Skip to content
Legal

Data Processing Addendum

Last updated October 1, 2026

This Data Processing Addendum ("DPA") forms part of and is incorporated into the Master Subscription Agreement, Terms of Service or other written agreement between Ankord Labs LLC, a Delaware limited liability company with its principal office at 8549 Wilshire Blvd #5173, Beverly Hills, CA 90211 ("Ankord Labs", "we", "us") and the customer that accepts or purchases the Service or is identified in the applicable Order ("Customer", "you") (together, the "Agreement"). It governs the Processing of Personal Data in connection with the ComplyMo service (the "Service").

This DPA is effective as of the effective date of the Agreement.

1. Definitions

1.1 The terms "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Supervisory Authority", "Personal Data Breach" and "special categories of personal data" have the meanings given to them in the GDPR, and cognate terms shall be construed accordingly.

1.2 "Account Data" means Personal Data relating to Customer's personnel, authorized users, administrators and billing contacts that Ankord Labs Processes as a Controller under Section 4.

1.3 “Canadian Privacy Laws” means the Personal Information Protection and Electronic Documents Act, the Alberta Personal Information Protection Act, the British Columbia Personal Information Protection Act, Québec’s Act respecting the protection of personal information in the private sector, and any other Canadian federal, provincial or territorial privacy law applicable to the Processing.

1.4 "CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, together with its implementing regulations.

1.5 "Customer Personal Data" means Personal Data contained within Customer Data, excluding Account Data, that Ankord Labs Processes on Customer's behalf as a Processor or Sub-processor under Section 3.

1.6 "Customer Data" means all data, content and information submitted to, made available through, or generated through Customer’s use of the Service, including Service Data.

1.7 "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including (a) Regulation (EU) 2016/679 (the "GDPR"); (b) the GDPR as incorporated into United Kingdom law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018 (the "UK GDPR"); (c) the Swiss Federal Act on Data Protection (the "FADP"); (d) Canadian Privacy Laws; (e) the CCPA; and (f) the state privacy laws identified in Annex 4, in each case as amended, superseded or replaced from time to time.

1.8 "EEA" means the European Economic Area.

1.9 "Property" means a website, web application, document or other digital property that Customer configures for use with the Service.

1.10 “Service Data” means data generated, derived or collected through operation of the Service in connection with a Property, including automated review results and interaction data relating to individuals who interact with a Property (each, an “End User”) that is Processed on Customer’s behalf, as further described in Annex 1.

1.11 "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.

1.12 "Sub-processor" means any third party engaged by Ankord Labs to Process Customer Personal Data in connection with the Service.

1.13 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

1.14 Capitalized terms not defined in this DPA have the meanings given in the Agreement.

2. Roles of the parties

2.1 Roles by Processing activity. The parties acknowledge that Ankord Labs may act as a Controller, Processor or Sub-processor under the Agreement, and that the applicable capacity is determined by the relevant Processing activity and category of data rather than by the transaction as a whole:

DATA CATEGORYANKORD LABS' ROLECUSTOMER'S ROLEGOVERNING SECTION
Customer Personal Data made available through, or generated through, Customer’s use of the Service, including information relating to Customer’s Properties and individuals interacting with those PropertiesProcessor or Sub-processorController or ProcessorSection 3
Account DataControllerIndependent Controller, where applicableSection 4
Limited service security, diagnostic and operational information Processed by Ankord Labs for its own account administration, fraud prevention, legal compliance and defense of claimsControllerNot applicableSection 4

Information that forms part of Customer Personal Data and is Processed solely to provide or secure the Service remains subject to Section 3. Data meeting the requirements of Section 13 is governed by that Section.

2.2 Customer's responsibilities. Customer warrants that, whether it acts as a Controller or Processor, in respect of all Customer Personal Data: (a) Customer or the relevant Controller has a valid legal basis for the Processing it instructs; (b) Customer or the relevant Controller has provided all notices and obtained all consents required by Data Protection Laws; (c) Customer’s instructions comply with Data Protection Laws and, where Customer acts as a Processor, with the relevant Controller’s instructions; (d) it is entitled to transfer the Customer Personal Data to Ankord Labs for Processing; and (e) it has the right to configure each Property for use with the Service and to instruct Ankord Labs to Process Customer Personal Data as contemplated by the Agreement and this DPA.

