DATA PROCESSING AGREEMENT (Art. 28 GDPR) Product: Centropic (centropic.ai) Processor / Provider: Engineering Factory Version: 2026-08-12 · Updated: 2026-08-12 Contact: info@centropic.ai 1. Parties and roles The Customer (Controller) uses Centropic SaaS. The Provider acts as Processor for personal data processed to deliver the service (account data, analyzed public URLs, analysis results, technical logs). Payment card data is processed by Paddle as merchant of record (independent controller for billing). 2. Subject matter and duration Processing is limited to providing Centropic features (crawl of public pages, scoring, packs, Edge signals, citation probes when entitled) for the term of the Customer's account and the retention periods in the Privacy Policy. 3. Nature and purpose Hosting, analysis of Customer-submitted public URLs, generation of artifacts, optional LLM probes, email transactional delivery, security logging, support. 4. Types of personal data and data subjects Account holders and invited users: name, email, company/role (optional), phone/country (optional), hashed password, plan/billing identifiers from Paddle, usage credits. Technical: IP, timestamps, session identifiers. Site content crawled is public web content submitted by Customer; Customer warrants it has rights to analyze it. 5. Provider obligations (Art. 28) - process only on documented Customer instructions (use of the SaaS); - ensure confidentiality of authorized persons; - implement appropriate technical and organizational security measures; - engage sub-processors listed in Annex A (and material updates notified); - assist with data subject rights, DPIA and breach notification where applicable; - delete or return personal data after account closure, subject to legal retention; - make available information necessary to demonstrate compliance. 6. International transfers Where sub-processors process outside the EEA/UK, transfers rely on appropriate safeguards (e.g. SCCs / adequacy) as described by each provider. Customer may request the current transfer summary via the contact email above. 7. Customer obligations Customer is Controller for data it uploads or causes to be processed, configures access, and must not submit special-category data unless a separate written addendum is agreed. Customer must not use Centropic to scan systems without authorization. 8. Liability and precedence This DPA supplements the Terms of Service and Privacy Policy. In case of conflict on data-protection obligations, this DPA prevails for processing topics. Governing law follows the Terms, without prejudice to mandatory data-protection rules. 9. Acceptance Using Centropic Business / agency features, or signing an order that references this DPA version, constitutes acceptance of this DPA. A countersigned copy is available on request to info@centropic.ai. ANNEX A — Sub-processors (active configuration) - Paddle.com Market Limited Role: Merchant of record / pagamenti (titolare autonomo per billing) Data: Email, identificativi cliente/transazione, importi, stato abbonamento Location: UE / UK (Paddle) Docs: https://www.paddle.com/legal/privacy - Hosting VPS (IONOS / infrastruttura Centropic) Role: Hosting applicazione, database, log tecnici Data: Account, siti analizzati, risultati, log IP/timestamp Location: UE (Germania / EU region) Docs: https://www.ionos.com/terms-gtc/privacy-policy/ - Object storage S3-compatible (MinIO / AWS S3) Role: Archiviazione pack/artifact analisi Data: Artifact HTML/testo generati, metadati job Location: UE (configurabile via endpoint) Docs: https://aws.amazon.com/privacy/ - Redis Role: Coda job / rate limit / cache operativa Data: Identificativi job, contatori, slot temporanei Location: Stesso host / rete privata UE - Email transazionale (SMTP / Resend) Role: Invio email account, pack, alert Data: Email destinatario, contenuto messaggi transazionali Location: UE o USA a seconda del provider configurato Docs: https://resend.com/legal/privacy-policy - OpenAI, LLC Role: LLM per artifact / citation monitor (se abilitato) Data: Prompt, snippet pagine pubbliche, output modello Location: USA / regioni OpenAI Docs: https://openai.com/policies/privacy-policy - Anthropic, PBC Role: LLM citation monitor (se abilitato) Data: Prompt, snippet pagine pubbliche, output modello Location: USA Docs: https://www.anthropic.com/legal/privacy - Perplexity AI, Inc. Role: LLM citation monitor (se abilitato) Data: Prompt, snippet pagine pubbliche, output modello Location: USA Docs: https://www.perplexity.ai/privacy - Google LLC (Gemini / Analytics) Role: LLM Gemini e/o GA4 misurazione (consenso cookie) Data: Prompt LLM e/o dati misurazione web se consenso Location: USA / UE (Google Cloud) Docs: https://policies.google.com/privacy - xAI Role: LLM citation monitor (se abilitato) Data: Prompt, snippet pagine pubbliche, output modello Location: USA Docs: https://x.ai/legal/privacy-policy - Sentry Role: Error tracking applicativo (se abilitato) Data: Stack trace, ID richiesta; evitare PII in log Location: UE / USA a seconda del progetto Docs: https://sentry.io/privacy/ End of DPA 2026-08-12