We value your privacy

We use cookies and other technologies to personalize your experience, perform marketing, and collect analytics. Learn more in our Privacy Policy.

Master Services Agreement

Last Updated: July 30, 2026

This Master SaaS Agreement (this “Agreement”) governs your and your Authorized Users’ (as defined below) access to and use of our Platform (as defined below), which is made available to you (“Customer” “you,” or “your”) by Dreamhub Inc. (“Dreamhub” “we,” “our,” or “us”), each, a “Party” and collectively, the “Parties.”

If you are entering into this Agreement on behalf of a legal entity, you represent that you have the authority to bind such entity to this Agreement, in which case the terms “you” or “your” refers to such entity. Dreamhub and Customer may each be referred to individually as a “Party” and collectively as the “Parties.”

BY CLICKING THE “ACCEPT” BUTTON, EXECUTING AN ORDER FORM, AND/OR ACCESSING AND USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE REVIEWED AND AGREE TO BE LEGALLY BOUND BY THE TERMS AND CONDITIONS OF THIS AGREEMENT. IF YOU DO NOT ACCEPT THE TERMS OF THIS AGREEMENT, OR DO NOT HAVE THE AUTHORITY TO BIND THE ENTITY TO THIS AGREEMENT, YOU AND YOUR AUTHORIZED USERS MAY NOT ACCESS OR USE THE PLATFORM.

The Parties hereby agree as follows:

1. DEFINITIONS.

The definitions for some of the defined terms used in this Agreement are set forth below. The definitions for other defined terms are set forth elsewhere in this Agreement.

1.1. “Affiliate” means, with respect to any entity, any other entity that, directly or indirectly, through one or more intermediaries, controls, is controlled by, or is under common control with, such entity. The term “control” means the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through the ownership of voting securities, by contract, or otherwise.

1.2. “Applicable Law” means, with respect to any Party, any federal, state, or local statute, law, ordinance, rule, administrative interpretation, regulation, order, writ, injunction, directive, judgment, decree, or other requirement of any international, federal, state, or local court, administrative agency, or commission or other governmental or regulatory authority or instrumentality, domestic or foreign, applicable to such Party or any of its properties, assets, or business operations.

1.3. “Authorized User” means Customer’s employees, contractors, or agents authorized by Customer to access and use the Platform pursuant to the terms and conditions of this Agreement; provided, however, that any contractors’ or agents’ access to and use of the Platform will be limited to their provision of services to Customer. You are responsible for all acts and omissions of Authorized Users and any other person who accesses and uses the Platform using any of your or any Authorized Users’ login credentials.

1.4. “Confidential Information” means: (i) with respect to Dreamhub, the Platform, and any and all source code relating thereto, the Usage Data, the Insights, the Documentation, pricing and fees related to the Platform provided hereunder, and any other non-public information or material regarding our legal or business affairs, financing, customers, properties, pricing, or data; (ii) with respect to you, the Customer Data, and any other non-public information or material regarding your legal or business affairs, financing, Authorized Users, properties, or data; and (iii) with respect to each Party, the terms and conditions of this Agreement. Notwithstanding any of the foregoing, Confidential Information does not include information which: (a) is or becomes public knowledge without any action by, or involvement of, the Party to which the Confidential Information is disclosed (the “Receiving Party”); (b) is documented as being known to the Receiving Party prior to its disclosure by the other Party (the “Disclosing Party”); (c) is independently developed by the Receiving Party without reference or access to the Confidential Information of the Disclosing Party and is so documented; or (d) is obtained by the Receiving Party without restrictions on use or disclosure from a third party.

1.5. “Customer Data” means any data and information that you or your Authorized Users submit to the Platform and/or provide to Dreamhub through the Platform, including, without limitation, the Personal Information (such as name, email address, and other identifying information) of your Authorized Users and Shared Data.

1.6. “DPA” means the Data Processing Agreement, attached hereto and incorporated herein as Schedule B.

1.7. “Documentation” means the manuals, specifications, and other materials describing the functionality, features, and operating characteristics, and use of the Platform as provided or made available by Dreamhub to Customer whether in a written or electronic form.

1.8. “Effective Date” means the date you accept this Agreement.

1.9. “Fees” means the fees set forth on the applicable Order Form.

1.10. “Harmful Code” means computer code, programs, or programming devices that are intentionally designed to disrupt, modify, access, delete, damage, deactivate, disable, harm, or otherwise impede in any manner, including aesthetic disruptions or distortions, the operation of the Platform, or any other associated software, firmware, hardware, computer system, or network (including, without limitation, “Trojan horses,” “viruses,” “worms,” “time bombs,” “time locks,” “devices,” “traps,” “access codes,” or “drop dead” or “trap door” devices) or any other harmful, malicious, or hidden procedures, routines or mechanisms that would cause the Platform to cease functioning or to damage or corrupt data, storage media, programs, equipment, or communications, or otherwise interfere with the operations of the Platform.

1.11. “Insights” means anonymized learnings generated by processing Customer Data together with data that Dreamhub collects from public sources and third-party sources, including but not limited to, data provided by other Dreamhub customers, including but not limited to, learnings about how different metrics (such as time to close a deal, or deal size) impact overall performance. For the avoidance of doubt, Insights uses only de-identified data that cannot be re-identified back to Customer Data, and the generation of Insights does not combine identifiable Customer Data with other customers’ data.

1.12. “Maximum Number of Authorized Users” means the maximum number of Authorized Users specified on the applicable Order Form.

1.13. “Order Form” means an order that is signed by authorized representatives of both Parties and that sets forth: (i) any applicable Usage Limitations (as defined below); (ii) the applicable Fees; and (iii) other mutually-agreed upon terms and conditions relating to such order. The Parties may subsequently elect to enter into additional Order Forms during the Term of this Agreement.

1.14. “Personal Data” or “Personal Information” shall have the meaning set forth in the DPA.

1.15. “Platform” means our proprietary CRM suite made available as a service (SaaS) platform, and any Updates that Dreamhub makes available to Customer pursuant to this Agreement, together with all Documentation.

1.16. “Professional Services” means customization, development, data migration, integration, testing, conversion, consulting, or other services and deliverables, related to the Platform but not otherwise provided as part of the Platform, as further described in the applicable Statement of Work.

1.17. “Sensitive Information” means credit or debit card numbers; financial account numbers or wire instructions, government issued identification numbers (such as Social Security numbers, passport numbers), biometric information, protected health information, personal information of children protected under any child data protection laws, and any other information or combinations of information that falls within the definition of “special categories of data” under Applicable Law relating to privacy and data protection.

1.18. “Shared Data” means information about your customers including, customer’s email address, phone number, LinkedIn URL, companies where the customer works, title, and role that you or your Authorized Users submit to the Platform and/or provide to Dreamhub through the Platform.

1.19. “Subscription Term” means the duration of the subscription for access to the Platform as set forth in the applicable Order Form.

1.20. “Updates” means any corrections, fixes, patches, workarounds, and minor modifications denominated by version changes to the right of the decimal point (e.g., v3.0 to v3.1) to the Platform that Dreamhub provides to Customer under this Agreement. All version numbers shall be reasonably determined by Dreamhub in accordance with normal industry practice.

1.21. “Upgrades” means any new releases, features or functionalities of the Platform that are not Updates, including new modules.

1.22. “Usage Data” means the data that we collect in connection with our monitoring of the performance and use of the Platform by you and your Authorized Users, including, without limitation, date and time that you access the Platform, the portions of the Platform visited, the frequency and number of times such pages are accessed, the number of times the Platform is used in a given time period, Platform uptime, number of active users, number of successful queries, and other usage and performance data.

2. ORDERS.

The access to the Platform to be made available under this Agreement will be as set forth in one or more Order Forms. Each Order Form is deemed incorporated into and made a part of this Agreement. To the extent any provision set forth in an Order Form conflicts with any provision set forth elsewhere in this Agreement, the provision set forth in this Agreement shall govern, unless such Order Form includes the section numbers of this Agreement that the Parties agree no longer govern or are modified for the matters covered thereby.

3. ACCESS TO THE PLATFORM.

3.1. Right to Access the Platform. Subject to the terms and conditions of this Agreement and the applicable Order Form, we hereby grant you during the Subscription Term a limited, non-exclusive, non-transferable (except as permitted under Section 13.1), non-sublicensable, revocable right and license to permit your Authorized Users (but no more than Maximum Number of Authorized Users) to access and use the Platform, including the Insights made available to you through the Platform solely for your internal business purposes.

3.2. Usage Limitations. The subscription to the Platform will be subject to any usage limitations that are set forth in the applicable Order Form (“Usage Limitations”).

3.3. Modifications. We reserve the right to modify the Platform, from time to time by adding, deleting, or modifying features to improve the user experience or for other business purposes. We further reserve the right to discontinue any feature of the Platform at any time during the Term at our sole and reasonable discretion. Any such modification or discontinuance will not materially decrease the overall functionality of the Platform.

