# Data Processing Addendum

This Data Processing Addendum (this "**DPA**") is entered into by and between Sonarly, Inc. ("**Sonarly**", "**we**", or "**us**") and the party that electronically accepts or otherwise agrees to this DPA ("**Customer**", or "**you**"). This DPA is effective as of the date electronically agreed and accepted by you.

You have entered into one or more agreements with us (each, as amended from time to time, an "**Agreement**") governing the provision of our AI-powered error and incident analysis platform, more fully described at [sonarly.com](/content/site-root.html) (the "**Service**"). This DPA amends the terms of the Agreement to reflect the parties' rights and responsibilities with respect to the processing and security of Customer Data as defined below under the Agreement. If you are accepting this DPA in your capacity as an employee, consultant, or agent of Customer, you represent that you have the authority to bind Customer to this DPA.

Any capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement.

## 1. Definitions
The following definitions apply to this DPA:

- **CCPA** means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder.
- **Controller** means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing of Personal Data.
- **Customer Data** means data you submit to, store on, or send to us via the Service, including error data, stack traces, source code accessed via connected repositories, observability data (logs, metrics, traces), and incident data.
- **Data Incident** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data on systems managed and controlled by Sonarly.
- **Data Privacy Framework** means (as applicable) the EU-U.S. Data Privacy Framework...

## 2. Data Processing
### 2.1 Roles and Regulatory Compliance
**Scope.** This DPA applies where and only to the extent Sonarly processes Personal Data as a Processor for the purposes of Privacy Laws.

### 2.2 Customer Responsibilities
**Customer Authorization.** Sonarly shall process Personal Data in accordance with Customer's documented lawful instructions.

### 2.3 AI Processing
You acknowledge that the Service uses artificial intelligence models provided by third-party Subprocessors to analyze Customer Data.

## 3. Deletion
### 3.1 Deletion During Term
We will enable you to delete Personal Data during the Term in a manner consistent with the functionality of the Service.

### 3.2 Deletion When Term Expires
When the Term expires, we will destroy any Personal Data in our possession or control.

## 4. Data Security
### 4.1 Security Measures
We will implement and maintain appropriate technical and organizational measures to protect Personal Data.

### 4.2 Data Incidents
Upon becoming aware of a Data Incident, we will notify you promptly and without undue delay.

### 4.3 Your Security Responsibilities
You are solely responsible for your use of the Service, including securing account credentials.

## 5. Data Subject Rights; Data Export
### 5.1 Access; Rectification; Restricted Processing; Portability
You acknowledge that the Service may, depending on functionality, enable you to access Customer Data; rectify inaccurate Customer Data; restrict processing of Customer Data; delete Customer Data; and export Customer Data.

### 5.2 Cooperation; Data Subjects' Rights
To the extent that you cannot access the relevant Personal Data within the Service...

## 6. Data Transfers
### 6.1 Data Storage and Processing Facilities
You agree that we may, subject to compliance with applicable Privacy Laws, store and process Customer Data in the United States and any other country in which we or our Subprocessors maintain data processing operations.

## 7. Subprocessors
### 7.1 Consent to Engagement
You authorize us to engage third parties as Subprocessors.

### 7.2 List of Subprocessors
| Subprocessor | Purpose | Location |
| --- | --- | --- |
| Amazon Web Services (AWS) | Cloud infrastructure hosting | United States |
| Anthropic | AI model provider | United States |
| Google Cloud (Vertex AI) | AI model provider | United States |
| Stripe | Payment processing | United States |

## 8. Data Protection Impact Assessment
We will provide you with reasonable and timely assistance as you may require in order to conduct a data protection impact assessment.

## 9. Jurisdiction-Specific Terms
The terms specified in Schedule 4 with respect to the listed jurisdictions will apply in addition to the terms of this DPA.

## 10. Miscellaneous
There are no third-party beneficiaries to this DPA.

## Schedule 1 — Data Processing Description
### Subject Matter and Purpose
Sonarly's provision of the Service to Customer.

### Categories of Data Subjects
- Customer's employees and contractors.
- Customer's end users whose data may be present...

## Schedule 2 — Security Measures
| Measure | Description |
| --- | --- |
| Encryption of data in transit | All data transmitted is encrypted...

## Schedule 3 — Cross-Border Transfer Mechanisms
### 1. Data Privacy Framework
Sonarly complies with the Data Privacy Framework in relation to transfers.

### 2. Standard Contractual Clauses
In the event that the Data Privacy Framework is invalidated...

## Schedule 4 — Jurisdiction-Specific Terms
### Europe
**Additional Information.** You acknowledge that Sonarly is required under European Data Protection Legislation...
