DATA PROCESSING ADDENDUM

Last updated: August 4, 2026

Worksprings, LLC d/b/a HuntDocs — myhuntdocs.com

This Data Processing Addendum (“DPA”) forms part of the HuntDocs Terms of Service (the “Terms”) between Worksprings, LLC d/b/a HuntDocs (“HuntDocs”) and the Outfitter identified in the applicable account (“Customer”), and applies to the extent HuntDocs processes Personal Information contained in Customer Data on Customer’s behalf. Capitalized terms not defined here have the meanings given in the Terms.

1. DEFINITIONS

2. ROLES AND SCOPE

Customer determines the purposes and means of Processing Personal Information (acting as the controller, the “agency” under the New Zealand Privacy Act 2020, or the accountable organization under PIPEDA), and HuntDocs Processes Personal Information only on Customer’s behalf and documented instructions as a service provider / processor. Customer’s instructions are: (a) these Terms and this DPA; (b) Customer’s configuration and use of the Services; and (c) other written instructions agreed by the parties. HuntDocs will notify Customer if, in its opinion, an instruction violates applicable Privacy Laws (without any obligation to monitor Customer’s compliance), and may suspend the affected Processing until Customer issues a revised lawful instruction. HuntDocs certifies that it understands and will comply with the restrictions applicable to a “service provider” under the California Consumer Privacy Act, as amended (Cal. Civ. Code § 1798.140(ag)).

HuntDocs will not sell Personal Information and will not “share” it for cross-context behavioral advertising (as those terms are defined under California law); will not use it for advertising or profiling purposes of its own; will not combine it with personal information received from other sources or collected from HuntDocs’ own interactions with individuals, except as necessary for the business purposes described in this DPA; and will not Process it for any purpose other than providing, securing, and supporting the Services and complying with law. HuntDocs may create aggregated or de-identified data from Customer Data — data that does not identify, and cannot reasonably be used to re-identify, Customer or any individual — and may use that data to operate, analyze, and improve the Services. Customer may take reasonable and appropriate steps to ensure that HuntDocs uses Personal Information consistently with Customer’s obligations under Privacy Laws and, upon written notice, may require HuntDocs to stop and remediate any unauthorized use of Personal Information.

Customer is responsible for: (a) the accuracy and lawfulness of Personal Information it submits; (b) providing privacy notices to, and obtaining any required consents from, the individuals whose Personal Information it Processes through the Services; and (c) its own compliance with Privacy Laws applicable to it as a controller/agency/organization.

3. CONFIDENTIALITY

HuntDocs will ensure that personnel authorized to Process Personal Information are subject to written confidentiality obligations, and will limit access to personnel who need it to provide, secure, or support the Services. These confidentiality obligations survive the termination of each individual’s employment or engagement, and HuntDocs provides its personnel with data protection training at least annually.

4. SECURITY

HuntDocs will maintain appropriate administrative, technical, and physical safeguards designed to protect Personal Information against Security Incidents, as described in Annex B, and will not materially decrease the overall protection of the Services during a subscription term. HuntDocs will review and update its security measures periodically in light of evolving threats, technological developments, and industry practices, and will notify Customer of any change that materially decreases the protections described in Annex B. HuntDocs does not warrant that its security measures will prevent all unauthorized access; the remedies for a Security Incident are as set out in this DPA and the Terms.

5. SUB-PROCESSORS

Customer generally authorizes HuntDocs to engage the Sub-processors listed in Annex C, and to replace or add Sub-processors, provided that HuntDocs: (a) imposes data-protection obligations on each Sub-processor that are at least as protective as those in this DPA, to the extent applicable to the services the Sub-processor provides; (b) remains responsible to Customer for each Sub-processor’s performance; and (c) gives Customer at least 30 days’ notice (by email to the account address or by notice in the Services) before a new Sub-processor Processes Personal Information. If Customer reasonably objects on data-protection grounds within that period and the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused term as its exclusive remedy.

6. SECURITY INCIDENT NOTIFICATION

HuntDocs will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of, or having reasonable grounds to believe there has been, a Security Incident affecting Customer’s Personal Information. The notification will describe, to the extent then known: the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed to address it, with updates as material information becomes available. HuntDocs will take reasonable steps to contain and remediate the incident. Customer, as the controller/agency/accountable organization, is responsible for determining whether the incident is notifiable to regulators or individuals under Privacy Laws applicable to Customer (including notifiable privacy breaches under the NZ Privacy Act 2020 and breaches of security safeguards under PIPEDA), and HuntDocs will provide reasonable cooperation and information to support those assessments and notifications. HuntDocs’ notification of or response to a Security Incident is not an acknowledgment of fault or liability.

