENTS, AND CUSTOMER IS SOLELY RESPONSIBLE FOR DETERMINING WHETHER ITS USE OF THE APPLICATION SATISFIES CUSTOMER'S OWN COMPLIANCE OBLIGATIONS; (IV) THE SECURITY OF THE APPLICATION AGAINST ALL FORMS OF UNAUTHORIZED ACCESS, INTRUSION, OR DATA BREACH, NOTWITHSTANDING ANY SECURITY MEASURES IMPLEMENTED BY CAKEWALK; OR (V) THE PERFORMANCE OR AVAILABILITY OF THE APPLICATION AS AFFECTED BY INTERNET CONNECTIVITY, TELECOMMUNICATIONS INFRASTRUCTURE, OR OTHER NETWORK CONDITIONS OUTSIDE OF CAKEWALK'S REASONABLE CONTROL. CUSTOMER IS SOLELY RESPONSIBLE FOR ASSESSING WHETHER THE APPLICATION MEETS ITS REQUIREMENTS AND FOR REGULAR AND COMPLETE BACKUP OF ITS DATA.

8. Limitation of Liability

  1. Cap. EXCEPT FOR THE EXCLUDED CLAIMS (DEFINED BELOW) AND CUSTOMER’S PAYMENT OBLIGATIONS, EACH PARTY’S TOTAL CUMULATIVE AND AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT AND ALL ORDER FORMS, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE, OR OTHERWISE, AND WHETHER ARISING BEFORE OR AFTER TERMINATION OR EXPIRATION OF THIS AGREEMENT, SHALL NOT EXCEED THE GREATER OF (A) USD 10,000 OR (B) THE FEES PAID OR PAYABLE BY CUSTOMER TO CAKEWALK UNDER ALL ORDER FORMS IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO SUCH LIABILITY. MULTIPLE CLAIMS WILL NOT EXPAND THIS LIMITATION.

  2. Exclusion of Indirect Damages. EXCEPT FOR THE EXCLUDED CLAIMS, IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, RELIANCE, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, DATA, BUSINESS OPPORTUNITY, OR ANTICIPATED SAVINGS, REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE, OR OTHERWISE, AND REGARDLESS OF WHETHER SUCH DAMAGES WERE FORESEEABLE OR WHETHER SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

  3. Data Loss. IN THE EVENT OF DATA LOSS, CAKEWALK'S LIABILITY (IF ANY) SHALL BE LIMITED TO THE REASONABLE COST OF RECOVERING DATA THAT WOULD HAVE BEEN INCURRED HAD CUSTOMER MAINTAINED PROPER AND REGULAR BACKUPS OF ITS DATA IN ACCORDANCE WITH INDUSTRY-STANDARD PRACTICES. CUSTOMER ACKNOWLEDGES THAT IT IS SOLELY RESPONSIBLE FOR MAINTAINING REGULAR AND COMPLETE BACKUPS OF ITS DATA. THE FOREGOING LIMITATION SHALL NOT APPLY TO THE EXTENT THAT SUCH DATA LOSS IS DIRECTLY CAUSED BY CAKEWALK'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.

  4. Excluded Claims. "Excluded Claims" means: (i) either Party’s indemnification obligations under Section 10; (ii) breach of Section 9 (Confidentiality); (iii) Customer’s payment obligations; (iv) a Party’s gross negligence or willful misconduct; (v) infringement or misappropriation of the other Party’s intellectual property rights; and (vi) liability that cannot be limited under applicable law. The limitations set forth in Sections 8.1 and 8.2 do not apply to Excluded Claims. However, except for claims arising under clauses (iv) and (vi) above (which shall be uncapped), each Party's total cumulative and aggregate liability for all Excluded Claims arising under clauses (i), (ii), (iii), and (v) above shall not exceed two (2) times the Fees paid or payable by Customer to Cakewalk under all Order Forms in the twelve (12) months immediately preceding the first event giving rise to such liability. THIS SECTION 8 SHALL BE GIVEN FULL EFFECT EVEN IF ANY REMEDY SPECIFIED IN THIS AGREEMENT IS DEEMED TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.

  5. Acknowledgment. The Parties acknowledge that the foregoing limitations are an essential basis of the bargain and that the Fees reflect the allocation of risk set forth in this Section.

9. Confidentiality

  1. Definition. “Confidential Information” means information disclosed by one Party (“Disclosing Party”) to the other Party (“Receiving Party”) that is identified as confidential or that should reasonably be understood to be confidential given its nature and the circumstances of disclosure. Confidential Information of Cakewalk includes: (i) the pricing and terms of this Agreement, marketing strategies, financial information, sales estimates, and business plans; (ii) plans for products or services; (iii) inventions, designs, processes, formulas, and technologies; and (iv) any other information designated as confidential or obviously confidential.

  2. Exclusions. Confidential Information does not include information that the Receiving Party can demonstrate: (i) was publicly known and generally available prior to disclosure; (ii) becomes publicly known after disclosure without any action or inaction of the Receiving Party; (iii) was already in the Receiving Party’s possession at the time of disclosure; (iv) was obtained from a third party without breach of a confidentiality obligation; or (v) was independently developed without reference to or use of the Disclosing Party’s Confidential Information.

