Data Processing Addendum

Playful Software, Inc. · Effective September 3, 2026

The short version

This Data Processing Addendum ("DPA") applies when Playful processes personal information in App Data for a Creator, including Consumer Health Data permitted by the Agreement. The Creator decides what the App collects and why. Playful processes that data only to run, secure, and support the App and does not use it to improve Playful or train or fine-tune generative AI models.

1. Scope and definitions

This DPA forms part of the Playful Terms of Use (the "Agreement") between Playful Software, Inc. ("Playful") and the Creator or organization that controls the relevant App ("Customer"). It applies only to Playful's processing of personal information contained in App Data on Customer's behalf. It does not govern account information, Platform Content, creator prompts, creator feature interactions, billing information, or technical information Playful processes for its own purposes as described in the Privacy Policy.

"App Data" and "Consumer Health Data" have the meanings given in the Agreement. "Data Protection Laws" means privacy and data-protection laws applicable to Playful's processing under this DPA, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act ("CCPA"), other applicable U.S. state privacy laws, state consumer-health privacy laws such as Washington's My Health My Data Act, and the FTC Health Breach Notification Rule. "Personal Data" means personal data, personal information, consumer health data, or a similar regulated category contained in App Data. "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Playful, as well as an unauthorized acquisition or disclosure that constitutes a breach under applicable Data Protection Laws. Terms such as "controller," "processor," "business," "service provider," "consumer," "data subject," and "processing" have the meanings given by applicable Data Protection Laws.

2. Roles and instructions

Customer determines the purposes and essential means of processing Personal Data through its App. As between the parties and where those legal concepts apply, Customer is the controller or business and Playful is the processor or service provider. If Customer processes Personal Data for another controller, Customer is a processor and Playful is Customer's subprocessor.

The Agreement, this DPA, Customer's configuration and use of the Service, and other documented instructions consistent with them are Customer's complete instructions to Playful. Customer instructs Playful to process Personal Data for the purposes in Schedule 1 and as otherwise necessary to provide features Customer enables, comply with law, or protect the Service from abuse, fraud, and security threats. Playful will tell Customer if it believes an instruction violates Data Protection Laws, unless law prohibits the notice.

Playful does not use App Data to improve the Playful product or to train or fine-tune generative AI models. Playful may generate service telemetry and aggregated or de-identified statistics that do not identify Customer or an End User and are not reasonably capable of being linked back to them.

3. Playful's obligations

Playful will:

4. Customer's obligations

Customer is responsible for the lawfulness, fairness, and accuracy of Personal Data and Customer's instructions. Customer will provide all required notices, establish a valid legal basis, obtain all required consents, honor End User rights, and configure its App to collect only information reasonably necessary for its disclosed purposes. If an App processes Consumer Health Data, Customer will comply with applicable consumer-health privacy and breach-notification laws and, where required, provide a separate consumer-health privacy notice and obtain consent that is distinct from acceptance of general terms. If law requires Customer to notify Playful that Customer is a vendor of personal health records, a related entity, or otherwise regulated, Customer will do so before the relevant processing and identify an appropriate breach-notification contact.

Customer will not submit Restricted Data, use the Service in a manner that would make Playful a business associate under HIPAA, build an App directed to children under 13 or knowingly collect personal information from a child under 13 other than in a Family App permitted by Section 3.4 of the Agreement, or permit unapproved minor use of Playful-provided AI features, as described in the Agreement. For a Family App, Customer represents that it is the parent or legal guardian of each child whose Personal Data the App processes, has given any consent the law requires on the child's behalf, and is responsible for compliance with children's privacy laws.

Customer will not instruct Playful to process Personal Data in a way that violates Data Protection Laws. Customer is responsible for responding to End Users and regulators regarding Customer's App, except for assistance Playful must provide under this DPA.

5. Subprocessors

Customer gives Playful general authorization to engage subprocessors to provide the Service. Playful will maintain a current list of subprocessors, their locations, and their functions at playful.app/terms-and-conditions/subprocessors. The list will include AI Providers when an App feature sends End User inputs to them.

