Data Protection Agreement

Last updated: August 24, 2026

DATA PROTECTION AGREEMENT

Supplement to the DS ProSolution Master Services Agreement

Version: DPA v1.4 (2026-08-24)

Effective Date: as provided in Section 16

This Data Protection Agreement (this "DPA") is entered into between RLIM LLC, a New Mexico limited liability company doing business as DS ProSolution ("DS Pro"), and the natural person or legally organized entity identified as Client in the Master Services Agreement ("Client"). This DPA supplements and forms part of the Master Services Agreement between the Parties (the "MSA"), as incorporated by the MSA (including by MSA Section 7.7), and applies to the Services under all applicable Order Forms between the Parties.

The Schedule matching Client's location, as selected under MSA Section 7.7, attaches to and forms part of this DPA and applies together with it: Schedule A (United States), Schedule B (Canada), or Schedule C (United Kingdom, EEA, and Other International). Where a Schedule applies, that Schedule's "Applicable Privacy Laws" and jurisdiction-specific terms control for the matters they address. If more than one Schedule could apply, the Schedule matching Client's location controls, and Schedule B applies in addition only to the extent Canadian Privacy Laws mandatorily apply to particular processing. Capitalized terms not defined in this DPA have the meanings given in the MSA.

1) Definitions

Applicable Privacy Laws means the privacy and data-protection laws identified in the Schedule that applies to Client, plus any other privacy or data-protection law applicable to the Services.

Personal Information means information about an identifiable individual, or information treated as personal information or personal data under Applicable Privacy Laws.

Processing (and 'process') means any operation performed on Personal Information, whether or not by automated means, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, combination, restriction, erasure, and destruction.

DS Pro Business Data means Personal Information that DS Pro processes for its own business administration, billing, support, security, fraud prevention, legal compliance, contract enforcement, audit, service improvement, and internal operations.

Client Account Operational Data means Personal Information and other account data that DS Pro processes to access, manage, secure, support, reconcile, invoice, or offboard Client's marketplace, supplier, payment, fulfillment, shipping, and related accounts, including credentials, OAuth tokens, two-factor authentication secrets, account identifiers, platform data, order data, payout data, funds data, profit data, inbox/message data, activity logs, and raw marketplace payloads.

End-Customer Personal Information means Personal Information of buyers, recipients, customers, or other individuals whose information appears in or through Client's Accounts, including names, usernames, shipping addresses, contact details, order details, messages, returns, refunds, tracking data, and dispute or chargeback data.

Sensitive Platform Data means Client Account Operational Data or End-Customer Personal Information that is sensitive because it includes credentials, passwords, authentication tokens, two-factor authentication secrets, financial or payout information, payment-card references, tax or banking information, buyer addresses, buyer contact information, message contents, raw marketplace payloads, or security/audit logs.

Security Incident means an actual or reasonably suspected unauthorized access to, acquisition of, disclosure of, loss of, alteration of, destruction of, or misuse of Personal Information or Sensitive Platform Data processed by DS Pro or its Subprocessors.

Subprocessor means a third-party service provider that processes Personal Information for DS Pro to provide, secure, host, support, invoice, or administer the Services.

Connected Third-Party Platform means a marketplace, supplier, payment, shipping, fulfillment, banking, or similar platform connected to Client's Accounts or used to perform the Services. Connected Third-Party Platforms may operate under their own terms and privacy notices.

Schedule means Schedule A (United States), Schedule B (Canada), or Schedule C (United Kingdom, EEA, and Other International), as applicable to Client under MSA Section 7.7 and this DPA.

2) Scope and Order of Precedence

This DPA governs DS Pro's processing of Personal Information for the Services. For privacy and data-protection matters, this DPA controls over the MSA and any Order Form to the extent of conflict. For commercial terms, fees, service scope, account-specific obligations, and non-privacy disputes, the MSA and applicable Order Form control. Where the applicable Schedule addresses a matter differently for that jurisdiction, the Schedule controls for that matter.

This DPA does not reduce any non-waivable rights or obligations under Applicable Privacy Laws. If Applicable Privacy Laws require a different result for a particular issue, the mandatory legal requirement controls only for that issue.

This DPA, together with the applicable Schedule, replaces and supersedes any prior data protection agreement between the Parties with respect to the processing it governs, effective as provided in Section 16.

3) Roles and Responsibility Model

For DS Pro Business Data, DS Pro acts as the responsible organization (controller, where Applicable Privacy Laws use that term) for that processing under Applicable Privacy Laws.

For Client Account Operational Data and End-Customer Personal Information, Client remains the responsible organization (controller, where Applicable Privacy Laws use that term) for the Accounts and for the lawful collection, use, disclosure, retention, and instructions relating to that information. DS Pro processes that information as Client's service provider (processor, where Applicable Privacy Laws use that term) for the limited purposes described in the MSA, the applicable Order Form, and this DPA.

The Parties acknowledge that jurisdictions use different controller and processor vocabulary. The role descriptions in this DPA are contractual allocations of responsibility intended to support accountability, comparable protection, and lawful service-provider processing, as further specified in the applicable Schedule.

Overlapping data and limited post-service controller role. While DS Pro processes Client Account Operational Data or End-Customer Personal Information to provide the Services or on Client's documented instructions, that information remains Client Account Operational Data or End-Customer Personal Information and DS Pro acts solely as Client's service provider or processor, even if the same information could also support a DS Pro business function. This does not prevent DS Pro from acting as an independent responsible organization or controller, after the applicable Services end, solely with respect to a limited copy of records that DS Pro is required by applicable law to retain or that DS Pro reasonably needs to establish, exercise, or defend legal claims, administer its own tax or accounting obligations, or preserve evidence, subject to Section 13. That limited role does not transfer ownership of Client data to DS Pro, authorize continued account operation, permit product or service improvement using identifiable Client data, or permit use for any unrelated purpose. The applicable Schedule controls where it imposes a narrower retention or role rule.

