Data Processing Addendum

For business customers using North, Agents, or both.

Version: October 3, 2026

This Data Processing Addendum ("DPA") is between Novo Industries, Inc. ("Novo") and the business customer identified in the customer agreement ("Customer"). It covers Novo North, Novo Agents, or both, as ordered. It takes effect when incorporated into or executed with that agreement. Posting this page alone does not execute a DPA.

1. Scope and instructions

"Customer Personal Data" means personal information Novo processes on Customer's behalf through the ordered services. Applicable Data Protection Law includes the EU GDPR, UK GDPR and other privacy laws applicable to that processing. Customer acts as controller, or as a processor authorized by its controller; Novo acts as processor or subprocessor respectively. This DPA does not govern information Novo processes as controller for its own accounts, billing, security and legal obligations, described in the relevant Privacy Policy.

Novo will process Customer Personal Data only on documented instructions to provide, secure and support the services, including the agreement, service settings and authorized requests. Customer is responsible for its lawful basis, required notices and authority to issue instructions. Novo will inform Customer if it believes an instruction violates Applicable Data Protection Law. If law requires other processing, Novo will notify Customer before processing unless prohibited by law. Novo will not use Customer Personal Data to train AI models.

2. Confidentiality and security

Novo will ensure that people authorized to process Customer Personal Data are bound by confidentiality duties. Novo will maintain technical and organizational measures appropriate to the risks, including the measures in Annex II, and will not materially reduce their overall protection during the agreement.

3. Subprocessors

Customer gives general written authorization for the providers in the shared subprocessor register, including their disclosed downstream providers, insofar as needed for the ordered services. Novo remains responsible for their processing obligations and will impose equivalent data-protection obligations by written contract.

Novo will give notice to Customer's designated privacy contact at least seven calendar days before an intended addition or replacement begins processing Customer Personal Data, including changes to downstream providers. Customer may object before the change on reasonable data-protection grounds. The parties will work to resolve the objection; if they cannot, Customer may terminate the affected service before the new provider processes its data and receive a refund of prepaid fees for the unused terminated period. Novo will provide the identities, contact details, processing activities and locations of relevant providers on request.

4. Assistance and incidents

Taking account of the processing and information available, Novo will assist Customer with individuals' rights requests, security obligations, breach notifications, impact assessments and regulator consultations. Novo will refer requests concerning Customer Personal Data to Customer unless law requires otherwise.

Novo will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Novo will provide available information about the breach, affected data and people, likely consequences, and mitigation, with further information as it becomes available, and cooperate with Customer's response. A notice is not an admission of liability.

5. Return, deletion and audits

At the end of the processing services, Novo will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies, unless law requires retention. Customer may use supported export and deletion tools or send instructions to privacy@novoindustries.co. Any data remaining in backups will be protected, kept beyond operational use and deleted in the applicable backup cycle. Legally required retained data will be limited to that purpose and remain protected.

Novo will provide information needed to demonstrate compliance with this DPA and allow and contribute to audits and inspections by Customer or its independent auditor. The parties will coordinate reasonable scope, confidentiality and timing to protect other customers and service security. These arrangements do not limit audits required by law, a regulator, or a material breach.

6. International transfers and precedence

The services involve processing in the United States and other countries used by the relevant providers. Novo will ensure that restricted transfers have safeguards required by Applicable Data Protection Law. For transfers from the EEA to Novo requiring standard clauses, the EU Standard Contractual Clauses in Decision 2021/914 are incorporated, using Module Two for a controller Customer and Module Three for a processor Customer. Clause 7 applies; Clause 9 uses general authorization with seven calendar days' notice; Clause 11's optional language does not apply; Clause 17 uses Irish law; Clause 18 selects Irish courts. Annexes I and II are completed below; the competent supervisory authority is determined under Clause 13.

For restricted UK transfers, the ICO International Data Transfer Addendum, version B1.0, including its mandatory clauses, is incorporated. Table 1 uses the parties, contacts and start date in Annex I and the customer agreement. Table 2 uses the EU clauses, modules and selections above. Table 3 uses Annexes I and II and the shared register for provider information. In Table 4, neither party may end the Addendum under Section 19. The Addendum applies its required UK-law and court substitutions.

The applicable transfer clauses prevail over this DPA, which prevails over conflicting agreement terms concerning Customer Personal Data. Other agreement terms continue to apply without limiting mandatory data-subject rights or legal obligations. The parties will document any additional required transfer safeguards before the affected processing.

Annex I: Parties and processing

  • Exporter: Customer, with legal name, address and privacy contact identified in the customer agreement. Its role is controller or processor as applicable. Its relevant activity is using the ordered services for its business and directing the processing described here.
  • Importer: Novo Industries, Inc., 169 Madison Ave, #67931, New York, NY 10016, United States; privacy@novoindustries.co. Its role is processor or subprocessor. Its relevant activity is operating the ordered services.
  • Acceptance and date: incorporation or execution of this DPA in the customer agreement records both parties' acceptance and its effective date. The agreement must identify Customer and its privacy contact and complete required party details, including registration numbers and legal addresses where applicable, before this DPA is used.
  • People: Customer's members, employees, contractors, meeting participants, customers, suppliers and others whose information Customer supplies or authorizes the services to access.
  • Data: identifiers and contact details; messages, prompts, files, records, images, audio/video and transcripts; connected-service data and credentials; tool inputs/results, generated outputs and related technical metadata. Customer determines the specific contents. Special-category data may be included only where Customer has an appropriate legal basis and has agreed any additional safeguards needed with Novo before processing.
  • Nature and purpose: collection, transmission, storage, retrieval, analysis, AI inference, media processing, transcription, authorized tool execution and output generation to provide, secure and support the ordered services on Customer's instructions.
  • Frequency and duration: ongoing transfers as Customer uses the services, for the agreement's duration and the return/deletion period in Section 5. Customer controls submitted content and instructions. Novo's processing duties continue for retained Customer Personal Data.
  • Subprocessor activities: the feature-specific purposes in the shared register, for the relevant service's duration and applicable deletion period.

Annex II: Security measures

  • Encryption in transit and at rest; application encryption of saved credentials.
  • Authenticated access and workspace-scoped authorization to Customer Data; workspace-scoped API keys for Agents.
  • Provider credentials kept in Novo-managed infrastructure; saved customer credentials used for authorized work.
  • Managed isolation for Novo-hosted sandbox and browser work; customer-hosted environments remain Customer's responsibility.
  • Service error and abuse monitoring, access restrictions, and confidentiality obligations for authorized personnel.
  • Maintenance and assessment of security controls, incident response, and cooperation with Customer's data-protection obligations under this DPA.

The North security overview and Agents security overview describe product-specific controls. Customer remains responsible for account security, permissions and connected systems.

Contact

Send DPA requests, privacy instructions and your designated notice contact to privacy@novoindustries.co.