SciFin is at Dreamforce 2026 — Live at booth 308.

Meet us there (opens in a new tab)
Legal

Terms of Service

MASTER SERVICES AGREEMENT

This Master Services Agreement (this "Agreement") is between SciFin Inc., a Delaware corporation ("SciFin"), and the customer identified in the Order Form ("Customer"). This Agreement sets forth conditions regarding Customer's use of SciFin's go-to-market platform (the "Platform"). By accessing or using the Platform in any manner, Customer agrees to be bound by this Agreement.

The person entering into this Agreement on behalf of Customer represents and warrants that the person is a duly authorized representative with the authorization to act on behalf of Customer and bind Customer to this Agreement.

In consideration of the mutual promises set forth in this Agreement, the parties, intending to be legally bound, agree as follows:

1. Use of Platform; Order Form

(a)

Order Form. The specific details regarding Customer's use of the Platform will be set forth in an order form (the "Order Form"). In the event of a conflict between the terms of this Agreement and the terms of the Order Form, the terms of this Agreement shall control unless the language in the Order Form states that it is intended to supersede this Agreement. If Customer purchases access to the Platform from an authorized reseller of SciFin (each, a "Reseller"), the Order Form may be presented to Customer by the Reseller.

(b)

Use of Platform. Customer may use the Platform during the Term. The Order Form sets forth the number of authorized users (each, a "User") that may access the Platform on behalf of Customer.

(c)

Responsibility for Users. Customer shall ensure that each of its Users uses the Platform in accordance with this Agreement. Any action by a User that is a breach of this Agreement will be deemed a breach of this Agreement by Customer.

(d)

Modifications to Platform. SciFin may modify and/or update the Platform from time to time. SciFin shall have no liability for any damage, liabilities, losses, or any other consequences that Customer, any of Customer's Users, or any other third party may incuras a result of modifications to the Platform.

2. Payment

In consideration for access to the Platform, Customer shall pay SciFin (or the Reseller, if applicable) the fees set forth in the Order Form (the "Fees"). Unless stated otherwise in the Order Form, all such Fees are due within 30 days of Customer's receipt of the applicable invoice. Payments not received on time are subject to a 1.5% late fee per month.

3. Restrictions

Customer may not:

(a)

modify, disclose, alter, translate or create derivative works of the Platform;

(b)

sublicense, resell, distribute, lease, rent, lend, transfer, assign, make the Platform available to third parties, or otherwise dispose of the Platform;

(c)

reverse engineer, disassemble, decompile, decode, adapt, or otherwise attempt to derive or gain access to any source code, object code, or underlying structure, ideas, or algorithms of the Platform, in whole or in part;

(d)

use the Platform to store or transmit any viruses, software routines or other code designed to permit unauthorized access, to disable, erase or otherwise harm software, hardware or data, or to perform any other harmful actions;

(e)

use the Platform in any manner or for any purpose that infringes, misappropriates, or otherwise violates any intellectual property right, privacy right, or other right of any person, or that violates any applicable laws;

(f)

interfere with or disable any features, functionality, or security controls of the Platform or otherwise circumvent any protection mechanisms for the Platform

(g)

copy, frame or mirror any part or content of the Platform;

(h)

build a competitive product or service, or copy any features or functions of the Platform;

(i)

interfere with or disrupt the integrity or performance of the Platform; or

(j)

attempt to gain unauthorized access to the Platform or related systems or networks.

SciFin may temporarily suspend Customer's access to the Platform if SciFin determines or reasonably suspects that Customer has or intends toviolate, or has assisted others in violating or preparing to violate, any provision of this Section 3 (any such temporary suspension, a "Service Suspension"). SciFin shall have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer or any third party may incur as a result of a Service Suspension, and Customer shall not be entitled to any refunds of any Fees on account of any Service Suspension.

4. Term; Termination

(a)

Term. This Agreement commences on the date set forth in the Order Form (the "Effective Date"), and will continue in effectfor the duration identified in the Order Form (the "Term"). Notwithstanding the foregoing, this Agreement may be terminated in accordance with this Section 4.

(b)

Termination for Cause. Either party may immediately terminate this Agreement upon notice if the other party (i) materially breaches this Agreement and such breach is not cured within 30 days after the breaching party receives notice of the breach from the other party, or (ii) ceases to do business in the normal course, becomes or is declared insolvent or bankrupt, is the subject of any proceeding related to its liquidation or insolvency (whether voluntary or involuntary) that is not dismissed within 90 days, or makes an assignment for the benefit of creditors.

