UNDERWRITE — DATA PROCESSING ADDENDUM Ellis Intelligence LLC d/b/a Underwrite ====================================================================== NOT YET IN FORCE. This document is not executed or binding on any customer until separately signed. No commercial transaction is governed by this page until execution. Provided for prospective-customer / security-review reference only. Status: Not yet executed. Brand delta to the Ellis Intelligence LLC DPA Core. The deployed document at underwrite.com/dpa inlines the Core (variablized for Underwrite) plus the brand-specific provisions below, and stands alone. ---------------------------------------------------------------------- PART A — UNDERWRITE DPA ADDENDUM (brand-specific terms) ---------------------------------------------------------------------- Effective Date: [Date upon Customer's acceptance] This Data Processing Addendum forms part of the Terms of Service between Ellis Intelligence LLC d/b/a Underwrite ("Processor", "we") and the customer identified in the subscription order ("Customer"). --- 1. Definitions As in the DPA Core. Capitalized terms not defined in this Addendum or the DPA Core (including "MSP Client", "MSP Customer", and "Customer Data") have the meanings given in the Underwrite Terms of Service. Additionally: - "MSP Client Data" means data the Customer uploads on behalf of one or more MSP Clients on MSP-tier subscriptions. 2. Roles and Scope 2.1 SMB Tiers. Customer is controller of Personal Data within Customer Data. Processor acts as processor on Customer's documented instructions. 2.2 MSP Tiers. The MSP Customer is controller for both its own Customer Data and the MSP Client Data it uploads. Processor acts as processor for both. The MSP Customer warrants it has a lawful basis (typically a managed-services agreement) with each MSP Client to share that MSP Client's renewal materials with Processor for the purpose of providing the Service. 2.3 Nested Tenancy. Three-level isolation: Underwrite → MSP Customer → MSP Client. Processor maintains row-level security enforcing that no MSP Customer accesses another's data and no MSP Client is exposed across MSP Customers. 3. Categories of Data — Underwriting Context 3.1 Customer Data and MSP Client Data may include: - Business profile and security posture information - Prior-year renewal questionnaire responses - Carrier-response history (acceptance, premium, coverage terms) - Risk-narrative content and supporting documentation 3.2 Personal Data within these categories typically includes business contact information of personnel. Customer is expected to minimize personally identifiable information of natural persons (clients of MSP Clients, employee SSNs, etc.) per Privacy Policy §3. 4. Data Subject Rights 4.1 Where a Data Subject (a natural person whose information appears in Customer Data or MSP Client Data) contacts Processor with a rights request, Processor will: - Acknowledge receipt - Not respond substantively - Forward to Customer (or the relevant MSP Customer if the data is MSP Client Data) within 5 business days - Reasonably assist Customer in responding 4.2 For MSP Client Data, the MSP Customer is responsible to its MSP Client for response. 5–10. Subprocessors, Breach, Audit, Transfers, Deletion, Liability As in the DPA Core §§5–10. Current subprocessor list at underwrite.com/subprocessors. 11. General As in the DPA Core §11. --- Schedule 1 — Processing Description - Subject matter: Provision of the Underwrite cyber-insurance renewal Service - Duration: Subscription term + 30-day deletion window - Nature: Storage, retrieval, transmission, display, AI-assisted analysis and drafting - Purpose: Enable Customer (and, on MSP tiers, MSP Customer on behalf of MSP Clients) to prepare and compare cyber-insurance renewal materials - Types of Personal Data: - Customer personnel: business contact information - On MSP tiers: MSP Client personnel business contact information; potentially names of insured natural persons appearing in renewal narratives (Customer-controlled) - Categories of Data Subjects: Customer personnel; MSP Client personnel; persons referenced in renewal narratives where applicable - Frequency: Continuous during subscription - Retention: Per Terms §10.4 Schedule 2 — Technical and Organizational Measures As in the DPA Core Schedule 2, plus: - Three-level tenancy isolation (Underwrite → MSP → MSP Client) enforced at database and application layers - Carrier-template library segregated from customer data stores - No outbound transmission of Customer Data or MSP Client Data to any insurance carrier, broker, or aggregator ---------------------------------------------------------------------- PART B — ELLIS INTELLIGENCE LLC DPA CORE (incorporated by reference, variablized for Underwrite) ---------------------------------------------------------------------- --- Effective Date: [Date upon Customer's acceptance] This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between Ellis Intelligence LLC d/b/a Underwrite ("Processor", "we") and the customer entity identified in the subscription order ("Customer"). It governs Processor's Processing of Personal Data on Customer's behalf. Customer acts as the controller of that Personal Data as described in §2.1. --- 1. Definitions - "Adequacy Decision" means a decision by the European Commission (or, for transfers from the UK or Switzerland, the competent UK or Swiss authority) that