Data Processing Addendum

Last Update:

October 3, 2026

Projection Genie Data Processing Addendum

Version 1.0
Effective Date: October 3, 2026

This Data Processing Addendum (“DPA”) forms part of the Projection Genie Customer Agreement or other written agreement governing Customer’s use of the Services (the “Agreement”) between Projection Genie Inc. (“Projection Genie”) and the customer identified in the Agreement (“Customer”).

This DPA applies to the extent Projection Genie Processes Customer Personal Data on behalf of Customer in connection with the Services.

If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA will control to the extent of the conflict. If the Standard Contractual Clauses or another legally required international data transfer mechanism applies and conflicts with this DPA, the applicable transfer mechanism will control with respect to that conflict.

1. Definitions

1.1 “Applicable Data Protection Law”

means any law or regulation applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable:

(a) Regulation (EU) 2016/679, the General Data Protection Regulation (“EU GDPR”);

(b) the EU GDPR as incorporated into the laws of the United Kingdom and the United Kingdom Data Protection Act 2018 (“UK GDPR”);

(c) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act and implementing regulations (“CCPA”); and

(d) other applicable privacy or data protection laws imposing processor, service provider, or contractor obligations substantially similar to those addressed by this DPA.

1.2 “Controller”

means the entity that determines the purposes and means of Processing Personal Data, including a “business” where that term is used under the CCPA.

1.3 “Customer Personal Data”

means Personal Data contained in information submitted to, stored within, obtained by, or otherwise Processed through the Services by Projection Genie on behalf of Customer.

Customer Personal Data does not include Personal Data for which Projection Genie determines the purposes and means of Processing independently of Customer, such as certain account administration, billing, security, website, or business-operation information processed by Projection Genie as a Controller.

1.4 “Data Subject”

means an identified or identifiable natural person to whom Customer Personal Data relates, or the equivalent term under Applicable Data Protection Law.

1.5 “Personal Data”

means any information relating to an identified or identifiable natural person, household, or other protected person or unit to the extent such information is protected as “personal data,” “personal information,” or a substantially similar term under Applicable Data Protection Law.

1.6 “Personal Data Breach”

means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Projection Genie.

1.7 “Process,” “Processing,” and “Processed”

have the meanings provided under Applicable Data Protection Law.

1.8 “Processor”

means an entity that Processes Personal Data on behalf of a Controller and includes a “service provider” or “contractor” where applicable under the CCPA.

1.9 “Services”

means the Offerings and other services provided by Projection Genie under the Agreement.

1.10 “Subprocessor”

means a third party engaged by Projection Genie to Process Customer Personal Data on behalf of Customer in connection with the Services.

1.11 “Connected Service”

has the meaning provided in the Agreement and includes customer-selected third-party applications, artificial intelligence systems, assistants, agents, or other services connected to the Services through an API, Model Context Protocol (“MCP”), integration, or other supported interface.

2. Roles of the Parties

2.1 Customer as Controller

Where Customer determines the purposes and means of Processing Customer Personal Data, Customer is the Controller and Projection Genie is the Processor.

2.2 Customer as Processor

Where Customer Processes Personal Data on behalf of another Controller, Customer is a Processor and Projection Genie acts as Customer’s Subprocessor with respect to that Personal Data.

Customer represents that it has been authorized by the applicable Controller to appoint Projection Genie as a Subprocessor and to provide the instructions contained in this DPA and the Agreement.

2.3 Projection Genie as Independent Controller

Nothing in this DPA applies to Processing activities for which Projection Genie acts as an independent Controller. Such Processing is governed by Projection Genie’s Privacy Policy and applicable law.

3. Customer Instructions and Responsibilities

3.1 Documented Instructions

Projection Genie will Process Customer Personal Data only:

(a) in accordance with Customer’s documented instructions;

(b) as necessary to provide, secure, maintain, support, and improve the Services consistent with the Agreement;

(c) as initiated or authorized by Customer or its authorized Users through use of the Services, including supported integrations and Connected Services; or

(d) as required by applicable law.

The Agreement, this DPA, Customer’s configuration and use of the Services, requests made by Customer or its authorized Users, and other written instructions agreed by the Parties constitute Customer’s documented instructions.

3.2 Legally Required Processing

If Projection Genie is required by applicable law to Process Customer Personal Data contrary to or beyond Customer’s documented instructions, Projection Genie will notify Customer of that legal requirement before Processing unless applicable law prohibits such notice.