3.4. Beta Features. From time to time, we may invite Customer to try “beta” features or functionalities of the Platform which are not generally available to our customers for use at no charge. Customer may accept or decline any such trial in its sole discretion. Such beta features are for evaluation purposes only and not for use, are not considered part of the Platform under this Agreement, are not supported, and may be subject to additional terms. Unless otherwise expressly agreed to by us, any beta feature trial period will expire upon the date that a version of the beta feature becomes generally available to all of our customers for use or upon the date that we elect to discontinue such beta feature. We may discontinue beta features at any time in our sole discretion and may never make them generally available as part of the Platform. We will have no liability to Customer or any third party for any harm or damage arising out of or in connection with any use of a beta feature, and Customer’s use of any beta feature is at Customer’s own risk.

3.5. Restrictions on Use. You shall not (and shall not authorize, permit, or encourage any third party to): (i) allow anyone other than Authorized Users to use the Platform; (ii) reverse engineer, decompile, disassemble, or otherwise attempt to discern the source code or interface protocols of the Platform; (iii) modify, adapt, or translate the Platform, or any portion or component thereof; (iv) make any copies of the Platform, or any portion or component thereof; (v) resell, distribute, or sublicense the Platform, or any portion or component thereof, or use any of the foregoing for the benefit of anyone other than Customer; (vi) remove or modify any proprietary markings or restrictive legends placed on the Platform; (vii) use the Platform, or any portion or component thereof in violation of any Applicable Law, in order to build a competitive product or service, or for any purpose not specifically permitted in this Agreement; (viii) introduce, post, or upload to the Platform any Harmful Code; (ix) use the Platform in connection with service bureau, timeshare, service provider or like activity whereby you operate the Platform for the benefit of a third party; or (xi) circumvent any processes, procedures, or technologies that we have put in place to safeguard the Platform.

3.6. Documentation. Customer may copy and use (and permit the Authorized Users to copy and use) the Documentation solely in connection with the use of the Platform under this Agreement.

3.7. Onboarding of Authorized Users. Each Authorized User will be required to create an account, which includes a username, a password, and certain additional information, including a valid email address, that will assist in authenticating the Authorized User’s identity when he or she logs into the Software in the future (collectively, “Log-in Credentials”). When creating an account, an Authorized User must provide true, accurate, current, and complete information. You are solely responsible for the confidentiality and use of Authorized Users’ Log-in Credentials, as well as for any use, misuse, or communications entered through the Software. You shall promptly inform us of any need to deactivate a username, password, or other Log-in Credential. We reserve the right to delete or change Authorized Users’ Log-in Credentials at any time and for any reason. We will not be liable for any unauthorized use of an Authorized User’s account.

3.8. Hosting. During the Subscription Term, we, or our contractors, shall host the Platform, such that the Platform is available for use by your Authorized Users. We and/or our contractors shall periodically monitor the Platform to optimize performance, and shall use commercially reasonable efforts to minimize any downtime, other than for scheduled maintenance or downtime caused by reasons beyond our reasonable control, including, but not limited to, acts of God, acts of any governmental body, war, insurrection, sabotage, armed conflict, terrorism, embargo, fire, flood, strike or other labor disturbance, unavailability of or interruption or delay in telecommunications or third-party services, or virus attacks or hackers. We will notify you of any unavailability or other issue with the Platform. You and your Authorized Users will be responsible for obtaining Internet connections and other third-party software and services necessary for them to access the Platform.

3.9. Support Services. Dreamhub shall use commercially reasonable efforts to provide you and your Authorized Users problem resolution and technical support in connection with the Platform during the Subscription Term (the “Support Services”) as more specifically described in the applicable Order Form and our Service Level Agreement, which is attached hereto and incorporated herein as Schedule A.

3.10. Upgrades. From time to time, Dreamhub may release Upgrades to the Platform. All such Upgrades will be available for purchase at additional cost and may be subject to additional terms and conditions. If Customer wishes to purchase any Upgrade, Customer shall notify Dreamhub and the Parties will work together in good faith to negotiate and mutually agrees on the pricing and additional terms and conditions (if any) that will be applicable to such Upgrade.

4. PROFESSIONAL SERVICES.

4.1. Statements of Work. Customer may request Dreamhub to provide Professional Services. All such Professional Services will be covered by one or more statements of work agreed on by the Parties (each, a “Statement of Work”). The work covered by a particular Statement of Work will be referred to in this Agreement as a “Project.” Each Statement of Work will be in writing, signed by an authorized representative of each Party, will reference this Agreement, and will specify for the Project covered by that Statement of Work, without limitation: (i) a description of the Project, including any applicable specifications, milestones, and deliverables to be developed; and (ii) the applicable fees.

4.2. Ownership of Work Product. Unless otherwise set forth in a Statement of Work, Dreamhub shall own all right, title, and interest, including, without limitation, all intellectual property rights, in and to all deliverables, customizations, functionalities, and other work product created by Dreamhub in the performance of the Professional Services (collectively, “Work Product”); provided, however, that upon the full payment of the applicable Professional Services fees, any Work Product shall be considered part of the Platform hereunder and Customer shall have a license thereto as set forth in Section 3.1 subject to the terms and conditions of this Agreement including the restrictions in Section 3.5.

5. DATA.

5.1. Customer Data. Subject to the terms and conditions of this Agreement, Customer hereby grants us a non-exclusive, worldwide, fully paid-up, royalty-free right and license to reproduce, execute, use, store, archive, modify, perform, display, and distribute the Customer Data (i) during the Term for the purpose of providing you access to the Platform, including Insights, Support Services, and Professional Services; and (ii) for Dreamhub’s internal business purposes to service your account. You will have sole responsibility for the accuracy, quality, and legality of your Customer Data.

5.2. Shared Data. Subject to the terms and conditions of this Agreement, Customer hereby grants us a non-exclusive, worldwide, fully paid-up, royalty-free right and license, with the right to grant sublicenses, to share the Shared Data with Dreamhub’s other customers through the Platform, unless Customer has opted-out of sharing its Shared Data as set forth herein. By submitting Shared Data through the Platform, you acknowledge and agree that your Shared Data will be made available through the Platform by Dreamhub to its other customers, unless you opt-out by notifying us in writing at product@dreamhub.ai.

5.3. Usage Data and Insights. Notwithstanding anything to the contrary herein, we may use, and may permit our third-party service providers to access and use the Usage Data and Insights for the purposes of operating, maintaining, managing, and improving our products and services, including the Platform, as well as for training and machine learning, benchmarking, analysis and analytics purposes.

5.4. Data Protection. We (and any third-party hosting provider that we may engage) will employ commercially reasonable physical, administrative, and technical safeguards to secure the Customer Data, from unauthorized use or disclosure. Personal Information shall be processed in accordance with the DPA.

6. INTELLECTUAL PROPERTY.

As between the Parties, all right, title, and interest in and to the Platform, the Insights, and the Usage Data, including all modifications, improvements, adaptations, enhancements, derivatives, or translations made thereto or therefrom, and all intellectual property rights therein, are and will remain the sole and exclusive property of Dreamhub. Subject to Section 5, all right, title, and interest in and to Customer Data, and all intellectual property rights therein, will be and remain Customer’s sole and exclusive property.

7. CONFIDENTIALITY; FEEDBACK.

7.1. Confidentiality Obligations. At all times, the Receiving Party will protect and preserve the Confidential Information of the Disclosing Party as confidential, using no less care than that with which it protects and preserves its own confidential and proprietary information (but in no event less than a reasonable degree of care), and will not use the Confidential Information for any purpose except to perform its obligations and exercise its rights under this Agreement. The Receiving Party may disclose, distribute, or disseminate the Disclosing Party’s Confidential Information to any of its officers, directors, members, managers, partners, employees, contractors, or agents (its “Representatives”), provided that the Receiving Party reasonably believes that its Representatives have a need to know and such Representatives are bound by confidentiality obligations at least as restrictive as those contained herein. The Receiving Party will not disclose, distribute, or disseminate the Confidential Information to any third party, other than its Representatives, without the prior written consent of the Disclosing Party. The Receiving Party will at all times remain responsible for any violations of this Agreement by any of its Representatives. If the Receiving Party is legally compelled to disclose any of the Disclosing Party’s Confidential Information, the Receiving Party will provide the Disclosing Party prompt prior written notice of such requirement so that the Disclosing Party may seek a protective order or other appropriate remedy and/or waive compliance with the terms of this Section. If such protective order or other remedy is not obtained or the Disclosing Party waives compliance with the provisions of this Section, the Receiving Party may furnish only that portion of the Confidential Information which it is advised by its counsel is legally required to be disclosed, and will use its best efforts to insure that confidential treatment will be afforded such disclosed portion of the Confidential Information.