  3. Obligations. The Receiving Party shall: (i) use Confidential Information solely to perform its obligations or exercise its rights under this Agreement; (ii) protect Confidential Information using at least the same degree of care it uses to protect its own confidential information of similar nature, but no less than reasonable care; and (iii) not disclose Confidential Information to any third party except to its employees, contractors, and advisors who have a need to know and who are bound by confidentiality obligations no less protective than those in this Agreement.

  4. Duration. The obligations set forth in this Section 9 shall survive for a period of five (5) years following the disclosure of the applicable Confidential Information; provided, however, that with respect to any Confidential Information that constitutes a trade secret under applicable law, the Receiving Party's obligations shall continue for so long as such information remains a trade secret.

  5. Compelled Disclosure. If the Receiving Party is required to disclose Confidential Information pursuant to a legal process, it shall disclose only what is necessary, give the Disclosing Party prompt prior notice (where legally permitted), and reasonably cooperate to enable the Disclosing Party to seek protective relief.

  6. Data Protection. The Parties shall comply with applicable data protection laws. To the extent processing of personal data is involved, the Parties’ data processing agreement (the “DPA”) governs and forms part of this Agreement.

10. Indemnification

  1. By Cakewalk. Cakewalk shall defend, indemnify, and hold harmless Customer and its officers, directors, employees, and agents from and against any third-party claim alleging that Customer’s authorized use of the Application in accordance with this Agreement infringes any valid U.S. patent or copyright, or misappropriates any U.S. trade secret (an “IP Claim”), and shall pay any damages finally awarded by a court of competent jurisdiction or amounts agreed in settlement. If the Application becomes, or in Cakewalk's reasonable opinion is likely to become, the subject of an IP Claim, Cakewalk may, at its sole option and expense: (a) modify or replace the Application (or the affected component thereof) so that it is non-infringing, provided that such modification or replacement contains substantially similar features and functionality; (b) procure for Customer the right to continue using the Application; or (c) if Cakewalk determines that neither (a) nor (b) is commercially practicable, terminate the affected Order Form upon written notice and refund any prepaid Fees for the unused portion of the then-current subscription term. Cakewalk shall have no liability or obligation under this Section 10.1 with respect to any IP Claim arising from: (1) Customer Data; (2) use of the Application in combination with any products, services, hardware, or software not provided or specified by Cakewalk, where the claim would not have arisen but for such combination; (3) modifications to the Application not made or authorized by Cakewalk; (4) Customer's use of the Application other than in accordance with this Agreement or the applicable documentation; or (5) Customer’s continued use of the Application after Cakewalk has notified Customer to cease use or after Cakewalk has made available a non-infringing modification or replacement. This Section 10.1 states Cakewalk’s entire liability and Customer’s sole and exclusive remedy with respect to IP Claims. Cakewalk's aggregate liability under this Section 10.1 is subject to the super cap set forth in Section 8.4 (Excluded Claims).

  2. By Customer. Customer shall defend, indemnify, and hold harmless Cakewalk and its officers, directors, employees, and agents from and against any third-party claim arising from or related to: (i) Customer Data, including any claim that Customer Data violates applicable law or infringes, misappropriates, or otherwise violates the rights of any third party; (ii) Customer’s breach of Section 5.1 (Restrictions) or Section 5.2 (Acceptable Use); (iii) Customer’s use of the Application in violation of applicable law; or (iv) Customer's use of the Application in combination with any products, services, hardware, or software not provided by Cakewalk, where the claim would not have arisen but for such combination, and shall pay any damages finally awarded by a court of competent jurisdiction or amounts agreed in settlement. Customer's aggregate liability under this Section 10.2 is subject to the super cap set forth in Section 8.4 (Excluded Claims).

  3. Indemnification Procedure. A Party seeking indemnification (the "Indemnified Party") shall: (i) provide the indemnifying party (the "Indemnifying Party") with prompt written notice of the claim giving rise to the indemnification obligation; provided that any delay in providing such notice shall not relieve the Indemnifying Party of its obligations except to the extent the Indemnifying Party is materially prejudiced by such delay; (ii) grant the Indemnifying Party sole control of the defense and settlement of the claim (provided that the Indemnifying Party shall not settle any claim that imposes any liability, obligation, or admission of fault on the Indemnified Party without the Indemnified Party's prior written consent, not to be unreasonably withheld, conditioned, or delayed); and (iii) provide reasonable cooperation to the Indemnifying Party at the Indemnifying Party's expense. The Indemnified Party may participate in the defense of the claim with its own counsel and at its own expense. The Indemnifying Party shall keep the Indemnified Party reasonably informed of the status of the claim and any related proceedings.

11. Compliance with Laws

  1. General. Each Party shall comply with all laws and regulations applicable to its performance under this Agreement.

  2. Export Controls. Customer shall not access or use the Application in violation of any U.S. export control or sanctions law, including the U.S. Export Administration Regulations and regulations administered by the U.S. Office of Foreign Assets Control. Customer represents that it is not located in, organized under the laws of, or ordinarily resident in any country or territory subject to comprehensive U.S. sanctions, and is not on any U.S. government list of prohibited or restricted parties.