2.3 Customer acting as Processor. Where Customer acts as a Processor, Customer represents and warrants that it is authorized by the relevant Controller to appoint Ankord Labs as a Sub-processor, provide the instructions set out in this DPA, and transfer Customer Personal Data to Ankord Labs and its authorized Sub-processors. References in this DPA to Customer’s obligations as Controller apply to Customer in its capacity as Processor to the extent Customer is responsible for satisfying or flowing down those obligations.

2.4 Incidental Personal Data. Personal Data incidentally appearing on a Property, including Personal Data that Customer did not anticipate would appear, remains Customer Personal Data to the extent Ankord Labs Processes it solely to provide the Service on Customer's instructions. Ankord Labs shall not determine a separate purpose for or otherwise Process that Personal Data as a Controller unless the parties first document the applicable roles and requirements under Data Protection Laws.

3. Processing as Processor or Sub-processor

3.1 Documented instructions. Ankord Labs shall Process Customer Personal Data only on and in accordance with Customer's documented instructions, which comprise the Agreement, this DPA, Customer's configuration of and use of the Service, and any further written instructions agreed by the parties. Where Customer acts as a Processor, its instructions must be consistent with the instructions of the relevant Controller. Ankord Labs shall immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws, provided that Ankord Labs is not obliged to conduct a legal review of the lawfulness of Customer's instructions.

3.2 Legal requirement to Process. Where Ankord Labs is required by applicable law to Process Customer Personal Data other than on Customer's instructions, Ankord Labs shall inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.

3.3 Purpose limitation. Ankord Labs shall not Process Customer Personal Data for any purpose other than providing, securing and supporting the Service, complying with law, and as otherwise permitted by this DPA. Ankord Labs shall not sell or share Customer Personal Data, shall not use it for its own commercial purposes, and shall not combine it with Personal Data obtained from other sources except as permitted by Data Protection Laws.

3.4 Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.

3.5 Confidentiality of personnel. Ankord Labs shall ensure that any person authorized to Process Customer Personal Data is subject to a binding written obligation of confidentiality that survives termination of the person's engagement and is granted access only to the extent necessary to perform assigned responsibilities.

3.6 Security. Ankord Labs shall implement and maintain the technical and organizational measures set out in Annex 2, having regard to the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing, and the risks to Data Subjects. Ankord Labs may update those measures from time to time provided that the overall level of protection is not reduced.

3.7 Assistance with Data Subject rights. Taking into account the nature of the Processing, Ankord Labs shall assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling Customer's obligations to respond to requests to exercise Data Subject rights under Chapter III of the GDPR and equivalent provisions of other Data Protection Laws.

3.8 Assistance with compliance obligations. Ankord Labs shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities under Articles 35 and 36 of the GDPR, and with Customer's obligations under Articles 32 to 34, in each case taking into account the nature of the Processing and the information available to Ankord Labs.

3.9 Fees for assistance. Ankord Labs shall provide the assistance described in Sections 3.7 and 3.8 at no additional charge, save that Ankord Labs may charge a reasonable fee, notified in advance, where requests are manifestly unfounded, excessive, or repetitive, or where the assistance requested is materially disproportionate to the nature of the Processing.

3.10 Requests received directly. If Ankord Labs receives a request or complaint from a Data Subject, a Supervisory Authority or any other third party relating to Customer Personal Data, Ankord Labs shall not respond to it substantively except to confirm that the request should be directed to Customer, and shall notify Customer of the request without undue delay and provide reasonable cooperation in responding to it.

3.11 Records. Ankord Labs shall maintain records of its Processing activities carried out on behalf of Customer in accordance with Article 30(2) of the GDPR and shall make them available to Customer on reasonable request.

4. Processing as Controller

4.1 Ankord Labs Processes Account Data and limited Service telemetry, security, diagnostic and operational information as a Controller for the purposes of providing, securing, administering, billing for, supporting and improving the Service, communicating with Customer, detecting and preventing fraud and abuse, exercising and defending legal claims, and complying with legal obligations. Its lawful bases are performance of a contract under Article 6(1)(b) of the GDPR where the individual is a party to the contract, its legitimate interests under Article 6(1)(f), and compliance with legal obligations under Article 6(1)(c), as applicable.

4.2 Ankord Labs' Processing as a Controller under Section 4.1 is described in the Ankord Labs Privacy Policy and is not subject to Sections 3, 5, 7, 8, 9, 10, 11 or 12 of this DPA.

