# Data Protection Agreement

Version: 3.1, effective October 9, 2026 for new acceptances

Published October 9, 2026. Replaces Version 3.0, effective October 8, 2026. Version 3.1 changes Provider: the Polestar GRC business was assigned to Jonathan Prine, an individual doing business as Polestar GRC, who signs this DPA as Owner. Version 3.1 also replaces the assignment terms in Section 15.7, which now require a written assumption by any assignee and allow one further assignment, to an LLC of which Jonathan Prine is the sole member, only after at least thirty (30) days' notice and that company's signed assumption; states which documents AI features send without redaction (Section 2.5); corrects the Washington citations (Sections 2.6 and 4.1); adds impact assessments and California cybersecurity audits and risk assessments to Provider's assistance (Section 2.7); requires Customer's consent, and an annual cycle, for an assessment Provider arranges (Section 4.4); and corrects the audit log duration in Annex A.5. This version applies to every acceptance made on or after October 9, 2026. A Customer that accepted an earlier version stays on the version it accepted until it accepts this version (Section 14.5). For a customer that accepted an earlier version, Jonathan Prine became the Provider by assignment on the date stated in our notice of assignment. The assignment right in Section 15.7 applies to that customer only after an administrator accepts this version. Every earlier version is archived at polestargrc.com/legal/archive.

About this document. This Data Protection Agreement is Polestar GRC's contract for protecting the sensitive personal and health information your organization stores in the Service. It is for organizations that are not HIPAA covered entities or business associates with respect to that information: for example cash-pay clinics, wellness and counseling practices, pregnancy resource centers, and other organizations whose privacy obligations come from state consumer health data laws, state medical confidentiality laws, state consumer privacy and breach notification laws, and the Federal Trade Commission Act. If your organization is a HIPAA covered entity or business associate, do not accept this document; switch your organization to HIPAA mode and accept the Business Associate Agreement or Subcontractor Business Associate Agreement instead. This document binds both parties when your organization accepts it electronically. Questions or requests for changes: legal@polestargrc.com before you accept.

This Data Protection Agreement ("DPA") is entered into by and between:

- Customer: [CUSTOMER LEGAL NAME] ("Customer"). Business address: [CUSTOMER ADDRESS]. Customer is identified by its Polestar GRC organization account. Notices to Customer are delivered as described in Section 13, which does not depend on a mailing address being on file.
- Provider: Jonathan Prine, an individual doing business as Polestar GRC, 434 Kern St, Taft, CA 93268 ("Provider", "Polestar GRC" or "Polestar").

Effective Date. This DPA takes effect on the date Customer accepts it electronically, as shown in the Execution Record appended to the executed copy.

Relationship to the Agreement. This DPA supplements and is incorporated into the Polestar GRC Terms of Service, or any other written services agreement between the parties that expressly refers to this DPA (the "Agreement"). Section 9 of the Terms of Service also applies to Protected Data except where this DPA says something different. If this DPA and the Agreement conflict about Protected Data, this DPA controls.

## 1. Definitions

1.1 Protected Data means all Customer Data (as defined in the Agreement) that Provider processes on Customer's behalf through the Service and that is personal information, personal data, consumer health data, medical information, or other information about an identified or identifiable individual, including information in uploaded evidence files, incident records, training records and assessment answers.

1.2 Consumer Health Data has the meaning given in the Washington My Health My Data Act (RCW 19.373.010), Nevada's consumer health data law (NRS 603A.400 to 603A.550) and the Connecticut Data Privacy Act (Conn. Gen. Stat. 42-515), and includes any similar category under another state's law.

1.3 Medical Information has the meaning given in the California Confidentiality of Medical Information Act (Cal. Civ. Code 56 et seq., "CMIA").

