Data Processing Agreement

Onion — The Coding Company, S.L.

Version 1.0 — Effective September 6th 2026

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the agreement between:

The Coding Company, S.L., a Spanish sociedad limitada with CIF B-44697217, registered office at c/ Pompeu Fabra 3, 17320 Tossa de Mar, Girona, Spain, trading as Onion ("Onion", "we", "us"); and

the customer identified in the applicable order form or services agreement ("Customer", "you"),

(each a "Party" and together the "Parties").

Corporate transition. Onion's business is in the process of being transferred to Onion, S.L., a Spanish sociedad limitada in registration with registered office in Barcelona, Spain. Upon completion of that registration and transfer, Onion, S.L. will succeed to this DPA and to the underlying services agreement by operation of the transfer, and references to "Onion" will be read accordingly. Onion will notify the Customer in writing when the transfer takes effect. The transfer does not change the scope, purposes or security of the processing described in this DPA, and no personal data leaves the European Union as a result of it.

This DPA governs the processing of personal data carried out by Onion on the Customer's behalf in connection with the Onion platform and related services (the "Services"). It applies from the effective date above and remains in force for as long as Onion processes personal data on the Customer's behalf.

Where the underlying services agreement or terms of service conflict with this DPA in respect of the processing of personal data, this DPA prevails.

2. Definitions

Terms used but not defined in this DPA — including "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" — have the meanings given to them in the GDPR.

"Applicable Data Protection Law" means Regulation (EU) 2016/679 ("GDPR"), Spanish Organic Law 3/2018 ("LOPDGDD"), the UK GDPR and Data Protection Act 2018 where applicable, and any other data protection or privacy law applicable to the processing under this DPA.

"Customer Personal Data" means personal data that Onion processes on the Customer's behalf under the Services, as described in Annex I.

3. Roles of the Parties

3.1 Customer Personal Data. In respect of Customer Personal Data, the Customer acts as controller and Onion acts as processor. Where the Customer is itself a processor acting on behalf of a third-party controller, Onion acts as sub-processor and the Customer warrants that it has the authority of that controller to enter into this DPA.

3.2 Independently sourced data. The Services also make use of business contact and firmographic data that Onion obtains independently from licensed B2B data providers and from publicly available sources. Onion determines the purposes and means of that collection and therefore acts as controller in respect of it. That processing is not governed by this DPA; it is described in Onion's privacy policy at https://onionos.io/privacy, which sets out Onion's lawful basis and the transparency information required by Article 14 GDPR. Where such data is subsequently combined with, or delivered into, the Customer's systems at the Customer's instruction, the Customer acts as controller of the resulting records within its own environment.

3.3 Independent controllers. Each Party is separately responsible for its own compliance with Applicable Data Protection Law in respect of the processing for which it is controller. Nothing in this DPA creates a joint controllership between the Parties unless expressly agreed in writing.

4. Subject matter and details of processing

The subject matter, duration, nature and purpose of the processing, the categories of personal data and of data subjects, are set out in Annex I. The Customer may update Annex I where its use of the Services changes materially.

5. Processing on documented instructions

5.1 Onion processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which Onion is subject. In that case, Onion will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

5.2 The Customer's instructions are given by: (a) this DPA and the underlying services agreement; (b) the configuration choices and authorizations the Customer makes within the platform, including which integrations it connects and which scopes it grants; and (c) any further written instructions the Parties agree.

5.3 Onion will inform the Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. Onion may suspend the affected processing until the instruction is confirmed, amended or withdrawn.

5.4 Onion does not sell Customer Personal Data, and does not use it to train machine learning models, for its own product development, or for any purpose other than providing the Services to the Customer.

6. Customer authorizations and scope of access

6.1 No access to the Customer's systems is required to use the Services. Access to a Customer system is established only where the Customer enables the corresponding integration and authorizes it on its own side through that system's standard authorization flow.

6.2 Onion requests only those permissions and scopes required by the functionality the Customer has enabled. The Customer may revoke any authorization at any time; Onion will cease the corresponding processing without undue delay, and the Customer acknowledges that the dependent functionality will no longer operate.

7. Confidentiality

Onion ensures that persons authorized to process Customer Personal Data are subject to an appropriate statutory or contractual duty of confidentiality, that access is limited to those personnel who need it to provide the Services, and that such access is withdrawn when it is no longer required.