(c)

Effect of Expiration or Termination. Upon expiration or termination of this Agreement, (a) Customer's right to access the Platform will terminate; (b) each party shall delete the other party's Confidential Information (except to the extent retention is required by applicable law); and (c) Customer shall pay all unpaid fees owed as of the date of expiration or termination of this Agreement.

5. Intellectual Property and Data

(a)

SciFin Ownership. SciFin owns all right, title and interest (including intellectual property rights) in and to the Platform (collectively, the "SciFin Property").

(b)

Feedback. Customer is encouraged to provide feedback, comments, and suggestions for improvements to the Platform ("Feedback"). Any modifications to the Platform that SciFin makes based on the Feedback are deemed to be SciFin Property. SciFin has the right, but not the obligation, to use such Feedback without any obligation to provide Customer credit, royalty payment, ownership interest, or any other type of compensation.

(c)

Customer Data. As between Customer and SciFin, Customer owns all documentation and data that it provides to SciFin pursuant to this Agreement (the "Customer Data"). Customer hereby grants SciFin the right to use the Customer Data as necessaryduring the Term to provide the Platform to Customer.

(d)

De-Identified Data. Customer acknowledges and agrees that SciFin may de-identify Customer Data in a manner that it can no longer reasonably be used to identify Customer or individuals ("De-Identified Data"). Customer acknowledges that the De-Identified Data does not constitute Customer Data, and SciFin may use the De-Identified Data for the purpose of improving the Platform, and to understand and analyze trends across SciFin's customers.

6. Confidentiality

(a)

Confidential Information. For purposes of this Agreement: "Recipient" means the party receiving Confidential Information from the other party; "Discloser" means the party providing Confidential Information to the other party; and "Confidential Information" means any information whether written or oral that (i) is identified by the Discloser as being confidential, or (ii) should reasonably be expected by the Recipient to be confidential. For the avoidance of doubt, Customer Data is Customer's Confidential Information, but De-Identified Data is not. Notwithstanding the foregoing, Confidential Information does not include information that (a) becomes generally available to the public through no fault of Recipient, (b) was rightfully in possession of Recipient without obligation of confidentiality prior to receipt from Discloser, (c) is independently developed by Recipient without benefit of any Confidential Information, or (d) is rightfully received by Recipient from another source on a non-confidential basis.

(b)

Use and Disclosure. Recipient shall not use or disclose any Confidential Information of Discloser except to the extent necessary to perform its obligations or exercise its rights hereunder, including by disclosing Confidential Information to its employees, independent contractors, and advisors who have a need to know such information to enable Recipient to perform its obligations or exercise its rights hereunder, and who are bound to keep such information confidential (collectively, the "Representatives"). Recipient is responsible for its Representatives' compliance with this Section 6. Recipient shall give Discloser's Confidential Information at least the same level of protection as it gives its own Confidential Information of similar nature, but not less than a reasonable level of protection. All confidentiality obligations will survive termination of this Agreement. Upon written request from Discloser and subject to any legal obligation to preserve Confidential Information, Recipient shall promptly return or destroy all Confidential Information, except that neither party is obligated to purge information archived pursuant to their normal document retention procedures if theprovisions of this section otherwise continue to be observed. The Recipient may disclose Confidential Information as required by law if the Recipient (a) gives the Discloser reasonable written notice to allow the Discloser to seek a protective order or other appropriate remedy, but only if such notice is legally permitted, (b) discloses only such information as is required by law, and (c) uses commercially reasonable efforts to obtain confidential treatment for any Confidential Information so disclosed.

(c)

Injunctive Relief. As money damages may not be a sufficient remedy for any breach of confidentiality obligations herein, the Discloser will be entitled to seek specific injunctive relief as a non-exclusive remedy for any such breach.

7. Data Processing Agreement

To the extent SciFin processes any personal dataas a result of Customer's use of the Platform,SciFin's processing of the personal data will be governed by the Data Processing Addendum attached as Exhibit A to this Agreement (the "DPA").

