Think Smart Inc.

Data Processing Addendum (GDPR)

Data-protection terms for customers subject to the GDPR.

Last updated: December 9, 2025

← All agreements
Draft — pending review. This document is a working draft adapted for Think Smart Group Inc. and should be confirmed by legal counsel before launch.

This Data Processing Addendum (“DPA”) supplements and is incorporated into the Master Service Agreement (“MSA”) between Think Smart Group, Inc. (“TSI”) and the Customer. This DPA applies where the General Data Protection Regulation (“GDPR”), UK GDPR, or California Consumer Privacy Acts (CCPA/CPRA) apply to personal data processed by TSI in connection with the Services. Capitalized terms not defined in this DPA have the meanings given in the MSA and incorporated policies.

1. Processing Instructions

TSI will process personal data only on documented instructions from Customer/ISV as set out in the MSA, this DPA, and Order Forms, including for provisioning, operating, securing, supporting, and improving the Services.

2. Confidentiality & Personnel

TSI will ensure personnel with access to personal data are bound by confidentiality and receive appropriate training.

3. Security Measures

TSI will implement the technical and organizational measures described in the Security Annex (as updated occasionally) appropriate to the risk, including access controls, encryption in transit/at rest where applicable, logging/monitoring, backup, and incident response.

4. Subprocessors

Customer/ISV authorizes TSI to use subprocessors for delivery of the Services. TSI will impose data protection obligations on subprocessors, remain responsible for their performance, and provide a subprocessor list or mechanism for notice/updates. For GDPR, Customer/ISV may object on reasonable grounds per the mechanism provided.

5. International Transfers

Where personal data is transferred outside the EEA/UK to a country without an adequacy decision, the parties agree the applicable Standard Contractual Clauses (SCCs) are incorporated by reference (Module 2: Controller→Processor). TSI will implement supplementary measures as required by law.

6. Data Subject Requests

TSI will assist Customer/ISV by appropriate technical and organizational measures to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection) where feasible and legally permissible.

7. Personal Data Breach

TSI will notify Customer/ISV without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting Customer/ISV personal data, providing details as they become available.

8. Audits & Reports

Upon reasonable written request and subject to confidentiality and security requirements, TSI will provide Customer/ISV with information necessary to demonstrate compliance with this DPA. This may include independent third-party audit reports or certifications (e.g., SOC 2, ISO 27001). Formal audits or inspections at TSI facilities may only occur if required by applicable law or a competent supervisory authority, and only after the foregoing information has been provided and found insufficient.

9. Return & Deletion

Upon termination, TSI will return or delete personal data per the Data Retention & Deletion Addendum, unless retention is required by law.

10. CCPA/CPRA Service Provider Terms

TSI will not: (a) sell or share personal information; (b) retain, use, or disclose personal information for purposes other than providing the Services or as permitted by law; or (c) combine personal information with personal information obtained from other sources except as permitted to provide the Services.

11. Governing Terms

This DPA is governed by the MSA. In case of conflict between the MSA and this DPA regarding data protection, this DPA controls to the extent of the conflict.

This DPA is accepted and agreed to by Customer as of the Effective Date of the Master Service Agreement into which it is incorporated.

Questions?

Prefer to ask a person?

For questions about this document or about Think Smart, reach out and we will help.