a country or territory ensures an adequate level of data protection, so that Personal Data may be transferred there without additional transfer safeguards. - "Customer Data" has the meaning given in the Terms and is the data subject to this DPA. - "Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, in each case as amended: (a) Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"); (b) the GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 (the "UK GDPR"); (c) the Swiss Federal Act on Data Protection ("FADP"); (d) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA"); (e) the Colorado Privacy Act ("CPA"); and (f) any other law that applies to a party's Processing of Personal Data under this DPA. Where more than one such law applies to a given Processing activity, each applies only to the extent of its own scope, and this DPA does not extend any such law's obligations beyond that scope. - "Data Subject" means the identified or identifiable natural person to whom Personal Data relates (including, under the CCPA, a "consumer"). - "Personal Data" has the meaning set out in applicable Data Protection Law and includes "personal information" as defined in the CCPA. - "Process" / "Processing" has the meaning under applicable Data Protection Law. - "SCCs" means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module 2 (controller-to-processor). - "Service" means the Underwrite software-as-a-service offering provided by Processor under the Terms. - "Subprocessor" means a third party engaged by Processor to Process Personal Data on Customer's behalf. - "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the United Kingdom Information Commissioner's Office ("ICO"). (Per-brand deltas may add defined terms — e.g., Couple Data, MSP Client Data, Consumer-Report Data, Firm/Privileged Data, Consumer Data — in their own §1.) --- 2. Roles and Scope 2.1 As between the parties, Customer is the controller (as that term is defined in applicable Data Protection Law) of Personal Data within Customer Data. Processor Processes Personal Data only as Customer's processor and on Customer's documented instructions. (This DPA refers to the parties as "Customer" and "Processor" throughout; "controller" and "processor" are used only when describing the statutory roles.) 2.2 The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Schedule 1 (in the per-brand delta). 2.3 Processor will not process Personal Data for any purpose other than to provide the Service to Customer, except as required by law. If law requires Processor to process for another purpose, Processor will inform Customer before processing (unless prohibited from doing so by law). --- 3. Processor's Obligations 3.1 Compliance with Instructions. Processor will process Personal Data only on Customer's documented instructions as set forth in this DPA, the Terms, and Customer's use of the Service. Processor will inform Customer if Processor believes an instruction may violate applicable Data Protection Law. 3.2 Confidentiality. Persons authorized by Processor to process Personal Data are subject to a duty of confidentiality. 3.3 Security Measures. Processor will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures described in Schedule 2. 3.4 Assistance to Customer. Processor will assist Customer, taking into account the nature of the Processing, in: - Responding to Data Subject Rights requests (see §4) - Notifying Personal Data breaches (see §6) - Conducting data protection impact assessments (where required) - Consulting with supervisory authorities (where required) 3.5 Records of Processing. Processor maintains records of processing activities as required by Article 30 GDPR. --- 4. Data Subject Rights 4.1 Where a Data Subject contacts Processor directly with a rights request related to Customer's Personal Data, Processor will: - Not respond substantively except to acknowledge receipt - Promptly forward the request to Customer (within 5 business days) - Reasonably assist Customer in responding 4.2 Customer is responsible for verifying Data Subject identity and determining whether the request is valid and applicable. 4.3 Processor provides export tooling within the Service to assist Customer with access and portability rights. 4.4 As between the parties, Customer is solely responsible for responding to Data Subject requests forwarded under §4.1 within the time and in the manner required by applicable Data Protection Law. Liability for a failure to do so is allocated in §10.3. (Per-brand deltas may add Data-Subject-rights specifics — e.g., couple/guest portals, MSP Client escalation, applicant requests, privileged-data carve-outs.) --- 5. Subprocessors 5.1 Customer authorizes Processor to engage Subprocessors. The current list is at underwrite.com/subprocessors. 5.2 Processor will impose contractual obligations on each Subprocessor that are no less protective in substance than this DPA with respect to security, confidentiality, and assistance to Customer. Processor's liability to Customer for its Subprocessors is governed by §5.5 and is not conditioned on Processor's recovery from any Subprocessor. 