DataProcessing Agreement

ZORYA

DPA

DataProcessing Agreement

This Data ProcessingAgreement (the "DPA") forms an integral part of the Agreemententered into between Zorya and the Customer and is incorporated by referenceinto the Terms and Conditions of Use, in both its Self Service and Enterprisemodalities. This DPA governs solely the processing that Zorya carries out, onbehalf of the Customer, with respect to the personal data of the End Users. Itneither replaces nor limits Zorya's Privacy Notice, which governs the processingthat Zorya carries out in its capacity as controller with respect to thepersonal data of the Customer and its representatives.

1. Definitions

Capitalized terms not defined inthis DPA shall have the meaning ascribed to them in the Terms, in the ServiceOrder or in the MSA, as applicable. Forpurposes of this DPA:

•       "End-UserData" means the personal data of the End Users that Zorya processes forand on behalf of the Customer in connection with the provision of the Service,including the Customer Content and the metadata associated with itstransmission and delivery. It forms part of the Customer Data and excludes theZorya Data.

•       "Third-PartyPlatform Data" means such End-User Data that, by virtue of itstransmission to a Third-Party Platform, becomes subject to the terms of thatplatform, including any information derived from it or combined with it, on theterms established by such conditions.

•       "ARCO Rights"means the rights of access, rectification, cancellation and opposition providedfor in the Law, as well as any equivalent rights recognized by the regulationsapplicable to the End Users.

•       "Processor","Controller", "Data Subject", "Processing","Transfer" and "Remission" shall have themeaning ascribed to them by the Law.

•       "SecurityIncident" means any breach of security resulting in the destruction,loss, alteration, disclosure of, or unauthorized access to, the End-User Dataprocessed by Zorya or by its Sub-processors.

•       "Law" meansthe Federal Law on the Protection of Personal Data Held by Private Parties (LeyFederal de Protección de Datos Personales en Posesión de los Particulares),published in the Official Gazette of the Federation on March 20, 2025, and theother provisions that may be applicable.

•       "Third-PartyPlatform" means any messaging platform, network or channel operated bya third party that is necessary and indispensable for the delivery of thecommunications requested by the Customer, including but not limited to MetaPlatforms, Inc. and its Affiliates (WhatsApp Business API), Google LLC and itsAffiliates (RCS Business Messaging) and the Carriers.

•       "Sub-processor"means any third party engaged by Zorya to process End-User Data in theperformance of the provision of the Service. Third-Party Platforms do notconstitute Sub-processors, in accordance with Section 8 of this DPA.

2. Purpose and Roles of the Parties

2.1 Purpose

The purpose of this DPA is togovern the conditions under which Zorya processes the End-User Data on behalfof the Customer, as well as the obligations corresponding to each Partyregarding purposes, instructions, security, confidentiality, sub-processing,international transfers, assistance to the Controller, handling of ARCO Rights,notification of Security Incidents, and return or deletion of data.

2.2 Roles

With respect to the End-User Data,the Customer acts as Controller and Zorya as Processor. Zorya does notdetermine the purposes or the essential means of the Processing, nor does ituse the End-User Data for its own purposes.

2.3 Scope Delimitation

The personal data of the Customer,of its legal representatives and of the users of its account on the Panel donot constitute End-User Data. With respect to such data, Zorya acts asController and its processing is governed by Zorya's Privacy Notice and not bythis DPA.

3. Documented Instructions

3.1 Scope of the instructions

Zorya shall process the End-UserData solely in accordance with the Customer's documented instructions and forthe provision of the Service. The following constitute the Customer's completeand sufficient documented instructions: (i) the Terms; (ii) this DPA and itsAnnexes; (iii) the Service Order or the MSA, as applicable; (iv) theDocumentation; and (v) the configurations, parameters, templates, recipientlists and send requests that the Customer executes through the Panel or theAPIs.

3.2 Additional instructions

Any additional instruction thatexceeds the scope of the Service must be in writing and accepted by Zorya.Zorya may condition its performance on the execution of an annex and on thepayment of the reasonable costs involved.