  3. Anti-Corruption. Each Party shall comply with the U.S. Foreign Corrupt Practices Act, the U.K. Bribery Act, and other applicable anti-bribery laws.

12. General Provisions

  1. Governing Law. This Agreement is governed by the laws of the State of California, without regard to its conflict of laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

  2. Dispute Resolution. Each Party submits to the exclusive jurisdiction of any state or federal court sitting in San Francisco, California (the "Chosen Courts") in any litigation arising out of or relating to this Agreement, agrees that all claims in respect of any such litigation will be heard and decided only in any such Chosen Court, waives any claim of inconvenient forum or other challenge to venue in any such Chosen Court, and agrees not to bring or maintain any such litigation before any tribunal other than the Chosen Courts (except, for clarity, in any proper appeal from a Chosen Court). In any action or proceeding to enforce rights under this Agreement, the prevailing Party will be entitled to recover its reasonable costs and attorneys' fees.

  3. Notices. All notices under this Agreement shall be in writing and sent to (i) Cakewalk at: Cakewalk Tech Inc., 345 California Avenue, Palo Alto, CA 94306, Attn: Legal, with a copy by email to legal@getcakewalk.io; and (ii) Customer at the address set forth on the Order Form. Notices are effective upon receipt and may be sent by email (with confirmation of receipt), nationally recognized overnight courier, or certified mail.

  4. Assignment. Neither Party may assign this Agreement without the other Party’s prior written consent, except that either Party may assign this Agreement (together with its rights and obligations hereunder), without consent, to an affiliate or in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets to which this Agreement relates. Any assignment in violation of this Section is void.

  5. Force Majeure. Neither Party shall be liable for any failure or delay in performance (other than payment obligations) due to causes beyond its reasonable control, including acts of God, war, terrorism, civil unrest, governmental action, labor disputes, internet or telecommunications failures, or epidemics.

  6. Publicity. Cakewalk may identify Customer by name and logo on its website and in marketing materials as a customer of Cakewalk, in accordance with Customer’s trademark usage guidelines if provided. Customer may revoke this permission at any time upon written notice.

  7. Independent Contractors. The Parties are independent contractors. This Agreement does not create any agency, partnership, joint venture, or employment relationship.

  8. No Third-Party Beneficiaries. This Agreement is for the sole benefit of the Parties and does not create any third-party beneficiary rights.

  9. Severability. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision shall be modified to the minimum extent necessary to make it enforceable.

  10. Waiver. No waiver of any provision of this Agreement is effective unless in writing and signed by the waiving Party. No failure or delay in exercising any right is a waiver of that right.

  11. Entire Agreement; Amendment. This Agreement (including any Order Forms, the DPA, and any exhibits) constitutes the entire agreement between the Parties regarding its subject matter and supersedes all prior or contemporaneous agreements, communications, and understandings. Any amendment must be in writing and signed by both Parties. Pre-printed terms on any Customer purchase order or similar document are void and have no effect.

  12. Counterparts; Electronic Signatures. This Agreement may be executed in counterparts, including by electronic signature, each of which is an original and all of which together constitute one agreement.

  13. Survival. Provisions that by their nature should survive termination shall survive, including Sections 2 (with respect to amounts accrued), 5.1, 6, 8, 9, 10, 11, and 12.

IN WITNESS WHEREOF, the Parties have executed this Agreement as of the Effective Date.

CAKEWALK TECH INC. CUSTOMER

By: __________________________ By: __________________________

Name: Name:

Title: Title:

Date: Date:

DATA PROCESSING AGREEMENT

Cakewalk Tech Inc.

This Data Processing Agreement (the “DPA”) is entered into by and between the customer identified in the Master Subscription Agreement (the “Controller” or “Customer”) and Cakewalk Tech Inc., a Delaware corporation with its principal place of business at 345 California Avenue, Palo Alto, CA 94306 (the “Processor” or “Cakewalk”). The Controller and the Processor are each a “Party” and together the “Parties.”

This DPA supplements and forms part of the Master Subscription Agreement between the Parties (the “Main Contract”) and governs the Processor's processing of Personal Data on behalf of the Controller in connection with the Application. Capitalized terms not defined herein have the meanings set forth in the Main Contract or, where applicable, in the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) or the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq., as amended by the CPRA, the “CCPA”).

1. Structure and Applicability

  1. This DPA consists of these general terms and the following annexes:

    1. Annex 1 – Details of Processing (categories of data, data subjects, purposes, duration)

    2. Annex 2 – Technical and Organizational Measures

    3. Annex 3 – Approved Sub-Processors

    4. Annex 4 – Standard Contractual Clauses and UK Addendum (applies where Personal Data of EU/UK data subjects is processed)

    5. Annex 5 – CCPA Service Provider Addendum (applies where Personal Information of California residents is processed; also applies, with appropriate substitutions, to comparable U.S. state privacy laws)

  2. Annex 4 applies where, and only to the extent that, the Processor processes Personal Data subject to the GDPR or UK GDPR. Annex 5 applies where, and only to the extent that, the Processor processes Personal Information subject to the CCPA or comparable U.S. state privacy laws (including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and Texas TDPSA).

  3. In the event of a conflict, the order of precedence is: (i) the Standard Contractual Clauses in Annex 4 (to the extent applicable); (ii) this DPA; (iii) the Main Contract.

