AVATARIC.AI DATA PROCESSING ADDENDUM (DPA)

Effective Date: June 10, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service, Subscription Agreement, Order Form, or other written agreement (collectively, the "Agreement") between Avataric.ai Technologies Corp. ("Avataric.ai", "Processor", "Service Provider", "we", "our", or "us") and the Customer ("Customer", "Controller", "Business", or "you").

This DPA applies whenever Avataric.ai processes Personal Data on behalf of the Customer in connection with the Services.

1. PURPOSE

The purpose of this DPA is to define the parties' respective obligations regarding the processing of Personal Data and to demonstrate compliance with applicable privacy laws.

This DPA applies only where Avataric.ai processes Personal Data on behalf of the Customer.

2. DEFINITIONS

For purposes of this DPA:

Agreement means the governing commercial agreement between the parties.

Customer Data means any information submitted to the Services by or on behalf of the Customer, including Personal Data.

Data Subject means an identified or identifiable natural person.

Personal Data means information relating to an identified or identifiable individual, as defined by applicable privacy laws.

Processing means any operation performed on Personal Data, including collection, storage, organization, retrieval, consultation, transmission, use, disclosure, deletion, or destruction.

Controller means the entity that determines the purposes and means of Processing Personal Data.

Processor means the entity Processing Personal Data on behalf of the Controller.

Subprocessor means a third party engaged by Avataric.ai to Process Personal Data on behalf of the Customer.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

3. ROLES OF THE PARTIES

Except where otherwise agreed in writing:

  • Customer acts as the Controller (or equivalent under applicable law).

  • Avataric.ai acts as the Processor or Service Provider.

  • Customer determines the purposes and means of Processing.

  • Avataric.ai Processes Personal Data solely to provide the Services.

Nothing in this DPA transfers ownership of Customer Data to Avataric.ai.

4. PROCESSING INSTRUCTIONS

Avataric.ai will Process Personal Data only:

  • to provide the Services;

  • to fulfill Customer instructions;

  • to comply with the Agreement;

  • to comply with applicable law.

Avataric.ai will not Process Personal Data for its own marketing purposes.

Avataric.ai will not sell Personal Data.

Avataric.ai will not use Customer Data to train public or shared artificial intelligence models.

5. CUSTOMER RESPONSIBILITIES

Customer represents and warrants that it:

  • has all necessary rights to provide Personal Data;

  • has provided required privacy notices;

  • has obtained required consents where applicable;

  • has an appropriate legal basis for Processing;

  • complies with applicable privacy laws.

Customer is responsible for determining whether Personal Data may lawfully be submitted to the Services.

6. NATURE OF PROCESSING

Processing activities may include:

  • hosting;

  • storage;

  • retrieval;

  • indexing;

  • search;

  • AI processing;

  • document analysis;

  • natural language processing;

  • conversational AI;

  • voice processing;

  • avatar generation;

  • API processing;

  • system administration;

  • customer support;

  • security monitoring;

  • backup and recovery.

7. TYPES OF PERSONAL DATA

Depending on Customer use, Personal Data may include:

  • names;

  • email addresses;

  • telephone numbers;

  • organization names;

  • job titles;

  • account information;

  • uploaded documents;

  • CRM records;

  • support records;

  • website content;

  • conversation histories;

  • voice recordings;

  • images;

  • videos;

  • AI Agent interactions;

  • metadata.

Customer controls the categories of Personal Data submitted to the Services.

8. CATEGORIES OF DATA SUBJECTS

Data Subjects may include:

  • Customer employees;

  • contractors;

  • volunteers;

  • donors;

  • members;

  • website visitors;

  • clients;

  • customers;

  • prospects;

  • suppliers;

  • partners;

  • other individuals whose information Customer submits to the Services.

9. CONFIDENTIALITY

Avataric.ai will ensure that personnel authorized to Process Personal Data:

  • are subject to confidentiality obligations;

  • receive appropriate training;

  • access Personal Data only where necessary to perform their duties.

10. SECURITY MEASURES

Avataric.ai maintains commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data.

Security measures may include:

  • encryption in transit;

  • encryption at rest where supported by infrastructure;

  • authentication controls;

  • role-based access controls;

  • logging;

  • monitoring;

  • vulnerability management;

  • security patching;

  • incident response procedures;

  • backup procedures.