3.3 Instructions contrary to the Law

If Zorya considers, in itsreasonable judgment, that an instruction of the Customer infringes the Law orthe applicable regulations, it shall notify the Customer without undue delayand may suspend the execution of such instruction until it is confirmed,modified or withdrawn, without this constituting a breach by Zorya.

3.4 Processing required by law

Zorya may process the End-User Dataoutside the scope of the Customer's instructions where applicable legislationso requires. In such case, it shall inform the Customer of such requirementprior to the processing, unless the legislation itself prohibits it.

4. Obligations of the Customer as Controller

The Customer represents, warrantsand undertakes to:

•       Have, with respect toall of the End-User Data, a valid lawful basis in accordance with the Law andwith the regulations applicable in the jurisdiction of the End Users, includingconsent where required, and to retain the corresponding evidence.

•       Make available to itsEnd Users the applicable privacy notice, informing them of the processing, thetransfers and the means to exercise their ARCO Rights.

•       Handle, in its capacityas Controller, the requests for the exercise of ARCO Rights and any authorityrequest related to the End-User Data.

•       Ensure the accuracy,relevance and currency of the End-User Data it provides to Zorya, as well asthe lawfulness of the Customer Content.

•       Comply with the policiesof the Third-Party Platforms applicable to it, including the Meta and Googlepolicies, and with the Acceptable Use Policy set forth in the Terms.

4.1 Prohibition of sensitive personal data

The Customer undertakes not totransmit, through the Service, sensitive personal data in the Customer Contentor in any field, template, attachment or parameter thereof. The Service is notdesigned or configured for the processing of sensitive personal data, and theThird-Party Platforms represent, in the applicable transfer instruments, thatno categories of confidential personal data are transferred.

Exceptionally, the Customer mayrequest in writing that Zorya enable a data flow involving sensitive personaldata. Such request must be accepted in writing by Zorya, shall specify thecategories involved, the applicable enhanced security measures and the enabledchannels, and shall be documented through the update of Annex A. In the absenceof such written acceptance, it shall be understood that the Customer does nottransmit sensitive personal data.

The Customer shall be solely liablefor any claim, penalty, fine or damage arising from the breach of this Section,under the indemnification provisions set forth in the Terms.

5. Obligations of Zorya as Processor

Zorya undertakes to:

•       Process the End-UserData solely in accordance with the Customer's documented instructions and forthe provision of the Service, and not for its own purposes, except in the caseof Zorya Data on the terms provided for in the Terms and in Section 8.4 of thisDPA.

•       Refrain fromtransferring the End-User Data, except upon the Customer's instruction, asrequired by applicable legislation, or in accordance with Sections 7 and 8 ofthis DPA.

•       Implement and maintainthe security measures set forth in Annex B.

•       Ensure that the personsauthorized to process the End-User Data are subject to confidentialityobligations, in accordance with Section 6.

•       Assist the Customer inhandling the ARCO Rights, in accordance with Section 10.

•       Notify the Customer ofSecurity Incidents, in accordance with Section 9.

•       Return or delete theEnd-User Data upon termination of the Agreement, in accordance with Section 12.

•       Make available to theCustomer the information reasonably necessary to demonstrate compliance withthe obligations under this DPA, in accordance with Section 11.

•       Maintain confidentialitywith respect to the End-User Data even after the conclusion of the legalrelationship with the Customer.

6. Confidentiality of Personnel

Zorya shall limit access to theEnd-User Data to the personnel who need to know it for the provision of theService, in accordance with the need-to-know principle. Such personnel arebound to confidentiality by a written instrument or by legal provision, anobligation that subsists after the termination of their relationship withZorya. Zorya shall establish controls or mechanisms intended to ensure that allpersons involved in any phase of the processing maintain confidentiality withrespect to the End-User Data.