3.3 Unlawful Instructions

Projection Genie will inform Customer if, in Projection Genie’s reasonable opinion, a Customer instruction violates Applicable Data Protection Law. Projection Genie may suspend performance of the affected instruction while the Parties work in good faith to resolve the issue.

3.4 Customer Responsibilities

Customer is responsible for:

(a) complying with Applicable Data Protection Law in connection with its collection, use, disclosure, and instructions regarding Customer Personal Data;

(b) providing any required notices to Data Subjects;

(c) establishing an appropriate legal basis for Processing;

(d) obtaining any required consents, permissions, or authorizations;

(e) ensuring that Customer has authority to provide Customer Personal Data to Projection Genie;

(f) configuring and using the Services in a manner consistent with Applicable Data Protection Law; and

(g) determining whether the Services are appropriate for the types of Personal Data Customer chooses to Process.

4. Confidentiality

Projection Genie will ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and are permitted to access Customer Personal Data only to the extent reasonably necessary to perform their responsibilities.

Projection Genie will limit access to Customer Personal Data to personnel, contractors, and Subprocessors with a legitimate need for such access in connection with providing or supporting the Services.

5. Security

5.1 Security Measures

Taking into account the state of the art, costs of implementation, nature, scope, context and purposes of Processing, and the risks to the rights and freedoms of individuals, Projection Genie will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Projection Genie’s current technical and organizational measures are described in Schedule 2.

5.2 Security Changes

Projection Genie may modify its technical and organizational measures from time to time provided that such modifications do not materially reduce the overall level of protection provided to Customer Personal Data during the applicable term of the Services.

5.3 Customer Security Responsibilities

Customer is responsible for securely configuring and administering its accounts, Users, credentials, permissions, integrations, Connected Services, and other settings under Customer’s control.

6. Subprocessors

6.1 General Authorization

Customer provides Projection Genie with general written authorization to engage Subprocessors to Process Customer Personal Data in connection with providing the Services.

Projection Genie’s current Subprocessors are identified on Projection Genie’s GDPR page at /legal/gdpr or another location designated by Projection Genie for its current Subprocessor list.

6.2 Subprocessor Obligations

Projection Genie will enter into a written agreement with each Subprocessor that imposes data protection obligations appropriate to the Processing performed by that Subprocessor and requiring protection of Customer Personal Data to a standard substantially consistent with Projection Genie’s applicable obligations under this DPA.

Projection Genie remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.

6.3 Changes to Subprocessors

Projection Genie will provide Customer notice of any intended addition or replacement of a Subprocessor that will Process Customer Personal Data. Notice may be provided by email, through the Services, through Customer’s account, or through another reasonable electronic method.

Where reasonably practicable, Projection Genie will provide such notice at least fifteen (15) days before the new Subprocessor begins Processing Customer Personal Data.

6.4 Objections

Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice to Projection Genie during the applicable notice period and explaining the basis of the objection.

The Parties will work in good faith to address the objection. If the Parties cannot reasonably resolve the objection and Projection Genie cannot provide the applicable Services without using the Subprocessor, Customer may discontinue the affected portion of the Services in accordance with the Agreement.

7. Data Subject Requests

7.1 Customer Responsibility

As between Customer and Projection Genie, Customer is responsible for responding to requests from Data Subjects seeking to exercise rights under Applicable Data Protection Law.

7.2 Projection Genie Assistance

Taking into account the nature of the Processing, Projection Genie will provide reasonable assistance to Customer through appropriate technical or organizational measures, where possible, to enable Customer to respond to applicable Data Subject requests.

Such requests may include, where applicable, requests for access, correction, deletion, restriction, objection, or portability.

7.3 Requests Received Directly

If Projection Genie receives a Data Subject request relating primarily to Customer Personal Data that Projection Genie Processes solely on behalf of Customer, Projection Genie may direct the requester to Customer and, where legally permitted, notify Customer of the request.

Projection Genie will not independently respond to such a request except as instructed by Customer or required by applicable law.

8. Personal Data Breaches

8.1 Notification

Projection Genie will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 Information Provided

To the extent reasonably available, Projection Genie’s notification will include information necessary to assist Customer in satisfying applicable breach notification obligations, which may include:

(a) the nature of the Personal Data Breach;

(b) the categories of Customer Personal Data affected;

(c) the categories or approximate number of affected Data Subjects, where known;

(d) the likely consequences of the Personal Data Breach;

(e) measures taken or proposed by Projection Genie to address or mitigate the Personal Data Breach; and

(f) a contact through which Customer may request additional information.

