logo

Platform

Solutions

JetStream AI Blueprints™

JetStream AI Kill Switch™

Verified MCP Catalog™

Executive Order AI Action Plan

The AI Budget Black Box

Executives & Business Leaders

Builders & Platform Teams

Security & Risk Leaders

Partner

Insights

About

AI Altitude

Trust Center
Get a Demo
Menu
  • Platform
  • Solutions

    JetStream AI Blueprints™

    JetStream AI Kill Switch™

    Verified MCP Catalog™

    Executive Order AI Action Plan

    The AI Budget Black Box

    Executives & Business Leaders

    Builders & Platform Teams

    Security & Risk Leaders

  • Partner
  • Insights
  • About
  • AI Altitude
Trust Center
Get a Demo

JetStream Master Subscription Agreement

Effective Date: April 30, 2026

This Master Subscription Agreement (this “Agreement”) is entered into as of the date last signed below (the “Effective Date”) by and between:

JetStream Security Inc., a Delaware corporation, with its principal place of business at 5201 Great America Parkway, Suite 346, Santa Clara, California 95054 (“JetStream” or “Company”);

and

[Customer Legal Entity Name], with its principal place of business at [Customer Address] (“Customer“).

JetStream and Customer are each referred to herein individually as a “Party” and collectively as the “Parties.”

Recitals

WHEREAS, JetStream develops and operates a security-first AI governance and control platform known as the JetStream SAIG Platform (the “Platform”), and offers subscription-based access to the Platform and related services to its customers; and

WHEREAS, Customer wishes to subscribe to the Platform and related services on the terms and conditions set forth in this Agreement;

NOW, THEREFORE, in consideration of the mutual covenants, representations, warranties, and agreements contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows.

SECTION 1. DEFINITIONS

As used in this Agreement, the following terms shall have the meanings set forth below:

  1. “Affiliate” means, with respect to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with such Party, where “control” means the ownership of more than fifty percent (50%) of the voting securities or other equity interests of such entity.
  2. “AI Model” means any artificial intelligence or machine learning model, algorithm, or system accessed, integrated, or deployed through or in connection with the Platform.
  3. “Applicable Data Protection Law” means all applicable data protection, privacy or cybersecurity laws, regulations or guidance, including U.S. Data Protection Law, E.U. GDPR and the U.K GDPR.
  4. “Applicable Law” means all federal, state, local, and international laws, regulations, rules, orders, and governmental requirements applicable to a Party’s performance of its obligations under this Agreement, including applicable data protection and privacy laws.
  5. “API” means any application programming interface made available by JetStream that enables programmatic access to or integration with the Platform.
  6. “Authorized Users” or “Users” means Customer’s employees, contractors, and agents who are authorized by Customer to access and use the Platform on Customer’s behalf under this Agreement, subject to the usage limits set out in the applicable Order Form.
  7. “Customer Data” means all data, content, information, and materials submitted, uploaded, transmitted, or otherwise provided by Customer or its Users to or through the Platform in connection with Customer’s use of the Services.
  8. “De-identified Data” means data derived from Customer Data or usage data that has been processed and anonymized such that it cannot reasonably be used to identify Customer, any User, or any individual data subject.
  9. “Documentation” means any technical documentation, user guides, help materials, release notes, and specifications relating to the Platform that JetStream makes available to Customer, whether in print or electronic form, as updated from time to time.
  10. “E.U. GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended, and guidance thereunder, including E.U. Member State implementing laws and regulations.
  11. “Features” means any module, tool, functionality, or feature of the Service.
  12. “Feedback” means any suggestions, ideas, enhancement requests, recommendations, corrections, or other feedback provided by Customer or its Users to JetStream regarding the Platform or Services.
  13. “Fees” means all subscription fees, usage-based fees, professional services fees, and any other amounts payable by Customer to JetStream under this Agreement, as set out in the applicable Order Form.
  14. “Force Majeure Event” means any event beyond a Party’s reasonable control, including acts of God, natural disasters, earthquakes, floods, fires, epidemics, pandemics, acts of war, terrorism, explosions, riots, civil unrest, governmental actions, embargoes, labor disputes, or failures of third-party telecommunications or internet infrastructure.
  15. “Including” or “includes” means including without limitation, and shall not be construed to limit the generality of any preceding term or provision.
  16. “Initial Subscription Term” means the Service initial subscription period specified in the Order Form.
  17. “Intellectual Property Rights” means all patents, copyrights, trademarks, trade secrets, moral rights, database rights, and all other intellectual property and proprietary rights recognized under applicable law, whether registered or unregistered.
  18. “JetStream Technology” means the Platform, all underlying software, source code, object code, algorithms, AI Models, APIs, Documentation, and all Intellectual Property Rights therein, together with any improvements, modifications, derivative works, or enhancements thereof, whether developed independently by JetStream or jointly with Customer.
  19. “Order Form” means a written or electronic order document executed by both Parties that specifies the subscription tier, scope of Services, Fees, Subscription Term, and any other relevant commercial terms applicable to Customer’s subscription to the Platform. Each Order Form shall be incorporated into and governed by this Agreement.
  20. “Output” means any content, data, results, reports, analyses, recommendations, or other materials generated by or through the Platform in response to Customer Data or User inputs.
  21. “Personal Data” shall have the meaning as defined under Applicable Data Protection Law.
  22. “Platform” means JetStream’s proprietary SAIG Platform, including all software, algorithms, AI Models, APIs, interfaces, tools, features, and functionalities made available to Customer under this Agreement, as may be updated, modified, or enhanced by JetStream from time to time.
  23. “Professional Services” means any implementation, configuration, training, consulting, or other professional services provided by JetStream to Customer, as specified in an applicable Order Form or Statement of Work.
  24. “Security Incident” means any confirmed unauthorized access to, disclosure of, alteration of, or destruction of Customer Data stored on or processed through the Platform.
  25. “Services” means, collectively, Customer’s subscription-based access to and use of the Platform, together with any Support Services and Professional Services provided by JetStream to Customer under this Agreement.
  26. “Statement of Work” or “SOW” means a written document executed by both Parties that describes the scope, deliverables, timeline, and fees applicable to any Professional Services to be performed by JetStream.
  27. “Subscription Term” means the Initial Term together with any Renewal Terms, as set forth in the applicable Order Form.
  28. “Support Services” means the technical support and maintenance services provided by JetStream to Customer in connection with the Platform, as described in the applicable Support Services terms or Order Form.
  29. “Third-Party Services” means any software, services, data sources, or platforms provided by third parties that may be integrated with or accessed through the Platform, but which are not owned or operated by JetStream.
  30. “Trial Period” means any limited, time-bound period during which JetStream grants Customer access to the Platform on a no-charge evaluation basis, as specified in an applicable Order Form or as otherwise agreed in writing by the Parties.
  31. “U.K. GDPR” means the UK General Data Protection Regulation, as defined in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018 (c. 12), as amended and revised, including guidance thereunder.
  32. “U.S. Data Protection Law” means all United States federal, state and local laws and regulations applicable to data protection, privacy and cybersecurity.
  33. “Users” means an employee of Customer authorized to access and use the Service.