2. Subject Matter, Nature, and Term

  1. Subject matter and nature. The Processor processes Personal Data on behalf of the Controller solely to provide the Application as set forth in the Main Contract.

  2. Duration. This DPA applies for the duration of the Main Contract and survives termination to the extent required to fulfill applicable legal obligations, including data return and deletion under Section 9.

  3. Details. The categories of data subjects, types of Personal Data, processing operations, and duration of processing are set out in Annex 1.

3. Processor Obligations

  1. Documented Instructions. The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data, unless required to do so by applicable law. The Main Contract and this DPA (including the Annexes) constitute the Controller's complete and final instructions. Additional instructions require the Parties’ mutual agreement; the Processor may charge reasonable fees for changes that materially exceed the scope of the agreed services. Notwithstanding the foregoing, the Controller acknowledges and agrees that the Processor may create and derive from the processing of Personal Data anonymized and/or aggregated data that does not identify or relate to the Controller or any data subject (“Analytics Data”), and may use and otherwise process such Analytics Data for the Processor's legitimate business purposes, including to improve the Application.

  2. Compliance Notice. If the Processor reasonably believes that an instruction violates applicable data protection law, it shall promptly notify the Controller and may suspend performance of the relevant instruction until the Controller confirms or amends it.

  3. Confidentiality. The Processor shall ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are familiarized with applicable data protection requirements.

  4. Technical and Organizational Measures. The Processor shall implement and maintain the technical and organizational measures set out in Annex 2, designed to ensure a level of security appropriate to the risk. The Processor is ISO 27001:2022 certified. The Processor may update measures over time provided that the overall level of security is not reduced; material changes will be documented.

  5. Assistance to Controller. Taking into account the nature of the processing and the information available to it, the Processor shall provide reasonable assistance to the Controller in:

    1. responding to requests from data subjects to exercise their rights (including access, rectification, erasure, restriction, portability, and objection);

    2. complying with the Controller's obligations relating to security of processing, data breach notification, data protection impact assessments, and prior consultation with supervisory authorities; and

    3. responding to inquiries from supervisory authorities or attorneys general concerning the processing.

The Processor shall provide assistance required under Article 28(3) GDPR or comparable provisions of U.S. state privacy law at no additional cost. For other assistance, the Processor may charge reasonable fees.

  1. Data Subject Requests. If a data subject contacts the Processor directly to exercise their rights, the Processor shall forward the request to the Controller without undue delay and shall not respond directly except to confirm receipt and refer the data subject to the Controller, unless instructed otherwise.

  2. Records. The Processor shall maintain records of processing activities carried out on behalf of the Controller as required by Article 30(2) GDPR and shall make them available to the Controller or to the supervisory authority on request.

4. Security Incidents

  1. Notification. The Processor shall notify the Controller without undue delay, and in no event later than seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.

  2. Content. The notification shall include, to the extent known at the time of notification: (i) a description of the nature of the breach, the categories and approximate number of data subjects and records concerned; (ii) the likely consequences; (iii) the measures taken or proposed to address the breach and mitigate its adverse effects; and (iv) the contact details of the relevant point of contact. Where not all information is available at the time of initial notification, the Processor shall provide updates without undue delay.

  3. Cooperation. The Processor shall reasonably cooperate with the Controller in investigating, mitigating, and remediating any Personal Data Breach, and in fulfilling the Controller's notification obligations to supervisory authorities and data subjects. The Processor reserves the right to charge a reasonable fee for such requested assistance.

  4. No Admission. Notifications under this Section 4 are not an admission of fault or liability.

5. Sub-Processors

  1. General Authorization. The Controller grants the Processor general authorization to engage Sub-Processors to process Personal Data, subject to this Section 5. “Sub-Processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller in connection with the Application. It does not include service providers providing ancillary services (e.g., telecommunications, mail/transport, maintenance) that do not have access to Personal Data in a manner constituting processing on behalf of the Controller; the Processor remains responsible for safeguarding any Controller data accessed by such providers.

  2. Approved Sub-Processors. The Controller approves the Sub-Processors listed in Annex 3.

  3. Changes. The Processor shall notify the Controller of any intended addition or replacement of Sub-Processors with at least thirty (30) days’ prior notice (by email, in-product notification, or publication on the Processor's website), giving the Controller an opportunity to object on reasonable data protection grounds. If the Controller objects in writing within fifteen (15) days, the Parties shall work together in good faith to find a workable solution. If no resolution is reached within thirty (30) days, the Controller may terminate the affected portion of the Main Contract on a pro-rata refund basis for the remainder of the prepaid term.

  4. Sub-Processor Contracts. The Processor shall impose contractual obligations on each Sub-Processor that are no less protective than those set out in this DPA, including with respect to security, confidentiality, and assistance with data subject rights.

  5. Liability for Sub-Processors. The Processor remains fully liable to the Controller for the performance of each Sub-Processor's obligations to the same extent as for its own performance.

6. International Data Transfers

  1. Transfers from the EEA/UK/Switzerland. To the extent that the Processor or any Sub-Processor processes Personal Data subject to the GDPR, UK GDPR, or Swiss Federal Act on Data Protection outside of the EEA, UK, or Switzerland (as applicable) to a country that does not benefit from an adequacy decision, the Standard Contractual Clauses and the UK Addendum (or Swiss equivalent) set out in Annex 4 apply and form an integral part of this DPA.

