Taktile raised a $110M Series C led by Goldman Sachs to power AI transformation in financial services. Learn more →

Taktile

Global Data Processing Agreement

Effective Date: As defined in the Agreement

This Global Data Processing Agreement (“DPA”) is incorporated into and forms part of the Agreement between the applicable Taktile entity and Customer (“you,” “your,” or “Customer”) as defined in the Terms of Service.

Taktile,” “we,” “us,” or “our” means:

Taktile LLC, a Delaware limited liability company with its principal place of business at 200 Vesey Street, Brookfield Place, New York, NY 10281, USA, for Customers located in the United States, Canada, or South America regions.

Taktile GmbH, a German limited liability company registered at HRB 216607 B, Amtsgericht Charlottenburg, with offices in  Schönhauser Allee 9, 10119 Berlin, Germany, for Customers located in the European Union and  Switzerland.

Taktile Limited, a company incorporated under the laws of England and Wales with registered number 16992965, with its registered office at 30 Old Bailey, London, United Kingdom, EC4M 7AU, for Customers located in the United Kingdom, or Asia-Pacific regions.

The applicable Taktile entity is determined by the Terms of Service executed between the parties.

This DPA governs the processing of Covered Personal Information in connection with the Taktile Services and addresses requirements under applicable Privacy Laws. This DPA is designed to meet the requirements of global privacy laws including GDPR, CCPA/CPRA, LGPD, and other applicable regulations.

For additional security and compliance information, please visit our Trust Center at https://app.vanta.com/taktile.com/trust/5fofvswspy35fupntb4i6.

1. DEFINITIONS

1.1 General Definitions. Capitalized terms not defined in this DPA have the meanings given in the Agreement. “Agreement” means the Terms of Service or other written agreement between Customer and the applicable Taktile entity governing Customer’s use of the Taktile Services. “Taktile” means the Taktile entity (Taktile LLC, Taktile GmbH or Taktile Limited) with which Customer has contracted, as specified in the Agreement. This DPA supplements and is incorporated into Section 11 (Privacy and Security) of the Terms of Service. In the event of conflict between this DPA and Section 11, this DPA controls with respect to Covered Personal Information.

1.2 “Covered Personal Information” means personal data or personal information that is Customer Data and has been or will be uploaded by (or on behalf of) Customer to the Taktile Platform for processing through Customer’s decision flows. For avoidance of doubt, Covered Personal Information does not include: (a) Usage Data; (b) business contact information of Authorized Users used for account access and platform administration (e.g., names, business email addresses, login credentials); or (c) any information that does not constitute 'personal data' or 'personal information' under applicable Privacy Laws.

1.3 “Data Subject” means an identified or identifiable natural person to whom Covered Personal Information relates.

1.4 “Privacy Laws” means applicable statutes, regulations or other laws pertaining to privacy or data protection, processing of personal information, and/or information security, including, but not limited to: the EU General Data Protection Regulation 2016/679 (“GDPR”); United Kingdom General Data Protection Regulation (“UK GDPR”); UK Data (Use and Access) Act 2025 (effective in phases through June 2026); the revised Swiss Federal Act on Data Protection (“revFADP”); Brazil Law No. 13,709/2018 (“LGPD”); Personal Information Protection and Electronic Documents Act (“PIPEDA”); California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”); the Virginia Consumer Data Protection Act (“VCDPA”); the Colorado Privacy Act (“CPA”); the Utah Consumer Privacy Act (“UCPA”); the Connecticut Act Concerning Personal Data Protection and Online Monitoring (“PDPOM”); Montana Consumer Data Privacy Act (Mont. Code Ann. § 30-14-1901 et seq.); Delaware Personal Data Privacy Act (Del. Code Ann. tit. 6, § 12D-101 et seq.); Iowa Consumer Data Protection Act (Iowa Code Ch. 715D); Indiana Consumer Data Protection Act (Ind. Code § 24-15); Nebraska Data Privacy Act (Neb. Rev. Stat. § 87-401 et seq.); New Hampshire Privacy Act (N.H. Rev. Stat. Ann. § 507-H); New Jersey Data Protection Act (N.J. Stat. Ann. § 56:8-166 et seq.); Minnesota Consumer Data Privacy Act (Minn. Stat. § 325O); Texas Data Privacy and Security Act (Tex. Bus. & Com. Code § 541 et seq.); Oregon Consumer Privacy Act (Or. Rev. Stat. § 646A.600 et seq.); Tennessee Information Protection Act (Tenn. Code Ann. § 47-18-3201 et seq.); Kentucky Consumer Data Protection Act (Ky. Rev. Stat. Ann. § 365.851 et seq.); Rhode Island Data Transparency and Privacy Act (R.I. Gen. Laws § 6-48.1 et seq.); German Federal Data Protection Act (“BDSG”); German Telecommunications Act (Telekommunikationsgesetz - “TKG”); German Telemedia Act (Telemediengesetz - “TMG”); and any other applicable federal, state, provincial, or local laws or regulations regarding information privacy that are in effect or will come into effect during the term of the Agreement.

1.5 “Processing” means any operation or set of operations performed on Covered Personal Information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

1.6 “Sensitive Personal Information” means, to the extent treated distinctly as a special category of personal information under Privacy Laws: (a) personal information that is genetic data, biometric data, data concerning health, a natural person’s sex life or sexual orientation; (b) data about racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; or (c) precise geolocation data.

1.7 “Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries pursuant to European Commission Implementing Decision (EU) 2021/914 (and any successor clauses).

1.8 “Subprocessor” means any third party appointed by or on behalf of Taktile to process Covered Personal Information.

1.9 Jurisdictional Applicability. The jurisdiction-specific provisions in Section 13 apply only to the extent Customer’s use of the Services involves processing activities subject to the laws of that jurisdiction. If Customer does not process personal data of residents in a particular state, region, or country, the corresponding provisions in Section 13 do not apply and may be disregarded. Customer is responsible for determining which jurisdictions’ laws apply to its processing activities.


2. DATA PROCESSING RELATIONSHIP

2.1 Roles and Responsibilities. Customer is the controller (or business, or “controlador” under LGPD) and the applicable Taktile entity is the processor (or service provider, or “operador” under LGPD, or “Auftragsverarbeiter” under GDPR/BDSG) of Covered Personal Information under applicable Privacy Laws. Customer retains control of the Covered Personal Information and remains responsible for its compliance obligations under applicable Privacy Laws, including providing any required notices and obtaining any required consents.

2.2 Processing Instructions. Taktile processes Covered Personal Information only in accordance with Customer’s documented instructions as set forth in this DPA and the Agreement, unless required to process such information by applicable law. If Taktile believes any instruction violates applicable Privacy Laws, Taktile will promptly notify Customer and may suspend execution of the instruction until Customer confirms or modifies it. For the avoidance of doubt, Customer’s activation of features or services through the Platform’s administrative controls (including enablement of AI Agents functionality and selection of Optional Subprocessors) constitutes a documented instruction for purposes of this Section.

2.3 Processing Scope. The details of processing, including subject matter, duration, nature, purpose, categories of Covered Personal Information, and categories of Data Subjects, are set forth in Exhibit A attached hereto.