1.4 Applicable Privacy Law means every law that applies to a party's processing of Protected Data, which may include: the laws in Section 1.2; state comprehensive consumer privacy laws and their service provider, processor and contractor requirements (including the California Consumer Privacy Act, Cal. Civ. Code 1798.100 et seq., and its regulations, Cal. Code Regs. tit. 11, 7000 et seq.); state medical confidentiality laws (including the CMIA and Tex. Health and Safety Code ch. 181); state data security and breach notification laws (including Cal. Civ. Code 1798.81.5 and 1798.82, RCW 19.255.010 and NRS 603A.010 to 603A.290); Section 5 of the Federal Trade Commission Act (15 U.S.C. 45); and the FTC Health Breach Notification Rule (16 C.F.R. Part 318) where it applies to Customer.

1.5 Breach of Security means the unauthorized acquisition of, or unauthorized access to, Protected Data that compromises its security, confidentiality or integrity, or any event that is a breach of security, breach of the security of the system or similar term under Applicable Privacy Law, whichever is broader. Good-faith access by Provider's workforce within the scope of their duties that does not result in further unauthorized use or disclosure is not a Breach of Security.

1.6 Discovery means the first day on which Provider knows of a Breach of Security, or would have known by exercising reasonable diligence. Provider is treated as knowing what any of its workforce members or Subprocessors (other than the person who committed the breach) knows.

1.7 Process and processing mean any operation performed on Protected Data, including collection, storage, use, disclosure and deletion.

1.8 Business Day means Monday through Friday, excluding United States federal holidays.

1.9 Subprocessor means a third party that Provider engages to process Protected Data on Provider's behalf. A Partner (Section 2.10) and any service Customer connects to the Service are not Subprocessors.

## 2. Roles, Instructions and Customer Responsibilities

2.1 Roles. Customer determines the purposes and means of processing Protected Data and is the regulated entity, controller or business under Applicable Privacy Law, or a processor acting for its own client. Provider processes Protected Data on Customer's behalf as Customer's processor, service provider or contractor. Determining the role is a matter of fact; Provider will not determine the purposes or means of processing Protected Data.

2.2 Instructions. Provider will process Protected Data only on Customer's documented instructions, which are this DPA, the Agreement, Annex A, Customer's configuration and use of the Service's features, and any other written instructions Customer gives that are consistent with the Agreement. Provider will process Protected Data for the business purposes in Annex A, to comply with law, and for no other purpose. Provider will notify Customer promptly if it believes an instruction violates Applicable Privacy Law, and may suspend the affected processing until Customer confirms or changes it.

2.3 Restrictions. Provider will not: (a) sell or share Protected Data, or disclose it to anyone in exchange for monetary or other valuable consideration; (b) use Protected Data for targeted advertising, cross-context behavioral advertising, profiling or marketing; (c) retain, use or disclose Protected Data for any purpose other than the business purposes in Annex A, or outside the direct business relationship with Customer; (d) combine Protected Data with personal information Provider receives from or on behalf of another person or collects from its own interactions with individuals, except as Cal. Code Regs. tit. 11, 7050 permits a service provider to do; (e) use Protected Data to train, fine-tune or improve any artificial intelligence or machine learning model, or permit a Subprocessor to do so; (f) use a geofence around any health care facility; or (g) process Protected Data in a way that would be prohibited to Customer under Applicable Privacy Law.

2.4 De-identified data. Provider may create de-identified or aggregated data from Protected Data so that it cannot reasonably be linked to an identified or identifiable individual or household, and may use that data only to operate, benchmark, secure and improve the Service. Provider publicly commits to maintain and use such data only in de-identified form, will take reasonable measures to ensure it cannot be associated with an individual, will not attempt to re-identify it, and will contractually require any recipient to do the same. Consumer Health Data and Medical Information are de-identified for this purpose only if they also meet the de-identification standard of the law that protects them.

