Data Processing Agreement

Effective date: August 3, 2026.

Part A — Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Reflexion Interactive Technologies, Inc., 355 E Liberty Street, Suite 300, Lancaster, PA 17602, USA (“Reflexion”) and the customer identified on the applicable order, contract, or account (“Customer”) for the Reflexion services (the “Agreement”), and applies whenever Reflexion processes personal data on behalf of Customer in connection with the Agreement, to the extent required by applicable privacy laws.

In consideration of the mutual obligations set out herein, Reflexion and Customer (also individually a “Party” and collectively the “Parties”) hereby agree that the terms and conditions set out below shall be added as an Addendum to the Agreement.

1. Roles and scope

  1. For personal data that Customer submits or directs Reflexion to process as described in Annex I.B (“Customer member data”), Customer is the controller and hereby designates Reflexion as the processor.
  2. For data Reflexion processes for its own purposes described in the Reflexion Privacy Policy, such as securing the platform, billing, and product improvement on aggregated or de-identified data, Reflexion is an independent controller.
  3. For the avoidance of doubt, the account and contact data of the individuals who register and administer Customer’s account, which Reflexion collects directly from them and controls in its own right, is not Customer member data. Reflexion may process this data pursuant to the Privacy Policy (see Annex III).
  4. Personal data collected on the basis of an adult member’s own direct consent shall be processed by Reflexion as an independent controller under the Privacy Policy, not under this DPA. Any such consent shall be sought from the member directly, shall not be a condition of using the services, shall not draw on Customer’s roster data absent that consent, and shall not be sought from or applied to minors.

2. Processing instructions and description

  1. Where Reflexion is a processor, Customer authorizes Reflexion to process Customer member data solely for the purposes of the Agreement and in the context of the business relationship with Customer, and to transfer Customer member data to any country or territory as reasonably necessary for the provision of the services under the Agreement.
  2. Reflexion shall process Customer personal data only on Customer’s documented instructions, as set out in the Agreement, this DPA, and Customer’s configuration of the services, unless required to do otherwise by law (in which case Reflexion informs Customer unless legally prohibited). The subject matter, duration, nature, and purposes of processing, the data subjects, and the categories of data are described in Annex I.B.
  3. Special-category data. The Agreement may involve processing of personal data that constitutes special categories of personal data under applicable privacy laws. Customer represents and warrants that it has and will maintain a valid lawful basis under applicable privacy laws for the personal data that Customer provides to Reflexion or directs Reflexion to process.

3. Confidentiality and personnel

  1. Customer member data may be accessed by the Parties, authorized employees, and agents of each Party, and any sub-processor in connection with this DPA under a binding agreement that provides for substantially the same privacy and security obligations under applicable laws, subject to the other provisions of this DPA.
  2. Reflexion shall ensure that persons authorized to process Customer member data are bound by confidentiality obligations or an appropriate statutory obligation of confidentiality, and access data strictly on a need-to-know basis.

4. Security

  1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Reflexion shall implement and maintain reasonable technical and organizational measures. Such measures are described in Annex II. Reflexion shall not materially decrease the overall security of the services during a subscription term.
  2. Reflexion shall grant Customer the right to take reasonable and appropriate steps to (i) ensure that Reflexion uses Customer member data in a manner consistent with Customer’s obligations under Applicable Laws; and (ii) upon notice, stop and remediate unauthorized use of Customer member data.

5. Sub-processors

  1. Customer agrees that Reflexion may use the sub-processors listed in Annex III. Reflexion shall provide at least 30 days’ notice of intended additions or replacements, during which Customer may object on reasonable data protection grounds; if the objection cannot be resolved, the Parties shall work together in good faith to find an alternative solution or other reasonable resolution. Reflexion imposes data protection obligations on each sub-processor equivalent to those in this DPA and remains liable for its sub-processors’ performance.

6. International transfers

  1. Where processing involves a transfer of European Economic Area (“EEA”), UK, or Swiss personal data to a country without an adequacy decision, the parties incorporate the European Commission’s Standard Contractual Clauses (“EU SCCs”), Module 2 (controller → processor), Commission Implementing Decision (EU) 2021/914, as set out in Exhibit 1, with Customer as data exporter and Reflexion as data importer.
  2. For UK transfers, the UK International Data Transfer Addendum as amended or replaced from time to time (“UK Addendum”) applies. For Swiss transfers, the Clauses are adapted as required by the Swiss FADP, and Annex I.C designates the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) as the supervisory authority, alongside the competent EEA authority. References to the GDPR are read to include the FADP and Swiss data subjects may enforce their rights in Switzerland.
  3. Reflexion flows the same obligations down to its sub-processors.