5.3 Processor will notify Customer in writing at least 30 days before adding or replacing a Subprocessor, by emailing the account's designated notification contacts (or by in-product notice) and by posting the change on the public subprocessor list at underwrite.com/subprocessors. Written notice is deemed given when sent to the contact details then on the account (or when the in-product notice is first displayed); Customer is responsible for keeping those details current, and the notice and objection periods are not extended by a failure to read a properly sent notice. Customer may object on reasonable data-protection grounds within 30 days of the date notice is given. If Customer timely objects, Processor will not Process Customer's Personal Data using the objected-to Subprocessor while the objection is unresolved. If the parties cannot agree on a resolution within 15 days of the objection, Customer may terminate the affected subscription by written notice. Termination takes effect on Processor's receipt of that notice (or a later date Customer specifies, no more than 30 days after receipt), and Processor will refund the pro rata portion of prepaid fees attributable to the period after the effective date of termination within 30 days after that date. This §5.3 applies to changes in Processor's direct Subprocessors (the entities on the public subprocessor list); a Subprocessor's changes to its own subcontractors are governed by that Subprocessor's terms and remain subject to §5.2 and §5.5. 5.4 Notwithstanding §5.3, where a Subprocessor must be replaced immediately for reasons beyond Processor's reasonable control (including a security incident affecting the Subprocessor, its insolvency, its sudden unavailability, or a change imposed by the Subprocessor on notice too short for Processor to give 30 days' advance notice), Processor may engage a replacement without advance notice and will post and email notice of the replacement without undue delay. Customer's objection right under §5.3 then applies from the date that notice is posted. 5.5 Processor remains liable to Customer for the acts and omissions of its Subprocessors to the same extent as if Processor performed the Processing itself. --- 6. Personal Data Breaches 6.1 Processor will notify Customer without undue delay, and in any event within five (5) business days of becoming aware, of a Personal Data Breach affecting Customer's Personal Data; provided that where the strictest applicable state breach-notification law or an FCRA-specific notice trigger requires Customer to act on a shorter timeline, Processor will use commercially reasonable efforts to notify Customer within whatever shorter period is necessary for Customer to meet that deadline. 6.2 The notice will include, to the extent reasonably known: - Nature of the breach and categories and approximate number of Data Subjects and records affected - Likely consequences - Measures taken or proposed to address the breach and mitigate adverse effects - A point of contact for additional information 6.3 Processor will cooperate with Customer's investigation and provide reasonably necessary information. --- 7. Audit Rights 7.1 On reasonable advance written notice (at least 30 days, unless an emergency arising from a Personal Data Breach), Customer may verify Processor's compliance with this DPA by: (a) Reviewing Processor's most recent SOC 2 Type I or Type II report under NDA; or (b) Submitting a written questionnaire that Processor will respond to within 30 days; or (c) For material verified deficiencies not addressed within 60 days, conducting an on-site audit during business hours by a mutually agreed independent auditor at Customer's expense, subject to confidentiality and not more than once in any 12-month period. 7.2 Customer may not access another customer's data, Processor's source code, or any data that would breach Processor's confidentiality obligations to third parties. --- 8. International Data Transfers 8.1 Where Processor's Processing of Personal Data subject to the GDPR or UK GDPR involves transfer outside the EEA, UK, or Switzerland to a country not covered by an Adequacy Decision (see §1 — i.e., a country the European Commission or competent UK/Swiss authority has not approved as providing adequate data protection), the SCCs (Module 2) and UK Addendum are incorporated into this DPA by reference, with the following selections: - Clause 7 (Docking Clause): does not apply - Clause 9 (Subprocessors): Option 2 (general authorization with notice, per §5 of this DPA) - Clause 11 (Redress): independent dispute resolution body not designated - Clause 17 (Governing law): law of Ireland - Clause 18 (Forum): courts of Ireland - Annex I.A (Parties): as set out in this DPA and the subscription order - Annex I.B (Description of Transfer): as set out in Schedule 1 - Annex I.C (Competent Supervisory Authority): (i) where Customer is established in an EEA Member State, the supervisory authority of that Member State (or Customer's lead supervisory authority under Article 56 GDPR, where one exists); (ii) where Customer is not established in the EEA but is subject to Article 3(2) GDPR and has appointed a representative under Article 27 GDPR, the supervisory authority of the Member State where that representative is established; (iii) otherwise, the supervisory authority of a Member State in which the Data Subjects whose Personal Data is transferred are located - Annex II (Technical and Organizational Measures): as set out in Schedule 2 8.2 UK Addendum: Table 1 (parties) and Table 3 (transfer information) per the subscription order and this DPA; Table 2 selection: SCC version above; Table 4 (Importer/Exporter ending): neither. For transfers subject to the UK GDPR, the UK Addendum's mandatory clauses override Clauses 17 and 18, so those transfers are governed by the laws of England and Wales with disputes resolved in the courts of England and Wales. 