4) Processing Purposes and Instructions

Client instructs DS Pro to process Personal Information as necessary to provide, secure, support, measure, invoice, reconcile, offboard, and legally administer the Services. Authorized purposes include:

  • onboarding Client and Accounts;
  • accessing and managing marketplace, supplier, payment, fulfillment, and shipping accounts;
  • storing and using credentials, authentication data, OAuth tokens, and two-factor authentication information only as needed for account access and security;
  • maintaining secure and consistent network access to Accounts;
  • retrieving, storing, reconciling, and analyzing order history, refunds, returns, chargebacks, payouts, fees, funds, profit, costs of goods sold, invoices, and cash-flow information;
  • fulfilling or supporting orders, shipment tracking, customer-service workflows, inbox/message workflows, and account-health workflows;
  • generating profit statements, bookkeeping records, invoices, dispute records, audit records, and offboarding exports;
  • protecting accounts, systems, data, users, and the Services from unauthorized access, fraud, abuse, and security incidents;
  • complying with law, enforcing contracts, resolving disputes, preserving evidence, and responding to lawful requests; and
  • using aggregated or de-identified information that does not identify any individual, as described in Section 13.

DS Pro will not sell or share Personal Information and will not process Personal Information for targeted or cross-context behavioral advertising. DS Pro will not profile individuals except as part of providing, securing, supporting, invoicing, or legally administering the Services (including the de-identified optimization described in Section 13).

5) Cross-Border Processing (General)

Client authorizes DS Pro to process Personal Information in the United States and in other locations where DS Pro or its Subprocessors operate. Client acknowledges that Personal Information processed outside Client's home jurisdiction may be subject to lawful access by courts, law-enforcement, national-security, or regulatory authorities in those jurisdictions.

DS Pro will use contractual, technical, and organizational measures designed to provide a level of protection comparable to that required by Applicable Privacy Laws, and remains accountable, as between DS Pro and Client, for Personal Information processed by Subprocessors on DS Pro's behalf, subject to the MSA's limitations and this DPA. Jurisdiction-specific transfer mechanisms (including the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, and Canadian cross-border accountability requirements) are set out in the applicable Schedule.

6) Data Categories and Data Minimization

DS Pro follows a data-minimization principle: it collects and retains only the categories of Personal Information reasonably necessary to provide, secure, support, invoice, reconcile, offboard, and optimize the Services, and may narrow what it holds over time. Categories are described by type and purpose (not by specific system or field) in Appendix A and may evolve as the Services and supporting infrastructure change; a current description is maintained in the DS ProSolution Privacy Policy.

DS Pro is not authorized to retain full payment-card numbers, CVV/security codes, magnetic-stripe data, PINs, or equivalent card authentication data. If Client accidentally provides that information, Client authorizes DS Pro to delete it or return it without retaining a copy, except to the extent a short-lived record is technically necessary to document deletion or security handling.

7) Service-Provider Commitments

For Client Account Operational Data and End-Customer Personal Information, DS Pro will:

  • process that information only for the Services and other purposes permitted by this DPA, the MSA, the applicable Order Form, and Applicable Privacy Laws;
  • restrict access to authorized personnel, contractors, and Subprocessors who need access for the Services;
  • require personnel, contractors, and Subprocessors with access to maintain confidentiality obligations;
  • not sell, rent, disclose, or use that information for DS Pro's unrelated commercial purposes;
  • not combine that information with unrelated data except as necessary to provide, secure, support, invoice, improve, or legally administer the Services or as otherwise permitted by law;
  • promptly inform Client if DS Pro believes an instruction violates Applicable Privacy Laws, unless prohibited by law; and
  • provide reasonable information needed to demonstrate DS Pro's compliance with this DPA, subject to protection of DS Pro's confidential information, security information, trade secrets, and third-party obligations.

Jurisdiction-specific service-provider certifications and role provisions are set out in the applicable Schedule.

8) Client Obligations

Client represents and warrants that Client has lawful authority to provide Account access, credentials, Client Account Operational Data, and End-Customer Personal Information to DS Pro for the Services.

Client is responsible for all notices, consents, permissions, platform authorizations, and lawful bases required for Client's collection, use, disclosure, and instruction of DS Pro's processing of Personal Information through Client's Accounts.

Client will not provide DS Pro with full payment-card numbers, CVV/security codes, tax identifiers, banking credentials, government identification numbers, or other highly sensitive information unless DS Pro has expressly requested the information in writing for a specific lawful purpose and has confirmed an approved intake method.

Client will maintain accurate contact information, promptly respond to privacy and security communications from DS Pro, and cooperate with DS Pro when DS Pro reasonably needs Client instructions to respond to individual requests, regulator or platform inquiries, open orders, chargebacks, refunds, tax/accounting issues, or Security Incidents.

9) Subprocessors and Connected Third-Party Platforms

Client authorizes DS Pro to use Subprocessors to provide, host, secure, support, invoice, monitor, and administer the Services. Current expected Subprocessor and infrastructure categories are described in Appendix B and include infrastructure and hosting providers (database, authentication, storage, secrets-management, application and web hosting, telemetry, logging, monitoring, backup, and security); billing, invoicing, and payment-processing providers; email and communication providers; and monitoring and logging providers.

