0
Data Processing Addendum
Human Solutions+ · Exhibit to the Terms of Service · Effective date: July 18, 2026

1. Introduction and Relationship to the Terms

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Human Solutions+ Terms of Service (the "Terms") between Human Solutions Plus LLC ("Human Solutions+," "we," "us") and the customer that agrees to the Terms ("Customer," "you"). It applies to our processing of Personal Data that you or your Authorized Users submit to the Human Solutions+ platform and services (the "Service") in connection with your use of the Service. Capitalized terms not defined here have the meanings given in the Terms.

If there is a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA controls. This DPA does not need to be signed separately to be effective; it applies automatically when you agree to the Terms.

2. Definitions

•"Personal Data" means information relating to an identified or identifiable individual that you submit to the Service, such as your employees' personnel information.
•"Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
•"Controller" means the party that determines the purposes and means of Processing Personal Data. As between the parties, you are the Controller.
•"Processor" means the party that Processes Personal Data on behalf of the Controller. As between the parties, Human Solutions+ is the Processor.
•"Sub-processor" means a third party engaged by us to Process Personal Data in providing the Service.
•"Data Subject" means the individual to whom Personal Data relates, such as your employee.
•"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by us.

3. Roles of the Parties

The parties acknowledge that, with respect to the Processing of Personal Data under the Service: you are the Controller, Human Solutions+ is the Processor, and Human Solutions+ Processes Personal Data only on your behalf and on your documented instructions. Human Solutions+ is not the employer of, and makes no employment decisions regarding, your employees or other Data Subjects. You are responsible for the accuracy, quality, and legality of Personal Data and for having the necessary rights, consents, and legal basis to provide it to us for Processing.

4. Scope and Instructions for Processing

We will Process Personal Data only: (a) to provide, maintain, secure, and support the Service in accordance with the Terms; (b) as further instructed by you through your use and configuration of the Service; and (c) as required by applicable law (in which case we will, where legally permitted, inform you of the legal requirement before Processing).

The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A. You instruct us not to collect Social Security numbers, and the Service is not designed to store them.

5. Our Obligations as Processor

•Confidentiality. We ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
•Limited use. We will not sell Personal Data, and we will not use or disclose it except as necessary to provide the Service, as permitted by this DPA and the Terms, or as required by law.
•Instructions. We will Process Personal Data in accordance with your instructions as described in Section 4, and will inform you if we believe an instruction violates applicable law.
•Aggregated / de-identified data. We may create and use aggregated, anonymized, or de-identified information that does not identify any Customer, employee, or individual, as described in the Terms and Privacy Policy.

6. Security Measures

We will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data, taking into account the nature of the Service. These measures currently include:

•Authentication through our identity provider, with two-factor authentication available for administrators;
•Tenant isolation using row-level security to logically separate each Customer's data;
•Role-based access controls;
•Encryption of Personal Data in transit and at rest;
•Data minimization, including not storing Social Security numbers;
•Activity logging of certain actions for security and audit purposes; and
•Encrypted backups and disaster-recovery measures maintained through our infrastructure providers.

We periodically review and update these measures as the Service evolves.

7. Sub-processors

You authorize us to engage Sub-processors to Process Personal Data in providing the Service. Our current Sub-processors are listed in Annex B. We will impose data-protection obligations on our Sub-processors that are substantially similar to those in this DPA, and we remain responsible for our Sub-processors' performance of their obligations.

If we add or replace a Sub-processor, we will update Annex B (for example, on a page referenced in our Privacy Policy) and, where reasonable, provide a mechanism for notice. If you have a reasonable, data-protection-based objection to a new Sub-processor, you may notify us, and the parties will work in good faith to address it.

8. AI Features and AI Providers

The Service includes AI-assisted features (such as document drafting and the "Ask Toby" assistant). When you use these features, Personal Data you submit is disclosed to our AI provider (identified in Annex B) as a Sub-processor, and is Processed only to generate the output you request. Human Solutions+ does not use Customer Personal Data to train its own AI models, and our AI providers are configured not to use Customer inputs or outputs to train their foundation models, unless you separately and expressly agree otherwise. The AI provider is subject to the Sub-processor obligations described in this DPA.

