DATA PROCESSING ADDENDUM

Last updated September 2, 2026

Sampark Inc. d/b/a Composio

Table of contents

This DPA is not binding unless and until accepted by Customer through the Composio dashboard.

Upon acceptance, this Data Processing Addendum, including its Attachments (“DPA”) is entered into between Sampark, Inc. dba Composio, a Delaware company with offices at 2 Bryant St., Suite 220, San Francisco, CA 94105 (“Composio”) and the customer that accepts this DPA (“Customer”). By accepting this DPA, Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of Customer’s authorized Affiliates, if and to the extent Composio processes Personal Data for which such authorized Affiliates qualify as the Controller. All capitalized terms not defined herein shall have the meaning set forth in Attachment 1 to this DPA. In the course of providing the Services, Composio may Process Personal Data on Customer’s behalf and the parties agree to comply with the terms and conditions in this DPA in connection with such Personal Data.

Acceptance is available to Pro and Enterprise Developer customers on the billing page in the Composio developer dashboard. No countersignature is required: as set out in Section 5, acceptance of this DPA constitutes execution of the applicable Standard Contractual Clauses.

Composio does not review, negotiate or countersign customer-supplied data processing agreements, and does not customize this DPA on a case-by-case basis. Enterprise customers requiring bespoke terms should contact their account team.

1. DEFINITIONS

Capitalized terms used in this DPA will have the meanings set forth in Attachment 1 to this DPA.

2. DATA PROCESSING AND PROTECTION

2.1 Roles of Parties. With respect to the CCPA, Customer is a “business” (as defined in the CCPA) and is engaging Composio as a “service provider” (as defined in CCPA) to Process Personal Data in the performance of the Services on behalf of Customer. With respect to US State Data Protection Laws, Customer is a “controller” (as defined in US State Data Protection Laws) and Composio is a “processor” (as defined in US State Data Protection Laws). With respect to the European Data Protection Laws, Customer is the Controller and Composio is the Processor (as defined in the European Data Protection Laws).

2.2 Limitations on Use. Composio will Process Personal Data only: (a) in a manner consistent with documented instructions from Customer, including with regard to transfers of Personal Data to a third country, which will include Processing (i) as authorized or permitted under this DPA, including as specified in Attachment 2 to this DPA, and (ii) consistent with other reasonable instructions of Customer; and (b) as required by Data Protection Law, provided that Customer will inform Composio (unless prohibited by such Data Protection Law) of the applicable legal requirement before Processing pursuant to such Data Protection Law. Without limiting the foregoing, Composio will not retain, use, or disclose the Personal Data for any purpose other than for the specific purpose of performing the Services, including retaining, using, or disclosing the Personal Data for a commercial purpose other than providing the Services.

2.3 Confidentiality. Composio will ensure that persons authorized by Composio to Process any Personal Data are subject to appropriate confidentiality obligations.

2.4 Security. Composio will protect Personal Data in accordance with requirements under Data Protection Law. Composio will use reasonably appropriate technical and organizational measures appropriate for the nature, scope and type of processing being performed to protect Personal Data against Personal Data Breach that will meet or exceed the requirements specified Attachment 3 to this DPA.

2.5 Return or Disposal. Composio will (or will enable Customer via the Services to) delete or return (and will delete existing copies of) all Personal Data after the end of the provision of Services (unless Data Protection Law requires the storage of such Personal Data by Composio).

2.6 Processing Subject to the CCPA. As used in this Section 2.6, the terms “Sell,” “Share,” “Business Purpose,” and “Commercial Purpose” shall have the meanings given in the CCPA. Composio shall not: (a) Sell or Share any Personal Data; (b) retain, use, or disclose any Personal Data (i) for any purpose other than for the Business Purposes specified in this DPA, including for any Commercial Purpose other than the Business Purposes specified in this DPA and permitted by the CCPA, or (ii) outside of the direct business relationship between Customer and Composio; or (c) combine Personal Data received from, or on behalf of, Customer with Personal Data received from or on behalf of any third party, or collected from Composio’s own interaction with Data Subjects, except to perform a Business Purpose required by this DPA and permitted by the CCPA.

2.7 Data Minimization. Composio shall process only the minimum amount of Personal Data necessary to provide the Services and shall not collect or process Personal Data beyond what is specified in this DPA.