Where all information is not immediately available, Projection Genie may provide information in phases as it becomes available.

8.3 No Admission

Notification of a Personal Data Breach does not constitute an acknowledgment by Projection Genie of fault, liability, or violation of Applicable Data Protection Law.

9. Compliance Assistance

Taking into account the nature of the Processing and information available to Projection Genie, Projection Genie will provide reasonable assistance to Customer with Customer’s obligations under Applicable Data Protection Law concerning:

(a) security of Processing;

(b) Personal Data Breach notifications;

(c) data protection impact assessments;

(d) prior consultation with supervisory authorities, where required; and

(e) other obligations for which processor assistance is expressly required by Applicable Data Protection Law.

Customer remains responsible for determining whether a data protection impact assessment, transfer assessment, consultation, notice, consent, or other compliance measure is required for Customer’s Processing.

10. Return and Deletion of Customer Personal Data

10.1 During the Agreement

Customer may access, retrieve, export, disconnect, or delete certain Customer Personal Data using functionality made available through the Services.

Retention periods associated with particular integrations or features may also be described in Projection Genie’s Privacy Policy or applicable product documentation.

10.2 Termination

Following termination or expiration of the Services, and subject to Customer’s written instructions, Projection Genie will delete or return Customer Personal Data to the extent required by Applicable Data Protection Law.

If Customer does not provide contrary instructions within thirty (30) days following termination, Projection Genie may delete Customer Personal Data in accordance with its standard retention and deletion procedures.

10.3 Exceptions and Backups

Projection Genie may retain Customer Personal Data where and for so long as required by applicable law.

Customer Personal Data may also remain temporarily in backup or disaster-recovery systems until overwritten or deleted through Projection Genie’s ordinary backup retention cycle. During that period, the retained Customer Personal Data will remain protected under this DPA and will not be Processed for other purposes except as necessary for security, recovery, legal compliance, or maintenance of the backup systems.

11. Audits and Compliance Information

11.1 Information

Upon reasonable written request, Projection Genie will make available to Customer information reasonably necessary to demonstrate compliance with the processor obligations applicable to Projection Genie under this DPA.

11.2 Audits

Where required by Applicable Data Protection Law, Customer may conduct an audit of Projection Genie’s compliance with this DPA, subject to the following conditions:

(a) Customer will first use available security, compliance, contractual, and audit information supplied by Projection Genie where such information reasonably satisfies Customer’s audit requirement;

(b) any additional audit will generally be limited to once in any twelve-month period unless a Personal Data Breach, regulatory requirement, or reasonable evidence of material noncompliance justifies an additional audit;

(c) Customer will provide reasonable advance written notice;

(d) the audit will occur during normal business hours and will not unreasonably interfere with Projection Genie’s business operations;

(e) the audit will be conducted by Customer or a qualified independent auditor that is not a competitor of Projection Genie and is bound by appropriate confidentiality obligations;

(f) the audit will not provide Customer access to information concerning other Projection Genie customers or to information that would compromise the security of Projection Genie’s systems; and

(g) Customer will bear its reasonable audit costs unless the audit establishes material noncompliance by Projection Genie with this DPA.

Nothing in this Section limits audit rights that cannot lawfully be restricted under Applicable Data Protection Law.

12. International Transfers

12.1 General

Projection Genie is located in the United States. Customer Personal Data may therefore be transferred to or Processed in the United States or other countries outside the country in which Customer or the applicable Data Subject is located.

Where Applicable Data Protection Law requires a specific mechanism for an international transfer, the Parties will rely on an applicable adequacy decision, approved standard contractual clauses, or another legally permitted transfer mechanism.

12.2 European Economic Area Transfers

Where Customer Personal Data subject to the EU GDPR is transferred to Projection Genie in a country not recognized as providing an adequate level of protection and another lawful transfer mechanism does not apply, the Standard Contractual Clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of June 4, 2021 (“EU SCCs”) are incorporated into and form part of this DPA.

