Data Processing Addendum — HatchAnalytics

Legal / DPA

Data Processing Addendum for the HatchAnalytics® Service

Between Customer and Hatch Analytics, LLC

Effective Date: July 1, 2026

Version: 1.0

Processor: Hatch Analytics, LLC

Privacy Contact: hatchanalytics-privacy@hatcherygroup.com

Subprocessor List: hatchanalytics.ai/legal/subprocessor

This Data Processing Addendum (the “DPA”) is entered into between Customer and Hatch Analytics, LLC (“Hatch Analytics”) and is incorporated into the HatchAnalytics Terms and Conditions to the extent Hatch Analytics processes Customer Personal Data on Customer's behalf in connection with the HatchAnalytics Service. Personal information Hatch Analytics processes for its own account administration, billing, security, support, legal, and business purposes is governed by the HatchAnalytics Privacy Policy and is outside this DPA.

1. Definitions

Agreement. The HatchAnalytics Terms and Conditions, the applicable Order, and this DPA.

Applicable Data Protection Law. Any privacy or data protection law applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and U.S. state privacy laws.

Customer Personal Data. Personal Data included in Customer Data or Provider Data that Hatch Analytics Processes on Customer's behalf in providing the Service. It does not include information Hatch Analytics Processes as an independent Controller or Business under the Privacy Policy.

Personal Data Breach. A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

Subprocessor. A third party engaged by Hatch Analytics to Process Customer Personal Data on Hatch Analytics' behalf. Other capitalized privacy terms have the meanings given under Applicable Data Protection Law, and terms defined in the Terms retain those meanings.

2. Roles and Instructions

Customer is the Controller or Business, and Hatch Analytics is the Processor, Service Provider, or Contractor, for Customer Personal Data Processed on Customer's behalf. Customer is responsible for the lawfulness of its instructions, notices, consents, and disclosures.

Hatch Analytics will Process Customer Personal Data only as necessary to provide, secure, support, maintain, and administer the Service; generate Output; follow Customer's documented instructions; and comply with applicable law. The Agreement, Customer's use and configuration of the Service, and written instructions consistent with the Agreement constitute documented instructions.

Hatch Analytics will notify Customer if it reasonably believes an instruction violates Applicable Data Protection Law, unless prohibited by law, and may suspend the affected Processing until the issue is resolved.

3. Confidentiality, Security, and Breach Notice

Hatch Analytics will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary for their duties.

Hatch Analytics will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current categories of measures are described in Schedule 2 and may be updated without materially reducing the overall level of protection.

Hatch Analytics will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, provide available information reasonably necessary for Customer to meet applicable notification obligations, and take reasonable steps to contain, investigate, and mitigate the breach. Information may be provided in phases. Notice is not an admission of fault or liability.

4. Subprocessors

Customer provides Hatch Analytics with general written authorization to engage Subprocessors to Process Customer Personal Data in connection with the Service. Hatch Analytics' current Subprocessor List is available at https://hatchanalytics.ai/legal/subprocessor and is incorporated into this DPA by reference. The list may also identify service providers that act as independent controllers for limited activities, which are outside the scope of Hatch Analytics' processor obligations under this DPA.

Hatch Analytics will impose written data-protection obligations on each Subprocessor that are no less protective in substance than the relevant obligations in this DPA and remains responsible for the Subprocessor's performance to the extent required by Applicable Data Protection Law.

Hatch Analytics will provide at least 30 days' advance notice by email, in-app notice, or another reasonable method before adding or replacing a Subprocessor that will materially Process Customer Personal Data. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If they cannot resolve it and Hatch Analytics cannot reasonably provide the affected Service without the Subprocessor, Hatch Analytics may provide an alternative, limit the affected feature, or permit Customer to terminate the affected portion of the Service, with a refund of unused prepaid Fees attributable to the terminated portion, if any.

5. Requests and Compliance Assistance

Taking into account the nature of the Processing, Hatch Analytics will provide reasonable assistance with requests to access, correct, delete, restrict, object to, or obtain a copy of Customer Personal Data. If Hatch Analytics receives a request concerning Customer Personal Data Processed solely on Customer's behalf, it may direct the requester to Customer unless law requires a direct response.

Hatch Analytics will provide reasonable assistance with data-protection impact assessments, prior consultations, regulatory inquiries, security obligations, and breach notification where required by Applicable Data Protection Law. Customer will reimburse reasonable costs for assistance disproportionate to the ordinary Service unless required because of Hatch Analytics' breach of this DPA.

6. Return, Deletion, and Retention

Customer is responsible for exporting Customer Personal Data before termination. Following termination, Hatch Analytics may retain Customer Personal Data for up to 60 days to permit reactivation or export but does not guarantee post-termination access, and may then delete it from active systems. Residual copies may remain in backups until overwritten in the ordinary course. Hatch Analytics may retain records required for legal, security, fraud-prevention, billing, or dispute-resolution purposes.

Upon reasonable written request, Hatch Analytics will confirm deletion, except where retention is permitted or required by law or deletion from backups is not reasonably practicable before the ordinary overwrite cycle.

