Data Processing Addendum

Effective Date: July 2026
Last Updated: July 2026
This document reflects our standard data processing terms. Executed agreements with individual clients govern in the event of any conflict.

1. Roles & Scope

This Data Processing Addendum ("DPA") establishes the terms under which LORIQ Technologies, LLC ("Processor") processes Personal Data on behalf of the Customer ("Controller"). It applies when LORIQ acts as a data processor subject to applicable data protection laws.

2. Processing Instructions

LORIQ will process Personal Data only in accordance with Customer's documented instructions, which include processing to provide the services as defined in the primary agreement.

3. Confidentiality & Security Measures

LORIQ ensures that personnel authorized to process Personal Data have committed themselves to confidentiality. LORIQ implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

4. Subprocessors

Customer provides general authorization for LORIQ to engage Subprocessors. LORIQ will impose data protection obligations on Subprocessors that are substantially the same as those set out in this DPA.

5. Data Subject Requests

LORIQ will provide reasonable assistance to the Customer in fulfilling its obligation to respond to requests for exercising data subjects' rights (such as access, deletion, or rectification).

6. Incident Notification

In the event of a confirmed Personal Data Breach, LORIQ will notify the Customer without undue delay and provide reasonable assistance in investigating and mitigating the incident.

7. Deletion & Return

Upon termination of the services, LORIQ will, at the Customer's choice, delete or return all Personal Data, unless applicable law requires continued storage.

8. Audits & Compliance

LORIQ will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits conducted by the Customer or an independent auditor.

9. International Transfers

Any transfer of Personal Data originating from the EEA, UK, or Switzerland to countries lacking an adequacy decision will be governed by the applicable Standard Contractual Clauses (SCCs).

Exhibits

Exhibit A: Processing Details

The categories of Personal Data processed, the categories of data subjects, the nature and purpose of processing, and the duration of processing are specified for each Customer during enterprise onboarding and documented in the applicable order form or statement of work. Absent such documentation, LORIQ processes only the Personal Data submitted by the Customer through the services, solely for the purpose of providing those services, and for the duration of the primary agreement.

Exhibit B: Security Measures

LORIQ maintains technical and organizational security measures that include: encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256); role-based access controls with least-privilege provisioning; multi-factor authentication for administrative access; network segmentation and firewall protection; centralized logging and monitoring; regular vulnerability management; and documented incident response procedures. A current, detailed description of these measures is available to Customers upon request.

Exhibit C: Subprocessor List

LORIQ engages a limited set of infrastructure and service providers (such as cloud hosting and email delivery providers) to support delivery of the services. A current list of subprocessors is available to Customers upon written request to info@loriqtechnologies.com. LORIQ will provide notice of new subprocessors in accordance with Section 4 of this DPA.

Contact Information

For questions regarding this policy, please contact us at:

LORIQ Technologies, LLC