ZORYA
DPA
DataProcessing Agreement
This Data ProcessingAgreement (the "DPA") forms an integral part of the Agreemententered into between Zorya and the Customer and is incorporated by referenceinto the Terms and Conditions of Use, in both its Self Service and Enterprisemodalities. This DPA governs solely the processing that Zorya carries out, onbehalf of the Customer, with respect to the personal data of the End Users. Itneither replaces nor limits Zorya's Privacy Notice, which governs the processingthat Zorya carries out in its capacity as controller with respect to thepersonal data of the Customer and its representatives.
1. Definitions
Capitalized terms not defined inthis DPA shall have the meaning ascribed to them in the Terms, in the ServiceOrder or in the MSA, as applicable. Forpurposes of this DPA:
• "End-UserData" means the personal data of the End Users that Zorya processes forand on behalf of the Customer in connection with the provision of the Service,including the Customer Content and the metadata associated with itstransmission and delivery. It forms part of the Customer Data and excludes theZorya Data.
• "Third-PartyPlatform Data" means such End-User Data that, by virtue of itstransmission to a Third-Party Platform, becomes subject to the terms of thatplatform, including any information derived from it or combined with it, on theterms established by such conditions.
• "ARCO Rights"means the rights of access, rectification, cancellation and opposition providedfor in the Law, as well as any equivalent rights recognized by the regulationsapplicable to the End Users.
• "Processor","Controller", "Data Subject", "Processing","Transfer" and "Remission" shall have themeaning ascribed to them by the Law.
• "SecurityIncident" means any breach of security resulting in the destruction,loss, alteration, disclosure of, or unauthorized access to, the End-User Dataprocessed by Zorya or by its Sub-processors.
• "Law" meansthe Federal Law on the Protection of Personal Data Held by Private Parties (LeyFederal de Protección de Datos Personales en Posesión de los Particulares),published in the Official Gazette of the Federation on March 20, 2025, and theother provisions that may be applicable.
• "Third-PartyPlatform" means any messaging platform, network or channel operated bya third party that is necessary and indispensable for the delivery of thecommunications requested by the Customer, including but not limited to MetaPlatforms, Inc. and its Affiliates (WhatsApp Business API), Google LLC and itsAffiliates (RCS Business Messaging) and the Carriers.
• "Sub-processor"means any third party engaged by Zorya to process End-User Data in theperformance of the provision of the Service. Third-Party Platforms do notconstitute Sub-processors, in accordance with Section 8 of this DPA.
2. Purpose and Roles of the Parties
2.1 Purpose
The purpose of this DPA is togovern the conditions under which Zorya processes the End-User Data on behalfof the Customer, as well as the obligations corresponding to each Partyregarding purposes, instructions, security, confidentiality, sub-processing,international transfers, assistance to the Controller, handling of ARCO Rights,notification of Security Incidents, and return or deletion of data.
2.2 Roles
With respect to the End-User Data,the Customer acts as Controller and Zorya as Processor. Zorya does notdetermine the purposes or the essential means of the Processing, nor does ituse the End-User Data for its own purposes.
2.3 Scope Delimitation
The personal data of the Customer,of its legal representatives and of the users of its account on the Panel donot constitute End-User Data. With respect to such data, Zorya acts asController and its processing is governed by Zorya's Privacy Notice and not bythis DPA.
3. Documented Instructions
3.1 Scope of the instructions
Zorya shall process the End-UserData solely in accordance with the Customer's documented instructions and forthe provision of the Service. The following constitute the Customer's completeand sufficient documented instructions: (i) the Terms; (ii) this DPA and itsAnnexes; (iii) the Service Order or the MSA, as applicable; (iv) theDocumentation; and (v) the configurations, parameters, templates, recipientlists and send requests that the Customer executes through the Panel or theAPIs.
3.2 Additional instructions
Any additional instruction thatexceeds the scope of the Service must be in writing and accepted by Zorya.Zorya may condition its performance on the execution of an annex and on thepayment of the reasonable costs involved.
