Legal

Data Processing Addendum

Last updated 15 September 2026

Quilt AI Pte. Ltd. · Version 1.0 · 15 September 2026

This Data Processing Addendum (DPA) forms part of, and is incorporated by reference into, the Terms of Service published at quilt.ai/terms-of-service (the Terms) between Quilt AI Pte. Ltd. and the customer identified in those Terms. It applies from the Start Date and for as long as we process Customer Personal Data.

Capitalised terms not defined here have the meaning given in the Terms.

01Definitions

Controller, Processor, Data Subject, Personal Data Breach, Processing and Supervisory Authority have the meanings given in the GDPR, and cognate terms are construed accordingly.

Customer Personal Data: Personal Data contained in the Data, and Usage Information to the extent that it identifies an individual. It does not include the account, billing and contact data that we collect and use as controller, or publicly sourced data that we collect on our own account; our processing of those is described in the Privacy Notice.

Data Intermediary has the meaning given in section 2(1) of the PDPA.

Data Protection Law: whichever of the following applies to a party's processing of Customer Personal Data — the PDPA; the GDPR; the UK GDPR together with the Data Protection Act 2018; the Swiss Federal Act on Data Protection; and any other data protection or privacy law applicable to that party.

GDPR: Regulation (EU) 2016/679.

PDPA: the Personal Data Protection Act 2012 of Singapore, as amended.

Restricted Transfer: a transfer of Customer Personal Data that is subject to a restriction or condition on transfers to a third country under Data Protection Law.

SCCs: the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

Special Category Data: Personal Data of the kinds described in Articles 9(1) and 10 of the GDPR.

Sub-processor: a third party engaged by us to process Customer Personal Data, including a Model Provider.

UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

we, us, our: Quilt AI Pte. Ltd. (UEN 201802722N), 101 Telok Ayer Street #03-06, Singapore 068574.

you, your: the customer under the Terms.

02Scope, Roles and Precedence

2.1 Roles. In respect of Customer Personal Data:

(a)you are the Controller and we are the Processor for the purposes of the GDPR, the UK GDPR and the Swiss FADP; and

(b)you are the organisation on whose behalf the data is processed and we are the Data Intermediary for the purposes of the PDPA.

Where you are yourself a processor acting on behalf of a third-party controller, you warrant that you are authorised by that controller to enter into this DPA and to give the instructions in Clause 3, and references to you as Controller are to be read accordingly.

2.2 Written contract. This DPA is the written contract required by section 4(2) of the PDPA and the contract required by Article 28(3) of the GDPR.

2.3 Precedence. Where there is a conflict in respect of Customer Personal Data, the following order applies: (a) the SCCs and, where applicable, the UK Addendum; (b) this DPA; (c) any Software Subscription Agreement; (d) the Terms. In all other respects the order of precedence in Clause 1.3 of the Terms applies.

2.4 What this DPA does not displace. The commitments in Clause 6.3 of the Terms (no training), Clause 7.1 (security measures) and Clause 7.3 (Security Incident notification) apply to all Data, whether or not it is Personal Data. Nothing in this DPA narrows them.

03Processing of Customer Personal Data

3.1 Documented instructions. We will process Customer Personal Data only on your documented instructions, including in relation to transfers to a third country, unless required to do so by a law to which we are subject. Where such a law applies, we will inform you of that requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.

3.2 What your instructions are. Your documented instructions consist of:

(a)the Terms, this DPA and any Software Subscription Agreement;

(b)your use of the Services and that of your Permitted Users, including the Pipelines you launch and the instructions you or your automated agents issue through the API or MCP;

(c)the purposes set out in Clause 6.2(a) of the Terms and, in relation to Usage Information, the purposes set out in Clause 6.5(a) of the Terms; and

(d)any further written instruction you give us that we agree to in writing.

3.3 Unlawful instructions. We will inform you if, in our opinion, an instruction infringes Data Protection Law. We may suspend performance of that instruction until it is withdrawn, amended or confirmed. We are not obliged to give legal advice and this Clause does not make us responsible for assessing the lawfulness of your processing.

