LeaderCoreAI

LeaderCoreAI Data Processing Agreement

Data Processing Agreement (B2B)

Version 2.5 – Effective on publication (subject to Clause 14.2 notice for material changes)

What's new in this version:

  • Added Namecheap, Inc. (Private Email) as an authorised Sub-processor for leadercore.ai email delivery, with the Google Workspace role narrowed accordingly (Annex 3).
  • Clarified that AI processing of conversation inputs takes place within the EEA (Google Cloud europe-central2 and the EU multi-region), and disclosed the short-lived context-caching of conversation turns used to improve performance (Annexes 1 and 3).
  • Clarified the data location for Firebase Authentication: account-level authentication data is processed on Google's global infrastructure under the Google Cloud DPA and EU Standard Contractual Clauses, separately from the EEA-resident database, compute and file-storage services (Annex 3).
  • Disclosed consent-gated Reseller analytics access — a pseudonymised, aggregated cohort view a Customer may choose to share with its Reseller (Annex 3) — and added read-only HR analytics viewers to the categories of data subjects (Annex 1).
  • Disclosed AI usage / token telemetry held in the analytics warehouse in pseudonymised form (Annexes 1 and 3).
  • Stated the GDPR/UK GDPR standard as a self-sufficient baseline that governs all Customer processing, with country-specific addenda supplementing (not replacing) it (new Clause 1.7).
  • Clarified that whether a country-specific addendum applies is determined by the Customer's establishment and governing data protection law as Controller — not by the location, residence or nationality of individual users (Clauses 1.6 and 8.3).
  • Added that the Customer, as Controller, is responsible for identifying and instructing Vendor on any law applicable to its processing beyond the baseline (new Clause 4.4).

Part of: LeaderCoreAI Platform Terms (Flow-Through for Indirect Sales – B2B Only)

Blue Horizon Training S.R.L.

1. Parties and Scope

1.1 Parties

This Data Processing Agreement ("DPA") is between: Blue Horizon Training S.R.L., Intrarea Biserica Albă 3, Ap. 6, 010298, Bucharest, Romania, CUI RO43434054 ("Vendor" or "Processor"); and the business entity identified as Customer in the relevant order form or subscription arrangement, whether concluded with Vendor or with an authorised reseller ("Customer" or "Controller").

1.2 Incorporation

This DPA forms part of: the LeaderCoreAI Platform Terms (Flow-Through for Indirect Sales – B2B Only), and any commercial agreement or order under which Customer acquires subscriptions to the LeaderCoreAI Platform, whether such order is concluded with Vendor directly or via an authorised reseller ("Reseller").

1.3 Indirect Sales

Where Customer purchases via a Reseller, this DPA is a separate and direct agreement between Vendor (as Processor) and Customer (as Controller) for the processing of personal data in connection with Customer's use of the Platform. Reseller is not a party to this DPA, but remains responsible for its own processing activities as described in Customer's agreement with the Reseller.

1.4 Role of the Parties

For the Processing of Personal Data described in this DPA, Customer is the Controller, Vendor is the Processor, and Vendor may engage Sub-processors as set out herein.

1.5 Precedence

In case of conflict between this DPA and other terms between the parties regarding data protection, this DPA prevails to the extent of the conflict.

1.6 Country-Specific Addenda

Where Customer, in its capacity as Controller, is established in or otherwise subject to a data protection law that imposes requirements beyond or different from the GDPR in respect of its processing under this DPA, Vendor may make available country-specific addenda. The following country-specific addenda are hereby incorporated into this DPA and apply automatically, without further action by either party, to the extent their respective scope conditions are met:

  • (a) UK Data Protection Addendum, available at https://leadercore.ai/legal/uk-dpa-addendum, which applies whenever and to the extent that Customer's processing under this DPA is subject to UK Data Protection Laws (as defined in that Addendum). Whether that Addendum applies is determined by reference to Customer's establishment and the data protection law governing Customer's processing as Controller, and not by the location, residence or nationality of individual data subjects.

Vendor may add further country-specific addenda from time to time in accordance with Clause 14.2 (Amendments), by publishing them at a URL referenced in this Clause 1.6 or otherwise notifying Customer. Where a country-specific addendum is incorporated under this Clause 1.6, it forms part of this DPA, and in case of conflict with this DPA regarding the processing of Personal Data covered by that addendum, the addendum prevails.