SECTION 2. SUBSCRIPTION

  1. Subject to the terms and conditions of this Agreement (including without limitation the payment obligations set forth herein or in an Order Form), Company hereby grants Customer a limited, worldwide, non-exclusive, non-sublicensable, non-assignable, non-transferable and revocable right to and license to access and use the Services during the corresponding Subscription Term solely for Customer’s internal purposes (collectively, the “Subscription“). Unless otherwise indicated, the term Subscription also includes any software, revisions, fixes and/or updates thereto and any manuals or Documentation provided or made available to the Customer in connection with the use of the Service. Customer may use the Service subject to the use limitations specified in this Agreement and the respective Order Form and Applicable Laws. Customer shall be solely responsible for providing all equipment, systems, assets, access, and ancillary goods and services needed to access and use the Service, for ensuring their compatibility with the Service.
  2. Additional Purchases. Purchases of access to additional Features and/or purchases of additional volume shall be made by mutually signed written addendum to the Order Form or by executing a new Order Form, in each case according to the pricing agreed between the Parties.
  3. Account Setup. In order to access the Services, Customer is required to set up an administrative account with Company by submitting the information requested in the applicable Services interface, and each User may need to set up a user account. Customer warrants that all information submitted during the registration process is, and will thereafter remain, complete and accurate. Customer is responsible and liable for all activities that occur under or in their account. Customer will require that all Users keep User ID and password information strictly confidential and not share such information with any unauthorized person. Customer shall be fully responsible and liable for any breach of this Agreement by a User. Customer shall be further responsible and liable for all activities or use of the Services by unauthorized persons using Customer’s User IDs, and shall promptly report such activity to Company.
  4. Hosting. The Platform may be hosted by a third-party hosting service (“Hosting Provider”) and, accordingly, the availability of the Services would be in accordance with the Hosting Provider’s then-current uptime commitments.

SECTION 3. SUBSCRIPTION FEES

  1. Fees. In consideration for the Services, Customer shall pay Company the Subscription fees specified in the Order Form (the “Fees”).
  2. Unless expressly stated otherwise in the Order Form: (i) all Fees are stated, and are to be paid, in U.S. Dollars; (ii) all payments under this Agreement are non-refundable, and are without any right of set-off or cancellation; (iii) Fees for the entire Subscription Term set out in the applicable Order Form are due at the commencement of such Subscription Term and payable as described in the Order ; (iv) the Fees shall be paid within thirty (30) days of the date of the invoice; and (v) any amount not paid when due will accrue interest on a daily basis until paid in full, at the lesser of (vi) the rate of one and a half percent (1.5%) per month (18% per annum); or (vii) such lower rate which is the highest amount permitted by applicable law.
  3. Company reserves the right to suspend provision of Services for: (i) non or late payment; (ii) if Company deems such suspension necessary as a result of Customer’s breach under Section ‎4 (SubscriptionRestrictions); (iii) if Company reasonably determines that the suspension is necessary to avoid material harm to Company or its other customers, including if the Services’ infrastructure is experiencing denial of service attacks or other attacks or disruptions outside of Company’s control; or (iv) as required by Law or at the request of governmental entities.
  4. Taxes. Amounts payable under this Agreement are exclusive of all applicable sales, use, consumption, value added, and other direct or indirect taxes, charges, levies and duties. Customer shall bear all value added, state, local, withholding, and other taxes or other charges applicable to the Services.
  5. If Customer purchased the Subscription via a Partner, the Subscription is subject to the full payment of the applicable fees as set forth in the Partner Order Form between Customer and the respective Partner. All payments shall be made by the Customer directly to the Partner, as agreed between Customer and Partner. If Customer is entitled to a refund under the terms and conditions of this Agreement, then, unless Company specifies otherwise, Company will refund any applicable fees to the Partner, and the Partner alone will be responsible for refunding the appropriate amounts to Customer.