3.3 Instructions contrary to the Law
If Zorya considers, in itsreasonable judgment, that an instruction of the Customer infringes the Law orthe applicable regulations, it shall notify the Customer without undue delayand may suspend the execution of such instruction until it is confirmed,modified or withdrawn, without this constituting a breach by Zorya.
3.4 Processing required by law
Zorya may process the End-User Dataoutside the scope of the Customer's instructions where applicable legislationso requires. In such case, it shall inform the Customer of such requirementprior to the processing, unless the legislation itself prohibits it.
4. Obligations of the Customer as Controller
The Customer represents, warrantsand undertakes to:
• Have, with respect toall of the End-User Data, a valid lawful basis in accordance with the Law andwith the regulations applicable in the jurisdiction of the End Users, includingconsent where required, and to retain the corresponding evidence.
• Make available to itsEnd Users the applicable privacy notice, informing them of the processing, thetransfers and the means to exercise their ARCO Rights.
• Handle, in its capacityas Controller, the requests for the exercise of ARCO Rights and any authorityrequest related to the End-User Data.
• Ensure the accuracy,relevance and currency of the End-User Data it provides to Zorya, as well asthe lawfulness of the Customer Content.
• Comply with the policiesof the Third-Party Platforms applicable to it, including the Meta and Googlepolicies, and with the Acceptable Use Policy set forth in the Terms.
4.1 Prohibition of sensitive personal data
The Customer undertakes not totransmit, through the Service, sensitive personal data in the Customer Contentor in any field, template, attachment or parameter thereof. The Service is notdesigned or configured for the processing of sensitive personal data, and theThird-Party Platforms represent, in the applicable transfer instruments, thatno categories of confidential personal data are transferred.
Exceptionally, the Customer mayrequest in writing that Zorya enable a data flow involving sensitive personaldata. Such request must be accepted in writing by Zorya, shall specify thecategories involved, the applicable enhanced security measures and the enabledchannels, and shall be documented through the update of Annex A. In the absenceof such written acceptance, it shall be understood that the Customer does nottransmit sensitive personal data.
The Customer shall be solely liablefor any claim, penalty, fine or damage arising from the breach of this Section,under the indemnification provisions set forth in the Terms.
5. Obligations of Zorya as Processor
Zorya undertakes to:
• Process the End-UserData solely in accordance with the Customer's documented instructions and forthe provision of the Service, and not for its own purposes, except in the caseof Zorya Data on the terms provided for in the Terms and in Section 8.4 of thisDPA.
• Refrain fromtransferring the End-User Data, except upon the Customer's instruction, asrequired by applicable legislation, or in accordance with Sections 7 and 8 ofthis DPA.
• Implement and maintainthe security measures set forth in Annex B.
• Ensure that the personsauthorized to process the End-User Data are subject to confidentialityobligations, in accordance with Section 6.
• Assist the Customer inhandling the ARCO Rights, in accordance with Section 10.
• Notify the Customer ofSecurity Incidents, in accordance with Section 9.
• Return or delete theEnd-User Data upon termination of the Agreement, in accordance with Section 12.
• Make available to theCustomer the information reasonably necessary to demonstrate compliance withthe obligations under this DPA, in accordance with Section 11.
• Maintain confidentialitywith respect to the End-User Data even after the conclusion of the legalrelationship with the Customer.
6. Confidentiality of Personnel
Zorya shall limit access to theEnd-User Data to the personnel who need to know it for the provision of theService, in accordance with the need-to-know principle. Such personnel arebound to confidentiality by a written instrument or by legal provision, anobligation that subsists after the termination of their relationship withZorya. Zorya shall establish controls or mechanisms intended to ensure that allpersons involved in any phase of the processing maintain confidentiality withrespect to the End-User Data.
7. Sub-processors
7.1 General authorization
The Customer grants Zorya a generalwritten authorization to engage Sub-processors for the provision of theService. The categories of current Sub-processors are set forth in Annex C. Theupdated list is available to the Customer upon request to legal@zorya.mx.
