DATA PROCESSING ADDENDUM

Data Processing Addendum

Effective Date: August 27, 2026 · Last Updated: August 27, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Sunshower, Inc., doing business as FileWisely (“FileWisely,” “Processor,” “Service Provider,” “we,” “us,” or “our”) and the business or organization using the FileWisely Services (“Customer,” “Controller,” or “Business”).

This DPA applies where FileWisely processes Personal Data on behalf of Customer in connection with the FileWisely Services.

If there is a conflict between this DPA and the FileWisely Terms of Service regarding the processing of Personal Data, this DPA controls with respect to that conflict.

1. Definitions

“Applicable Data Protection Law” means privacy, data-protection, and security laws applicable to the processing of Personal Data under this DPA.

“Customer Data” means data submitted to, transmitted through, stored in, or generated through the Services on behalf of Customer.

“Personal Data” means information relating to an identified or identifiable individual and includes “personal information,” “personal data,” and similar terms defined under Applicable Data Protection Law.

“Processing” means any operation performed on Personal Data, including collection, storage, access, use, disclosure, transmission, analysis, modification, deletion, or destruction.

“Subprocessor” means a third party engaged by FileWisely to Process Personal Data on behalf of Customer.

2. Roles of the Parties

For Personal Data that FileWisely Processes on behalf of Customer: Customer acts as the Controller, Business, or equivalent entity under Applicable Data Protection Law. FileWisely acts as the Processor, Service Provider, Contractor, or equivalent entity.

Customer determines the purposes and means of the Processing.

FileWisely will Process Personal Data only: to provide the Services, according to Customer’s documented instructions, as described in the applicable agreement, and as required by law.

If FileWisely is legally required to Process Personal Data contrary to Customer instructions, FileWisely will notify Customer where permitted by law.

3. Customer Instructions

The agreement between the parties, Customer’s configuration of the Services, and Customer’s lawful use of FileWisely constitute documented instructions to FileWisely.

Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law.

FileWisely may notify Customer if, in FileWisely’s reasonable judgment, an instruction violates Applicable Data Protection Law.

4. Nature and Purpose of Processing

FileWisely may Process Personal Data to provide functionality including account management, customer communications, telephone services, SMS and messaging, email processing, voicemail, call recording and transcription, document management, digital authorizations, repair and job workflow management, scheduling, customer portals, payment-related functionality, invoice and document processing, reporting, AI-assisted features, security, support, integrations, and other functionality requested or configured by Customer.

5. Categories of Personal Data

Depending on Customer’s use of the Services, Personal Data may include names, email addresses, phone numbers, mailing addresses, account identifiers, user credentials, employment or role information, vehicle information, repair information, claim-related information, communications, emails, text messages, telephone recordings, voicemail, transcripts, images, documents, invoices, payment-related information, transaction information, signatures, appointment information, IP addresses, device information, system usage information, and information submitted to AI-powered features.

6. Categories of Data Subjects

Personal Data may relate to Customer employees, Customer contractors, Customer administrators, Customer users, Customer customers, vehicle owners, insurance representatives, vendors, repair partners, business contacts, prospective customers, and other persons whose information Customer lawfully processes through FileWisely.

7. Duration of Processing

FileWisely may Process Personal Data for the duration of Customer’s use of the Services and afterward as reasonably necessary to comply with law, maintain security, resolve disputes, prevent fraud, enforce agreements, complete backup cycles, and satisfy legitimate record-retention requirements.

8. Confidentiality

FileWisely will ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations. Access to Personal Data will be limited to personnel and service providers who reasonably require access to perform authorized functions.

9. Security Measures

FileWisely will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, unauthorized disclosure, accidental loss, unlawful destruction, alteration, and misuse.

Security measures may include encryption in transit, encryption at rest where supported, authentication, access controls, least-privilege access, logging, monitoring, secure development practices, vulnerability management, backups, incident-response procedures, and security controls for service providers.

No security system can be guaranteed to be completely secure.

10. Security Incidents

FileWisely will notify Customer without undue delay after becoming aware of a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed on behalf of Customer (“Security Incident”).

The notice will include available information reasonably necessary for Customer to understand the nature and potential impact of the Security Incident. FileWisely will take reasonable steps to investigate, mitigate, and remediate the Security Incident.

A Security Incident does not include unsuccessful attempts or activities that do not compromise Personal Data, such as blocked login attempts, probes, scans, or unsuccessful attacks.

11. Subprocessors

Customer authorizes FileWisely to use Subprocessors to provide the Services. Subprocessors may include providers of cloud hosting, databases, communications, telephony, SMS, email, artificial intelligence, payment infrastructure, analytics, monitoring, authentication, storage, and other technology infrastructure.

FileWisely will require Subprocessors that Process Personal Data on FileWisely’s behalf to maintain data-protection obligations appropriate to the services they provide. FileWisely remains responsible for its obligations under this DPA to the extent required by Applicable Data Protection Law.

12. Data Subject Requests

Where required by Applicable Data Protection Law, FileWisely will provide reasonable assistance to Customer in responding to individuals seeking to exercise privacy rights, including rights relating to access, correction, deletion, portability, restriction, objection, and other applicable rights.

If FileWisely receives a request relating primarily to Personal Data controlled by Customer, FileWisely may refer the individual to Customer unless prohibited by law. Customer remains responsible for responding to the request.

13. California Privacy Requirements

To the extent California privacy laws apply, FileWisely will act as a Service Provider or Contractor with respect to Personal Information Processed on behalf of Customer.

