Data Processing Agreement
Effective August 6, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement governing Customer’s use of the Services (the “Agreement”) between the customer identified in the Agreement (“Customer”) and Ballyhoo Group LLC d/b/a Within (“Processor” or “Within”) (each a “Party” and together, the “Parties”).
WHEREAS
(A) The Customer acts as a Data Controller with respect to Customer Personal Data.
(B) Customer wishes to engage Within to provide Services that may involve Processing Customer Personal Data on Customer’s behalf.
(C) The Parties wish to ensure that such Processing complies with applicable Data Protection Laws, including the GDPR and other privacy laws such as CCPA/CPRA and other US state privacy laws, where applicable.
(D) The Parties wish to set out their respective rights and obligations regarding such Processing.
IT IS AGREED AS FOLLOWS:
-
Definitions and Interpretation
-
Unless otherwise defined in this DPA, capitalized terms have the meanings given in the Agreement.
-
“Agreement” means the agreement governing Customer’s use of the Services, including applicable order forms, statements of work, and this DPA;
-
“Customer Personal Data” means Personal Data Processed by Processor on behalf of Customer in connection with the Services;
-
“Data Protection Laws” means all privacy, data protection, and data security laws applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and U.S. state comprehensive privacy laws;
-
“EEA” means the European Economic Area;
-
“EU Data Protection Laws” means the GDPR and laws implementing or supplementing the GDPR in the EEA;
-
“GDPR” means EU General Data Protection Regulation 2016/679;
-
“Restricted Transfer” means a transfer of Customer Personal Data that requires an approved transfer mechanism under applicable Data Protection Laws;
-
“Account Data” means business contact, account administration, billing, support, and service-usage information relating to Customer’s relationship with Within that is not Customer Personal Data;
-
“Aggregated Data” means data derived from Customer Personal Data or use of the Services that has been aggregated or deidentified so that it does not reasonably identify Customer or any Data Subject;
-
“Services” means the services provided by Processor to Customer under the Agreement;
-
“Subprocessor” means any third party appointed by or on behalf of Processor to Process Customer Personal Data in connection with the Services;
-
The terms “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processing,” “Processor,” and “Supervisory Authority” have the meanings given in the GDPR. Where applicable U.S. Data Protection Laws use analogous terms, such terms will be interpreted consistently with those laws.
-
-
Processing of Customer Personal Data
-
Processor shall:
-
comply with Data Protection Laws applicable to Processor in its role as a Processor; and
-
Process Customer Personal Data only on Customer’s documented instructions, including with respect to Restricted Transfers, unless Processing is required by applicable law. If legally permitted, Processor will inform Customer of that requirement before Processing.
-
-
Customer’s documented instructions include the Agreement, this DPA, Customer’s authorized use and configuration of the Services, and any additional written instructions consistent with the Agreement. Processor will promptly inform Customer if it reasonably believes an instruction violates applicable Data Protection Laws and may suspend the affected Processing until the Parties resolve the issue.
-
-
Applicability and Scope.
-
This DPA applies only to the extent Processor Processes Customer Personal Data on behalf of Customer and Data Protection Laws require the Parties to enter into processor terms.
-
Scope. The subject matter, duration, nature, and purpose of the Processing, and the types of Customer Personal Data and categories of Data Subjects, are described in the Agreement and Section 11.
-
Within as a Processor. For Customer Personal Data, Customer may act as a Controller or Processor and Within acts as a Processor or Subprocessor, as applicable. Within will Process Customer Personal Data in accordance with Customer’s documented instructions and the Agreement.
-
Within as an Independent Controller. Within acts as an independent Controller, and not a joint Controller with Customer, when Processing Account Data to manage the customer relationship, provide billing and support, operate and secure its business and Services, prevent fraud and misuse, comply with legal obligations, and as otherwise described in its applicable privacy notice.
-
Aggregated Data. Processor may create and use Aggregated Data to operate, analyze, secure, and improve the Services, provided Processor does not attempt to reidentify any person or Customer from Aggregated Data.