The EU SCCs will apply as follows:

(a) Module Two (Controller to Processor) applies where Customer is a Controller and Projection Genie is a Processor;

(b) Module Three (Processor to Processor) applies where Customer acts as a Processor on behalf of another Controller and Projection Genie acts as Customer’s Subprocessor;

(c) the optional docking clause in Clause 7 applies;

(d) for Clause 9, Option 2, general written authorization for Subprocessors applies, and the notice procedure described in Section 6 of this DPA constitutes the applicable notice mechanism;

(e) the optional language in Clause 11 does not apply;

(f) for Clause 17, the EU SCCs will be governed by the law of the EU Member State in which Customer is established, provided that law permits third-party beneficiary rights under the EU SCCs. If Customer is not established in an EU Member State or such law does not satisfy that requirement, the laws of Ireland will apply;

(g) for Clause 18, disputes will be resolved before the courts of the jurisdiction selected under Clause 17;

(h) the competent supervisory authority under Clause 13 will be determined in accordance with the criteria specified in the EU SCCs; and

(i) Annexes I and II to the EU SCCs will be deemed completed using the information contained in Schedules 1 and 2 of this DPA and the identifying information contained in the Agreement, applicable order documentation, or Customer’s account.

If the EU SCCs cease to constitute a valid transfer mechanism, the Parties will cooperate in good faith to implement a replacement transfer mechanism permitted by Applicable Data Protection Law.

12.3 United Kingdom Transfers

Where Customer Personal Data is subject to the UK GDPR and is transferred to Projection Genie in circumstances requiring an appropriate safeguard for a restricted transfer, the Parties agree that the then-applicable International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses approved by the United Kingdom Information Commissioner (“UK Addendum”) will apply to and supplement the EU SCCs.

The information contained in this DPA, including Schedules 1 and 2 and the Parties’ identifying information in the Agreement, will be used to complete the applicable tables and appendix information to the extent permitted.

If the UK Addendum or applicable United Kingdom transfer requirements are replaced or amended, the Parties will apply the successor mechanism to the extent required by UK Data Protection Law.

12.4 Transfer Assessments and Supplementary Measures

Each Party will reasonably cooperate with the other, to the extent required by Applicable Data Protection Law, in assessing international transfers and implementing supplementary contractual, technical, or organizational measures reasonably necessary to support a lawful transfer.

13. California Privacy Requirements

This Section applies to the extent Projection Genie Processes Personal Information on behalf of Customer in circumstances in which Customer is a “business” and Projection Genie acts as a “service provider” or “contractor” under the CCPA.

13.1 Limited and Specified Purposes

Customer discloses Personal Information to Projection Genie solely for the limited and specified business purposes described in the Agreement and Schedule 1, including providing, maintaining, securing, supporting, and enabling the functionality of the Services.

13.2 Restrictions

Projection Genie will not:

(a) sell or share Customer Personal Data as those terms are defined by the CCPA;

(b) retain, use, or disclose Customer Personal Data for any purpose other than the limited and specified purposes described in the Agreement, this DPA, Schedule 1, or as otherwise permitted by the CCPA;

(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Projection Genie and Customer except as permitted by the CCPA; or

(d) combine Customer Personal Data received from or on behalf of Customer with Personal Information received from another person or collected from Projection Genie’s own interactions with a consumer except where permitted under the CCPA.

13.3 Compliance

Projection Genie will comply with applicable obligations imposed on service providers and contractors under the CCPA and will provide the same level of privacy protection required of such entities by applicable law.

Projection Genie will notify Customer if Projection Genie determines that it can no longer meet its applicable CCPA obligations.

Customer may take reasonable and appropriate steps permitted under the CCPA to help ensure that Projection Genie uses Customer Personal Data consistently with Customer’s obligations, and Projection Genie will cooperate with reasonable measures necessary to stop and remediate unauthorized use of Customer Personal Data.

13.4 Consumer Requests

Projection Genie will reasonably cooperate with Customer in responding to verified consumer requests as required by the CCPA and will not use information received in connection with such requests for purposes inconsistent with the CCPA.

14. Customer-Directed Connected Services and MCP

14.1 Customer Instructions

Where Customer or an authorized User enables a Connected Service and requests, authorizes, or initiates access, retrieval, transmission, modification, or another action through that Connected Service, such activity constitutes a documented instruction from Customer to Projection Genie for purposes of this DPA.

Projection Genie may Process and transmit Customer Personal Data as reasonably necessary to carry out that instruction within the permissions granted by Customer.