7. Data Subject requests

  1. The Parties agree that the responsibility for responding to a request from any data subject whose personal data is controlled by Customer falls to Customer. Should such a data subject contact Reflexion directly regarding Customer-controlled data, Reflexion shall redirect them to Customer.
  2. Taking into account the nature of processing, Reflexion assists Customer with data subject requests made under Applicable Laws.
  3. Notwithstanding the above, Reflexion shall respond to any data subject requests to the extent required by Applicable Laws.

8. Data Breach notice

  1. The Parties agree that the responsibility for notifying the relevant supervisory or regulatory authority of any personal data breach involving personal data controlled by Customer falls to Customer.
  2. Reflexion shall notify Customer without undue delay, and in any event within 72 hours, upon becoming aware of a personal data breach affecting Customer member data, with the information reasonably required for Customer’s own notifications.
  3. The Parties shall provide one another with cooperation and assistance as reasonably requested by either Party in relation to (i) any complaint, communication, or request made in relation to the processing of the Customer member data and/or (ii) the handling of any personal data breach.

9. Audit

  1. Reflexion makes available information reasonably necessary to demonstrate compliance with this DPA and allows audits by Customer or its mandated auditor, no more than once per year on at least 30 days’ notice, under confidentiality, during business hours, and without disrupting operations. Reflexion may first satisfy an audit request with current third-party attestations and detailed written responses.

10. Deletion

  1. Upon termination of the Agreement, Reflexion deletes Customer personal data within 24 months of termination of the Agreement, or sooner upon reasonable written request, subject to a reasonable wind-down. Customer may export member data at any time during the term. Reflexion may retain data where retention is required by law and where data has been irreversibly anonymized.

11. Liability and order of precedence

  1. The liability terms of the Agreement shall apply to this DPA. If this DPA conflicts with the Agreement, this DPA shall control for data-protection matters; the Standard Contractual Clauses shall control over both where they apply.

12. Warranties

  1. Each Party warrants and undertakes to the other Party that:
    1. It has the right, power, and authority to enter into this DPA and to perform its obligations thereunder; and,
    2. It shall comply with all applicable laws with respect to the Customer member data.
  2. Reflexion further warrants that where acting as a processor:
    1. It shall not process, retain, use, or disclose Customer member data for any purpose other than for the specific business purpose of performing the services specified in the Agreement, this DPA or as otherwise permitted or required by applicable laws;
    2. It shall not retain, use, or disclose Customer member data outside the direct business relationship between the Parties, unless expressly permitted by applicable laws;
    3. It shall not “sell” or “share” any Customer member data as defined under applicable laws; and
    4. It shall notify Customer if it determines it can no longer meet its obligations under applicable laws.
  3. Customer further warrants that:
    1. Where Customer becomes aware of inaccuracies in Customer member data, Customer shall correct or promptly notify Reflexion in writing of such inaccuracies;
    2. Where Customer seeks to rely on notice or consent, or notice or consent are required in order to process the Customer member data, such notice and consent have been provided and collected; and,
    3. Where the Customer member data includes personal information that has been provided and/or processed by a third party, Customer has in place arrangement with those third parties which are adequate to permit Customer to share such data with Reflexion, and for Reflexion to process such data for the purposes of the Agreement and otherwise in accordance with this DPA.

13. General Terms

  1. This DPA, together with the Agreement and any Annexes, constitutes the entire agreement of the Parties relating to the subject matter of this DPA and supersedes all other oral or written agreements relating thereto. This DPA is entered into and becomes a binding part of the Agreement with effect from the date first set out above, thereafter terminating upon the cessation of processing under the Agreement.
  2. The Parties hereto agree and acknowledge that this DPA and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Agreement. The Parties hereto further hereby submit to the choice of jurisdiction stipulated in the Agreement with respect to any disputes or claims howsoever arising under this DPA, including disputes regarding its existence, validity or termination or the consequences of its nullity.
  3. Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.

Part B — Exhibit 1: Standard Contractual Clauses (Module 2, Controller → Processor)

The parties agree to the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (transfer controller to processor), which are incorporated into and form part of this DPA. The full official text is attached at execution; the module and optional-clause selections are:

Supplementary measures. Data is encrypted in transit and at rest; access is role-based and least-privilege.