8. Meeting Recordings

Through the Platform, Customer will have the ability to record video-conference meetings ("Meetings"). Although SciFin provides the functionality for Customer to record Meetings, Customer is solelyresponsible for compliance with, and shall comply with,alllaws governing the monitoring or recording ofconversations. As part of that compliance, Customer shall ensure that it obtains all consents required by applicable law when recording Meetings.

9. Representations and Warranties

(a)

Mutual Representations and Warranties. Each party represents and warrants that (a) it has the full right, power and authority to enter into this Agreement and to perform the acts required of it hereunder; and (b) the execution of this Agreement and the performance of its obligations hereunder do not and will not violate any agreement to which it is a party or by which it is bound.

(b)

Customer Representations and Warranties. Customer represents and warrants that it has all rights necessary to provide the Customer Data to SciFin and to grant SciFin the rights set forth in Section 5.

10. Disclaimers

(a)

General Disclaimer. EXCEPT AS EXPRESSLY SET FORTH HEREIN, SCIFIN'S SERVICES ARE PROVIDED "AS-IS" AND SCIFIN DISCLAIMS ALL EXPRESS AND IMPLIED REPRESENTATIONS AND WARRANTIES WITH RESPECT TO THE PLATFORM (INCLUDING, WITHOUT LIMITATION, WARRANTIES OF NONINFRINGEMENT, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE).

(b)

Use of Platform. CUSTOMER ACKNOWLEDGES THAT THE PLATFORM IS NOT INTENDED TO REPLACE ANY HUMAN DECISIONS, AND IS SOLELY INTENDED TO ASSIST HUMAN DECISION MAKERS. ACCORDINGLY, CUSTOMER IS SOLELY RESPONSIBLE FOR ANY DECISIONS CUSTOMER MAKES OR ACTIONS CUSTOMER TAKES WITH RESPECT TO CUSTOMER'S OWN CUSTOMERS, CUSTOMER DATA, OR CUSTOMER'S PERSONNEL.

(c)

Third Party Platforms. CUSTOMER ACKNOWLEDGES THAT SCIFIN DOES NOT CONTROL THE THIRD PARTY PLATFORMS THAT CUSTOMER MAY INTEGRATE THE PLATFORM WITH (E.G., SALESFORCE, HUBSPOT). BECAUSE SCIFIN HAS NO CONTROL OVER THE THIRD PARTY PLATFORMS, SCIFIN DISCLAIMS ANY GUARANTEES ABOUT ITS ABILITY TO COLLECT CUSTOMER DATA FROM THE THIRD PARTY PLATFORMS, THE ACCURACY OF CUSTOMER DATA, OR THE ACCURACY OF INFORMATION THAT THE THIRD PARTY PLATFORMS PROVIDE TO CUSTOMER.

11. Indemnification

(a)

By Customer. Customer shall defend and indemnify SciFin and its officers, directors, employees, contractors, and agents (collectively, "Indemnitees") from and against any and all liability, damage, loss, cost, or expense, including reasonable attorneys' fees and expenses (collectively, "Costs"), arising out of or in connection with any actual claim, suit, action, or proceeding against SciFin or its Indemnitees by a third party as a result of (a) a breach of this Agreement by Customer, (b) the gross negligence or willful misconduct of Customer related to this Agreement, or (c)SciFin's authorized use of the Customer Data.

(b)

General Indemnity By SciFin. SciFin shall defend and indemnify Customer and its Indemnitees from and against any and all Costs arising out of or relating to any actual claim, suit, action, or proceeding against Customer or its Indemnitees by a third party as a result of (a) a breach of this Agreement by SciFin, or (b) the gross negligence or willful misconduct of SciFin related to this Agreement.

(c)

Infringement Indemnity by SciFin. SciFin shall defend and indemnify Customer and its Indemnitees from and against any and all Costs arising out of or relating to any actual claim, suit, action, or proceeding against Customer or its Indemnitees by a third party as a result of the infringement or misappropriation ofthird party intellectual property rights by the Platform. In the event of a claim pursuant to this Section11(c),SciFin may, at its option and expense (i) obtain for Customer the right to continue to exercise the rights granted to Customer under this Agreement; (ii) substitute the allegedly infringing component for an equivalent non-infringing component; or (iii) modify the Platform(s) to make them non-infringing. If none of subparts (i), (ii), or (iii) in the foregoing sentence are obtainable on commercially reasonable terms (as determined by SciFin),SciFin may terminate this Agreement, effective immediately, by written notice to Customer and refund to Customer any unused, prepaid Fees. SciFin's indemnification obligations do not extend to claims arising from or relating to: (i) any negligent or willful misconduct of Customer Indemnitees; or (ii) the use of the Platform by Customer in a manner contrary to the terms of this Agreement where the infringement would not have occurred but for such use.