2.5 AI features. Some features of the Service send text and, where Customer chooses to analyze a document, the document itself, to AI models (Anthropic Claude models on Amazon Bedrock, in AWS United States Regions). Provider uses AI models only through infrastructure whose terms prohibit storing prompts and outputs after the response, using them to train models, or making them available to the model developer. Before a request leaves Provider's systems, Provider applies automated redaction: in the in-app assistant, of patterns that look like Social Security numbers, dates of birth, phone numbers, email addresses, medical record numbers, payment card numbers, street addresses and personal names; in other AI features, of Social Security numbers, phone numbers, dates of birth, labeled medical record numbers and payment card numbers in text. In other AI features, names, email addresses and free-text descriptions are sent without redaction. Where Customer chooses to analyze a document, a PDF file or image is sent as uploaded, without redaction, and a text file (plain text, CSV, JSON or HTML) is sent after redaction of the patterns listed above for the in-app assistant. Redaction is pattern based and will miss some identifiers. Customer will not enter client-identifying information into AI features except in documents it chooses to analyze, and will not use AI features to analyze client records. AI features are optional and an administrator can choose not to use them.

2.6 Minimum necessary and access. Provider will limit access to Protected Data to those workforce members and Subprocessors who need it to perform the Service, and will access only the Protected Data needed for the task at hand (RCW 19.373.050(1)(a); NRS 603A.525(1)). Customer will upload only the Protected Data reasonably necessary for its compliance documentation and will not use the Service as a client record, scheduling or clinical system.

2.7 Statutory processor terms. In addition to the rest of this DPA, Provider will: (a) assist Customer, taking into account the nature of processing and the information available to Provider, by appropriate technical and organizational measures, in responding to individuals' requests, in meeting Customer's security and breach notification obligations, and in conducting and documenting data protection assessments and impact assessments, and in Customer's cybersecurity audits and risk assessments under Cal. Code Regs. tit. 11, 7050(h); (b) at the end of the Service, delete or return Protected Data as Section 9 provides, unless law requires retention; (c) on Customer's reasonable request, make available all information in Provider's possession necessary to demonstrate Provider's compliance with this DPA and Applicable Privacy Law; (d) engage Subprocessors only as Section 5 provides; and (e) allow and cooperate with reasonable assessments under Section 4.4. This Section 2.7 and Annex A are intended to satisfy Conn. Gen. Stat. 42-521, RCW 19.373.060, NRS 603A.530 and the processor contract requirements of the other state laws within Applicable Privacy Law.

2.8 California service provider terms. With respect to personal information subject to the California Consumer Privacy Act, Provider: (a) will comply with the obligations that apply to it under the CCPA and its regulations and provide the same level of privacy protection the CCPA requires of Customer; (b) grants Customer the right to take reasonable and appropriate steps to help ensure that Provider uses the personal information in a manner consistent with Customer's CCPA obligations, including the assessments in Section 4.4; (c) will notify Customer within five (5) Business Days if Provider determines that it can no longer meet its obligations under the CCPA; and (d) grants Customer the right, on notice, including after a notice under clause (c), to take reasonable and appropriate steps to stop and remediate unauthorized use of the personal information, including by suspending the affected processing or exporting and deleting the data. Provider certifies that it understands the restrictions in Sections 2.3 and 2.8 and will comply with them (Cal. Civ. Code 1798.100(d), 1798.140(ag); Cal. Code Regs. tit. 11, 7051(a)).

2.9 Customer responsibilities. Customer is responsible for its own obligations as a regulated entity, controller or business, including: (a) publishing any consumer health data privacy policy or privacy notice the law requires (for example RCW 19.373.020 and NRS 603A.495); (b) obtaining any consent the law requires to collect Consumer Health Data and to disclose it to Provider for processing (for example RCW 19.373.030 and NRS 603A.500), and any authorization CMIA requires before disclosing Medical Information other than as Cal. Civ. Code 56.10(c)(3) permits; (c) responding to individuals' requests; and (d) the accuracy of the information it gives Provider about its HIPAA status (Section 10). Customer represents that its disclosure of Protected Data to Provider for processing under this DPA is lawful.