7.2. Feedback. During the Term, you and your Authorized Users may elect to provide us with feedback, comments, and suggestions with respect to the Platform (“Feedback”). Customer agrees that Dreamhub will be free to use, reproduce, disclose, and otherwise exploit any and all such Feedback without compensation or attribution to Customer or any Authorized User.

8. REPRESENTATIONS AND WARRANTIES; OUR DISCLAIMER.

8.1. Representations and Warranties. Each Party represents and warrants to the other Party that: (i) to the extent it is an entity, it is duly organized, validly existing, and in good standing under its jurisdiction of organization and has the right to enter into this Agreement; (ii) the execution, delivery, and performance of this Agreement and the consummation of the transactions contemplated hereby constitute a valid and binding agreement of such Party; (iii) the individual accepting this Agreement on behalf of a legal entity has the authority to bind such entity to this Agreement; (iv) it has the full power, authority, and right to perform its obligations and grant the rights it grants hereunder; and (v) it will perform its obligations under this Agreement in compliance with all Applicable Laws.

8.2. Additional Representations and Warranties of Dreamhub. In addition to the representations and warranties set forth in Section 8.1, Dreamhub represents and warrants that the Professional Services and Support Services shall be performed in a professional and workmanlike manner.

8.3. Representations and Warranties of Customer. In addition to the representations and warranties set forth in Section 8.1, Customer represents and warrants that: (i) Customer has all rights and permissions necessary for Customer to provide Dreamhub with or grant Dreamhub access to and use of all Customer Data; (ii) Customer has obtained all legally-required consents, permissions, and authorizations from each individual whose data, including Personal Information in included in the Customer Data to use such data in the manner contemplated by this Agreement; (iii) Customer has obtained all legally-required consents, permissions, and authorizations in accordance with all Applicable Laws with respect to the Customer Data provided hereunder, and (iv) the collection and provision of Customer Data by Customer and/or its Authorized User, and Dreamhub’s permitted use of the Customer Data does not, and will not, violate any Applicable Law, any right of privacy, personal or proprietary right, or other common law or statutory right of any third party, or any agreement that Customer has with any third party, including but not limited to, any terms of service.

8.4. Our Disclaimer. ALTHOUGH CERTAIN DATA AND MATERIALS THAT MAY BE GENERATED BY THE PLATFORM, INCLUDING BUT NOT LIMITED TO, THE OUTPUT GENERATED THROUGH THE PLATFORM, CAN BE USED AS AN AID TO CUSTOMER AND ITS AUTHORIZED USERS TO MAKE INFORMED BUSINESS DECISIONS, SUCH DATA AND MATERIALS ARE NOT MEANT TO SUBSTITUTE LEGAL OR BUSINESS ADVICE OR CUSTOMER’S OR ANY AUTHORIZED USER’S EXERCISE OF THEIR OWN BUSINESS JUDGMENT. ANY SUCH DECISIONS OR JUDGMENTS ARE MADE AT SUCH PARTY’S SOLE DISCRETION AND ELECTION. YOU ACKNOWLEDGE AND AGREE THAT THE PLATFORM HAS NOT BEEN DESIGNED TO PROCESS OR MANAGE SENSITIVE INFORMATION, AND YOU AND YOUR AUTHORIZED USERS’ AGREE NOT TO USE THE PLATFORM TO COLLECT, MANAGE, OR OTHERWISE PROCESS ANY SENSITIVE INFORMATION. WE WILL NOT HAVE, AND WE SPECIFICALLY DISCLAIM ANY LIABILITY THAT MAY RESULT FROM YOUR OR YOUR AUTHORIZED USER’S USE OF THE PLATFORM TO COLLECT, MANAGE OR OTHERWISE PROCESS SENSITIVE INFORMATION. EXCEPT AS EXPRESSLY SET FORTH IN SECTION 8.1 AND SECTION 8.2, THE PLATFORM, ANY BETA FEATURES, THEIR COMPONENTS, ANY DOCUMENTATION, THE SUPPORT SERVICES, THE PROFESSIONAL SERVICES, AND ANY OTHER MATERIALS AND INFORMATION PROVIDED BY DREAMHUB HEREUNDER ARE PROVIDED “AS IS” AND “AS AVAILABLE,” AND NEITHER DREAMHUB NOR OUR SUPPLIERS OR SERVICE PROVIDERS MAKES ANY REPRESENTATIONS OR WARRANTIES WITH RESPECT TO THE SAME OR OTHERWISE IN CONNECTION WITH THIS AGREEMENT, AND DREAMHUB HEREBY DISCLAIMS ANY AND ALL EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, ANY WARRANTIES OF NON-INFRINGEMENT, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AVAILABILITY, ACCURACY, COMPLETENESS, CURRENTNESS, ERROR-FREE OR UNINTERRUPTED OPERATION, AND ANY WARRANTIES ARISING FROM A COURSE OF DEALING, COURSE OF PERFORMANCE, OR USAGE OF TRADE. DREAMHUB DOES NOT WARRANT, GUARANTEE OR MAKE ANY REPRESENTATION TO CUSTOMER OR ANY AUTHORIZED USER REGARDING THE USE OR PERFORMANCE OF THE PLATFORM, OR ANY COMPONENT THEREOF OR ANY OUTPUT PRODUCED BY THE PLATFORM. DREAMHUB WILL HAVE NO LIABILITY FOR ANY HARM OR DAMAGE ARISING OUT OF OR IN CONNECTION WITH ANY USE OF THE PLATFORM, AND/OR THE OUTPUT PRODUCED BY THE PLATFORM, INCLUDING INSIGHTS. DREAMHUB IS NOT RESPONSIBLE FOR ANY DECISIONS TAKEN BY YOU OR ANY OF YOUR AUTHORIZED USERS BASED ON THE OUTPUT PRODUCED AND/OR MADE AVAILABLE THROUGH THE PLATFORM, INCLUDING INSIGHTS. CUSTOMER AND EACH AUTHORIZED USER AGREES THAT ITS USE OF THE PLATFORM, THE OUTPUT GENERATED THROUGH THE PLATFORM, INCLUDING INSIGHTS OR ANY COMPONENT THEREOF IS ENTIRELY AT ITS OWN RISK. TO THE EXTENT THAT WE MAY NOT AS A MATTER OF APPLICABLE LAW DISCLAIM ANY IMPLIED WARRANTY, THE SCOPE AND DURATION OF SUCH WARRANTY WILL BE THE MINIMUM PERMITTED UNDER SUCH LAW.

9. LIMITATION OF LIABILITY.

9.1. Liability Exclusion. SUBJECT TO SECTION 9.3, NEITHER PARTY WILL BE LIABLE TO THE OTHER PARTY (NOR TO ANY PERSON CLAIMING RIGHTS DERIVED FROM SUCH OTHER PARTY’S RIGHTS) FOR CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES OF ANY KIND (INCLUDING, WITHOUT LIMITATION, LOST REVENUES OR PROFITS, LOSS OF USE, OR LOSS OF GOODWILL OR REPUTATION) WITH RESPECT TO ANY CLAIMS BASED ON CONTRACT, TORT, OR OTHERWISE (INCLUDING NEGLIGENCE AND STRICT LIABILITY) ARISING OUT OF THIS AGREEMENT, REGARDLESS OF WHETHER THE PARTY LIABLE OR ALLEGEDLY LIABLE WAS ADVISED, HAD OTHER REASON TO KNOW, OR IN FACT KNEW OF THE POSSIBILITY THEREOF.

9.2. Limitation of Damages. SUBJECT TO SECTION 9.3, EACH PARTY’S MAXIMUM LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT, REGARDLESS OF THE CAUSE OF ACTION (WHETHER IN CONTRACT, TORT, BREACH OF WARRANTY, OR OTHERWISE), WILL NOT EXCEED THE AGGREGATE AMOUNT OF THE FEES PAID AND PAYABLE TO DREAMHUB BY CUSTOMER DURING THE TWELVE (12) MONTH PERIOD PRECEDING THE DATE ON WHICH THE CLAIM ARISES.

9.3. Exceptions. NOTWITHSTANDING THE FOREGOING: (A) THE EXCLUSIONS AND LIMITATIONS OF LIABILITY SET FORTH IN SECTION 9.1 AND SECTION 9.2 SHALL NOT APPLY TO: (i) A PARTY’S INDEMNIFICATION OBLIGATIONS; (ii) A PARTY’S BREACH OF ITS CONFIDENTIALITY OBLIGATIONS; (iii) A PARTY’S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD; OR (iv) CUSTOMER’S FAILURE TO PAY ANY UNDISPUTED SUMS DUE HEREUNDER OR BREACH OF SECTION 3.5 (RESTRICTIONS ON USE); AND (B) DREAMHUB’S TOTAL AGGREGATE LIABILITY FOR DAMAGES ARISING FROM ITS BREACH OF THE DPA SHALL NOT EXCEED THREE (3) TIMES THE AGGREGATE AMOUNT OF THE FEES PAID AND PAYABLE TO DREAMHUB BY CUSTOMER DURING THE TWELVE (12) MONTH PERIOD PRECEDING THE DATE ON WHICH THE CLAIM ARISES.