DS Pro will require Subprocessors that process Personal Information on DS Pro's behalf to maintain confidentiality, reasonable safeguards, and contractual restrictions appropriate to their role. DS Pro remains responsible for Subprocessors' processing of Personal Information on DS Pro's behalf, except to the extent an issue is caused by Client instructions, Client platforms, Client credentials, Connected Third-Party Platforms acting under their own terms, or events outside DS Pro's reasonable control.

Connected Third-Party Platforms (including marketplace, supplier, shipping, payment or payout, and banking platforms) may act under their own terms and privacy notices and may be independent organizations, businesses, controllers, or service providers depending on the platform and workflow. DS Pro does not control those platforms' independent processing, but will use commercially reasonable efforts to route Personal Information to them only as needed for the Services and Client's instructions.

DS Pro will make available, on request, reasonable information about material Subprocessors then used for the Services. DS Pro may update Subprocessors as the Services evolve. If Client reasonably objects to a new material Subprocessor on privacy or security grounds, the Parties will work in good faith on a commercially reasonable mitigation, alternative, or transition path.

10) Security Measures

DS Pro will maintain technical and organizational measures designed to protect Personal Information and Sensitive Platform Data against unauthorized access, acquisition, disclosure, loss, alteration, destruction, and misuse, appropriate to the nature, scope, context, and purposes of the processing and the risks presented to individuals. Such measures may include, by way of illustration and not as a guarantee that any specific measure is applied to any specific data element:

  • encryption in transit and encryption at rest where supported by the relevant system;
  • secrets-management or vaulting practices for sensitive credentials and secrets where implemented;
  • role-based access controls, least-privilege access, and separation of duties where practical;
  • administrative multi-factor authentication or equivalent access controls where available and appropriate;
  • access logging, audit records, monitoring, and alerting for systems handling Sensitive Platform Data;
  • restrictions on copying, exporting, logging, or displaying secrets and raw sensitive data;
  • personnel and contractor confidentiality obligations;
  • reasonable onboarding and offboarding access controls for personnel and contractors;
  • backup, recovery, vulnerability-management, patching, and dependency-review practices appropriate for the Services;
  • secure deletion or deactivation practices when data or credentials are no longer required; and
  • incident-response procedures designed to detect, contain, investigate, mitigate, and document Security Incidents.

The measures listed above are illustrative examples of the kinds of safeguards DS Pro may employ; they evolve over time and are not representations that every measure applies to every data element or system. No security program can guarantee that unauthorized access will never occur. DS Pro's binding obligation is to maintain reasonable and appropriate technical and organizational safeguards, respond appropriately to Security Incidents, and meet the obligations of this DPA.

11) Security Incident Notice and Cooperation

DS Pro will notify Client without undue delay after becoming aware of a Security Incident involving Personal Information or Sensitive Platform Data processed by DS Pro or its Subprocessors and, where practicable, no later than 72 hours after becoming aware. Initial notice may be preliminary and based on then-available information, may be provided by email under the MSA, and will be supplemented under this Section 11 as the investigation develops; DS Pro will not unreasonably delay initial notice pending completion of its investigation.

DS Pro's notice will include available information reasonably needed for Client to assess legal, platform, and individual-notification obligations, including the nature of the incident, affected data categories, affected systems or Subprocessors, approximate timing, mitigation steps, and recommended actions, to the extent known and legally permitted.

DS Pro will provide reasonable updates as material information becomes available, take reasonable steps to contain and mitigate the Security Incident, preserve relevant evidence, and cooperate with Client's legally required privacy, platform, or regulator response. DS Pro will not notify regulators, platforms, or affected individuals on Client's behalf unless legally required, authorized by Client, or necessary to prevent imminent harm.

DS Pro will maintain records of Security Incidents as required by Applicable Privacy Laws. Force majeure or third-party-platform language in the MSA does not excuse DS Pro's breach-notification, mitigation, cooperation, or record-keeping duties after DS Pro becomes aware of a Security Incident.

12) Individual Rights, Access, Correction, and Complaints

Taking into account the nature of the Services, DS Pro will provide reasonable assistance to Client in responding to requests by individuals to access, correct, challenge, delete, withdraw consent for, port, restrict, or otherwise exercise rights regarding Personal Information DS Pro processes for Client.

If DS Pro receives a request or complaint from an individual relating to Client Account Operational Data or End-Customer Personal Information, DS Pro may direct the individual to Client or notify Client, unless DS Pro is legally required to respond directly. DS Pro may respond directly for DS Pro Business Data.

Client remains responsible for determining whether and how to respond to requests relating to Client's Accounts, buyers, recipients, products, orders, refunds, chargebacks, or marketplace obligations. DS Pro will provide reasonable support where the requested information is in DS Pro's systems and can be located without disproportionate burden. The specific regulators and complaint bodies for Client's jurisdiction are identified in the applicable Schedule.

13) Retention, Return, and Deletion

DS Pro will retain Personal Information only as long as reasonably necessary for the Services, offboarding, open orders, refunds, chargebacks, payout reconciliation, invoices, bookkeeping, tax/accounting, security, audit, legal compliance, dispute resolution, and enforcement of the MSA or applicable Order Form.

On termination or offboarding, DS Pro will stop active account management except as needed to complete wind-down tasks, open transactions, final invoicing, security response, or legal obligations. At Client's request, DS Pro will provide a reasonable export or return of available Client Account Operational Data in a commercially reasonable format, subject to platform limits, third-party terms, and security limits. DS Pro may withhold optional value-added export formatting or compilation services while undisputed amounts remain unpaid, but will not condition the return or deletion of Personal Information required by Applicable Privacy Laws or this Section 13 on payment.