2.10 Partners. If a managed service provider or other partner ("Partner") created or manages Customer's workspace, the Partner acts for Customer under Customer's own agreement with it, and not as Provider's Subprocessor. A Partner's users can see Customer Data only if Customer's workspace gives them access, and Customer is responsible for the Partner's access and for having a processor contract with the Partner that Applicable Privacy Law requires. A Partner, and anyone whose access to Customer's workspace comes through a Partner, may not accept this DPA for Customer, and the Service refuses such an acceptance; a Customer administrator must accept it under Section 17. Partner features are offered only under a Partner Agreement (Terms of Service Section 26). Customer will review the compliance mode and HIPAA role the Partner selected and correct them before storing Protected Data.

## 3. Confidentiality

3.1 Provider will hold Protected Data in confidence, will ensure that each person who processes Protected Data for Provider is subject to a written or statutory duty of confidentiality and completes privacy and security training before access and at least annually, and will apply sanctions for violations. These obligations continue for as long as Provider or any Subprocessor holds Protected Data.

3.2 Medical Information. Where Protected Data includes Medical Information disclosed to Provider by a provider of health care under Cal. Civ. Code 56.10(c)(3) or a comparable provision, Provider will use it only to perform the Service for Customer and will not further disclose it in any way that would violate the CMIA.

## 4. Security

4.1 Program. Provider maintains a written information security program with administrative, physical and technical safeguards appropriate to the sensitivity of Protected Data, designed to meet the security requirements of Applicable Privacy Law, including RCW 19.373.050(1)(b), NRS 603A.525(2), NRS 603A.210 and Cal. Civ. Code 1798.81.5. Provider's program is built to the standards of the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), even though HIPAA does not apply to Customer, and applies to Customer's Protected Data the same safeguards it applies to protected health information of HIPAA-regulated customers.

4.2 Specific controls. Provider maintains: encryption of Protected Data in transit (TLS 1.2 or higher) and at rest (AES-256); organization-scoped and role-based access controls enforced on every application procedure; multi-factor authentication available to all users, with organization-wide enforcement available to Customer's administrators; brute-force lockouts; audit logging protected so that application users, including Customer's own administrators, cannot alter or delete entries; time-limited, signed download links for uploaded files; an annual documented risk assessment; and a documented incident response plan tested at least annually.

4.3 Data location. Provider stores and processes Protected Data only in the United States and will not transfer Protected Data outside the United States without Customer's prior written consent.

4.4 Assurances and assessments. On Customer's written request, not more than once in any twelve (12) month period unless following a Breach of Security or a notice under Section 2.8(c), or as a regulator requires, Provider will provide a description of its security program, a summary of its most recent risk assessment, a completed security questionnaire of reasonable length, and copies of any third-party security assessments or certifications it holds. If Customer reasonably determines that this material is not enough to assess Provider's compliance, Customer may, at its expense, on at least thirty (30) days' written notice, during business hours and without access to other customers' data, have a qualified assessor bound by confidentiality assess Provider's policies and technical and organizational measures; alternatively, with Customer's consent, Provider may, at its expense and at least annually, arrange for a qualified and independent assessor to conduct that assessment using an accepted control standard and give Customer the report. Customer will treat this material as Provider's confidential information.

## 5. Subprocessors

5.1 Provider may engage Subprocessors to help provide the Service. The current list of Subprocessors that may process Protected Data, with each one's service and location, is published in the Polestar GRC Privacy Policy. Before a Subprocessor processes Protected Data, Provider will bind it by written contract to obligations that are at least as protective of Protected Data as those in this DPA with respect to the services it performs.

5.2 Provider will give Customer at least thirty (30) days' notice by email and in-product notice before a new Subprocessor processes Protected Data. If Customer objects on reasonable grounds related to the protection of Protected Data within that period and the parties cannot resolve the objection, Customer may terminate the Agreement and this DPA on written notice and Provider will refund any prepaid fees for the period after termination.