4.3 Each party shall comply with its own obligations as an independent Controller in respect of any Personal Data exchanged between the parties for the purposes of contract administration, and neither party is a joint Controller with the other in respect of such Personal Data.

5. Sub-processors

5.1 General authorization. Customer grants Ankord Labs general written authorization to engage Sub-processors to Process Customer Personal Data, subject to this Section 5. The Sub-processors engaged as at the effective date of this DPA are listed in Annex 3 and are published on the Ankord Labs sub-processor page.

5.2 Obligations of Sub-processors. Before permitting any direct Sub-processor to Process Customer Personal Data, Ankord Labs shall enter into a written agreement with that Sub-processor imposing data protection obligations that are no less protective than those set out in this DPA, including the obligations required by Article 28(3) of the GDPR. Where a direct Sub-processor engages an underlying infrastructure provider identified in Annex 3, Ankord Labs shall require that Sub-processor to impose on the provider the data protection obligations required by applicable Data Protection Laws.

5.3 Liability for Sub-processors. Ankord Labs remains fully liable to Customer for the performance of each Sub-processor's obligations to the same extent as if Ankord Labs were performing the Processing itself.

5.4 Notice and objection. Ankord Labs shall give Customer at least thirty (30) days' prior notice of the appointment of any new or replacement Sub-processor by updating the sub-processor page and notifying subscribers to its change-notification mechanism. Customer may object to the appointment on reasonable and documented grounds relating to data protection by giving written notice within that period. The parties shall discuss the objection in good faith. If they are unable to resolve it within thirty (30) days after Ankord Labs receives the objection, Customer may terminate the affected subscription on written notice and shall receive a pro-rata refund of fees prepaid for the unexpired portion of the then-current Subscription Term.

5.5 Emergency replacement. Where the appointment of a Sub-processor is required urgently in order to protect the security, integrity or continuity of the Service, or to comply with a legal obligation, Ankord Labs may make the appointment with immediate effect and shall notify Customer as soon as reasonably practicable thereafter, whereupon Section 5.4 shall apply to that appointment from the date of notification.

5.6 Customer's obligation to subscribe. Customer is responsible for subscribing to the change notification mechanism and for ensuring that the notification address it provides remains current. Ankord Labs' obligation to notify is satisfied by notification to the address on record.

6. International transfers

6.1 The Service is hosted in the United States. Customer Personal Data will be transferred to and Processed in the United States and in any other jurisdiction in which a Sub-processor listed in Annex 3 operates. Account Data may also be transferred to and Processed in the United States as described in the Privacy Policy.

6.2 EEA transfers. Where Customer Personal Data originating in the EEA is transferred to Ankord Labs in a country that has not been the subject of an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

(a) Module Two applies where Customer acts as Controller and Ankord Labs acts as Processor;

(b) Module Three applies where Customer acts as Processor and Ankord Labs acts as Sub-processor; and

(c) Module One applies only to Account Data or another transfer expressly identified in the Agreement or an Order as a Controller-to-Controller transfer.

Module Four does not apply unless the parties expressly identify a Processor-to-Controller transfer in writing. The applicable module is determined separately for each Processing activity based on the parties’ actual roles. The SCCs apply only to the extent their legal scope requirements are satisfied. If the relevant Processing by Ankord Labs as data importer is directly subject to the GDPR under Article 3, the parties shall cooperate in good faith to implement another valid transfer mechanism applicable to that Processing.

6.3 UK transfers. Where Customer Personal Data originating in the United Kingdom is so transferred, the UK Addendum is incorporated into this DPA by reference. The SCC module selected under Section 6.2 applies, as amended by the UK Addendum, and the UK Addendum is completed as set out in Annex 5.

6.4 Swiss transfers. Where Customer Personal Data originating in Switzerland is so transferred, the SCC module selected under Section 6.2 applies with the following modifications: references to the GDPR are to be understood as references to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and the term "member state" shall not be interpreted so as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.

6.5 Alternative mechanisms. If Ankord Labs adopts an alternative lawful transfer mechanism, including certification under the EU-U.S. Data Privacy Framework, that mechanism may apply to a transfer to the extent it validly covers that transfer. The SCCs, UK Addendum and Swiss adaptations remain available as a fallback where the alternative mechanism does not apply or ceases to apply.

6.6 Conflict. In the event of any conflict between the SCCs or the UK Addendum and any other term of this DPA or the Agreement, the SCCs or the UK Addendum shall prevail in respect of the transfer concerned.