-
Customer Responsibilities. Customer is responsible for the lawfulness, accuracy, quality, and means by which it acquires Customer Personal Data; providing required notices and obtaining required rights, consents, and authorizations; and ensuring its instructions comply with Data Protection Laws. Unless the Parties expressly agree otherwise in writing, Customer will not submit special-category data under Article 9 of the GDPR, criminal-offense data, payment-card data, account passwords, government identification numbers, precise geolocation, consumer health data, or other highly sensitive Personal Data to the Services.
-
Processor Personnel. Processor will take reasonable steps to ensure that personnel authorized to Process Customer Personal Data are reliable, access it only as necessary to perform the Services, and are subject to confidentiality obligations.
-
-
Security.
-
Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and the risks to Data Subjects, Processor will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, including the measures described in Exhibit A.
-
Processor may update its technical and organizational measures from time to time, provided the overall level of security is not materially reduced. Customer is responsible for securely configuring and using the Services, safeguarding credentials under its control, and managing the security of systems and integrations outside Processor’s control.
-
-
Subprocessing
-
Customer provides general authorization for Processor to engage Subprocessors. Processor will require each Subprocessor to Process Customer Personal Data only as necessary to provide the Services, protect Customer Personal Data through contractual obligations that are materially consistent with the applicable obligations in this DPA, and implement appropriate security measures. Processor remains responsible for its Subprocessors’ performance of those obligations to the same extent Processor would be responsible for its own performance.
-
Processor will provide prior notice of a new Subprocessor that will Process Customer Personal Data. Customer may object during that period on reasonable, documented grounds relating to data protection. Processor will use commercially reasonable efforts to address the objection. If the Parties cannot resolve it, Processor may elect not to use the Subprocessor for Customer, or either Party may terminate the affected Services, in which case Processor will refund any prepaid fees for the terminated period.
-
Processor’s current Subprocessors and their Processing locations are listed at https://getwith.in/subprocessors or, if no online list is maintained, will be provided to Customer upon request.
-
Notice under this Section may be provided by email, in-product notice, or an update to the online list where Customer has a reasonable means to subscribe to updates.
-
Customer’s authorization includes Processing by Subprocessors in the locations identified on the applicable list, subject to the transfer safeguards in Section 12.
-
-
Data Subject Rights
-
Taking into account the nature of the Processing, Processor will provide commercially reasonable assistance, through appropriate technical and organizational measures where feasible, to help Customer respond to requests by Data Subjects under Data Protection Laws. Customer is responsible for verifying and responding to each request. Processor may charge reasonable fees for assistance that is materially beyond ordinary support, to the extent permitted by applicable law.
-
Processor shall:
-
promptly notify Customer if Processor receives a request from a Data Subject relating to Customer Personal Data and, where appropriate, direct the Data Subject to Customer; and
-
not respond to the request except on Customer’s documented instructions or as required by applicable law, in which case Processor will, where legally permitted, inform Customer before responding.
-
-
-
Personal Data Breach
-
Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to Processor that Customer needs to meet applicable notification obligations. Processor may provide information in phases as it becomes available.
-
Processor will reasonably cooperate with Customer in investigating, mitigating, and remediating the Personal Data Breach. Customer is responsible for determining whether and how to notify Data Subjects, regulators, or other third parties. Processor’s notice or assistance is not an admission of fault or liability.
-
-
Data Protection Impact Assessments and Prior Consultation. Taking into account the nature of the Processing and information available to Processor, Processor will provide reasonable assistance with data protection impact assessments and prior consultations that Customer is required to conduct under Data Protection Laws in relation to the Services. Customer is responsible for the assessment or consultation and will reimburse Processor’s reasonable costs for material assistance beyond ordinary support, to the extent permitted by law.
-
Deletion or Return of Customer Personal Data. At Customer’s choice, Processor will delete or return Customer Personal Data within ninety (90) days after expiration or termination of the affected Services, except to the extent applicable law requires retention. Customer Personal Data in backups may be retained until deleted in the ordinary course under Processor’s retention schedule, provided it remains protected and is not further Processed except as required by law. Customer is responsible for exporting Customer Personal Data it wishes to retain before termination.
-
Audit rights
-
No more than once in any twelve (12)-month period, and additionally following a confirmed Personal Data Breach or where required by a Supervisory Authority, Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Customer agrees that Processor may satisfy this obligation through security documentation, certifications, audit reports, and written responses.