SECTION 4. SUBSCRIPTION RESTRICTIONS

Except as expressly permitted under this Agreement, Customer shall not and shall not allow any User to: (i) copy, “frame” or “mirror” the Services; (ii) sell, assign, transfer, lease, rent, license or sublicense, or otherwise distribute or make available the Service or any part thereof to any third party ; (iii) publicly perform, display or communicate the Services; (iv) modify, alter, adapt, arrange, or translate the Services; (v) decompile, disassemble, decrypt, reverse engineer, extract, or otherwise attempt to discover the source code or non-literal aspects (such as the underlying structure, sequence, organization, file formats, non-public APIs, ideas, or algorithms) of, the Services; (v) remove, alter, or conceal any proprietary rights notices displayed on or related to the Services; (vi) circumvent, disable or otherwise interfere with security-related or technical features or protocols of the Service; (vii) make derivative works of the Services, or use it to develop any service or product that is the same as (or substantially similar to) it; (viii) store or transmit any robot, malware, Trojan horse, spyware, or similar malicious item intended (or that has the potential) to damage or disrupt the Services; or (ix) take any action that imposes or may impose (as determined in Company’s reasonable discretion) an unreasonable or disproportionately large load on the servers, network, bandwidth, or other cloud infrastructure which operate or support the Services, or otherwise systematically abuse or disrupt the integrity of such servers, network, bandwidth, or infrastructure; (x) use the Platform in a manner that violates or infringes any rights of any third party .

SECTION 5. CUSTOMER DATA

  1. As between the parties, Customer owns and retains all right, title and interest (including all Intellectual Property Rights) in and to any Customer Data. Customer has exclusive control and responsibility for determining what Customer Data it and its permitted Users submit into the Services and for obtaining all necessary rights, consents, and permissions for submission of Customer Data and processing instructions to JetStream. To the extent the Customer Data includes any Personal Data, Customer confirms that it has received and/or obtained any and all required consents or permits and has acted in compliance with any Applicable Data Protection Laws. Customer hereby grants to JetStream a non-exclusive, worldwide, royalty-free, non-transferable right to use Customer Data to provide the Services and perform its obligations under this Agreement.
  2. Data Processing.
    1. Company’s use of information collected or processed about the Customer and other individuals will be governed by the Company’s Privacy Policy available at https://jetstream.security/privacy-policy/
    2. The terms of the Company’s Data Protection Agreement attached hereto as Exhibit A (“DPA“) are incorporated by reference to these Terms and apply to the processing of personal information, which is part of your consent.
    3. Customer acknowledges and agrees that JetStream may collect and process information regarding the configuration, performance, security, access to and use of the Services by Customer for its internal business purposes including to develop, improve, support, secure and operate the Services and to fulfill legal obligations. Notwithstanding the foregoing, nothing in this Agreement shall restrict JetStream’s use of data that has been anonymized and/or aggregated, provided that such data does not in any way identify and cannot be reasonably associated with Customer, its Affiliates, Permitted Users, or any individuals connected to Customer or Customer Confidential Information.

SECTION 6. MUTUAL WARRANTIES

Each Party represents and warrants that it is duly organized, validly existing and in good standing under the laws of its jurisdiction of incorporation or organization; and that the execution and performance of this Agreement will not conflict with other agreements to which it is bound or violate Applicable Law.

SECTION 7. INTELLECTUAL PROPERTY RIGHTS

As between the Parties, Company is, and shall be, the sole and exclusive owner of all Intellectual Property Rights in and to: (a) the Services and all related software and intellectual property; and (b) any and all improvements, derivative works, and/or modifications of/to the foregoing, regardless of inventorship or authorship; (c) any customer Feedback, suggestions, or ideas for or about the Service whether verbally or in writing. It is further understood that use of Feedback, if any, may be made by Company at its sole discretion, and that Company in no way shall be obliged to make use of the Feedback or compensate the Customer for such use in any way. Customer shall make, and hereby irrevocably makes, all assignments necessary or reasonably requested by Company to ensure and/or provide Company the ownership rights set forth in this paragraph. Company shall be entitled, from time to time, to modify and replace the Features (without materially changing the Service’s functionality) and user interface of the Services. Nothing herein constitutes a waiver of Company’s Intellectual Property Rights under any law.