5.3 Provider remains responsible to Customer for its Subprocessors' processing of Protected Data.

## 6. Breach of Security

6.1 Notice. Provider will notify Customer of a Breach of Security, or of facts that give Provider reason to believe that Protected Data was or may have been acquired or accessed without authorization, without unreasonable delay, immediately following Discovery where Applicable Privacy Law requires that, and in no case later than seven (7) calendar days after Discovery. Provider will not delay notice to finish its investigation. The notice will include, to the extent then known: what happened and when; the categories of Protected Data and the number and states of residence of individuals involved; the steps Provider has taken and plans to take to investigate, contain and mitigate; and a contact for further information. Provider will supplement the notice promptly as information becomes available, will give Customer the information it needs for notices due under Applicable Privacy Law within the time needed to meet them, and will provide a written summary when its investigation is complete and in any event within twenty (20) calendar days after the initial notice. Provider delivers each notice under this Section 6 inside the Service to Customer's administrators, with an email to the contacts in Section 13.1 that says a notice is waiting and does not itself contain Protected Data, and asks the recipient to confirm receipt. The seven (7) day period is an outer limit, not a target, and does not extend any shorter period that Applicable Privacy Law requires of Provider.

6.2 Law enforcement delay. If a law enforcement agency tells Provider in writing that notice to Customer would impede a criminal investigation, Provider may delay notice for the period the agency specifies, as the law permits.

6.3 Customer controls notifications. Customer decides whether and how to notify individuals, regulators and others under Applicable Privacy Law. Provider will not notify individuals or regulators of a Breach of Security involving Protected Data without Customer's consent unless the law requires Provider to do so. Customer is responsible for meeting its own deadlines, including deadlines as short as thirty (30) calendar days for notice to individuals (for example RCW 19.255.010(8) and Cal. Civ. Code 1798.82), and Provider's cooperation under Section 6.1 is designed so Customer can meet them.

6.4 FTC Health Breach Notification Rule. If Customer is a vendor of personal health records or a PHR related entity under 16 C.F.R. Part 318, Customer designates the Privacy Officer recorded in its organization settings as the official to receive notice under 16 C.F.R. 318.3(b). Provider will give that official the notice under Section 6.1, including the identification of each affected individual known to Provider, and will obtain the official's acknowledgment of receipt (a reply email is sufficient).

6.5 Costs. To the extent a Breach of Security is caused by Provider's or its Subprocessors' breach of this DPA, Provider will reimburse Customer's reasonable, documented, out-of-pocket costs of the notifications Applicable Privacy Law requires, subject to Section 11.

6.6 Unsuccessful attempts. Provider does not report routine unsuccessful attacks, such as port scans, blocked malware and failed log-in attempts, that do not result in unauthorized access to Protected Data.

## 7. Individual Rights

7.1 Where Applicable Privacy Law gives individuals rights to access, correct, delete or obtain a copy of their Protected Data, to appeal, or to withdraw consent, Customer is responsible for responding. Provider will, within ten (10) Business Days after Customer's written request, provide the Protected Data, make the correction or carry out the deletion Customer directs, and will instruct its Subprocessors to do the same. Customer may also use the Service's export and deletion features at any time.

7.2 Where the Washington My Health My Data Act (RCW 19.373.040), NRS 603A.515 or a similar law requires Customer to pass a deletion request to its processors, Customer may do so through the Service's deletion features or by written request. Provider will delete the Protected Data from production systems within thirty (30) days and from backups as they rotate within ninety (90) days, which is within the six-month limit for archived and backup systems in RCW 19.373.040, and will not restore deleted data from a backup except for disaster recovery, in which case it will re-delete it.

7.3 If an individual contacts Provider directly about Protected Data, Provider will forward the request to Customer within five (5) Business Days and will not respond substantively except as Customer directs or as required by law.

## 8. Legal Process and Government Requests

8.1 Provider may disclose Protected Data when required by law. Unless legally prohibited, Provider will notify Customer before complying with a subpoena, court order, warrant or other legal demand for Protected Data and will give Customer a reasonable opportunity to object or seek a protective order. Provider will not voluntarily disclose Protected Data to a government authority, will first try to redirect the requester to Customer, and will disclose only the Protected Data the demand requires.