-
Such audits will have measures to avoid disruption or access to other customers’ data or Processor’s sensitive security information. Audits will occur during normal business hours, no more than once annually unless required by law, and at Customer’s expense. Processor may charge its reasonable costs of supporting an audit.
-
-
Data Processing Schedule
| Subject matter of the Processing | Provision of Within’s agent-telemetry, analytics, account-health and revenue-signal, support, and related Services under the Agreement. |
|---|---|
| Duration of the Processing | The term of the Agreement and any limited post-termination period required for return, deletion, backup retention, or legal compliance. |
| Nature and purpose of the Processing | Collection, transmission, hosting, organization, analysis, matching, scoring, and generation of insights from agent/MCP telemetry and Customer-provided account, CRM, billing, product, and outcome data; operation, support, troubleshooting, and security of the Services; and other Processing on Customer’s documented instructions. |
| Types of Personal Data | Business contact and identity data; account and customer identifiers; CRM, billing, renewal, churn, upgrade, and other account-outcome data; agent/MCP session and product-usage telemetry (including tool calls, timestamps, arguments or results, success, error, and retry data); IP address, device, log, and connection data; and other Personal Data Customer elects to submit. Special-category or highly sensitive Personal Data is not intended or permitted unless expressly agreed in writing. |
| Categories of Data Subjects | Customer personnel, authorized users, and administrators; Customer’s customers, prospects, business partners, and vendors; and individuals whose Personal Data Customer or its authorized users include in integrations, telemetry, or tool inputs or outputs. |
-
Data Transfers. Processor and its Subprocessors may Process Customer Personal Data in the countries identified in the applicable Subprocessor list, subject to Data Protection Laws. For a Restricted Transfer, the Parties will rely on a valid transfer mechanism, such as an adequacy decision, an applicable certification framework, or approved standard contractual clauses. Where the European Commission Standard Contractual Clauses issued under Decision (EU) 2021/914 (“EU SCCs”) are required, the applicable controller-to-processor or processor-to-processor module is incorporated by reference; the Agreement and this DPA complete the relevant annexes; Clause 9(a), Option 2 applies using the notice period in Section 5; Clause 11 does not apply; and the governing law and courts are those of the EU Member State in which Customer is established or, if Customer is not established in an EU Member State, Ireland. For UK Restricted Transfers, the Parties incorporate the then-current ICO International Data Transfer Addendum to the EU SCCs by reference. For transfers subject to Swiss law, the EU SCCs will be interpreted with the modifications required by Swiss Data Protection Laws. The applicable transfer terms prevail over conflicting terms of the Agreement or this DPA.
-
U.S. State Privacy Laws
-
To the extent Customer Personal Data is Personal Information subject to applicable U.S. state comprehensive privacy laws and Customer is a Business or Controller, Customer discloses the Personal Information to Processor solely for the limited and specified business purposes described in the Agreement and Section 11, and Processor acts as a Service Provider, Contractor, or Processor, as applicable.
-
Processor will not sell or share such Personal Information; retain, use, or disclose it outside the direct business relationship with Customer or for a purpose other than the specified business purposes; or combine it with Personal Information received from another person or collected from Processor’s own interactions with a Consumer, except as permitted by applicable law. Processor will provide the same level of privacy protection required of a Service Provider, Contractor, or Processor and will require applicable Subprocessors to comply with corresponding restrictions.
-
Processor will reasonably assist Customer with verified consumer requests and other obligations required by applicable U.S. Data Protection Laws. Processor will notify Customer if it determines it can no longer comply with this Section. Subject to Section 10, Customer may take reasonable and appropriate steps to monitor compliance and, upon notice, to stop and remediate unauthorized use. Processor certifies that it understands and will comply with the restrictions in this Section.
-
-
General Terms
-
Confidentiality. The confidentiality obligations in the Agreement apply to this DPA and to information exchanged under it.
-
A Party may disclose such information to its personnel, professional advisers, and Subprocessors that need to know it and are bound by confidentiality obligations; and
-
a Party may disclose information to the extent required by law, provided it gives prior notice where legally permitted and discloses only what is required.