FileWisely will not sell Customer Personal Information, share Customer Personal Information for cross-context behavioral advertising, retain, use, or disclose Customer Personal Information outside the direct business relationship with Customer except as permitted by law, or combine Customer Personal Information with information received from another person except as permitted by law.

FileWisely may Process Personal Information as reasonably necessary to provide, secure, maintain, support, and improve the Services where permitted by applicable law.

14. Sale and Sharing of Data

FileWisely does not sell Customer Personal Data for monetary consideration. FileWisely will not disclose Customer Personal Data to third parties for their independent direct-marketing purposes except at Customer’s direction or with legally sufficient authorization.

Mobile phone numbers and SMS opt-in consent information will not be sold or shared with third parties for their independent marketing purposes.

15. Artificial Intelligence Processing

Customer authorizes FileWisely to Process Personal Data using artificial-intelligence and machine-learning providers where necessary to provide AI-enabled Services. Such Processing may include summarization, extraction, classification, document analysis, communications analysis, drafting, workflow recommendations, search, and other related automated processing.

Customer is responsible for ensuring it has lawful authority to submit Personal Data to AI-enabled features.

16. International Data Transfers

Personal Data may be Processed in the United States and other jurisdictions in which FileWisely or its Subprocessors operate. Where Applicable Data Protection Law requires specific safeguards for international transfers, the parties will cooperate in implementing an appropriate lawful transfer mechanism.

17. Audits and Compliance Information

Upon reasonable written request, FileWisely will provide information reasonably necessary to demonstrate compliance with this DPA. Where required by Applicable Data Protection Law, Customer may conduct or commission an audit concerning FileWisely’s Processing of Personal Data.

Audits must occur no more than once annually unless a Security Incident or legal requirement reasonably requires additional review, be conducted during normal business hours, provide reasonable advance notice, avoid unreasonable disruption, and protect FileWisely confidential information and other Customer information.

FileWisely may satisfy reasonable audit requests through available third-party security assessments, certifications, reports, questionnaires, or similar documentation where reasonably sufficient.

18. Regulatory Assistance

Taking into account the nature of Processing and information available to FileWisely, FileWisely will provide reasonable assistance relating to privacy impact assessments, regulatory consultations, security incident obligations, and other obligations required under Applicable Data Protection Law. Customer remains responsible for determining whether those obligations apply.

19. Return and Deletion of Data

Following termination of the Services, FileWisely will delete or return Personal Data upon Customer request, subject to technical feasibility, backup cycles, security requirements, legal obligations, fraud-prevention requirements, and legitimate record-retention obligations.

Data retained following termination will remain protected under this DPA for as long as FileWisely Processes it on Customer’s behalf.

20. Customer Responsibilities

Customer represents that it has a lawful basis for Processing Personal Data through FileWisely, it has provided legally required privacy notices, it has obtained legally required consents, its instructions comply with Applicable Data Protection Law, and it will not instruct FileWisely to Process Personal Data unlawfully.

Customer remains responsible for laws applicable specifically to its industry, operations, communications, employees, and customers.

21. Call Recording and Communications

Customer is responsible for determining whether notice or consent is required before recording telephone calls, monitoring communications, sending automated calls, sending SMS messages, and using AI-powered communications. Customer will obtain any legally required consent.

FileWisely provides the technical functionality but does not determine whether Customer’s particular communication is lawful.

22. Payment Information

Certain payment data may be collected and processed directly by third-party payment processors. To the extent payment credentials are processed directly by such providers and are not received by FileWisely, those providers operate according to their applicable terms and privacy obligations.

FileWisely may Process transaction metadata and other payment-related information necessary to provide payment functionality.

23. Limitation of Liability

The liability of each party arising from this DPA is subject to the applicable limitations of liability contained in the FileWisely Terms of Service or other agreement between the parties, except where prohibited by Applicable Data Protection Law.

24. Term

This DPA remains in effect for as long as FileWisely Processes Personal Data on behalf of Customer. Provisions relating to confidentiality, security, deletion, liability, and regulatory obligations will survive termination where necessary to fulfill their purpose.

25. Governing Law and Dispute Resolution

This DPA is governed by the same governing-law and dispute-resolution provisions contained in the FileWisely Terms of Service unless Applicable Data Protection Law requires otherwise.

26. Contact Information

Questions regarding this DPA may be directed to: Sunshower, Inc. d/b/a FileWisely, 730 W 17th St, Costa Mesa, CA 92627. Privacy: privacy@filewisely.com. Legal: legal@filewisely.com. Support: support@filewisely.com. Phone: 949-776-0237.

Appendix A — Processing Details

Subject Matter: Providing the FileWisely software platform and related Services.

Processing Duration: For the duration of the Customer relationship and any applicable retention period.

Nature of Processing: Collection, organization, storage, hosting, transmission, retrieval, analysis, classification, transcription, summarization, modification, disclosure at Customer direction, deletion, and other Processing necessary to provide the Services.

Purposes of Processing: Providing, operating, securing, supporting, and improving FileWisely functionality requested by Customer.

Categories of Data Subjects: Customer personnel, Customer customers, prospective customers, vehicle owners, insurers, vendors, repair partners, and other authorized business contacts.

Categories of Personal Data: Contact information, communications, repair information, vehicle information, documents, recordings, transcripts, payment-related information, account information, device information, usage information, and other information submitted by Customer.