SECTION 8. CONFIDENTIALITY

Each Party may have access to certain non-public information and materials of the other Party, in any form or media, including without limitation trade secrets and other information related to the products, software, technology, data, know-how, or business of the other Party, and any other information that a reasonable person should have reason to believe is proprietary, confidential, or competitively sensitive (the “Confidential Information“). Each Party shall take reasonable measures, at least as protective as those taken to protect its own confidential information, but in no event less than reasonable care, to protect the other Party’s Confidential Information from disclosure to a third party. The receiving party’s obligations under this Section ‎8, with respect to any Confidential Information of the disclosing Party, shall not apply to and/or shall terminate if such information: (a) was already lawfully known to the receiving party at the time of disclosure by the disclosing Party; (b) was disclosed to the receiving Party by a third party who had the right to make such disclosure without any confidentiality restrictions; (c) is, or through no fault of the receiving Party has become, generally available to the public; or (d) was independently developed by the receiving party without access to, use of, or reliance on, the disclosing party’s Confidential Information. Neither Party shall use or disclose the Confidential Information of the other Party except for performance of its obligations under this Agreement (“Permitted Use“). The receiving Party shall only permit access to the disclosing party’s Confidential Information to its respective employees, consultants, affiliates, agents and subcontractors having a need to know such information in connection with the Permitted Use, who have signed a like-written confidentiality undertaking or, in any event, the receiving Party shall remain liable for any acts or omissions of such persons. The receiving Party will be allowed to disclose Confidential Information to the extent that such disclosure is required by law or by the order of a court or similar judicial or administrative body, provided that, if legally permissible, it promptly notifies the disclosing Party in writing of such required disclosure to enable the disclosing Party to seek a protective order or otherwise prevent or restrict such disclosure and cooperates reasonably with disclosing Party in connection therewith. All right, title and interest in and to Confidential Information is and shall remain the sole and exclusive property of the disclosing Party.

SECTION 9. FEATURES AND SERVICES

  1. Evaluations. If Customer is using the Services for a free trial, proof of concept, evaluation, or other similar purpose (“Evaluation”), such Evaluation is granted for a limited period of thirty (30) days unless Company agrees to an extension in writing. Use of the Services during such Evaluation period shall be solely for the purpose of evaluating and testing the Services for Customer’s internal use to determine whether to purchase a subscription. The Company may terminate Customer’s access to and use of any Evaluation at any time. Evaluations are provided on an “as is” “where is” basis without guaranteed support levels, indemnification, or warranty of any kind, whether express, implied, statutory, or otherwise. Notwithstanding Section 11 (Limitation of Liability) or any other provision of this Agreement, the Company’s maximum aggregate liability under any Evaluation shall be capped at one thousand (1,000) U.S. dollars.
  2. Third Party Components. The Services may use or include third party open-source software, files, libraries, or components that may be distributed to Customer and are subject to third party open-source license terms. A list of such components will be provided upon request and may be updated from time to time by Company. If there is a conflict between any open-source license and the terms of this Agreement, then the open-source license terms shall prevail but solely in connection with the related third-party open-source software. Company makes no warranty or indemnity hereunder with respect to any third-party open-source software.
  3. Customer Integrations. Customer acknowledges that the Services may link to third-party websites, applications or services that can be integrated with or connected to the Services (“Third-Party Integrations”). To use such features, Customer must either obtain access to the Third-Party Integrations via the third-party provider or authorize the Company to obtain access on Customer’s behalf. If Customer uses such Third-Party Integrations, it acknowledges and agrees that: (a) any link from the Services does not imply any Company endorsement of, or responsibility for, those Third-Party Integrations and the use of such Third-Party Integrations are subject to the terms and conditions of the Third-Party Integration provider; (b) Customer may be required to grant the Company access to its Third-Party Integration account and/or to grant the Third-Party Integration provider access to its Company account; (c) Customer Data may be transferred between JetStream and the Third-Party Integration provider as required for the interoperation with the Services; and (d) JetStream will use its best commercial efforts to support the Third-Party Integrations that are currently integrated with the Service however, JetStream does not guarantee the continued availability of such Third-Party Integrations, and may cease supporting them without liability to Customer. To the maximum extent permitted by law but without derogating from JetStream’s obligations under this Agreement, JetStream shall not bear and expressly disclaims all responsibility or liability of any kind relating to such Third-Party Integrations, including, without limitation, for any disclosure of, access to or other processing of Customer Data by Third-Party Integration providers.
  4. Generative Artificial Intelligence (AI). Customer is aware that, JetStream may utilize artificial intelligence, machine learning, or similar technologies through the Services to process or analyze Customer Data, provide insights or recommendations or in order to automate certain actions (the “AI Features”). Customer Data will not be used to train or improve third-party AI models. Customer explicitly consents for the Company to use its input, including Customer Data and any Customer User data contained therein, for use with the AI Features in order to provide the Services (“AI Input”) and receive output generated and returned by the AI Features based on the AI Input (“AI Output”). Customer acknowledges that AI outputs are inherently probabilistic and may not always be accurate. The Customer agrees to use the outputs of the AI Features as supplementary information and not as definitive or sole guidance for critical decisions. Customer is therefore responsible for reviewing and validating any AI Output for its needs and technical environment before electing to use such AI Output. Customer agrees to comply with any applicable AI Feature restrictions described in the Documentation. NOTWITHSTANDING ANYTHING HEREIN TO CONTRARY, JETSTREAM DOES NOT REPRESENT OR WARRANT THAT THE AI OUTPUT WILL BE ACCURATE, COMPLETE, ERROR-FREE, OR FIT FOR A PARTICULAR PURPOSE. JETSTREAM EXPRESSLY DISCLAIMS ANY AND ALL LIABILITY FOR ANY DAMAGES OR LOSSES ARISING FROM CUSTOMER’S USE OF AI-GENERATED CONTENT OR ANY DECISIONS MADE BASED ON SUCH CONTENT.