(d)

Procedure. A party seeking indemnification ("Indemnified Party") shall promptly notify the party against which indemnification is sought ("Indemnifying Party") upon becoming aware of any claim for which indemnification is sought and will: (a) provide reasonable cooperation to the Indemnifying Party, at the Indemnifying Party's expense, in connection with the defense or settlement of any such claim and (b) be entitled to participate at its own expense in the defense of any such claim. The Indemnifying Party will have sole and exclusive control over the defense and settlement of any such third-party claim, except that the Indemnifying Party shall not, without the Indemnified Party's written consent, submit to any judgment orenter into any settlement that adversely affects the Indemnified Party's rights or interests.

12. Reseller Relationship

(a)

If Customer purchases access to the Platform from a Reseller, Customer acknowledges that SciFin does not control the actions of the Reseller, and Customer hereby expressly disclaims and releases SciFin from any and all liability whatsoever for any controversies, claims, suits, injuries, loss, harm or damages arising from or related to disputes, dealings, or interactions between Customer and the Reseller.

(b)

Customer expressly waives and releasesany and all rights and benefits under Section 1542 of the California Civil Code (or any analogous law of any other state or jurisdiction), which reads as follows:

A GENERAL RELEASE DOES NOT EXTEND TO CLAIMS THAT THE CREDITOR OR RELEASING PARTY DOES NOT KNOW OR SUSPECT TO EXIST IN HIS OR HER FAVOR AT THE TIME OF EXECUTING THE RELEASE AND THAT, IF KNOWN BY HIM OR HER, WOULD HAVE MATERIALLY AFFECTED HIS OR HER SETTLEMENT WITH THE DEBTOR OR RELEASED PARTY.

13. Non-Solicitation

(a)

During the Term and for a period of twelve (12) months following expiration or termination of this Agreement (the "Restricted Period"), each party agrees that it will not, directly or indirectly, solicit for employment or engagement, or hire, any employee or independent contractor of the other party without the prior written consent of the other party.

(b)

The restrictionin Section 13(a)shall not apply to (a) general solicitations or advertisements not specifically targeted at the other party's personnel, including job postings on public job boards or through third-party recruiters acting without specific direction to target such personnel; or (b) any individual who has ceased to be employed by or engaged with the other party for a period of at least three (3) months prior to any such solicitation or hiring.

(c)

Each party acknowledges that a breach of this Section 13 would cause irreparable harm to the other party for which monetary damages would be an inadequate remedy, and that the non-breaching party shall be entitled to seek injunctive or other equitable relief in addition to any other remedies available at law or in equity.

14. Limitation of Liability

EXCEPT FOR LIABILITIES RELATING TO INDEMNIFICATION OBLIGATIONS, FRAUD, GROSS NEGLIGENCE, WILLFUL MISCONDUCT, AND VIOLATIONS OF SECTION 6 (CONFIDENTIALITY), (A) IN NO EVENT WILL EITHER PARTY BE LIABLE TO THE OTHER PARTY FOR ANY SPECIAL, INDIRECT, INCIDENTAL OR CONSEQUENTIAL DAMAGES (INCLUDING WITHOUT LIMITATION LOSS OF USE, BUSINESS OR PROFITS, OR COSTS OF COVER) ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT, AND (B) EACH PARTY'S CUMULATIVE LIABILITY TO THE OTHER PARTY WILL NOT EXCEED THE FEES PAID BY CUSTOMER TO SCIFIN DURING THE 12-MONTH PERIOD PRECEDING THE CLAIM.

15. General

(a)

No Agency. Nothing in this Agreement creates an agency, franchise, joint venture, employment relationship, or partnership between the parties. The parties are and will remain independent contractors. Neither party has the authority to bind the other or to incur any liability or otherwise act on behalf of the other. Each party shall ensure the timely disposition ofall of its employee matters in connection with its organization, including employee benefits, insurance, withholdings, taxes, and similar employee-related matters.