7.2 Additions and replacements
Zorya shall notify the Customer ofthe addition or replacement of any Sub-processor at least fifteen (15) calendardays in advance, through the Panel or the registered email address. TheCustomer may object to the addition or replacement within such period, onreasonable grounds founded on personal data protection, by written notice tolegal@zorya.mx. If the objection cannot be resolved, either Party may terminatethe Agreement with respect to the affected Service, without liability andwithout the right to a refund of the accrued Fees. The absence of an objectionwithin the period shall be deemed acceptance.
7.3 Equivalent obligations
Zorya shall enter into with eachSub-processor a binding legal instrument imposing personal data protectionobligations no less protective than those set forth in this DPA. Suchinstrument shall require the Sub-processor to notify Zorya of any SecurityIncident within twenty-four (24) hours of its discovery.
7.4 Liability
Zorya shall be liable to theCustomer for the acts and omissions of its Sub-processors as if they were itsown.
8. Third-Party Platforms
8.1 Acknowledgment and instruction
The Customer acknowledges that thedelivery of the communications it requests through the Service necessarily andindispensably requires the transmission of End-User Data to the Third-PartyPlatforms. The send request that the Customer executes through the Panel orthe APIs constitutes its express and unequivocal instruction for Zorya to carryout such transmission.
8.2 Nature
Third-Party Platforms do notconstitute Sub-processors of Zorya. Each Third-Party Platform autonomouslydetermines its own terms, policies and roles regarding personal dataprotection, and in certain cases acts in the capacity of controller. Zorya doesnot negotiate, modify or control such terms.
8.3 Subjection to the terms of the Third-Party Platforms
The Customer acknowledges andaccepts that the processing of the Third-Party Platform Data is subject to theterms of the relevant Third-Party Platform, which: (i) are incorporated byreference into the agreements entered into between Zorya and such platform;(ii) may be updated unilaterally by the platform without requiring the consentof Zorya or of the Customer; and (iii) prevail, in matters of personal data protection,over the provisions of this DPA that are contrary to them, solely with respectto the Third-Party Platform Data and to the extent strictly necessary.
8.4 Restrictions on Third-Party Platform Data
Consistent with the applicableterms, Zorya undertakes, with respect to the Third-Party Platform Data, to: (i)not process it for purposes other than those authorized by the relevantThird-Party Platform; and (ii) not re-identify it, de-anonymize it, decrypt it,reverse its hash algorithm, or apply reverse-engineering techniques to it.
Accordingly, the definition of"Zorya Data" set forth in the Terms does not comprise any informationderived from Third-Party Platform Data or combined with it where the termsof the relevant platform restrict its use.
8.5 Deletion or return on demand
The Customer acknowledges that theThird-Party Platform may require Zorya, at any time and at its election, todelete or return the Third-Party Platform Data, as well as to certify suchdeletion or return. Zorya shall comply with such requirements and shall notifythe Customer without undue delay, to the extent permitted. Compliance with suchrequirements shall not constitute a breach by Zorya vis-à-vis the Customer.
8.6 Suspension by the Third-Party Platform
The Customer acknowledges that theThird-Party Platform may limit, suspend or cancel access to the Third-PartyPlatform Data or to the relevant channel. The unavailability resulting fromsuch measure shall not be attributable to Zorya.
8.7 Disclosure restrictions
The Customer acknowledges that theterms of certain Third-Party Platforms restrict Zorya's ability to discloseinformation relating to the processing of the Third-Party Platform Data,including that relating to a Security Incident, without the prior approval ofsuch platform. Zorya shall provide the Customer with the information requiredof it under the Law and this DPA, and that such restrictions permit it todisclose.
9. International Transfers
9.1 Acknowledgment
The Customer acknowledges that theprovision of the Service involves the transfer of End-User Data to, or theaccess to it from, jurisdictions other than the United Mexican States,including the United States of America, Ireland and those in which the EndUsers, the Third-Party Platforms or the Sub-processors are located.