Playful will impose written data-protection obligations on each subprocessor that are no less protective in material respects than the obligations applicable to Playful under this DPA. Playful remains responsible for each subprocessor's performance to the extent required by Data Protection Laws.

Playful will give at least 15 days' notice before a new subprocessor begins processing Personal Data, ordinarily by updating the list and notifying the account email. Customer may object during that period on reasonable data-protection grounds. The parties will try in good faith to resolve the objection. If they cannot, Customer's sole remedy is to stop using the affected feature or terminate the affected App before the new subprocessor begins processing, without penalty other than fees already incurred.

6. Requests and compliance assistance

Taking into account the nature of the processing and information available to Playful, Playful will reasonably assist Customer with:

If Playful receives a request directly from an End User concerning App Data, Playful will ordinarily direct the person to Customer or forward the request to Customer. Playful will not independently respond unless Customer instructs it to do so, Playful is legally required to respond, or the App is unavailable and action is reasonably necessary to protect the person or comply with law.

7. Security incidents

Playful will notify Customer without undue delay after confirming a Security Incident affecting Customer's Personal Data. The notice will include information reasonably available to Playful about the nature of the incident, affected data and people, likely consequences, measures taken or proposed, and a contact for follow-up. Playful may provide information in phases as it becomes available.

Playful will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident. Notification is not an admission of fault or liability. Customer is responsible for determining whether to notify End Users, regulators, or others, with Playful's assistance as required by this DPA.

8. Deletion and return

Customer may delete or export App Data using available Service tools or by contacting Playful. When Customer deletes App Data, the relevant App, or its account, Playful will remove the affected App Data from active systems within 30 days and from backups within 90 days, unless law requires longer retention or isolated retention is reasonably necessary to establish, exercise, or defend legal claims. During any permitted extended retention, Playful will keep the data protected and will not process it for another purpose.

At the end of the Agreement, Customer instructs Playful to delete remaining Personal Data according to the preceding paragraph unless Customer requests an available export before termination. Playful need not return data in a proprietary format or retain data after the applicable deletion period.

9. Audits and information

On reasonable written request, no more than once annually unless a Security Incident or regulator requires otherwise, Playful will provide information reasonably necessary to demonstrate compliance with this DPA. This may include responses to a security questionnaire and summaries of relevant independent assessments, if available.

If that information is reasonably insufficient, Customer may request an audit by an independent auditor mutually agreed by the parties. Audits must occur during normal business hours, on reasonable advance notice, without access to other customers' data or material disruption to the Service, and subject to confidentiality obligations. Customer bears its audit costs unless the audit identifies a material breach by Playful. Nothing requires Playful to disclose information that would compromise security, violate law, or breach another person's confidentiality.

10. International transfers

10.1 EEA transfers

If Personal Data protected by the GDPR is transferred to Playful in a country that does not have an applicable adequacy decision, the Standard Contractual Clauses in European Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated by reference. Module Two applies when Customer is a controller and Playful is a processor; Module Three applies when Customer is a processor and Playful is a subprocessor.

For the EU SCCs: Clause 7 applies; in Clause 9, Option 2 applies with the notice period in Section 5; the optional language in Clause 11 does not apply; in Clause 17, Option 1 applies and the governing law is Ireland; the courts of Ireland apply under Clause 18; the competent supervisory authority under Clause 13 is determined by the GDPR and, where no other authority is specified, is the Irish Data Protection Commission. The Agreement and Schedule 1 complete Annex I, Schedule 2 completes Annex II, and Playful's Subprocessor List completes Annex III.

10.2 United Kingdom and Switzerland

For transfers protected by the UK GDPR, the EU SCCs are modified by the UK International Data Transfer Addendum issued by the Information Commissioner's Office, which is incorporated by reference. The parties select the exporter and importer information in Schedule 1, the tables are completed using this DPA, and either party may terminate the Addendum as permitted by its mandatory clauses if it is materially revised.