Customer acknowledges that no security system can guarantee absolute protection.

11. SUBPROCESSORS

Avataric.ai may engage Subprocessors to provide portions of the Services.

Current categories of Subprocessors include:

  • cloud infrastructure providers;

  • AI model providers;

  • avatar rendering providers;

  • customer support providers;

  • payment processors;

  • authentication providers;

  • communications providers.

Current primary Subprocessors include:

  • OpenAI

  • HeyGen

  • Google Cloud

  • DigitalOcean

Avataric.ai will require Subprocessors to maintain contractual obligations that provide appropriate protection for Personal Data.

Avataric.ai may update its list of Subprocessors from time to time.

A current Subprocessor List will be maintained separately from this DPA.

12. INTERNATIONAL TRANSFERS

Avataric.ai is incorporated in British Columbia, Canada.

Customer Data is primarily stored and processed in the United States.

Customer acknowledges that Personal Data may be transferred to:

  • the United States;

  • Canada;

  • other jurisdictions where authorized Subprocessors operate.

Avataric.ai will implement reasonable contractual safeguards appropriate to such transfers.

13. ASSISTANCE WITH PRIVACY REQUESTS

Where reasonably requested, Avataric.ai will assist Customer in responding to:

  • access requests;

  • correction requests;

  • deletion requests;

  • restriction requests;

  • regulatory inquiries;

to the extent reasonably possible and appropriate to the Services.

Customer remains responsible for responding to Data Subject requests.

14. SECURITY INCIDENTS

If Avataric.ai becomes aware of a confirmed Security Incident affecting Customer Personal Data, Avataric.ai will notify Customer without undue delay after confirming the incident.

Notification may include:

  • nature of the incident;

  • affected information (where known);

  • mitigation steps;

  • remediation efforts;

  • recommended Customer actions.

Avataric.ai will investigate and take commercially reasonable steps to mitigate the impact of the Security Incident.

15. AUDITS

Upon reasonable written request and subject to appropriate confidentiality obligations, Avataric.ai will make available information reasonably necessary to demonstrate compliance with this DPA.

Avataric.ai may satisfy this obligation by providing:

  • security documentation;

  • audit summaries;

  • certifications (if available);

  • questionnaires;

  • other reasonable documentation.

Customer agrees not to conduct intrusive testing of Avataric.ai systems without prior written authorization.

16. DATA RETENTION

Avataric.ai retains Personal Data only for as long as necessary to:

  • provide the Services;

  • comply with legal obligations;

  • resolve disputes;

  • maintain platform security.

Retention periods may vary depending on the type of information.

17. DATA DELETION

Upon Customer deletion of AI Agents, uploaded documents, or Customer Data, Avataric.ai will remove the associated Customer Data from active production systems without undue delay.

Certain encrypted backups, system logs, and archival records may temporarily remain where reasonably necessary for:

  • disaster recovery;

  • legal compliance;

  • fraud prevention;

  • security;

  • business continuity.

Such retained information will be securely deleted or overwritten according to Avataric.ai's standard retention schedules.

Upon termination of the Agreement, Customer may request deletion of Customer Data, subject to applicable legal obligations.

18. RETURN OF CUSTOMER DATA

Where technically feasible and requested by Customer before termination, Avataric.ai will make Customer Data available for retrieval in accordance with the Services and the applicable Subscription Plan.

Avataric.ai is not required to maintain Customer Data indefinitely following termination.

19. LIABILITY

The liability limitations contained in the Agreement apply to this DPA to the maximum extent permitted by applicable law.

20. TERM

This DPA becomes effective on the Effective Date and remains in force for as long as Avataric.ai Processes Personal Data on behalf of Customer.

21. GOVERNING LAW

This DPA is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein, unless the Agreement expressly provides otherwise.

22. ORDER OF PRECEDENCE

If there is a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA controls to the extent of that conflict.

23. CONTACT

Questions regarding this DPA may be directed to:

Privacy Officer

Avataric.ai Technologies Corp.

Email: hello@avataric.ai

Website: https://www.avataric.ai

501-3292 Production Way

Burnaby, BC V5A 4R4

Canada