3.4 Your obligations. You warrant and undertake that:

(a)you have a lawful basis for the processing you instruct, and have given all notices and obtained all consents and authorisations required for us and our Sub-processors to process Customer Personal Data as contemplated by the Terms and this DPA;

(b)your instructions comply with Data Protection Law, and the Customer Personal Data has been collected in accordance with it;

(c)you will not submit to the Services any Special Category Data, or Personal Data of a child, unless we have agreed in writing in advance and the additional measures we specify are in place; and

(d)you are responsible for the accuracy, quality and legality of the Customer Personal Data and for the means by which you acquired it.

3.5 Purpose limitation. We will not process Customer Personal Data for our own purposes, and in particular will not use it to train, fine-tune or retrain any Model. Clause 6.3 of the Terms governs, and this Clause does not limit it. Our rights in Analytical Data under Clause 6.5 of the Terms are subject to Clause 6.5(e) and (f) of the Terms.

04Confidentiality of Personnel

4.1 We will ensure that each person we authorise to process Customer Personal Data is subject to an appropriate statutory or contractual obligation of confidentiality that survives the end of their engagement.

4.2 We will limit access to Customer Personal Data to those personnel who need it to perform the purposes in Clause 3.2, and will subject that access to authentication and authorisation controls.

4.3 We will ensure that personnel processing Customer Personal Data receive appropriate data protection and security awareness training.

05Security

5.1 We will implement and maintain the technical and organisational measures required by Article 32 of the GDPR and section 24 of the PDPA. Clause 7.1 of the Terms applies, and the measures in force as at the date of this DPA are described in Annex 2.

5.2 We may update those measures as technology and risk evolve, provided that we do not materially reduce the overall level of security during your subscription term. The current description is published in our trust centre at trustcenter.quilt.ai.

5.3 You are responsible for the security of the environments from which you access the Services, for the configuration of any identity provider you connect, for the roles and entitlements you grant, and for the safekeeping of your credentials and API Keys under Clauses 4.3(d) and 4.4(b) of the Terms.

06Sub-processors

6.1 General authorisation. You give us a general written authorisation to engage Sub-processors to process Customer Personal Data.

6.2 Current Sub-processors. The Sub-processors and Model Providers engaged as at the date of this DPA are published at trustcenter.quilt.ai, with the processing location and the purpose for each. Annex 3 describes the categories.

6.3 Changes. We will give at least thirty (30) days' notice before adding or replacing a Sub-processor that processes Customer Personal Data. Notice is given by updating the published list and, where you have subscribed to notifications of changes to it, by email.

6.4 Objection. You may object to an addition or replacement on reasonable data protection grounds by notice within that thirty (30) day period. If you do, we will work with you in good faith to make available a means of avoiding the processing by the objected-to Sub-processor. If no such means can reasonably be made available within a further thirty (30) days, you may terminate the affected Services on notice and we will refund a pro-rata portion of any Fees prepaid for the period after termination. That is your sole remedy for an objection under this Clause.

6.5 Flow-down. We will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, including the obligations in Clauses 3.5, 4 and 5 to the extent relevant to the processing the Sub-processor performs.

6.6 Our responsibility. We remain fully liable to you for the performance of each Sub-processor's data protection obligations.

07Data Subject Rights

7.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights under Data Protection Law.

7.2 Where the Services provide a function by which you can access, correct, export or delete Customer Personal Data yourself, that function is our primary means of assistance and you will use it before asking us to act.

7.3 If we receive a request from a Data Subject that relates to Customer Personal Data, we will not respond to it substantively, except to acknowledge receipt and to direct the Data Subject to you. We will notify you of the request without undue delay, unless prohibited by law.

7.4 Assistance that goes beyond the functions of the Services and beyond what is proportionate to the request may be charged at our reasonable rates, notified to you in advance.

08Assistance with Your Obligations

8.1 Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you in relation to your obligations under Articles 32 to 36 of the GDPR, including in relation to security of processing, notification of a Personal Data Breach to a Supervisory Authority and to Data Subjects, data protection impact assessments, and prior consultation with a Supervisory Authority.

8.2 Our assistance under Clause 8.1 consists in the first instance of the materials described in Clause 7.2(a) of the Terms, our trust centre disclosures, this DPA and its Annexes. Where those do not reasonably answer your question, Clause 11 applies.

8.3 We will notify you without undue delay if we receive a legally binding request from a public authority for disclosure of Customer Personal Data, unless we are prohibited from doing so by law. Where we are prohibited, we will use reasonable efforts to obtain a waiver of the prohibition and to challenge the request where there are reasonable grounds to consider it unlawful.