6.7 Transfer impact assessment. Ankord Labs maintains an assessment of the risks associated with the transfers described in this Section and shall make a copy available to Customer on reasonable written request, subject to redaction of confidential information.

7. Personal Data Breach

7.1 Notification. Ankord Labs shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Ankord Labs becomes aware when its personnel responsible for security have a reasonable degree of certainty that Customer Personal Data has been compromised.

7.2 Content of notification. The notification shall, to the extent known at the time, describe: the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and to mitigate its effects; and the name and contact details of a point of contact from whom further information may be obtained. Where and insofar as it is not possible to provide the information at the same time, it shall be provided in phases without further undue delay.

7.3 Cooperation. Ankord Labs shall provide reasonable cooperation and assistance to Customer in respect of Customer's own obligations to notify Supervisory Authorities and Data Subjects, and shall take reasonable steps to identify the cause of the breach, mitigate its effects, and prevent recurrence.

7.4 No admission. Ankord Labs' notification of, or response to, a Personal Data Breach shall not be construed as an acknowledgement by Ankord Labs of any fault or liability.

7.5 Public communications. Neither party shall issue any public statement or communication identifying the other party in connection with a Personal Data Breach without the other party's prior written consent, except where and to the extent required by applicable law, in which case the disclosing party shall give as much prior notice as is lawful and practicable.

8. Audit and information rights

8.1 Information. Ankord Labs shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA.

8.2 Reports first. Customer's rights under Section 8.1 and Section 8.3 shall in the first instance be satisfied by Ankord Labs providing: its then-current third-party audit report or certification, where one is available; its completed standard security questionnaire where available; and written responses to reasonable follow-up questions.

8.3 On-site and remote audits. Where the materials provided under Section 8.2 are not reasonably sufficient to demonstrate compliance, or following a Personal Data Breach affecting Customer Personal Data, Customer or a mandated auditor may conduct an audit of Ankord Labs' Processing. Such audits shall be: limited to once in any twelve (12) month period, save where required by a Supervisory Authority or following a Personal Data Breach; conducted on at least thirty (30) days' prior written notice; conducted during normal business hours; conducted in a manner that does not unreasonably disrupt Ankord Labs' business; subject to the confidentiality obligations in the Agreement; and conducted without accessing the data or systems of any other customer of Ankord Labs.

8.4 Auditor. Any mandated auditor shall not be a competitor of Ankord Labs and shall execute a confidentiality agreement with Ankord Labs on reasonable terms before the audit commences.

8.5 Costs. Each party shall bear its own costs in relation to an audit, save that Customer shall reimburse Ankord Labs' reasonable costs where the audit reveals no material non-compliance, and Ankord Labs shall bear its own costs where material non-compliance is revealed.

8.6 Remediation. Where an audit identifies non-compliance, Ankord Labs shall promptly agree and implement a remediation plan.

9. Deletion and return of Customer Personal Data

9.1 Return and deletion. On expiry or termination of the Agreement, or on Customer's verified written request, Ankord Labs will make Customer Personal Data available for export where reasonably practicable and will delete it from active production systems within thirty (30) days, subject to Sections 9.3 and 9.4. Ankord Labs may verify that a request is made by an authorized account owner before acting on it.

9.2 Default retention. Unless Customer deletes the data earlier or instructs Ankord Labs otherwise, Ankord Labs retains: (a) End User consent records for twenty-four (24) months after creation; (b) tracker detection records for ninety (90) days after the tracker was last detected; and (c) automated review results for twelve (12) months after the review date. Deletion from active production systems will be completed within thirty (30) days after the applicable period ends.

9.3 Point-in-time recovery. Customer Personal Data deleted from active production systems may remain in provider-managed point-in-time recovery history for up to seven (7) additional days. During that period, Ankord Labs will continue to protect the data under Annex 2 and will not Process it except for storage and restoration. The Service does not use separate object storage for Customer Personal Data.

9.4 Limited retention exceptions. Ankord Labs or a Sub-processor may retain limited Customer Personal Data beyond the periods above only to the extent required by applicable law or reasonably necessary to investigate abuse, protect the security or integrity of the Service, or enforce applicable acceptable-use restrictions, and only as permitted by the applicable written agreement and Data Protection Laws. Such data will remain protected, access-restricted and excluded from other Processing. The AI provider's standard retention exceptions are described in Annex 1 Part F.

