Data Processing Agreement
Last Updated: September 2026
1. Definitions
For purposes of this DPA:
1.1 "Applicable Data Protection Law"
Means any applicable law, regulation, or binding regulatory requirement governing the processing or protection of Personal Data applicable to the processing contemplated by this DPA, including, where applicable, the California Consumer Privacy Act, as amended ("CCPA"), and the EU General Data Protection Regulation ("GDPR").
1.2 "Customer Data"
Means information, content, files, communications, prompts, instructions, project information, and other data submitted to or generated through the Services by or on behalf of Customer or its Authorized Users.
1.3 "Personal Data"
Means any information relating to an identified or identifiable individual that is processed by The Coast on behalf of Customer under this DPA. Where applicable, "Personal Data" includes "personal information" or equivalent terms under Applicable Data Protection Law.
1.4 "Processing"
Has the meaning given to it under Applicable Data Protection Law and includes collecting, recording, organizing, storing, retrieving, using, disclosing, transmitting, restricting, deleting, or otherwise processing Personal Data.
1.5 "Subprocessor"
Means a third party engaged by The Coast to Process Personal Data on behalf of Customer in connection with the Services.
1.6 "Authorized User"
Means an individual whom Customer authorizes to access or use the Services.
2. Roles of the Parties
2.1 Customer determines the purposes and means of processing Customer Personal Data and acts as the Controller, or equivalent role, under Applicable Data Protection Law.
2.2 The Coast acts as the Processor, service provider, or equivalent role, to the extent it Processes Customer Personal Data on Customer's behalf.
2.3 The parties acknowledge that The Coast may process certain information for its own independent purposes, including account administration, security, fraud prevention, service improvement, legal compliance, and billing. Such processing is governed by The Coast's Privacy Policy and applicable Law and is outside the scope of processing carried out solely on Customer's documented instructions.
2.4 Nothing in this DPA changes the parties' respective roles where applicable Law independently determines that a party is a controller, business, service provider, contractor, or equivalent entity.
3. Subject Matter and Purpose of Processing
3.1 The Coast will Process Customer Personal Data only as necessary to provide, maintain, secure, and support the Services and in accordance with:
- •Customer's documented instructions;
- •the applicable agreement between the parties;
- •this DPA; and
- •Applicable Data Protection Law.
3.2 Processing may include activities necessary to provide Colony's team-workspace and AI-enabled functionality, including:
- •Creating and maintaining customer accounts and workspaces;
- •Facilitating collaboration between Authorized Users;
- •Storing and retrieving project, task, and workspace information;
- •Enabling role-based access and permissions;
- •Processing user instructions, prompts, and other inputs submitted to AI-enabled features;
- •Generating and delivering AI-assisted outputs;
- •Maintaining shared knowledge and workspace information;
- •Providing customer support;
- •Maintaining service availability and security;
- •Monitoring and troubleshooting the Services;
- •Preventing fraud, abuse, and unauthorized access; and
- •Performing other processing reasonably necessary to provide the Services as directed by Customer.
3.3 The Coast will not Process Customer Personal Data for purposes inconsistent with the documented purposes of the Services.
3.4 Where Customer provides additional written instructions that require material changes to the scope of processing, the parties may agree to appropriate changes to this DPA or the applicable commercial agreement.
4. Categories of Data and Data Subjects
4.1 Categories of Personal Data
Depending on how Customer uses the Services, Customer Personal Data may include:
- •Name and contact information;
- •Account and authentication information;
- •Organization, company, and professional information;
- •Role and workspace information;
- •Project, task, and collaboration information;
- •Communications and content submitted through the Services;
- •AI prompts, instructions, and outputs;
- •Files or other materials uploaded by Customer or Authorized Users;
- •Usage, activity, and log information associated with use of the Services;
- •Technical information necessary for security and service operation; and
- •Other Personal Data that Customer chooses to submit through the Services.
Customer remains responsible for determining whether the categories of information it submits to the Services are appropriate for the Services and for complying with any restrictions applicable to such information.
4.2 Categories of Data Subjects
Depending on Customer's use of the Services, Personal Data may relate to:
- •Customer's employees;
- •Contractors;
- •Representatives;
- •Authorized Users;
- •Customers or clients of Customer;
- •Business contacts; and
- •Other individuals whose information Customer chooses to submit to the Services.
4.3 Sensitive or Special Categories of Data
The Services are not intended to require Customer to submit sensitive or special-category Personal Data unless expressly supported and agreed by the parties.
Customer should not submit highly sensitive or regulated information unless Customer has confirmed that the Services are appropriate for that information and any necessary contractual or technical safeguards have been established.