(b)

Severability. If any provision of this Agreement is held invalid, illegal, or unenforceable, such invalid, illegal, or unenforceable provision will be modified, if possible, to the minimum extent necessary to make it valid and enforceable, or if it cannot be so modified, then severed, and the remaining provisions contained herein will not in any way be affected or impaired.

(c)

Waiver. Neither party's failure to enforce strict performance of any provision of this Agreement will constitute a waiver of a right to subsequently enforce such provision, and no waiver of one obligation or condition will constitute a waiver of another obligation or condition. No waiver of this Agreement will be valid unless made in writing and signed by an authorized representative of the party providing the waiver.

(d)

Remedies. Except as otherwise stated herein, the remedies under this Agreement are intended to be cumulative and not exclusive.

(e)

Assignment. Either party may assign this Agreement, by operation of law or otherwise, without consent, to its successor in a merger or acquisition of all or substantiallyall of its assets, equity, or business to which this Agreement relates. Otherwise, assignment of this Agreement is prohibited without the consent of the other party.

(f)

Survival. The provisions of Sections 2, 4(c), 5 (except for the license grant in Section 5(c)), 6,7,8, 10, 11, 12, 13, 14, and 15 will survive any termination or expiration of this Agreement.

(g)

Entire Agreement; Amendment. This Agreement and the Order Form(s) constitute the entire agreement between the parties concerning the subject matter hereof and supersedes all written or oral prior agreements or understandings with respect thereto. This Agreement may not be amended except in a writing signed by authorized representatives of both parties.

(h)

Notice. Each party shall send any official notice given pursuant to this Agreement to the other party at the address stated in the Order Form by: (a) certified mail return receipt requested, (b) overnight courier, or (c) confirmed electronic mail.

(i)

Force Majeure. Neither party will be liable for any delays or failures of performance hereunder, except for payments, to the extent that performance of such party's obligations or attempts to cure any breach under this Agreement are delayed orprevented as a result of acts of God, labor disputes or other industrial disturbances, systemic electrical, telecommunications, or other utility failures, fires, floods, earthquake, storms or other elements of nature, blockages, embargoes, riots, acts of terrorism or war, acts of government, civil unrest, or any other similar event or circumstance beyond its reasonable control ("Force Majeure Event"), except that the other party may terminate this Agreement upon written notice if the Force Majeure Event continues for more than 30 days.

(j)

Dispute Resolution. The parties agree to resolve any dispute, claim or controversy arising out of or relating to this Agreement according to the terms of this section. First, the parties agree to attempt in good faith to resolve the dispute through informal resolution. Second, if the dispute is not resolved through informal resolution, the parties agree to participate in binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules in Santa Clara County, California. The parties agree that, in the event of arbitration (or in the event of a lawsuit if this arbitration clause is deemed invalid or does not apply to a given dispute) the prevailing party shall be entitled to costs and fees (including reasonable attorneys' fees). Either party may bring a lawsuit solely for injunctive relief without first engaging in the dispute resolution process described in this section. In the event that the dispute resolution procedures in this section are found not to apply to a given claim, or in the event of a claim for injunctive relief as specified in the previous sentence, the parties agree that any judicial proceeding will be brought in the state or federal courts in Santa Clara County, California. Both parties consent to venue and personal jurisdiction there.

(k)

Governing Law. The validity, interpretation, construction and performance of this Agreement, and all acts and transactions pursuant hereto and the rights and obligations of the parties hereto shall be governed, construed and interpreted in accordance with the laws of the State of California, without giving effect to principles of conflicts of law.

Exhibit A - Data Processing Addendum

This Data Processing Addendum (this "DPA") is between SciFin Inc., a Delaware corporation ("SciFin") and the customer identified in the Order Form ("Customer") and is effective as of the effective date of the Master Services Agreement between Customer and SciFin (the "Service Agreement"). Customer and SciFin may be referred to herein together as the "Parties", and each may be referred to herein as a "Party". This DPA is subject to, and incorporated into, the Service Agreement. However, in the event of a conflict between the terms of this DPA and the terms of the Service Agreement, the terms of this DPA shallcontrol. Any capitalized terms not defined in this DPA have the meaning assigned to them in the Service Agreement. For good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, Customer and SciFin hereby agree as follows:

1. Definitions

(a)

"Applicable Laws". means, collectively, all now existing or hereinafter enacted or amended Data Protection Laws applicable to a Party's performance under this DPA.

