Data Processing Addendum

Template — version January 1, 2026

This is a template. It is completed and signed per customer. Fields shown as [like this] are filled in at signing. This DPA forms part of, and is incorporated into, the services agreement between the parties (the "Agreement").

This Data Processing Addendum ("DPA") is entered into between [Customer legal name] ("Customer," the Controller) and MORnet Communications, LLC, operating Hosted Voice ("Processor," "we"), effective [date]. Where Customer processes personal data on behalf of its own customers, Customer is a processor and we are a sub-processor, and this DPA applies accordingly.

1. Definitions

"Data Protection Laws" means all applicable privacy and data-protection laws, including the EU/UK GDPR and the California Consumer Privacy Act as amended (CCPA/CPRA). "Personal Data," "Controller," "Processor," "Process," "Data Subject," and "Personal Data Breach" have the meanings given under Data Protection Laws. "Customer Personal Data" means personal data we process on Customer's behalf under the Agreement, described in Annex A.

2. Roles and scope

Customer is the Controller (or a processor acting for a third-party controller) and we act as Processor. We Process Customer Personal Data only to provide the services and only on Customer's documented instructions (including as set out in the Agreement and this DPA), unless required by law, in which case we will notify Customer unless legally prohibited. Details of Processing are in Annex A.

3. Our obligations as Processor

4. Sub-processors

Customer provides general authorization for us to engage sub-processors (including messaging carriers/aggregators and infrastructure providers) to deliver the services. Current sub-processors are listed in Annex C. We impose data-protection obligations on sub-processors that are substantially the same as those in this DPA and remain responsible for their performance. We will give Customer reasonable notice of intended changes to sub-processors and an opportunity to object on reasonable data-protection grounds.

5. International transfers

Where Customer Personal Data is transferred out of the EEA, UK, or other restricted regions, such transfers are made under an approved transfer mechanism (for example, the EU Standard Contractual Clauses and the UK Addendum), which the parties agree to incorporate by reference where applicable.

6. Data subject requests

Taking into account the nature of the Processing, we will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise Data Subject rights. If we receive such a request directly, we will (unless legally required to act) direct the Data Subject to Customer.

7. Personal data breaches

We will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.

8. Deletion or return

On expiry or termination of the services, we will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law (for example, call-detail and messaging records required for regulatory or billing purposes), in which case we protect it and Process it only as required.

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (or after a material breach or where required by a supervisory authority), allow Customer or its mandated auditor to conduct an audit, subject to confidentiality and to reasonable limits protecting other customers' data and our operations.

10. CCPA/CPRA terms

To the extent the CCPA/CPRA applies, we act as a service provider. We will not sell or share Customer Personal Data, will not retain, use, or disclose it except to perform the services (or as permitted by the CCPA), and will not combine it with other data except as permitted. We certify we understand and will comply with these restrictions.

11. General

If there is a conflict between this DPA and the Agreement on data protection, this DPA controls. Liability is subject to the limitations in the Agreement. This DPA is governed by the law stated in the Agreement.

Annex A — Details of Processing

Subject matterProvision of hosted voice and messaging services under the Agreement.
DurationThe term of the Agreement, plus any legally required retention.
Nature & purposeTransmitting, routing, storing, and supporting voice calls and SMS/MMS messages, and related billing and abuse prevention.
Types of personal dataPhone numbers; caller/recipient identifiers; call-detail and message metadata (time, duration, status); message content in transit; account and contact details; [other, if any].
Categories of data subjectsCustomer's staff, callers, message recipients, and end users.

Annex B — Security Measures

Annex C — Sub-processors

Sub-processorPurposeLocation
[Messaging carrier/aggregator, e.g. Bandwidth / Telnyx / Commio]SMS/MMS transmission & 10DLC registrationUSA
Microsoft (Microsoft 365 / Azure)Email, hosting/infrastructureUSA
Cloudflare, Inc.Network, security, edge deliveryUSA
[Add others as applicable]

Signatures

Customer (Controller)
Name: [ ]
Title: [ ]
Date: [ ]
MORnet Communications, LLC (Processor)
Name: [ ]
Title: [ ]
Date: [ ]