3. DATA PROCESSING ASSISTANCE

3.1 Data Subject’s Rights Assistance. Composio will provide reasonable assistance to Customer to allow Customer to respond to requests for exercising any individual’s rights provided under applicable Data Protection Law.

3.2 Compliance Review Assistance. Composio will cooperate in good faith with Customer in Customer’s efforts to ensure Composio’s reasonable compliance with this DPA, by making available to Customer a copy of Composio’s or its hosting provider’s most recent audit report. To the extent that Composio’s provision of an audit report does not provide sufficient information for Customer to verify Composio’s compliance with this DPA, Composio will assist Customer, to the extent possible, in auditing Composio’s compliance with its obligations under this DPA through reasonable requests for information, including security and audit questionnaires. Composio will provide written responses, subject to confidentiality procedures. Any requests for information will be with thirty (30) days’ advance notice to Composio, and shall be limited to once per year, unless Customer has reasonable concerns about Composio’s data protection compliance, following a breach or following instruction from a data protection authority.

3.3 Data Protection Impact Assessment and Assistance. Composio will provide reasonable assistance to Customer as required for Customer to comply with its obligations under European Data Protection Laws in connection with Composio’s Processing of Personal Data under this DPA.

3.4 Personal Data Breach Notice and Assistance. Composio will notify Customer without undue delay after becoming aware of a Personal Data Breach. Composio will provide reasonable assistance to Customer as may be necessary for Customer to satisfy any of its notification obligations imposed under Data Protection Law in connection with any Personal Data Breach, including assistance necessary to facilitate Customer’s compliance with European Data Protection Laws.

3.5 Personal Data Inquiries Assistance. Where required by Data Protection Laws, Composio agrees to provide reasonable assistance and comply with reasonable instructions from Customer related to any inquiries, complaints or other communications from individuals and/or regulatory bodies related to the Processing of Personal Data under this DPA. In the event that any such request, complaint or communication is made directly to Composio, Composio shall promptly notify Customer, shall provide full details of the request, shall not respond to such communication without Customer’s express authorization and shall reasonably comply with Customer’s instruction in respect of the request.

4. SUBPROCESSORS

Customer authorizes Composio to use the following subprocessors: https://trust.composio.dev/subprocessors to Process Personal Data in connection with the provision of Services to Customer (“Subprocessor”). Composio will impose data protection obligations upon any Subprocessor that are no less protective than those included in this DPA. Composio will remain liable for any acts or omissions of its Subprocessors in violation of this DPA.

5. TRANSFERS OF PERSONAL DATA SUBJECT TO EUROPEAN DATA PROTECTION LAWS

If Customer transfers Personal Data to Composio that is subject to European Data Protection Laws, and such transfer is not subject to an alternative adequate transfer mechanism under European Data Protection Laws or otherwise exempt from cross-border transfer restrictions, then Customer (as “data exporter”) and Composio (as “data importer”) agree that the applicable terms of the SCCs shall apply to and govern such transfer and are hereby incorporated herein by reference. In furtherance of the foregoing, the parties agree that: (a) the execution of this DPA shall constitute execution of the applicable SCCs as of the effective date of the DPA; (b) the relevant selections, terms, and modifications set forth in Attachment 4 shall apply, as applicable; and (c) the SCCs shall automatically terminate once the Personal Data transfer governed thereby becomes lawful under European Data Protection Laws in the absence of such SCCs on any other basis.

6. MISCELLANEOUS

This DPA constitutes the entire agreement between the parties with respect to Composio’s Processing of Personal Data on behalf of Customer and supersedes any prior agreements or understandings on that subject matter. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions will remain in full force and effect. This DPA will be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of laws principles, and the parties submit to the exclusive jurisdiction of the state and federal courts located in San Francisco County, California with respect to any disputes arising out of this DPA.

ATTACHMENT 1: DEFINITIONS

For purposes of this DPA, the following terms will have the meaning ascribed below:

“Connected Apps” means a third-party application or service that Customer or its End Users authorize Composio to access on their behalf using credentials supplied or generated through the Services, and through which Customer Personal Data is transmitted or processed at Customer’s direction.

“Data Protection Law” means all applicable laws, regulations, principles, regulatory guidelines, or other requirements of any jurisdiction relating to the protection, privacy, security, integrity, confidentiality, storage, transfer, or other Processing of Personal Data, including, without limitation, European Data Protection Laws, and the California Consumer Privacy Act of 2018 together with its implementing regulations (in each case as amended from time to time, the “CCPA”).