7. Sub-processors

7.1 General authorization

The Customer grants Zorya a generalwritten authorization to engage Sub-processors for the provision of theService. The categories of current Sub-processors are set forth in Annex C. Theupdated list is available to the Customer upon request to legal@zorya.mx.

7.2 Additions and replacements

Zorya shall notify the Customer ofthe addition or replacement of any Sub-processor at least fifteen (15) calendardays in advance, through the Panel or the registered email address. TheCustomer may object to the addition or replacement within such period, onreasonable grounds founded on personal data protection, by written notice tolegal@zorya.mx. If the objection cannot be resolved, either Party may terminatethe Agreement with respect to the affected Service, without liability andwithout the right to a refund of the accrued Fees. The absence of an objectionwithin the period shall be deemed acceptance.

7.3 Equivalent obligations

Zorya shall enter into with eachSub-processor a binding legal instrument imposing personal data protectionobligations no less protective than those set forth in this DPA. Suchinstrument shall require the Sub-processor to notify Zorya of any SecurityIncident within twenty-four (24) hours of its discovery.

7.4 Liability

Zorya shall be liable to theCustomer for the acts and omissions of its Sub-processors as if they were itsown.

8. Third-Party Platforms

8.1 Acknowledgment and instruction

The Customer acknowledges that thedelivery of the communications it requests through the Service necessarily andindispensably requires the transmission of End-User Data to the Third-PartyPlatforms. The send request that the Customer executes through the Panel orthe APIs constitutes its express and unequivocal instruction for Zorya to carryout such transmission.

8.2 Nature

Third-Party Platforms do notconstitute Sub-processors of Zorya. Each Third-Party Platform autonomouslydetermines its own terms, policies and roles regarding personal dataprotection, and in certain cases acts in the capacity of controller. Zorya doesnot negotiate, modify or control such terms.

8.3 Subjection to the terms of the Third-Party Platforms

The Customer acknowledges andaccepts that the processing of the Third-Party Platform Data is subject to theterms of the relevant Third-Party Platform, which: (i) are incorporated byreference into the agreements entered into between Zorya and such platform;(ii) may be updated unilaterally by the platform without requiring the consentof Zorya or of the Customer; and (iii) prevail, in matters of personal data protection,over the provisions of this DPA that are contrary to them, solely with respectto the Third-Party Platform Data and to the extent strictly necessary.

8.4 Restrictions on Third-Party Platform Data

Consistent with the applicableterms, Zorya undertakes, with respect to the Third-Party Platform Data, to: (i)not process it for purposes other than those authorized by the relevantThird-Party Platform; and (ii) not re-identify it, de-anonymize it, decrypt it,reverse its hash algorithm, or apply reverse-engineering techniques to it.

Accordingly, the definition of"Zorya Data" set forth in the Terms does not comprise any informationderived from Third-Party Platform Data or combined with it where the termsof the relevant platform restrict its use.

8.5 Deletion or return on demand

The Customer acknowledges that theThird-Party Platform may require Zorya, at any time and at its election, todelete or return the Third-Party Platform Data, as well as to certify suchdeletion or return. Zorya shall comply with such requirements and shall notifythe Customer without undue delay, to the extent permitted. Compliance with suchrequirements shall not constitute a breach by Zorya vis-à-vis the Customer.

8.6 Suspension by the Third-Party Platform

The Customer acknowledges that theThird-Party Platform may limit, suspend or cancel access to the Third-PartyPlatform Data or to the relevant channel. The unavailability resulting fromsuch measure shall not be attributable to Zorya.

8.7 Disclosure restrictions

The Customer acknowledges that theterms of certain Third-Party Platforms restrict Zorya's ability to discloseinformation relating to the processing of the Third-Party Platform Data,including that relating to a Security Incident, without the prior approval ofsuch platform. Zorya shall provide the Customer with the information requiredof it under the Law and this DPA, and that such restrictions permit it todisclose.

9. International Transfers

9.1 Acknowledgment

The Customer acknowledges that theprovision of the Service involves the transfer of End-User Data to, or theaccess to it from, jurisdictions other than the United Mexican States,including the United States of America, Ireland and those in which the EndUsers, the Third-Party Platforms or the Sub-processors are located.