14.2 Customer-Selected Providers

A Connected Service selected and independently contracted for, enabled, or authorized by Customer is not a Projection Genie Subprocessor solely because Projection Genie interoperates with or transmits Customer Personal Data to that Connected Service at Customer’s direction.

Once Customer Personal Data has been transmitted to a Customer-selected Connected Service, the recipient may act as a separate Controller, Processor, or Subprocessor depending on Customer’s relationship with that provider and applicable law.

14.3 Customer Responsibility

Customer is responsible for:

(a) evaluating whether a Connected Service is appropriate for the Customer Personal Data made available to it;

(b) reviewing the Connected Service provider’s privacy, security, data processing, retention, and international transfer practices;

(c) establishing any necessary contractual relationship with the Connected Service provider;

(d) ensuring that Customer has an appropriate legal basis to disclose Customer Personal Data to the Connected Service; and

(e) managing and revoking authorizations granted to the Connected Service.

14.4 Projection Genie Responsibility

Nothing in this Section limits Projection Genie’s responsibility for securely Processing and transmitting Customer Personal Data while that information remains under Projection Genie’s control or for complying with Customer’s documented instructions.

15. Liability

The limitations and exclusions of liability contained in the Agreement apply to this DPA except to the extent such limitations or exclusions are prohibited by Applicable Data Protection Law or conflict with mandatory provisions of the EU SCCs, UK Addendum, or another applicable transfer mechanism.

16. Term and Termination

This DPA becomes effective when it is incorporated into the Agreement and continues for as long as Projection Genie Processes Customer Personal Data on behalf of Customer.

Sections of this DPA that by their nature are intended to survive termination, including confidentiality, deletion and retention, audit obligations applicable to prior Processing, international transfer protections, and liability provisions, will survive for as long as necessary to fulfill their purpose.

Schedule 1

Details of Processing

1. Subject Matter

Processing of Customer Personal Data as necessary for Projection Genie to provide the Services to Customer under the Agreement.

2. Duration

For the duration of the Agreement and for any limited period thereafter during which Projection Genie retains Customer Personal Data in accordance with the Agreement, this DPA, Projection Genie’s Privacy Policy, applicable product-specific retention practices, or applicable law.

3. Nature and Purpose of Processing

Depending on the Services selected and used by Customer, Processing may include:

  • receiving and retrieving data submitted by Customer or obtained through Customer-authorized integrations;
  • hosting and storing data;
  • organizing, structuring, and displaying data;
  • performing calculations and financial analysis;
  • generating financial forecasts;
  • calculating financial, operational, subscription, and business metrics;
  • budgeting and scenario modeling;
  • financial health analysis;
  • workforce planning;
  • portfolio analysis;
  • creating and providing reports;
  • synchronizing data with authorized third-party services;
  • responding to requests initiated through Connected Services;
  • performing actions authorized through Connected Services;
  • providing customer support and troubleshooting;
  • authenticating Users and maintaining account security;
  • detecting, preventing, and responding to security incidents;
  • maintaining backups and disaster-recovery capabilities; and
  • otherwise providing, maintaining, securing, and supporting the Services requested by Customer.

4. Categories of Personal Data

Depending on Customer’s use of the Services, Customer Personal Data may include:

  • names;
  • email addresses;
  • telephone numbers;
  • business contact information;
  • User and account identifiers;
  • IP addresses and technical identifiers;
  • customer or subscriber identifiers;
  • vendor and supplier information;
  • invoice information;
  • transaction information;
  • payment status information;
  • subscription information;
  • product and pricing information;
  • accounting records;
  • financial records associated with identifiable individuals;
  • employment information;
  • position and job information;
  • compensation-related information;
  • employment type;
  • reporting relationships;
  • employment start and end dates;
  • location information provided for workforce planning purposes;
  • communications and support information;
  • usage and activity information; and
  • other Personal Data submitted by Customer or made available through a Customer-authorized integration or Connected Service.

5. Categories of Data Subjects

Depending on Customer’s use of the Services, Data Subjects may include:

  • Customer’s Users;
  • Customer’s employees;
  • Customer’s contractors and consultants;
  • Customer’s customers or subscribers;
  • prospective customers;
  • vendors;
  • suppliers;
  • business contacts;
  • employees or personnel of Customer’s clients;
  • customers or subscribers of Customer’s clients; and
  • other individuals whose Personal Data Customer elects to Process through the Services.