  2. Data Residency. The current data hosting region(s) are set out in Annex 3. The Processor may add or change hosting regions in accordance with Section 5 (Sub-Processors).

7. Audit Rights

  1. Reports. The Processor shall make available to the Controller, on request and subject to confidentiality obligations, copies of its then-current third-party audit reports, certifications, and summaries (including its ISO 27001:2022 certification and, when available, its SOC 2 Type II report) (collectively, “Audit Reports”). The Controller agrees that Audit Reports are sufficient to demonstrate the Processor's compliance with this DPA in the ordinary course.

  2. On-Site Audits. The Controller may, on no more than one occasion per twelve (12) month period and on at least thirty (30) days’ prior written notice, conduct an audit of the Processor's compliance with this DPA, subject to the following conditions: (i) the audit must be conducted during the Processor's normal business hours and in a manner that does not unreasonably interfere with the Processor's operations; (ii) the auditor must execute a confidentiality agreement reasonably acceptable to the Processor and may not be a competitor of the Processor; (iii) the audit is limited to information and systems relating to processing of the Controller's Personal Data; (iv) the Controller bears its own costs and reimburses the Processor's reasonable costs for time spent supporting the audit; and (v) the Audit Reports remain the first-line means of evidencing compliance, with on-site audits limited to matters not adequately addressed by such reports.

  3. Increased Frequency. Notwithstanding Section 7.2, on-site audits may take place more than once per twelve (12) month period only where (i) required by a supervisory authority of competent jurisdiction, or (ii) the Controller has a reasonable, good-faith belief, based on specific information, that the Processor has materially breached this DPA.

  4. Findings. Findings shall be communicated to the Processor, which shall have a reasonable opportunity to remediate any material non-compliance.

8. Controller Obligations

  1. Lawful Basis. The Controller represents and warrants that it has a valid legal basis under applicable data protection law for the processing of Personal Data by the Processor, including for the disclosure of Personal Data to the Processor and to any Sub-Processors.

  2. Instructions. The Controller is responsible for the accuracy, quality, and legality of Personal Data and the means by which it was acquired. The Controller shall ensure that its instructions to the Processor comply with applicable law.

  3. Notices. The Controller is responsible for providing all required notices to data subjects and obtaining all necessary consents and permissions to enable the lawful processing of Personal Data by the Processor in accordance with this DPA.

  4. The Controller shall provide only Personal Data that is adequate, relevant, and reasonably necessary for the Processor to provide the Application.

9. Return and Deletion of Personal Data

  1. Active Account. During the term of the Main Contract, the Controller may export its data through the Application's standard functionality at any time.

  2. Expiry on Voluntary Closure. When the Controller voluntarily closes its account, the account enters an “Expired” state. The Processor retains the data for a maximum of three (3) months thereafter, after which the account and related data are removed from production systems. The Controller is responsible for exporting any data it wishes to retain prior to closing its account.

  3. Involuntary Suspension. If the Controller's account is involuntarily suspended, there is a three (3) month grace period during which the account is inaccessible but can be reopened if the Controller resolves the underlying issue (e.g., outstanding payments or terms of service violations). To export data during this period, the Controller must first bring the account back to good standing. After the three (3) month grace period, the suspended account is closed and the data enters the Expired state, with permanent removal occurring within a maximum of three (3) further months thereafter.

  4. Backups. Personal Data residing in routine, encrypted backups will be deleted on the standard backup rotation cycle and will not be restored other than for disaster recovery purposes.

  5. Legal Retention. The Processor may retain Personal Data to the extent and for so long as required by applicable law. Such retained Personal Data shall remain subject to this DPA.

  6. Certification. The Processor shall, upon written request, certify completion of deletion.

10. Liability

  1. Cross-Reference. The liability of each Party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Main Contract. For the avoidance of doubt, breaches of this DPA constitute breaches of confidentiality obligations under the Main Contract for purposes of the liability provisions therein.

  2. Notification of Claims. Where claims for damages, fines under Article 83 GDPR, or other sanctions are threatened or imposed against a Party in connection with the processing covered by this DPA, that Party shall notify the other Party without undue delay. The Parties shall reasonably cooperate in defending such claims.

11. EU Representative

In accordance with Article 27 GDPR, the Processor has designated Cakewalk Technology GmbH, Hardenbergstraße 32, 10623 Berlin, Germany, as its representative in the European Union for matters relating to the processing of Personal Data of data subjects in the EEA. Data subjects and supervisory authorities may contact the EU representative on all issues related to processing, in addition to or instead of the Processor. Contact: privacy@getcakewalk.io.

12. Final Provisions

  1. Precedence. To the extent of any conflict between this DPA and the Main Contract regarding the processing of Personal Data, this DPA prevails (subject to Section 1.3).

  2. Amendments. Any amendment to this DPA must be in writing and signed by both Parties. Electronic signatures are sufficient.

  3. Governing Law and Forum. This DPA is governed by, and disputes shall be resolved in accordance with, the governing law and dispute resolution provisions of the Main Contract, except that mandatory provisions of applicable data protection law and the SCCs (where applicable) remain unaffected.