7. U.S. State Privacy Terms

To the extent Hatch Analytics Processes Personal Data as a Service Provider or Contractor under U.S. state privacy law, Hatch Analytics will Process it only for the limited and specified purposes in the Agreement; will not sell or share it; will not retain, use, or disclose it outside the direct business relationship except as permitted by law; and will not combine it with Personal Data received from another person or collected from Hatch Analytics' own interactions with a Consumer except as legally permitted to provide the Service.

Hatch Analytics will provide the level of privacy protection required by applicable law, notify Customer if it determines it can no longer meet its obligations, and permit Customer to take reasonable steps to help ensure compliant Processing and to stop and remediate unauthorized use. Hatch Analytics may use aggregated or de-identified information as permitted by the Agreement and law and will not attempt to reidentify legally de-identified information.

8. International Transfers

Customer authorizes Hatch Analytics and its Subprocessors to Process Customer Personal Data in the United States and other countries where they operate, subject to Applicable Data Protection Law.

Where a restricted transfer from the EEA requires contractual safeguards, the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 are incorporated by reference. Module Two applies unless another module is required; Clause 7 applies; Clause 9 uses Option 2 with 30 days' notice; Clause 11's optional language does not apply; and Schedules 1 and 2 complete the relevant annexes. If no EEA governing jurisdiction is identified in an Order, Ireland applies. For UK transfers, the then-current UK Addendum applies. For Swiss transfers, the clauses apply with adaptations required by Swiss law.

9. Audit, Precedence, and Duration

Upon reasonable request, Hatch Analytics will provide information reasonably necessary to demonstrate compliance, such as available audit reports, certifications, security summaries, or a reasonable questionnaire response. Requests are limited to once annually unless a Personal Data Breach, material compliance concern, or regulator requires otherwise.

An on-site audit may occur only where required by Applicable Data Protection Law and available documentation is insufficient. It must be conducted during normal business hours, on reasonable notice, without unreasonable disruption, subject to confidentiality and security restrictions, and at Customer's expense unless it identifies a material breach by Hatch Analytics.

If this DPA conflicts with the Terms regarding Customer Personal Data, this DPA controls. The liability and indemnification provisions in the Terms apply to this DPA to the maximum extent permitted by law. This DPA ends when Hatch Analytics no longer Processes Customer Personal Data, subject to provisions that by their nature survive.

Schedule 1 — Processing Details

Item
Processing description
Parties
Data exporter: Customer identified in the applicable Order. Data importer: Hatch Analytics, LLC; privacy contact: hatchanalytics-privacy@hatcherygroup.com; legal contact: hatchanalytics-legal@hatcherygroup.com.
Subject Matter
Provision, operation, security, support, maintenance, and administration of the HatchAnalytics Service.
Duration
For the Subscription and the limited post-termination retention period in the Agreement.
Nature of Processing
Collection, recording, organization, storage, retrieval, access, use, transmission, analysis, authentication, support, security monitoring, and deletion.
Purposes
Account provisioning; authentication and two-factor authentication; dashboard access; support; security; service operation; billing administration; legal compliance; and generation of Output.
Data Subjects
Customer administrators, Authorized Users, business contacts, and individuals communicating with support.
Personal Data
First name, last name, business email address, company, phone number used for two-factor authentication, account or user identifier, role and permission data, limited authentication and security records, and support communications or ticket content.
Payment Data
Payment method information is submitted directly to Stripe and is not stored by Hatch Analytics. Hatch Analytics may receive billing contact information, transaction identifiers, payment status, card brand, and last four digits.
Sensitive Data
No special-category, health, biometric, government-identifier, precise-geolocation, or similar sensitive Personal Data is intended to be Processed. Customer must not submit such data unless expressly agreed in writing.
Frequency
Continuous or as initiated by Customer and Authorized Users during the Subscription.
Retention
During the Subscription; up to 60 days in active systems after termination; backups until overwritten in the ordinary course; longer where legally required.

Schedule 2 — Technical and Organizational Measures

Control area
Measures
Governance and Personnel
Documented security responsibilities; confidentiality obligations; role-based access; access removal; and security awareness appropriate to role.
Access and Tenant Controls
Unique accounts, least-privilege access, authentication controls, privileged-access safeguards, and logical controls designed to restrict each Customer to authorized data and Output.
Encryption
Industry-standard encryption in transit and encryption at rest where supported by applicable hosting and storage services.
Logging and Monitoring
Logging of relevant authentication, administrative, and security events and investigation of suspected unauthorized activity.
Availability and Recovery
Backups and recovery procedures appropriate to the Service, with periodic review or testing of restoration capabilities.
Vulnerability and Development Practices
Risk-based patching, dependency management, change controls, code review or equivalent checks, environment separation where appropriate, and testing before production deployment.
Incident Response
Processes to identify, contain, investigate, remediate, document, and communicate confirmed security incidents.
Vendor and Data Management
Risk-based vendor review, contractual data-protection obligations, data minimization, retention controls, and management of Subprocessors.

HatchAnalytics® | Data Processing Addendum | Version 1.0