2.4 Customer Processing Controls. Customer may configure certain processing parameters through the Taktile Services interface or via email (as indicated below), including:

- Data retention periods (within applicable limits)
- Automated decision-making parameters
- Access controls and user permissions
- Export and deletion requests (requests are made via email at privacy@taktile.com

2.5 Compliance with Privacy Laws. Taktile will comply with all Privacy Laws applicable to Taktile’s processing of Covered Personal Information in its role as processor, service provider, or operador. Customer will comply with all Privacy Laws applicable to Customer’s processing of Covered Personal Information in its role as controller, business, or controlador. Each Party is responsible for its own compliance obligations under applicable Privacy Laws.


3. DATA PROCESSING RESTRICTIONS

3.1 Processing Limitations. Taktile will not:

(a) sell or share Covered Personal Information;

(b) retain, use, or disclose Covered Personal Information for any purpose other than the limited purposes specified in the Agreement and this DPA; or

(c) unless permitted by applicable Privacy Laws, (i) retain, use, or disclose Covered Personal Information outside the direct business relationship with Customer, or (ii) retain, use, or disclose Covered Personal Information for any commercial purpose not specified in the Agreement or this DPA.

3.2 Confidentiality. Taktile will maintain the confidentiality of all Covered Personal Information and will not disclose it to third parties unless Customer or this DPA specifically authorizes the disclosure, or as required by law. If required by law to disclose Covered Personal Information, Taktile will first inform Customer of the legal requirement and give Customer an opportunity to object or challenge the requirement, unless prohibited by law.

3.3 Employee Obligations. Taktile ensures that employees processing Covered Personal Information are informed of applicable Privacy Laws and bound by appropriate confidentiality obligations during and after their employment.


4. SUBPROCESSORS

4.1 Standard Subprocessors. Customer hereby provides general authorization for Taktile to engage Subprocessors to process Covered Personal Information. The following Subprocessors are engaged by Taktile LLC, Taktile GmbH and Taktile Limited as of the Effective Date and are deemed approved by Customer upon execution of the Agreement:

Amazon Web Services – Cloud infrastructure

An updated list of Subprocessors is maintained in Taktile’s Trust Center at https://app.vanta.com/taktile.com/trust/5fofvswspy35fupntb4i6/subprocessors

4.2 Subprocessor Changes. Taktile will provide at least thirty (30) days’ prior written notice of any intended changes concerning the addition or replacement of Subprocessors by updating the Trust Center and providing email notification to Customer’s designated contact. Such notice constitutes Taktile’s fulfillment of its notification obligation, and no additional consent or approval from Customer is required unless Customer exercises its objection rights under Section 4.3. The following Subprocessors shall be exempt from the notice requirement: (a)); Security and monitoring service providers; (b) Subprocessors engaged for emergency security or operational purposes (with notice provided within 48 hours); and (c) Subprocessors listed in this Section 4.

4.3 Objection Rights. Customer may object in writing to any new or replacement Subprocessor on reasonable data protection grounds within thirty (30) days of receiving notice. The objection must specify the data protection concerns that form the basis of the objection. If Customer timely objects on reasonable grounds, Taktile will use commercially reasonable efforts to: (a) make available to Customer a change in the Services or recommend a commercially reasonable change to Customer’s configuration or use of the Services to avoid processing of Covered Personal Information by the objected-to Subprocessor; or (b) provide an alternative solution. If Taktile is unable to provide an alternative within sixty (60) days of Customer’s objection, Customer may terminate the affected Services by providing written notice to Taktile, and Customer will receive a pro-rata refund of any prepaid fees for the terminated Services covering the remainder of the then-current term.

4.4 Subprocessor Obligations. Taktile ensures all Subprocessors are bound by written agreements requiring them to provide at least the same level of data protection as required under this DPA and applicable Privacy Laws. Taktile remains fully liable to Customer for the performance of any Subprocessor’s obligations under this DPA.

4.5 Optional Subprocessors.

(a) Definition. “Optional Subprocessors” are third-party service providers that process Covered Personal Information only when Customer affirmatively elects to use an integrated service or feature that requires such processing. Optional Subprocessors are not engaged by default and do not process Covered Personal Information unless Customer activates the applicable service through the Platform’s administrative controls or an applicable Order Form. For the avoidance of doubt, Customer acknowledges that for certain features (e.g., AI Copilots), the Platform may pre-select a specific Optional Subprocessor.

(b) Categories. The following categories of Optional Subprocessors may be engaged upon Customer’s election:

(i) AI Model Providers. Third-party providers of large language models or other generative AI technologies that process Covered Personal Information in connection with AI Agents functionality on the Platform. AI Model Providers are engaged only where Customer enables AI Agents and selects a third-party AI model provider through the Platform’s administrative controls.

(ii) Third-Party Data Providers. Third-party providers of data enrichment, credit, identity verification, fraud detection, or similar data services that Taktile makes available to Customer as a reseller through the Platform pursuant to Section 3.4(b) of the Terms of Service. These specific Optional Subprocessors are identified in the applicable Order Form at the time Customer orders the integrated service.

(c) Activation as Documented Instruction. Customer’s activation of a feature or service that engages an Optional Subprocessor, whether through the Platform’s administrative controls or by executing an Order Form that includes such service, constitutes Customer's documented instruction to Taktile to engage that Optional Subprocessor for the processing of Covered Personal Information. Customer’s designated administrator is responsible for determining which Optional Subprocessors are activated for the Customer Account.

(e) Data Processing Location. Covered Personal Information processed by Optional Subprocessors may be transferred to and processed in jurisdictions outside Customer's primary data processing location as specified in Section 8.1. The processing locations for each Optional Subprocessor are identified in the applicable Order Form and the Trust Center.

(f) Obligations. Taktile ensures that all Optional Subprocessors are bound by written agreements requiring them to provide at least the same level of data protection as required under this DPA. Taktile remains liable to Customer for the performance of Optional Subprocessors' obligations to the same extent as for Subprocessors under Section 4.4.

(g) Changes and Objection Rights. Changes to Optional Subprocessors for services Customer has elected to use are subject to the notice and objection rights set forth in Sections 4.2 and 4.3. Customer may also deactivate any Optional Subprocessor at any time through the Platform’s administrative controls or by written notice to Taktile, which shall constitute an instruction to cease processing through that provider. Deactivation may result in the unavailability of features that depend on the deactivated Optional Subprocessor.


5. SECURITY MEASURES

5.1 Technical and Organizational Measures. Taktile implements and maintains appropriate technical and organizational measures to ensure processing complies with Privacy Laws and protects Data Subject rights. These measures ensure appropriate security of processing, including confidentiality, integrity, availability, and resilience of systems processing Covered Personal Information. Such measures meet or exceed applicable industry standards for financial services data processing.

5.2 Security Standards. Taktile maintains information security practices and controls as detailed in Exhibit B and the Trust Center at https://app.vanta.com/taktile.com/trust/5fofvswspy35fupntb4i6/controls, including but not limited to:

- Encryption of data at rest using AES-256 or equivalent
- Encryption of data in transit using TLS 1.2 or higher
- Role-based access control with principle of least privilege
- Multi-factor authentication for all system access
- Regular penetration testing by qualified third parties
- Centralized vulnerability management and patch procedures
- Daily automated backups
- Security monitoring and incident response capabilities

5.3 Security Certifications and Attestations. Taktile maintains SOC 2 Type II and ISO 27001:2022 certifications applicable to Taktile LLC,  Taktile GmbH and Taktile Limited operations. Current certification documentation is available through the Trust Center.

