SERVERSCAN DATA PROCESSING ADDENDUM

Effective Date: August 13, 2026  |  Version 1.0

This Data Processing Addendum (“DPA”) forms part of the ServerScan Subscriber Agreement between you (“Customer”) and ServerScan, LLC. (“ServerScan”) and applies where ServerScan processes Customer Personal Data on Customer’s behalf in the course of providing the services. It is incorporated into the Subscriber Agreement by section 2.5 of that agreement. Capitalized terms not defined here have the meaning given in the Subscriber Agreement.

1. Definitions

1.1. “Data Protection Laws” means all laws applicable to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as incorporated into the law of the United Kingdom (“UK GDPR”) together with the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (“CCPA”).

1.2. “Customer Personal Data” means personal data contained in or derived from the Systems Customer submits for scanning, and personal data in Customer’s account and support communications, that ServerScan processes on Customer’s behalf.

1.3. “controller”, “processor”, “data subject”, “personal data”, “processing”, and “personal data breach” have the meanings given in the GDPR. “business”, “service provider”, “sell”, “share”, and “consumer” have the meanings given in the CCPA.

1.4. “Subprocessor” means any third party engaged by ServerScan to process Customer Personal Data.

1.5. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.

2. Roles and scope

2.1. As between the parties, Customer is the controller and ServerScan is the processor in respect of Customer Personal Data. Where the CCPA applies, Customer is the business and ServerScan is a service provider.

2.2. ServerScan is an independent controller in respect of the personal data it processes for its own purposes, including account administration, billing, fraud prevention, security of its own systems, and the improvement and marketing of the services as described in its privacy policy. This DPA does not apply to that processing.

2.3. Customer is responsible for the accuracy and lawfulness of Customer Personal Data, for having a lawful basis for the processing it instructs, for providing any notice and obtaining any consent required from data subjects, and for the accuracy and completeness of the scan scope it submits.

3. Processing instructions

3.1. ServerScan processes Customer Personal Data only on Customer’s documented instructions, including as set out in this DPA, the Subscriber Agreement, and Customer’s use and configuration of the services. Customer’s submission of a System for scanning is an instruction to process the personal data that scanning that System reveals.

3.2. ServerScan will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, unless prohibited from doing so by law.

3.3. Where ServerScan is required by law to process Customer Personal Data other than on Customer’s instructions, ServerScan will inform Customer of that requirement before processing, unless the law prohibits that notice on important grounds of public interest.

3.4. ServerScan does not sell or share Customer Personal Data, does not retain, use, or disclose it for any purpose other than performing the services specified in the Subscriber Agreement, and does not combine it with personal data received from another source except as permitted by the CCPA for a service provider. ServerScan certifies that it understands and will comply with these restrictions.

4. Confidentiality

4.1. ServerScan ensures that every person authorized to process Customer Personal Data is bound by an obligation of confidentiality, whether by contract or by statutory duty, that survives the end of their engagement.

4.2. ServerScan limits access to Customer Personal Data to personnel who need it to deliver, support, or secure the services.

5. Security

5.1. ServerScan implements and maintains the technical and organizational measures set out in Annex II, which are designed to ensure a level of security appropriate to the risk, taking into account the nature, scope, context, and purposes of the processing.

5.2. ServerScan may update those measures over time provided the level of security is not materially reduced.

5.3. Customer is responsible for its own use and configuration of the services, for the security of its own Systems and credentials, and for deciding whether the measures in Annex II are appropriate to the personal data it chooses to expose to scanning.

6. Subprocessors

6.1. Customer gives ServerScan general written authorization to engage Subprocessors. The Subprocessors ServerScan engages include the Approved Scanning Vendor that performs the scans, the infrastructure and hosting provider, the content delivery and security network, and the email delivery provider. A current list, naming each Subprocessor and its processing location, is available on request to custservice@serverscan.com.

6.2. ServerScan imposes on each Subprocessor, by written contract, data protection obligations that are substantially the same as those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor’s obligations.

6.3. ServerScan will give Customer at least 30 days notice, by email to the address on Customer’s account, before adding or replacing a Subprocessor. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected services by written notice and ServerScan will refund any prepaid fees covering the period after termination.

7. Data subject rights

7.1. Taking into account the nature of the processing, ServerScan will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests to exercise data subject rights under Data Protection Laws.

7.2. If ServerScan receives a request directly from a data subject relating to Customer Personal Data, ServerScan will not respond to it other than to acknowledge receipt and direct the data subject to Customer, and will notify Customer of the request without undue delay.

8. Personal data breach

8.1. ServerScan will notify Customer of a personal data breach affecting Customer Personal Data without undue delay after ServerScan confirms the breach, and in any event within 72 hours of confirmation where the processing is subject to the EU or UK General Data Protection Regulation, and within 21 days of confirmation in every other case.

8.2. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. Where ServerScan cannot provide all of that information at once, it will provide it in phases without further undue delay.

8.3. ServerScan will provide the information and cooperation Customer reasonably requires in order to meet Customer’s own notification obligations to supervisory authorities and data subjects.

8.4. Notification of a breach is not an acknowledgement of fault or liability by ServerScan.

9. Data protection impact assessments

9.1. Taking into account the nature of the processing and the information available to it, ServerScan will provide Customer with reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, at Customer’s cost where the assistance requires more than the provision of documentation ServerScan already maintains.

10. Return and deletion

10.1. On termination of the Subscriber Agreement, ServerScan will, at Customer’s election, delete or return Customer Personal Data, and delete existing copies, except to the extent that ServerScan is required to retain it by law or needs to retain it to establish, exercise, or defend a legal claim.