8.2 Reproductive and gender-affirming care. Provider will not disclose Protected Data that relates to a person seeking, obtaining, providing or facilitating abortion, contraception or gender-affirming care, or to a person allowing a child to receive gender-affirming care, in response to a subpoena, warrant, request or inquiry that is based on another state's law that interferes with rights protected by California law, or for the enforcement of such a law, to the extent California law (including Cal. Civ. Code 56.108 and 56.109) would prohibit Customer from making that disclosure, or to the extent the law of Customer's state contains a comparable prohibition. Provider will notify Customer of any such demand unless prohibited by law, and will contest it where Provider reasonably can.

## 9. Return and Deletion

On termination or expiration of the Agreement for any reason, Customer may export its Protected Data using the Service's export features for thirty (30) days (the "Export Window"). After the Export Window, Provider will delete all Protected Data it holds on Customer's behalf, including Protected Data held by Subprocessors, using methods consistent with NIST Special Publication 800-88, except where retention is required by law or a litigation hold. Deletion from production systems will be complete within thirty (30) days after the Export Window and from encrypted backups within ninety (90) days after the Export Window. Customer may also direct deletion at any time from the Data Deletion page. Provider will certify deletion in writing on request. Audit log entries are kept for six (6) years from creation, as Section 18.5 of the Terms of Service describes, and are then purged; they contain only the minimum Protected Data needed for the audit trail and remain protected by this DPA until deleted.

## 10. HIPAA Status

10.1 Customer represents that, with respect to the data it places in the Service, it is not a covered entity or business associate under HIPAA (45 C.F.R. 160.103). Provider relies on this representation in offering this DPA rather than a business associate agreement.

10.2 If Customer is or becomes a HIPAA covered entity or business associate, or intends to place protected health information governed by HIPAA in the Service, Customer will promptly switch its organization to HIPAA mode and accept the applicable Business Associate Agreement or Subcontractor Business Associate Agreement.

10.3 If protected health information governed by HIPAA is placed in the Service while this DPA is in effect, then, from the time Provider first received it until Customer accepts the applicable agreement or removes the information: (a) the Business Associate Agreement published at polestargrc.com/legal/hipaa-baa (if Customer is a covered entity) or the Subcontractor Business Associate Agreement published at polestargrc.com/legal/hipaa-subcontractor-baa (if Customer is a business associate), in the version then current, is incorporated into this DPA and governs that information; and (b) for that information, the BAA controls over this DPA where they differ. Customer will accept the applicable agreement or remove the information within thirty (30) days after either party learns that this Section 10.3 applies.

10.4 Nothing in this DPA is a representation by Provider that Customer is or is not subject to HIPAA.

## 11. Liability

The limitations and exclusions of liability in the Agreement apply to this DPA except as this Section 11 modifies them. For purposes of the Agreement, the following are direct damages when caused by a party's breach of this DPA: the reasonable, documented costs of investigating a Breach of Security, including forensic services; the costs of notifying individuals and regulators as required by Applicable Privacy Law; and the cost of credit monitoring or identity protection services where required by law or reasonably necessary to mitigate harm to individuals.

Liability relating to Protected Data under this DPA is subject to a separate cap equal to the greater of (a) two (2) times the fees paid or payable by Customer in the twelve (12) months before the event giving rise to the claim, or (b) fifty thousand US dollars (USD 50,000), which becomes one hundred thousand US dollars (USD 100,000) for an event that occurs on a date when Provider carries cyber liability insurance with an aggregate limit of two million US dollars (USD 2,000,000) or more. This cap applies in addition to the cap in Section 20.2 of the Terms of Service. Provider states the insurance it carries in Section 11.5 of its published Business Associate Agreement and will provide a certificate of insurance on request. Nothing in this Section 11 limits liability for a party's fraud, gross negligence or willful misconduct, or liability that cannot be limited under applicable law.

