**DATA PROCESSING ADDENDUM**

The undersigned customer ("Customer") and [<mark>CompanyName</mark>] ("Provider") (each a "Party" and collectively the "Parties") enter into this Data Processing Addendum (including the annexes attached hereto, this "DPA") as of the date signed by both Parties and forms part of that certain [<mark>CUSTOMER AGREEMENT</mark>] dated [<mark>Effective Date of the Agreement</mark>] (as amended, the "Agreement") between the Parties.

**Definitions**

The following terms have the meanings set out below for purposes of this DPA. Any capitalized terms not defined in this DPA have the meanings given in the Agreement.

Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.

Applicable Data Protection Laws means the privacy, data protection and data security laws and regulations of any jurisdiction within the United States applicable to Provider's Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws.

Customer Data means information provided or otherwise made available by or on behalf of Customer to Provider for Processing on Customer's behalf to perform the Services.

Data Subject means the identified or identifiable natural person to whom Personal Data relates.

Information Security Incident means a breach of Provider's security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Provider's possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.

Personal Data means Customer Data that constitutes "personal data," "personal information," or "personally identifiable information" defined in Applicable Data Protection Laws or information of a similar character regulated thereby, provided that Personal Data does not include such information pertaining to Customer's business contacts who are Customer personnel or such information that Provider receives, collects, or generates independently of the Services and not from or on behalf of Customer.

Process or Processing means any operation or set of operations which is performed by Provider (or on Provider's behalf) for Customer under the Agreement on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Security Measures has the meaning given in Section 4(a) (Provider Security Measures).

Services has the meaning given in the Agreement.

State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws (and any implementing regulations) currently in effect and applicable to Provider's Processing of Personal Data under the Agreement.

Subprocessors means Provider's Affiliates and third parties that Provider engages to Process Personal Data in relation to the Services.

**Duration and Scope of DPA**

This DPA will remain in effect so long as Provider Processes Personal Data, notwithstanding the expiration or termination of the Agreement.

Processing of Personal Data subject to the State Privacy Laws with respect to which Customer is a Business, Controller, Processor, or Service Provider (as such terms are defined in State Privacy Laws) shall be subject to Annex 2 (State Privacy Laws Annex) to this DPA.

**Customer Instructions**

Provider will Process Personal Data only in accordance with Customer's documented instructions to Provider, including as set out in this DPA, the Agreement, any applicable order form(s), and any other written instructions provided by Customer from time to time that are consistent with the Agreement and this DPA. To the extent Customer requests instructions that are outside the scope of the Services or that would require Provider to materially change the Services or undertake additional work not contemplated by the Agreement, the Parties will agree to such instructions in a mutually executed amendment to this DPA or other written agreement. By entering into this DPA, Customer instructs Provider to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The parties agree that the details of Provider's Processing of Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA.

**Security**

Provider Security Measures. Provider will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data as described in Annex 3 (the "Security Measures"), taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing and the risks to Data Subjects.  Provider may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.

Security Compliance by Provider Staff. Provider will require that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.

Information Security Incidents. Provider will notify Customer without undue delay of any Information Security Incident of which Provider becomes aware. Such notifications will describe, to the extent then known, available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Provider recommends Customer take to address the Information Security Incident. Provider's notification of or response to an Information Security Incident will not be construed as Provider's acknowledgement of any fault or liability with respect to the Information Security Incident. Provider will reasonably cooperate with Customer and take such commercially reasonable steps, to the extent within Provider's control, as may be reasonably requested by Customer and mutually agreed in good faith by the Parties to assist in the investigation of any such Information Security Incident. Customer is solely responsible for complying with notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Information Security Incident. If Customer determines that an Information Security Incident must be notified to any regulatory authority, any Data Subject(s), the public or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies Provider, where permitted by applicable law, Customer agrees to (i) notify Provider in advance, and (ii) in good faith, consult with Provider and consider any clarifications or corrections Provider may reasonably recommend or request to any such notification, which: (a) relate to Provider's involvement in or relevance to such Information Security Incident; and (b) are consistent with applicable law.

Customer's Security Responsibilities and Assessment

Customer's Security Responsibilities. Customer agrees that, without limitation of Provider's obligations under Section 4 (Security), Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer's systems and devices that Customer provides or makes available for Provider to access in order to provide the Services; and (d) backing up Personal Data, as applicable.

Customer's Security Assessment. Customer acknowledges that it has evaluated the Services, the Security Measures and Provider's commitments under this DPA and, based on information made available by Provider, determines that they are adequate to meet Customer's needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.

