← Front Row Desk

Data Processing Addendum (DPA)

Effective Date: September 20, 2026

Overview: This DPA governs Front Row Desk’s processing of customer personal data on behalf of business clients in compliance with GDPR Article 28, UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).

1. Background & Scope

This Data Processing Addendum ("DPA") supplements and forms part of the Terms of Service, Master Subscription Agreement ("MSA"), or other written agreement between Front Row Desk ("Front Row Desk", "Processor", "we", or "us") and the customer agreeing to this DPA ("Customer", "Controller", or "you") governing your use of the Services (the "Agreement"). This DPA applies to the processing of Personal Data by Front Row Desk on behalf of Customer in connection with providing the Services under the Agreement, in accordance with Data Protection Laws including: • The General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"). • The UK General Data Protection Regulation and UK Data Protection Act 2018 ("UK GDPR"). • The Swiss Federal Act on Data Protection ("FADP"). • The California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). • Other applicable state, federal, or national data privacy regulations.

2. Definitions & Roles

For the purposes of this DPA: • "Customer Data" means all electronic data, communications, text messages, audio, media, contact details, calendar entries, and materials submitted, synced, or forwarded to Customer's workspace. • "Personal Data" means any Customer Data that identifies or relates to an identified or identifiable natural person. • "Controller" and "Processor" (or "Business" and "Service Provider" under the CCPA) have the meanings given in applicable Data Protection Laws. • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates. Roles of the Parties: The parties acknowledge and agree that Customer is the Controller (or Business) of Customer Personal Data, and Front Row Desk is the Processor (or Service Provider) acting on behalf of Customer.

3. Details & Nature of Processing

Subject Matter: The provision, operation, maintenance, and support of the Front Row Desk software platform as described in the Agreement. Duration: The duration of Customer's subscription term plus any post-termination retention period specified in Section 10 of this DPA. Nature & Purpose: • Unified communication aggregation across channels (SMS, WhatsApp, Instagram DM, Facebook Messenger, email, web chat, and voice call logs). • Intent detection, automated message classification, semantic vector search, and AI-assisted reply drafting. • Appointment scheduling, two-way calendar sync, and automated appointment reminders. • Contact management, CRM deal progression, and team task tracking. Categories of Data Subjects: Customer's end-clients, leads, prospects, communication partners, and Customer's authorized workspace team members. Types of Personal Data: Contact details (names, phone numbers, email addresses, social profile usernames), communication contents and message histories, scheduling metadata, notes, and task assignments.

4. Processor Obligations

Front Row Desk covenants and agrees that it will: 1. Documented Instructions: Process Customer Personal Data solely on documented instructions from Customer (including those set forth in the Agreement, this DPA, and via Customer's configuration of the platform), unless required to do so by applicable law. 2. Confidentiality: Ensure that all employees, contractors, and agents authorized to process Customer Personal Data are under enforceable statutory or contractual duties of confidentiality. 3. Security of Processing: Implement and maintain appropriate technical and organizational measures ("TOMs") designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as detailed in Section 8. 4. Data Subject Requests: Taking into account the nature of the processing, assist Customer by appropriate technical measures to enable Customer to respond to requests from Data Subjects exercising their rights under Data Protection Laws (e.g., access, rectification, erasure, portability, or restriction). 5. Compliance Assistance: Provide reasonable assistance to Customer in ensuring compliance with Customer's obligations regarding security, breach notification, and Data Protection Impact Assessments (DPIAs), where required.

5. California Consumer Privacy Act (CCPA/CPRA) Terms

To the extent Customer Personal Data includes Personal Information of California residents, Front Row Desk certifies that it acts as a "Service Provider" and: • Shall not "sell" or "share" Customer Personal Information as those terms are defined under the CCPA/CPRA. • Shall not retain, use, or disclose Customer Personal Information for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing Personal Information outside the direct business relationship. • Shall not combine Customer Personal Information with personal information received from or on behalf of any other person or entity, except as expressly permitted under the CCPA/CPRA. • Understands and complies with all applicable restrictions and requirements under Cal. Civ. Code § 1798.140.