Credentials, passwords, OAuth tokens, two-factor authentication secrets, network-connection credentials used to maintain secure, stable, and consistent access to Accounts, and similar access secrets will be deleted, revoked, disabled, or returned within a commercially reasonable period after they are no longer needed for offboarding, open transactions, dispute handling, security, or legal obligations. DS Pro's target is within 30 days after offboarding completion unless a longer period is reasonably required.

DS Pro will delete, redact, or de-identify Personal Information from its active production systems when required by Applicable Privacy Laws or by Connected Third-Party Platform requirements (such as marketplace account-deletion or erasure obligations), within the period those requirements specify or, where none is specified, within a commercially reasonable period; locating and removing Personal Information dispersed across systems is performed through commercially reasonable, good-faith processes. Client acknowledges that removal from backups, caches, logs, and archival copies occurs through the ordinary retention and backup lifecycle rather than instantaneously, and that DS Pro retains the financial, tax, and transaction records described below even where associated identifiers are otherwise redacted.

Order, payout, bookkeeping, invoice, profit, tax/accounting, dispute, audit, and legal records may be retained for the period reasonably required for accounting, tax, business records, platform disputes, chargebacks, enforcement, and legal compliance, generally up to seven years unless a longer period is required or justified by law, dispute, investigation, or preservation obligation.

Any Personal Information retained after the Services end under this Section remains Client Account Operational Data or End-Customer Personal Information unless the limited controller exception in Section 3 applies. Where that exception applies, DS Pro acts as an independent responsible organization or controller solely for the stated legal-claims, tax, accounting, or evidence-preservation purpose, shall restrict access and use accordingly, and shall delete or anonymize the information when that purpose and any applicable legal retention period end. No such role change transfers ownership of Client data. A Schedule requiring deletion at contract expiry or prohibiting this role change controls.

Backups and archival copies may continue to contain Personal Information until overwritten or deleted in the ordinary backup lifecycle. DS Pro will not restore backup data to active systems except as needed for security response, business continuity, disaster recovery, or legal obligations; if Personal Information previously deleted from active systems is restored, DS Pro will re-apply the deletion obligations of this Section 13 within a commercially reasonable period.

De-identified and aggregated data. DS Pro may create, retain, and use indefinitely De-identified Optimization Data. 'De-identified Optimization Data' means information (for example, product, listing, pricing, category, timing, and performance signals) that has been aggregated or otherwise transformed so that it: (a) has had removed or irreversibly transformed all direct identifiers (such as names, usernames, contact details, addresses, account identifiers, order identifiers, and device or machine identifiers) relating to Client, any buyer, recipient, or other individual; and (b) cannot reasonably be used, alone or in combination with other reasonably available information, to identify, single out, be linked to, or support inferences about an identifiable individual or identifiable Client. DS Pro will: (i) maintain reasonable technical and organizational measures designed to prevent re-identification and inadvertent release; (ii) not attempt to re-identify De-identified Optimization Data, except solely to test whether its de-identification process is effective; (iii) contractually require any recipient of De-identified Optimization Data to comply with the restrictions of this paragraph; and (iv) publicly commit, including in the DS ProSolution Privacy Policy, to maintain and use such data only in de-identified form. If DS Pro learns that any such data has been re-identified or no longer meets this standard, DS Pro will treat it as Personal Information under this DPA and promptly re-de-identify, aggregate, or delete it. Where Applicable Privacy Laws impose specific de-identification or anonymization criteria (including generally accepted best practices and prescribed criteria under Quebec law), DS Pro will apply them to data subject to those laws. De-identified Optimization Data is not Personal Information under this DPA, is not subject to the deletion obligations of this Section 13, and may be used for DS Pro's legitimate business purposes, including operating, benchmarking, improving, and training the algorithms and models used to run and optimize the Services across accounts.

14) Regulatory and Mandatory-Law Carveouts

Nothing in this DPA prevents an individual from contacting a competent privacy regulator (as identified in the applicable Schedule), and nothing in this DPA prevents either Party from complying with lawful regulator, court, law-enforcement, platform, or legal-process obligations.

If a regulator, court, platform, or other authority requests Personal Information from DS Pro relating to Client Account Operational Data or End-Customer Personal Information, DS Pro will notify Client where legally permitted and reasonably practicable. DS Pro may respond without prior notice where legally required, where notice is prohibited, or where delay would create material risk.

15) Dispute Resolution and Relationship to MSA

The Parties intend disputes under this DPA to be resolved in the same forum and proceeding as related disputes under the MSA and applicable Order Form, so that privacy, security, account, fee, accounting-reconciliation, onboarding, termination, and service disputes are not split across separate courts or countries.

This DPA does not create a separate accounting-reconciliation process or a separate court or forum. Accounting reconciliation, profit-statement review, invoice questions, and payment disputes remain governed by the MSA and the applicable Order Form. Privacy and security operational issues are handled through this DPA's request, Security Incident, retention, and regulatory-cooperation sections.

Except for non-waivable privacy rights, regulator jurisdiction, individual complaint rights, and mandatory Applicable Privacy Laws, this DPA adopts and is subject to the MSA's governing-law, dispute-resolution, venue, arbitration, remote-proceeding, electronic-service, and enforcement provisions, including any arbitration clause in the MSA or an applicable Order Form.

All liability of either Party arising out of or relating to this DPA and its Schedules is subject to the limitations and exceptions in MSA Section 7.3, which the Parties agree is not a term concerning the processing of personal information for purposes of any precedence rule. Transfer-specific disputes governed by incorporated SCC or IDTA forum and governing-law terms proceed as those terms require; all other disputes remain subject to the MSA's dispute-resolution provisions.