5.4 Security Updates. Technical and organizational measures may be updated to reflect technological developments and evolving security threats, provided the updated measures maintain at least the same level of security. Material changes will be documented and communicated to Customer.


6. DATA SUBJECT RIGHTS

6.1 Data Subject Requests. Taktile will promptly notify Customer within five (5) business days if it receives any request from a Data Subject to exercise rights under Privacy Laws regarding their Covered Personal Information. Taktile will provide Customer with all relevant documentation and correspondence related to such requests and will not respond directly to the Data Subject without Customer’s prior written authorization.

6.2 Assistance with Rights. Taking into account the nature of processing, Taktile will assist Customer by implementing appropriate technical and organizational measures, insofar as reasonably practicable, to help Customer fulfill its obligations to respond to Data Subject requests under Privacy Laws, including requests for:

- Access to personal information
- Correction or rectification of inaccurate data
- Deletion or erasure of personal information
- Restriction of processing
- Data portability
- Objection to processing

6.3 Data Protection Impact Assessments. Upon Customer’s reasonable request, Taktile will provide assistance and information reasonably necessary to enable Customer to conduct data protection impact assessments and consultations with supervisory authorities as required by applicable Privacy Laws.

6.4 Data Retention. Taktile retains Covered Personal Information only for as long as necessary to fulfill the purposes outlined in this DPA and the Agreement, or as required by applicable law. 


7. SECURITY INCIDENTS AND BREACH NOTIFICATION

7.1 Incident Notification. Taktile will notify Customer without undue delay, and in any event within forty-eight (48) hours, upon becoming aware of any confirmed unauthorized access, destruction, use, modification, or disclosure of Covered Personal Information (a “Security Incident”).

7.2 Incident Response Timeline. Following discovery of a Security Incident, Taktile will:

- Initial notification: Within 48 hours of discovery
- Preliminary assessment: Within 72 hours, including affected data categories and estimated number of Data Subjects
- Root cause analysis and remediation plan: Within 15 business days

7.3 Incident Information. Taktile will provide Customer with information and cooperation reasonably requested regarding Security Incidents, including:

- Description of the nature of the Security Incident
- Categories and approximate number of Data Subjects affected
- Categories and approximate number of Covered Personal Information records affected
- Likely consequences of the Security Incident
- Measures taken or proposed to address the Security Incident and mitigate potential adverse effects

7.4 Third-Party Notification. Taktile will not inform any third party of Security Incidents involving Covered Personal Information without Customer’s prior written consent, except as required by law. Customer has the sole right to determine whether to notify Data Subjects, supervisory authorities, or other parties as required by law.


8. CROSS-BORDER DATA TRANSFERS

8.1 Data Processing Location.

(a) For Customers contracting with Taktile LLC (customers in the United States, Canada, and South America): Covered Personal Information is processed and stored primarily in the United States using Amazon Web Services infrastructure located in the United States.

(b) For Customers contracting with Taktile GmbH (customers in the European Union and Switzerland): Covered Personal Information is processed and stored primarily in Germany using Amazon Web Services infrastructure located in Germany. 

(c) For Customers contracting with Taktile Limited (customers in the United Kingdom and Asia Pacific regions): Covered Personal Information is processed and stored primarily in the UK using Amazon Web Services infrastructure located in the UK, unless otherwise agreed in writing.

By using the Taktile Services and entering into this DPA, Customer authorizes processing and storage in the applicable location based on the contracting entity.

​​Notwithstanding 8.1(a) - (c) above, Taktile may deploy Customer’s infrastructure into a different region upon Customer’s prior written request (email will suffice).

8.2 Limited Cross-Border Transfers. Notwithstanding Section 8.1, Covered Personal Information may be accessed or processed outside the primary storage location in limited circumstances, including:

(a) Technical support and incident response by Taktile personnel located in the United States,  European Union, or the United Kingdom;

(b) Use of Subprocessors as listed in Section 4.1 and the Trust Center;

(c) Backup and disaster recovery operations; or

(d) As necessary to provide the Taktile Services or comply with legal obligations.

8.3 Safeguards for International Transfers.

(a) Transfers within adequate jurisdictions: Where transfers occur between jurisdictions recognized as providing adequate data protection (e.g., within the EEA, or pursuant to adequacy decisions), no additional safeguards are required beyond those set forth in this DPA.

(b) Transfers from the EU/UK/Switzerland to the United States: Where Taktile GmbH transfers Covered Personal Information to Taktile LLC or US-based personnel for the limited purposes described in Section 8.2, such transfers are governed by the Standard Contractual Clauses set forth in Exhibit D.

(c) Transfers from Brazil to the United States: Transfers from Brazil comply with LGPD Chapter V requirements, including appropriate contractual, technical, and organizational safeguards.

(d) Other international transfers: For any other cross-border transfers, Taktile implements appropriate safeguards as required by applicable Privacy Laws.

8.4 Standard Contractual Clauses. Where the Standard Contractual Clauses apply under Section 8.3(b), they are incorporated into this DPA as Exhibit D with the following specifications:

- Module Two (controller-to-processor) applies
- Customer is the data exporter; Taktile LLC is the data importer
- The optional docking clause (Clause 7) does not apply
- The optional clause for advance notice of Subprocessor changes (Clause 9(a), Option 2) applies with a 30-day notice period
- Mediation (Clause 18) and governing law/jurisdiction provisions are as specified in Exhibit A

For transfers from the UK, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies. For transfers from Switzerland, the Standard Contractual Clauses apply with references to “GDPR” interpreted as references to the revFADP and the competent supervisory authority being the Swiss Federal Data Protection and Information Commissioner.

8.5 Intra-Group Transfers. Transfers of Covered Personal Information between Taktile LLC, Taktile GmbH and Taktile Limited for internal administrative purposes (e.g., consolidated reporting, group-wide security monitoring) are governed by intra-group data transfer agreements that incorporate the same protections as this DPA.


9. AUDIT AND COMPLIANCE

9.1 Audit Rights. Customer has the right to audit or appoint an independent third-party auditor to audit Taktile’s compliance with this DPA, provided such audits:

(a) do not unreasonably interfere with Taktile’s business operations;

(b) are conducted during normal business hours with at least thirty (30) days’ prior written notice;

(c) are limited to once per twelve (12) month period, unless (i) required by applicable law, (ii) requested by Customer’s regulatory authority, or (iii) following a Security Incident affecting Customer’s Covered Personal Information; and

(d) are subject to reasonable confidentiality obligations.

Customer may satisfy its audit rights by reviewing Taktile’s SOC 2 Type II and ISO 27001 reports available through the Trust Center, which Taktile will update and make available at least annually.

9.2 Compliance Documentation. Upon reasonable request, Taktile will make available information necessary to demonstrate compliance with this DPA and applicable Privacy Laws. Taktile maintains SOC 2 Type II attestation and ISO 27001:2022 certification, which are available through Taktile’s Trust Center at https://app.vanta.com/taktile.com/trust/5fofvswspy35fupntb4i6. Customer may review these certifications and compliance reports in lieu of conducting on-site audits, unless required by applicable law or following a Security Incident.

9.3 Data Protection Officer. For data subject access and deletion requests, contact privacy@taktile.com. For security incidents and breach notifications, contact security@taktile.com.  