-
-
Government and Third-Party Requests. If Processor receives a legally binding request from a public authority or other third party for Customer Personal Data, Processor will, to the extent legally permitted, promptly notify Customer. Processor will review the request, disclose only the minimum information legally required, and, where reasonable, challenge requests it considers unlawful or materially overbroad.
-
Notices. Notices under this DPA must be in writing and may be sent to the notice or account-administrator contacts identified in the Agreement, including by email.
-
Order of Precedence. In the event of a conflict, the following order of precedence applies: (a) applicable standard contractual clauses or other mandatory transfer terms; (b) this DPA; and (c) the Agreement.
-
Liability. Any claims arising from this DPA are subject to the exclusions and limitations of liability in the Agreement, except to the extent prohibited by applicable law or the applicable standard contractual clauses.
-
Nothing in this DPA restricts the rights of any Data Subject or competent Supervisory Authority under applicable law.
-
If applicable Data Protection Laws impose conflicting requirements, each Party will comply with the laws applicable to it and the Parties will cooperate in good faith to identify a lawful approach.
-
For clarity, Processor receives Customer Personal Data only for the limited and specified purposes described in the Agreement and this DPA and does not receive Customer Personal Data as payment or other consideration.
-
IN WITNESS WHEREOF, this DPA is entered into with effect from the date first set out below.
CUSTOMER Signature: Name: Title: Date: | Ballyhoo Group LLCn Signature: Name: Title: Date: |
EXHIBIT A
TECHNICAL AND ORGANIZATIONAL MEASURES
The following measures describe Processor’s current security program. Processor may update them from time to time, provided the overall level of security is not materially diminished.
-
Encryption in Transit. Processor uses industry-standard encryption protocols to protect Customer Personal Data transmitted over public networks.
-
Hosting. Customer Personal Data is hosted on DigitalOcean Cloud Platform and/or other infrastructure Subprocessors identified under Section 5.
-
Encryption at Rest. Processor uses encryption at rest for production Customer Personal Data where supported by its hosting infrastructure.
-
Security Program. Processor maintains a documented information security program appropriate to its size, resources, the Services, and the risks presented by its Processing. Responsibility for information security is assigned to designated personnel, and relevant policies are reviewed periodically.
- Personnel Security. Personnel are informed of relevant security and confidentiality responsibilities, and violations may result in appropriate corrective or disciplinary action.
-
Risk Management. Processor maintains measures designed to identify, assess, and address material security risks to the Services and Customer Personal Data.
- Security Controls. Processor implements technical and organizational measures designed to protect against unauthorized or unlawful Processing and accidental loss, destruction, alteration, or disclosure of Customer Personal Data.
-
Access Control. Access to production systems and Customer Personal Data is authenticated and limited to authorized personnel with a business need.
- Least Privilege. Access rights are assigned based on job responsibilities and the principle of least privilege and are removed or adjusted when no longer required.
-
Vulnerability and Patch Management. Processor uses risk-based processes and available tooling to identify, prioritize, and remediate material vulnerabilities and to apply security updates within reasonable timeframes.
-
Network and System Security. Processor maintains reasonable network, application, and infrastructure safeguards designed to protect systems accessible from the Internet, including logging or monitoring appropriate to the Services.
-
Data Minimization. The Services are designed to limit collection to data needed for the Processing purposes or data Customer elects to provide. Access is limited to the minimum reasonably necessary to perform required functions.
-
Data Quality. Customer controls the Customer Personal Data submitted to the Services. Processor will provide available functionality and reasonable assistance to enable Customer to correct or update Customer Personal Data.
-
Vendor Management. Before engaging a Subprocessor with access to Customer Personal Data, Processor conducts a risk-based review of relevant privacy and security practices and imposes written data-protection obligations.
-
Incident Response. Processor maintains procedures to identify, respond to, mitigate, and learn from material security incidents.
-
Secure Disposal. Processor uses controls designed to securely delete or dispose of Customer Personal Data in accordance with applicable law and its retention practices, taking into account available technology.
-
Data Retention. Upon expiration or termination of the Agreement, Processor will delete or return Customer Personal Data as described in Section 9. Backup copies may be retained until deleted in the ordinary course, and legally required copies will be isolated and protected from further Processing except as required by law.