9.2 Adequate safeguards
Zorya shall adopt adequatesafeguards so that the End-User Data maintains a level of protection equivalentto that provided for in the Law, through the execution of binding legalinstruments with the recipients and, where applicable, through the adoption ofinternationally recognized standard contractual clauses, including the standardcontractual clauses of the Ibero-American Data Protection Network.
9.3 Applicable regime
The Parties acknowledge thattransfers necessary for the maintenance or performance of the legalrelationship between the Controller and the Data Subject, as well as thosenecessary by virtue of a contract entered into in the interest of the DataSubject, fall within the exceptions provided for in Article 36 of the Law. Theforegoing is without prejudice to the Customer's information obligations underSection 4.
10. Security Incidents
10.1 Notification to the Customer
Zorya shall notify the Customer ofany Security Incident without undue delay and, in any event, withinforty-eight (48) hours of its discovery, or within the shorter periodrequired by applicable regulations.
10.2 Content of thenotification
The notification shall describe, tothe extent of the information reasonably available: (i) the nature of theSecurity Incident; (ii) the categories and approximate volume of affectedEnd-User Data; (iii) the likely consequences; (iv) the measures adopted orproposed to address it and mitigate its effects; and (v) a point of contact forobtaining further information. Where it is not possible to provide all of theinformation at once, it shall be delivered on a phased basis without unduedelay.
10.3 Cooperation
Zorya shall reasonably cooperatewith the Customer and shall provide the assistance that the Customer reasonablyrequires to investigate the Security Incident and to comply with itsobligations as Controller, including those of notification to the Data Subjectsand, where applicable, to the competent authority. It is exclusively for theCustomer, as Controller, to determine whether notification is appropriate andto carry out such notifications.
10.4 No acknowledgment of liability
The notification of a SecurityIncident shall not constitute an acknowledgment of liability or fault on thepart of Zorya.
11. Assistance to the Controller and ARCO Rights
11.1 Channeling
Where Zorya receives directly froman End User a request for the exercise of ARCO Rights or any communicationrelating to the processing of its personal data, it shall refrain fromresponding to it on the merits and shall channel it to the Customer withoutundue delay and, in any event, within five (5) business days of its receipt,informing the requester that its request was channeled to the Controller.
11.2 Technical assistance
Taking into account the nature ofthe processing, Zorya shall reasonably assist the Customer through thefunctionalities available in the Panel and the APIs, so that the Customer canhandle the ARCO Rights requests. Where handling requires manual intervention byZorya, it shall be provided within ten (10) business days of the Customer'swritten request.
11.3 Additional assistance
Zorya shall reasonably assist theCustomer in the preparation of personal data protection impact assessments andin consultations with the competent authority, where this is required andrelates to the processing that is the subject of this DPA, making available tothe Customer the information reasonably within its possession.
11.4 Costs
The assistance provided for inSections 11.2 and 11.3 shall be provided at no cost where it can be handledthrough the standard functionalities of the Service. Where it requiresdevelopment, extraction or significant manual effort, Zorya may pass through tothe Customer the reasonable and documented costs, subject to a quotationaccepted in writing.
12. Demonstration of Compliance and Audit
12.1 Information and certifications
Upon the Customer's writtenrequest, no more than once per calendar year and with reasonable prior notice,Zorya shall make available to the Customer the information, policies,certifications or third-party assessment reports that demonstrate compliance withthe obligations set forth in this DPA.
12.2 On-site audit
In the case of Customers under theEnterprise modality, where the information referred to in Section 12.1 isinsufficient to demonstrate compliance with respect to a specific andreasonably founded finding, the Customer may conduct an on-site audit, uponthirty (30) calendar days' notice, on business days and hours, subject toconfidentiality obligations, without access to information of other Zoryacustomers and without interfering with its operation. The costs of the auditshall be borne by the Customer, unless it demonstrates a material breachattributable to Zorya.