“European Data Protection Laws” means: (a) the EU General Data Protection Regulation 2016/679 (“GDPR”); (b) the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), the Data Protection Act of 2018, and all other laws relating to data protection, the processing of personal data, privacy, or electronic communications in force from time to time in the United Kingdom (collectively, “UK Data Protection Laws”); (c) the Swiss Federal Act on Data Protection (“Swiss FADP”); and (d) any other applicable law, rule, or regulation related to the protection of Personal Data in the European Economic Area, United Kingdom, or Switzerland that is already in force or that will come into force during the term of this DPA.

“Personal Data” means any data that Composio Processes on behalf of Customer that is deemed personal data or personal information (or other analogous variations of such terms) under Data Protection Law.

“Personal Data Breach” means any accidental or unlawful destruction, loss, or alteration of Personal Data, or any unauthorized use or disclosure of, or access to, Personal Data in Composio’s control, custody or possession.

“Process” or “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Services” means the services provided by Composio to Customer pursuant to an underlying agreement or terms.

ATTACHMENT 2: SCOPE OF PROCESSING

Subject-Matter and Duration of Processing. Composio Processes Personal Data for the purpose of providing the Services and for the duration of Customer’s use of the Services, unless otherwise agreed upon by the parties in writing.

Nature and Purpose of Processing (i.e., Processing operations). Personal Data is subject to the following basic processing activity: Collection, storage, transmission, retrieval and deletion of personal data to (i) authenticate Customer’s users with Connected Apps and store the resulting credentials, (ii) relay requests and responses between Customer’s agents and Connected Apps, and (iii) log activity for security, debugging and billing.

Categories of Personal Data. (a) Account and identifier data: name, email, user ID, IP address. (b) Authentication data: OAuth tokens, API keys and similar credentials for Connected Apps, encrypted at rest. (c) Content data: any personal data contained in data Customer’s agents read from or write to Connected Apps. Its scope is determined solely by Customer and may include contact details, communications, calendar entries, files and business records. (d) Usage and log data: tool-call metadata (timestamps, action name, status) and request/response payloads where logging is enabled.

Categories of Data Subjects. (a) Customer’s employees, contractors and authorized users; (b) Customer’s end users whose accounts are connected to the Services; (c) third parties whose personal data appears in Connected Apps accessed via the Services (e.g. email correspondents, CRM contacts, calendar attendees).

Special Categories of Data (as applicable). None.

Data exporter. The Customer that accepts this DPA, as identified in the Composio account through which acceptance is recorded, together with the contact details and activities relevant to the data transferred recorded at acceptance. Role (controller/processor): CONTROLLER.

Data importer. SAMPARK, INC. DBA COMPOSIO. Address: 2 Bryant St., Suite 220, San Francisco, CA 94105. Contact person’s name, position and contact details: Soham Ganatra, CEO, support@composio.dev. Role (controller/processor): PROCESSOR.

ATTACHMENT 3: TECHNICAL AND ORGANIZATIONAL MEASURES

1. Program. Composio will implement and maintain a written information security program (“Information Security Program”), which contains appropriate administrative, technical and organizational safeguards that comply with this Attachment 3 and that: (a) ensure the security, integrity, availability, resilience and confidentiality of Personal Data; (b) prevent any Personal Data Breach; and (c) meet or exceed prevailing industry standards.

2. Access Controls. Composio will: (a) abide by the “principle of least privilege,” pursuant to which Composio will permit access to Personal Data by its personnel solely on a need-to-know basis; (b) promptly terminate its personnel’s access to Personal Data when such access is no longer required for the performance of the Services; and (c) be responsible for any Processing of Personal Data by its personnel.

3. Account Management. Composio will use reasonable measures to manage the creation, use, and deletion of all account credentials used to access the Composio systems, including by implementing: (a) a segregated account with unique credentials for each user; (b) strict management of administrative accounts; and (c) password best practices, including the use of strong passwords and secure password storage.

4. Vulnerability Management. Composio will: (a) use automated vulnerability scanning tools to scan the Composio systems; (b) log vulnerability scan reports; (c) conduct periodic reviews of vulnerability scan reports over time; (d) use patch management and software update tools for the Composio systems; (e) prioritize and remediate vulnerabilities by severity; and (f) use compensating controls if no patch or remediation is immediately available.