10. INDEMNIFICATION.

10.1. Indemnification by Customer. You will indemnify, defend, and hold Dreamhub, our Affiliates, our suppliers and service providers, and our and their respective Representatives harmless from and against any and all damages, liabilities, costs, fines, and expenses (including reasonable attorneys’ fees) (“Losses”) incurred by any of such parties in connection with any third-party action, claim, or proceeding (each, a “Claim”) arising from (i) your or any of your Authorized Users’ gross negligence, willful misconduct, violation of Applicable Law, or breach or violation of Section 8.1 or Section 8.3; or (ii) an allegation that the Customer Data and/or the use thereof in accordance with this Agreement infringes, violates, or misappropriates any third-party intellectual property or privacy rights.

10.2. Indemnification by Dreamhub. Dreamhub will indemnify, defend, and hold Customer and its Representatives harmless from and against any and Losses incurred by any such parties in connection with any Claim (i) arising from Dreamhub’s gross negligence or willful misconduct, or (ii) alleging that the Platform or your use thereof in accordance with this Agreement infringes or misappropriates any third-party intellectual property rights (an “Infringement Claim”). In the event that we reasonably determine that any Platform is likely to be the subject of a third-party Claim, we will have the right (but not the obligation), at our own expense, to: (a) procure for you the right to continue to use the Platform as provided in this Agreement; (b) replace the infringing components of Platform with other components with equivalent functionality; or (c) suitably modify the Platform so that it is non-infringing and functionally equivalent. If none of the foregoing options are available to us on commercially reasonable terms, we may terminate this Agreement and provide you a pro-rata refund of unused portion of any Fees that you have prepaid. Notwithstanding the foregoing, we are not obligated to indemnify, defend, or hold Customer or its Representatives harmless with respect to any Infringement Claim to the extent the Infringement Claim arises from or is based upon (v) your or your Authorized Users’ use of the Platform not in accordance with the Documentation or this Agreement; (w) any unauthorized modifications, alterations, or implementations of the Platform made by or on behalf of Customer (other than by Dreamhub); (x) use of the Platform in combination with unauthorized modules, apparatus, hardware, software, or services not supplied or expressly permitted in writing by us; (y) your or your Authorized User’s failure to implement or use any Updates provided by Dreamhub in a timely manner; or (z) use of the Platform in a manner or for a purpose for which it was not designed. This Section 10.2 states Customer’s sole and exclusive remedy, and our sole and exclusive liability, regarding any Infringement Claim.

10.3. Procedure. The indemnification obligations set forth in Section 10.1 and Section 10.2 are subject to the indemnified Party: (i) promptly notifying the indemnifying Party of the Claim (provided that failure to provide prompt written notice to of such Claim will not alleviate the indemnifying Party of its obligations under this Section 10 to the extent any associated delay does not materially prejudice or impair the defense of the related Claim); (ii) providing the indemnifying Party, at its sole cost and expense, with reasonable cooperation in the defense of the Claim; and (iii) providing the indemnifying Party with sole control over the defense and negotiations for a settlement or compromise of the Claim, provided that the indemnifying Party may not make any admission of liability on behalf of the indemnified Party without the indemnified Party’s approval.

11. FEES AND PAYMENT.

11.1. Fees and Taxes. All Fees are due and payable as set forth below. Fees are in addition to and do not include any federal, provincial, or local sales, PST, GST, HST, VAT, foreign withholding, use, property, excise, service, or similar transaction taxes (“Taxes”) now or hereafter levied, all of which will be for your account. Any applicable direct pay permits or valid tax-exempt certificates must be provided to us prior to the execution of this Agreement. If we are required to collect and remit Taxes on your behalf, we will invoice you for such Taxes, and you will pay us for such Taxes in accordance with Section 11.2. You hereby agree to defend, indemnify, and hold harmless us, our suppliers, our hosting providers, and our and their respective officers, directors, managers, employees, contractors and agents from any and all liabilities, costs, and expenses (including reasonable attorneys’ fees) in connection with any Taxes and related costs, interest, and penalties paid or payable by us on your behalf. For the avoidance of doubt, we will only be responsible for any taxes related to our income, property, franchise, or employees.

11.2. Payments. We will invoice you for the Fees and any applicable Taxes. Except as otherwise set forth in the applicable Order Form, all amounts are due and payable to us within thirty (30) days from your receipt of the invoice without setoff or deduction. All amounts due under this Agreement shall be paid by credit card, ACH or wire transfer, or other payment method agreed to by us in writing. If you choose to pay by credit card, you hereby authorize us to charge your credit card on file for the Fees, Expenses and applicable Taxes in accordance with this Section. You further authorize us to use a third party to process such payments, and hereby consent to the disclosure of your billing information to such third party. You shall promptly provide us with updated credit card information in the event that your credit card on file is no longer valid. If the credit card information on file with us is not valid at any time during the Term, or if your credit card cannot be processed on any payment date, you hereby authorize us to continue to attempt to charge the amounts due until such amounts are paid in full.

11.3. Expenses. You will reimburse us for any reasonable, documented, out-of-pocket expenses (“Expenses”) actually incurred by us in connection with the performance of the Services that you have approved in advance, that are set forth in the applicable Statement of Work.

11.4. Late Payments. In the event that any invoiced amount is not received by us by the due date as set forth in Section 11.2, then without limiting our rights and remedies, we may: (i) charge interest on the outstanding balance (at a rate not to exceed the lesser of one percent (1%) per month or the maximum rate permitted by law); (ii) condition future provision of Platform on payment terms shorter than those specified in Section 11.2; (iii) suspend the access to the Platform pursuant to Section 11.3; and/or (iv) terminate this Agreement in accordance with and pursuant to Section 11.2.

11.5. Non-Refundable. Unless otherwise expressly provided for in this Agreement, all Fees paid under this Agreement are non-refundable. Notwithstanding the foregoing, if you terminate this Agreement pursuant to and in accordance with Section 12.2.1, we shall provide you a pro-rata refund of the unused portion of any Fees that you have prepaid.

11.6. No Contingency for Future Commitments. You agree that payment of the Fees under this Agreement is not contingent on the delivery of any future functionalities, or features, or any other future commitments for the Platform.

12. TERM AND TERMINATION.

12.1. Term. The initial term of this Agreement commences on the Effective Date and continues in full force and effect for one (1) year (the “Initial Term”). Upon expiration of the Initial Term, this Agreement will automatically renew for a successive one (1) year renewal terms (each, a “Renewal Term” and collectively, with the Initial Term, the “Term”), unless either Party notifies the other Party of its intent to not renew at least thirty (30) days prior to the expiration of the then-current Term. The term of each Statement of Work will be for the term set forth therein. The Subscription Term will be set forth in the applicable Order Form.

12.2. Termination.

12.2.1. Either Party may terminate this Agreement, any Order Forms and/or any Statements of Work: (i) upon thirty (30) days’ notice to the other Party if the other Party breaches a material term of this Agreement, any Order Form and/or any Statement of Work, and the breach remains uncured at the expiration of such thirty (30) day period; or (ii) immediately, if the other Party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, liquidation, or assignment for the benefit of creditors.

12.2.2. We may terminate this Agreement upon written notice to you under the limited circumstances set forth in Section 10.2.

12.3. Suspension for Non-Payment. We may suspend your access to the Platform upon written notice to you if any undisputed invoiced amount due to us is past due. We will not suspend your access to the Platform while you are disputing any invoiced amount due to us reasonably and in good faith and are cooperating diligently to resolve the dispute. If your access to the Platform is suspended for non-payment, we may charge a re-activation fee to reinstate the access. You will promptly reimburse us for any reasonable expenses of collection, including costs, disbursements, and reasonable outside legal fees we incur, to the extent necessitated by your refusal to pay any invoiced amounts that you are not disputing in good faith.

12.4. Effect of Termination. Upon termination of this Agreement: (i) we will stop providing the Platform, and you will stop all access to and use of the Platform; (ii) you will promptly pay all unpaid Fees and applicable Taxes due through the end of the Term; (iii) each Party will either return to the Disclosing Party (or, at such Disclosing Party’s instruction, destroy and provide such Disclosing Party with written certification of the destruction of) all documents, computer files, and other materials containing any of such Disclosing Party’s Confidential Information that are in the Receiving Party’s possession or control; and (iv) we shall provide you thirty (30) days to export the Customer Data from the Platform, after which time we shall delete the Customer Data, and upon your request, certify to such destruction.

