Data Processing Addendum

Effective: January 2026

This addendum ("Addendum") is incorporated into and forms a part of the Agreement. Any terms not defined in this Addendum shall have the meaning set forth in the Agreement. In the event of a conflict between the terms and conditions of this Addendum and the Agreement, the terms and conditions of this Addendum shall supersede and control with respect to the subject matter provided herein.

1. Processor and Subprocessor Relationships

1.1. Cooper AI as Processor

In situations where Customer is a Controller of the Customer Personal Data, Cooper AI will be deemed a Processor that is Processing Personal Data on behalf of Customer.

1.2. Cooper AI as Subprocessor

In situations where Customer is a Processor of the Customer Personal Data, Cooper AI will be deemed a Subprocessor of the Customer Personal Data.

1.3. Limited and Specified Purpose

Cooper AI shall collect, retain, use, disclose, and otherwise process Personal Information solely to perform and improve the Services for, and on behalf of, Customer for the limited and specified purposes described in the Agreement and this Addendum, and any documented instructions from Customer (collectively, the "Business Purpose").

2. Processing

2.1. Processing Details

The table on the attached Exhibit A describes the subject matter, nature, purpose, and duration of the Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.

2.2. Processing Instructions

Customer instructs Cooper AI to Process Customer Personal Data: (a) to provide, maintain and improve the Services; (b) as may be further specified through Customer's use of the Services; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Cooper AI about Processing Customer Personal Data under this Addendum. Cooper AI will abide by these instructions unless prohibited from doing so by Applicable Laws. Cooper AI will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.

2.3. Processing by Cooper AI

Cooper AI will only Process Customer Personal Data in accordance with this Addendum, including the details on Exhibit A, and in accordance with Applicable Law. Cooper AI will not: (a) Sell or Share Customer Personal Data, (b) store, retain, access, use, disclose, Transfer or otherwise Process Customer Personal Data outside of its direct business relationship with the Customer or for any other commercial or business purpose other than the Business Purpose, or (c) combine Customer Personal Data with personal data that Cooper AI receives from, or on behalf of, other persons, or collects from its own interaction with the data subject, except as expressly permitted under Applicable Data Protection Laws, and with respect to anonymized data as provided for in the Agreement. Cooper AI shall provide the same level of privacy protection with respect to Customer Personal Data as required of businesses under the Applicable Data Protection Laws. If Cooper AI updates the Services to update existing or include new products, features, or functionality, Cooper AI may change the Categories of Data Subjects, Categories of Personal Data, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect the updates by notifying Customer of the updates and changes.

2.4. Customer Processing

Where Customer is a Processor and Cooper AI is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer's Processing of Customer Personal Data. Customer's agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer's agreement with its Controller.

2.5. Subprocessors

Cooper AI will provide, transfer, or hand over any Customer Personal Data only to the list of Approved Subprocessors, which can be found at the subprocessors page. Customer may subscribe to receive notifications of changes to this list through an opt-in subscription option provided by Cooper AI. Customer may object to Cooper AI's use of a new Subprocessor (limited to reasonable privacy considerations) by notifying Cooper AI within 10 business days after receipt of notice from Cooper AI regarding a change to its list of Subprocessors or after Cooper AI publicly publishes such Subprocessor on its website. If the parties cannot resolve the objection, Cooper AI will use commercially reasonable efforts to provide the Services without the new Subprocessor, or Customer may terminate the affected Services and receive a prorated refund for prepaid, unused fees for the terminated portion.

When engaging a Subprocessor, Cooper AI will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of Agreement.

Cooper AI remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Cooper AI will notify Customer of any failure by its Subprocessors to fulfill a material obligation about Customer Personal Data under the agreement between Cooper AI and the Subprocessor.

3. Restricted Transfers

Cooper AI is currently only operational within the United States, and does not Process any Personal Data of individuals located within the European Union, United Kingdom or Switzerland. If this changes, this Addendum will be amended to incorporate the restrictions provided under other applicable data protection and privacy legal regimes.

4. Security Incident Response

Upon becoming aware of any Security Incident, Cooper AI will: (a) notify Customer without undue delay when feasible, (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and (c) take reasonable steps to contain and investigate the Security Incident. Cooper AI's notification of or response to a Security Incident as required by this Addendum will not be construed as an acknowledgment by Cooper AI of any fault or liability for the Security Incident.

5. Audit and Reports

5.1. Audit Rights

Upon request, Cooper AI will provide reasonable information to demonstrate compliance with this Addendum, including (where available) summaries of its then-current and available Report under confidentiality restrictions. Cooper AI will also respond to reasonable information security due diligence and audit questionnaires, provided such requests are made in writing and only made once a year. Cooper AI may restrict access to data or information if Customer's access to the information would negatively impact Cooper AI's intellectual property rights or other obligations under Applicable Laws.

5.2.

Any audit rights will be satisfied primarily through provision of reports and responses to reasonable questionnaires. On-site audits may be permitted only if required by Applicable Data Protection Laws and subject to reasonable advance notice, scope limitations, and confidentiality restrictions, and if made no more than once a year.

