Data Protection Addendum
Innabox, Inc. DBA CharacterQuilt — Last Updated: March 23, 2026
This Data Protection Addendum ("Addendum") forms part of the Innabox Inc. dba CharacterQuilt ("CharacterQuilt") ("Principal Agreement") between: (i) Customer ("Controller") and (ii) CharacterQuilt ("Processor"). This Addendum is entered into and effective as of the last dated signature below ("Effective Date").
Capitalized terms not otherwise defined herein shall have the meaning given to them in the Principal Agreement. Except as modified below, the terms of the Principal Agreement shall remain in full force and effect. In the event of a conflict between this Addendum and the provisions of related agreements, including the Principal Agreement, the terms of this Addendum shall prevail.
Agreement
1. Definitions
In this Addendum, the following terms shall have the meanings set out below:
- "Applicable Laws" means data protection and privacy laws and regulations currently in effect and in force, solely to the extent applicable to Processor's Services on behalf of Controller pursuant to the Agreement in jurisdictions where the Services are provided, as applicable. Applicable Laws may include, where applicable the CCPA;
- "CCPA" means the California Consumer Privacy Act of 2018;
- "Contracted Processor" means Processor or a Subprocessor;
- "Data Subject" means an identified or identifiable natural person to whom Personal Data relates;
- "Personal Data" means any information that is reasonably associated or linked with an identified or identifiable person and Processed by the Processor on behalf of the Controller pursuant to the Principal Agreement;
- "Processor-Controlled Systems" means information technology systems, networks, devices, and storage environments owned or controlled by Processor and that are used to Process Personal Data on behalf of Controller. Processor-Controlled Systems exclude Controller's systems and third-party systems not controlled by Processor;
- "Security Incident" means any confirmed accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access to Personal Data, provided that such Personal Data is within Processor-Controlled Systems. Security Incident excludes unsuccessful attempts or activities that do not compromise the security of Personal Data (e.g., pings, port scans, unsuccessful log-in attempts, etc.);
- "Services" means the services and other activities to be supplied to or carried out by or on behalf of Contracted Processor for Controller pursuant to the Principal Agreement;
- "Subprocessor" means any entity or person (including any third party but excluding an employee of Processor or any of its sub-contractors) appointed by or on behalf of Processor to Process Personal Data on behalf of any Controller in connection with the Principal Agreement;
- The terms "Process," "Service Provider," "Sell," "Share," and "Supervisory Authority" shall have the same meaning as in the Applicable Laws; and,
- The term "Data Subject" includes analogous terms, such as "Consumer," as defined by Applicable Laws.
2. Processing of Personal Data
Processor shall:
- comply with all Applicable Laws in the Processing of Personal Data in Processor-Controlled Systems;
- not Process Personal Data other than on the Controller's documented lawful instructions unless Processing is required or permitted by Applicable Laws to which the Processor is subject. As used herein, Controller's "instructions" means written instructions issued by Controller within the scope of the Services (including email or ticketing systems) that are lawful, feasible, and technically reasonable;
- not directly or indirectly Sell or Share any Personal Data, or retain, use, or disclose any Personal Data for any purpose other than for the purpose of performing Services for Controller; or retain, use, or disclose any Personal Data outside the scope of this Addendum or the Principal Agreement; and
- not combine Personal Data received from Controller with Personal Data from any other source, including Personal Data obtained from other persons or Personal Data obtained by Processor itself from its own interactions with the consumer with whom the Personal Data is associated, provided that Processor may combine Personal Data to perform any business purpose authorized or otherwise permitted by Applicable Laws.
Controller shall:
- instruct Processor (and authorizes Processor to instruct each Subprocessor) to:
- Process Personal Data as described in Appendix; and
- in particular, transfer Personal Data to any country or territory, as reasonably necessary for the provision of the Services and consistent with the Principal Agreement.