8. Security

8.1 Onion implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. Those measures are described in Annex II.

8.2 Onion may update the measures in Annex II from time to time provided the level of protection is not reduced.

9. Sub-processors

9.1 General authorization. The Customer grants Onion general authorization to engage sub-processors for the provision of the Services. The sub-processors engaged as at the effective date are listed in Annex III and published at https://onionos.io/privacy.

9.2 Notice and objection. Onion will notify the Customer at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. The Parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected Services without penalty for the remainder of the then-current term.

9.3 Flow-down and liability. Onion imposes on each sub-processor, by written contract, data protection obligations at least as protective as those in this DPA. Onion remains fully liable to the Customer for the performance of each sub-processor's obligations.

10. International transfers

10.1 Customer Personal Data is hosted within the European Union. Onion does not transfer Customer Personal Data outside the European Economic Area except as set out in Annex III.

10.2 Where a transfer to a third country not covered by an adequacy decision is necessary, it is made under the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module Three, processor to processor, where applicable), which are incorporated into this DPA by reference and completed by the information in Annexes I to III. Onion applies encryption in transit and at rest as supplementary measures and has carried out a transfer impact assessment in respect of each such transfer, available to the Customer on request.

10.3 In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

11. Assistance with data subject rights

11.1 Onion provides the Customer with functionality within the platform to access, correct, export and delete Customer Personal Data, so that the Customer can respond to data subject requests itself.

11.2 Where a data subject request cannot be fulfilled through that functionality, Onion will provide reasonable assistance to the Customer at no additional charge, taking into account the nature of the processing and the information available to Onion. Where requests are manifestly unfounded, excessive, voluminous or repetitive, Onion may charge a reasonable fee reflecting the administrative cost of providing the assistance, notified to the Customer in advance.

11.3 If a data subject contacts Onion directly in respect of Customer Personal Data, Onion will not respond to the substance of the request but will forward it to the Customer without undue delay.

12. Personal data breach

12.1 Onion will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data.

12.2 The notification will describe, to the extent known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. Where the information cannot be provided at once, it will be provided in phases without further undue delay.

12.3 Onion will cooperate with the Customer and take the steps reasonably requested to assist in the investigation, mitigation and remediation of the breach, including assisting the Customer with its obligations under Articles 33 and 34 GDPR.

12.4 Onion will not notify a supervisory authority or any data subject on the Customer's behalf, or make any public statement identifying the Customer in connection with a breach, without the Customer's prior written consent, unless required by law.

13. Data protection impact assessments

Taking into account the nature of the processing and the information available to it, Onion will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR.

14. Deletion and return

14.1 On termination or expiry of the Services, the Customer may export its data through the platform's export functionality.

14.2 Onion will delete Customer Personal Data within 90 days of the end of the contract, unless Union or Member State law requires continued storage. Accounting records are retained for six years in accordance with the Spanish Commercial Code. Security logs are retained for 12 months.

14.3 Backups containing Customer Personal Data are overwritten in the ordinary course of the backup cycle and are deleted no later than 30 days after the primary data. Until deletion, such data remains subject to this DPA.

14.4 Onion will certify deletion in writing on the Customer's request.

15. Audits and information

15.1 Onion makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including its current CASA Tier 3 assessment status, a summary of its most recent independent penetration test, and its published sub-processor list.

15.2 Where that information is insufficient, the Customer may conduct an audit, or mandate an independent auditor bound by confidentiality to do so, no more than once in any twelve-month period and on at least 30 days' written notice, during normal business hours and without unreasonably disrupting Onion's operations. The Customer bears the cost of the audit unless it reveals a material breach of this DPA. Additional audits may be conducted where required by a supervisory authority or following a personal data breach affecting Customer Personal Data.

15.3 Onion is not required to disclose information that would compromise the security or confidentiality of other customers' data, or its own confidential commercial information.

16. Liability and term

16.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the underlying services agreement.

16.2 This DPA takes effect on the effective date and continues for the duration of the Services and thereafter for as long as Onion processes Customer Personal Data.

17. Governing law and jurisdiction

This DPA is governed by the laws of Spain. The Parties submit to the exclusive jurisdiction of the courts of Girona, Spain, and, following completion of the corporate transition described in clause 1, to the exclusive jurisdiction of the courts of Barcelona, Spain. This is without prejudice to any mandatory rights of data subjects or to the jurisdiction of any competent supervisory authority.