10. REGULATORY INQUIRIES

10.1 Regulatory Cooperation. If Taktile receives any regulatory inquiry, investigation, or request from a supervisory authority regarding Covered Personal Information, Taktile will, to the extent not prohibited by law:

- Promptly notify Customer of the inquiry within forty-eight (48) hours
- Provide Customer with copies of relevant documents and correspondence
- Not disclose Customer’s confidential information without prior written consent
- Take necessary measures to respond appropriately and timely
- Cooperate with Customer’s legal counsel in formulating responses

10.2 Customer Regulatory Obligations. Customer acknowledges that it remains responsible for compliance with all applicable Privacy Laws and regulatory requirements. Taktile’s cooperation under this Section does not transfer any regulatory obligations from Customer to Taktile.


11. TERM AND DATA RETURN

11.1 Term. This DPA remains in effect for the duration of the Agreement and terminates automatically upon termination of the Agreement, except for provisions that expressly survive termination.

11.2 Data Return and Deletion. Upon termination of the Agreement, Taktile will, at Customer’s choice, return or delete all Covered Personal Information, including copies, unless applicable law requires continued storage. Customer must make this election in writing within thirty (30) days of termination. If no election is made, Taktile will delete all Covered Personal Information within ninety (90) days of termination.

11.3 Certification of Deletion. Upon Customer’s written request, Taktile will provide written certification that all Covered Personal Information has been returned or deleted in accordance with this Section, except where retention is required by applicable law. Such certification will identify any data retained and the legal basis for retention.

11.4 Subprocessor Data Handling. Taktile will ensure that all Subprocessors return or delete Covered Personal Information in accordance with the same requirements applicable to Taktile under this Section.

11.5 Post-Termination Assistance. For a period of thirty (30) days following termination, Taktile will provide reasonable assistance to Customer in retrieving Covered Personal Information at no additional charge. Assistance beyond thirty (30) days or requiring significant custom development may be subject to Taktile’s then-current professional services rates.


12. LIABILITY AND INDEMNIFICATION

12.1 Incorporation of Agreement Terms. All liability, indemnification, limitation of liability, disclaimer, and related provisions in the Agreement apply in full to this DPA and any claims arising under or related to this DPA, including claims for breach of Privacy Laws.

12.2 Allocation of Responsibility.

(a) Taktile's Responsibility: Taktile is responsible for compliance with its obligations as a processor/service provider under this DPA, including implementing appropriate security measures and processing data only as instructed.

(b) Customer's Responsibility: Customer is solely responsible for:

- Ensuring it has a lawful basis to provide Covered Personal Information to Taktile
- Providing required notices and obtaining required consents from Data Subjects
- Ensuring Customer-configured decision logic complies with applicable fair lending, anti-discrimination, and consumer protection laws
- Customer’s own compliance with Privacy Laws as a controller/business
- Any regulatory fines or penalties imposed on Customer

(c) No Liability for Customer Actions: Taktile has no liability for violations arising from Customer’s instructions, Customer’s configurations, Customer’s failure to obtain required consents, or Customer’s failure to comply with its obligations under this DPA or Privacy Laws.

12.3 Regulatory Fines. Each party is responsible for regulatory fines and penalties imposed directly on that party by a supervisory authority. The Agreement's liability limitations apply to all other claims, including claims for damages, third-party claims, and consequential damages.

12.4 Joint Liability (LGPD). Where applicable law provides for joint liability between controller and processor (e.g., LGPD Article 42), each party is liable only for damages it directly causes through its own acts or omissions. This Section does not expand liability beyond what is provided in the Agreement.


13. JURISDICTION-SPECIFIC REQUIREMENTS

13.1 General Applicability. The provisions of Sections 1-12 of this DPA establish a comprehensive global framework for data protection that applies to all Customers regardless of jurisdiction. This Section 13 provides additional jurisdiction-specific requirements, clarifications, and modifications. Where this Section conflicts with earlier provisions, this Section controls for the specified jurisdiction. Customers should review the subsection(s) applicable to their jurisdiction and may disregard non-applicable provisions.

13.2 EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND

13.2.1 Applicability. This Section applies to Customers contracting with Taktile GmbH or Taktile Limited who are established in the European Economic Area, United Kingdom, or Switzerland, or who process personal data of data subjects in these jurisdictions.

13.2.2 Applicable Laws. The following laws apply in addition to the general provisions of this DPA:

- EU/EEA: General Data Protection Regulation (GDPR) 2016/679
- Germany: GDPR and German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG)
- United Kingdom: UK GDPR and Data Protection Act 2018
- Switzerland: Revised Swiss Federal Act on Data Protection (revFADP), effective September 1, 2023

13.2.3 Terminology. Under these laws:

- Customer is the “controller” (Verantwortlicher / responsable du traitement)
- Taktile GmbH is the “processor” (Auftragsverarbeiter / sous-traitant)
- Processing is conducted as specified in Section 2 of this DPA

13.2.4 Supervisory Authorities. The competent supervisory authorities are:

- EU/EEA: Data protection authority of Customer’s establishment or Data Subject’s habitual residence under GDPR Article 56
- Germany: Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit - BfDI) or relevant state data protection authority
- United Kingdom: Information Commissioner’s Office (ICO)
- Switzerland: Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter / Préposé fédéral à la protection des données et à la transparence - FDPIC)

13.2.5 Cross-Border Data Transfers. International data transfers are governed by Section 8 of this DPA, with the following jurisdiction-specific mechanisms:

- EU/EEA to non-adequate countries: Standard Contractual Clauses per Section 8.4
- UK to non-adequate countries: UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses
- Switzerland to non-adequate countries: EU Standard Contractual Clauses modified for Swiss law (references to “GDPR” interpreted as revFADP; FDPIC as competent authority)

13.2.6 German-Specific Requirements. For processing activities conducted by Taktile GmbH in Germany:

(a) Employee Data Protection: Processing of employee data of German residents is subject to BDSG § 26, which requires:

- Legitimate interests assessment for employee data processing
- Enhanced employee rights and transparency
- Works council consultation where applicable (Customer’s responsibility to confirm compliance before providing employee data)

(b) Documentation: Additional documentation requirements under BDSG apply to records of processing activities maintained by Taktile GmbH.

(c) Language: Upon request, Taktile will provide German-language translations of this DPA and related documentation for German supervisory authorities or data subjects.

13.2.7 UK-Specific Requirements. For processing activities involving UK personal data:

(a) Post-Brexit Framework: Taktile acknowledges that UK data protection law has diverged from EU GDPR following Brexit and monitors UK regulatory developments.

(b) ICO Guidance: Taktile has regard to ICO statutory codes of practice and guidance where applicable to the Services, including guidance on AI and data protection.

(c) UK Transfer Mechanisms: Transfers from the UK are governed by UK-recognized mechanisms, including the UK IDTA, UK Addendum to SCCs, or UK-US Data Bridge (if and when operational).

13.2.8 Swiss-Specific Requirements. For processing activities involving Swiss personal data:

(a) Stricter Consent Standards: Where consent is the legal basis for processing, Taktile processes data only in accordance with valid consent meeting revFADP standards (explicit, informed, freely given, and specific).

(b) Profiling Disclosure: Where processing involves profiling or automated decision-making, Taktile assists Customer in complying with revFADP Article 21 requirements regarding disclosure of logic, significance, and consequences.