9.5 Aggregated data. Nothing in this Section 9 requires the deletion of data meeting the requirements of Section 13.

9.6 Certification. Ankord Labs shall, on Customer's written request, provide written certification of deletion carried out under this Section 9.

10. CCPA and CPRA service provider terms

10.1 Roles. With respect to Personal Information (as defined in the CCPA) contained within Customer Personal Data, Customer is a Business, Service Provider or Contractor, and Ankord Labs is a Service Provider or Contractor, in each case as applicable.

10.2 Restrictions. Ankord Labs shall not: (a) sell or share Personal Information; (b) retain, use or disclose Personal Information for any purpose other than for the specific purpose of performing the Service specified in the Agreement, or as otherwise permitted by the CCPA; (c) retain, use or disclose Personal Information outside the direct business relationship between Ankord Labs and Customer; or (d) combine Personal Information received from or on behalf of Customer with Personal Information received from or on behalf of any other person, or collected from its own interaction with a consumer, except as expressly permitted by the CCPA and its implementing regulations.

10.3 Certification. Ankord Labs certifies that it understands the restrictions set out in Section 10.2 and will comply with them.

10.4 Notification of inability to comply. Ankord Labs shall notify Customer promptly, and in any event within five (5) business days, if it determines that it can no longer meet its obligations under the CCPA.

10.5 Customer's remediation rights. Customer may, on notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information by Ankord Labs.

10.6 Monitoring. Customer may take reasonable and appropriate steps to help ensure that Ankord Labs uses Personal Information in a manner consistent with Customer's obligations under the CCPA, which steps shall be satisfied by the mechanisms in Section 8.

10.7 Assistance with consumer requests. Ankord Labs shall provide reasonable assistance to Customer in responding to verifiable consumer requests to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information.

10.8 No consideration. The parties acknowledge that no monetary or other valuable consideration is provided by Ankord Labs to Customer in exchange for Personal Information, and that the disclosure of Personal Information by Customer to Ankord Labs does not constitute a sale or a share.

10.9 Sub-processors. Ankord Labs shall enter into a written agreement with each Sub-processor that is a service provider or contractor under the CCPA, imposing obligations equivalent to those in this Section 10.

11. United States multistate addendum

11.1 Application. This Section 11 applies to Personal Data subject to any of the state privacy laws listed in Annex 4. Where such a law imposes an obligation more protective or more specific than the obligations elsewhere in this DPA, that obligation applies in respect of Processing subject to that law.

11.2 Processor obligations. In respect of Personal Data subject to a law listed in Annex 4, and to the extent Ankord Labs acts as a processor or service provider under that law, Ankord Labs shall: (a) adhere to Customer's instructions; (b) assist Customer in responding to consumer rights requests; (c) assist Customer with data protection assessments where required; (d) implement appropriate technical and organizational security measures; (e) engage sub-processors only pursuant to a written contract imposing equivalent obligations; (f) make available to Customer information reasonably necessary to demonstrate compliance; (g) allow and cooperate with reasonable assessments, or arrange for a qualified and independent assessor to conduct one; and (h) at Customer's direction, delete or return Personal Data at the end of the provision of services, unless retention is required by law.

11.3 Sensitive data. Customer shall not intentionally submit Customer Data to the Service, or configure the Service to collect Customer Data, that Customer knows or reasonably should know will result in the Processing of sensitive data as defined under applicable Data Protection Laws, including data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation data, personal data collected from a known child, or criminal-offence data, unless the parties agree in writing to any additional measures required.

11.4 Children's data. Customer shall not use the Service to Process Personal Data of children in circumstances requiring verifiable parental consent unless it has obtained that consent and has notified Ankord Labs in writing.

11.5 Universal opt-out mechanisms. Where a law listed in Annex 4 requires recognition of a universal opt-out mechanism, that obligation rests with Customer as Controller or Business in respect of Properties it owns, controls or with which it is authorized to use the Service. The Service does not serve advertising, does not set advertising identifiers, and does not engage in targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects.

11.6 De-identified data. Where Ankord Labs Processes de-identified data, it shall take reasonable measures to ensure the data cannot be associated with an individual, shall publicly commit to maintaining it in de-identified form, and shall contractually obligate any recipient to comply with equivalent requirements.