6. Artificial Intelligence & Foundation Models

Front Row Desk utilizes third-party artificial intelligence APIs (including Anthropic Claude, OpenAI, and Voyage AI) to provide message classification, semantic caching, and response drafting. Processor Commitments Regarding AI Processing: 1. No Model Training: Processor ensures and contractually binds all subprocessor AI providers that Customer Personal Data shall NOT be used to train, retrain, fine-tune, or improve public foundation artificial intelligence models. 2. Transient Inference: Data submitted for classification and drafting is processed in transient memory over encrypted TLS connections strictly to provide the immediate response to Customer's workspace. 3. Human-in-the-Loop Oversight: Processor's architecture defaults to drafting responses for human review, giving Customer Controller complete authority over outgoing communications.

7. Subprocessors

Authorization: Customer grants general written authorization to Front Row Desk to engage the third-party subprocessors listed below to assist in delivering the Services: • Hosting & Serverless Compute: Vercel Inc. (United States) • Database & Authentication: Supabase Inc. / Amazon Web Services (United States) • AI Inference & Embeddings: Anthropic PBC, OpenAI LLC, Voyage AI Inc. (United States) • Telephony & Messaging: Twilio Inc., Sent.dm Inc. (United States) • Transactional & Marketing Email: Resend Inc. (United States) • Calendar & Review APIs: Google LLC, Meta Platforms Inc. (United States) Subprocessor Safeguards: Processor enters into written data processing agreements with each subprocessor imposing data protection terms no less protective than those set forth in this DPA. Processor remains fully liable to Customer for the performance of each subprocessor's obligations. Notification of Changes: Processor will provide notice of any intended appointment of new subprocessors by updating its online subprocessor list or notifying Customer via email. Customer may object on reasonable data protection grounds within fourteen (14) days of notice.

8. Technical & Organizational Measures (TOMs)

Processor maintains comprehensive technical and organizational security measures, including: • Encryption: End-to-end HTTPS/TLS 1.3 encryption for all data in transit across public networks; AES-256 encryption for data at rest. • Tenant Isolation: Strict row-level database tenant isolation ensuring that Customer Data is inaccessible to other customers or unauthorized accounts. • Access Controls: Multi-factor authentication (MFA), least-privilege role-based access controls (RBAC), and rotating API keys for all production infrastructure. • Audit Logging: Immutable audit logging of operational actions (via agent_actions table) recording user timestamps, agent actions, and system decisions. • Incident Detection: Continuous vulnerability monitoring, rate limiting, and automated health checks to prevent denial-of-service or unauthorized access attempts.

9. Security Incident Notification

Notification: In the event Front Row Desk confirms a Security Incident (meaning an actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data), Processor will notify Customer without undue delay (and in any event within 72 hours of confirmation). Details: The notification will provide, to the extent known: (a) a description of the nature of the incident; (b) the categories and approximate number of Data Subjects involved; (c) the likely consequences; and (d) measures taken or proposed to mitigate its effects. Mitigation: Processor will promptly take all reasonable and appropriate remediation steps to contain, control, and remediate the incident.

10. Return & Deletion of Personal Data

Upon expiration or termination of the Agreement, Front Row Desk shall, at Customer's election, return or delete all Customer Personal Data in its possession or control, except to the extent that applicable law requires storage of the Personal Data. Customer may export Customer Data at any time during the active subscription term. Following account closure, Customer Data is scheduled for irreversible deletion or anonymization within thirty (30) days, except for transaction records or logs required by regulatory, tax, or legal retention rules. Meta Platform Data Deletion: Requests to delete data received via connected Facebook Pages or Instagram accounts can be initiated at any time via our automated instructions at https://www.frontrowdesk.com/data-deletion.

11. International Data Transfers & Standard Contractual Clauses

To the extent Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to Front Row Desk in the United States, the parties agree that the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) ("SCCs") are incorporated by reference into this DPA. For the purposes of the SCCs: • Customer is the Data Exporter and Front Row Desk is the Data Importer. • The governing law shall be the laws of Ireland (for EEA transfers) or England & Wales (for UK transfers). • The technical and organizational measures in Section 8 serve as Annex II of the SCCs.

12. Inquiries & Data Protection Contact

If you have questions, notifications, or audit inquiries regarding this Data Processing Addendum, please contact our privacy and security team at: Front Row Desk Attn: Data Protection Team Email: hello@frontrowdesk.com Website: https://www.frontrowdesk.com Privacy Policy: https://www.frontrowdesk.com/privacy