NerdPress® Guided Agent Connector Terms

EXHIBIT A — DATA PROCESSING ADDENDUM

 (to the NerdPress® Guided Agent Connector Terms (the “Connector Terms”))

This Data Processing Addendum (DPA”) forms part of, and is incorporated by reference into, the NerdPress® Guided Agent Connector Terms (the “Connector Terms”) between Why Watermelon Incorporated, d/b/a “NerdPress®” (we,” us,” or Provider”) and the customer that activates the NerdPress® Guided Agent Connector (you” or Customer”). It governs how we handle Personal Information processed through the NerdPress® Guided Agent Connector (the Service”). If this DPA conflicts with the Connector Terms as to data protection, this DPA controls.

1. Definitions.

Capitalized terms not defined here have the meaning given in the Connector Terms. “Personal Information” means information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual, and includes “personal data” as defined under applicable law. “Applicable Privacy Law” means all privacy and data-protection laws applicable to a party’s processing, including the California Consumer Privacy Act as amended (the CCPA”; Cal. Civ. Code § 1798.100 et seq.) and its regulations (11 CCR § 7000 et seq.), and, where and to the extent applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR”) and the UK GDPR. “Process” and “Processing” include any operation performed on Personal Information, including collection, storage, and transmission.

2. Roles of the parties.

As between the parties, you are the business/controller and determine the purposes and means of Processing Personal Information through the Service, and we act solely as your service provider/processor, Processing Personal Information only on your documented instructions and on your behalf. Your activation and configuration of the Service, your permission settings, and the Connector Terms and this DPA constitute your complete and final Processing instructions; we will notify you if we believe an instruction violates Applicable Privacy Law. Nothing in this DPA makes us a controller of, or responsible for, the content you or your authorized connections choose to route through the Service.

3. Nature and scope of Processing.

The Service routes Personal Information transiently between your authorized connections and your site; we do not retain or have visibility into the content of the prompts routed through the Service. The gateway does not store or cache site content; content passes through in transit only. Separately, we retain connection and action logs (metadata about requests made through the connection), and, as part of your plan, backup copies of your site (which may contain Personal Information), as described in Annex 1. Some operational data used to support recovery of changes may reside on your own website rather than on our systems; where that is the case, it is within the site you control. We may change where such data is stored over time. Personal Information may therefore be Processed both (a) transiently, in routing your requests, and (b) at rest, in backups and logs retained to provide security, recovery, and support. We do not require or intend for the Service to Process Personal Information beyond what is necessary for these purposes.

4. Our obligations as service provider/processor.

We will:

  (a) Purpose limitation. Process Personal Information only to provide, secure, maintain, and support the Service for you — specifically for routing your requests, security monitoring, audit logging, abuse prevention, and troubleshooting — and for no other purpose. We will not “sell” or “share” Personal Information (as those terms are defined under the CCPA), and we will not retain, use, or disclose it outside the direct business relationship with you or for any commercial purpose of our own.

  (b) No independent use; no model training. We may use the connection and action logs described in Annex 1 to operate, secure, maintain, and improve the Service we provide to you. We will not use any Personal Information Processed through the Service to build, train, fine-tune, improve, or develop any artificial-intelligence or machine-learning model, or any product or service other than the Service, unless you give separate, specific, written consent. Any “service improvement” we perform is limited to securing and maintaining the Service provided to you, using the minimum data necessary.

  (c) Combination limits. We will not combine Personal Information received through the Service with Personal Information from other sources, except as permitted for a service provider under the CCPA (e.g., to detect security incidents or protect against fraudulent or illegal activity).

  (d) Confidentiality. Ensure that personnel authorized to Process Personal Information are bound by appropriate confidentiality obligations.

  (e) Security. Implement and maintain reasonable technical and organizational measures appropriate to the risk, designed to protect Personal Information against unauthorized access, loss, or disclosure. We do not access or store your passwords or payment card details.

  (f) Assistance. Taking into account the nature of the Processing, provide reasonable assistance to help you respond to verifiable individual-rights requests and to meet your own security, breach-notification, and (where applicable) impact-assessment obligations.

  (g) Individual requests. Promptly notify you (to the extent legally permitted) if we receive a request from an individual seeking to exercise rights over Personal Information Processed through the Service, and not respond except to confirm the request relates to you.

5. Your obligations as business/controller.

You represent, warrant, and agree that:

  (a) you have provided all notices and obtained all consents and lawful bases required under Applicable Privacy Law from every individual whose Personal Information may be Processed through the Service — including your own personnel, contractors, and your site’s end users/visitors — for that Personal Information to be routed through and logged by the Service;

  (b) you will not route through the Service any special-category/sensitive data, protected health information subject to HIPAA, or payment card data for which you have not established a lawful basis and appropriate safeguards; we are not a HIPAA business associate and will not knowingly accept PHI;

  (c) your instructions to us for Processing Personal Information will comply with Applicable Privacy Law, and you are solely responsible for the lawfulness of the content and instructions you and your authorized connections route through the Service; and

  (d) you will configure permissions, and supervise the connections and users you authorize, consistent with your obligations under Applicable Privacy Law.