12. Canadian Privacy Laws. To the extent Customer Personal Data is subject to Canadian Privacy Laws, Ankord Labs shall: (a) Process such data only to provide the Service and in accordance with Customer’s documented instructions; (b) maintain safeguards appropriate to the sensitivity of the data; (c) require each Sub-processor to provide a comparable level of protection; (d) notify Customer without undue delay of any actual or attempted Personal Data Breach to the extent required by applicable law; (e) permit reasonable verification in accordance with Section 8; and (f) return or delete the data in accordance with Section 9. Customer is responsible for determining that its instructions and transfer of Customer Personal Data to Ankord Labs comply with applicable Canadian Privacy Laws. Ankord Labs shall provide information reasonably requested by Customer to complete any required privacy impact or cross-border transfer assessment, including an assessment required before Personal Data is communicated outside Québec.

13. Aggregated and de-identified data

13.1 Ankord Labs may generate aggregated and de-identified data derived from the Processing of Customer Data and may use it for the purposes of operating, securing, analyzing, benchmarking, developing and improving the Service and Ankord Labs' other products.

13.2 Ankord Labs shall not disclose aggregated and de-identified data in any manner that identifies Customer or any Data Subject, and shall not attempt to re-identify it.

13.3 Ankord Labs shall not use Customer Personal Data to train, fine-tune or otherwise develop any machine learning or artificial intelligence model that is made available to any third party, and shall contractually prohibit each Sub-processor from doing so.

14. Liability

14.1 Cap. Each party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to and counts towards the exclusions and limitations of liability set out in the Agreement. This DPA does not create any separate or additional limit of liability, and any amount recovered under this DPA reduces, on a pound-for-pound or dollar-for-dollar basis, the aggregate liability available under the Agreement. For clarity, liability under this DPA remains subject to the Agreement's cap even if the same facts also constitute a breach of the Agreement's confidentiality obligations, except to the extent the Agreement expressly provides otherwise.

14.2 Data Subject Rights. Nothing in this DPA limits a Data Subject's rights against either party under applicable Data Protection Laws. As between the parties, all liability, contribution and reimbursement arising from Processing is subject to the exclusions and limitations in the Agreement to the maximum extent permitted by law.

14.3 Apportionment. Where both parties are responsible for damage caused by Processing, each party shall be liable to the Data Subject in accordance with applicable Data Protection Laws. As between the parties, either party may claim from the other the portion of the compensation corresponding to the other party's responsibility subject to Section 14.1.

15. General

15.1 Precedence. In the event of any conflict or inconsistency between this DPA and the Agreement in respect of the Processing of Personal Data, this DPA prevails. In all other respects the Agreement continues in full force and effect. For clarity, the exclusions and limitations of liability in the Agreement govern liability under this DPA as provided in Section 14.

15.2 Term. This DPA takes effect on the effective date of the Agreement and continues until all Customer Personal Data has been deleted or returned in accordance with Section 9. The obligations in Sections 3.5, 9, 10, 11, 12, 13, 14 and 15 survive termination.

15.3 Variation. Ankord Labs may amend this DPA on thirty (30) days' written notice where required to comply with Data Protection Laws, to reflect a change in transfer mechanism, or to reflect a change in the Service, provided that no amendment shall materially reduce the protections afforded to Customer Personal Data. Any other amendment is governed by the Agreement.

15.4 Severability. If any provision of this DPA is held invalid, illegal or unenforceable, that provision shall be severed and the remaining provisions shall continue in full force and effect.

15.5 Governing law. This DPA is governed by the law and subject to the jurisdiction specified in the Agreement, save that where the SCCs or the UK Addendum apply, the governing law and forum specified in those instruments shall apply to the transfer concerned.

15.6 Counterparts and execution. This DPA may be executed in counterparts, each of which is an original and all of which together constitute one instrument. Where Customer accepts the Agreement electronically, this DPA is deemed executed on the same basis without further signature.

15.7 Notices. Notices under this DPA shall be given in accordance with the notices provision of the Agreement, and notices to Ankord Labs concerning data protection shall additionally be sent to privacy@complymo.com.

Annex 1 — Details of Processing

This Annex describes only Customer Personal Data Processed by Ankord Labs as a Processor or Sub-processor under Section 3. Account Data and other Personal Data Processed by Ankord Labs as a Controller under Section 4 are excluded.