6. Coordination and Cooperation

6.1. Response to Inquiries

If Cooper AI receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Cooper AI will notify Customer about the request and Cooper AI will not respond to the request without Customer's prior consent. Examples of these kinds of inquiries and requests include a judicial or administrative or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Cooper AI will follow Customer's reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer's giving of Customer Personal Data to Cooper AI, Cooper AI will assist Customer in fulfilling the request according to the Applicable Data Protection Law. Cooper AI will cooperate with and provide reasonable assistance to Customer, at Customer's expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Cooper AI's Processing of Customer Personal Data under this Addendum.

6.2. Security Assessments and ADMTs

If required by Applicable Data Protection Laws, Cooper AI will reasonably assist Customer in completing Customer's cybersecurity audit, risk assessment, and ADMT requirements.

7. Deletion of Customer Personal Data

Upon the termination or expiration of this Addendum, which shall be coterminous with the Subscription Term under the Agreement, Cooper AI will return or delete Customer Personal Data at Customer's instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Laws, Cooper AI will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control. For example, Applicable Laws may require Cooper AI to continue hosting or Processing Customer Personal Data.

8. Limitation of Liability

8.1. Liability Caps and Damages Waiver

To the maximum extent permitted under Applicable Data Protection Laws, each party's total cumulative liability to the other party arising out of or related to this Addendum will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.

8.2. Related-Party Claims

Any claims made against Cooper AI or its Affiliates arising out of or related to this Addendum may only be brought by the Customer entity that is a party to the Agreement.

8.3. Exceptions

This Addendum does not limit any liability to an individual about the individual's data protection rights under Applicable Data Protection Laws.

9. Term

This Addendum will start when Cooper AI and Customer agree to an Exhibit A for the Addendum and shall be coterminous with the Agreement. However, Cooper AI and Customer will each remain subject to the obligations in this Addendum and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Cooper AI and Cooper AI stops Processing Customer Personal Data.

10. Definitions

"Agreement" means any subscription agreement governing Customer's access to and use of the Services, which may include the Cooper AI MSA (available at Master Services Agreement) and an Order Form executed by Cooper AI and the Customer.

"Applicable Laws" means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.

"Applicable Data Protection Laws" means the Applicable Laws that govern how the Services may process or use an individual's personal information, personal data, personally identifiable information, or other similar term.

"Controller" will have the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.

"Customer" means the entity and the entity's affiliates that agree to be bound by the Agreement and this Addendum.

"Customer Personal Data" means Personal Data that Customer uploads or provides to Cooper AI as part of the Services and that is governed by this Addendum.

"Personal Data" will have the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.

"Processing" or "Process" will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.

"Processor" will have the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.

"Report" means audit reports, summaries or documentation prepared by another company with respect to Cooper AI's information security system.

"Security Incident" means any actual or reasonably suspected unauthorized use, disclosure or acquisition of, or access to, any unencrypted Customer Personal Data, or encrypted Customer Personal Data with the means to unencrypt, including: (i) discovery of the presence of malware, viruses, logic bombs, trojan horses, etc. in its systems; (ii) the unauthorized disclosure of any Customer Personal Data; (iii) Customer Personal Data being in possession of an unauthorized third party; and (iv) any security incident relating to Customer Personal Data which would constitute a violation of Applicable Law.

"Sell" means exchanging, disclosing, making available, transferring or otherwise providing or communicating Personal Data to a third party for monetary or other valuable consideration, or as otherwise defined by Applicable Data Protection Laws.

"Services" means the product and/or services described in the Agreement.

"Share" means sharing, releasing, disclosing, making available, transferring or otherwise providing or communicating Personal Data to a third party for cross-context behavioral advertising, as defined in Applicable Data Protection Laws, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-contextual behavioral advertising for the benefit of a business in which no money is exchanged, or as otherwise defined by Applicable Data Protection Laws.

"Subprocessor" will have the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.

Exhibit A

Customer Role: Data Processor and Data Controller (for different processing activities)

Cooper AI Role: Data Processor

Subject Matter of Processing: Cooper AI will process Personal Data for the purpose of completing insurance-related tasks. Examples of such tasks include: (a) comparing insurance policies, (b) facilitating submission of requests for insurance quotes, (c) managing policy renewals, (d) comparing insurance quotes, (e) automated submission intake, (f) compliance verification, (g) claims recovery analysis, (h) managing claims intake and claims adjudication and processing.

Duration of Processing: Subscription Term as defined in the Agreement

Nature and Purpose of Processing: To facilitate the Customer's provision of services to its customers, as well as for internal business purposes such as operations, analytics, and reporting

Types of Personal Data: Personal information (name, date of birth, gender, nationality); Contact information (address, email, telephone number); Professional information (employer, job title); Financial information (bank account information, payout from policies, claims information); National or unique identification numbers; Sensitive personal data; Personal life information (dependents or family members); Technical data (IP address, log files); Location data (GPS, geolocation)

Categories of Data Subjects: Customer's customers (which may be consumers) and business contacts; Customer's employees and contingent workers

Cooper AI's Authorized Subprocessors: View current list