12.5. Survival. The following provisions will survive termination of this Agreement: Section 1 (“Definitions”), Section 5 (“Customer Data; Shared Data”), Section 6 (“Intellectual Property”), Section 7 (“Confidentiality; Feedback”), Section 8.4 (“Our Disclaimer”), Section 9 (“Limitation of Liability”), Section 10 (“Indemnification”), Section 11 (“Fees and Payment”); Section 12.4 (“Effect of Termination”), this Section 12.5 (“Survival”), and Section 13 (“General Provisions”).

13. GENERAL PROVISIONS.

13.1. Assignment. Neither Party may assign or otherwise transfer any of its rights or obligations under this Agreement without the prior, written consent of the other Party; provided, however, that Dreamhub may, upon written notice to you, assign or otherwise transfer this Agreement: (i) to any of its Affiliates; or (ii) in connection with a change of control transaction (whether by merger, consolidation, sale of equity interests, sale of all or substantially all assets, or otherwise). Any assignment or other transfer in violation of this Section will be null and void. Subject to the foregoing, this Agreement will be binding upon and inure to the benefit of the Parties hereto and their permitted successors and assigns.

13.2. Waiver. No failure or delay by either Party in exercising any right or remedy under this Agreement will operate, or be deemed to operate, as a waiver of any such right or remedy.

13.3. Governing Law and Venue. This Agreement shall be governed by, and construed and enforced in accordance with, the laws of the State of New York, without regard to conflict of law principles. Each Party hereby irrevocably and unconditionally agrees that any legal action or suit related to this Agreement shall be brought exclusively in any state or federal court of competent jurisdiction sitting in the State of New York.

13.4. Notices. All notices that we are required to give you under this Agreement may be given via your dashboard on the Platform, and will be effective as of the date we post such notice. All notices that you are required to give us under this Agreement must be in writing and will be delivered either personally or by e-mail, national overnight courier. Notices from you will be effective upon actual delivery to and receipt by us.

13.5. Independent Contractors. The Parties are independent contractors. Neither Party will be deemed to be an employee, agent, partner, joint venturer, or legal representative of the other Party for any purpose, and neither Party will have any right, power, or authority to obligate the other Party.

13.6. Severability. If any provision of this Agreement is found invalid or unenforceable by a court of competent jurisdiction, that provision will be amended to achieve as nearly as possible the same economic effect as the original provision, and the remainder of this Agreement will remain in full force and effect. Any provision of this Agreement, which is unenforceable in any jurisdiction, will be ineffective only as to that jurisdiction, and only to the extent of such unenforceability, without invalidating the remaining provisions hereof.

13.7. Force Majeure. Neither Party will be deemed to be in breach of this Agreement for any failure or delay in performance to the extent caused by reasons beyond its reasonable control, including, but not limited to, acts of God, acts of any governmental body, war, insurrection, sabotage, armed conflict, terrorism, embargo, fire, flood, strike or other labor disturbance, COVID-19, quarantine restrictions, freight embargoes, unavailability of or interruption or delay in telecommunications or third-party services, or virus attacks or hackers (collectively, “Force Majeure Event”). When such Force Majeure Event arises, either Party shall notify the other immediately in writing of its failure to perform, describing the cause of failure and how it affects performance, and the anticipated duration of the inability to perform. For the avoidance of doubt, nothing in this Section 13.7 shall be construed to excuse any payment obligations hereunder.

13.8. Third-Party Beneficiaries. The Parties agree that there are no third-party beneficiaries under this Agreement.

13.9. Complete Understanding; Amendments. This Agreement, together with the attached Schedules and all executed Order Forms and Statements of Work, constitutes the final and complete agreement between you and us regarding the subject matter hereof, and supersedes any prior or contemporaneous communications, representations, or agreements between us, whether oral or written, including, without limitation, any confidentiality or non-disclosure agreements. Dreamhub may modify this Agreement at any time by posting such modification on the Platform, and any such modification shall go into effect on the Last Updated date set forth in the modified Agreement. It is Customer’s responsibility to check for such modifications.

CUSTOMER ACKNOWLEDGES THAT CUSTOMER HAS READ THIS AGREEMENT, UNDERSTANDS IT, AND AGREES TO BE BOUND BY ITS TERMS AND CONDITIONS.

Schedule A – Service Level Agreement

1. General.

1.1. This Service Level Agreement forms part of the Master SaaS Agreement entered into by the Parties on the Effective Date. Capitalized terms not defined herein shall have the meaning set forth in the Agreement.

2. Purpose.

2.1. This SLA sets out the expectations, support commitments, and service levels necessary to support the delivery of the Company’s Services effectively.

3. Support Services.

3.1. The Company will provide Support Services to assist the Customer in resolving issues related to the use of the Service. Support is available through the following channels:

3.1.1. Email support: support@dreamhub.ai

3.1.2. Via the Company’s website: https://www.dreamhub.ai/support

3.2. Support services are available during the following hours:

3.2.1. Standard support: Monday to Friday, 9:00 – 17:00 EST

3.2.2. Emergency support: 24/7 for critical issues affecting service availability

4. Response and Resolution Times.

4.1. The Company commits to the following response and resolution times based on the severity of the issue:

Severity LevelDescriptionResponse TimeResolution Target
CriticalService is unavailable or severely impacted4 hoursWork continuously until a workaround is available
HighMajor functionality is impaired, but the Service remains available1 business day2 business days
MediumPartial impairment, minor impact on usability1 business dayNot provided
LowGeneral enquiries, minor issues or feature requests1 business dayNot provided

5. Customer Responsibilities.

5.1. To facilitate effective support, the Customer agrees to:

5.1.1. Provide detailed descriptions of the issue, including screenshots or error messages;

5.1.2. Make reasonable efforts to resolve minor issues using provided documentation and FAQs; and

5.1.3. Ensure authorized personnel make support requests.

6. Uptime.

6.1. Dreamhub shall use commercially reasonable efforts designed to ensure that the Platform is available 99.9% of the time measured on a monthly basis using Dreamhub’s availability measurements.

7. Exclusions.

7.1. This SLA does not include:

7.1.1. Issues caused by third-party software or integrations outside the Company’s control;

7.1.2. Problems resulting from the Customer’s improper use of the Service; and

7.1.3. Scheduled maintenance and system updates. The Company will provide the Customer with a notice regarding maintenance and system updates in advance.

Schedule B – Dreamhub Data Processing Agreement

This Dreamhub Data Processing Agreement and its Annexes (“DPA”) is incorporated into and forms part of the Master SaaS Agreement (the “Agreement”) between you (“Customer” “you,” or “your”) and us (“Dreamhub” “we,” “our,” or “us”).

This DPA reflects the parties’ agreement with respect to the Processing of Personal Data by us as a Processor on your behalf. In case of any conflict or inconsistency with the terms of the Agreement, this DPA will take precedence over other terms in the Agreement to the extent of such conflict or inconsistency.

1. Interpretation and Definitions.

1.1. Unless otherwise defined herein, all capitalized words and expressions will have the same meanings assigned in the Agreement. In the event of any conflict or inconsistency between this DPA and the Agreement, the terms of this DPA shall control to the extent of any conflict or inconsistency.

1.2. “Affiliate” means with respect to any entity, any other entity that, directly or indirectly, through one or more intermediaries, controls, is controlled by, or is under common control with, such entity. The term “control” means the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through the ownership of voting securities, by contract, or otherwise.

1.3. “Applicable Data Protection Laws” means, as applicable, (i) State Data Protection Laws; (ii) European Data Protection Laws; and/or (iii) any other laws, rules, and regulations relating to the privacy, security, protection, and/or Processing of Personal Data, in each case as amended, superseded, or replaced.

1.4. “Authorized User” means any natural person that is authorized by Dreamhub and/or a Dreamhub Affiliate to Process Personal Data on Dreamhub’s behalf pursuant to the Agreement and this DPA.

1.5. “Data Subject” means any natural person who can be identified, directly or indirectly, by reference to that person’s Personal Data including, as applicable, “Consumers” as defined under Applicable Data Protection Laws.

1.6. “Data Subject Rights” means certain rights granted to Data Subjects under Applicable Data Protection Laws regarding their own Personal Data.

1.7. “DP Regulator” means any local, state, provincial, national or multinational governmental or supervisory authority or regulatory body with competent jurisdiction to promulgate, administer, and/or enforce Applicable Data Protection Laws.

1.8. “European Data Protection Law(s)” means (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“EU GDPR”); (ii) all laws relating to data protection, the Processing of personal data, privacy and/or electronic communications in force from time to time in the United Kingdom including the U.K. Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003 and the GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 (“UK GDPR”) (collectively with the EU GDPR, the “GDPR”); (iii) the EU e-Privacy Directive (2002/58/EC); (iv) any national data protection laws made under or pursuant to (i), (ii) or (iii); and (iv) the Swiss Federal Data Protection Act (“Swiss DPA”), in each case as superseded, amended or replaced, provided that, in the event of a conflict in the meanings of defined terms in the European Data Protection Laws, the meaning from the law applicable to the location of the relevant Data Subject shall apply.