(c) High-Risk Breach Notification: For Security Incidents creating high risk to personality or fundamental rights of Swiss data subjects, Taktile provides information necessary for Customer to notify FDPIC as soon as possible.

(d) Language: Upon request, Taktile will provide French, German, or Italian translations of this DPA for Swiss supervisory authorities or data subjects.

13.2.9 UK Data (Use and Access) Act 2025. For UK Customers, the following provisions apply in addition to UK GDPR requirements: 

(a) Automated Decision-Making: Where Taktile’s Services involve automated decision-making with legal or similarly significant effects, Taktile will implement safeguards enabling Customer to:

- Provide individuals with information about significant decisions
- Enable individuals to make representations and challenge decisions
- Obtain human intervention in decision-making processes

(b) Complaint Handling: Taktile will establish procedures to handle data protection complaints directly from individuals as required by the Act, including providing an electronic complaint form and informing individuals of complaint outcomes

(c) Subject Access Requests: Taktile will conduct reasonable and proportionate searches when responding to DSARs, consistent with the Act’s clarifications

(d) Implementation Timeline: These provisions will be implemented in accordance with UK commencement regulations (2-12 months after Royal Assent on June 19, 2025)

13.3 UNITED STATES

13.3.1 Applicability. This Section applies to Customers contracting with Taktile LLC who are subject to US federal or state privacy laws.

13.3.2 Applicable Laws. The following state privacy laws apply in addition to the general provisions of this DPA:

- California Consumer Privacy Act (CCPA) as amended by California Privacy Rights Act (CPRA)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Utah Consumer Privacy Act (UCPA)
- Montana, Delaware, Iowa, Indiana, Nebraska, New Hampshire, New Jersey, and Minnesota, Texas, Oregon, Tennessee, Kentucky, and Rhode Island state privacy laws
- Other applicable state privacy laws, as defined in Section 1.4

13.3.3 Service Provider and Processor Status.

(a) Under California Law: Taktile LLC is a “service provider” as defined under CCPA/CPRA. Taktile certifies that it understands and will comply with the restrictions in California Civil Code § 1798.140(w)(2)(A) and § 1798.140(ag)(2)(A).

(b) Under Other State Laws: Taktile LLC is a “processor” under Virginia, Colorado, Connecticut, Utah, Montana, Delaware, Iowa, Indiana, Nebraska, New Hampshire, New Jersey, and Minnesota privacy laws.

(c) Processing Restrictions: As specified in Section 3.1, Taktile will not:

- Sell or share Covered Personal Information
- Retain, use, or disclose Covered Personal Information outside the direct business relationship with Customer
- Combine Covered Personal Information with personal information from other sources except as permitted by law

13.3.4 Supervisory Authorities and Enforcement. Enforcement authorities include:

- Federal Trade Commission (FTC)
- California Privacy Protection Agency (CPPA)
- State Attorneys General
- Other state-level enforcement agencies as applicable

13.3.5 Sensitive Personal Information. Where Customer provides Sensitive Personal Information as defined under CPRA and other state laws, Taktile:

(a) Processes such information only to perform the Services or as otherwise permitted without requiring consumer consent under applicable state laws

(b) Does not use or disclose Sensitive Personal Information for inferring characteristics about consumers beyond what is necessary to provide the Services

13.3.6 Consumer Rights Assistance. In addition to the data subject rights assistance provided under Section 6, Taktile will assist Customer with US-specific consumer rights, including:

(a) Authorized Agents: If Taktile receives a request from an authorized agent, Taktile will promptly notify Customer and will not respond without Customer’s authorization.

(b) Verification: Customer is responsible for verifying consumer identity; Taktile provides reasonable assistance including information about consumer interactions with the Services.

(c) Opt-Out Rights: Honoring opt-out requests for sale/sharing (though Taktile does not sell or share data).

(d) Right to Limit Use of Sensitive Personal Information: Restricting use of Sensitive Personal Information to permitted purposes under CPRA.

13.3.7 State Breach Notification Laws. In addition to Section 7 requirements, Taktile acknowledges that Customer may be subject to state-specific breach notification laws with varying timelines. Taktile will:

(a) Provide Customer with information necessary to comply with state breach notification laws, including nature and extent of breach, types of information involved, and number of affected consumers by state

(b) Cooperate with Customer’s notifications to state attorneys general, consumer reporting agencies, and affected consumers

(c) Not notify consumers, regulators, or third parties without Customer’s prior written consent, except as required by law

13.3.8 California-Specific Provisions.

(a) Audit Rights: Customer’s audit rights under Section 9.1 satisfy Customer’s right to take reasonable steps to ensure Taktile’s compliance with CCPA/CPRA obligations.

(b) Subprocessor Notice: The 30-day advance notice in Section 4.2 satisfies Taktile’s obligation to inform Customer of Subprocessors under CPRA.

(c) Consumer Request Metrics: Upon reasonable request, Taktile will provide information about consumer rights requests received directly by Taktile to assist Customer with CCPA/CPRA reporting obligations.

13.4 CANADA

13.4.1 Applicability. This Section applies to Customers contracting with Taktile LLC who are subject to Canadian federal or provincial privacy laws.

13.4.2 Applicable Laws. The following laws apply in addition to the general provisions of this DPA:

- Personal Information Protection and Electronic Documents Act (PIPEDA)
- Substantially similar provincial legislation (Alberta PIPA, British Columbia PIPA)
- Quebec’s Act respecting the protection of personal information in the private sector (as modernized by Law 25)
- Consumer-Driven Banking Act (CDBA) - effective early 2026

13.4.3 Roles and Accountability. Under PIPEDA:

- Customer is the “organization” responsible for personal information
- Taktile LLC is a third-party service provider processing personal information on behalf of Customer
- Customer remains accountable for personal information in Taktile’s possession or control under PIPEDA Principle 4.1.3
- Taktile provides comparable protection through this DPA and the measures in Exhibit B

13.4.4 Supervisory Authorities. The competent authorities are:

- Federal: Office of the Privacy Commissioner of Canada (OPC)
- Provincial: Provincial privacy commissioners (e.g., Commission d’accès à l’information du Québec for Quebec)

13.4.5 Consent and Withdrawal. Taktile acknowledges that PIPEDA requires meaningful consent for collection, use, and disclosure of personal information:

(a) Customer is responsible for obtaining appropriate consent from individuals

(b) Taktile processes personal information only for purposes for which Customer has obtained consent or as otherwise permitted by law

(c) Taktile assists Customer in responding to consent withdrawal requests as specified in Section 6

13.4.6 Cross-Border Transfers and Transparency.

(a) Customer acknowledges that personal information will be transferred to and processed in the United States where it may be accessible to US law enforcement and government agencies under US law, as specified in Section 8.1(a).

(b) Upon request, Taktile will provide Customer with information about US processing to enable Customer to comply with PIPEDA’s transparency requirements regarding cross-border transfers.