16) Effective Date and Acceptance

This DPA, together with the applicable Schedule, is incorporated into the MSA and effective as of the earliest of: the MSA effective date, Client's signature or electronic acceptance of this DPA, Client's email acceptance of this DPA, or DS Pro's first processing of Personal Information for Client in connection with the Services.

For a Client that previously accepted a data protection agreement with DS Pro, this DPA is effective on Client's signature or electronic or email acceptance and applies prospectively; the prior agreement governs processing before that date, and the Parties agree that DS Pro's continued provision of the Services is good and sufficient consideration for the updated terms.

Electronic signatures, email acceptance, and electronic records are binding to the fullest extent permitted by applicable electronic-signature laws, including ESIGN/UETA and comparable non-U.S. electronic-transaction laws.

The applicable Schedule is agreed upon signature or acceptance of this DPA and does not require separate execution.

Signatures

Applicable Schedule: Schedule A, B or C, whichever matches Client's jurisdiction, selected from Client's jurisdiction and incorporated in full below.

DS ProSolution (RLIM LLC d/b/a DS ProSolution)

Status: Standing offer authorized by RLIM LLC and issued through DS ProSolution's electronic contracting system under MSA Section 9.15.

Client

Legal Name: As recorded in DS ProSolution's acceptance record

By: /electronic acceptance/

Name: As recorded in DS ProSolution's acceptance record

Title or Capacity: As recorded in DS ProSolution's acceptance record

Date: As recorded in DS ProSolution's acceptance record

Appendix A — Processing Schedule

Subject matter: DS Pro's operation, management, bookkeeping, reconciliation, support, security, offboarding, and administration of Client's marketplace, supplier, payment, fulfillment, shipping, and related accounts.

Duration: The MSA and applicable Order Form term, plus any retention period required for offboarding, open transactions, refunds, chargebacks, disputes, accounting, tax, audit, security, legal compliance, and backup lifecycle.

Data subjects: Client, Client representatives, authorized users, buyers, recipients, marketplace users, DS Pro personnel, DS Pro contractors, and support contacts.

Data categories (described by type and purpose):

  • Client identity and contact data, including name, business name if any, mailing address, email, phone number, state or province, country, and signature or acceptance records;
  • account identifiers, including marketplace usernames, registered account emails, marketplace account labels, account IDs, OAuth user IDs, and connected profile identifiers;
  • account-access information, including passwords, OAuth refresh/access tokens, two-factor authentication secrets, network-connection credentials used to maintain secure, stable, and consistent access to Accounts, recovery information, and access-status indicators;
  • payment and billing references, including payment-card last four digits, expiration month and year, billing contact information, payment-processor customer and invoice records, payout instrument references, and payment status;
  • order, fulfillment, and buyer information, including order IDs, item details, buyer usernames, recipient names, shipping addresses, phone numbers when available, tracking data, returns, refunds, disputes, chargebacks, and marketplace message contents;
  • payout, bookkeeping, and financial-performance data, including payout amounts, fees, taxes, funds summaries, costs of goods sold, profit calculations, cash-flow metrics, invoices, subscription transactions, bonuses, and reconciliation records;
  • platform, telemetry, security, and support data, including device or machine identifiers, account-health data, activity logs, audit logs, error logs, support communications, and raw marketplace payloads; and
  • legal, compliance, offboarding, dispute, and audit records needed to administer the Services.

Sensitive Platform Data: Credentials, passwords, OAuth tokens, two-factor authentication secrets, network-connection credentials used to maintain secure, stable, and consistent access to Accounts, payment-card references, payout and funds data, buyer shipping and contact information, message contents, raw marketplace payloads, audit logs, tax/accounting records, and security records. DS Pro is not authorized to retain full payment-card numbers or CVV/security codes.

Processing operations: Collection, access, recording, organization, storage, retrieval, consultation, use, disclosure to authorized Subprocessors and Connected Third-Party Platforms, transmission, matching, reconciliation, restriction, export, deletion, and archival.

Appendix B — Subprocessor and Platform Categories

  • Infrastructure and hosting: database, authentication, storage, application and web hosting, secrets-management, telemetry, logging, monitoring, backup, and security providers.
  • Payments and billing: payment processors, invoicing providers, receipt providers, and accounting-support systems.
  • Communications and support: email, support, notification, collaboration, and customer-communication systems.
  • Connected Third-Party Platforms: marketplace platforms, supplier platforms, shipping providers, payment and payout providers, banking or card providers, and other platforms connected to Client's Accounts or used for the Services.
  • Professional services: legal, accounting, security, compliance, and technical advisers when needed for the Services, disputes, investigations, audits, or legal compliance.

SCHEDULE A — UNITED STATES

Schedule to the DS ProSolution Data Protection Agreement

Version: DPA Schedule A v1.1 (2026-07-15)

This Schedule A attaches to and forms part of the DS ProSolution Data Protection Agreement (the "Master DPA") between RLIM LLC, a New Mexico limited liability company doing business as DS ProSolution ("DS Pro"), and the Client identified in the Master Services Agreement (the "MSA") or applicable Order Form ("Client"). This Schedule applies when Client is located in the United States, as provided in the Master DPA and MSA Section 7.7. Capitalized terms not defined in this Schedule have the meanings given in the Master DPA or, if not defined there, in the MSA.

A.1 Applicable Privacy Laws

"Applicable Privacy Laws" for this Schedule means the U.S. federal and state privacy and data-protection laws applicable to the processing under the Master DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and comparable state privacy laws, in each case to the extent applicable.

