Data Processing Addendum (DPA) — TEMPLATE

> THIS IS A TEMPLATE, NOT AN EXECUTED AGREEMENT. > It is provided as part of SiteRevive's SOC2-LITE evidence trail so a > prospective customer can review the shape of our data-processing commitments. > Bracketed […] fields are placeholders to be filled in and the document > reviewed by each party's counsel before signing. Nothing here is legal advice, > and an unsigned template creates no obligations.

_Template version: 2026-07-06_

---

1. Parties

This Addendum supplements the Agreement between the parties for the provision of the SiteRevive service (the "Service") and governs the Processor's Processing of Personal Data on behalf of the Controller.

2. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Subprocessor" have the meanings given in [applicable data-protection law, e.g. GDPR / UK GDPR / CCPA]. Terms not defined here take the meaning in the Agreement.

3. Scope and roles

4. Processor obligations

The Processor shall:

  1. Process Personal Data only per documented instructions;
  2. ensure persons authorized to process are bound by confidentiality;
  3. implement the technical and organizational measures described in Section 6;
  4. respect the conditions in Section 5 for engaging Subprocessors;
  5. assist the Controller, insofar as possible, with Data Subject requests and with the Controller's own security, breach-notification, and impact- assessment obligations;
  6. at the Controller's choice, delete or return Personal Data at the end of the Service (see Section 8); and
  7. make available information reasonably necessary to demonstrate compliance with this Addendum.

5. Subprocessors

6. Security measures

The Processor maintains technical and organizational measures appropriate to the risk, including those documented in the Processor's Encryption Inventory:

7. Personal Data breach

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's Personal Data, and provide information reasonably available to help the Controller meet its own notification obligations. Notification address: [Controller contact].

8. Return and deletion

On termination or expiry of the Service, and at the Controller's choice, the Processor will delete or return the Controller's Personal Data within [X days], and delete existing copies unless retention is required by law. The Service provides a self-serve per-workspace data export and a workspace deletion path to support this.

9. Audit

The Processor will make available the evidence artifacts referenced above and respond to reasonable written questionnaires. On-site or third-party audits, if any, are subject to [agreed scope, notice, frequency, and cost terms]. Note: SiteRevive's compliance posture is an evidence trail, not a SOC 2 certification; this Section does not represent that a certification exists.

10. International transfers

Where Processing involves transfer of Personal Data across borders, the parties will rely on [transfer mechanism, e.g. Standard Contractual Clauses] as applicable.

11. Term, order of precedence, governing law

---

Signatures _(to be completed on execution — this template is unsigned):_

| Controller | Processor | |---|---| | Name: […] | Name: […] | | Title: […] | Title: […] | | Date: […] | Date: […] |