Controller represents and warrants that:
- it has complied, and will continue to comply, with all Applicable Laws in respect of its processing of Personal Data and any processing instructions issued to Processor;
- it is and will at all relevant times remain duly and effectively authorized to give the instructions set out in this section;
- it has all necessary rights to provide the Personal Data to the Processor for the Processing to be performed in relation to the Services;
- one or more lawful bases set forth in the Applicable Laws support the lawfulness of the Processing;
- all necessary privacy notices are provided to data subjects;
- any necessary data subject consents to the Processing are obtained and a record of such consents is maintained; and
- should such a consent be revoked by a data subject, and no other lawful basis remains to keep the data subject's personal data, it will communicate the fact of such revocation to the Processor.
Controller will ensure that Processor's processing of the Personal Data in accordance with Controller's instructions will not cause Processor to violate any applicable law, regulation, or rule.
Controller, upon written prior notice and a reasonable opportunity to cure, may stop and remediate unauthorized use of Personal Data by Processor, including without limitation, exercising Controller's right to conduct an audit of Processor or terminate the Principal Agreement and exercise Controller's right to request deletion of Personal Data.
Processor acknowledges that it is a Service Provider and that all Personal Data that it may receive from Controller, Controller's employees or consultants, or otherwise acquired by virtue of the performance of services under the Principal Agreement shall be regarded by Processor as confidential and held by Processor in confidence.
Processor understands the restrictions in this Section 2 and will comply with them.
Processor shall notify Controller without undue delay if it makes the determination that it can no longer meet any of its obligations under this Addendum.
3. Processor Personnel
Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Personal Data, ensuring in each case that access is limited to those individuals who need to know / access the relevant Personal Data as necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual's duties to the Processor, ensuring that all such individuals are subject to appropriate confidentiality undertakings or professional or statutory obligations of confidentiality.
4. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk.
In assessing the appropriate level of security, Processor shall take account in particular of the risks that are presented by Processing, in particular from a Security Incident.
Processor shall notify Controller without undue delay upon becoming aware of a Security Incident affecting Personal Data. Controller is solely responsible for complying with incident notification laws applicable to Controller and fulfilling third party notification obligations related to any Security Incidents.
The Parties acknowledge that security requirements are constantly changing and that effective security may require improvements of outdated security measures. Controller will bear the cost, if any, to implement material changes required by specific updated security requirements set forth in Applicable Laws or by regulatory authorities of competent jurisdiction.
Where an amendment to the Principal Agreement is necessary in order to execute a Controller instruction to the Processor to improve security measures as may be required by changes in Applicable Laws from time to time, the Parties shall negotiate an amendment to the Principal Agreement in good faith.
5. Subprocessing
Controller authorizes Processor to appoint (and permit each Subprocessor appointed in accordance with this section to appoint) Subprocessors in accordance with this section and any restrictions in the Principal Agreement.
Processor may continue to use those Subprocessors already engaged by Processor as of the date of this Addendum, subject to Processor in each case as soon as practicable meeting the obligations set out in this Section.
Prior to engaging any new Subprocessors to perform services under the Principal Agreement, Processor shall first provide Controller with an opportunity to object to the Subprocessor on reasonable grounds. If Controller does not object within ten (10) days, Processor may engage the Subprocessor and shall:
- ensure that the arrangement between Processor, on the one hand, and the Subprocessor, on the other hand, is governed by a written contract including terms which offer a substantially similar level of protection for Personal Data as those set out in this Addendum, to the extent applicable to the nature of the Services provided by such Subprocessor; and
- if that arrangement involves a Restricted Transfer, ensure an approved transfer mechanism is at all relevant times incorporated into the agreement between Processor, on the one hand, and the Subprocessor, on the other hand.
6. Cooperation
Taking into account the nature of the Processing, Processor shall reasonably assist Controller with any Data Subject requests made under Applicable Laws, solely with respect to Personal Data in Processor-Controlled Systems.
If Processor receives a subpoena, court order, warrant, or other legal demand from a third party (including law enforcement or other public or judicial authorities) seeking the disclosure of Personal Data, to the extent permitted by Applicable Law(s), Processor shall not disclose any information but shall notify Controller of such request.