7. ASSISTANCE WITH INDIVIDUALS' RIGHTS AND INQUIRIES

Taking into account the nature of the Processing, HuntDocs will provide reasonable assistance to Customer (through the features of the Services and, where those are insufficient, on request) in responding to requests from individuals to access, correct, or delete their Personal Information under applicable Privacy Laws, including access and correction requests under the NZ Privacy Act 2020 (IPPs 6 and 7) and PIPEDA. If HuntDocs receives such a request directly, it will direct the individual to the Customer, except where legally required to respond itself. HuntDocs will also provide reasonable assistance with Customer's privacy impact assessments and regulator inquiries relating to the Services, to the extent the required information is available to HuntDocs.

8. CROSS-BORDER PROCESSING AND TRANSFERS

The Services are hosted in the United States, and Personal Information is Processed and stored in the United States by HuntDocs and the Sub-processors listed in Annex C. For Customers in New Zealand: this DPA constitutes the written agreement contemplated by the NZ Privacy Act 2020 under which HuntDocs, as Customer's service provider, is required to protect Personal Information with safeguards that, taken as a whole, are comparable to those in the New Zealand Information Privacy Principles, including limits on use and disclosure (Section 2), security safeguards (Section 4 and Annex B), breach notification (Section 6), assistance with access and correction (Section 7), and retention limits (Section 9). HuntDocs acknowledges that under the NZ Privacy Act 2020 it may use or disclose the information only for the purposes for which Customer engaged it. For Customers subject to PIPEDA or substantially similar Canadian provincial laws: Customer remains accountable for Personal Information transferred to HuntDocs for processing, and this DPA provides the contractual protection PIPEDA's accountability principle contemplates for transfers to a third-party processor, including comparable protection while the information is in HuntDocs' hands. HuntDocs will notify Customer, unless legally prohibited, of any legally binding demand by a government authority for disclosure of Customer's Personal Information, and will challenge or narrow overbroad demands where reasonably practicable.

9. RETENTION, RETURN, AND DELETION

HuntDocs retains Personal Information for as long as Customer maintains it in the Services. Upon termination or expiration of Customer's subscription: (a) for 60 days, Customer may export Customer Data, including completed signed Documents, in commonly used formats as described in Section 18.4 of the Terms; (b) after that period, HuntDocs will delete Customer Data from active systems within 30 days, and residual copies will be removed from backups as they age out of the backup rotation cycle (currently daily backups retained for approximately one week and weekly backups for approximately one month), and in any event within 45 days; and (c) HuntDocs may retain information to the extent required by law, or as contained in routine backups pending rotation, in each case protected under this DPA until deleted. On written request, HuntDocs will confirm deletion.

10. AUDITS AND INFORMATION

On written request no more than once per 12-month period (or following a Security Incident affecting Customer), HuntDocs will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, architecture descriptions, Sub-processor diligence summaries, and completed security questionnaires. Where Privacy Laws applicable to Customer require more, the parties will discuss a mutually agreed audit process at Customer's expense, conducted so as not to disrupt the Services or compromise other customers' data.

11. LIABILITY AND ORDER OF PRECEDENCE

This DPA is subject to the limitations and exclusions of liability in the Terms, and the parties' aggregate liability arising under or in connection with this DPA is subject to Section 15 of the Terms. In case of conflict between this DPA and the Terms with respect to the Processing of Personal Information, this DPA controls. This DPA is governed by the same law and dispute-resolution provisions as the Terms (Sections 22 and 23), and terminates automatically upon deletion of Personal Information under Section 9.

ANNEX A — DETAILS OF PROCESSING

ANNEX B — SECURITY MEASURES

ANNEX C — SUB-PROCESSORS

Customer-directed integrations. Where Customer connects its own third-party accounts to the Services — currently QuickBooks Online (Intuit Inc.) — the resulting transfer of Personal Information to that provider is made at Customer’s direction under Customer’s own agreement with the provider, and the provider is not a HuntDocs Sub-processor.