**Data Subject Rights**

Provider's Data Subject Request Assistance. Provider will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws ("Data Subject Requests") with respect to Personal Data in Provider's possession or control.  Customer will compensate Provider for any such assistance, to the extent such assistance requires work beyond the Services, at Provider's then-current professional services rates, which shall be made available to Customer upon request, and Provider will, upon request, provide Customer with a good-faith estimate of applicable fees.

Customer's Responsibility for Requests. If Provider receives a Data Subject Request, Provider will (i) promptly notify Customer (unless prohibited by applicable law); and (ii) advise the Data Subject to submit the request to Customer. Customer will be solely responsible for responding to any such request, unless otherwise required by applicable law.

**Customer Responsibilities**

Customer will ensure (and is solely responsible for ensuring) that it has provided all notices to, and obtained all consents and permissions from, third parties (including, without limitation, Data Subjects), and has reserved all necessary rights, in each case, as may be required under Applicable Data Protection Laws for Provider to Process Personal Data as contemplated by the Agreement.

Customer represents and warrants to Provider that Customer Data does not and will not contain any social security numbers or other government-issued identification numbers, protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; health insurance information; biometric information; passwords or other credentials for third-party online accounts (other than credentials created for and used solely to access the Services); credentials to any financial accounts; tax return data; any payment card information subject to the Payment Card Industry Data Security Standard; personal data of children under 16 years of age; or any other information that falls within any special categories of data (as defined in Applicable Data Protection Laws) ("**Restricted Data**").

**Subprocessors**

Consent to Subprocessor Engagement. Customer specifically authorizes the engagement of Provider's Affiliates as Subprocessors and generally authorizes Provider to engage third parties as Subprocessors in accordance with this Section.

Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available in Annex 4 of this DPA/at [WEBSITE] (the "Subprocessor Site"). Provider may continue to use those Subprocessors already engaged by Provider as of the effective date of this DPA.

Requirements for Subprocessor Engagement. When engaging any Subprocessor, Provider will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Provider will remain responsible for the performance of all obligations subcontracted to the Subprocessor and will be liable for all acts and omissions of the Subprocessor to the same extent as Provider would have been had it performed the Processing itself.

Opportunity to Object to Subprocessor Changes. When Provider engages any new Subprocessor after the effective date of the DPA, Provider will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor Site and providing written notice (including by email) to Customer's designated contact for Services-related communications, or by other written means. If Customer objects to such engagement in a written notice to Provider within 15 days after receipt of such notice on reasonable grounds relating to the protection of Personal Data, Customer and Provider will work together in good faith to find a mutually acceptable resolution to address such objection. If the Parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by providing written notice to Provider and pay Provider for all amounts due and owing under the Agreement as of the date of such termination.

**Audits**

Reviews and Audits of Compliance. Customer may audit Provider's compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct such additional audit or a competent regulatory authority with jurisdiction over Customer requires it, in each case upon Customer's written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Provider will contribute to such audits by providing Customer with the information and assistance reasonably necessary to conduct the audit.  If a third party is to conduct the audit, Provider may object to the auditor if the auditor is, in Provider's reasonable opinion, not independent, a competitor of Provider, or otherwise manifestly unsuitable.  Such objection by Provider will require Customer to appoint another auditor or conduct the audit itself.  To request an audit, Customer must submit a proposed audit plan to Provider at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the Parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Provider will review the proposed audit plan and provide Customer with any concerns or questions (for example, any request for information that could compromise Provider security, privacy, employment or other relevant policies). Provider will work cooperatively with Customer to agree on a final audit plan.  Nothing in this Section 8 will require Provider to breach any duties of confidentiality.  If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within 12 months of Customer's audit request and Provider has confirmed there have been no known material changes in the controls audited since the date of such report, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures.  The audit must be conducted during regular business hours, subject to the agreed final audit plan and Provider's safety, security or other relevant policies, and may not unreasonably interfere with Provider business activities.  Customer will promptly notify Provider of any non-compliance discovered during the course of an audit and provide Provider any audit reports generated in connection with any audit under this Section 8, unless prohibited by Applicable Data Protection Laws. Customer may use the audit reports only for the purposes of meeting Customer's regulatory audit requirements and/or confirming compliance with the requirements of this DPA.  Any audits are at Customer's sole expense. Customer will reimburse Provider for any reasonable, documented costs (including reasonable internal time expended by Provider and any third parties in connection with any audits or inspections under this Section 8 at Provider's then-current professional services rates, which shall be made available to Customer upon request). Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.

**Return and Deletion**

Subject to Sections 9(b) and 9(c), upon the date of cessation of any Services involving the Processing of Personal Data (the "Cessation Date"), Provider will promptly cease all Processing of Personal Data for any purpose other than for storage and Processing necessary to effect the return, deletion, or anonymization of such Personal Data, or as otherwise permitted or required under this DPA or applicable law.