In the event that any such request, complaint, or communication is made directly to Processor, Processor shall promptly notify Controller. Controller shall be solely responsible for responding to a request from a Data Subject as required under any Applicable Laws in respect of Personal Data.
If a Data Subject exercises the right to delete under the CCPA, Processor shall, at the written request of the Controller, delete or enable Controller to delete, and shall notify its Subprocessors to delete, Personal Data about the Data Subject collected, used, processed, or retained by the Subprocessor. Processor shall also notify all other parties who may have accessed such Personal Data from or through the Subprocessor to delete the Data Subject's Personal Data unless the Data Subject's Personal Data was accessed at the direction of the Controller.
To the extent required under Applicable Laws, and taking into account the nature of processing and the information available to the Processor, the Processor shall, at Controller's expense, reasonably assist the Controller with privacy, risk, and impact assessments and prior consultations with supervisory authorities.
7. Audits
To the extent audits are required by Applicable Laws or requested by a regulatory authority of competent jurisdiction, Controller shall provide Processor with 30 days' written notice of the audit and shall identify the relevant requirement or request in its notice to Processor of the audit.
The Parties shall negotiate in good faith the time, manner, and scope of such audit and such audit shall be conducted at Controller's sole expense, including without limitation the personnel costs of Processor for personnel involved in an audit of Controller. Processor may provide copies of its policies and procedures and written responses to Controller's questions for purposes of such an audit. All information provided during such audits shall be treated as Processor's confidential information and Controller shall ensure that such protections satisfactory to Processor are in force prior to the initiation of any audit.
Controller shall make (and ensure that each of its mandated auditors makes) reasonable endeavors to avoid causing any damage, injury or disruption to Processor's premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection.
Processor need not give access to its premises or records for the purposes of such an audit or inspection:
- to any individual unless he or she produces reasonable evidence of identity and authority;
- outside normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis and the Controller undertaking an audit has given notice to Processor that this is the case before attendance outside those hours begins; or
- for the purposes of more than one audit or inspection in any calendar year, except for any additional audits or inspections which the controller is required or requested to carry out by Applicable Laws or a regulatory authority of competent jurisdiction, where the Controller has identified the relevant requirement or request in its notice to Processor of the audit or inspection.
Under no circumstances shall Controller have or require logical or administrative access to Processor's systems, access to the confidential information of Processor's other customers, or access to Processor's proprietary information.
8. Deletion or Return of Personal Data
Within 30 days of the termination or expiration of this Addendum, Controller may by written notice request that Processor (a) return a copy of all Personal Data in its possession to Controller and/or (b) delete and procure the deletion of all other copies of Personal Data Processed by any Contracted Processor.
Processor may retain Personal Data to the extent required by Applicable Laws and shall ensure that such Personal Data is only Processed as necessary for the purpose(s) specified in the Applicable Laws.
9. General
- The parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the Principal Agreement;
- This Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Principal Agreement; and,
- Any liability arising under this Addendum shall be subject to the limitation of liability provisions, if any, within the Principal Agreement.
In witness whereof, the parties have executed this Addendum as of the date first set forth above.
Name: _____________________
Title: ____________________
Date: _____________________
Name: _____________________
Title: ____________________
Date: _____________________
Appendix
Description of Processing
Nature of the processing. The Personal Data will be Processed as incidental to providing the Services as specified in the Principal Agreement and/or applicable SOW.
Purpose(s) of the processing. The Personal Data will be Processed for the provision of the Services as specified in the Principal Agreement and/or applicable SOW.
Retention period. The Personal Data transferred will be retained for as long as necessary for the provision of the Services as specified in the Principal Agreement and/or applicable SOW.
List of Sub-Processors
The Controller has authorized the use of the following Subprocessors:
| Name | Nature of Processing | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud Data Storage, Application Hosting | USA |
| Anyscale Inc. | Large Language Model Services | USA |
| OpenAI LLC | Large Language Model Services | USA |
| Anthropic | Large Language Model Services | USA |
For a current list of subprocessors, please see the Subprocessors page. Questions about this Addendum may be directed to bhairav@characterquilt.com.