5. Security Segmentation. Composio will monitor, detect and restrict the flow of information on a multilayered basis within the Composio systems using tools such as firewalls, proxies, and network-based intrusion detection systems.

6. Data Loss Prevention. Composio will use reasonable data loss prevention measures to identify, monitor and protect Personal Data in use, in transit and at rest. Such data loss prevention processes and tools will include: (a) use of certificate-based security; and (b) secure key management policies and procedures.

7. Encryption. Composio will encrypt, using industry standard encryption tools, all Personal Data that Composio: (i) transmits or sends wirelessly or across public networks or within the Composio systems; (ii) stores on laptops or storage media, and (iii) stores on portable devices or within the Composio System. Composio will safeguard the security and confidentiality of all encryption keys associated with encrypted Personal Data.

8. Secure Software Development. Composio represents and warrants that any software used in connection with the Processing of Personal Data is or has been developed using secure software development practices, including: (a) segregating development and production environments; (b) filtering out potentially malicious character sequences in user inputs; (c) using secure communication techniques, including encryption; (d) using sound memory management practices; (e) using web application firewalls to address common web application attacks such as cross-site scripting, SQL injection and command injection; (f) implementing the OWASP Top Ten recommendations, as applicable; (g) patching of software; and (h) testing of web applications for vulnerabilities using web application scanners.

9. Administrative Safeguards. Prior to providing access to Personal Data to any of its personnel, Composio will: (a) ensure the reliability of such personnel, including by performing background screening (to the extent permitted by Data Protection Law); and (b) provide appropriate security training to such personnel to ensure such personnel can comply with the obligations under this Attachment 3. Composio will periodically provide additional training to its personnel as may be appropriate to help ensure that Composio’s Information Security Program meets or exceeds prevailing industry standards.

ATTACHMENT 4: STANDARD CONTRACTUAL CLAUSES

1. Application of Modules. If Customer is acting as a Controller with respect to Customer Personal Data, “Module Two: Transfer controller to processor” of the SCCs shall apply. If Customer is acting as a Processor to a third-party Controller with respect to Customer Personal Data, Composio is a sub-Processor and “Module Three: Transfer processor to processor” of the SCCs shall apply.

2. Sections I-V. The parties agree to the following selections in Sections I-IV of the SCCs: (a) the parties select Option 2 in Clause 9(a) and the specified time period shall be thirty (30) days; (b) the optional language in Clause 11(a) is omitted; (c) the parties select Option 1 in Clause 17 and the governing law of the Republic of Ireland will apply; and (d) in Clause 18(b), the parties select the courts of the Republic of Ireland.

3. Annexes. The name, address, contact details, activities relevant to the transfer, and role of the parties set forth in this DPA shall be used to complete Annex I.A. of the SCCs. The information set forth in Attachment 2 to the DPA shall be used to complete Annex I.B. of the SCCs. The competent supervisory authority in Annex I.C. of the SCCs shall be determined pursuant to Clause 13 of the SCCs. The technical and organizational measures in Annex II of the SCCs shall be the measures set forth in Attachment 3 to the DPA.

4. Transfers from the United Kingdom. If Customer transfers Customer Personal Data to Composio that is subject to UK Data Protection Laws, the parties acknowledge and agree that: (a) the template addendum issued by the Information Commissioner’s Office of the United Kingdom and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it may be revised from time to time by the Information Commissioner’s Office (the “UK Addendum”) shall be incorporated by reference herein; (b) the UK Addendum shall apply to and modify the SCCs solely to the extent that UK Data Protection Laws apply to Customer’s Processing when making the transfer; (c) the information required to be set forth in “Part 1: Tables” of the UK Addendum shall be completed using the information provided in Attachment 2; and (d) either party may end the UK Addendum in accordance with section 19 thereof.

5. Transfers from Switzerland. If Customer transfers Customer Personal Data to Composio that is subject to the Swiss FADP, the following modifications shall apply to the SCCs to the extent that the Swiss FADP applies to Customer’s Processing when making that transfer: (a) the term “member state” as used in the SCCs shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence in accordance with Clause 18(c) of the SCCs; (b) references to the GDPR or other governing law contained in the SCCs shall also be interpreted to include the Swiss FADP; and (c) the parties agree that the supervisory authority as indicated in Annex I.C of the SCCs shall be the Swiss Federal Data Protection and Information Commissioner.

Last updated September 2, 2026