Subject to Section 9(d), to the extent technically possible in the circumstances, on written request to Provider (to be made no later than 30 days after the Cessation Date ("Post-cessation Storage Period")), Provider shall within a commercially reasonable period following receipt of such request (i) return a complete copy of all Personal Data within Provider's possession to Customer by secure file transfer or other commercially reasonable secure method, promptly following which Provider shall delete or anonymize all other copies of such Personal Data, or (ii) (at its option) delete or anonymize all Personal Data within Provider's possession.

If, during the Post-cessation Storage Period, Customer does not instruct Provider in writing to either delete or return Personal Data under Section 9(b), Provider shall, within a commercially reasonable time after the expiry of the Post-cessation Storage Period, either (at its option) delete or render anonymous all Personal Data then within Provider's possession, custody or control to the fullest extent technically feasible in the circumstances.

Provider may retain Personal Data to the extent permitted or required by applicable law, for no longer than such applicable law requires, provided that Provider will (i) maintain the confidentiality of all such Personal Data and protect it in accordance with the Security Measures, (ii) Process such Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention, and (iii) delete or anonymize such Personal Data once it is no longer permitted or required to be retained under applicable law.

**Artificial Intelligence and Automated Processing**

Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether the Provider's own or a third party's, unless (a) such use is reasonably necessary to provide the Services in accordance with the Customer's documented instructions, or (b) expressly authorized by the Customer in writing.

Provider will prohibit its Subprocessors, including any AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as expressly authorized by the Customer in writing.

If the Services involve automated decision-making that produces legal or similarly significant effects on Data Subjects, Provider will: (a) disclose the existence of such processing to the Customer; (b) to the extent reasonably available to the Provider, provide meaningful information about the logic involved without requiring disclosure of the Provider's trade secrets or confidential information; and (c) reasonably cooperate with the Customer, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights under such laws relating to automated decision-making.

**Miscellaneous**

Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. To the extent of any conflict or inconsistency between this DPA and the other terms of the Agreement, this DPA will govern. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the Parties acknowledge and agree that Provider's access to Personal Data does not constitute part of the consideration exchanged by the Parties in respect of the Agreement.  Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Provider to Customer under this DPA may be given (a) in accordance with any notice clause of the Agreement; (b) to Customer's contact details for data protection set out in Annex 1; (c) to Provider's primary points of contact with Customer; or (d) to any email address designated by Customer in writing for the purpose of receiving Services-related communications or alerts. Customer is solely responsible for ensuring that such email addresses are valid.

Provider agrees to cooperate in good faith with Customer to consider any amendments that may be reasonably necessary to address compliance with the Applicable Data Protection Laws.

Provider may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, provided that any such variation will not materially reduce the protections afforded to Personal Data or materially increase Customer's obligations under this DPA without Customer's written agreement.

The total aggregate liability of either Party to the other Party, however arising, under or in connection with this DPA will under no circumstances exceed any limitations or caps on, and will be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement.

By signing below, the parties' duly authorized representatives agree to be legally bound by this DPA.

---
**Signature Block**

- [Customer Name]	 By:	 Name:	 Title:	 Date:
- [CompanyName]	 By:	 Name:	 Title:	 Date:

---

**Annex 1
Data Processing Details**

**PROVIDER DETAILS**

**Name:** [<mark>CompanyName</mark>]

**Address:** [<mark>INSERT</mark>]

**Contact Details for Data Protection:** [<mark>Role</mark>] ‍[<mark>Email</mark>] 

**Provider Activities:** [<mark>Brief Company description</mark>]

**CUSTOMER DETAILS**

**Name:** The entity or other person who is a counterparty to the Agreement

**Customer's address:** [<mark>INSERT</mark>]

**Customer's Contact Details for Data Protection:** [<mark>Role</mark>] ‍[<mark>Email</mark>]

**Customer Activities:** Customer's activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.

**Categories of Data Subjects:** Relevant Data Subjects include any Data Subjects whose Personal Data Customer causes Provider to Process in connection with the Services, including end-users and other users of Customer's products and services, and Customer's personnel (including employees and contractors) and other business contacts or representatives of Customer.

**Categories of Personal Data:** Relevant Personal Data includes any categories of Personal Data Customer causes Provider to Process as part of the provision of the Services, including:

**Personal details -** for example any information that identifies the Data Subject, including name and contact information.

**Authentication details -** for example usernames, passwords or PIN codes used to access the Services, security questions and other access protocols.

**Technological details -** for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifiers in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.

**Sensitive Categories of Data, and associated additional restrictions/safeguards:**

**Categories of sensitive data:** None - as noted in Section 6(b) of the DPA, Customer agrees that Restricted Data must not be submitted to the Services without the Parties' prior written agreement.