9.2 Adequate safeguards

Zorya shall adopt adequatesafeguards so that the End-User Data maintains a level of protection equivalentto that provided for in the Law, through the execution of binding legalinstruments with the recipients and, where applicable, through the adoption ofinternationally recognized standard contractual clauses, including the standardcontractual clauses of the Ibero-American Data Protection Network.

9.3 Applicable regime

The Parties acknowledge thattransfers necessary for the maintenance or performance of the legalrelationship between the Controller and the Data Subject, as well as thosenecessary by virtue of a contract entered into in the interest of the DataSubject, fall within the exceptions provided for in Article 36 of the Law. Theforegoing is without prejudice to the Customer's information obligations underSection 4.

10. Security Incidents

10.1 Notification to the Customer

Zorya shall notify the Customer ofany Security Incident without undue delay and, in any event, withinforty-eight (48) hours of its discovery, or within the shorter periodrequired by applicable regulations.

10.2 Content of thenotification

The notification shall describe, tothe extent of the information reasonably available: (i) the nature of theSecurity Incident; (ii) the categories and approximate volume of affectedEnd-User Data; (iii) the likely consequences; (iv) the measures adopted orproposed to address it and mitigate its effects; and (v) a point of contact forobtaining further information. Where it is not possible to provide all of theinformation at once, it shall be delivered on a phased basis without unduedelay.

10.3 Cooperation

Zorya shall reasonably cooperatewith the Customer and shall provide the assistance that the Customer reasonablyrequires to investigate the Security Incident and to comply with itsobligations as Controller, including those of notification to the Data Subjectsand, where applicable, to the competent authority. It is exclusively for theCustomer, as Controller, to determine whether notification is appropriate andto carry out such notifications.

10.4 No acknowledgment of liability

The notification of a SecurityIncident shall not constitute an acknowledgment of liability or fault on thepart of Zorya.

11. Assistance to the Controller and ARCO Rights

11.1 Channeling

Where Zorya receives directly froman End User a request for the exercise of ARCO Rights or any communicationrelating to the processing of its personal data, it shall refrain fromresponding to it on the merits and shall channel it to the Customer withoutundue delay and, in any event, within five (5) business days of its receipt,informing the requester that its request was channeled to the Controller.

11.2 Technical assistance

Taking into account the nature ofthe processing, Zorya shall reasonably assist the Customer through thefunctionalities available in the Panel and the APIs, so that the Customer canhandle the ARCO Rights requests. Where handling requires manual intervention byZorya, it shall be provided within ten (10) business days of the Customer'swritten request.

11.3 Additional assistance

Zorya shall reasonably assist theCustomer in the preparation of personal data protection impact assessments andin consultations with the competent authority, where this is required andrelates to the processing that is the subject of this DPA, making available tothe Customer the information reasonably within its possession.

11.4 Costs

The assistance provided for inSections 11.2 and 11.3 shall be provided at no cost where it can be handledthrough the standard functionalities of the Service. Where it requiresdevelopment, extraction or significant manual effort, Zorya may pass through tothe Customer the reasonable and documented costs, subject to a quotationaccepted in writing.

12. Demonstration of Compliance and Audit

12.1 Information and certifications

Upon the Customer's writtenrequest, no more than once per calendar year and with reasonable prior notice,Zorya shall make available to the Customer the information, policies,certifications or third-party assessment reports that demonstrate compliance withthe obligations set forth in this DPA.

12.2 On-site audit

In the case of Customers under theEnterprise modality, where the information referred to in Section 12.1 isinsufficient to demonstrate compliance with respect to a specific andreasonably founded finding, the Customer may conduct an on-site audit, uponthirty (30) calendar days' notice, on business days and hours, subject toconfidentiality obligations, without access to information of other Zoryacustomers and without interfering with its operation. The costs of the auditshall be borne by the Customer, unless it demonstrates a material breachattributable to Zorya.