A.2 Service-Provider Certification (CCPA/CPRA)

To the extent DS Pro acts as a "service provider" under the CCPA/CPRA (or a comparable role under another state privacy law) with respect to Client Account Operational Data and End-Customer Personal Information, DS Pro certifies that it will:

  • process Personal Information only for the specific business purposes of providing the Services as described in Section 4 of, and Appendix A to, the Master DPA and the applicable Order Form, and not for any other purpose;
  • not "sell" or "share" Personal Information (as those terms are defined under the CCPA/CPRA);
  • not retain, use, or disclose Personal Information outside the direct business relationship with Client, or for any purpose other than the Services, except as permitted by Applicable Privacy Laws;
  • not combine Personal Information with information received from or on behalf of other parties except as permitted under Applicable Privacy Laws;
  • notify Client if DS Pro determines it can no longer meet these obligations;
  • comply with applicable obligations under the CCPA/CPRA and provide the same level of privacy protection as is required of businesses;
  • grant Client the right to take reasonable and appropriate steps, on notice, to help ensure DS Pro uses Personal Information consistently with Client's obligations under Applicable Privacy Laws and to stop and remediate any unauthorized use of Personal Information; and
  • impose on any subcontractor that processes Personal Information for the Services written obligations consistent with this Section A.2.

DS Pro certifies that it understands and will comply with these restrictions.

A.3 Consumer Rights

Taking into account the nature of the processing, DS Pro will assist Client in responding to verifiable requests from individuals to exercise rights under Applicable Privacy Laws (including, to the extent applicable, the rights to know/access, correct, delete, and opt out of the sale or sharing of Personal Information). With respect to their own Personal Information, individuals may exercise these rights as described in the DS ProSolution Privacy Policy by contacting support@dsprosolution.com.

A.4 Regulators

Individuals may direct complaints to the applicable state authority (for California, the California Privacy Protection Agency and/or the California Attorney General), consistent with the Master DPA's regulatory and mandatory-law carveouts.

A.5 Governing Law

Consistent with the Master DPA, this Schedule is governed by the MSA's governing-law provision (New Mexico), except that mandatory provisions of Applicable Privacy Laws apply to the processing of Personal Information regardless of the MSA's governing-law clause.

A.6 Other State Privacy Laws

Where a U.S. state privacy law other than the CCPA/CPRA applies to the processing and requires specific contract terms between a controller and a processor, this Schedule and the Master DPA are deemed to include those terms, including: processing only on documented instructions (Master DPA Section 4); the nature, purpose, type, and duration of processing (Master DPA Appendix A); a duty of confidentiality on persons processing Personal Information (Master DPA Section 7); engagement of subcontractors under written contracts imposing equivalent obligations (Master DPA Section 9 and Section A.2); making available information necessary to demonstrate compliance (Master DPA Section 7); and allowing and cooperating with reasonable assessments as required by those laws, which DS Pro may satisfy, where those laws permit, by providing a report of an assessment conducted by a qualified and independent assessor.

Deletion or return. To the extent DS Pro acts as Client's service provider, contractor, or processor under Applicable Privacy Laws, upon termination or expiry of the Services or at Client's written direction, DS Pro shall, at Client's choice, return or delete the Personal Information processed on Client's behalf and delete existing copies, except to the extent and for the period that applicable law requires retention. Personal Information retained under that exception shall be isolated from ordinary use, used only for the legally required purpose, protected under the Master DPA, and deleted when the requirement ends. If immediate deletion from a backup is technically infeasible, DS Pro shall place the backup copy beyond ordinary use and delete it through the ordinary backup expiration or overwrite cycle, unless Applicable Privacy Laws require an earlier result. DS Pro shall confirm completion on reasonable written request. Payment disputes do not suspend this paragraph. Information validly de-identified so it is no longer Personal Information is outside this paragraph.


SCHEDULE B — CANADA

Schedule to the DS ProSolution Data Protection Agreement

Version: DPA Schedule B v1.1 (2026-07-15)

This Schedule B attaches to and forms part of the DS ProSolution Data Protection Agreement (the "Master DPA") between RLIM LLC, a New Mexico limited liability company doing business as DS ProSolution ("DS Pro"), and the Client identified in the Master Services Agreement (the "MSA") or applicable Order Form ("Client"). This Schedule applies, as provided in the Master DPA and MSA Section 7.7, when Client is located in Canada, when an Account is registered or primarily operated from Canada, or when DS Pro otherwise processes Personal Information subject to Canadian Privacy Laws (as defined in Section B.1) for the Services. Capitalized terms not defined in this Schedule have the meanings given in the Master DPA or, if not defined there, in the MSA.

B.1 Applicable Privacy Laws

"Applicable Privacy Laws" for this Schedule (also referred to in this Schedule as "Canadian Privacy Laws") means Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and any substantially similar or otherwise applicable Canadian federal, provincial, or territorial private-sector privacy law, including the private-sector privacy laws of Quebec, Alberta, and British Columbia, in each case to the extent applicable to the Services.

"Quebec Service Data" means Personal Information subject to Quebec's Act respecting the protection of personal information in the private sector that Client communicates to DS Pro, or that DS Pro collects, uses, communicates, or keeps on Client's behalf, to perform the Services. It excludes DS Pro Business Data collected independently from the individual for DS Pro's own administration and information validly anonymized under section 23 of the Quebec Act and its regulation.

B.2 Accountability and Comparable Protection

The Parties acknowledge that PIPEDA and Canadian provincial privacy laws do not always use the "controller" and "processor" vocabulary used in other jurisdictions. The role descriptions in the Master DPA are contractual allocations of responsibility intended to support PIPEDA accountability, comparable protection for information handled by a service provider, and lawful service-provider processing. DS Pro will use contractual, technical, and organizational measures designed to provide a level of protection comparable to that required by Canadian Privacy Laws for Personal Information it processes and transfers for the Services.