1.7 Baseline Data Protection Standard

This DPA constitutes a complete and self-sufficient set of data protection terms that governs all processing of Customer Data, regardless of Customer's location or the location of any data subject. Vendor's obligations under this DPA are designed to meet the requirements of the GDPR and the UK GDPR, which Vendor applies as its baseline standard for all Customer Data. Any country-specific addendum incorporated under Clause 1.6 supplements, and does not replace, this baseline standard, and adds only the additional or different requirements of the relevant jurisdiction. Where no country-specific addendum applies to a particular Customer, this DPA nonetheless governs that Customer's processing in full on the basis of this baseline standard.

2. Definitions

Terms used in this DPA have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), in the Platform Terms, or as defined below:

  • "Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
  • "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" and "Personal Data Breach" have the meanings given in the GDPR.
  • "Platform" means the LeaderCoreAI AI-powered leadership simulation platform as defined in the Platform Terms.
  • "Customer Data" means Personal Data for which Customer is Controller and which Vendor processes on Customer's behalf in providing the Platform.
  • "Sub-processor" means another processor engaged by Vendor to process Customer Data.
  • "Applicable Data Protection Law" means the GDPR, and any other data protection or privacy law that applies to the processing of Customer Data under this DPA, including where applicable through a country-specific addendum (e.g., the UK GDPR and Data Protection Act 2018).

3. Subject Matter, Duration, Nature and Purpose of Processing

3.1 Subject Matter

Vendor processes Customer Data solely to provide the Platform, related services and support to Customer in accordance with the Platform Terms and this DPA.

3.2 Duration

This DPA applies for as long as Vendor processes Customer Data on behalf of Customer under any active Subscription Term and during subsequent deletion/anonymisation periods described in the Platform Terms.

3.3 Nature and Purpose

The Processing includes collection, storage, organisation, retrieval, use, analysis, transmission, display and deletion, as necessary to:

  • register and authenticate users;
  • run training simulations and capture user responses;
  • generate scores, feedback and reports;
  • provide dashboards and analytics to authorised HR/Admin users;
  • maintain security, monitor misuse, perform troubleshooting and quality improvements (in aggregated/pseudonymised form); and
  • comply with applicable legal obligations.

3.4 Type of Personal Data and Categories of Data Subjects

Typical categories are described in Annex 1 and align with the Platform Terms (Clause 10).

3.5 Retention

Retention periods and deletion/anonymisation practices follow the schedule set out in the Platform Terms (currently Clause 10.3), as updated from time to time, and are deemed incorporated into this DPA.

4. Controller's Instructions

4.1

Vendor shall process Customer Data only on documented instructions from Customer, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by EU or Member State law (or other Applicable Data Protection Law). In that case, Vendor shall inform Customer of that legal requirement before processing, unless the law prohibits such information.

4.2

The Platform Terms, this DPA (together with any applicable country-specific addendum) and Customer's documented configuration and use of the Platform constitute Customer's complete and final instructions to Vendor.

4.3

If Vendor reasonably believes an instruction infringes the GDPR or other Applicable Data Protection Law, Vendor will inform Customer without undue delay and may suspend the relevant processing until Customer confirms or modifies the instruction.

4.4 Customer's Responsibility for Applicable Law

As between the parties, Customer, as Controller, is responsible for identifying and informing Vendor of any data protection or other law applicable to Customer's processing under this DPA that imposes requirements beyond the baseline standard in Clause 1.7 (for example, requirements arising from Customer's own establishment, operations or activities). Vendor processes Customer Data to that baseline standard and to any country-specific addendum applicable under Clause 1.6, and will provide reasonable assistance in relation to additional requirements that Customer identifies and documents as an instruction under Clause 4.1. Vendor is not required to determine the location, residence or nationality of individual data subjects; the applicability of any country-specific addendum is determined as set out in Clause 1.6.

5. Confidentiality and Personnel

5.1

Vendor shall ensure that persons authorised to process Customer Data are subject to appropriate confidentiality obligations (whether contractual or statutory).