  4. Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect.

IN WITNESS WHEREOF, the Parties have executed this DPA as of the Effective Date of the Main Contract.

CAKEWALK TECH INC.CONTROLLER

By: __________________________By: __________________________

Name:Name:

Title:Title:

Date:Date:

ANNEX 1

Details of Processing

Subject matter of processing Provision of the Cakewalk Application (AI agent and human identity access management) as software-as-a-service, as further described in the Main Contract.
Duration The duration of the Main Contract, plus any applicable retention or deletion period set out in Section 9 of this DPA.
Nature and purpose Hosting, storage, transmission, access management, governance, logging, and related processing activities necessary to provide the Application, including support, security, and service improvement.
Frequency Continuous, for the duration of the Main Contract.

Categories of Data Subjects

☑ Employees of the Controller

☑ Suppliers / service providers (and their employees) of the Controller

☑ Business partners of the Controller - Agent Access Management module only

☑ Clients of the Controller - Agent Access Management module only

☐ Other: ________________________

Categories of Personal Data

Identification data

☑ First and last name / title

☑ Phone / mobile (optional)

☑ E-mail address

Employment-related data

☑ Employee organization information (phone, mobile, email)

☑ Internal security data (group ID, certificates, access rights)

☑ Department / role

Authentication and system data

☑ Login identifiers / authentication credentials (hashed where applicable); Agent Access Management module only: for Agent Connections, Cakewalk stores OAuth tokens and other access tokens like API keys where provided; Cakewalk does not store passwords for connected downstream systems

☑ Communication content data (whether and to what extent communication content is processed depends on the systems the Controller connects and the content the Controller's agents are given access to) - Agent Access Management module only

☑ Log data (log-in / log-off, access events)

☑ System data (configuration information, alarm messages)

☑ Cookies

☑ User identifiers (IDs)

Other

☑ Tools / software used by employees (as collected by the Application for access governance)

☑ Slack integration data (where Customer connects Slack): messages mentioning @cakewalk in conversations the app is added to; messages sent as @cakewalk; messages in DMs the app is added to; workspace user names and email addresses

Special categories of Personal Data: None expected. The Processor does not require or solicit special categories of Personal Data (Article 9 GDPR) for the operation of the Application.

ANNEX 2

Technical and Organizational Measures

The Processor implements and maintains the technical and organizational measures set out below to ensure a level of security appropriate to the risk. The Processor is ISO 27001:2022 certified and complies with the requirements arising from that certification.

Cloud Infrastructure Security

☑ VPN-based administrative access only

☑ Secrets management via AWS Secrets Manager

☑ APIs protected with OpenID Connect

☑ Encryption in transit (TLS) and at rest (AES-256)

☑ Logical tenant separation; each customer has a separate database

Confidentiality

System admission control

☑ Strong passwords enforced via password policy

☑ Automatic session locking

☑ Two-factor authentication; Single Sign-On

☑ Encryption of storage media

☑ Enterprise password manager for all employees

Access control (within systems)

☑ Role- and need-based access rights

☑ Documented authorization concepts

☑ Logging of access events

Tenant separation

☑ Multi-tenancy with logical separation

☑ Sandboxing

Pseudonymization

☑ Personal Data is pseudonymized where feasible; additional information enabling re-attribution is stored separately and protected by appropriate technical and organizational measures.

Integrity

Transfer control

☑ Encryption in transit

☑ Virtual Private Networks (VPN)

Input control

☑ Logging of data input and modifications

Availability and Resilience

☑ Anti-malware / virus protection

☑ Firewalls

☑ Regular encrypted backups (on-site and off-site) in accordance with ISO 27001:2022 backup requirements

☑ Documented incident response and disaster recovery procedures

Procedures for Regular Review, Assessment, and Evaluation

☑ Documented data processing agreements with all Sub-Processors

☑ Strict selection process for Sub-Processors, including security and compliance review

☑ Periodic review and follow-up inspections of Sub-Processor compliance

☑ Annual external review under ISO 27001:2022 certification

Mobile Working

Personnel may process Personal Data outside of Processor business premises (mobile working). The Processor warrants that appropriate technical and organizational measures are extended to such mobile working, including device encryption, VPN access, MDM controls where applicable, and personnel obligations. The Processor's mobile working guideline is available upon request.

ANNEX 3

Approved Sub-Processors

The Controller approves the engagement of the following Sub-Processors. Changes to this list are governed by Section 5 of the DPA.

For the avoidance of doubt, the Processor may permit its Affiliates to process Personal Data for the purposes set out in this DPA. Such Affiliates are subject to an intra-group data processing agreement imposing obligations no less protective than those in this DPA, and the Processor remains fully liable for their performance.

Hosting and Infrastructure

Sub-Processor Location Service Provided Personal Data / Notes
Amazon Web Services EMEA SARL (AWS Frankfurt) 38 Avenue John F. Kennedy, L-1855 Luxembourg / Marcel-Breuer-Str. 12, 80807 Munich, Germany Cloud hosting (primary)

All Customer Data hosted in EU region (AWS eu-central-1).