B.3 Cross-Border Processing

Client authorizes DS Pro to process Personal Information in the United States and in other locations where DS Pro or its Subprocessors operate, and acknowledges that such Personal Information may be accessible to courts, law-enforcement, national-security, or regulatory authorities in those jurisdictions under applicable law. On request, DS Pro will describe how it protects such Personal Information. The additional Quebec transfer conditions in Section B.4 apply before any Quebec Service Data is transferred or entrusted outside Quebec.

B.4 Provincial Requirements (Quebec, Alberta, British Columbia)

Quebec transfers. Before Quebec Service Data is communicated outside Quebec or DS Pro or a Subprocessor outside Quebec is entrusted to collect, use, communicate, or keep it on Client's behalf, Client shall complete the privacy impact assessment required of Client by section 17 of the Quebec Act. DS Pro shall timely provide the information reasonably needed for that assessment, including the data categories and sensitivity, processing purposes, destination countries, material Subprocessors, available destination-law information, contractual and technical safeguards, retention, deletion, and proposed risk mitigations. The affected transfer may begin only after Client confirms in writing that its assessment found adequate protection and the Parties execute a Quebec Transfer Addendum identifying the assessment by date or version and recording the contractual measures and agreed mitigation terms resulting from it. DS Pro shall not materially change a documented destination, purpose, Subprocessor, or safeguard until it gives Client information reasonably needed to determine whether the assessment and Addendum must be updated.

If Client is located in Alberta, British Columbia, or another province with additional private-sector privacy requirements, Client will notify DS Pro before onboarding if Client believes those requirements apply to the Services, and DS Pro will provide reasonable assistance and information needed for Client's compliance with those requirements.

Quebec service-provider terms. The MSA, Order Form, Master DPA, this Schedule, the Quebec Transfer Addendum, and the Confidential Quebec Security Measures Annex constitute the written service mandate for Quebec Service Data. DS Pro shall: (a) use Quebec Service Data only to perform the Services on Client's documented instructions; (b) implement the specific confidentiality and security measures stated in the Confidential Quebec Security Measures Annex, which are binding notwithstanding the illustrative wording of Master DPA Section 10; (c) not retain Quebec Service Data after expiry or termination of the applicable Services and, at Client's choice, return or securely destroy it and certify completion; (d) notify Client's designated person in charge of the protection of personal information without delay of any violation or attempted violation by any person of an obligation concerning the confidentiality of Quebec Service Data; (e) permit Client or that designated person to conduct reasonable verification relating to those confidentiality obligations, subject to safeguards for other clients and security-sensitive information; and (f) require every Subprocessor receiving Quebec Service Data to be bound in writing to equivalent confidentiality, service-only use, return or destruction, incident-notice, and verification-support obligations. Master DPA Section 13 does not authorize post-service controller reclassification or continued retention of Quebec Service Data under this paragraph. If applicable law requires DS Pro itself to retain a specific record, DS Pro shall identify the requirement to Client where legally permitted, isolate the minimum required data, and delete it when that requirement ends.

Quebec anonymization. DS Pro may anonymize Quebec Service Data only on Client's documented instruction, for a serious and legitimate purpose identified in the Quebec Transfer Addendum, and in accordance with section 23 of the Quebec Act and the Regulation respecting the anonymization of personal information. DS Pro shall document the purpose, techniques, security measures, re-identification risk analysis, periodic reassessments, and required register entries. Unless and until those requirements are demonstrably satisfied, the information remains Quebec Service Data and is subject to return or destruction at expiry.

B.5 Regulators

Nothing in this Schedule or the Master DPA prevents an individual from contacting the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator (including, for Quebec, the Commission d'accès à l'information).

B.6 Governing Law

Consistent with the Master DPA, this Schedule is governed by the MSA's governing-law provision (New Mexico), except that mandatory provisions of Applicable Privacy Laws apply regardless of the MSA's governing-law clause. This Schedule does not require the Parties to litigate commercial, fee, account, or contract claims in Canada unless non-waivable law requires otherwise. For clarity, nothing in this Section B.6 or the MSA's dispute-resolution provisions limits an individual's right to complain to the Office of the Privacy Commissioner of Canada or an applicable provincial regulator (Section B.5), any regulator's jurisdiction, or any non-waivable statutory right of an individual to bring proceedings before a Canadian court or tribunal following a regulatory process.


SCHEDULE C — UNITED KINGDOM, EEA, AND OTHER INTERNATIONAL

Schedule to the DS ProSolution Data Protection Agreement

Version: DPA Schedule C v1.0 (2026-07-04)

This Schedule C attaches to and forms part of the DS ProSolution Data Protection Agreement (the "Master DPA") between RLIM LLC, a New Mexico limited liability company doing business as DS ProSolution ("DS Pro"), and the Client identified in the Master Services Agreement (the "MSA") or applicable Order Form ("Client"). This Schedule applies, as provided in the Master DPA and MSA Section 7.7, when Client is located outside the United States and Canada (including the United Kingdom and the European Economic Area). Capitalized terms not defined in this Schedule have the meanings given in the Master DPA or, if not defined there, in the MSA. In this Schedule, "Personal Data," "Processing," "Data Subject," "Controller," and "Processor" have the meanings given under Applicable Privacy Laws, and "Personal Data" includes Personal Information as defined in the Master DPA.

