Data Processing Addendum

GDPR Compliance Framework

This Data Processing Addendum ("DPA") forms part of the Master Platform Services Agreement between Deal Box, Inc. and users located in the European Economic Area, United Kingdom, or Switzerland.

1. Definitions and Interpretation

Terms used in this DPA have the meanings given in the GDPR. "Personal Data," "Data Subject," "Processing," and "Controller" shall have the meanings set forth in applicable data protection laws.

2. Processing of Personal Data

Deal Box processes personal data as a processor on behalf of controllers (issuers and users). Processing is limited to purposes specified in the service agreement and in accordance with documented instructions.

3. Data Subject Rights

Deal Box will assist controllers in responding to data subject requests regarding access, rectification, erasure, restriction, portability, and objection rights under GDPR.

4. Security Measures

Technical and organizational measures include encryption, access controls, security monitoring, incident response procedures, and regular security assessments.