5.2

Vendor shall ensure that such personnel only access Customer Data to the extent necessary to perform their role in providing the Platform.

6. Security of Processing

6.1

Vendor shall implement and maintain appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as required by Article 32 GDPR (and equivalent provisions of any other Applicable Data Protection Law).

6.2

These measures include, where appropriate, measures relating to:

  • access control and authentication;
  • encryption in transit and at rest (where reasonably feasible);
  • network and application security;
  • logging and monitoring of security-relevant events;
  • regular backup and recovery procedures;
  • secure development and change-management practices; and
  • incident response and business continuity processes.

6.3

A summary of the technical and organisational measures is set out in Annex 2. Customer is responsible for reviewing this summary and determining whether it satisfies Customer's own security requirements.

7. Sub-processors

7.1

Customer authorises Vendor to appoint Sub-processors for the purposes described in this DPA, subject to the conditions below.

7.2

Vendor shall:

  • ensure that Sub-processors are bound by written agreements imposing obligations that are no less protective of Customer Data than this DPA; and
  • remain responsible to Customer for the performance of each Sub-processor's obligations.

7.3

Vendor shall maintain a list of current Sub-processors and their relevant processing locations in Annex 3 (or at a URL referenced in Annex 3). Vendor may update this list from time to time.

7.4

Vendor shall provide notice (e.g. via email or posting on a Sub-processor list URL) of any intended addition or replacement of Sub-processors, giving Customer at least 14 days to object. Customer may object on reasonable grounds relating to data protection; in that case the parties will discuss in good faith. If no mutually acceptable solution is found, Customer may, as a sole and exclusive remedy, terminate the affected subscription(s) by written notice, with a pro-rated refund for any prepaid unused Subscription Term.

8. International Transfers

8.1

Vendor shall process Customer Data within the European Economic Area (EEA) or other countries recognised by the European Commission as providing an adequate level of protection, except as necessary to use authorised Sub-processors.

8.2

Where Customer Data is transferred to a country without an adequacy decision, Vendor shall ensure that appropriate safeguards under Article 46 GDPR are in place, such as:

  • EU Standard Contractual Clauses (controller-to-processor) between Customer and Vendor or between Vendor and its Sub-processors; and/or
  • other mechanisms permitted by Applicable Data Protection Law.

8.3

Where Customer's processing under this DPA is subject to non-EU data protection laws that impose separate transfer requirements (e.g., the UK GDPR) under Clause 1.6, the applicable country-specific addendum shall specify the transfer mechanisms for that jurisdiction.

8.4

Upon Customer's reasonable request, Vendor will provide information about the applicable transfer mechanism for specific Sub-processors listed in Annex 3.

9. Assistance to Customer

9.1 Data Subject Requests

Taking into account the nature of the Processing, Vendor shall assist Customer, by appropriate technical and organisational measures and where reasonably possible, in responding to Data Subjects' requests to exercise their rights under Chapter III GDPR (and equivalent provisions of any other Applicable Data Protection Law), including access, rectification, erasure, restriction, portability and objection.

  • If a Data Subject contacts Vendor directly with such a request, Vendor will, where it can identify the Customer concerned, forward the request to Customer without undue delay.
  • Vendor shall not respond directly on Customer's behalf unless authorised or legally required to do so.

9.2 Compliance and Impact Assessments

Taking into account the nature of Processing and the information available to Vendor, Vendor shall provide reasonable assistance to Customer in:

  • ensuring compliance with the obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation) and equivalent provisions of any other Applicable Data Protection Law, and
  • responding to inquiries or inspections by Supervisory Authorities relating to the Processing covered by this DPA.

9.3

Vendor may charge a reasonable fee for assistance under this Clause 9 if requests are manifestly unfounded, excessive or repetitive, or if they require effort beyond what is customary for comparable B2B SaaS services.

10. Personal Data Breach Notification

10.1

Vendor shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach involving Customer Data.

10.2

Such notice shall include, to the extent reasonably available:

  • a description of the nature of the Personal Data Breach;
  • categories and approximate number of Data Subjects and data records concerned;
  • likely consequences of the breach; and
  • measures taken or proposed by Vendor to address the breach and to mitigate possible adverse effects.