5. Customer Responsibilities
5.1 Customer is responsible for:
- •Ensuring that its Processing of Personal Data and instructions to The Coast comply with Applicable Data Protection Law;
- •Providing all notices and obtaining any consents or other lawful bases required for its Processing activities;
- •Ensuring that it has the necessary rights and permissions to provide Personal Data to The Coast;
- •Determining what Personal Data is submitted to the Services;
- •Ensuring that Authorized Users are appropriately authorized to access Customer Data; and
- •Responding to requests from individuals concerning Customer's Processing of their Personal Data, with assistance from The Coast as required under this DPA.
5.2 Customer will not instruct The Coast to Process Personal Data in a manner that would cause The Coast to violate Applicable Data Protection Law.
6. The Coast's Data Protection Obligations
The Coast will:
- •Process Customer Personal Data only for the purposes described in this DPA and in accordance with Customer's documented instructions;
- •Ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations;
- •Implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and accidental loss, destruction, alteration, or disclosure;
- •Assist Customer, taking into account the nature of the Processing, with obligations relating to applicable data subject requests;
- •Assist Customer, where reasonably necessary, with applicable security, breach notification, impact assessment, and regulatory consultation obligations;
- •Notify Customer if The Coast becomes aware that a Customer instruction relating to Personal Data appears to violate Applicable Data Protection Law; and
- •Maintain appropriate records and documentation reasonably necessary to demonstrate compliance with this DPA, subject to applicable confidentiality and security restrictions.
7. Confidentiality
7.1 The Coast will ensure that personnel and other persons authorized to Process Customer Personal Data are subject to confidentiality obligations appropriate to the nature of the information.
7.2 Confidentiality obligations will survive termination of the applicable relationship for so long as required by the applicable agreement or Applicable Data Protection Law.
8. Security of Processing
8.1 The Coast will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data.
8.2 Such measures may include, as appropriate to the Services and applicable risk:
- •Access controls and role-based permissions;
- •Authentication and administrative access protections;
- •Encryption or other safeguards for data in transit and, where implemented, at rest;
- •Logging and monitoring;
- •Vulnerability and security management;
- •Backup and recovery measures;
- •Confidentiality controls;
- •Secure development and deployment practices; and
- •Incident detection, response, and remediation procedures.
8.3 The specific security measures applicable to the Services may be described in The Coast's current security documentation or security overview, where available.
8.4 The Coast may update its security measures from time to time provided that such changes do not materially reduce the overall security of the Services.
9. Security Incidents
9.1 If The Coast becomes aware of a confirmed Security Incident affecting Customer Personal Data, The Coast will notify Customer without undue delay after confirming the incident, subject to applicable legal restrictions.
9.2 "Security Incident" means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.
9.3 The notification will, to the extent reasonably available and legally permissible, include:
- •The nature of the incident;
- •The categories of Personal Data affected;
- •The affected data subjects, where known;
- •The likely consequences of the incident; and
- •Measures taken or proposed to address and mitigate the incident.
9.4 The Coast will take reasonable steps to contain, investigate, and mitigate a Security Incident and will cooperate reasonably with Customer in relation to applicable notification and remediation obligations.
9.5 Customer remains responsible for determining whether and how it must notify affected individuals, regulators, or other third parties, unless applicable law places that obligation directly on The Coast.
10. Subprocessors
10.1 Customer generally authorizes The Coast to engage Subprocessors in connection with the Services.
10.2 The Coast will maintain information identifying relevant Subprocessors and the services they provide.
10.3 The Coast will impose data protection obligations on Subprocessors that are appropriate to the nature of the services and the Personal Data being processed.
10.4 Where GDPR applies, The Coast will comply with the requirements applicable to the engagement of Subprocessors, including providing Customer with the opportunity to object to relevant changes where required by Article 28.
10.5 The Coast remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and this DPA.
10.6 A general, categorized description of the types of Subprocessors The Coast uses is set out in Colony's Privacy Policy. The current named list of Subprocessors is set out in Annex 3 to this DPA and is made available to Customer on execution of this DPA and thereafter on request.
11. Data Subject Requests
11.1 Where Customer receives a request from an individual concerning Personal Data processed through the Services, Customer will remain primarily responsible for responding to the request.
11.2 Taking into account the nature of the Processing, The Coast will provide reasonable assistance to Customer in responding to requests relating to:
- •access;
- •correction;
- •deletion;
- •restriction;
- •portability; and
- •objection,
where such rights apply.
11.3 Where The Coast receives a request directly from an individual concerning Personal Data Processed on Customer's behalf, The Coast will, where legally permitted, direct the individual to Customer and will not independently respond to the request except as required by law.