SECTION 10. LIMITED WARRANTIES

Company represents and warrants that, under normal authorized use, the Services shall substantially perform in conformance with its Documentation. As Customer’s sole and exclusive remedy and Company’s sole liability for breach of this warranty, Company shall use commercially reasonable efforts to repair the Services. The warranty set forth herein shall not apply if the failure of the Services results from or is otherwise attributable to: (i) repair, maintenance or modification of the Services by persons other than Company or its authorized contractors; (ii) failure of Customer’s internet access or any public telecommunications network, or shortage of adequate power or maintenance of Customer’s system effecting the Services; (iii) use of the Services other than in accordance with the provisions of this Agreement and any Documentation; or (iv) the combination of the Services with equipment or software not authorized or provided by Company. OTHER THAN AS EXPLICITLY STATED IN THIS AGREEMENT, TO THE EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICES AND THE RESULTS THEREOF ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS. COMPANY DOES NOT WARRANT THAT: (i) THE SERVICES WILL MEET CUSTOMER’S REQUIREMENTS, OR (ii) THE SERVICES WILL OPERATE ERROR-FREE. EXCEPT AS SET FORTH IN SECTION ‎6 AND THIS SECTION ‎10, THE COMPANY EXPRESSLY DISCLAIMS ALL EXPRESS OR IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, SATISFACTORY QUALITY TITLE, NON- INFRINGEMENT, NON-INTERFERENCE, OR FITNESS FOR A PARTICULAR PURPOSE. COMPANY SHALL NOT BE RESPONSIBLE FOR ANY WARRANTIES AND REPRESENTATIONS MADE BY ANY PARTNER TO CUSTOMER.

