Data Processing Agreement

Effective Date: July 26, 2026

Processor: Motus Labs LLC, a Wyoming limited liability company, with a registered address at 30 N Gould St, Sheridan, WY 82801 (“Motus Labs,” “Processor”)

Contact: legal@motuslabsllc.com

 

Applies to: Zyntriq Dispatch (the “Service”).

This Data Processing Agreement (“DPA”) forms part of the agreement between Motus Labs LLC (“Processor,” “Motus Labs”) and the customer entity that has agreed to the Terms of Service and/or an enterprise order form referencing this DPA (“Customer,” “Controller”), governing Motus Labs’ processing of personal data on Customer’s behalf in connection with Zyntriq Dispatch. This DPA is intended for enterprise customers and customers in regulated industries who require contractual data-processing terms beyond the standard Privacy Policy.

1. Definitions

Terms such as “personal data,” “processing,” “controller,” “processor,” “sub-processor,” and “data subject” have the meanings given in applicable Data Protection Law (including GDPR and, where applicable, CCPA/CPRA, using the analogous terms “business” and “service provider”).

2. Roles of the Parties

Customer is the Controller (or “business”) of personal data submitted to the Service. Motus Labs is the Processor (or “service provider”) and will process personal data only as necessary to provide the Service and in accordance with Customer’s documented instructions, except where otherwise required by law.

3. Scope, Nature, and Purpose of Processing

Details of processing are set out in Annex I, including the subject matter, duration, nature, purpose of processing, categories of data, and categories of data subjects. In general, processing is limited to what is necessary to operate Zyntriq Dispatch (dispatch scheduling and routing data) for the duration of the underlying commercial agreement.

4. Processor Obligations

Motus Labs will: (a) process personal data only on Customer’s documented instructions, including regarding international transfers, unless required otherwise by law (in which case Motus Labs will notify Customer, where legally permitted); (b) ensure personnel authorized to process personal data are bound by confidentiality obligations; (c) implement appropriate technical and organizational measures as described in Annex II; (d) assist Customer, at Customer’s reasonable expense, in responding to data subject requests and in meeting obligations relating to security, breach notification, and data protection impact assessments; and (e) make available information reasonably necessary to demonstrate compliance with this DPA.

5. Sub-processors

Customer authorizes Motus Labs to engage sub-processors to support the Service, including cloud hosting, database/backend infrastructure, mapping/routing, and messaging/notification providers. Motus Labs will: (a) maintain a current list of sub-processors available upon request to legal@motuslabsllc.com; (b) provide advance notice of any new sub-processor with a material role in processing personal data; (c) allow Customer to object on reasonable data-protection grounds within 15 days of notice; and (d) impose data protection obligations on sub-processors substantially similar to those in this DPA. Motus Labs remains liable for sub-processors’ acts and omissions.

6. Data Subject Requests

If Motus Labs receives a request from a data subject relating to Customer’s data, Motus Labs will promptly forward it to Customer and will not respond directly except to confirm receipt, unless legally required or instructed by Customer.

7. Security Measures

Motus Labs implements the technical and organizational security measures described in Annex II, designed to ensure a level of security appropriate to the risk, including encryption in transit, access controls, logging, and vendor security review.

8. Breach Notification

Motus Labs will notify Customer without undue delay, and in any event within 48 hours of becoming aware, of any confirmed personal data breach affecting Customer’s data, providing information reasonably necessary for Customer to meet its own regulatory notification obligations (e.g., the 72-hour window under GDPR Article 33), and will cooperate in good faith on remediation.

9. International Data Transfers

Where personal data is transferred outside the country of origin (including to the United States), the parties will rely on an appropriate transfer mechanism, such as the EU Standard Contractual Clauses (2021 version, correct module for the transfer type) or another lawful transfer mechanism, which the parties agree are incorporated by reference where required.

10. Audit Rights

Motus Labs will make available on request a summary of its security practices and, where applicable, current third-party security certifications or assessments. Customer (or an independent auditor bound by confidentiality) may request an audit of Motus Labs’ compliance with this DPA no more than once per year, or following a confirmed security incident, on reasonable notice and during business hours, at Customer’s expense.

11. Return or Deletion of Data

Upon termination of the underlying agreement, Motus Labs will, at Customer’s choice, delete or return all personal data processed on Customer’s behalf within 60 days, except to the extent retention is required by law.

12. Liability

Liability under this DPA is subject to the limitation of liability set out in our Terms of Service, except where applicable Data Protection Law prohibits such limitation.

13. Term and Termination

This DPA remains in effect for as long as Motus Labs processes personal data on Customer’s behalf under the Service, and survives termination of the underlying agreement solely with respect to obligations relating to previously processed data.

Annex I — Description of Processing

ItemDescription
Subject matterProvision of Zyntriq Dispatch
DurationTerm of the underlying agreement plus any post-termination retention/deletion period
Nature and purposeHosting, storage, transmission, and processing of Customer data to deliver dispatch scheduling and routing functionality
Categories of dataAccount/contact data, dispatch and scheduling data
Categories of data subjectsCustomer’s employees, contractors, dispatch personnel, and end customers

Annex II — Technical and Organizational Security Measures

  • Encryption of data in transit (TLS) and, where applicable, at rest.
  • Role-based access controls and least-privilege access to production systems.
  • Authentication controls for administrative and API access, including credential rotation practices.
  • Logging and monitoring of access to systems processing personal data.
  • Vendor security review for sub-processors handling personal data.
  • Defined incident response process, including the breach notification commitment in Section 8.