09Personal Data Breach

9.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event within seventy-two (72) hours. Clause 7.3 of the Terms applies to the content of the notification, to phased notification and to our cooperation, and applies whether or not the Data affected is Personal Data.

9.2 For the purposes of section 26C of the PDPA, notification under Clause 9.1 is the notification we are required to give you as Data Intermediary, and we will give it without undue delay from the time we have credible grounds to believe that a data breach has occurred.

9.3 You are responsible for determining whether a Personal Data Breach is notifiable to a Supervisory Authority, to the Personal Data Protection Commission or to Data Subjects, and for making any such notification. We will not make a notification on your behalf or naming you without your prior written agreement, unless required to do so by law.

9.4 Notification is not an acknowledgement of fault or liability.

10Deletion and Return

10.1 At the end of the provision of the Services, we will, at your choice, delete or return all Customer Personal Data. Clause 13.4(e) of the Terms governs the mechanism and the one (1) month window in which you may make that choice.

10.2 If you make no election within that period, we will delete Customer Personal Data in accordance with our published retention periods.

10.3 Clause 10.1 does not apply to the extent that we are required by a law to which we are subject to retain Customer Personal Data. Where that applies, we will inform you of the requirement, retain only what the law requires, and continue to protect it in accordance with Clause 5 for as long as we hold it.

10.4 A copy of Customer Personal Data may persist in a routine backup until that backup expires in accordance with our published retention periods, and may be held by a Sub-processor under its own retention period. Clause 6.2(b) of the Terms governs the licence over any such copy. Provider-side retention periods are stated in our trust centre.

11Information and Audit

11.1 We will make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR and with this DPA. In the first instance that information consists of the materials described in Clause 7.2(a) of the Terms — our then-current independent third party audit or attestation report on the Services, if one exists, a completed copy of our standard security questionnaire, and our then-current trust centre disclosures — which we will provide on request and no more than once in any twelve (12) month period.

11.2 Where the materials in Clause 11.1 do not reasonably answer your question, you may, on at least thirty (30) days' written notice, audit our compliance with this DPA and the Terms in relation to Customer Personal Data. Any such audit:

(a)may be conducted no more than once in any twelve (12) month period, except following a Personal Data Breach affecting Customer Personal Data or where a Supervisory Authority with jurisdiction over you requires it;

(b)must be conducted during our normal business hours, in a manner that does not unreasonably disrupt our operations, and must not extend to the data, systems or premises of any other customer;

(c)may be conducted by you or by an independent auditor appointed by you, provided that the auditor is not one of our competitors and is bound by confidentiality obligations no less protective than Clause 10 of the Terms;

(d)is at your cost, save that where the audit identifies a material breach by us of this DPA or the Terms, we will bear our own costs and reimburse your reasonable costs of the audit; and

(e)is subject to Clause 10 of the Terms, and its findings are our Confidential Information.

11.3 We will remediate any material non-conformity identified by an audit within a reasonable period, and will report progress to you.

11.4 Clause 11.2 applies to an audit or inspection conducted by a Supervisory Authority as it applies to an audit conducted by you, save that Clause 11.2(a) and 11.2(d) do not apply.

12International Transfers

12.1 Where we process. We are established in Singapore. Customer Personal Data is stored on infrastructure located in Singapore. Model inference and certain support, monitoring and content acquisition functions are performed outside Singapore, including in the United States, the United Kingdom, India and any other jurisdiction in which a Sub-processor operates. The processing location for each Sub-processor is stated in our trust centre.

12.2 EEA transfers. Where a Restricted Transfer is made from the European Economic Area, the SCCs apply and are incorporated into this DPA, as follows:

(a)Module Two (controller to processor) applies where you are a Controller, and Module Three (processor to processor) applies where you are a processor acting on behalf of a third-party controller;

(b)you are the data exporter and we are the data importer;

(c)in Clause 7, the optional docking clause applies;

(d)in Clause 9, Option 2 (general written authorisation) applies, with the notice period stated in Clause 6.3 of this DPA;

(e)in Clause 11, the optional independent dispute resolution paragraph does not apply;

(f)in Clause 17, Option 1 applies and the governing law is the law of Ireland;

(g)in Clause 18(b), the courts of Ireland are the chosen forum;

(h)Annex I to the SCCs is Annex 1 to this DPA; Annex II to the SCCs is Annex 2 to this DPA; and Annex III to the SCCs is Annex 3 to this DPA; and

(i)the audit and information rights in Clause 8.9 of the SCCs are exercised in accordance with Clause 11 of this DPA.