UK Addendum. For UK GDPR transfers, the parties execute the Information Commissioner’s Office’s (“ICO”) International Data Transfer Addendum to the EU SCCs (B1.0), with the tables completed by reference to Annexes I–III.

Swiss adaptation. For FADP transfers: the FDPIC is the competent authority for Swiss data subjects; GDPR references are read to include the FADP; Swiss data subjects may sue in Switzerland; “member state” includes Switzerland for Clause 18(c).

Annex I.A — List of parties

Data importer (processor): Reflexion Interactive Technologies, Inc., 355 E Liberty Street, Suite 300, Lancaster, PA 17602, USA. Contact (data protection and security incidents): [email protected]. EU and UK representative (Art 27 GDPR / Art 27 UK GDPR — UK: Prighter Ltd, 20 Mortlake High Street, London SW14 8JN, United Kingdom, appointed 2026-07-13, signed LOA on file; EU below): Prighter (iuro Rechtsanwälte GmbH), Schellinggasse 3, 1010 Vienna, Austria — https://app.prighter.com/portal/reflexion.

Data exporter (controller): the Customer identified in the applicable account, order, or addendum.

Annex I.B — Description of the transfer

Data subjects: Customer’s athletes and end users (including minor athletes enrolled with verified guardian consent), and Customer’s coaches, staff, and account administrators.

Categories of personal data: identification and contact data (name, email, date of birth, birth sex); account and consent records; demographic and athletic profile (dominant hand; sport, position, level, sub-level; team name; school or college name and zip); device and technical data (IP address, device identifiers, logs); training, assessment, and performance data (assessment scores, drill results, training frequency, goals, personal bests; for Reflexion Breathe, audio recordings, head pose, and inertial data used to compute an estimated normalized lung-volume waveform).

Sensitive data: Training and assessment data may constitute data concerning health.

Frequency: continuous, for the duration of the Agreement.

Nature and purposes: hosting and storage; delivery of training drills and assessments; scoring and progress analytics; account management and support; security and abuse prevention.

Retention: term of the Agreement plus deletion within 24 months of termination (sooner on request); anonymized and aggregated training records retained as described in the Privacy Policy.

Sub-processor transfers: as per Annex III.

Annex I.C — Competent supervisory authority

Determined by operation of Clause 13: the supervisory authority of the EU Member State in which the Customer (data exporter) is established (for a Customer established in more than one Member State, the authority of its main establishment). For UK transfers, the Information Commissioner’s Office (ICO); for Swiss data subjects, the Federal Data Protection and Information Commissioner (FDPIC), alongside the competent EEA authority.

Annex II — Technical and organizational measures

  • Encryption of personal data in transit (TLS) and encrypted storage for credentials; cloud KMS (AWS KMS) key management with documented procedures and restricted access.
  • Role-based access control, least-privilege administration, and need-to-know access; personnel confidentiality obligations.
  • Logical separation of Customer member data; pseudonymization and minimization where feasible.
  • Vulnerability monitoring and patching; error and security monitoring; application and database-engine logging (centralized log management is a roadmap item).
  • Backup with 35-day rotation; disaster-recovery procedures.
  • Data-quality, retention, and erasure procedures and automated purges of unlinked funnel records.
  • Incident-response process with 72-hour customer notification.
  • Sub-processor due diligence and contractual flow-down.
  • Consent capture and versioned consent records.

Annex III — Authorized sub-processors

7 sub-processors

Authorized sub-processors — current as of August 3, 2026.
Amazon Web Services, Inc. Cloud hosting and storage United States
Cloudflare, Inc. Content delivery and security United States (global edge)
Zoho Corporation Subscription billing and invoicing; support desk; and business analytics on member personal data and training/assessment data that may constitute data concerning health (processed under the consents and safeguards described in this DPA) United States; remote support access from India under Zoho’s DPA and SCC flow-down
Intuit Mailchimp (Mailchimp Transactional / Mandrill) Transactional email delivery United States
RudderStack, Inc. Product analytics (consent-gated) United States
Calendly LLC Scheduling (support and onboarding) United States
Stripe, Inc. Payment processing for website checkout (card data handled by Stripe as an independent controller under its Services Agreement) United States

This Data Processing Agreement is effective August 3, 2026. Questions: [email protected].