12.3 Self Service modality
In the case of Customers under theSelf Service modality, the demonstration of compliance shall be carried outsolely in accordance with Section 12.1, without the right to an on-site audit.
12.4 Limitations
The rights provided for in thisSection shall be exercised without prejudice to Zorya's confidentialityobligations vis-à-vis third parties, including those arising from the terms ofthe Third-Party Platforms.
13. Return or Deletion of the Data
13.1 Customer's election
Within thirty (30) calendar daysfollowing the termination of the Agreement for any cause, the Customer mayrequest Zorya, by written notice to legal@zorya.mx, to return the End-User Datain a structured and commonly used format. Zorya may pass through the reasonableextraction costs where such extraction exceeds the standard functionalities ofthe Service.
13.2 Deletion
Upon expiry of the period referredto in Section 13.1 without the Customer having requested the return, or oncesuch return has been effected, Zorya shall delete the End-User Data and shallprocure that its Sub-processors do likewise. Upon the Customer's writtenrequest, Zorya shall issue a deletion certificate.
13.3 Retention
Notwithstanding the foregoing,Zorya may retain the End-User Data where applicable legislation so requires orwhere it is necessary for the determination of possible liabilities arisingfrom the processing, until the statutory or contractual limitation periodthereof. In such case, the data shall remain blocked, subject to the securitymeasures of Annex B and to the confidentiality obligations of this DPA, andshall not be subject to any active processing other than that strictlynecessary for compliance with such obligation.
13.4 Backup copies
Backup copies containing End-UserData shall be deleted in accordance with Zorya's ordinary backup rotationcycles, remaining in the meantime subject to the applicable security andconfidentiality measures.
13.5 Third-Party Platforms
The provisions of this Section arewithout prejudice to the provisions of Section 8.5.
14. Term, Survival and Final Provisions
14.1 Term
This DPA shall enter into force onthe Effective Date or on the date of execution of the Service Order or the MSA,as applicable, and shall remain in force for as long as Zorya processesEnd-User Data on behalf of the Customer.
14.2 Survival
Zorya's obligations with respect tothe End-User Data shall subsist after the termination of the Agreement, to theextent that Zorya retains or continues to process such data in accordance withSection 13.3.
14.3 Liability
The liability of the Partiesarising from this DPA shall be subject to the limitations, exclusions and capsset forth in the Terms, in the Service Order or in the MSA, as applicable,except for those cases that, under such instruments, are excluded from suchlimitations.
14.4 Amendments
Zorya may amend this DPA wherenecessary to reflect changes in applicable legislation, in the terms of theThird-Party Platforms or in the Service. Material amendments shall be notifiedto the Customer at least fifteen (15) calendar days in advance of their entryinto force, in accordance with the procedure provided for in the Terms.
14.5 Order of precedence
In the event of a conflict betweenthis DPA and the Terms, with respect to the processing of End-User Data thisDPA shall prevail, without prejudice to the order of precedence provided for inthe Enterprise Terms and to the provisions of Section 8.3.
14.6 Governing law and dispute resolution
This DPA shall be governed by andconstrued in accordance with the laws of the United Mexican States and shall besubject to the dispute resolution mechanism provided for in the Termsapplicable to the Customer.
14.7 Effectiveness
In the case of the Self Servicemodality, this DPA shall be deemed accepted by the Customer upon accepting theTerms and creating and verifying its account on the Panel. In the case of theEnterprise modality, this DPA shall be deemed accepted upon execution of theService Order or the MSA that incorporates it by reference, or by itshandwritten signature or electronic signature as an annex thereto.
Last Updated
July 2026.
AnnexA
Detailsof the Processing
Concept
Description
Subject matter of the processing
Provision of the cloud messaging Service, consisting of the transmission, routing and delivery of the communications that the Customer directs to its End Users through the contracted channels.