10.2. Customer may export scan reports at any time while the account is active and for 30 days after termination, as provided in section 2.7 of the Subscriber Agreement. Absent an election by Customer within that period, ServerScan will delete or de-identify Customer Personal Data in accordance with section 2.7.

10.3. Backup copies are deleted in the ordinary course of ServerScan’s backup cycle, and remain subject to this DPA until deleted.

11. Audit and information

11.1. ServerScan will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates.

11.2. Customer will exercise that right no more than once in any twelve month period, except where required by a supervisory authority or following a personal data breach affecting Customer Personal Data, on at least 30 days written notice, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt ServerScan’s operations or compromise the confidentiality or security of another customer’s data.

11.3. ServerScan may satisfy its obligations under this section by providing then-current third-party certifications, audit reports, or a completed security questionnaire, where these reasonably address Customer’s request.

11.4. Customer bears its own costs and ServerScan’s reasonable costs of any audit it conducts.

12. International transfers

12.1. ServerScan processes and stores Customer Personal Data in the United States. Customer instructs and authorizes that transfer.

12.2. Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision, the SCCs are incorporated into this DPA and apply to that transfer, with Module Two (controller to processor) applying, with Customer as data exporter and ServerScan as data importer. For the purposes of the SCCs: the optional docking clause in Clause 7 does not apply; option 2 in Clause 9(a) applies with the notice period in section 6.3 of this DPA; the optional redress language in Clause 11(a) does not apply; Clause 17 is governed by the law of Ireland; Clause 18(b) designates the courts of Ireland; and Annexes I and II to this DPA populate Annexes I and II to the SCCs. Annex III to the SCCs is not used, because it applies only where the specific prior authorisation option in Clause 9(a) Option 1 is chosen and the parties have chosen Option 2.

12.3. For transfers from the United Kingdom, the SCCs apply as modified by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, with the relevant tables completed by reference to this DPA. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.

12.4. If the SCCs or the transfer mechanism relied on are invalidated or superseded, the parties will work in good faith to put an alternative lawful mechanism in place.

13. Liability

13.1. Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in section 5 of the Subscriber Agreement, and any reference in that section to liability of a party means the aggregate liability of that party under the Subscriber Agreement and this DPA together.

13.2. Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws, including a data subject’s rights to compensation.

14. General

14.1. In the event of a conflict between this DPA and the Subscriber Agreement in respect of the processing this DPA governs, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.

14.2. This DPA takes effect on the Effective Date and continues for as long as ServerScan processes Customer Personal Data.

14.3. ServerScan may amend this DPA in accordance with section 7.2 of the Subscriber Agreement, and will not amend it in a way that reduces the protections it provides except where required to reflect a change in Data Protection Laws.

14.4. Questions about this DPA, and any request under it, should be sent to custservice@serverscan.com.

Annex I: Details of processing

Data exporter: Customer, as identified in its ServerScan account. Data importer: ServerScan, LLC., 959 Carnation Drive, Spring Hill, TN 37174, custservice@serverscan.com.

Subject matter: provision of vulnerability and PCI DSS scanning services to Customer.

Duration: the term of the Subscriber Agreement, plus the retention period described in section 2.7 of that agreement.

Nature and purpose: scanning Internet-facing Systems that Customer submits, generating and storing vulnerability findings and scan reports, making those reports available to Customer, transmitting scan scope and findings to the Approved Scanning Vendor that performs the scans, providing support, and issuing site seal status for Systems that pass.

Categories of data subjects: Customer’s personnel who hold or use a ServerScan account or contact support; and any individual whose personal data happens to be present in, or inferable from, the Systems Customer submits for scanning, which may include Customer’s own employees, customers, or website visitors.

Categories of personal data: account and contact data (name, business email address, telephone number, billing contact details); technical data about submitted Systems (IP addresses, domain names, hostnames, open ports, service banners, software and version information, certificate details, configuration details, and any personal data incidentally exposed by a scanned System or contained in a scan finding); support correspondence; and usage and log data including IP addresses and timestamps.

Special category data: none is requested or required. Customer should not submit Systems in a way that deliberately exposes special category data to scanning, and any such data reaching ServerScan does so incidentally and at Customer’s instruction.

Frequency: continuous for account and log data; on a scheduled and on-demand basis for scanning.

Competent supervisory authority for the SCCs: determined under Clause 13 by reference to Customer’s establishment or representative in the European Economic Area.

Annex II: Technical and organizational measures

Encryption: personal data and scan reports are encrypted in transit using current TLS, and encrypted at rest.

Access control: access to production systems and to scan reports is restricted to named personnel with a documented need, authenticated individually, with administrative access separated from ordinary access, and reviewed periodically. Customer accounts are protected by credentials that Customer controls.

Logging and monitoring: access to production systems and to scan reports is logged. Logs are monitored and retained for one year. Failed authentication and anomalous access are subject to automated blocking.

Network security: production systems sit behind a managed firewall and web application firewall. Administrative access is not exposed to the public internet and is reached through an authenticated tunnel. Intrusion attempts trigger automated banning.

Segregation: production and non-production environments are separated, and production personal data is not used in non-production environments.

Resilience and recovery: systems are backed up daily, backups are encrypted and retained for one week, and restoration is tested quarterly.

Vulnerability management: operating system and application security updates are applied on a regular schedule. ServerScan’s own infrastructure is scanned for vulnerabilities.

Personnel: personnel with access to personal data are bound by confidentiality obligations and receive security awareness guidance appropriate to their role.

Governance: ServerScan maintains a written information security program, reviews it periodically, and maintains an incident response process covering detection, containment, assessment, notification, and remediation.

Subprocessor assurance: Subprocessors are subject to written data protection terms substantially the same as those in this DPA.