18. Contact

Data protection enquiries relating to this DPA: privacy@onionos.io

Security enquiries and personal data breach notifications: security@onionos.io


Annex I — Details of the processing

Subject matter. Provision of the Onion commercial operations platform, including data ingestion, enrichment, validation, scoring, routing, workflow automation, scheduling and activation to the Customer's connected systems.

Duration. For the term of the services agreement, plus the retention periods set out in clause 14.

Nature and purpose of processing. Collection, structuring, storage, enrichment, analysis, classification, retrieval, transmission to the Customer's connected systems, and erasure, all for the purpose of providing the Services to the Customer.

Categories of data subjects.

  • The Customer's personnel who use the platform (authorized users)

  • Business contacts and prospects within the Customer's connected systems

  • Individuals whose business contact details are contained in records the Customer imports or syncs

Categories of personal data.

  • Account data: name, business email address, authentication identifiers, role and permissions, activity logs

  • Business contact data: name, business email address, business telephone number, job title, employer, professional profile information

  • Data from connected systems, where the Customer enables the integration: CRM records (contacts, accounts, deals, pipelines, activity history); email metadata and content within the scope authorized by the Customer; calendar free/busy availability; messaging, helpdesk and customer success records within the authorized scope

Special categories of personal data. None. The Services are not designed for, and must not be used to process, special categories of personal data under Article 9 GDPR, or personal data relating to criminal convictions and offences.

Frequency of transfer. Continuous, for the duration of the Services.


Annex II — Technical and organisational measures

Hosting and data residency. Customer Personal Data is hosted on Google Cloud infrastructure in European Union regions.

Encryption. All data is encrypted at rest using AES-256 and in transit using TLS. Key management is performed by the cloud platform.

Access control. Authentication to the platform is provided by Firebase Authentication, supporting email and password, Login with Google and Login with Microsoft. Passwords are stored hashed and salted using a memory-hard function; Onion never handles password material in plaintext. Internal access to production systems is restricted to authorized personnel on a least-privilege basis, and the majority of internal application access is federated through Google Workspace single sign-on with two-factor authentication enforced at the identity provider. Onion is progressively bringing remaining direct-login accounts under that same federation.

Integration authorizations. Access to Customer systems is established only through Customer-authorized OAuth or API grants, scoped to the functionality enabled, and revocable by the Customer at any time.

Backups and resilience. Automated backups are taken daily and retained for 30 days, within the same EU regions and subject to the same encryption and access controls as primary data.

Security assessment and testing. Onion holds a CASA (Cloud Application Security Assessment) Tier 3 certification, which includes an annual independent penetration test against the OWASP Application Security Verification Standard. Dependency and vulnerability scanning is performed on an ongoing basis.

Vulnerability remediation. Vulnerabilities materially affecting security are triaged by severity and remediated within the following targets, measured from confirmation of the finding:

Severity Remediation target Critical 7 days High 30 days Medium 90 days Low Next scheduled release cycle

Onion's deployment pipeline supports same-day release of security fixes where the severity of a finding warrants it.

Logging and monitoring. Security and access logs are retained for 12 months.

Personnel. Personnel with access to Customer Personal Data are bound by confidentiality obligations and receive data protection guidance appropriate to their role.

Deletion. Data is deleted in accordance with clause 14 and the retention periods published in Onion's privacy policy.


Annex III — Authorized sub-processors

Sub-processor Entity and location Purpose Transfer mechanism Google Cloud Google Cloud EMEA Limited, Ireland Application hosting and databases (EU regions) Within EEA Google Calendar API Google Ireland Limited, Ireland Calendar free/busy availability Within EEA Microsoft Graph API Microsoft Ireland Operations Limited, Ireland Calendar free/busy availability Within EEA Framer Framer B.V., Netherlands Website hosting and website analytics Within EEA Anthropic Anthropic, PBC, United States AI classification and enrichment SCCs (2021/914) + supplementary measures OpenAI OpenAI, L.L.C., United States AI classification and enrichment SCCs (2021/914) + supplementary measures Slack Slack Technologies Limited, Ireland Internal communications Within EEA Mailjet Sinch, France Transactional and marketing email delivery Within EEA Licensed B2B data providers See privacy policy Enrichment sources As published

The current list is maintained at https://onionos.io/privacy. Changes are notified in accordance with clause 9.2.

FREE REVIEW

Get a free review of your commercial setup

A short review of your current commercial setup, how your strategy, systems and execution work together, and where the gaps are. We’ll then show you how Onion could fit into your existing process and help build a more repeatable commercial operating model.