6. Special Categories of Personal Data

The Services are not designed for Customer to submit special categories of Personal Data under Article 9 of the EU GDPR, including information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health information, or information concerning an individual’s sex life or sexual orientation.

Customer should not submit such information unless the applicable use has been expressly agreed with Projection Genie and Customer has established all legal requirements necessary for the Processing.

7. Frequency of Processing

Processing may occur continuously, periodically, or at Customer or User request depending on the applicable Service, integration, synchronization schedule, feature, or Connected Service.

Schedule 2

Technical and Organizational Security Measures

Projection Genie maintains technical and organizational safeguards designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, destruction, or loss.

Measures applicable to the Services include, as appropriate:

1. Access Controls

  • Access to production systems and Customer Personal Data is restricted to authorized personnel with a legitimate business need.
  • Access privileges are limited based on role and responsibility.
  • User access to the Services requires authentication.
  • Projection Genie maintains processes for modifying or revoking access when access is no longer required.

2. Confidentiality

  • Personnel and contractors with access to Customer Personal Data are subject to confidentiality obligations.
  • Access to Customer Personal Data is limited to purposes associated with providing, securing, maintaining, or supporting the Services.

3. Transmission Security

  • Customer information transmitted between supported client interfaces and Projection Genie systems is protected using industry-standard encrypted transport protocols such as TLS/SSL.
  • Projection Genie uses secure connections when communicating with supported third-party integrations where such interfaces support encrypted transmission.

4. Integration and Credential Security

  • Third-party integrations use authentication and authorization mechanisms supported by the applicable provider.
  • Authorization scopes and permissions are limited to those reasonably required to provide the applicable integration functionality.
  • Credentials, authorization tokens, and similar sensitive authentication information maintained by Projection Genie are protected using technical safeguards designed to prevent unauthorized access.
  • Where supported by an integration, Projection Genie validates authorization and authentication information associated with requests and connection events.

5. Data Storage and Infrastructure

  • Customer Personal Data is hosted using professional cloud infrastructure providers with physical and technical security controls.
  • Projection Genie uses logical controls designed to prevent unauthorized access to Customer information.
  • Production systems are protected through access restrictions and infrastructure security mechanisms appropriate to the Services.

6. Backup and Availability

  • Projection Genie maintains backup or redundancy processes designed to support restoration and continued availability of Customer data following certain system failures or disruptions.
  • Access to backup data is subject to security protections appropriate to the sensitivity of the information.

7. Security Monitoring and Incident Response

  • Projection Genie maintains processes designed to identify, investigate, and respond to suspected security incidents.
  • Projection Genie maintains procedures for escalating incidents involving Customer Personal Data and notifying affected customers where required.

8. Data Minimization and Retention

  • Projection Genie seeks to limit Processing to information reasonably necessary to provide and support the Services.
  • Customer Personal Data is retained in accordance with applicable service requirements, documented retention practices, contractual requirements, and applicable law.
  • Projection Genie maintains processes for deletion or de-identification of information when retention is no longer reasonably necessary, subject to applicable backup and legal retention requirements.

9. Vendor Management

  • Projection Genie evaluates service providers that Process Customer Personal Data based on the nature of the services and associated risks.
  • Subprocessors are subject to contractual privacy, confidentiality, and security obligations appropriate to the Processing they perform.

10. Security Review

  • Projection Genie periodically reviews and updates its security measures in light of changes to the Services, technology, identified risks, and applicable legal requirements.

Schedule 3

Subprocessors

Projection Genie’s current Subprocessors are identified on its GDPR page at:

https://www.projectiongenie.com/legal/gdpr

That list identifies the third-party providers Projection Genie uses to Process Customer Personal Data on its behalf, together with their relevant processing purpose and, where applicable, processing location.

Customer authorizes the Subprocessors identified on that page as of the date this DPA becomes applicable to Customer.

Projection Genie will notify Customer of intended additions or replacements in accordance with Section 6 of this DPA.

‍

Continue Discovering What Projection Genie Offers

Explore our suite of financial planning and decision intelligence tools designed for growing businesses.

Visit homepage
Dashboard view of Lizzie Smith's Toy Store showing 95% success probability, key metrics, and startup cost pie chart.Dashboard view of Lizzie Smith's Toy Store showing 95% success probability, key metrics, and startup cost pie chart.