Last Updated: September 2, 2026

Data Protection Addendum

Schedule C

1. Definitions and Interpretation

In this Exhibit: “Provider” means RavenTek Solution Partners, LLC; “Customer” means the Licensee under the ManagedDEX EULA or the Customer under the Talon Software Support Services Agreement, as applicable; and “Agreement” means the instrument to which this Exhibit is attached. “Data Protection Laws” means all Laws applicable to the Processing of Personal Information under this Exhibit. “Personal Information”, “Processing”, “business”, “service provider”, “controller”, “processor”, “sell” and “share” have the meanings given in the applicable Data Protection Laws.

Capitalized terms not defined here have the meanings given in the Agreement.

2. Scope

This Exhibit applies only to Personal Information contained in Customer Data and Processed by Provider on Customer’s behalf in the course of providing Talon or the Services. It does not apply to, and Provider’s rights are not limited by this Exhibit in respect of, Usage Data, telemetry, diagnostic and performance information, or de-identified or aggregated information created from Customer Data, each of which is governed by the Customer Data provisions of the ManagedDEX EULA.

3. Roles

As between the Parties, Customer is the business and controller and Provider is the service provider and processor. Provider Processes Personal Information only on Customer’s documented instructions, which are given by the Agreement, this Exhibit and Customer’s use of Talon and the Services. Provider does not sell or share Personal Information, does not retain, use or disclose it for any purpose other than performing the Agreement, and does not combine it with personal information received from other sources except as permitted by applicable Data Protection Laws. Provider shall not knowingly commingle Personal Information with identifiable personal information of another customer, except to the extent Personal Information is contained in common infrastructure, logs, backups, security systems, support systems, sub-processor environments, or de-identified, anonymized, or aggregated data sets that are logically segregated or otherwise protected in accordance with this Exhibit. Provider shall notify Customer if it determines that it can no longer meet its obligations under applicable Data Protection Laws.

4. Customer Obligations

Customer is responsible for: (a) the accuracy and lawfulness of Personal Information it submits and for having a valid legal basis and all necessary notices and consents for Provider’s Processing, including any Processing through AI-enabled tools or services authorized under this Exhibit; (b) configuring Talon, the Designated Environment, and any Customer-authorized prompts, queries, summaries, or analysis requests so that only Personal Information necessary for the relevant purpose is submitted; and (c) compliance with Data Protection Laws in its own capacity.

5. Prohibited Data

Customer shall not submit, and shall configure Talon and the Services so as not to submit, any of the following unless Provider has signed a written addendum expressly permitting it: protected health information subject to HIPAA; cardholder data subject to PCI DSS; non-public personal information subject to the Gramm-Leach-Bliley Act; biometric or genetic identifiers; personal information of children under sixteen; special category or sensitive data as defined in applicable Data Protection Laws; and classified, controlled unclassified or export-controlled information. Provider has no liability arising from Customer’s submission of such data in breach of this paragraph, and Customer shall indemnify Provider against all claims, damages, fines, penalties, costs, and expenses (including reasonable attorneys’ fees) arising from it.

6. Security

Provider shall implement and maintain the technical and organizational measures described in Annex 2, designed to protect Personal Information against accidental or unlawful destruction, loss, alteration and unauthorized disclosure or access. Provider may update those measures from time to time provided the updated measures are not materially less protective. Provider shall ensure that personnel authorised to Process Personal Information are bound by appropriate obligations of confidentiality.

7. Sub-processors; AI Services

Customer grants Provider general written authorisation to engage sub-processors, including cloud hosting providers, support tools, security tools, analytics providers, and AI-enabled tools or services used to provide, secure, support, maintain, troubleshoot, summarize, analyze, or improve Talon or the Services. Provider maintains a current list of sub-processors and shall give Customer at least thirty (30) days’ notice before adding or replacing one. Customer may object within that period on reasonable grounds relating to data protection, in which case the Parties shall discuss in good faith; if the objection cannot be resolved, Customer’s sole remedy is to terminate the affected Services on written notice, with a pro rata refund of prepaid Fees for the terminated Services. Provider remains responsible for the acts and omissions of its sub-processors to the same extent as for its own. Provider will not use Personal Information to train or fine-tune a generally available artificial intelligence or machine-learning model except as expressly authorized in a separate written agreement, and will use commercially reasonable efforts to configure AI-enabled tools or services used for Talon so that prompts and outputs are processed for Provider’s authorized purposes and not used by the AI service provider to train its generally available models where such configuration is made available to Provider.