(b)

"CCPA". means the California Consumer Privacy Act of 2018 (Title 1.81.5 of the Civil Code of the State of California), together with all effective regulations adopted thereunder (in each case, as amended from time to time).

(c)

"Customer Data". means all information, data, content and other materials, in any form or medium, that is submitted, posted, collected, transmitted or otherwise provided by or on behalf of Customer through the Services.

(d)

"Customer Personal Data". means Customer Data that is Personal Data processed by SciFin on behalf of Customer in the provision of the Services under the Service Agreement.

(e)

"Controller". means (i) under and in the context of CCPA, the "business" or "third party" (each, as defined by CCPA), and (ii) under and in the context of any other privacy or data protection law, rule, or regulation applicable to a Party's performance hereunder, a "controller", "business", or corresponding term denoting a substantially similar definition, role, and obligations under such law, rule or regulation.

(f)

"Data Protection Laws". means any laws, statutes, declarations, decrees, directives, legislative enactments, orders, ordinances, regulations, rules, or other binding restrictions (including any amendments or successors thereto) pertaining to data protection, privacy, security, and/or the processing of Personal Data, including, without limitation, the CCPA and other US state privacy laws.

(g)

"Personal Data". means any information that constitutes "personal data," "personal information," or other term denoting a substantially similar definition and obligations under, and in the context of, any other Applicable Laws.

(h)

"Process". means any operation or set of computer operations performed on Personal Data, including, but not limited to, collection, recording, organization, structuring, storage, access, adaptation, alteration, retrieval, consultation, use, transfer, transmit, sale, rental, disclosure, dissemination, making available, alignment, combination, deletion, erasure, or destruction.

(i)

"Processor". means (i) under and in the context of CCPA, a "service provider" (as definedby CCPA), and (ii) under and in the context of any other Applicable Law, a "processor", "service provider", or corresponding term denoting a substantially similar definition, role, and obligations under such law, rule or regulation.

(j)

"Security Incident". means (i) any accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to, Customer Personal Data or (ii) any other event that constitutes a "security breach", "personal data breach", or substantially similar term with respect to Customer Personal Data under an Applicable Laws.

(k)

"Services". means, collectively, the products and/or services provided by SciFin to Customer under the Service Agreement.

(l)

"Sub-Processor". means a contractor, subcontractor, consultant, third-party service provider, or agent engaged by SciFin for further Processing of Customer Personal Data.

2. Data Processing Obligations

(a)

General.

(i)

Each Party shall comply with its obligations relating to Personal Data under this DPA and under Applicable Laws at its own cost. With respect to Customer Personal Data, (i) Customer is a Controller and (ii)SciFin is a Processor that Processes Customer Personal Data only upon the instructions of Customer, including, without limitation, in accordance with the Service Agreement, this DPA, and any other documented instructions provided by Customer. Notwithstanding the foregoing,SciFin may Process Customer Personal Data as required by Applicable Laws. Schedule I sets forth specific details regarding SciFin's processing of Customer Personal Data.

(ii)

With regard to SciFin employees and contractors engaged in Processing Customer Personal Data,SciFinshall ensure that such employees and contractors are informed of the confidential nature of the Customer Personal Data and are subject to appropriate confidentiality obligations sufficient to comply with the terms of the Service Agreement and this DPA.

(iii)

Customer will have sole responsibility for the accuracy, quality, and legality of Customer Personal Data andthe means by which Customer obtains the Customer Personal Data, including, without limitation, obtaining appropriate consent to collect the Customer Personal Data and share such data with SciFin in accordance with Applicable Laws.

(b)

CCPA. With respect to Customer Personal Data relating to a California "consumer" or "household" (each as defined by CCPA) ("CCPA Personal Data"):

(i)

Customer will be disclosing such CCPA Personal Data under the Service Agreement to SciFin for a "business purpose" (as defined by CCPA), and SciFin shall Process such CCPA Personal Data solely on behalf of Customer and only as necessary to perform such business purpose for Customer; and

(ii)

Except as expressly permitted by the CCPA or its regulations,SciFin shall not: (i) "sell" or "share" (each as defined by the CCPA) CCPA Personal Data; (ii) retain, use, or disclose CCPA Personal Data (x) for any purpose (including a "commercial purpose" (as defined by CCPA)) other than for the business purpose(s) identified in Section 2.2(a), or (y) outside of the direct business relationship between SciFin and Customer; or (iii) combine the Customer Personal Data with Personal Data that SciFin collects or receives from another source (except in the performance of any "business purpose").