## 12. Governing Law

This DPA is governed by the law chosen in Section 23 of the Agreement, and the venue and dispute provisions of the Agreement (Sections 22 and 23 of the Terms of Service) apply to it. The parties will interpret this DPA so as to comply with Applicable Privacy Law. Nothing in this DPA prevents either party from complying with Applicable Privacy Law in the state where Customer operates or where the individuals whose Protected Data is processed reside, and the parties will cooperate so that each can do so.

## 13. Notices

13.1 To Customer. Provider gives notices under this DPA by in-product notice and by email to the Privacy Officer and Security Officer contacts recorded in Customer's organization settings and to the organization account owner's email address. A notice that contains Protected Data is delivered inside the Service, and the email says only that a notice is waiting. Notice is effective when sent, unless Provider receives an automated delivery failure, in which case Provider will attempt delivery to another administrator on the account and, for a notice under Section 6, by telephone to any number recorded for those contacts. No mailing address is required. Customer is responsible for keeping these contacts current, and for making sure they are Customer's own staff and not only a Partner's.

13.2 To Provider. Customer gives notices under this DPA by email to legal@polestargrc.com, and for security incidents also to security@polestargrc.com or through the in-product incident report, with a copy by mail to Polestar GRC, Attn: Jonathan Prine, 434 Kern St, Taft, CA 93268 for notices of breach or termination. Customer will not include Protected Data in an email notice. Notice is effective when received.

## 14. Amendments and Versions

14.1 Provider may publish a new version of this DPA to comply with changes in Applicable Privacy Law, effective on the compliance date of the change or thirty (30) days after notice to Customer, whichever is later, unless the law requires an earlier date.

14.2 Provider may otherwise publish a new version of this DPA with at least thirty (30) days' notice by email and in-product notice. If the new version does not reduce Provider's obligations or expand its permitted processing of Protected Data, Customer's continued use of the Service after the stated effective date constitutes acceptance. If it does, the new version takes effect for Customer only when an authorized representative of Customer accepts it electronically, and until then the version Customer last accepted remains in effect.

14.3 Each version of this DPA is identified by a version number and a SHA-256 fingerprint of its published text. The executed copy of each version Customer accepts, with its Execution Record, is retained in Customer's Vendor Agreements tracker, and the person who accepted it is emailed a link to it.

14.4 A written amendment signed by both parties, including by electronic signature, prevails over this published text for the parties who signed it.

14.5 A version of this DPA that Customer accepted before October 9, 2026 remains in effect for Customer until Customer accepts this version or the Agreement terminates. Section 14.2 does not make Customer's continued use of the Service an acceptance of this version.

## 15. Miscellaneous

15.1 Interpretation. Any ambiguity in this DPA will be resolved to permit compliance with Applicable Privacy Law. Headings are for convenience only.

15.2 No third-party beneficiaries. Nothing in this DPA confers any right, remedy or claim on any person other than the parties.

15.3 Independent contractors. The parties are independent contractors. This DPA does not create a partnership, joint venture or agency relationship.

15.4 Severability. If any provision of this DPA is held unenforceable, the remaining provisions remain in effect and the unenforceable provision will be modified to the minimum extent needed to make it enforceable.

15.5 Survival. Sections 2, 3, 6, 7, 8, 9, 10.3, 11 and 12 survive termination for as long as Provider or any Subprocessor holds Protected Data, and Sections 11 and 12 survive indefinitely.

15.6 Electronic records and signatures. The parties agree that this DPA is a written contract for purposes of Applicable Privacy Law, that it may be executed by electronic signature and electronic acceptance under the federal Electronic Signatures in Global and National Commerce Act (15 U.S.C. 7001 et seq.) and the applicable state Uniform Electronic Transactions Act (including Cal. Civ. Code 1633.1 et seq.), and that an electronic copy of this DPA with its Execution Record is admissible as an original.