1.9. “Person” means, as applicable, any natural person, corporation, limited liability company, general partnership, limited partnership, proprietorship, other business organization, trust, union, association, or governmental authority.

1.10. “Personal Data” or “Personal Information” means any information relating to an identified or identifiable natural person, or as otherwise defined in Applicable Data Protection Laws, that is Processed by or on behalf of Dreamhub in connection with the Agreement.

1.11. “Process,” “Processing,” or “Processed” means any operation or set of operations that is or may be performed on Personal Data (whether or not by automated means), or as otherwise defined in Applicable Data Protection Laws.

1.12. “Restricted Transfer” means (i) where the EU GDPR applies, a transfer of Personal Data from the European Economic Area (“EEA”) to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to the UK GDPR; (iii) where the Swiss DPA applies, a transfer of Personal Data from Switzerland to any other country which is not subject to an adequacy decision by the Swiss Federal Data Protection and Information Commissioner; or (iv) as otherwise defined in Applicable Data Protection Laws.

1.13. “Security Incident” or “Data Breach” means any unauthorized or unlawful breach of security leading to, or reasonably believed to have led to, the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Personal Data, or as otherwise defined in Applicable Data Protection Laws.

1.14. “Standard Contractual Clauses” means where the EU GDPR applies, the standard contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (Module II: Controller to Processor), (“EU SCCs”), as supplemented by this DPA.

1.15. “State Data Protection Laws” means, collectively, all U.S. state data protection laws and their implementing regulations, as amended or superseded from time to time, that apply generally to the Processing of Personal Data related to Consumers and/or Households including, but not limited to, the following: (i) California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (California Civil Code §§ 1798.100 to 1798.199) (“CPRA”); (ii) Colorado Privacy Act (Colorado Rev. Stat. §§ 6-1-1301 to 6-1-1313) (“ColoPA”); (iii) Connecticut Personal Data Privacy and Online Monitoring Act (Public Act No. 22-15) (“CPOMA”); (iv) Utah Consumer Privacy Act (Utah Code Ann. §§ 13-61-101 to 13-61-404) (“UCPA”); and Virginia Consumer Data Protection Act (Virginia Code Ann. §§ 59.1-575 to 59.1-585) (“VCDPA”), in each case as superseded, amended, or replaced, provided that, in the event of a conflict or inconsistency in the meanings of defined terms in the State Data Protection Laws, the meaning from the law applicable to the state of residence of the relevant Consumer, or the state where the relevant Household is located, shall apply.

1.16. “Subprocessor” means any Person (including Dreamhub Affiliate(s)) engaged directly or indirectly by Dreamhub to Process any Personal Data relating to the Agreement and this DPA. The term “Subprocessor” shall also include any Person engaged directly or indirectly by a Subprocessor to Process any Personal Data relating to the Agreement and this DPA.

1.17. “Technical and Organizational Security Measures” means measures aimed at safeguarding Personal Data including prevention of Security Incidents, or as otherwise specified in Applicable Data Protection Laws.

1.18. “UK IDT Addendum” means the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version 21, March 2022) laid before Parliament in accordance with s119A of the Data Protection Act 2018, as superseded, amended, or replaced.

1.19. “UK International Data Transfer Agreement” means the International Data Transfer Agreement (Version A1.0, in force 21 March 2022) laid before Parliament in accordance with S119A of the Data Protection Act 2018, as superseded, amended, or replaced.

1.20. The terms Notice of Collection, Business, Service Provider, Contractor, Third Party, Controller, Processor, Sell, and Share (capitalized or lowercase) have the meanings set forth in Applicable Data Protection Laws.

2. Obligations of the Parties.

2.1. Both Parties shall comply with their respective obligations under the Applicable Data Protection Laws, and each Party shall be solely responsible for determining its own legal and regulatory obligations. Customer further acknowledges that Customer is responsible for its secure use of the Services, including securing its account authentication credentials and taking any appropriate steps to backup any Personal Information Processed in connection with the Agreement.

2.2. Each Party shall reasonably cooperate with the other in any activities contemplated by this DPA and to enable each Party to comply with its respective obligations under Applicable Data Protection Laws.

3. Processing Activities.

3.1. The Parties acknowledge and agree that under the Applicable Data Protection Laws, Customer is the Controller or Business, as applicable, and Dreamhub is the Processor, Service Provider or Contractor, as applicable, for purposes of Processing the Personal Data in accordance with the Agreement and this DPA.

3.2. Dreamhub shall Process Personal Data in accordance with the Agreement and this DPA only as a Processor, Service Provider or Contractor as instructed by Customer, and on behalf of Customer. Customer’s instructions for the Processing of Personal Data shall comply with Applicable Data Protection Laws. Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquires Personal Data and provides it to Dreamhub. Annex A to this DPA describes the scope, nature, and purpose of Processing by and on behalf of Dreamhub, the duration of Processing, the types of Personal Data, and the categories of Data Subjects.

3.3. Dreamhub shall not (i) Sell (as defined under Applicable Data Protection Laws) or Share (as defined under the CPRA) Personal Data, (ii) retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing and/or providing the Dreamhub Services specified in the Agreement; (iii) retain, use, or disclose Personal Data outside of the direct business relationship between the Parties; and (iv) combine Personal Data with Personal Data obtained from, or on behalf of, sources other than Customer (unless specific statutory or regulatory exceptions apply to Section 2.3(iv)).

3.4. The Parties acknowledge and agree that the transfer and/or exchange of the Personal Data between the Parties does not form part of any monetary or other valuable consideration exchanged between the Parties with respect to the Agreement or this DPA.

3.5. Notwithstanding any provision to the contrary of the Agreement or this DPA, the terms of this DPA shall not apply to Dreamhub’s Processing of Personal Data that is excluded from the Applicable Data Protection Laws.

3.6. Dreamhub shall promptly notify Customer if it makes a determination that it cannot comply with its obligations under this DPA or Applicable Data Protection Laws, and in such event (and without prejudice to any other rights available to Customer) Dreamhub shall work with Customer and take all reasonable and appropriate steps to stop and remediate (if remediable) any Processing until such time as the Processing complies with such requirements. Dreamhub shall immediately cease (and instruct all Subprocessors to cease) Processing Personal Data if Customer determines that Dreamhub has not or cannot correct any such non-compliance within a reasonable time frame.

4. Technological and Organizational Security Measures.

4.1. Dreamhub shall ensure that any Authorized Person with access to the Personal Data Processed by Dreamhub for Customer is subject to a strict duty of confidentiality (contractual, statutory or otherwise) and that they Process the Personal Data only for the purpose of delivering the Services to Customer and/or its Affiliates under the Agreement and this DPA, and any third party as agreed therein.

4.2. Dreamhub will implement and maintain appropriate Technical and Organizational Security Measures to safeguard and preserve the security, integrity, and confidentiality of Personal Data and protect the Personal Data from Security Incidents in accordance with Applicable Data Protection Laws. At a minimum, Dreamhub agrees to comply with the security measures identified in Annex B. Customer acknowledges that the security measures are subject to technical progress and development and that Dreamhub may update or modify the security measures from time to time, provided that such updates and modifications do not materially degrade or diminish the overall security of the Platform.

5. Cooperation.

5.1. Dreamhub shall cooperate with Customer at Customer’s expense to enable Customer to respond to any requests, complaints or other communications from Data Subjects, DP Regulators, or judicial bodies relating to the Processing of Personal Data under the Agreement, including Data Subject Requests. If any such request, complaint or communication is made directly to Dreamhub, Dreamhub shall promptly notify Customer, providing a copy of the relevant communication, and shall not respond to such communication without Customer’s prior express written authorization unless required to do so under applicable law.

5.2. If Dreamhub receives a subpoena, court order, warrant or other legal demand from a third party (including law enforcement or other public or judicial authorities) seeking the disclosure of Personal Data, Dreamhub shall not disclose any information but shall promptly notify Customer in writing of such request, providing a copy of the relevant communication, and reasonably cooperate with Customer if it wishes to limit, challenge or protect against such disclosure, to the extent permitted by applicable laws.

5.3. To the extent Dreamhub is required under Applicable Data Protection Laws, Dreamhub will assist Customer at Customer’s expense to conduct a data protection impact assessment or equivalent and, where legally required, consult with applicable DR Regulators in respect of any proposed or modified Processing activity that presents a high risk to Data Subjects or requires such an assessment under Applicable Data Protection Laws.