12. Deletion and Return of Data
12.1 Upon termination or expiration of the Services, Customer may request the deletion or return of Customer Personal Data, subject to the terms of the applicable agreement and Applicable Data Protection Law.
12.2 The Coast will delete or return Customer Personal Data within a reasonable period following termination, unless retention is required or permitted by law.
12.3 Where Personal Data is retained for legal, security, backup, or other legitimate purposes, The Coast will continue to protect the retained information and will delete it when the applicable retention requirement expires.
12.4 Specific retention periods may depend on the Services, Customer's configuration, and applicable law.
13. International Data Transfers
13.1 The Coast may Process Customer Personal Data in jurisdictions in which The Coast or its Subprocessors operate, subject to Applicable Data Protection Law.
13.2 Where Applicable Data Protection Law requires a specific transfer mechanism for the international transfer of Personal Data, the parties will implement an appropriate mechanism.
13.3 Where the GDPR applies and Personal Data is transferred outside the European Economic Area in circumstances requiring a transfer mechanism, the parties will use an applicable lawful transfer mechanism, which may include the European Commission's Standard Contractual Clauses where appropriate.
13.4 The parties will cooperate reasonably in implementing additional safeguards required by Applicable Data Protection Law.
14. Regulatory and Audit Cooperation
14.1 The Coast will make available to Customer information reasonably necessary to demonstrate compliance with the obligations applicable to The Coast under this DPA.
14.2 Where required by Applicable Data Protection Law, The Coast will cooperate with reasonable audits or assessments relating to Customer Personal Data.
14.3 Any audit must:
- •Be conducted on reasonable advance notice;
- •Occur during normal business hours;
- •Avoid unreasonable disruption to The Coast's operations;
- •Protect the confidentiality and security of The Coast's systems and information; and
- •Not require access to information relating to other customers.
14.4 The parties may satisfy audit obligations through available security documentation, certifications, assessments, questionnaires, or other reasonable evidence where appropriate.
15. Government Requests
15.1 If The Coast receives a legally binding request from a government authority for Customer Personal Data, The Coast will, where legally permitted, notify Customer before disclosing the information.
15.2 The Coast will disclose only the information legally required and will reasonably consider any lawful objections or protective measures available to it.
16. Data Protection Impact Assessments
Where required by Applicable Data Protection Law, The Coast will provide reasonable assistance to Customer in relation to data protection impact assessments or similar regulatory assessments concerning the Services, taking into account the nature of the Processing and information reasonably available to The Coast.
17. Term and Termination
17.1 This DPA will remain in effect for as long as The Coast Processes Customer Personal Data on Customer's behalf.
17.2 The obligations relating to confidentiality, security, deletion, return of data, and any other provisions that by their nature are intended to survive termination will survive termination of this DPA.
18. Order of Precedence
18.1 This DPA forms part of the agreement governing Customer's use of the Services.
18.2 If there is a conflict between this DPA and another agreement between the parties concerning the Processing of Personal Data, this DPA will control with respect to data protection and Processing matters, unless the parties expressly agree otherwise in writing.
18.3 Nothing in this DPA limits any rights or obligations that cannot lawfully be limited under Applicable Data Protection Law.
19. Liability
The parties' liability in connection with this DPA will be governed by the liability provisions of the applicable commercial agreement between the parties, except to the extent Applicable Data Protection Law requires otherwise.
Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited.
20. Governing Law
This DPA will be governed by the governing-law and dispute-resolution provisions of the applicable agreement between the parties, except to the extent Applicable Data Protection Law requires otherwise.
Where no governing-law provision exists in the applicable agreement, the parties will apply the governing law specified in the applicable Terms of Service.
21. General
21.1 Entire Agreement
This DPA and the agreements incorporated into it constitute the parties' agreement concerning the Processing of Customer Personal Data in connection with the Services.
21.2 Amendments
Amendments to this DPA must be made in accordance with the amendment procedures applicable to the underlying agreement.
21.3 Severability
If any provision is held invalid or unenforceable, the remaining provisions will remain in effect.
21.4 Electronic Execution
This DPA may be executed electronically and in counterparts.
A. Annex 1 — Details of Processing
A. Subject Matter
The Processing of Personal Data necessary to provide Colony and related Services to Customer.
B. Duration
Processing will continue for the duration of Customer's use of the Services and for any additional period required for deletion, backup, legal, or other permitted retention.
C. Nature and Purpose
Processing may include:
- •Account administration;
- •Workspace and project management;
- •Collaboration;
- •Task management and execution;
- •AI-assisted processing;
- •Knowledge storage and retrieval;
- •Customer support;
- •Security and abuse prevention;
- •Service maintenance;
- •Troubleshooting;
- •Analytics and service operations; and
- •Other Processing necessary to provide the Services.