(c)

Changes in Applicable Laws. If, due to any change in Applicable Laws, a Party reasonably believes that (a)SciFin ceases to be able to provide the Services in whole or in part (e.g., with respect to a particular jurisdiction) and/or Customer ceases to be able to use the Services in whole or in part under the then-current terms and conditions of the Service Agreement and this DPA, each Party may terminate the Service Agreement (in whole or, if reasonably practicable, in part).

3. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons,SciFin will implement and maintain appropriate technical and organizational measures to ensure a level of security for the Customer Personal Data appropriate to the risks. In assessing the appropriate level of security, account shall be takenin particular of the risks that are presented by Processing,in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored or otherwise processed. Such measures will include reasonable administrative, physical, and technical security controls (including those required by Applicable Laws) that prevent the collection, use, disclosure, or access to Customer Personal Data that the Service Agreement does not expressly authorize, including maintaining a comprehensive information security program that safeguards Customer Personal Data. These security measures include the measures set forth in Schedule II.

4. Supplementary Measures and Safeguards

(a)

Assistance. SciFin shall assist Customer to ensure compliance with Applicable Laws in connection with the Processing of Customer Personal Data.

(b)

Orders. SciFin shall notify Customer in writing of any subpoena or other judicial or administrative order by a government authority or proceeding seeking access to or disclosure of Customer Personal Data. Customer shall have the right to defend such action in lieu of and/or on behalf of SciFin. Customer may, if it so chooses, seek a protective order. SciFin shall reasonably cooperate with Customer in such defense.

5. Notifications

(a)

Security Incidents. SciFin has and will maintain a security incident response plan that includes procedures to be followed in the event of a Security Incident. SciFin will provide Customer with written notice promptly after discovering a Security Incident (including those affecting SciFin or its Sub-Processors), including any known information that Customer is required by Applicable Laws to provide to an applicable regulatory agency or to the individuals whose Personal Data was involved in the Security Incident.

(b)

Data Subject Requests. SciFin shall (i) promptly notify Customer about any request under Applicable Law(s) with respect to Customer Personal Data received from or on behalf of the applicable data subject and (ii)cooperate as required by Applicable Law(s) with Customer's reasonable requests in connection with data subject requests with respect to Customer Personal Data. SciFin shall assist Customer, through appropriate technical and organizational measures, to fulfill its obligations with respect to requests of data subjects seeking to exercise rights under Applicable Law with respect to Customer Personal Data.

6. Sub-Processors

(a)

SciFin shall not have Customer Personal Data Processed by a Sub-Processor unless such Sub-Processor is bound by a written agreement with SciFin that includes data protection obligations at least as protective as those contained in this DPA and the Service Agreement and that meet the requirements of Applicable Laws. SciFin is and shall remain fully liable to Customer for any failure by any Sub-Processor to fulfill SciFin's data protection obligations under Applicable Laws.

(b)

SciFin's list of all Sub-Processors who access Customer Personal Data is available at Schedule III (the "Sub-Processor List"). Customer authorizes and instructs SciFin to engage the Sub-Processors listed in the Sub-Processor List. SciFin will notify Customer of any changes to the Sub-Processors listed on the Sub-Processor List and grant Customer the opportunity to object to such change. Upon Customer's request,SciFin will provide all information necessary to demonstrate that the Sub-Processors will meet all requirements pursuant to Section 6.1. If Customer objects to any Sub-Processor,SciFin can choose to either not engage the Sub-Processor or to terminate the Service Agreement with thirty (30) days' prior written notice.

7. Deletion

SciFin shall, at the choice of Customer: (i) delete or return all Customer Data to Customer after such Customer Data is no longer necessary for the provision of the Services, and (ii) delete existing copies of such Customer Data.

8. Documentation; Audit

SciFin shall, upon Customer's request, provide Customer (a) comprehensive documentation of SciFin's technical and organizational security measures, (b) any and all third-party audits and certifications available with respect to such security measures, and (c) all other information reasonably necessary to demonstrate compliance with the SciFin's obligations under this DPA and/or under Applicable Laws. Where (a) - (c) of this section are not sufficient for compliance with Applicable Laws, then upon reasonable notice and appropriate confidentiality agreements,SciFin shall cooperate with assessments, audits, or other steps performed by or on behalf of Customer at Customer's sole expense and in a manner that is minimally disruptive to SciFin's business that are necessary to confirm that SciFin is processing Customer Personal Data in a manner consistent with this DPA.