8. Assistance

Taking into account the nature of the Processing and the information available to it, Provider shall provide reasonable assistance to Customer with data subject or consumer requests, data protection impact assessments and consultations with supervisory authorities. Provider satisfies its obligations in respect of individual requests by making available the functionality within Talon that enables Customer to access, correct, delete and export Personal Information. Assistance beyond that available through Talon is chargeable at Provider’s then-current professional services rates.

9. Security Incidents

Provider shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident affecting Personal Information Processed on Customer’s behalf, and shall provide information reasonably available to it and reasonable cooperation in Customer’s investigation and notification obligations. Notification is not an acknowledgement of fault or liability. Customer is responsible for determining whether it must notify individuals or regulators and for making any such notification.

10. Audit

On written request not more than once in any twelve (12) month period, Provider shall make available a copy of its then-current third-party security certification or audit report, or a completed industry-standard security questionnaire, together with information reasonably necessary to demonstrate compliance with this Exhibit. Where no such report exists and an audit is required by Data Protection Laws, Customer may conduct an audit on not less than thirty (30) days’ written notice, during business hours, at Customer’s cost, subject to Provider’s site and security policies, by an independent auditor bound by confidentiality obligations and who is not a competitor of Provider. All audit materials and findings are Provider’s Confidential Information.

11. Return and Deletion

Within sixty (60) days after expiration or termination of the Agreement, Provider shall on written request delete or return Personal Information Processed on Customer’s behalf and delete existing copies, except to the extent retention is required by applicable Law or the copies are created automatically by routine archival or back-up systems and are not readily accessible in the ordinary course, in which case they remain subject to this Exhibit until deleted in the ordinary cycle. Provider is under no obligation to retain Personal Information beyond that period.

12. International Transfers

Where Provider Processes Personal Information subject to the GDPR or UK GDPR, the applicable Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum apply and are incorporated into this Exhibit, with Customer as data exporter and Provider as data importer, Module Two or Module Three as applicable, and with the details in Annex 1 completing the required annexes. This paragraph has no effect unless and until such Processing occurs.

13. Liability

This Exhibit creates no liability additional to, and no exception to, the exclusions and limitations set out in the Agreement, except that Customer’s indemnity obligation under paragraph 5 of this Exhibit is not subject to the limitations of liability in the Agreement. All other liability arising out of or relating to this Exhibit is subject to those exclusions and limitations. Where both the ManagedDEX EULA and the Talon Software Support Services Agreement are in force between the Parties, a single aggregate cap applies across both and this Exhibit.

14. Precedence and Term

In the event of conflict, this Exhibit prevails over the Agreement in respect of the subject matter of this Exhibit only, and the Agreement prevails in all other respects. This Exhibit takes effect on the effective date of the Agreement and continues for so long as Provider Processes Personal Information on Customer’s behalf.

Annex 1 to Schedule C

Details of Processing: categories of data subjects, categories of Personal Information, nature and purpose of Processing, duration, and the annex content required by the Standard Contractual Clauses.

Categories of data subjects may include Licensee personnel, contractors, authorized users, support users, endpoint users, administrators, and other individuals whose information is included in Customer Data. Categories of Personal Information may include business contact information, user identifiers, device identifiers, endpoint and system information, logs, telemetry, performance data, tickets, reports, and other Personal Information submitted to or generated through Talon or the Services. The nature and purpose of Processing are to provide, configure, secure, support, maintain, troubleshoot, improve, and enforce Talon and the Services, including authorized integrations with Customer-Authorized Data Sources and Third-Party Platforms. The duration of Processing is the Term of the Agreement and any post-termination period reasonably necessary for return, deletion, legal compliance, backups, security, dispute resolution, or enforcement, subject to Paragraph 11 of this Exhibit.