D. Categories of Personal Data
Depending on Customer's use of the Services:
- •Identity and contact information;
- •Account information;
- •Professional information;
- •Workspace and role information;
- •Project and task information;
- •Communications and content;
- •Uploaded files;
- •AI prompts, instructions, and outputs;
- •Technical and usage information; and
- •Other Personal Data submitted by Customer.
E. Categories of Data Subjects
- •Customer employees;
- •Contractors;
- •Authorized Users;
- •Customers and clients of Customer;
- •Business contacts; and
- •Other individuals whose information Customer submits to the Services.
B. Annex 2 — Technical and Organizational Measures
The Coast will maintain technical and organizational measures appropriate to the risks associated with the Processing.
These measures may include:
1. Access Control
Role-based access controls, authentication controls, and restrictions on administrative access.
2. Data Security
Appropriate safeguards for Personal Data in transit and, where implemented, at rest.
3. Personnel Security
Confidentiality obligations and access restrictions for personnel with access to Customer Personal Data.
4. Security Monitoring
Appropriate logging, monitoring, and detection mechanisms.
5. Incident Management
Processes for identifying, escalating, investigating, and responding to security incidents.
6. Business Resilience
Reasonable backup, recovery, and availability measures appropriate to the Services.
7. Vulnerability Management
Processes intended to identify and address material security vulnerabilities.
8. Data Lifecycle Management
Processes for retention, deletion, and disposal of Personal Data in accordance with applicable requirements.
9. Subprocessor Management
Processes for assessing and managing third parties that Process Personal Data on behalf of The Coast.
The specific controls implemented by The Coast may evolve as the Services and security environment develop.
C. Annex 3 — Subprocessor Framework
The Coast may use third-party service providers to support the Services.
The current Subprocessor List will identify, as applicable:
| Subprocessor | Service / Function | Categories of Data Processed | Location |
|---|---|---|---|
| Dodo Payments | Payment processing (merchant of record); billing, tax calculation and remittance, chargeback and fraud handling | Billing and transaction data; limited account identifiers necessary for payment | United States (see Dodo Payments' own subprocessor and data-location disclosures) |
| Anthropic, PBC | AI-assisted features (foundation model provider) | Prompts, instructions, and AI-generated Outputs; limited surrounding context necessary to process the request | United States (see Anthropic's own subprocessor and data-location disclosures) |
| OpenAI, L.L.C. | AI-assisted features (foundation model provider) | Prompts, instructions, and AI-generated Outputs; limited surrounding context necessary to process the request | United States (see OpenAI's own subprocessor and data-location disclosures) |
| Google LLC | AI-assisted features (foundation model provider) | Prompts, instructions, and AI-generated Outputs; limited surrounding context necessary to process the request | United States (see Google's own subprocessor and data-location disclosures) |
| [Provider — pending Engineering/Ops confirmation] | Cloud hosting and infrastructure | [● — to be confirmed] | [● — to be confirmed] |
| [Provider — pending Engineering/Ops confirmation] | Customer support and/or analytics tooling | [● — to be confirmed] | [● — to be confirmed] |
The Coast will update the applicable Subprocessor information when material changes occur.
D. Annex 4 — GDPR Terms
This Annex applies only to the extent that the GDPR applies to the Processing of Personal Data under this DPA.
1. Documented Instructions
The Coast will Process Personal Data only on documented instructions from Customer, unless applicable law requires otherwise.
2. Confidentiality
Persons authorized to Process Personal Data will be subject to appropriate confidentiality obligations.
3. Security
The Coast will implement appropriate technical and organizational measures taking into account the risks presented by the Processing.
4. Subprocessors
The Coast will comply with the requirements of Article 28 concerning the appointment of additional processors.
5. Assistance
The Coast will reasonably assist Customer with its obligations under Articles 32 through 36, taking into account the nature of Processing and information available to The Coast.
6. Deletion or Return
At the end of the provision of Services, The Coast will delete or return Personal Data in accordance with Customer's instructions unless applicable law requires continued storage.
7. Demonstration of Compliance
The Coast will make available information reasonably necessary to demonstrate compliance with Article 28 and will permit and contribute to audits where required by Article 28 and this DPA.
8. International Transfers
Where required, the parties will implement an appropriate lawful transfer mechanism for transfers of Personal Data outside the EEA.
E. Signatures
| THE COAST GLOBAL INC. | CUSTOMER |
|---|---|
| By: ___________ Name: ___________ Title: ___________ Date: ___________ | Legal Name: ___________ By: ___________ Name: ___________ Title: ___________ Date: ___________ |