13.4.7 Breach Notification to OPC. For Security Incidents involving Canadian personal information that pose a “real risk of significant harm” to individuals:

(a) Taktile will provide Customer with information necessary to report the breach to the Privacy Commissioner of Canada as soon as feasible, in accordance with the Breach of Security Safeguards Regulations

(b) Information provided will include circumstances of the breach, date/time period, personal information involved, number of affected individuals, steps taken to reduce risk of harm, and notification to affected individuals

(c) Taktile acknowledges that Customer must report to OPC as soon as feasible after determining a breach poses real risk of significant harm

13.4.8 Quebec-Specific Requirements. For Customers subject to Quebec’s modernized privacy law (Law 25):

(a) Taktile acknowledges Quebec’s stricter requirements regarding consent, data minimization, and privacy by design

(b) Taktile will assist Customer in complying with Quebec’s privacy impact assessment requirements

(c) Taktile will cooperate with the Commission d’accès à l’information du Québec (CAI)

(d) Upon request, Taktile will provide French-language versions of this DPA and related documentation

13.4.9 Retention and Disposal. Taktile retains Canadian personal information only as long as necessary to fulfill collection purposes or as required by law, in accordance with PIPEDA Principle 4.5 and Section 6.4 of this DPA.

3.4.10 Consumer-Driven Banking Framework. For Customers subject to Canada’s Consumer-Driven Banking Act (effective early 2026):

(a) Taktile acknowledges that the CDBA regulates third-party access to consumers’ financial data through APIs

(b) Where Customer uses Taktile Services to facilitate consumer-driven banking, Taktile will:

- Implement appropriate technical standards as designated by the Minister of Finance
- Maintain confidentiality, integrity, and availability of financial data accessed through APIs
- Support Customer’s compliance with FCAC oversight requirements
- Cooperate with any CDBA-related regulatory examinations

(c) Taktile will update this Section as additional CDBA regulations are published prior to the framework’s launch in early 2026

13.4.11 OSFI Guideline B-10 Compliance. For Customers subject to OSFI’s Third-Party Risk Management Guideline B-10 (effective May 1, 2024): 

(a) Taktile acknowledges Customer’s obligations under B-10 to manage third-party risks

(b) Taktile will:

- Maintain appropriate measures to protect confidentiality, integrity, and availability of Customer records and data
- Provide Customer with timely access to accurate and comprehensive information for oversight of Taktile’s performance and risks
- Permit Customer to conduct or commission independent audits as specified in Section 9.1
- Cooperate with Customer’s Third-Party Risk Management Programme requirements

13.4.12 AI Services Data Processing. Where Customer enables AI Agents functionality, Covered Personal Information processed through some AI model providers (as identified in the applicable Order Form) will be processed in the United States. It’s possible that no alternative processing location is currently available for some AI model provider processing. Customer’s activation of AI Agents functionality constitutes Customer’s informed consent to such US-based processing as applicable to selected AI model providers. Customer is responsible for providing appropriate notice to individuals and ensuring compliance with PIPEDA and applicable provincial privacy legislation regarding cross-border transfers. Customer may elect not to enable AI Agents functionality, in which case no Covered Personal Information will be routed to AI model providers.

13.5 BRAZIL

13.5.1 Applicability. This Section applies to Customers contracting with Taktile LLC who process personal data of Brazilian data subjects.

13.5.2 Applicable Law. The Brazilian General Data Protection Law (Lei Geral de Proteção de Dados - LGPD, Law No. 13,709/2018) and regulations issued by the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados - ANPD) apply in addition to the general provisions of this DPA.

13.5.3 Roles Under LGPD. For purposes of LGPD:

- Customer is the “controlador” (controller) of Covered Personal Information
- Taktile LLC is the “operador” (processor) of Covered Personal Information
- Taktile processes personal data only according to Customer’s instructions and for purposes set forth in this DPA

13.5.4 Supervisory Authority. The competent supervisory authority is the Autoridade Nacional de Proteção de Dados (ANPD). Taktile will cooperate with ANPD inquiries and investigations as required by law.

13.5.5 International Data Transfers. Transfers of personal data from Brazil to the United States are conducted in accordance with LGPD Chapter V (Articles 33-36) as specified in Section 8.3(c). Taktile implements appropriate contractual, technical, and organizational safeguards to ensure adequate protection of personal data transferred internationally.

13.5.6 Data Subject Rights Under LGPD. In addition to Section 6, Taktile will assist Customer in fulfilling LGPD-specific data subject rights under Articles 17-22, including:

- Confirmation of processing and access to data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of data
- Portability of data to another service provider
- Information about public and private entities with which data has been shared
- Information about the possibility of denying consent and consequences
- Revocation of consent

13.5.7 Joint Liability. The parties acknowledge that under LGPD Article 42, both controller and processor may be held jointly liable for damages caused by processing activities. Each party is responsible for damages it causes through violation of LGPD. Taktile’s liability is limited as set forth in Section 12 of this DPA and the Agreement.

13.5.8 Breach Notification. For Security Incidents involving Brazilian personal data, Taktile will provide information necessary for Customer to notify ANPD and affected data subjects in accordance with LGPD requirements and within the timelines specified in Section 7.

13.5.9 AI Services Data Processing. Where Customer enables AI Agents functionality, Covered Personal Information processed through AI model providers (as identified in the applicable Order Form) will be transferred to and processed in the United States. Such transfers are conducted in accordance with LGPD Chapter V and the safeguards specified in Section 8.3(c). Customer’s activation of AI Agents functionality constitutes Customer's documented instruction authorizing such transfer. Customer may elect not to enable AI Agents functionality, in which case no Covered Personal Information will be routed to AI model providers.

13.6 FINANCIAL SERVICES COMPLIANCE (ALL JURISDICTIONS)

13.6.1 Applicability. This Section applies to all Customers whose use of the Taktile Services is subject to financial services regulations, regardless of jurisdiction.

13.6.2 Regulatory Considerations. Taktile acknowledges that Customer may be subject to financial services regulations including but not limited to:

(a) United States: Fair Credit Reporting Act (FCRA), Gramm-Leach-Bliley Act (GLBA), Sarbanes-Oxley Act (SOX), Bank Secrecy Act (BSA), Anti-Money Laundering (AML) regulations, Payment Card Industry Data Security Standard (PCI DSS)

(b) European Union: Digital Operational Resilience Act (DORA), Payment Services Directive 2 (PSD2), Markets in Financial Instruments Directive (MiFID II)

(c) United Kingdom: Financial Services and Markets Act, FCA regulations

(d) Other Jurisdictions: Equivalent financial services regulations applicable to Customer’s operations

Taktile will cooperate with Customer’s compliance efforts under such regulations and maintain appropriate controls to support Customer’s regulatory obligations.

13.6.3 Automated Decision-Making. Where Covered Personal Information is used in automated decision-making systems, including credit under writing, fraud detection, or risk assessment, Taktile will:

(a) Maintain appropriate documentation and audit trails to support regulatory requirements

(b) Support Customer’s explainability and transparency obligations under applicable laws

(c) Provide Customer with access to decision logic and processing parameters

(d) Support Customer in conducting fairness and bias assessments

(e) Maintain version control for all decision models and algorithms

13.6.4 Model Governance. Taktile provides tools and capabilities enabling Customer to implement model governance for Customer-configured decision logic, including:

(a) Version control and change management for Customer-configured models

(b) Documentation capabilities for model inputs, logic, and outputs configured by Customer

(c) Audit trails for processing activities

(d) Customer acknowledges and agrees that Customer is solely responsible for:

- Ensuring fairness and absence of bias in decision models Customer configures
- Conducting required bias testing and fairness assessments
- Validating that Customer’s decision logic complies with applicable fair lending, anti-discrimination, and consumer protection laws
- Implementing appropriate human oversight and review processes
- Documenting Customer’s model governance and validation procedures

13.6.5 Regulatory Examinations. Taktile will cooperate with regulatory examinations of Customer by financial services regulators, including:

(a) Providing documentation regarding processing activities and security measures

(b) Granting access to systems and controls (subject to reasonable security measures and confidentiality protections)

(c) Responding to information requests within timeframes required by regulators

13.6.6 Record Retention for Financial Services. Notwithstanding the retention periods in Section 6.4, where Customer is subject to financial services regulations requiring longer retention periods (e.g., 7 years under certain regulations), Taktile will retain Covered Personal Information for such longer periods upon Customer’s written instruction and subject to applicable Privacy Laws.