Annex 2 to Schedule C

Technical and Organizational Security Measures

Automated PII Redaction and Sanitization. Prior to transmitting any content to hosted AI, machine learning, or large language model services or related sub-processors, Talon applies an automated multi-key redaction and sanitization step designed to detect and redact prohibited data. This control is designed to cover each category of prohibited data identified in paragraph 5 of this Exhibit, including: (a) protected health information subject to HIPAA; (b) cardholder data subject to PCI DSS; (c) non-public personal information subject to the Gramm-Leach-Bliley Act; (d) biometric and genetic identifiers; (e) personal information of children under sixteen; (f) special category or sensitive data as defined in applicable Data Protection Laws; and (g) classified, controlled unclassified, or export-controlled information.

Information Security Management System and Accreditations. Provider maintains an information security management system certified to ISO/IEC 27001:2022 (G-CERTI, Certificate No. GIUS-1039-IC, valid from May 26, 2026 to May 21, 2029, under IAS/IAF accreditation). Provider also holds ISO 9001:2015 certification for quality management systems covering Agile solutions, systems integration, IT engineering, and cybersecurity provided to U.S. Federal Government agencies (G-CERTI, Certificate No. GIUS-1039-QC, valid from May 26, 2026 to May 21, 2029), and a CMMI Services Maturity Level 3 (SVC/ML3) appraisal (Appraisal No. 79573, valid through November 3, 2028). For clarity, these accreditations reflect RavenTek’s organizational information security and quality management posture; their scopes are enterprise/IT-services and federal-services scopes and do not constitute a certification of the Talon software itself. The technical and organizational measures below are implemented and maintained in accordance with that management system. Provider may update these measures and refresh or replace these accreditations from time to time provided the updated measures are not materially less protective.

(a) Access Control. Provider maintains logical access controls, including role-based access, least-privilege provisioning, authentication controls, and periodic access reviews governing access to systems and Personal Information.

(b) Encryption. Provider encrypts Personal Information in transit and at rest using industry-standard cryptographic controls.

(c) Backup and Resilience. Provider maintains data backup and recovery processes designed to protect against accidental or unlawful destruction, loss, or alteration of Personal Information.

(d) Endpoint and Infrastructure Security. Provider maintains controls over employee computing devices and IT infrastructure maintenance, including patch and configuration management and malware protection.

(e) Incident Response. Provider maintains a documented security incident response process, consistent with the seventy-two (72) hour Security Incident notification commitment in paragraph 9 of this Exhibit and Section 6.4 of the Agreement.

(f) Personnel Confidentiality and Service Desk. Provider ensures that personnel authorized to Process Personal Information, including Service Desk support personnel, are bound by appropriate obligations of confidentiality and receive security awareness training.

(g) Application and Collaboration Security. Provider maintains security controls over corporate email and SharePoint environments used in the delivery of the Services.

Annex 3 to Schedule C

Sub-processor list, or the URL at which the current list is maintained.

Provider’s current sub-processors are: (1) Microsoft Azure – hosting of the msp.talonmsp.com application; and (2) Riverbed Technology (Aternity) – provision of the Bundled Aternity Component as a component of ManagedDEX. For the avoidance of doubt, the Bundled Aternity Component that Provider makes available as part of ManagedDEX is provided under Provider’s license from Riverbed, and Riverbed acts as Provider’s sub-processor with respect to that component. Customer-Authorized Data Sources and Third-Party Platforms (including any Aternity tenant that Customer separately elects to connect using its own subscription and Microsoft services) accessed using Customer’s own credentials are Customer’s processors and are not Provider’s sub-processors.

Provided by RavenTek Solution Partners, LLC. In the event of a conflict between this page and a customer’s signed agreement, the signed agreement governs.

Contents