6. Subprocessors.

6.1. Customer agrees that Dreamhub may engage Subprocessors to Process Personal Data on behalf of Customer. Customer provides general authorization to Dreamhub’s use of the Subprocessors listed in Annex C. Dreamhub will notify Customer at least fifteen (15) days prior to engagement of any new Subprocessor. If Customer objects to the engagement of a new Subprocessor within fifteen (15) days of Customer’s notification on reasonable grounds relating to the protection of Personal Data, the Parties will discuss Customer’s concerns in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, Dreamhub will, at Dreamhub’s sole discretion, either not appoint the new Sub-Processor, or permit Customer to suspend or terminate the affected services in accordance with the termination provisions of the Agreement without liability to either party (but without prejudice to any fees owed to Dreamhub prior to suspension or termination).

6.2. For each Subprocessor engaged by Dreamhub, Dreamhub will impose data protection terms on the Subprocessors that provide at least the same level of protection for Personal Data as those in this DPA, to the extent applicable to the nature of the services provided by such Subprocessor. Dreamhub will remain fully liable for any breach of this DPA or the Agreement that is caused by an act, error or omission of such Subprocessor.

7. Security Incidents.

7.1. Dreamhub shall notify Customer without undue delay after becoming aware of a Security Incident and will provide information relating to the Security Incident as it becomes known to Dreamhub. At Customer’s written request, Dreamhub will promptly provide Customer with such reasonable assistance as necessary to enable Customer to notify relevant Security Incident to competent authorities and/or affected Data Subjects, if Customer is required to do so under Applicable Data Protection Laws.

8. Jurisdiction Specific Terms for Personal Data subject to European Data Protection Laws.

8.1. To the extent that Personal Data is subject to European Data Protection Laws, the terms in this Section 8 shall apply in addition to the terms in the remainder of this DPA. In the event of any conflict or ambiguity between the terms in this Section 8 and any other terms in this DPA, the terms in this Section 8 shall take precedence but only to the extent they apply to the Personal Data in question.

8.2. Dreamhub shall notify Customer in writing, unless prohibited from doing so under Applicable Data Protection Laws, if it becomes aware or believes that any Processing instructions from Customer violate European Data Protection Laws.

8.3. The Parties agree that when the transfer of Personal Data from Customer (as “data exporter”) to Dreamhub (as “data importer”) is a Restricted Transfer, the Standard Contractual Clauses shall automatically be deemed incorporated into and form a part of this DPA, as follows:

8.3.1. in relation to Personal Data protected by the GDPR, the SCCs shall apply completed as follows: (i) Module Two (Controller to Processor) or Module Three (Processor to Processor) will apply, as appropriate; (ii) in Clause 7, the optional docking clause will not apply; (iii) in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Section 6.1; (iv) in Clause 11, the optional language will not apply; (v) in Clause 17, Option 1 will apply, and the SCCs will be governed by the laws of Ireland; (vi) in Clause 18(b), disputes shall be resolved before the courts of the EU Member State selected above; (vii) Annex I of the SCCs shall be deemed completed with the information set out in Annex I to this DPA; and (viii) Annex II of the SCCs shall be deemed completed with the information set out in Annex II to this DPA;

8.3.2. in relation to Personal Data protected by UK Data Protection Laws, the SCCs as implemented under sub-paragraph (a) above will apply with the following modifications: (i) the SCCs shall be deemed amended as specified by Part 2 of the UK Addendum; (ii) tables 1 to 3 in Part 1 of the UK Addendum shall be deemed completed respectively with the information set out in Annexes I and II and Section 4.1 of this DPA (as applicable); and (iii) table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting “neither party”.

8.3.3. in relation to Personal Data protected by the Swiss FADP, the SCCs will also apply in accordance with sub-paragraph (a) above with the following modifications: (i) references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss FADP; (ii) references to specific Articles of “Regulation (EU) 2016/679” shall be replaced with the equivalent article or section of the Swiss FADP; (iii) references to “EU”, “Union”, “Member State” and “Member State law” shall be replaced with references to “Switzerland” or “Swiss law”; (iv) the term “member state” shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., Switzerland); (v) Clause 13(a) and Part C of Annex I are not used and the “competent supervisory authority” is the Swiss Federal Data Protection Information Commissioner; (vi) references to the “competent supervisory authority” and “competent courts” shall be replaced with references to the “Swiss Federal Data Protection Information Commissioner” and “applicable courts of Switzerland”; (vii) in Clause 17, the Standard Contractual Clauses shall be governed by the laws of Switzerland; (viii) Clause 18(b) shall state that disputes shall be resolved before the applicable courts of Switzerland; and (ix) the SCCs shall also protect the data of legal entities until the entry into force of the revised Swiss Federal Data Protection Act.

8.3.4. It is not the intention of either Party to contradict or restrict any of the provisions set forth in the Standard Contractual Clauses and, accordingly, if and to the extent the SCCs conflict with any provision of the Agreement (including this DPA) the SCCs shall prevail to the extent of such conflict.

8.4. Transfer Arrangements. To the extent Dreamhub adopts an alternative lawful data export mechanism for the transfer of Personal Data not described in this DPA (“Alternative Transfer Mechanism”), the Alternative Transfer Mechanism shall, upon notice to Customer, apply instead of any applicable transfer mechanism described in this DPA (but only to the extent such Alternative Transfer Mechanism complies with European Data Protection Laws and extends to the territories to which Customer Personal Information is transferred) and Customer agrees to execute such other and further documents and take such other and further actions as may be reasonably necessary to give legal effect such Alternative Transfer Mechanism.

9. Audits.

9.1. Dreamhub shall provide Customer (on a confidential basis) with written responses (which may include summaries/extracts of audit reports or independent assessments) to all reasonable requests made by Customer for information relating to Dreamhub’s Processing of Personal Data that are necessary to (i) confirm Dreamhub’s compliance with this DPA; and/or (ii) required of Customer under Applicable Data Protection Law. Customer shall not exercise this right more than once per calendar year or when Customer is expressly requested or required to provide this information to a supervisory authority, or Dreamhub has experienced a Security Incident, or on another reasonably similar basis. Notwithstanding anything to the contrary set forth herein, Customer’s audit rights under this DPA shall be deemed fulfilled through the provision of an annual SOC 2 Type II report, except in cases where there is a reasonable suspicion of a breach of this DPA. Nothing herein shall be construed to require Dreamhub to provide: (i) trade secrets or any proprietary information; (ii) any information that would violate Dreamhub’s confidentiality obligations, contractual obligations, or applicable laws; or (iii) any information, the disclosure of which could threaten, compromise, or otherwise put at risk the security, confidentiality, or integrity of Dreamhub’s infrastructure, networks, systems, or data.

10. Effect of Termination.

10.1. This DPA shall (i) commence on the Effective Date and remain in effect until no Personal Data remains in the possession or control of Dreamhub, its Affiliates, or any Subprocessor; and (ii) survive expiration or termination (for any reason) of the Agreement. The termination or expiry of any Processing of Personal Data by Dreamhub, its Affiliates or any Subprocessor shall be without prejudice to any accrued rights or remedies of either Party under this DPA at the time of such termination or expiration.

10.2. At Customer’s direction upon termination or expiration of the Agreement or this DPA (in each case, for any reason), Dreamhub shall destroy or return to Customer all Personal Data (including copies) in its possession or control (including any Personal Data Processed by its Affiliates or Subprocessors). This requirement shall not apply to the extent that (i) Dreamhub is required by any applicable law to retain some or all of the Personal Data, and/or (ii) electronic copies of Personal Data are stored in automated backups or archives; in which event Dreamhub shall isolate and protect the Personal Data using the Technological and Organizational Security Measures required by this DPA and not Process the Personal Data except to the extent required by such applicable law.

11. General.

11.1. Any claim or remedy Customer or its Affiliates may have against Dreamhub and its Affiliates and their respective employees, agents and Sub-processors, arising under or in connection with this DPA (including the Standard Contractual Clauses), whether in contract, tort (including negligence) or under any other theory of liability, shall be subject to the limitations and exclusions of liability in the Agreement. Accordingly, any reference in the Agreement to the liability of a Party means the aggregate liability of that Party and all of its Affiliates under and in connection with the Agreement and this DPA together.

11.2. If any part of this DPA is held unenforceable, the validity of all remaining parts will not be affected. This DPA may not be modified except by a subsequent written instrument signed by both Parties.

11.3. To the extent required by Applicable Data Protection Laws, this DPA shall be governed by the law of the applicable jurisdiction. In all other cases, this DPA shall be governed by the law of the same jurisdiction as the Agreement.

11.4. This DPA (including Terms and Conditions, Appendices, and Annexes, each hereby incorporated by reference) is the entire agreement of the Parties with respect to its subject matter.

Annex A – Details of the Processing.

A. List of Parties.

Data Controller: The entity identified as the “Customer” in the Agreement. Address: Customer address as specified in the applicable Agreement. Contact person’s name, position and contact details: The contact details associated with Customer’s account, or otherwise specified in the Agreement.