12.3 UK transfers. Where a Restricted Transfer is made from the United Kingdom, the SCCs apply as varied by the UK Addendum, which is incorporated into this DPA and completed as set out in Annex 4. Neither party may end the UK Addendum under its Section 19 as though it were the Importer.

12.4 Swiss transfers. Where a Restricted Transfer is made from Switzerland, the SCCs apply with the following amendments: references to the GDPR are to the Swiss FADP insofar as it applies; the competent supervisory authority is the Federal Data Protection and Information Commissioner; and the term "Member State" is not to be interpreted so as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.

12.5 PDPA transfers. For the purposes of section 26 of the PDPA and Regulation 10 of the Personal Data Protection Regulations 2021, this DPA and the contracts referred to in Clause 6.5 are the legally enforceable obligations under which recipients outside Singapore are required to provide a standard of protection comparable to that under the PDPA.

12.6 Alternative mechanisms. If a mechanism relied on in this Clause 12 is invalidated, superseded or held not to apply, the parties will in good faith put in place an alternative mechanism that satisfies Data Protection Law. Until they do, we will suspend the affected transfer to the extent required by law.

13Liability

13.1 Each party's liability arising out of or in connection with this DPA, including under the SCCs, is subject to the exclusions and limitations in Clause 12 of the Terms. Liability under this DPA and liability under the Terms are aggregated and do not apply cumulatively.

13.2 Clause 13.1 does not limit any liability that cannot be limited under Data Protection Law, including a Data Subject's rights under Article 82 of the GDPR and the rights of Data Subjects as third-party beneficiaries under the SCCs.

14Term, Variation and General

14.1 Term. This DPA takes effect on the Start Date and continues for as long as we process Customer Personal Data. Clauses 10, 11, 12 and 13 survive its termination.

14.2 Variation. We may vary this DPA in accordance with Clause 2.3 of the Terms. A variation that reduces the protection given to Customer Personal Data is a material change for the purposes of Clause 2.3(b) of the Terms. We may in addition make any variation required to maintain compliance with Data Protection Law, or required by a change to the SCCs or the UK Addendum, effective on notice.

14.3 Governing law. This DPA is governed by the law stated in Clause 16.9 of the Terms, save that Clause 12.2(f) governs the SCCs and the UK Addendum is governed by the law of England and Wales.

14.4 Severability. If a provision of this DPA is held to be invalid or unenforceable, the remainder continues in force. Clause 16.6 of the Terms applies.

14.5 Contact. Questions about this DPA, and notices under it, should be sent to support@quilt.ai. Our Data Protection Officer is Angad Chowdhry, registered with the Accounting and Corporate Regulatory Authority of Singapore against UEN 201802722N, and contactable at support@quilt.ai.

A1Details of the Processing

This Annex is Annex I to the SCCs where the SCCs apply.

A. List of parties

Data exporter. The customer identified in the Terms, acting as Controller (Module Two) or as processor on behalf of a third-party controller (Module Three). Contact details, role and signature are those recorded in your account and, where one exists, in your Software Subscription Agreement. Activities relevant to the transfer: use of the Services as described in Schedule 1 to the Terms.

Data importer. Quilt AI Pte. Ltd. (UEN 201802722N), 101 Telok Ayer Street #03-06, Singapore 068574. Contact: support@quilt.ai. Data Protection Officer: Angad Chowdhry. Role: Processor. Activities relevant to the transfer: provision of the Services described in Schedule 1 to the Terms.

B. Description of the transfer

Categories of Data SubjectsYour Permitted Users and account administrators; and any individual whose Personal Data is contained in Data that you submit to the Services. You determine the latter
Categories of Personal DataAccount and contact data of Permitted Users (name, email address, organisation, role, authentication identifiers); Usage Information to the extent it identifies an individual; and any Personal Data contained in the Data you submit, which may include free text, documents, spreadsheets, images, audio and video. You determine the latter
Special Category DataNone. Clause 3.4(c) prohibits submission without our prior written agreement
Frequency of transferContinuous, for the duration of the Services
Nature of the processingHosting, storage, transmission, display, reformatting, indexing, analysis and model inference; generation of Output; support; security monitoring; billing and entitlement administration; backup
Purpose of the processingThe purposes set out in Clause 6.2(a) of the Terms and, for Usage Information, Clause 6.5(a) of the Terms
Retention periodFor the duration of the Services and thereafter in accordance with Clause 10 of this DPA and our published retention periods. Provider-side retention periods are stated in our trust centre
Transfers to Sub-processorsSubject matter, nature and duration as described in Annex 3 and in our trust centre