10.3

Customer is responsible for fulfilling any legal notification obligations to Supervisory Authorities and Data Subjects, unless Applicable Data Protection Law expressly requires Vendor to do so.

11. Return and Deletion of Data

11.1

At the end of the relevant Subscription Term (or upon earlier termination in accordance with the Platform Terms), Vendor shall delete or anonymise Customer Data in accordance with the retention schedule in the Platform Terms, unless EU or Member State law (or other Applicable Data Protection Law) requires storage of certain data.

11.2

During the active Subscription Term, Customer may export or request export of certain data via in-product features or reasonable assistance from Vendor, as described in the Platform Terms.

11.3

Upon Customer's written request within the applicable retention period, Vendor shall confirm deletion or anonymisation of Customer Data processed as Processor, subject to any legal obligations to retain data.

12. Audit Rights

12.1

Vendor shall provide Customer with all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR (and equivalent provisions of any other Applicable Data Protection Law), including:

  • responses to security and compliance questionnaires;
  • copies of relevant third-party certifications or audit reports (e.g. ISO, SOC), if available; or
  • high-level descriptions of its controls and procedures.

12.2 Audit and Information Rights

  • (a) Vendor will make available to Customer, upon reasonable request, information necessary to demonstrate compliance with this DPA and Article 28 GDPR, for example by providing written descriptions of its technical and organisational measures, responses to security/privacy questionnaires, or relevant third-party audit reports or certifications (if available).
  • (b) If, after reviewing such information, Customer still reasonably considers that it needs an audit, Vendor shall allow and reasonably cooperate with an audit of the processing activities covered by this DPA to the extent required by Article 28(3)(h) GDPR. Any such audit shall:
    • – be subject to at least 30 days' prior written notice;
    • – be carried out during normal business hours;
    • – be limited in scope to what is necessary to verify compliance with this DPA; and
    • – be subject to appropriate confidentiality undertakings.
  • (c) Customer is responsible for its own audit costs. Vendor may charge a reasonable fee for time spent by its personnel on audits, particularly where audits are requested more than once in any 12-month period, unless an additional audit is required by a Supervisory Authority.

13. Liability and Limitation

13.1

The limitations of liability in the Platform Terms and any applicable commercial agreement between the parties apply to this DPA and all claims arising from or in connection with it, to the maximum extent permitted by law.

13.2

Nothing in this DPA excludes or limits liability where such exclusion or limitation is not allowed under Applicable Data Protection Law or other applicable law.

14. Miscellaneous

14.1 Governing Law and Jurisdiction

This DPA is governed by Romanian law and subject to the exclusive jurisdiction of the courts of Bucharest, without prejudice to mandatory provisions of Applicable Data Protection Law (including the rights of data subjects and Supervisory Authorities under such law).

14.2 Amendments

Vendor may update this DPA, and may add or update country-specific addenda under Clause 1.6, to reflect changes in law or industry practice. Updates that increase only Vendor's obligations as Processor, or that are required to comply with applicable law, take effect on publication. Other material updates affecting Customer's data protection rights or Vendor's data protection obligations will be communicated via the Platform Terms URL or by other reasonable means at least 30 days before taking effect. If Customer objects to such a material update, Customer may terminate the affected subscription(s) by written notice within that 30-day period, with a pro-rated refund for any prepaid unused Subscription Term. If Customer does not object within that period, the updated DPA shall apply.

14.3 Severability

If any provision of this DPA is held invalid, the remaining provisions remain in effect.

Annex 1 – Description of Processing

Categories of Data Subjects

  • Employees, contractors and other authorised users of Customer and its affiliates who access the Platform (including HR/Admin users and read-only HR analytics viewers ("hrViewer")).
  • Reseller staff only to the extent they use the Platform as users of a Customer tenant.