For transfers protected by the Swiss Federal Act on Data Protection, references in the EU SCCs to the GDPR and European Union will be interpreted to include Swiss data-protection law and Switzerland as applicable, the competent authority will be the Swiss Federal Data Protection and Information Commissioner, and proceedings may be brought in an applicable Swiss court. These modifications do not exclude the application of the EU SCCs to data also protected by the GDPR.

10.3 Supplementary measures

Playful will provide information reasonably requested for Customer's transfer assessment and will use the measures in Schedule 2. If Playful receives a legally binding government demand for Personal Data, Playful will review its validity, challenge unlawful demands where reasonable, disclose only what is legally required, and notify Customer unless prohibited by law.

11. U.S. state privacy terms

For Personal Data subject to the CCPA or a similar U.S. state law, the specific business purposes for Playful's processing are those in Schedule 1. Playful will comply with applicable obligations imposed on service providers, contractors, or processors; provide the same level of privacy protection required by applicable law; cooperate with Customer's legally required consumer-request, risk-assessment, and cybersecurity-audit activities; and permit Customer to take reasonable and appropriate steps to help ensure Playful uses Personal Data consistently with Customer's obligations.

If Customer reasonably believes Playful is processing Personal Data without authorization, Customer may notify Playful and require reasonable steps to stop and remediate the unauthorized use. Each party will comply with applicable universal opt-out mechanisms to the extent relevant to its role and processing.

12. Order of precedence and liability

If this DPA conflicts with the Agreement regarding processing of Personal Data in App Data, this DPA controls. The EU SCCs or UK Addendum control over both documents where they expressly require. Otherwise, the Agreement remains in effect. Liability arising under this DPA is subject to the Agreement's limitations and exclusions to the maximum extent permitted by law, but nothing limits data-subject rights or liability that applicable law prohibits the parties from limiting.

Schedule 1 — Processing details

ItemDetails
PartiesCustomer / data exporter: the Creator or organization identified by the Playful account controlling the App, at its account contact address. Playful / data importer: Playful Software, Inc., 1904 3rd Ave, Suite 910, Seattle, WA 98101, United States; contact@playful.app.
Subject matterHosting, storing, processing, securing, maintaining, and supporting Personal Data contained in Customer's App Data.
DurationFor the term of the Agreement and the deletion periods in Section 8.
Nature and purposesStorage, database operations, hosting, network transmission, backup, troubleshooting, support, security, abuse and fraud prevention, legal compliance, and features Customer enables. If Customer enables an AI feature for End Users, transmitting their relevant inputs to the selected AI Provider and returning Output to the App.
Data subjectsEnd Users of Customer's App and other individuals whose Personal Data Customer or an End User lawfully submits to the App, including a child under 13 who uses a Family App with the consent of Customer as the child's parent or legal guardian.
Personal DataInformation Customer configures its App to collect or process, which may include identifiers, contact details, account or profile information, App submissions, communications, uploaded content, transaction or interaction information, approximate location, and device or technical information.
Sensitive dataCustomer may configure a personal, noncommercial App to process Consumer Health Data and other sensitive information permitted by the Agreement. Restricted Data remains prohibited, including protected health information processed for or on behalf of a HIPAA covered entity or business associate, financial-account credentials, government identifiers, biometric identifiers, precise location used to track people, third-party credentials, personal information of children under 13 (other than Customer's own child's information in a Family App, as permitted by the Agreement), and information requiring a compliance framework Playful does not offer.
FrequencyContinuous or as initiated by Customer and End Users through the App.
Customer instructions and rightsAs stated in the Agreement, this DPA, Customer's App configuration, support requests, and other documented instructions accepted by Playful.

Schedule 2 — Security measures

Playful maintains measures designed to protect Personal Data, including:

No system is completely secure. These measures are designed to provide a level of security appropriate to the nature and risk of the processing and may evolve as technology and risks change, provided Playful does not materially reduce their overall protection.

Contact

Playful Software, Inc. Attn: Privacy 1904 3rd Ave, Suite 910 Seattle, WA 98101, United States Email: contact@playful.app