**Additional safeguards for sensitive data:** N/A

**Frequency of transfer:** Ongoing - as initiated by Customer in and through its use, or use on its behalf, of the Services.

**Nature of the Processing:** Processing operations required in order to provide the Services and perform Provider's obligations in accordance with the Agreement and this DPA.

**Purpose of the Processing:** As necessary to provide the Services as initiated by Customer in its use thereof, and to comply with Customer's documented instructions as permitted under and in accordance with the terms of this DPA and the Agreement.

**Duration of Processing / Retention Period:** For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA.

**Transfers to (sub)processors:** Transfers to Subprocessors are as, and for the purposes, described from time to time in the <mark>Subprocessor List (Annex 4) / Subprocessor Site</mark>.

**Annex 2
State Privacy Laws Annex**

For purposes of this Annex 2, the terms "business," "controller," "processor," "commercial purpose," "sell," "share," "service provider" and "contractor" shall have the respective meanings given thereto in the applicable State Privacy Laws, and "personal information" shall mean Personal Data to the extent it constitutes "personal information" or "personal data" (or a similar term) governed by the State Privacy Laws.

It is the Parties' intent that with respect to any personal information, Provider is a service provider, contractor and/or processor, as applicable under the State Privacy Laws. Provider (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Provider's Processing of personal information is consistent with Customer's obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon reasonable notice, including under the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

Provider will not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Provider and Customer; or (d) combine personal information received under the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Provider's own interaction with any Data Subject to whom such personal information pertains, except as and to the extent permitted by the State Privacy Laws and necessary as part of Provider's provision of the Services. Provider hereby certifies that it understands its obligations under this Section 3 and will comply with them.

Giving Customer notice of Subprocessor engagements in accordance with Section 7 of the DPA will satisfy Provider's obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.

Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Provider's use of personal information is consistent with Provider's obligations under the State Privacy Laws.

The Parties acknowledge that Provider's retention, use and disclosure of personal information authorized by Customer's instructions documented in the Agreement and this DPA are integral to Provider's provision of the Services and the business relationship between the Parties.

**Annex 3
Security Measures**

Organizational management and personnel with assigned responsibility for the development, implementation and maintenance of the Provider's information security program.

Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Provider's organization, monitoring and maintaining compliance with the Provider's policies and procedures, and reporting the condition of its information security and compliance to internal senior management.

Data security controls which include, at a minimum, logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available industry-standard encryption technologies (or materially equivalent safeguards) for Personal Data when transmitted over public networks (i.e., the Internet) or when transmitted wirelessly or at rest or stored on portable or removable media (i.e., laptop computers, CD/DVD, USB drives, back-up tapes).

Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions (e.g., granting access on a need-to-know and least-privilege basis, use of unique user IDs and appropriate authentication credentials for all users, and periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).

Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that the Provider maintain password controls for its employees that are consistent with generally accepted industry standards and appropriate to the risk, including:  (i) minimum password length and/or use of multi-factor authentication as appropriate; (ii) not being stored in readable format on the Provider's computer systems (e.g., stored using industry-standard hashing and salting); (iii) appropriate complexity or other compensating controls; (iv) having a history threshold to prevent reuse of recent passwords; and (v) newly issued or reset passwords being changed after first use.

System audit or event logging and related monitoring procedures to proactively record user access and system activity.

Physical and environmental security of data centers, server room facilities and other areas containing Personal Data designed to: (i) protect information assets from unauthorized physical access, (ii) as appropriate, manage, monitor and log movement of persons into and out of the Provider's facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.

Operational procedures and controls to provide for the secure configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media in accordance with commercially reasonable industry standards to render all information or data contained therein unreadable and, to the extent technically feasible, unrecoverable prior to final disposal or release from the Provider's possession.

Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to Provider's technology and information assets that may affect the security of Personal Data.

Incident management procedures designed to allow Provider to investigate, respond to, mitigate, and provide notifications in accordance with this DPA regarding events related to Provider's technology and information assets.

Network security controls designed to protect systems from intrusion and limit the scope of any successful attack, including the use of firewalls and network segmentation, and intrusion detection and/or prevention, monitoring, and traffic and event correlation procedures.

Vulnerability assessment, patch management and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.

Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters.

**Annex 4
List of Subprocessors**

Customer approves Provider's engagement of the following Subprocessors to provide services under the Agreement:

[<mark>Name of Subprocessor | Location(s) | Description of Processing / Services Performed</mark>]

---

This template was prepared and made publicly available by General Legal, PC ("General Legal"). It is provided for general reference purposes only and does not constitute, and should not be construed as, legal advice, or an endorsement or review of any particular transaction in which it is used. Use of this template does not create an attorney-client relationship with General Legal. General Legal has not reviewed, and takes no position on, any modifications made to this document or the deal terms it is used to document.
