MogDock Data Processing Addendum

Version 2026-09-launch-v1 · effective September 9, 2026

MogDock Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the MogDock Terms of Service or
another agreement governing Customer's use of MogDock (the "Agreement") between
Customer and Upstage Creations LLC, 42075 Remington Ave, Suite 109, Temecula,
California 92590 ("Upstage").

1. Scope and roles

This DPA applies when Upstage processes personal data contained in Customer Content on
Customer's behalf in providing MogDock ("Customer Personal Data"). Customer is the
controller or business responsible for Customer Personal Data, and Upstage is the
processor or service provider, except where applicable law assigns different terms.

Each party will comply with the data-protection laws applicable to its role. Customer is
responsible for the lawfulness of its instructions, Customer Personal Data, and use of
MogDock.

2. Processing instructions

Upstage will process Customer Personal Data only to provide, secure, support, and maintain
MogDock; to follow Customer's documented use and configuration of the service; to comply
with the Agreement; or as required by law. If law requires different processing, Upstage
will inform Customer before processing unless the law prohibits notice.

The Agreement, this DPA, Customer's authorized use of MogDock, and support requests are
Customer's documented instructions. Upstage will notify Customer if it reasonably believes
an instruction violates applicable data-protection law.

3. Confidentiality and access

Upstage will limit access to Customer Personal Data to personnel and service providers who
need it for the permitted processing. Authorized personnel are subject to appropriate
confidentiality obligations.

4. Security

Upstage will maintain reasonable administrative, technical, and organizational safeguards
designed for the nature of Customer Personal Data and the processing risks. Measures
include access controls, tenant separation, protected credentials, encrypted network
transport, protected storage, backup controls, security logging or audit records where
appropriate, vulnerability and change management, and incident-response procedures.

No security program eliminates all risk. Customer remains responsible for its user access,
devices, connected services, permissions, and secure use of exported data and credentials.

5. Subprocessors

Customer authorizes Upstage to use subprocessors that are operationally necessary to
host, store, secure, communicate, support, monitor, or bill for MogDock. Upstage will
require subprocessors to protect Customer Personal Data consistently with Upstage's
obligations under this DPA for the processing they perform. Upstage remains responsible
for its subprocessors to the extent required by applicable law and the Agreement.

Upstage will provide reasonably requested information about current subprocessors and
material processing locations through support@mogdock.com. Customer-selected integrations
are controlled by Customer and may be subject to separate terms between Customer and the
integration provider.

6. Data-subject requests and compliance assistance

Taking into account the nature of processing and information available to it, Upstage will
reasonably assist Customer with requests from individuals concerning Customer Personal
Data and with Customer's applicable obligations for security, impact assessments,
regulatory consultation, and breach response. If Upstage receives a request concerning
Customer Personal Data, it may direct the requester to Customer unless law requires
Upstage to respond directly.

7. Security incidents

Upstage will notify Customer without undue delay after confirming unauthorized access to,
acquisition of, or disclosure of Customer Personal Data for which notice is required by
applicable law. Notice will include information reasonably available to Upstage. Notice is
not an admission of fault or liability. Customer is responsible for its own notices and
regulatory duties as controller unless applicable law assigns them to Upstage.

8. Return, deletion, and retention

During an active account, Customer may use available product functions to access or export
Customer Content. After cancellation, an account is ordinarily recoverable for 30 days
after paid access ends unless an earlier verified deletion request is completed.

Upstage completes a verified deletion request within 30 days, subject to lawful retention.
Encrypted backups expire within 90 days rather than being altered in place. Upstage may
retain legal, billing, security, and fraud-prevention records only as long as legally
necessary. Retained data remains protected and is not used for another purpose.

9. Information and review

Upon reasonable written request, Upstage will provide information reasonably necessary to
demonstrate compliance with this DPA. Any further review must protect other customers,
confidential information, security, and service continuity. The parties will first use
available documentation and remote review before considering a more intrusive inspection.

10. International processing

Customer authorizes processing in locations where Upstage and its operationally necessary
service providers operate, subject to safeguards required by applicable law. If a legally
required transfer mechanism applies to particular processing, the parties will cooperate
to put that mechanism in place. This DPA does not itself select a transfer mechanism where
the relevant countries, roles, and transfer have not been identified.

11. Conflict and duration

If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA
controls for that conflict. This DPA continues while Upstage processes Customer Personal
Data on Customer's behalf.

12. Contact

Privacy and DPA requests may be sent to support@mogdock.com.

Appendix 1 — Processing description

Subject matter: Hosting and providing MogDock's business-operations, account, billing,
integration, documentation, and support functions selected by Customer.

Duration: The subscription term plus the cancellation, verified-deletion, backup-expiry,
and lawful-retention periods described above.

Nature and purpose: Collection, recording, organization, storage, retrieval, consultation,
use, transmission, synchronization, support, security, deletion, and other processing
needed to provide MogDock under Customer's instructions.

Categories of individuals may include Customer's users, administrators, personnel,
customers, prospective customers, recipients, suppliers, service providers, support
contacts, and other people whose data Customer submits or connects.

Types of personal data may include identity and contact details, account and role data,
business and transaction records, order and fulfillment information, support messages and
attachments, connected-service identifiers and content, technical and security data, and
other Customer Personal Data selected by Customer.

Sensitive data: Customer must not submit legally sensitive or specially regulated data
unless the Agreement, product documentation, and applicable law expressly permit it and
Customer has implemented appropriate safeguards.