Data Processing and Data-Sharing Addendum

Effective date: July 11, 2026.

This Data Processing and Data-Sharing Addendum (the “Addendum” or “DPA”) forms part of and is incorporated into the Terms of Service Agreement between OpSynx AI and the Customer. It governs OpSynx AI’s processing of Personal Information on the Customer’s behalf in connection with the Service. In the event of a conflict between this Addendum and the Terms of Service Agreement regarding the processing of Personal Information, this Addendum controls.

1. Definitions

“Personal Information” means information relating to an identified or identifiable individual that is contained in Customer Data. “Controller,” “Processor,” “Data Subject,” and “Processing” have the meanings given under applicable data-protection law. “Sub-processor” means a third party engaged by OpSynx AI to process Personal Information.

2. Roles of the parties

For the lead, owner, and property-owner Personal Information the Customer uploads to or generates within its sub-account, the Customer is the Controller and OpSynx AI is the Processor. OpSynx AI processes Personal Information only on the Customer’s documented instructions (including as set out in the Terms and this Addendum), unless required to act by law, in which case OpSynx AI will inform the Customer unless legally prohibited.

3. Scope, nature, and purpose of processing

The subject matter is the provision of the Service. The nature and purpose of processing is to host, store, organize, analyze, enrich (including skip-trace), retrieve, transmit, and otherwise process Personal Information solely to provide and support the Service — including underwriting, valuation, lead routing and management, disposition, document generation, and support — and for no independent purpose. The categories of Data Subjects are the property owners, prospects, and contacts in the Customer’s records; the categories of Personal Information are identifiers and contact data such as name, mailing and property address, parcel identifiers, phone numbers, and related notes. Processing continues for the duration of the Agreement.

4. Customer obligations

The Customer is responsible for the accuracy, quality, and legality of Personal Information and for having provided all notices and obtained all rights, consents, and lawful bases necessary for OpSynx AI to process Personal Information as contemplated. The Customer’s instructions must comply with applicable law.

5. Confidentiality of processing

OpSynx AI ensures that personnel authorized to process Personal Information are subject to binding confidentiality obligations and are granted access on a least-privilege, need-to-know basis.

6. Security measures

OpSynx AI implements and maintains appropriate technical and organizational measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access, including: per-tenant logical and physical isolation of sub-accounts, encryption of data in transit, role-based access controls, least-privilege credentials, network and host controls, audit logging, and regular review of these measures.

7. Sub-processors

The Customer provides a general authorization for OpSynx AI to engage the following Sub-processors: Land Portal (skip-trace and contact data), GoHighLevel (CRM and lead capture), Slack (operational notifications), DigitalOcean (cloud hosting and infrastructure), and OpSynx AI’s AI provider(s) (automated analysis and document generation). OpSynx AI imposes data-protection obligations on each Sub-processor no less protective than those in this Addendum, remains responsible for each Sub-processor’s performance, and will give the Customer prior notice before adding or replacing a Sub-processor, allowing the Customer a reasonable opportunity to object on reasonable data-protection grounds.

8. Skip-trace and permitted use

Skip-trace and contact outputs are Personal Information and consumer contact information subject to privacy, telemarketing, TCPA, and Do-Not-Call law. Such outputs are not consumer reports and may not be used for any purpose governed by the Fair Credit Reporting Act. The Customer may use them only for its own lawful outreach concerning the underlying property, and must honor Do-Not-Call and consent requirements. Responsibility for lawful outreach rests solely with the Customer.

9. Data-subject requests

Taking into account the nature of the Processing, OpSynx AI will provide reasonable assistance to enable the Customer to respond to Data-Subject requests to access, correct, delete, restrict, or port Personal Information. If OpSynx AI receives such a request directly, it will, unless legally required to respond, refer the request to the Customer.

10. Personal-data breach notification

OpSynx AI will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s Personal Information, and will provide information reasonably available to it to help the Customer meet its own notification obligations. OpSynx AI will take reasonable steps to mitigate and remediate the breach.

11. Return and deletion

On expiry or termination of the Agreement, OpSynx AI will, at the Customer’s election, make Customer Data available for export for a limited period and then delete or return Personal Information (typically within 30 days), except to the extent retention is required by law or for routine backup cycles, in which case the data remains subject to this Addendum until deleted.

12. Audit

OpSynx AI will make available to the Customer, on reasonable written request and no more than once per year (or as required following a breach or by a regulator), information reasonably necessary to demonstrate compliance with this Addendum, subject to confidentiality and OpSynx AI’s security policies.

13. International transfers

Personal Information is hosted in the United States. Where a transfer of Personal Information implicates cross-border transfer rules, the parties will cooperate to implement an appropriate transfer mechanism.

14. Contact

Data-protection inquiries: [email protected].