13.6.7 Audit Rights for Regulated Entities. For Customers subject to financial services regulations requiring periodic vendor audits, Taktile will accommodate such regulatory-required audits with reasonable advance notice and coordination. Such audits remain subject to the general limitations in Section 9.1(a), (b), and (d) regarding interference with operations, business hours, and confidentiality.


13.7 ASIA-PACIFIC REGIONS

13.7.1 Applicability. This Section applies to Customers contracting with Taktile GmbH who are established in Asia-Pacific jurisdictions or who process personal data of data subjects in these regions. As Taktile’s Asia-Pacific operations evolve, this Section will be updated to address jurisdiction-specific requirements.

13.7.2 General Framework. For Asia-Pacific Customers, the general provisions of Sections 1-12 apply. Taktile processes data in accordance with applicable local data protection laws and will implement jurisdiction-specific requirements as needed.

13.7.3 Data Localization. Where Asia-Pacific jurisdictions require data localization or impose restrictions on cross-border data transfers, Taktile will work with Customer to implement appropriate technical and contractual measures, which may include:

(a) Processing data within the jurisdiction where technically feasible

(b) Implementing appropriate transfer mechanisms recognized under local law

(c) Obtaining necessary approvals or registrations for cross-border transfers

13.7.4 Future Enhancements. As Taktile expands its Asia-Pacific customer base, this Section will be enhanced to address specific requirements under laws including but not limited to:

- Singapore Personal Data Protection Act (PDPA)
- Australia Privacy Act 1988
- Japan Act on the Protection of Personal Information (APPI)
- Other applicable Asia-Pacific data protection laws

Customers in these jurisdictions should contact Taktile for current compliance information and jurisdiction-specific addenda as applicable.


14. MISCELLANEOUS

14.1 Conflict. In case of conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Covered Personal Information. In case of conflict between this DPA and Standard Contractual Clauses, the Standard Contractual Clauses prevail to the extent required by applicable law.

14.2 Amendments. This DPA may only be amended by written agreement signed by both parties, except that Taktile may update this DPA to comply with applicable Privacy Laws by providing thirty (30) days’ prior notice to Customer. Material changes require Customer’s affirmative acceptance; non-material changes (e.g., updated subprocessor list, corrected typos, clarifications) may be implemented with notice only. A changelog of all DPA versions is maintained at www.taktile.com/dpa-changelog.

14.3 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder of this DPA remains in full force and effect, and the invalid provision will be replaced with a valid provision that most closely reflects the original intent of the parties.

14.4 Governing Law. This DPA is governed by the same law as specified in the Agreement. 

(a) For Customers contracting with Taktile LLC: Laws of the State of New York, United States, without regard to conflicts of law principles.

(b) For Customers contracting with Taktile GmbH: Laws of Germany, without regard to conflicts of law principles.

(c) For Customers contracting with Taktile Limited: Laws of England and Wales, without regard to conflicts of law principles.

For Standard Contractual Clauses (where applicable), the governing law and jurisdiction are as specified in Exhibit A.

14.5 Survival. The following sections survive termination of this DPA: Section 7 (Security Incidents), Section 11 (Data Return), Section 12 (Liability and Indemnification), and Section 15 (Miscellaneous).

14.6 Entire Agreement. This DPA, together with the Agreement and its incorporated documents, constitutes the entire agreement between the parties regarding the processing of Covered Personal Information and supersedes all prior agreements, understandings, and communications regarding such subject matter.

14.7 Notices. All notices under this DPA must be in writing and delivered in accordance with the notice provisions in the Agreement. Notices regarding Security Incidents or regulatory inquiries may be provided by email to Customer’s designated contact and will be deemed effective upon transmission.

14.8 No Third-Party Beneficiaries. This DPA is solely for the benefit of the parties and does not create any third-party beneficiary rights, except that Data Subjects may enforce certain provisions as third-party beneficiaries to the extent required by applicable Privacy Laws.


ANNEX A

PROCESSING DETAILS

1. CONTRACTING ENTITY AND DATA PROCESSING LOCATION

For Customers contracting with Taktile LLC:

- Regions: United States, Canada, South America

- Primary Processing  Location: Customer may select from the following AWS regions for data storage:
United States (AWS US regions) — default
Canada (AWS Canada regions) — available upon Customer request
Brazil (AWS South America regions) — available upon Customer request
The selected storage location is specified in the Order Form or Customer's written request.

- Cross-Border Access: Regardless of the data storage location selected by Customer, Covered Personal Information may be accessed by Taktile personnel located in the United States, European Union, and United Kingdom for the limited purposes specified in Section 8.2, including technical support, incident response, and service delivery.

- Role: Processor/Service Provider

- Governing Law: New York, United States

- Supervisory Authority: Determined by Customer’s jurisdiction (FTC, CPPA, state AGs, OPC, ANPD, etc.)

For Customers contracting with Taktile GmbH:

- Regions: European Union, Switzerland

- Primary Processing  Location: Germany (AWS Germany/EU regions)

- Cross-Border Access: Covered Personal Information may be accessed by Taktile personnel located in the European Union and United Kingdom for the limited purposes specified in Section 8.2, including technical support, incident response, and service delivery

- Role: Processor (Auftragsverarbeiter)

- Governing Law: Germany

- Supervisory Authority: Determined by Customer’s jurisdiction (BfDI, ICO, FDPIC, etc.)

For Customers contracting with Taktile Limited:

- Region: United Kingdom, Asia-Pacific

- Primary Processing Location:  United Kingdom (AWS UK regions), unless otherwise agreed in writing

- Cross-Border Access: Covered Personal Information may be accessed by Taktile personnel located in the United Kingdom and the European Union for the limited purposes specified in Section 8.2, including technical support, incident response, and service delivery.

- Role: Processor

- Governing Law: England and Wales

- Supervisory Authority: Information Commissioner’s Office (ICO)

- Cross-Border Access: Personnel in US, Germany, and Romania may access data for technical support, incident response, and service delivery as specified in Section 8.2.


2. PROCESSING SCOPE

Subject Matter: Provision of Taktile’s decision management platform for financial services decisioning.

Duration: Term of Agreement plus post-termination obligations.