6. Sub-processors.

You authorize us to engage sub-processors to help provide the Service. We will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. A current list of sub-processors is set out in Annex 2; we will give you a reasonable means to receive notice of, and object on reasonable data-protection grounds to, new sub-processors.

7. End-user notice and consent flow-down (logging/monitoring).

Because the Service routes your instructions and site data through our gateway and records connection and action logs (including a record of resulting site changes), session metadata, IP addresses, and user identifiers — and does not retain the content of the prompts or model responses routed through it — you agree that, before routing any individual’s Personal Information through the Service, you will:

  (a) post a conspicuous notice in your own privacy policy and, where required, at the point of collection, disclosing that interactions may be routed through a third-party gateway and logged (as connection and action records) for security, logging, and support; and

  (b) obtain any consent required under applicable law — including, where applicable, California’s wiretap/eavesdropping consent rules (the California Invasion of Privacy Act, Cal. Penal Code §§ 631, 632, 632.7) — from the individuals whose communications or data may be captured.

You acknowledge that we record these actions as your service provider and at your direction, as a party to and provider of the routing service, and that you are responsible for the notices and consents in this Section 7. This Section 7 is a material term.

8. International data transfers.

The parties acknowledge that the Service is being made available to Customers and end users located both inside and outside the United States. Supplemental terms governing the Processing of Personal Information subject to the GDPR and UK GDPR — including the required Article 28 processor terms and a valid cross-border transfer mechanism (EU Standard Contractual Clauses and the UK International Data Transfer Addendum) — are forthcoming and, once issued by us, will be incorporated into and form part of this DPA. Until those supplemental terms are in place, you are responsible for determining whether your use of the Service is lawful for individuals located in the EEA or United Kingdom, for establishing any transfer mechanism required for Personal Information you route through the Service, and for limiting the Personal Information you route accordingly.

9. Security incidents.

We will notify you without undue delay after becoming aware of a confirmed breach of security leading to the unauthorized access, loss, or disclosure of Personal Information Processed through the Service, and will provide information reasonably available to us to help you meet your notification obligations. Our notice or assistance is not an acknowledgment of fault or liability.

10. Return and deletion.

On termination or on your written request, we will delete or return Personal Information that is in our possession or control and Processed on your behalf within 30 days, except that (a) Personal Information contained in routine connection/action logs will be deleted as those logs reach the end of their retention period, and Personal Information contained in backups will be deleted in the ordinary course as those backups age out on our standard backup cycle — rather than being extracted individually — and (b) we may retain Personal Information where required by law or for the limited security and audit purposes permitted for a service provider. Personal Information that resides on your own website — including operational data used to support recovery — is within your control, and you are responsible for deleting it from your site; we cannot delete data we do not hold. Any data we retain remains subject to this DPA and will not be used for any other purpose.

11. Audit.

We will make available, on reasonable written request and no more than once annually (absent a security incident or regulatory requirement), information reasonably necessary to demonstrate our compliance with this DPA, subject to confidentiality and to not compromising the security or data of other customers.

12. Liability.

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions in the Connector Terms and the Support Plan Terms, including the limitation of liability, to the maximum extent permitted by Applicable Privacy Law.

13. Order of precedence; effect.

This DPA supplements and forms part of the Connector Terms. In case of conflict on data-protection matters, the order of precedence is: (1) any executed international/SCC module once issued, (2) this DPA, (3) the Connector Terms, and (4) the Support Plan Terms.

Annex 1 — Description of Processing

  • Subject matter: Routing of Customer instructions and site data between Customer’s authorized connections and Customer’s WordPress site through the Service, and retention of site backups and operational logs provided under the Customer’s plan.
  • Duration: Connection and action logs currently retained approximately 30 days (certain technical/server logs may be retained longer; periods subject to change); backups are typically retained for at least 90 days; plus the limited retention in §10. Files uploaded through the gateway’s upload feature are held in temporary storage for up to 12 hours and then deleted; the gateway does not otherwise store or cache site content, which passes through in transit only.
  • Nature and purpose: Transient routing/gateway processing; backup and recovery; security monitoring; audit logging; abuse prevention; support.
  • Categories of Personal Information: Connection and action logs (metadata about requests made through a connection), session metadata, IP addresses, user identifiers, and backups of site content (which may include posts, pages, media, comments, users, settings). The content of prompts sent to the AI agent is not retained. Special-category data, PHI, and payment card data are not intended and are excluded.
  • Categories of data subjects: Customer’s personnel and authorized users; Customer’s site visitors/end users to the extent their data is contained in routed content or backups.

Annex 2 — Sub-processors

We use the following sub-processor to provide the Service:

Sub-processorPurposeLocation
Fly.io (Fly.io, Inc.)Cloud hosting and gateway infrastructure — hosts and routes the connections that make up the ServiceUnited States

We will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will provide a reasonable means to receive notice of new sub-processors as described in Section 6.