8.3 Swiss transfers. Where Processor's Processing of Personal Data is subject to the FADP, the SCCs apply with the following adaptations: (a) references to the GDPR are read as references to the FADP insofar as the transfer is governed by the FADP; (b) the Swiss Federal Data Protection and Information Commissioner ("FDPIC") is the competent supervisory authority under Annex I.C insofar as the transfer is governed by the FADP; (c) the term "Member State" is not interpreted to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence; and (d) Data Subjects in Switzerland may bring claims before the courts of Switzerland. --- 9. Deletion and Return 9.1 Upon Customer's written request, Processor will delete or return (at Customer's option) Personal Data within 30 days of the request, except as required by law to retain. Upon termination of the Terms, absent such a request, Processor will retain Personal Data for 24 months following the effective date of termination, to preserve the evidentiary and statutory record-keeping basis for potential disputes, and will thereafter delete or return it (at Customer's option) within 30 days, except in each case as required by law to retain. 9.2 Customer may export Personal Data via in-product export tooling at any time during the subscription. 9.3 Personal Data deleted by Processor under §9.1 may persist for a limited additional period in Processor's Subprocessors' backup, disaster-recovery, or system logs before those copies are themselves purged, consistent with each Subprocessor's own retention practice — for Fly.io (production hosting and database backups), active Customer Data is deleted within 30 days, with residual encrypted backup copies (volume snapshots) purged within 90 days; and up to 180 days for Google Workspace (Ellis's internal business email and documents only; Google Workspace does not process Customer's Personal Data). This subsection does not extend the 30-day or 24-month periods in §9.1, which govern Processor's own systems. --- 10. Liability and Indemnification 10.1 Each party's liability under this DPA is subject to the limitations of liability in the Terms. 10.2 Notwithstanding §10.1, neither party's limitation of liability applies to any finding, inquiry, investigation, or fine by any regulatory, supervisory, administrative, or enforcement body of any kind — including without limitation a data-protection supervisory authority, the FTC, a state attorney general, or any other regulator — arising from a violation of GDPR Article 82, any other provision of applicable Data Protection Law, or any other statute or regulation, which are in each case governed by the parties' respective regulatory obligations rather than by this DPA's limitation of liability. This carve-out is stated as broadly as possible and applies uniformly regardless of the specific statute, regulation, or regulatory or enforcement body involved; a party asserting that this carve-out does not apply to a particular claim, statute, or regulatory or enforcement body bears the burden of establishing that, rather than the other party bearing the burden of establishing the carve-out's applicability to each one individually. The parties apply this formulation uniformly across Processor's template library rather than tailoring it per statute, accepting that the carve-out's scope may be broader than strictly required under a given statute or jurisdiction as an acceptable consequence of uniformity. 10.3 Provided Processor has complied with §3.4 and §4, Customer will indemnify, defend, and hold harmless Processor from and against third-party claims, regulatory fines, and penalties to the extent arising out of Customer's failure to timely or properly respond to a Data Subject request forwarded to Customer under §4.1. --- 11. General 11.1 Conflict. In case of conflict between the Terms and this DPA, the DPA controls for matters within its scope. 11.2 Term. This DPA remains in force while Processor processes Customer's Personal Data and survives termination of the Terms for the period required by §9. 11.3 Governing Law. Same as the Terms, except where the SCCs or applicable Data Protection Law specifies otherwise. --- Schedule 2 — Technical and Organizational Measures (Core) Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, with independent external uptime monitoring being brought online ahead of launch. - Per-tenant data isolation with row-level security - Annual security review and remediation - Personnel confidentiality obligations and security training - Subprocessor due diligence and contractual obligations - Incident response procedures with a breach-notification commitment of five (5) business days of becoming aware (or sooner, per §6.1, where necessary to meet the strictest applicable state breach-notification law or FCRA-specific notice trigger) (Per-brand deltas append brand-specific measures — e.g., nested-tenancy isolation, sensitive-data flagging, consumer-report-data access logging, privileged-data controls, verification-PII minimization.) ---------------------------------------------------------------------- This is an informational export of the DPA text maintained at underwrite.com/dpa. Last generated: July 2026.