C.1 Applicable Privacy Laws

"Applicable Privacy Laws" for this Schedule means all data-protection and privacy laws applicable to the processing under the Master DPA, including the UK GDPR and the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "EU GDPR"), and, for any other non-U.S., non-Canada jurisdiction, that jurisdiction's applicable data-protection law.

C.2 Roles and Lawful Basis

With respect to DS Pro Business Data (including Client identity, contact, and billing information that DS Pro processes to establish, administer, invoice, support, and secure the Services), DS Pro acts as a Controller and is responsible for that processing under this Schedule and the DS ProSolution Privacy Policy. With respect to Client Account Operational Data and End-Customer Personal Information processed through the Accounts, Client is the Controller and DS Pro acts as a Processor, processing such Personal Data only to perform the Services and on Client's documented instructions (including the MSA, the applicable Order Form, and the Master DPA).

Where DS Pro acts as a Controller, DS Pro processes Personal Data to provide, operate, and secure the Services (performance of a contract), to comply with its legal obligations, and for its legitimate interests in operating its business; where DS Pro relies on consent for a specific processing activity, the individual may withdraw that consent at any time.

C.3 International Data Transfers

Personal Data processed under the Master DPA, including Client Account Operational Data and End-Customer Personal Information, is transferred to and processed in the United States, which may not provide the same level of protection as Client's home jurisdiction.

  • EEA. For transfers of Personal Data subject to the EU GDPR from Client (as data exporter and Controller) to DS Pro (as data importer and Processor), the Parties enter into the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), incorporated by reference into and forming part of this Schedule, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general written authorisation) with the notice period in Section C.7(c); the optional language in Clause 11 not used; Clause 17 Option 1, governed by Irish law; Clause 18(b), courts of Ireland; Annex I.A/I.B completed by the Parties' details and Appendix A to the Master DPA (frequency: continuous during the Services); Annex I.C, the supervisory authority of the Member State in which Client is established; Annex II completed by Master DPA Section 10; Annex III completed by Appendix B and the Subprocessor list under Section C.7(c). In the event of conflict, the SCCs prevail for the relevant transfer.
  • United Kingdom. For transfers subject to the UK GDPR, the Parties enter into the UK International Data Transfer Addendum to the EU SCCs (version B1.0), incorporated by reference and completed by the information above (Tables 1–3), with 'Importer and Exporter' selected in Table 4; in the event of conflict, the UK Addendum prevails for the relevant transfer.
  • Execution and exhibit. Execution or electronic acceptance of the Master DPA and this Schedule (including through an electronic in-app acceptance flow) constitutes execution of the SCCs and the UK Addendum by both Parties without separate signature; a completed copy of the SCCs, UK Addendum, and Annexes is deemed an exhibit to this Schedule and is available from DS Pro on request.
  • Transfer assessment. DS Pro maintains a documented transfer impact assessment addressing the laws and practices of the destination country and the measures applied, will make a summary available to Client on request in support of Clause 14 of the SCCs, and will update it on material change.

C.4 Data Subject Rights

Taking into account the nature of the processing, DS Pro will assist Client in responding to Data Subject requests under Applicable Privacy Laws (including access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent). With respect to their own Personal Data, individuals may exercise these rights as described in the DS ProSolution Privacy Policy by contacting support@dsprosolution.com.

C.5 Regulators and Complaints

Individuals in the United Kingdom may lodge a complaint with the Information Commissioner's Office (ICO); individuals in the EEA may complain to their competent supervisory authority; and individuals in other jurisdictions may contact their applicable data-protection authority, consistent with the Master DPA's regulatory and mandatory-law carveouts.

C.6 Governing Law

Consistent with the Master DPA, this Schedule is governed by the MSA's governing-law provision (New Mexico), except that mandatory provisions of Applicable Privacy Laws (and any incorporated SCC or IDTA governing-law and forum terms for the relevant transfer) apply regardless of the MSA's governing-law clause.

C.7 Additional Processor Terms — Article 28

(a) Instructions. The MSA, the applicable Order Form, the Master DPA, and this Schedule are Client's complete documented instructions; additional instructions require written agreement.

(b) Security. Master DPA Section 10 describes the technical and organisational measures required of DS Pro pursuant to Article 32, appropriate to the nature, scope, context, and purposes of the processing and the risks to individuals.

(c) Subprocessors. Client grants general written authorisation for the Subprocessor categories in Appendix B. DS Pro will maintain and make available a current Subprocessor list and will give Client at least 10 business days' notice (by email or a designated notification mechanism) before a new Subprocessor processes Personal Data under this Schedule, during which Client may object under Master DPA Section 9. DS Pro will impose on each such Subprocessor data-protection obligations in substance no less protective than this DPA, to the extent applicable to the Subprocessor's services.

(d) Assistance. Taking into account the nature of the processing and the information available to DS Pro, DS Pro will provide reasonable assistance with Client's obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments, and prior consultation).

(e) Audit and information. DS Pro will make available the information reasonably necessary to demonstrate compliance with Article 28 and, where that information is insufficient, will allow and contribute to audits, satisfied in the first instance by written responses and summaries of relevant policies and assessments; a remote or on-site audit may occur no more than once per 12 months (or as required by a supervisory authority or following a confirmed Security Incident), on at least 20 business days' notice, during business hours, at Client's cost, subject to confidentiality and without access to other clients' data or DS Pro trade secrets.

(f) Return or deletion. On termination or expiry of the Services, at Client's election, DS Pro will delete or return Personal Data processed under this Schedule and delete existing copies, in accordance with the timing, backup-lifecycle, and de-identification provisions of Master DPA Section 13, except where and for so long as storage is required by applicable law, in which case the retained-records provisions of Master DPA Section 13 (including DS Pro's role for such records) apply.