9. Assistance with Data-Subject Requests

The Service provides features that allow you to access, correct, delete, and export Personal Data. Because you are the Controller, you are responsible for responding to requests from Data Subjects (such as your employees). Taking into account the nature of the Processing, we will provide reasonable assistance to help you respond to such requests to the extent you cannot address them through the Service. If we receive a request directly from a Data Subject regarding Personal Data we Process on your behalf, we will, where legally permitted, direct them to you.

10. Security Incident Notification

If we become aware of a Security Incident affecting Personal Data we Process on your behalf, we will notify you without undue delay after becoming aware, and will provide information reasonably available to us to help you meet your own notification obligations. We will take reasonable steps to mitigate and, where appropriate, remediate the Security Incident. Our notification is not an acknowledgment of fault or liability.

11. Return and Deletion of Personal Data

Upon termination or expiration of the Service, Customer Personal Data will remain available to the Customer for export for thirty (30) days. Human Solutions+ will then permanently delete or de-identify Customer Personal Data within sixty (60) days, except where retention is required by applicable law or where data exists in routine encrypted backups that are automatically overwritten within ninety (90) days.

12. Audit and Verification

Upon your reasonable written request, and no more than once per twelve (12) months (unless required by a Security Incident or by applicable law), we will make available information reasonably necessary to demonstrate our compliance with this DPA, such as summaries of our security measures or relevant third-party reports where available.

Where documentation is not sufficient to satisfy a good-faith compliance concern, you may request a limited audit, subject to the following: (a) reasonable advance written notice of at least thirty (30) days; (b) conducting the audit during normal business hours in a manner that does not disrupt our operations or compromise the security or confidentiality of other customers' data; (c) executing reasonable confidentiality obligations; and (d) bearing your own costs and reimbursing our reasonable costs for time and resources expended in supporting the audit.

13. International Data Transfers

The Service is operated in, and Personal Data is primarily stored in, the United States, and is currently offered to U.S.-based businesses. This DPA does not currently address transfers of Personal Data subject to the European Union General Data Protection Regulation (GDPR), the United Kingdom GDPR, or similar non-U.S. laws.

14. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to a party's liability means the aggregate liability of that party under the Terms and this DPA together.

15. Term, Conflict, and Miscellaneous

This DPA takes effect when you agree to the Terms and remains in effect for as long as we Process Personal Data on your behalf. In the event of a conflict between this DPA and the Terms concerning the Processing of Personal Data, this DPA controls. All other terms of the Terms remain in full force. This DPA is governed by the same governing law and venue provisions set out in the Terms.

16. Contact

Questions about this DPA or our data-processing practices may be sent to privacy@humansolutionsplus.com or Human Solutions Plus LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702.

Annex A — Details of Processing

Subject matter and duration

Provision of the Human Solutions+ Service to the Customer for the duration of the Customer's subscription and any wind-down period described in the Terms and Privacy Policy.

Nature and purpose of Processing

Hosting, storage, organization, display, transmission, and related Processing of workforce Personal Data to provide people-management, documentation, and related HR-support features, including AI-assisted document drafting and informational insights, at the Customer's direction.

Categories of Data Subjects

The Customer's owners, administrators, managers, employees, and other Authorized Users whose information the Customer submits to the Service.

Types of Personal Data

Names and contact details; emergency contacts; job title, department, and manager; employment status and dates; compensation and paid-time-off information; documents, acknowledgements, and forms; performance, coaching, and disciplinary records; time-off requests; workplace concerns (including anonymous submissions where enabled); and voluntary self-identification information where enabled. The Service is not designed to collect Social Security numbers.

Annex B — Authorized Sub-processors

The following Sub-processors are currently authorized to Process Personal Data in providing the Service:

•Supabase — database, authentication, and file storage (data hosting) — United States.
•Vercel — application hosting and content delivery — United States.
•Resend — transactional email delivery — United States.
•Square (Block, Inc.) — payment processing (card data; full card numbers not stored by us) — United States.
•Anthropic — AI processing that powers AI Features — United States.