SECTION 11. LIMITATION OF LIABILITIES

  1. NOTWITHSTANDING ANYTHING HEREIN TO THE CONTRARY, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW; IN NO EVENT SHALL EITHER PARTY, ITS AFFILIATES OR THEIR RESPECTIVE DIRECTORS, OFFICERS, EMPLOYEES, MEMBERS, AGENTS OR REPRESENTATIVES BE LIABLE TO THE OTHER PARTY FOR ANY LOSS OF, OR DAMAGE TO REVENUE, PROFITS, ANTICIPATED SAVINGS, BUSINESS OR GOODWILL NOR FOR ANY INDIRECT, INCIDENTAL, PUNITIVE, RELIANCE, CONSEQUENTIAL OR OTHER SIMILAR DAMAGES OF ANY KIND, EVEN IF MADE AWARE OF THE POSSIBILITY OF SUCH DAMAGES AND WHETHER BASED IN, CONTRACT, TORT, PRODUCT OR OTHER STRICT LIABILITY, TRADE PRACTICES OR OTHERWISE.
  2. EITHER PARTY’S MAXIMUM LIABILITY FOR ANY DAMAGES ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT OR TORT, OR OTHERWISE, SHALL IN NO EVENT EXCEED, IN THE AGGREGATE, THE TOTAL AMOUNTS ACTUALLY PAID OR PAYABLE TO COMPANY BY CUSTOMER IN THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO SUCH CLAIM. THIS LIMITATION OF LIABILITY IS CUMULATIVE AND NOT PER INCIDENT. FOR CLARITY, THE LIMITATIONS IN THIS SECTION DO NOT APPLY TO (I) PAYMENTS DUE TO COMPANY UNDER THIS AGREEMENT; OR (II) CUSTOMER’S VIOLATION OF COMPANY’S INTELLECTUAL PROPERTY RIGHTS.

SECTION 12. INDEMNIFICATION

  1. Company agrees to defend, at its expense, any third party action or suit brought against Customer alleging that the Services, when used as permitted under this Agreement, infringes intellectual property rights of a third party (“IP Infringement Claim“);and Company will pay any damages awarded by court against Customer that are attributable to any such IP Infringement Claim, provided that (i) Customer promptly notifies Company in writing of such claim; and (ii) Customer grants Company the sole authority to handle the defense or settlement of any such claim and provides Company with all reasonable information and assistance in connection therewith, at Company’s expense. Company will not be bound by any settlement that Customer enters into without Company’s prior written consent.
  2. If the Services become, or in Company’s opinion is likely to become, the subject of an IP Infringement Claim, then Company may, at its sole discretion: (a) procure for Customer the right to continue using the Services; (b) replace or modify the Services to avoid the IP Infringement Claim; or (c) if options (a) and (b) cannot be accomplished despite Company’s reasonable efforts, then Company may terminate the affected Order Form(s) upon written notice to Customer, and Customer shall be entitled to receive a pro-rated refund of any prepaid Subscription Fees under such Order Form(s) based on the remaining period of the corresponding Subscription Term(s).
  3. Notwithstanding the foregoing, Company shall have no responsibility for IP Infringement Claims resulting from or based on: (i) Company’s compliance with Customer’s instructions or specification; or (ii) combination or use of the Services with equipment, devices or software not supplied by Company.
  4. This Section 12 states Company’s entire liability, and Customer’s exclusive remedy, for any IP Infringement Claim.