Nature of the processing
Collection, recording, storage, organization, structuring, retention, consultation, use, transmission, enabling of access, matching, blocking, deletion and destruction, by automated means.
Purpose
Solely the provision of the Service in accordance with the Customer's documented instructions. Zorya does not process the End-User Data for its own purposes.
Duration
For as long as the Agreement is in force, plus the retention periods provided for in Section 13.
Categories of Data Subjects
End Users, that is, the recipients of the communications that the Customer sends through the Service.
Categories of personal data
• Contact data: mobile phone number, channel user identifier, and, where applicable, name.
• Customer Content: the content of the messages and their attachments, determined exclusively by the Customer.
• Transmission and delivery metadata: date and time of sending, delivery status, delivery and read receipts, message identifier, channel and Carrier used, error codes.
• Technical data: session identifiers, source IP address of the send request, where technically necessary.
Sensitive personal data
None. The Customer undertakes not to transmit sensitive personal data through the Service, in accordance with Section 4.1. Any exception requires the written acceptance of Zorya and the update of this Annex.
Frequency
Continuous, for as long as the Agreement is in force.
Processing operations
Receipt of the send request; validation and normalization of the recipient; routing to the relevant channel and Third-Party Platform; delivery; recording of the delivery status; retention in accordance with the configured retention; deletion.
Retention period
That configured by the Customer on the Panel and, failing that, the one provided for in the Documentation. Delivery metadata is retained for the period necessary for billing, support and demonstration of regulatory compliance.
AnnexB
SecurityMeasures
Zorya maintains an InformationSecurity Management System aligned with recognized standards, including ISO/IEC27001, and implements at least the following measures, which may be updatedprovided that they do not reduce the level of protection:
Category
Measures
Organizational
• Documented policies and procedures for information security and personal data protection.
• Designation of persons responsible for security and personal data protection.
• Confidentiality obligations enforceable against personnel and third parties.
• Periodic training of personnel.
• Risk management and gap analysis; remediation work plan.
• Documented procedure for handling Security Incidents.
Technical
• Encryption of information in transit using current industry protocols.
• Encryption of information at rest with respect to the repositories that store End-User Data.
• Access control based on profiles and on the need-to-know principle.
• Enhanced authentication for administrative access.
• Logical segregation of each Customer's data.
• Audit logs of access and operations, with protection against tampering.
• Periodic backups and tested recovery procedures.
• Vulnerability management and timely patching.
• Perimeter protection and monitoring of security events.
Physical
• Hosting in data centers of providers with physical access controls and recognized certifications.
• Physical access controls to Zorya's facilities.
• Secure media destruction procedures.
Annex C
Sub-processorsand Third-Party Platforms
C.1 Third-Party Platforms
The following Third-Party Platformsare indispensable for the delivery of the communications and do not constituteSub-processors, in accordance with Section 8.2:
Platform
Location
Function
Meta Platforms, Inc., Meta Platforms Ireland Limited and its Affiliates
United States of America, Ireland and other jurisdictions
Delivery, routing, operation, security and integrity of the communications transmitted via WhatsApp Business API.
Google LLC and its Affiliates
United States of America and other jurisdictions
Delivery, routing, operation and security of the communications transmitted via RCS Business Messaging.
Mobile network operators, concessionaires, carriers and integrators
Mexico and the destination jurisdictions of the communications
Routing and delivery of SMS messages and other communications; handling of sender identification requirements.
C.2 Categories of Sub-processors
Category
Function
Technology infrastructure and cloud computing
Hosting, processing, storage and backup of the Service's information.
Technical support and help desk
Handling of the Customer's incidents and requests that may involve access to End-User Data.
Analytics, monitoring and information security
Monitoring of availability and performance, detection of security events and abuse prevention.
Billing and payment processing
Issuance of invoices and processing of charges arising from the Service.
The nominative and updated list ofSub-processors is available to the Customer upon request to legal@zorya.mx, inaccordance with Section 7.1.
2026 Zorya by Everlay Group