DPA:

https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html

Amazon Web Services, Inc. (AWS US) — future option 410 Terry Avenue North, Seattle, WA 98109, USA Cloud hosting (US region) — planned future availability for US customers requiring US data residency

Not yet active. Will be activated and notified to Controllers in accordance with Section 5 of the DPA.

DPA to be concluded prior to activation.

Application Integrations and Services

Sub-Processor Location Service Provided Personal Data / Notes
Kombo Technologies GmbH c/o Bridgemaker, Linienstr. 86, 10119 Berlin, Germany Unified HRIS API for employee directory integration Employee/user data (employee name, team, email, etc.).

DPA in place.
Forge Technology, Inc. dba Paragon 1301 N Broadway STE 32593, Los Angeles, CA 90012, USA Embedded iPaaS for third-party integrations - not applicable to Agent Access Management only usage

Integration data (user access in 3rd party systems)

DPA:

https://security.useparagon.com/

OpenAI, L.L.C. (US) / OpenAI Ireland Ltd. (EEA) 1455 3rd Street, San Francisco, CA 94158, USA / 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland LLM API for AI agent reasoning within the Application

Prompt content and metadata as required for agent reasoning. No training on Customer data (API default).

DPA:

https://openai.com/policies/data-processing-addendum/

Anthropic, PBC 548 Market Street, PMB 90375, San Francisco, CA 94104, USA Process of data from different sources (HubSpot, Sentry, etc.) to generate insights.

Insights generation. No training on Customer data (API default).

DPA:

https://trust.anthropic.com/

https://www.anthropic.com/legal/data-processing-addendum

Slack Technologies, LLC 415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA Notifications and conversational interface - not applicable to Agent Access Management only usage

Users receive notifications via Slack. Slack notifications may include details about user access to third party apps, users’ personal data (full name, email, address), and work-related information (start date, termination date, job title, users groups, region, department, team).
Users interact with our agent via Slack.

DPA:

https://slack.com/intl/en-gb/terms-of-service/data-processing

Twilio Inc. (SendGrid) 101 Spear Street, 5th Floor, San Francisco, CA 94105, USA Email services - not applicable to Agent Access Management only usage

Users receive email notifications via SendGrid. Emails may include details about user access to third party apps, users’ personal data (full name, email, address), and work-related information (start date, termination date, job title, users groups, region, department, team).

DPA:

https://www.twilio.com/en-us/legal/data-protection-addendum

Customer Support, Monitoring, and Analytics

Sub-Processor Location Service Provided Personal Data / Notes
Pylon Labs, Inc. 690 5th Street, San Francisco, CA 94107, USA Customer support and ticketing platform

Support ticket content, in-app messages, name and email of Customer users contacting support.

DPA:

https://www.usepylon.com/data-processing-agreement

Functional Software, Inc. dba Sentry 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA Application error monitoring and observability

Error stack traces, user identifiers, browser/device metadata, and any data incidentally present in error payloads.

DPA:
https://sentry.io/legal/dpa/

TMD Technology Limited (Embeddable) International House, 142 Cromwell Road, London, SW7 4EF, United Kingdom (Co. no. 13856879) Embedded analytics toolkit within the Application - not applicable to Agent Access Management only usage

Aggregated usage and analytics data; details about user access to third party apps, users’ personal data (full name, email, address), and work-related information (start date, termination date, job title, users groups, region, department, team). Customer-scoped analytics.

DPA:

https://embeddable.com/policies/dpa

HubSpot Germany GmbH Am Postbahnhof 17, 10243 Berlin Customer relationship management (CRM)

Customer billing and administrative contact data (names, business email, phone, conversation history).

DPA:

https://legal.hubspot.com/dpa

PostHog, Inc. 2261 Market Street, Suite 4008, San Francisco, CA 94114, USA Product analytics

User identifiers, session and event data attributable to Customer users for product analytics. Hosting region (EU eu-central-1 or US us-east-1) per Cakewalk configuration.

DPA:
https://posthog.com/dpa

Payment Processing

Sub-Processor Location Service Provided Personal Data / Notes
Stripe, Inc. (US customers) 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA Payment processing for US customers

Customer billing contact and payment data.

DPA in place.

Stripe Payments Europe, Ltd. (EU customers)

The One Building, 1 Grand Canal

Street Lower, Grand Canal Dock,

Dublin 2, Ireland

Payment processing for EU customers

Customer billing contact and payment data.

DPA:

https://stripe.com/en-de/legal/dpa

ANNEX 4

Standard Contractual Clauses and UK Addendum

(Applies where Personal Data of EU/UK/Swiss data subjects is processed)

A. EU Standard Contractual Clauses (SCCs)

The Parties incorporate by reference the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), available at https://eur-lex.europa.eu/eli/dec_impl/2021/914 (the “SCCs”), and the following module and options apply:

  1. Module: Module Two (Controller to Processor).

  2. Clause 7 (Docking Clause): Not applied.

  3. Clause 9(a): Option 2 (General written authorization). The minimum notice period for changes is thirty (30) days, as set out in Section 5.3 of this DPA.