A. Subject matter, duration, nature and purpose

ITEMDETAIL
Subject matterProvision of the ComplyMo website tools and automated functionality, including website accessibility-support, consent-management, website-content review and related AI-assisted functions.
DurationThe term of the Agreement, together with the retention periods set out in Section 9 and Part F below.
Nature of ProcessingCollection, receipt, storage, retrieval, consultation, automated and AI-assisted analysis, transmission, disclosure by transmission, organization, use, erasure and destruction, as necessary to provide, secure and support the Service.
PurposeTo provide, secure and support the Service; enable authorized users to configure and use Service functions; generate and present reports, findings, summaries and suggestions; respond to authorized-user prompts; and process interaction and consent-related data where Customer deploys applicable functionality.

B. Categories of Data Subjects

  1. Customer personnel and other authorized users whose Personal Data is included in Customer Data, including information they submit through interactive Service features.
  2. Individuals whose Personal Data appears in content made available through a Property.
  3. Individuals who interact with a Property where Customer deploys Service functionality that processes interaction or consent-related information.

C. Categories of Personal Data

Property and Service data. Property addresses, titles and configuration information; limited publicly available page text and code excerpts; tracker detection information; automated and AI-assisted review results, reports, summaries, recommendations and related outputs; messages and other information submitted by authorized users through interactive Service features; and limited element or location identifiers generated through authorized inspection functions.

Individual interaction and consent-related data. Where Customer deploys applicable Service functionality: pseudonymous visitor identifiers, interaction or consent choices, configuration or policy version, country, browser or device information, and timestamps. The Service is not designed to store End User names, contact information, IP addresses or form-field content through these functions.

Special categories. Not intentionally Processed. Incidental Processing may occur if a Property or an authorized user makes such information available to the Service. Customer shall not intentionally submit special-category or sensitive Personal Data unless the parties first agree in writing to appropriate additional measures.

D. Frequency of Processing

Continuous or scheduled, as configured by Customer.

E. Storage locations

LAYERPROVIDERLOCATION
Application hosting, edge delivery and serverless functionsVercel Inc.United States; global edge delivery and operational failover may involve other locations
Managed database servicesDatabricks, Inc. (Neon service), using Amazon Web ServicesUnited States (AWS US East, Northern Virginia)
AI-assisted Service functionalityAnthropic, PBC, through its direct APIUnited States
Transactional and service-related emailPlus Five Five, Inc. (Resend)United States (US East)

F. Retention

As set out in Section 9. Anthropic ordinarily retains API inputs and outputs for up to thirty (30) days. Content flagged under its usage or safety policies may be retained for longer periods, including up to two (2) years for flagged content and longer for limited safety-classification records, under access restrictions and the provider's applicable terms.

G. Data flow

Customer configures a Property for use with the Service. The Service receives and Processes Customer Data as necessary to provide the configured functions, including automated or AI-assisted review of Property content, authorized-user interaction with Service features and, where deployed by Customer, interaction with End Users through the Property. Service outputs and records are stored with the providers identified in Annex 3 and made available to Customer through the application, export or email.

Annex 2 — Technical and organizational measures

Ankord Labs maintains the following technical and organizational measures appropriate to the nature of the Processing and the risks to Data Subjects:

AREAMEASURESTATUS
Encryption in transitTLS 1.2 or higher for web traffic and database connections carrying Customer Personal DataIn effect
Encryption at restProvider-managed encryption for database storageIn effect
PseudonymizationEnd User consent records use a randomly generated visitor identifier and do not store IP addressesIn effect for consent records
Access controlUnique credentials, owner and member roles, tenant-level logical segregation and access limited to named personnelIn effect
Administrative authenticationMulti-factor authentication for administrative accounts at hosting, database, code-repository, payment, email and analytics providersEffective 25 September 2026
Credential managementProduction secrets are maintained in provider-managed encrypted environment settings rather than source codeIn effect
Operational loggingHosting-provider runtime logs are retained for one day or less; no separate administrative audit log is maintainedIn effect as described
RecoveryProvider-managed point-in-time database recovery with a seven-day windowIn effect
PersonnelProduction access is limited to named individuals subject to written confidentiality obligations; access is removed when an engagement endsEffective 1 October 2026
Endpoints and physical environmentRemote operation with no Ankord Labs-owned data centers; full-disk encryption and automatic screen lock required on devices used to access production systemsIn effect
Sub-processor managementSub-processors are engaged under written data-protection terms, including applicable standard DPAsIn effect
Data minimizationNo End User IP addresses are stored; page addresses are stored without query strings; stored excerpts and element locators are length-limitedIn effect

