Data Processing Addendum (DPA)

This addendum clarifies roles, responsibilities, and safeguards when servepilot.best processes customer and personal data in a B2B analytics context in Japan.

1. Scope and relationship of the parties

This DPA applies to use of our conversational-analytics services by customers (“Customer”) that provide data to us and/or instruct us to process data for analytics purposes. Depending on the Customer’s configuration and instructions, Customer may act as the party determining purposes and means of processing, and servepilot.best may process data on Customer’s behalf as a service provider.

If either party qualifies under Japan’s privacy framework as a relevant role for the processing activities described in the main agreement, the parties will comply with applicable obligations for that role.

2. Purpose limitation and lawful handling (APPI)

We process personal information only for the purposes described in the agreement and in any applicable data protection materials provided to Customer, including operational delivery of the service, analytics and reporting, security monitoring, and incident response.

To the extent personal information is involved, Customer is responsible for providing required disclosures to data subjects and obtaining consent (or relying on statutory exceptions) where required. We support Customer’s compliance through appropriate contractual and technical measures.

This addendum is issued to support transparency and appropriate handling under Act on the Protection of Personal Information (Act No. 57 of 2003).

3. Cookies, identifiers, and data collection controls

If our service uses cookies or other identifiers in a way that collects or processes personal information (or personal-related information that becomes personal data), the applicable disclosures and controls must be provided in accordance with APPI requirements. Where applicable, Customer must ensure that its end-user privacy notices and consent/controls are appropriately implemented for the relevant processing, and we will follow Customer’s instructions for such processing within the service.

Relevant obligations and transparency are supported under Act on the Protection of Personal Information (Act No. 57 of 2003).

4. Data processing within scope and instructions

We process data only on documented instructions from Customer (including configuration of analytics and reporting features) and only to the extent necessary to provide the contracted services. We do not use the data for our own independent marketing purposes unless expressly authorized in writing.

5. Sub-processors

We may engage sub-processors to provide parts of the service (e.g., infrastructure hosting, security tooling, and operations). Where sub-processors are used, we require them to protect data using appropriate contractual safeguards and to process data only for purposes consistent with Customer instructions and this DPA.

We will remain responsible for the sub-processor performance to the extent required by the parties’ agreement.

6. Security measures

We implement reasonable and appropriate technical and organizational measures designed to protect data against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, authentication, encryption in transit and/or at rest where applicable, logging and monitoring, and internal policies governing handling of data.

7. Data breach notification and incident cooperation

In the event of a personal data breach or other incident involving data covered by this DPA, we will notify Customer without undue delay after confirming the incident, and provide available information that supports Customer’s assessment and response.

The parties will cooperate in good faith to enable any required notifications and mitigation actions. Specific timelines and content may be further defined in the main agreement.

8. International transfers

Where data is transferred outside Japan for hosting or processing, the parties will apply appropriate safeguards consistent with the parties’ agreement and applicable Japanese privacy obligations. Customer should review relevant details in the service documentation or the main agreement.

9. Additional transparency/fairness framework (if applicable)

If we are designated as a “specified digital platform provider” under Japan’s transparency/fairness framework for certain digital platforms, additional disclosure and reporting duties may apply beyond standard APPI obligations. Where applicable, we will meet those additional duties in accordance with Act on Improving Transparency and Fairness of Specific Digital Platforms (Jun 12, 2026).

10. Consumer distance transaction disclosures (SCTA) — if applicable

If the service is offered as a distance transaction to consumers and/or otherwise falls within the scope of the Specified Commercial Transactions Act, mandatory seller/service-provider indications must be displayed so users can easily access them from the website top page or relevant pages. Where applicable, the required indications are provided in the “Contact and Business Information” section below.

This addendum references Act on Specified Commercial Transactions (Act No. 57 of 1970).

11. Governing terms

This DPA supplements the main agreement between Customer and servepilot.best. In case of conflict, the order of precedence in the main agreement will apply. Capitalized terms not defined here have the meaning given in the main agreement.