  4. Clause 11(a) (Independent dispute resolution): The option is not used.

  5. Clause 17 (Governing law): The SCCs are governed by the law of Ireland.

  6. Clause 18 (Forum and jurisdiction): Disputes shall be resolved by the courts of Ireland.

B. SCC Appendix Information

Annex I.A (List of Parties):

Data Exporter The Controller, as identified in the Main Contract. Contact details, role, signature, and date as per the Main Contract.
Data Importer Cakewalk Tech Inc., 345 California Avenue, Palo Alto, CA 94306, USA. Contact: privacy@getcakewalk.io. Role: Processor. Signature and date as per the Main Contract.

Annex I.B (Description of Transfer):

Categories of data subjects, categories of Personal Data, frequency, nature, purpose, and retention are as set out in Annex 1 and Section 9 of this DPA. The transfers are continuous for the duration of the Main Contract.

Annex I.C (Competent Supervisory Authority):

Where the Controller is established in an EU Member State, the supervisory authority of that Member State. Where the Controller is not established in the EU but has appointed an EU representative under Article 27 GDPR, the supervisory authority of the Member State in which the EU representative is established. Otherwise, the Irish Data Protection Commission.

Annex II (Technical and Organizational Measures):

As set out in Annex 2 of this DPA.

Annex III (List of Sub-Processors):

As set out in Annex 3 of this DPA.

C. UK International Data Transfer Addendum

To the extent that the Personal Data transferred is subject to the UK GDPR, the Parties incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 and laid before Parliament on 2 February 2022 (the “UK Addendum”), as further specified below:

Table 1: Parties As set out in Annex I.A above.
Table 2: Selected SCCs, Modules and Selected Clauses The version of the Approved EU SCCs is the version incorporated into this Annex 4 (Section A above).
Table 3: Appendix Information As set out in Annex I.B, Annex II, and Annex III above (and Annex 2 and Annex 3 of this DPA).
Table 4: Ending the Addendum when the Approved Addendum Changes Neither Party may end the Addendum unilaterally.

D. Swiss Data Protection

To the extent that the Personal Data transferred is subject to the Swiss Federal Act on Data Protection (“FADP”), the SCCs apply with the following adaptations: (i) references to “GDPR” include the FADP; (ii) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; (iii) the SCCs also protect Personal Data of legal entities until entry into force of the revised FADP; (iv) the governing law is Swiss law and the forum is the courts of Switzerland for matters subject to the FADP.

ANNEX 5

CCPA / U.S. State Privacy Law Addendum

(Applies where Personal Information subject to the CCPA or comparable U.S. state privacy law is processed)

1. Definitions

Terms used in this Annex 5 that are defined in the CCPA (including “Business,” “Service Provider,” “Personal Information,” “Sell,” “Share,” and “Consumer”) have the meanings given to them in the CCPA. For purposes of this Annex, the Controller is the “Business” and the Processor is the “Service Provider.”

2. Service Provider Status

The Processor processes Personal Information solely on behalf of the Business and only for the limited and specified Business Purposes set forth in the Main Contract and this DPA (the “Business Purposes”). The Processor shall not:

  1. Sell or Share Personal Information (as those terms are defined under the CCPA);

  2. Retain, use, or disclose Personal Information for any purpose other than the Business Purposes, including for any commercial purpose other than providing the services set out in the Main Contract, except as permitted by the CCPA;

  3. Retain, use, or disclose Personal Information outside the direct business relationship between the Business and the Processor;

  4. Combine Personal Information received from the Business with Personal Information received from another source, except as permitted under the CCPA; or

  5. Take any action that would cause a transfer of Personal Information to or from the Processor to constitute a “Sale” or “Share” under the CCPA.

3. Certification

The Processor certifies that it understands the restrictions set out in Section 2 of this Annex 5 and will comply with them.

4. Assistance to the Business

Taking into account the nature of the processing, the Processor shall provide reasonable assistance to the Business in responding to consumer requests received by the Business under the CCPA (including requests to know, delete, correct, opt out of Sale/Share, and limit use of sensitive Personal Information). If the Processor receives such a request directly from a Consumer, the Processor shall not respond directly (except to acknowledge receipt and refer the Consumer to the Business) and shall forward the request to the Business without undue delay.

5. Cooperation and Notice

The Processor shall grant the Business the right to take reasonable and appropriate steps to ensure that the Processor uses Personal Information in a manner consistent with the Business’s obligations under the CCPA. The Processor shall notify the Business if it determines that it can no longer meet its obligations under the CCPA. Upon such notice, the Business may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.

6. Subcontractors

The Processor may engage Sub-Processors (which constitute “Subcontractors” under the CCPA) in accordance with Section 5 of the DPA, subject to contractual obligations that are at least as protective as those set out in this Annex 5.

7. Other U.S. State Privacy Laws

To the extent the Processor processes Personal Information (or equivalent defined terms) subject to other U.S. state comprehensive privacy laws, including the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and the Texas Data Privacy and Security Act, this Annex 5 applies with the necessary contextual adjustments such that the Processor acts as a “processor” or equivalent for the purposes of those laws, and the substantive protections set out in this Annex shall be deemed to apply with respect to those laws.

8. Order of Precedence

In the event of a conflict between this Annex 5 and any other provision of this DPA or the Main Contract regarding the processing of Personal Information of California Consumers (or comparable consumers under other U.S. state privacy laws), this Annex 5 prevails.