Data Processor: Dreamhub Inc.. Address: Dreamhub address as set out in the Agreement. Contact person’s name, position and contact details: The contact details associated with Dreamhub’s account, or otherwise specified in the Agreement.

B. Description of Processing.

Categories of Data Subjects whose personal data is transferred: End users of customer organizations (sales representatives, account executives, customer success managers), CRM contacts and leads (prospective and existing customers of Dreamhub’s clients).

Categories of personal data transferred: Contact information (names, email addresses, phone numbers, business addresses), professional information (job titles, company names, industry, department), CRM interaction data (notes, call logs, email correspondence, meeting records, deal stages, pipeline data), user activity data (login timestamps, feature usage, IP addresses), account configuration data.

Sensitive data transferred (if applicable): None deliberately collected or processed. Business contact information may occasionally include personal phone numbers or email addresses. Access restricted to authorized personnel via role-based access control (RBAC). All data encrypted at rest (AES-256) and in transit (TLS 1.3). Audit logs maintained for all data access. SOC 2 Type II audit and certification completed.

The frequency of the transfer: Continuous basis – data is transferred and processed during ongoing use of the Dreamhub CRM platform, including real-time synchronization, API integrations with customer systems, and AI-powered CRM features.

Nature of the processing: The Personal Data Processed by Dreamhub and/or its Subprocessors will be subject to the Processing activities described in the Agreement for the purpose of providing the Platform. Personal Data may be Processed only to comply with Customer’s instructions issued in accordance with the DPA.

Purpose(s) of the data transfer and further processing: The purpose of the data Processing under this DPA is the provision of the Platform by Dreamhub to Customer as set out in the Agreement.

The period for which the personal data will be retained: The duration of the data Processing under this DPA is until the termination or expiration of the Agreement in accordance with its terms.

Annex B – Technical and Organizational Security Measures.

Dreamhub implements comprehensive technical and organizational security measures to protect Personal Data in accordance with industry standards and applicable data protection laws. These measures are continuously monitored, tested, and updated to address evolving security threats.

1. Infrastructure Security.

1.1. Cloud Infrastructure. Google Cloud Platform (GCP) infrastructure in EU and US regions with ISO 27001, SOC 2, and SOC 3 certifications; Google Kubernetes Engine (GKE) Autopilot clusters with automated security patching and updates; private GKE clusters with private nodes (no public IP addresses assigned to cluster nodes); network isolation using Virtual Private Cloud (VPC) with dedicated subnets per environment; Cloud NAT for controlled egress traffic from private clusters.

1.2. Network Security. Private cluster configuration with private nodes enabled; master control plane restricted to private IP ranges only; network segmentation with dedicated IP ranges for pods and services; ingress traffic managed through GCP Gateway API; TLS 1.3 encryption for all data in transit; DDoS protection via GCP Cloud Armor.

1.3. Database Security. Google Cloud Spanner as primary database with automatic encryption at rest using AES-256; automated backup and restore capabilities for disaster recovery; database access restricted to service accounts with least-privilege IAM roles; regional database replication for high availability.

2. Access Control and Authentication.

2.1. Identity and Access Management. Role-Based Access Control (RBAC) implemented via GCP IAM and Kubernetes RBAC; Workload Identity enabled for secure service account authentication; service account separation by function; principle of least privilege enforced.

2.2. Secrets Management. External Secrets Operator (ESO) for centralized secrets management; all secrets stored in Google Secret Manager with encryption at rest; secrets access logged and audited; no secrets stored in application code or container images; automatic secret rotation capabilities.

2.3. Authentication. Multi-factor authentication (MFA) enforced for all users; OAuth 2.0 and OpenID Connect protocols for user authentication; session management with secure token generation and validation; automated session timeout policies.

3. Data Security.

3.1. Encryption. Data at rest: AES-256 encryption via Google-managed or customer-managed encryption keys; data in transit: TLS 1.3 for all API communications and inter-service communication; database encryption: Google Cloud Spanner automatic encryption at rest; Kubernetes secrets encrypted using Google KMS.

3.2. Data Isolation. Multi-tenant architecture with strict logical data separation per customer tenant; tenant ID filtering enforced at application and database query level; row-level security controls prevent cross-tenant data access.

4. Monitoring and Logging.

4.1. Security Monitoring. GKE Security Posture with vulnerability scanning; real-time security monitoring via Sentry for application errors and anomalies; Cloud Monitoring with Managed Prometheus for infrastructure metrics; continuous monitoring of system components, pods, deployments, statefulsets, storage, HPA, Kubelet, and cAdvisor; uptime monitoring with automated alerts for service availability.

4.2. Audit Logging. Comprehensive audit logs for all data access and administrative actions; GCP Cloud Audit Logs for infrastructure changes; Kubernetes audit logging for cluster operations; centralized log aggregation and retention; log analysis for security incident detection.

4.3. Alerting. Automated alerting to operations team for security incidents; error rate monitoring with threshold-based notifications; container restart alerts for potential security or stability issues; uptime check failures trigger immediate notifications.

5. Vulnerability Management.

5.1. Patch Management. GKE Autopilot automatic security patching and node upgrades; STABLE release channel for cluster updates with proven security patches; container image vulnerability scanning via GCP Artifact Registry; regular dependency updates managed via Poetry for Python packages; automated security updates during maintenance windows (weekends, excluding peak hours).

5.2. Security Testing. Regular vulnerability assessments; dependency scanning for known CVEs; container image security analysis; penetration testing as part of SOC 2 Type II audit preparation.

6. Incident Response.

6.1. Security Incident Management. Defined incident response procedures and escalation paths; security incident logging and tracking via Sentry; automated alerting for critical security events; 24/7 monitoring for security incidents; post-incident analysis and remediation tracking.

6.2. Disaster Recovery. Automated database backups with point-in-time recovery (Google Cloud Spanner); scheduled Spanner backup and restore capabilities; Infrastructure as Code (Terraform) for rapid environment reconstruction; GitOps deployment model (ArgoCD) for consistent application state recovery; multi-region deployment capabilities for business continuity.

7. Application Security.

7.1. Secure Development Practices. Code review requirements enforced via GitHub branch protection; security-focused code review processes; separation of development, staging, and production environments; Infrastructure as Code (Terraform/Terragrunt) for consistent and auditable deployments; GitOps deployment workflow via ArgoCD with self-healing disabled during SOC 2 audit preparation.

7.2. API Security. Rate limiting on all public APIs; input validation and sanitization; OWASP Top 10 security controls implemented; API authentication and authorization via OAuth 2.0.

8. Physical and Environmental Security. All physical infrastructure is managed by Google Cloud Platform data centers, which maintain: ISO 27001, SOC 2, and SOC 3 certifications; 24/7 physical security with biometric access controls; redundant power and cooling systems; fire suppression and environmental monitoring; geographic distribution across multiple data centers for resilience.

9. Organizational Security Measures.

9.1. Personnel Security. Security awareness training for all personnel; confidentiality agreements and NDAs for all staff and contractors; defined access provisioning and de-provisioning procedures; principle of least privilege applied to all human access.

9.2. Vendor Management. Security assessments of all sub-processors; Data Processing Agreements with all sub-processors; regular review of sub-processor security practices; sub-processor change notification process.

9.3. Compliance and Audit. SOC 2 Type II audit and certification completed; regular internal security assessments; third-party security audits; compliance monitoring and reporting; annual security control reviews.

10. Data Retention and Disposal. Data retention policies aligned with customer agreements and legal requirements; secure data deletion procedures using cryptographic erasure; automated backup retention with configurable retention periods; secure disposal of physical media by GCP data centers; certificate of destruction available upon customer request.

11. Business Continuity. High-availability architecture with automatic failover; Vertical Pod Autoscaling for resource optimization; global and regional load balancing; regular disaster recovery testing; defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO); cost management and monitoring to ensure sustainable operations.

Updates to these measures: Dreamhub reserves the right to update these security measures to maintain alignment with industry best practices and evolving threats, provided such updates do not materially degrade the overall level of security.

Annex C – List of Dreamhub’s Subprocessors.

NameNature of ProcessingTerritory(ies)
AmpersandData synchronization servicesEU, US
AnthropicAI-powered CRM features and language model processingEU, US
FronteggAuthentication and user management servicesEU
GCP (Google Cloud Platform)Cloud infrastructure and data hosting, AI-powered featuresEU, US
Google AnalyticsWebsite analytics and visitor tracking (marketing website only)US
OpenAIAI-powered CRM features and language model processingUS
PendoProduct analytics and in-app user behavior trackingEU
Recall.aiMeeting note-taking serviceEU
SentryError monitoring, performance tracking, and application observabilityEU
ZoomVideo conferencing and collaboration platformUS

The CRM that changes everything for B2B software

Trial Dreamhub alongside your current CRM, risk-free.