C. Competent supervisory authority

The supervisory authority of the Member State in which the data exporter is established. Where the data exporter is not established in the European Economic Area, the supervisory authority of the Member State in which the data exporter's Article 27 representative is established, or in which the Data Subjects whose Personal Data is transferred are located.

A2Technical and Organisational Measures

This Annex is Annex II to the SCCs where the SCCs apply. The current description is published in our trust centre at trustcenter.quilt.ai and prevails over this Annex where the two differ.

MeasureDescription
EncryptionCustomer Personal Data is encrypted in transit using TLS and at rest using the encryption provided by the underlying cloud platform
Access controlAccess is granted on the principle of least privilege, through named accounts, and is reviewed on a defined cycle. Multi-factor authentication is required for personnel access to production systems
Customer authenticationEmail and password, Google sign-in, Microsoft sign-in, SAML single sign-on for customers that require it, and API Keys for programmatic access. Schedule 2 to the Terms describes the routes
SegregationCustomer Personal Data is logically segregated by Tenant. Access controls prevent a user of one Tenant from reaching the Data of another
Logging and monitoringSecurity and access events are logged, retained and monitored; alerts are raised on defined conditions
Vulnerability managementAutomated dependency and vulnerability scanning, triage on receipt against defined severity timeframes, and periodic penetration testing
Secure developmentVersion control, peer review before merge, separated development and production environments, and secrets held in a managed secret store
Incident managementA documented incident management process, with the notification obligations in Clause 7.3 of the Terms and Clause 9 of this DPA
Business continuityManaged database backups with point-in-time recovery, and documented business continuity and disaster recovery plans that are tested
Physical securityPhysical and environmental security of the processing infrastructure is provided by the underlying cloud platform and is covered by that provider's own certifications
PersonnelConfidentiality obligations, security awareness training, and a documented joiner-mover-leaver process including timely revocation of access
Supplier managementSub-processors are assessed before engagement and are bound by written terms no less protective than this DPA
AssuranceOur current independent assurance position, and the certifications held by each Sub-processor, are published in our trust centre

A3Sub-processors

This Annex is Annex III to the SCCs where the SCCs apply.

The authoritative, current list of Sub-processors and Model Providers — with the name, the processing performed and the processing location for each — is published at trustcenter.quilt.ai. The categories engaged as at the date of this DPA are:

CategoryProcessing performed
Cloud infrastructure and hostingCompute, storage and networking for the Services
Database hostingManaged database services holding application data
Edge, DNS and content deliveryDNS resolution, content delivery, and web application firewall
Model ProvidersModel inference on Data and Output at your direction. Bound by terms prohibiting use of your Data or Output to train, fine-tune, retrain or otherwise develop or improve any model
Data Acquisition ProvidersSupply of publicly available content in response to search terms derived from your use of the Services. Clause 6.8 of the Terms governs what is submitted to them; no Customer Personal Data is submitted
Error and performance monitoringReceipt of application error reports, which may include Customer Personal Data
Payment processingProcessing of subscription payments and retention of transaction records
Source controlHosting of the source code of the Services

A4UK Addendum

Where the UK Addendum applies under Clause 12.3, it is completed as follows.

Table 1 — Parties. The Exporter is the customer and the Importer is Quilt AI Pte. Ltd., with the details in Annex 1.A. Key contact for both parties: as stated in Annex 1.A.

Table 2 — Selected SCCs, Modules and Selected Clauses. The SCCs as incorporated by Clause 12.2 of this DPA, including the module selection and the clause options stated there.

Table 3 — Appendix Information. Annex 1.A of this DPA is the list of parties; Annex 1.B is the description of the transfer; Annex 2 is the technical and organisational measures; Annex 3 is the list of Sub-processors.

Table 4 — Ending the Addendum when the Approved Addendum changes. Neither party may end the UK Addendum as set out in Section 19 of it.