12.3 Self Service modality

In the case of Customers under theSelf Service modality, the demonstration of compliance shall be carried outsolely in accordance with Section 12.1, without the right to an on-site audit.

12.4 Limitations

The rights provided for in thisSection shall be exercised without prejudice to Zorya's confidentialityobligations vis-à-vis third parties, including those arising from the terms ofthe Third-Party Platforms.

13. Return or Deletion of the Data

13.1 Customer's election

Within thirty (30) calendar daysfollowing the termination of the Agreement for any cause, the Customer mayrequest Zorya, by written notice to legal@zorya.mx, to return the End-User Datain a structured and commonly used format. Zorya may pass through the reasonableextraction costs where such extraction exceeds the standard functionalities ofthe Service.

13.2 Deletion

Upon expiry of the period referredto in Section 13.1 without the Customer having requested the return, or oncesuch return has been effected, Zorya shall delete the End-User Data and shallprocure that its Sub-processors do likewise. Upon the Customer's writtenrequest, Zorya shall issue a deletion certificate.

13.3 Retention

Notwithstanding the foregoing,Zorya may retain the End-User Data where applicable legislation so requires orwhere it is necessary for the determination of possible liabilities arisingfrom the processing, until the statutory or contractual limitation periodthereof. In such case, the data shall remain blocked, subject to the securitymeasures of Annex B and to the confidentiality obligations of this DPA, andshall not be subject to any active processing other than that strictlynecessary for compliance with such obligation.

13.4 Backup copies

Backup copies containing End-UserData shall be deleted in accordance with Zorya's ordinary backup rotationcycles, remaining in the meantime subject to the applicable security andconfidentiality measures.

13.5 Third-Party Platforms

The provisions of this Section arewithout prejudice to the provisions of Section 8.5.

14. Term, Survival and Final Provisions

14.1 Term

This DPA shall enter into force onthe Effective Date or on the date of execution of the Service Order or the MSA,as applicable, and shall remain in force for as long as Zorya processesEnd-User Data on behalf of the Customer.

14.2 Survival

Zorya's obligations with respect tothe End-User Data shall subsist after the termination of the Agreement, to theextent that Zorya retains or continues to process such data in accordance withSection 13.3.

14.3 Liability

The liability of the Partiesarising from this DPA shall be subject to the limitations, exclusions and capsset forth in the Terms, in the Service Order or in the MSA, as applicable,except for those cases that, under such instruments, are excluded from suchlimitations.

14.4 Amendments

Zorya may amend this DPA wherenecessary to reflect changes in applicable legislation, in the terms of theThird-Party Platforms or in the Service. Material amendments shall be notifiedto the Customer at least fifteen (15) calendar days in advance of their entryinto force, in accordance with the procedure provided for in the Terms.

14.5 Order of precedence

In the event of a conflict betweenthis DPA and the Terms, with respect to the processing of End-User Data thisDPA shall prevail, without prejudice to the order of precedence provided for inthe Enterprise Terms and to the provisions of Section 8.3.

14.6 Governing law and dispute resolution

This DPA shall be governed by andconstrued in accordance with the laws of the United Mexican States and shall besubject to the dispute resolution mechanism provided for in the Termsapplicable to the Customer.

14.7 Effectiveness

In the case of the Self Servicemodality, this DPA shall be deemed accepted by the Customer upon accepting theTerms and creating and verifying its account on the Panel. In the case of theEnterprise modality, this DPA shall be deemed accepted upon execution of theService Order or the MSA that incorporates it by reference, or by itshandwritten signature or electronic signature as an annex thereto.

Last Updated

 

July 2026.

 

 

AnnexA

Detailsof the Processing

Concept

Description

Subject  matter of the processing

Provision of the cloud messaging Service, consisting of the  transmission, routing and delivery of the communications that the Customer  directs to its End Users through the contracted channels.

Nature of the processing

Collection, recording, storage, organization, structuring, retention,  consultation, use, transmission, enabling of access, matching, blocking,  deletion and destruction, by automated means.