Types of Personal Data

  • Identification data: name, business email address, role/department, organisation, country.
  • Account data: username, authentication data (hashed passwords if stored by Vendor, access tokens), subscription key used, seat allocations, last login time.
  • Simulation interaction data: free-text responses, selections, scenario choices, timestamps, scores, grading outputs and feedback texts.
  • Certificate records: name as it appeared at time of issuance, certificate type (scenario completion or scenario mastery, or collection-level equivalent), scenario name(s), score(s), difficulty, collection name, product name, date of award. Stored in the userCertificates collection with permanent retention to support third-party verification of attainment, surviving end of Subscription Term and account deletion. On a verified Article 17 erasure request, Vendor redacts the data subject's name on the certificate record (replacing it with a tombstone value) while preserving the certificate's verifiable metadata. The public verification endpoint is designed to never return the data subject's name regardless of redaction status.
  • Usage and telemetry data: feature usage, event logs, performance metrics, error messages; AI usage/token-consumption events (keyed by a pseudonymous user hash; no transcript text).
  • Audit and security logs: login attempts; IP addresses and user-agent strings captured for (a) demo account creation and demo-related fraud prevention, (b) Platform Terms click-wrap acceptance (evidence of contract formation), (c) Reseller Agreement click-wrap acceptance (evidence of contract formation), and (d) reseller user-invitation rate-limiting; consent and click-wrap acceptance events together with the IP and user-agent associated with each acceptance event. IP addresses captured for click-wrap acceptance are retained on the parent user/reseller record for the life of that record (i.e., for the duration of the relevant Subscription Term plus the post-termination retention periods set out in the Platform Terms).

Special Categories of Data

The Platform is not intended to process special categories of data within the meaning of Article 9 GDPR (e.g. health data, religious beliefs) or criminal offence data. Customer shall instruct users not to enter such data into free-text fields. If such data is incidentally submitted, Vendor will take reasonable steps to delete it upon becoming aware of its presence, and will not intentionally use it for profiling or any other purpose.

Processing Operations

  • Collection via user registration and interaction with the Platform;
  • Storage, organisation and retrieval in databases and logs;
  • Analysis (e.g. generating scores, feedback and aggregated analytics);
  • AI-powered processing of conversation text inputs for leadership scenario simulations (via Google Cloud Vertex AI, within the EEA — Google Cloud europe-central2 and the eu EU multi-region);
  • Short-lived ("context") caching of recent conversation turns at the AI Sub-processor within the EEA, to reduce repeated processing of the same tokens; cache entries carry a short time-to-live (in the order of minutes) and are deleted at session end or on expiry;
  • Pseudonymisation/aggregation for analytics, including export of pseudonymised activity data to the analytics warehouse;
  • Deletion or anonymisation following retention periods.

Duration

For the Subscription Term and the post-termination retention periods described in the Platform Terms.

Annex 2 – Technical and Organisational Measures (TOMs)

Vendor implements, among others, the following measures (adapted as needed over time):

  • Access control: role-based access to production systems; unique user accounts; least-privilege principles; periodic access reviews.
  • Authentication: strong authentication mechanisms for internal staff; password policies for Customer users.
  • Infrastructure security: use of reputable cloud providers with physical and environmental security; network segmentation; firewalls and security groups.
  • Encryption: encryption of data in transit using TLS; encryption at rest using industry-standard algorithms, where reasonably feasible.
  • Logging and monitoring: logging of security-relevant events; automated alerts for suspicious activity; retention of logs for security analysis in line with the Platform Terms.
  • Backup and recovery: regular backups of critical databases; tested restore procedures; geo-redundant or regionally redundant storage depending on provider.
  • Development security: use of version control; code reviews; dependency management; vulnerability scanning; separation of development, staging and production environments where appropriate.
  • Incident management: a designated point of contact (the Administrator) for security incidents; incidents are triaged, contained and remediated on becoming aware, and affected Customers are notified in accordance with Clause 10; findings are used to harden the Platform.
  • Organisational controls: confidentiality obligations for staff; security and privacy awareness training; policies covering acceptable use, device security and data handling.