Nature and Purpose:

- Credit underwriting and loan decisioning
- Fraud detection and prevention
- KYC/KYB verification and compliance screening
- Transaction monitoring
- Other customer decisioning use cases
- Technical support and service delivery
- Security monitoring and incident response
- Backup and disaster recovery
- Customer-specific performance and benchmarking (where enabled by the Customer pursuant to the Agreement)
- AI model provider processing (where Customer has elected to use AI Agents functionality and selected an Optional Subprocessor through the Platform or an applicable Order Form)

Categories of Data Subjects:

-
Customer’s end users (borrowers, applicants, account holders)
- Business representatives and beneficial owners
- Customer’s authorized users

Categories of Personal Information (including, but not limited to):

- Identity Data: Name, DOB, government IDs, addresses, contact information
- Financial Data: Credit scores, bank account information, income, assets, transaction history
- Demographic Data: Age, employment, location
- Technical Data: IP addresses, device identifiers, log data, session information


3. STANDARD CONTRACTUAL CLAUSES (where applicable)

Applicability: SCCs apply for transfers from EU/EEA/UK/Switzerland to US.
Module: Module Two (Controller to Processor) 
Data Exporter: Customer
Data Importer: Taktile LLC (for US transfers) or Taktile GmbH (for Germany/Romania transfers) 
Subprocessor Notice: 30-day advance notice (Clause 9(a) Option 2)
Governing Law/Jurisdiction: Customer’s jurisdiction as specified in Section 14.4
UK Transfers: UK IDTA or UK Addendum to SCCs
Swiss Transfers: SCCs modified for revFADP (FDPIC as competent authority)


4. CONTACT INFORMATION

Data Protection Inquiries:

Privacy/DSR Requests: privacy@taktile.com

Security Incidents: security@taktile.com

Trust Center: https://app.vanta.com/taktile.com/trust/5fofvswspy35fupntb4i6

Taktile LLC: 200 Vesey Street, Brookfield Place, New York, NY 10281, USA

Taktile GmbH: Schönhauser Allee 9, 10119 Berlin, Germany (HRB 216607 B, Amtsgericht Charlottenburg)

Taktile Limited: 30 Old Bailey, London, United Kingdom, EC4M 7AU, United Kingdom (Company No. 16992965)

ANNEX B

TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

Taktile maintains appropriate technical and organizational measures to protect Covered Personal Information as required by applicable Privacy Laws. Current security controls and certifications are detailed in the Trust Center at https://app.vanta.com/taktile.com/trust/5fofvswspy35fupntb4i6/controls.

1. ACCESS CONTROL

Physical Security:

- Cloud infrastructure hosted in certified data centers (SOC 2 Type II and ISO 27001:2022 compliant)
- Physical access controls and environmental protections maintained by infrastructure providers

Logical Access Control:

- Role-based access control with least privilege principle
- Multi-factor authentication for system access
- Regular access reviews and automated deprovisioning
- Strong authentication requirements

Network Security:

- Network segmentation and firewall protection
- Intrusion detection and prevention systems
- Secure remote access controls

2. DATA PROTECTION

Encryption:

- Data at rest encrypted using industry-standard encryption
- Data in transit encrypted using current secure protocols
- Secure key management procedures

Data Lifecycle:

- Data retention aligned with legal requirements and Customer instructions
- Secure deletion procedures
- Backup and recovery capabilities

3. SECURITY OPERATIONS

Vulnerability Management:

- Regular security assessments and penetration testing
- Patch management procedures
- Security scanning and remediation

Monitoring and Response:

- Security monitoring and logging
- Incident detection and response procedures
- Documented incident response plan

4. ORGANIZATIONAL MEASURES

Personnel:

- Background checks for personnel with data access
- Security and privacy training
- Confidentiality obligations

Governance:

- Information security policies and procedures
- Change management processes
- Vendor and subprocessor security requirements

Compliance:

- Annual SOC 2 Type II audits
- ISO 27001:2022 certification
- Regular compliance assessments

5. FINANCIAL SERVICES CONTROLS

For Customers subject to financial services regulations:

- Audit trails supporting regulatory requirements
- Data retention meeting applicable regulatory standards
- Model governance and documentation capabilities
- Support for Customer-conducted explainability, bias, and fairness assessments

6. DATA SUBJECT RIGHTS

Technical Support:

- Data discovery and retrieval capabilities
- Data export in machine-readable formats
- Secure deletion with verification
- Access logging and audit trails

Process Support:

- Documented procedures for handling data subject requests
- Designated personnel for request processing
- Customer portal for request management

7. DATA SUBJECT RIGHTS SUPPORT

Technical Capabilities:

- Data discovery and mapping tools
- Data subject request (DSR) processing capabilities with manual oversight
- Data export functionality in machine-readable formats
- Secure data deletion with verification
- Access logging for all personal data access
- Audit trails for DSR fulfillment

Organizational Measures:

- Documented DSR handling procedures
- Designated personnel for DSR processing
- Five (5) business day response time commitment for DSR notifications
- Customer portal for DSR submission and tracking
- Regular DSR process testing and improvement

8. FINANCIAL SERVICES SPECIFIC CONTROLS

Regulatory Compliance:

-
Audit trails meeting typical financial services regulatory requirements
- Data retention aligned with FCRA, GLBA, and SOX requirements
- Transaction monitoring and suspicious activity detection support

Model Security:

- Version control for Customer-configured decision models
- Model access controls and change management
- Model performance monitoring capabilities
- Model documentation and lineage tracking
- A/B testing capabilities with Customer-controlled parameters

ANNEX C

DATA PROCESSING IMPACT ASSESSMENT SUPPORT

IMPORTANT: Customer configures all decision logic, rules, and models within the Taktile platform. Taktile provides the technology infrastructure and tools, but does not determine, validate, or certify the fairness, accuracy, or compliance of Customer’s decision-making criteria. Customer is solely responsible for ensuring that Customer-configured decision logic complies with all applicable laws, including fair lending, anti-discrimination, and consumer protection requirements.

Taktile provides the following information to support Customer’s data protection impact assessments (DPIAs) as required by applicable Privacy Laws:

1. PROCESSING OVERVIEW

High-Risk Activities: Automated decision-making for credit, fraud detection, and risk assessment that may produce legal or similarly significant effects on individuals.

Scale: Platform capable of processing high volumes of decisions.

Data Types: Financial data, identity data, and other categories as specified in Exhibit A.

2. CUSTOMER RESPONSIBILITY FOR DECISION LOGIC

Customer configures all decision logic, rules, models, and thresholds within the Taktile platform. Taktile provides the technology infrastructure and tools but does not determine, validate, or certify the fairness, accuracy, or compliance of Customer’s decision-making criteria.

Customer is solely responsible for:

- Ensuring decision logic complies with applicable fair lending, anti-discrimination, and consumer protection laws
- Conducting required bias testing and fairness assessments
- Implementing appropriate human oversight and review processes
- Determining whether processing is necessary and proportionate for Customer’s purposes
- Providing appropriate notices and obtaining required consents from data subjects
- Consulting with supervisory authorities if required

3. TAKTILE’S SAFEGUARDS

Technical Measures:

- Encryption, access controls, and security monitoring (detailed in Exhibit B)
- Audit trails for all processing activities
- Data segregation between customers
- Tools enabling Customer to conduct bias testing and fairness assessments
- Version control for Customer-configured models

Organizational Measures:

- Contractual data protection obligations (this DPA)
- Personnel training on privacy and security
- Subprocessor oversight
- Incident response procedures
- SOC 2 Type II and ISO 27001:2022 certifications

4. DPIA SUPPORT

Upon request, Taktile will provide Customer with additional information reasonably necessary to complete Customer’s DPIA, including technical documentation about the Platform’s capabilities and security controls.

Discover Taktile