Purpose

Solely the provision of the Service in accordance with the Customer's  documented instructions. Zorya does not process the End-User Data for its own  purposes.

Duration

For as long as the Agreement is in force, plus the retention periods  provided for in Section 13.

Categories of Data Subjects

End Users, that is, the recipients of the communications that the  Customer sends through the Service.

Categories of personal data

• Contact data: mobile phone number, channel user identifier, and,  where applicable, name.

• Customer Content: the content of the messages and their attachments,  determined exclusively by the Customer.

• Transmission and delivery metadata: date and time of sending,  delivery status, delivery and read receipts, message identifier, channel and  Carrier used, error codes.

• Technical data: session identifiers, source IP address of the send  request, where technically necessary.

Sensitive personal data

None. The Customer undertakes not to transmit sensitive personal  data through the Service, in accordance with Section 4.1. Any exception  requires the written acceptance of Zorya and the update of this Annex.

Frequency

Continuous, for as long as the Agreement is in force.

Processing operations

Receipt of the send request; validation and normalization of the  recipient; routing to the relevant channel and Third-Party Platform;  delivery; recording of the delivery status; retention in accordance with the  configured retention; deletion.

Retention period

That configured by the Customer on the Panel and, failing that, the  one provided for in the Documentation. Delivery metadata is retained for the  period necessary for billing, support and demonstration of regulatory  compliance.

 AnnexB

SecurityMeasures

Zorya maintains an InformationSecurity Management System aligned with recognized standards, including ISO/IEC27001, and implements at least the following measures, which may be updatedprovided that they do not reduce the level of protection:

Category

Measures

Organizational

• Documented policies and procedures for information security and  personal data protection.

• Designation of persons responsible for security and personal data  protection.

• Confidentiality obligations enforceable against personnel and third  parties.

• Periodic training of personnel.

• Risk management and gap analysis; remediation work plan.

• Documented procedure for handling Security Incidents.

Technical

• Encryption of information in transit using current industry  protocols.

• Encryption of information at rest with respect to the repositories  that store End-User Data.

• Access control based on profiles and on the need-to-know principle.

• Enhanced authentication for administrative access.

• Logical segregation of each Customer's data.

• Audit logs of access and operations, with protection against  tampering.

• Periodic backups and tested recovery procedures.

• Vulnerability management and timely patching.

• Perimeter protection and monitoring of security events.

Physical

• Hosting in data centers of providers with physical access controls  and recognized certifications.

• Physical access controls to Zorya's facilities.

• Secure media destruction  procedures.

 Annex C

Sub-processorsand Third-Party Platforms

C.1  Third-Party Platforms

The following Third-Party Platformsare indispensable for the delivery of the communications and do not constituteSub-processors, in accordance with Section 8.2:

Platform

Location

Function

Meta Platforms, Inc., Meta Platforms Ireland Limited and its  Affiliates

United States of America, Ireland and other jurisdictions

Delivery, routing, operation, security and integrity of the  communications transmitted via WhatsApp Business API.

Google LLC and its Affiliates

United States of America and other jurisdictions

Delivery, routing, operation and security of the communications  transmitted via RCS Business Messaging.

Mobile network operators, concessionaires, carriers and integrators

Mexico and the destination jurisdictions of the communications

Routing and delivery of SMS messages and other communications;  handling of sender identification requirements.

C.2  Categories of Sub-processors

Category

Function

Technology infrastructure and cloud computing

Hosting, processing, storage and backup of the Service's information.

Technical support and help desk

Handling of the Customer's incidents and requests that may involve  access to End-User Data.

Analytics, monitoring and information security

Monitoring of availability and performance, detection of security  events and abuse prevention.

Billing and payment  processing

Issuance of invoices and processing of charges arising from the  Service.

The nominative and updated list ofSub-processors is available to the Customer upon request to legal@zorya.mx, inaccordance with Section 7.1.

2026 Zorya  by Everlay Group