Annex 3 – Authorised Sub-processors and Locations

Vendor uses the Sub-processors listed below, each providing infrastructure or services necessary to operate the Platform:

Sub-processorServiceData Location(s)Transfer Safeguard (if outside EEA)
Google Cloud Platform / FirebaseHosting (Cloud Functions/Cloud Run), database (Cloud Firestore), file storage (Firebase Storage)europe-central2 (Poland, EEA)n/a (EEA)
Google Cloud – Firebase AuthenticationUser authentication and account management (sign-in; business email/identifier, authentication credentials, internal user identifier)Google's global infrastructure (includes EU data centers); account data may be processed outside the EEAGoogle Cloud DPA + EU Standard Contractual Clauses (controller-to-processor)
Google Cloud – Vertex AIGenerative AI processing of conversation text inputs for leadership scenario simulations, including short-lived context caching of conversation turns to reduce repeated token processingGemini 2.5 models: europe-central2 (Poland, EEA) via Genkit. Gemini 3.5 models: EU multi-region (eu, EEA) via the @google/genai SDKn/a (EEA)
Google BigQueryAnalytics data warehouse: pseudonymised session/results data, monitoring, telemetry, and AI usage/token-consumption events (keyed by a pseudonymous user hash; no transcript text)europe-central2 (Poland, EEA)n/a (EEA)
Vercel Inc.Frontend hosting (Next.js application), edge networkPrimarily EEA regions (Frankfurt, Amsterdam) with global CDNVercel EU infrastructure + DPA with SCCs
Gmail / Google WorkspaceLegal-entity correspondence (privacy/GDPR, legal/contract notices, billing) and internal system/ops alerts via SMTP with OAuth2; fallback transport for leadercore.ai transactional emailGoogle's global infrastructure (includes EU data centers)Google Cloud DPA + SCCs + Article 49(1)(b) (contract performance)
Namecheap, Inc. (Private Email)Customer-facing email for the leadercore.ai domain: inbound mailboxes and primary outbound transactional/notification email via SMTPUnited StatesNamecheap Data Processing Addendum + EU Standard Contractual Clauses (controller-to-processor) + Article 49(1)(b) (contract performance)

Vendor will keep this Annex up to date. Any changes to Sub-processors will be communicated in accordance with Clause 7 of this DPA.

Note on Firebase Authentication. Firebase Authentication does not offer EEA-only data residency; account identifiers and authentication metadata may be processed on Google's global infrastructure, governed by the Google Cloud DPA and EU Standard Contractual Clauses. No simulation content or grading outputs are stored in this service.

Note on the Namecheap transfer mechanism. Namecheap's Data Processing Addendum incorporates the EU Standard Contractual Clauses (Commission Decision 2021/914, controller-to-processor) and the UK SCCs/IDTA; as the processor-to-processor module is not separately offered, the transfer additionally relies on Article 49(1)(b) (necessary to deliver email the data subject's use of the service requires). The data transferred is limited to the recipient's email address and message content.

Disclosure: public-authority recipients (not Sub-processors)

The following public-authority services may receive a Customer's or Reseller's company VAT/tax identifier during onboarding for the sole purpose of validating that identifier. These services are not Article 28 Sub-processors of Customer Data; they are independent public authorities receiving a company tax identifier provided by Customer/Reseller during onboarding. Where the tax identifier relates to a sole-trader natural person rather than a legal entity, that identifier is personal data and the recipient is disclosed for transparency:

RecipientServicePurposeLawful basis for the disclosure
European Commission – VIES (VAT Information Exchange System)https://ec.europa.eu/taxation_customs/vies/Validation of EU VAT numbers submitted by Customer or ResellerArticle 6(1)(c) GDPR – legal obligation (Romanian and EU VAT rules require validation of cross-border VAT numbers)
Romanian National Agency for Fiscal Administration (ANAF)https://webservicesp.anaf.ro/Validation of Romanian fiscal identifiers (CUI/CIF)Article 6(1)(c) GDPR – legal obligation (Romanian Tax Code)

Disclosure: consent-gated Reseller analytics access (not a Sub-processor relationship)

Where a Customer enables Reseller analytics access for its subscription (via an authorised HR/Admin user, or via Vendor acting on the Customer's documented request), Vendor discloses to the Customer's authorised Reseller a pseudonymised, aggregated view of the Customer's cohort analytics. Real user names are masked (display aliases only) and no row-level or CSV export is made available to the Reseller. The Reseller receives this disclosure in its own capacity in respect of its partner relationship, on the basis of the Customer's documented instruction/consent; the lawful basis as between the Customer and its users is the Customer's responsibility. The enablement flag and an append-only consent ledger are stored on the Customer's subscription record. Access ceases immediately on disablement and, in any event, within 30 days after the end of the Subscription Term.

END OF DATA PROCESSING AGREEMENT