Annex 3 — Sub-processors

SUB-PROCESSORPURPOSELOCATIONDATA PROTECTION AGREEMENT
Vercel Inc.Application hosting, edge delivery, serverless functions and deploymentUnited States; global edge delivery and operational failover may involve other locationsVercel standard DPA incorporated into its terms
Databricks, Inc. (Neon service)Managed PostgreSQL database servicesUnited States (AWS US East)Databricks DPA with Neon product terms
Amazon Web Services, Inc.Underlying infrastructure supporting the database serviceUnited StatesIndirect, through Databricks
Anthropic, PBCAI-assisted website review, troubleshooting assistance and public regulatory or standards-related summariesUnited StatesAnthropic DPA incorporated into its commercial terms
Plus Five Five, Inc. (Resend)Transactional and service-related emailUnited StatesResend standard DPA

The current list is published at the Ankord Labs sub-processor page, which prevails over this Annex where the two differ. Ankord Labs may update that list in accordance with Section 5 of this DPA.

Annex 4 — United States state privacy laws

California Consumer Privacy Act as amended by the California Privacy Rights Act; Virginia Consumer Data Protection Act; Colorado Privacy Act; Connecticut Data Privacy Act; Utah Consumer Privacy Act; Texas Data Privacy and Security Act; Oregon Consumer Privacy Act; Montana Consumer Data Privacy Act; Delaware Personal Data Privacy Act; Iowa Consumer Data Protection Act; Nebraska Data Privacy Act; New Hampshire Privacy Act; New Jersey Data Privacy Act; Tennessee Information Protection Act; Minnesota Consumer Data Privacy Act; Maryland Online Data Privacy Act; Indiana Consumer Data Protection Act; Kentucky Consumer Data Protection Act; Rhode Island Data Transparency and Privacy Protection Act and any other comprehensive state privacy law applicable to the Processing.

This Annex applies to each listed law only to the extent that law in fact applies to the Processing concerned.

Annex 5 — Standard Contractual Clauses and UK Addendum: completion inputs

The following terms complete the SCCs and UK Addendum incorporated under Section 6:

  1. The applicable module is determined under Section 6.2 based on the parties' actual roles for the Processing concerned.
  2. For Modules Two and Three, Customer is the data exporter and Ankord Labs is the data importer.
  3. For Module Three, Customer shall provide the identity and contact details of the relevant Controller when required by the SCCs.
  4. For the UK Addendum, Table 1 is completed with the party information below; Table 2 with the applicable module and selections below; Table 3 with Annexes 1, 2 and 3 of this DPA; and Table 4 by selecting neither party as entitled to end the UK Addendum under Section 19 of the Mandatory Clauses.

The following inputs are provided for completion of the Annexes to the SCCs and the UK Addendum.

FIELDINPUT
Data importerAnkord Labs LLC, 8549 Wilshire Blvd #5173, Beverly Hills, CA 90211, United States; Processor under Module Two, Processor acting as Customer's Sub-processor under Module Three, and Controller under Module One
Importer contactprivacy@complymo.com
Importer activitiesProvision of the ComplyMo service as described in Annex 1
Data exporterThe Customer that accepts or purchases the Service or is identified in the applicable Order. Controller under Module Two, Processor under Module Three, and Controller under Module One.
Exporter activitiesUse of the Service in connection with Properties that Customer owns, controls or is authorized to configure for use with the Service.
Categories of Data SubjectsAs Annex 1 Part B
Categories of Personal DataAs Annex 1 Part C
Sensitive dataNot intentionally Processed; see Annex 1 Part C
Frequency of transferContinuous or scheduled, as configured by Customer
Nature and purposeAs Annex 1 Part A
Retention periodAs Section 9
Onward transfersAs Annex 3
Technical and organizational measuresAs Annex 2
Competent Supervisory AuthorityTo be determined in accordance with Clause 13
Option in Clause 7 (docking)Applies
Option in Clause 9 (sub-processors)General written authorization, thirty (30) days' notice, consistent with Section 5.4
Option in Clause 11 (redress)The optional redress provision does not apply
Option in Clause 17 (governing law)The law of the EEA Member State in which Customer is established, if any and if that law permits third-party beneficiary rights; otherwise the laws of the Netherlands
Option in Clause 18 (forum)The courts of the Member State selected under Clause 17
ComplyMo

Compliance, handled
in five minutes.

Accessibility, GDPR, and cookies. One script. One price. 14 days free.