9. Term; Termination

This DPA shall remain in effect until (a) the Service Agreement has terminated and (b) all obligations that SciFin has under the Service Agreement and under Applicable Laws with respect to Customer Personal Data, and all rights that Customer has under the Service Agreement and under Applicable Laws with respect to Customer Personal Data, have terminated. Notwithstanding termination of this DPA, any provisions hereof that by their nature are intended to survive, shall survive termination.

10. Limitation of Liability

THE LIMITATIONS OF LIABILITY SET FORTH IN THE SERVICE AGREEMENT APPLY TO THIS DPA.

11. Miscellaneous

(a)

This DPA shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Service Agreement, unless required otherwise by Applicable Laws.

(b)

Neither Party may assign or transfer any part of this DPA without the written consent of the other Party;provided,however, that this DPA, collectively with the Service Agreement, may be assigned without the other Party's written consent by either Party to a person or entity who acquires, by sale, merger or otherwise, all or substantially all of such assigning Party's assets, stockor business. Subject to the foregoing, this DPA shall bind andinure to the benefit of the Parties, their respective successors and permitted assigns. Any attempted assignment in violation ofthis Section 11.2 shall be void and of no effect.

Schedule I - Details of Customer Personal Data

Nature and Purpose of Processing

To provide the Services pursuant to the Service Agreement.

Categories of Personal Data Subject to Processing

Any Personal Data that Customer chooses to include within the Customer Data.

Categories of Data Subjects Whose Personal Data is Transferred

Those Data Subjects whose Personal Data is included within the Customer Data.

Frequency of transfer

Continuous basis for the duration of the Services pursuant to the Service Agreement.

Duration of Processing

For the duration of the Services pursuant to the Service Agreement.

Period for which Personal Data will be retained

As long as necessary to provide the Services pursuant to the Service Agreement.

Schedule II - Security Measures

SciFin maintains an information security program aligned to ISO/IEC 27001:2022 and has completed SOC 2 Type I and Type II examinations (Security, Availability, Confidentiality). SciFin's security measures include the following:

Pseudonymization and encryption: Encryption in transit (TLS) and at rest (AES-256), with keys held in a managed key management service. Pseudonymization and anonymization techniques applied where identifiers are not required.
Confidentiality, integrity, availability and resilience: Production hosted on Google Cloud Platform in logically isolated private networks, with no direct public exposure, default-deny firewall rules, and multi-zone redundancy.
Restoring availability and access after an incident: Automated backups at least every 24 hours, encrypted and stored redundantly across zones. Restoration tested at least annually. Documented business continuity and disaster recovery plan, exercised at least annually.
Testing and evaluating effectiveness: Annual risk assessments, annual independent penetration testing, and vulnerability scanning. Findings remediated on a risk-prioritized basis. Internal audits conducted at least annually.
User identification and authorization: Role-based access on a least-privilege basis, unique user accounts, and multi-factor authentication for privileged, remote, and production access. Accounts lock after five failed attempts. Access reviewed periodically and revoked promptly on termination.
Protection during transmission: Customer Personal Data transmitted over public networks is encrypted using TLS. Remote access requires encrypted channels and multi-factor authentication.
Protection during storage: Data at rest encrypted as above. Endpoint protection with real-time malware scanning and automatic signature updates. Full-disk encryption on endpoints; removable media use restricted.
Physical security: Customer Personal Data is processed in Google Cloud Platform data centers.

Schedule III - List of Subprocessors

The controller has authorized the use of the following sub-processors:

Sub-Processor Name
Sub-Processor Category
Jira
Saas Software
Meltano
Infrastructure
Salesforce
Marketing & Sales
Zeni
Finance
Rippling
Human Resources
Temporal
Infrastructure
Open AI
Saas Software
Mongodb
Infrastructure
Kitecyber
Security
Google Cloud
Infrastructure
GitHub
Infrastructure
Monday.com
Saas Software
Atlassian / Jira
Saas Software
Google Workspace
Saas Software
OneLogin
Infrastructure
Scrut Automation
Security