15.7 Assignment. Neither party may assign this DPA except together with a permitted assignment of the Agreement, under the assignment terms of the Agreement. Any permitted assignee of Provider must assume this DPA in writing, and Provider will give Customer notice of the assignment under Section 13.1. In addition, Provider may assign this DPA, together with the Agreement, to Polestar GRC, LLC, a limited liability company of which Jonathan Prine is the sole member (the "LLC"), without Customer's consent, on these terms. (a) Provider will give Customer at least thirty (30) days' notice by email and in-product notice before the assignment takes effect, stating the LLC's exact legal name, its state of organization and entity number, and the effective date. (b) Before the effective date, the LLC will assume this DPA and the Agreement in a writing signed for the LLC, and will have in place the written contracts Section 5.1 requires with each Subprocessor. (c) On the effective date, the Service will give Customer an updated executed copy of this DPA naming the LLC. (d) The Service, the locations where Protected Data is stored and the Subprocessors will not change because of the assignment. (e) Jonathan Prine remains responsible for obligations that arose before the effective date.

## 16. Execution by Provider

Provider has executed this DPA by the electronic signature of Jonathan Prine, an individual doing business as Polestar GRC, who adopted the typed signature below with the intent to sign each published version of this DPA, including this version. That signature applies to every copy of this version accepted by a customer under Section 17. The published text of this version carries the SHA-256 fingerprint stated in the Execution Record. A countersigned copy of a customer's executed copy is available on request from legal@polestargrc.com.

Polestar GRC, by Jonathan Prine, Owner

Electronically signed on October 9, 2026 for Version 3.1.

## 17. Acceptance by Customer

Customer accepts this DPA when an individual who is an administrator of Customer's organization account, and who represents that he or she is authorized to bind Customer, enters Customer's legal name, his or her own name and title, confirms that authority, and selects the acceptance control in the Service. Acceptance happens only in the Service. A Partner user may not accept this DPA for Customer (Section 2.10). Provider records the acceptance in an Execution Record that states the legal name of Customer as entered by the person who accepted, Customer's organization account (its name and account number), the person who accepted, that person's title and account email address, the confirmation of authority, the date and time of acceptance (UTC), the network address and browser from which acceptance was made, the method of acceptance (in the Service), the version accepted, and the SHA-256 fingerprint of the published text that was displayed to the person who accepted. The Execution Record is appended to the executed copy, which is retained as a PDF in Customer's Vendor Agreements tracker, where Customer's administrators can download it; the person who accepted and the account owner are emailed a link to it, and the email contains no Protected Data.

## Annex A. Description of Processing

A.1 Subject matter and nature. Hosting, storage, organization, analysis, display, transmission, export and deletion of Customer's compliance program records through the Service, including AI-assisted drafting and analysis that Customer chooses to use.

A.2 Business purposes. Providing, supporting, securing and maintaining the Service for Customer; generating the reports, packages and exports Customer requests; sending the notifications Customer configures; detecting and preventing security incidents; debugging to identify and repair errors; and complying with law.

A.3 Categories of individuals. Customer's workforce members, contractors and volunteers; Customer's clients, patients or participants; Customer's vendors and their contacts; auditors Customer invites.

A.4 Types of Protected Data. Identifiers and contact details; workforce training and acknowledgment records; information in incident, breach and risk records; information in evidence files and assessment answers Customer uploads or enters, which may include Consumer Health Data, Medical Information and information about reproductive or sexual health care or gender-affirming care; account and access logs.

A.5 Duration. For the term of the Agreement, then the Export Window and the deletion periods in Section 9, and for audit log entries the six-year retention period in Section 9.

A.6 Subprocessors. As listed in the Privacy Policy on the date of processing, subject to Section 5.

A.7 Location. United States only (Section 4.3).

## Signatures

Customer: [CUSTOMER LEGAL NAME]

Accepted electronically as described in Section 17. The Execution Record below forms part of this DPA.

---

Earlier versions of this Data Protection Agreement: [Version 3.0, effective October 8, 2026](https://polestargrc.com/legal/archive/dpa-state-mode-v3.0) and [Version 2.0, effective October 1, 2026](https://polestargrc.com/legal/archive/dpa-state-mode-v2.0). Every version of our legal documents is listed at [polestargrc.com/legal/archive](https://polestargrc.com/legal/archive).