SECTION 13. TERM AND TERMINATION

  1. Term. This Agreement commences on the Effective Date and, unless terminated in accordance herewith, shall continue in full force and effect for the duration of the Initial Subscription Term or the initial subscription terms specified in the Order Form (as the case may be) (the “Initial Subscription Term“). In case Customer purchased the Subscription directly from the Company, following such Initial Subscription Term, the Order Form shall automatically renew for successive Subscription Terms of equal length (each, a “Renewal Subscription Term“, and together with the Initial Subscription Term, the “Subscription Term“), unless either Party notifies the other Party in writing of its intent not to renew the Order Form, not less than sixty (60) days prior to the expiration of the then-current Subscription Term.
  2. Termination for Breach. Each Party may terminate this Agreement immediately upon written notice to the other Party if the other Party commits a material breach under this Agreement and, if curable, fails to cure that breach within thirty (30) days after receipt of written notice specifying the material breach (except that for payment defaults, such cure period will be seven (7) days).
  3. Termination for Bankruptcy. Each Party may terminate this Agreement upon written notice to the other Party upon the occurrence of any of the following events in respect of such other Party: (a) a receiver is appointed for the other Party or its property, which appointment is not dismissed within sixty (60) days; (b) the other Party makes a general assignment for the benefit of its creditors; (c) the other Party commences, or has commenced against it, proceedings under any bankruptcy, insolvency or debtor’s relief Law, which proceedings are not dismissed within sixty (60) days; or (d) the other Party is liquidating, dissolving or ceasing normal business operations.
  4. Effect of Termination; Survival. Upon termination of this Agreement for any reason: (a) the Subscription shall automatically terminate, (b) Customer shall cease all access and use of the Services thereunder, and (c) Customer shall (as directed) permanently erase and/or return all Company Confidential Information in Customer’s possession or control. Following termination, all outstanding Fees and other charges that accrued as of termination, will become immediately due and payable. The provisions of this Agreement that, by their nature and content, must survive the termination of this Agreement in order to achieve the fundamental purposes of this Agreement (including limitation of liability) shall so survive. Termination shall not affect any rights and obligations accrued as of the effective date of termination.

SECTION 14. MISCELLANEOUS

This Agreement and any exhibits attached or referred hereto, represents the entire agreement between the Parties concerning the subject matter hereof, replaces all prior and contemporaneous oral or written understandings and statements, and may be amended only by a written agreement executed by both Parties. This Agreement supersedes any terms or conditions (whether printed, hyperlinked, or otherwise) in any Customer’s purchase order or other standardized business forms, which purport to supersede, modify or supplement this Agreement. The failure of either Party to enforce any rights granted hereunder or to take action against the other Party in the event of any breach shall not be deemed a waiver by that Party as to subsequent enforcement or actions in the event of future breaches. Any waiver granted hereunder must be in writing. If any provision of this Agreement is held by a court of competent jurisdiction to be illegal, invalid or unenforceable, the remaining provisions of this Agreement shall remain in full force and effect and such provision shall be revised only to the extent necessary to make it enforceable. Any use of the Services by an agency, department, or other entity of the United States government shall be governed solely by the terms of this Agreement. Company may use the trademarks, service marks, trade names, service names, logos or other brand designations of Customer in any promotional material or other public announcement or disclosure to indicate that Customer is a customer of Company. Except as stated otherwise herein, this Agreement is for the sole benefit of the parties hereto and nothing herein, express or implied, shall give, or be construed to give, any rights hereunder to any other person. Neither Party may assign its rights or obligations under this Agreement without the prior written consent of the other Party, which consent may not be unreasonably withheld or delayed. Notwithstanding the foregoing, this Agreement may be assigned by either Party in connection with a merger, consolidation, sale of all of the equity interests of such Party, or a sale of all or substantially all of the assets of the Party to which this Agreement relates. Without derogating from and subject to the abovementioned, this Agreement will bind and benefit each Party and its respective successors and assigns. This Agreement shall be governed by and construed under the laws of the State of New York, without reference to principles and laws relating to the conflict of laws. The competent courts of New York shall have the exclusive jurisdiction with respect to any dispute and action arising under or in relation to this Agreement. Notwithstanding the foregoing, each Party may seek equitable relief in any court of competent jurisdiction in order to protect its proprietary rights. Each Party irrevocably waives its right to trial of any issue by jury. This Agreement does not, and shall not be construed to create any relationship, partnership, joint venture, employer-employee, agency, or franchisor-franchisee relationship between the Parties. Neither Party has any authority to enter into agreements of any kind on behalf of the other Party. Company will not be liable for any delay or failure to provide the Services resulting from circumstances or causes beyond the reasonable control of Company including, but not limited to on account of strikes, shortages, riots, insurrection, fires, flood, storms, explosions, acts of God, war, government or quasi-governmental authorities actions, riot, acts of terrorism, earthquakes, explosions, power outages, pandemic or epidemic (or similar regional health crisis), or any other cause that is beyond the reasonable control of Company. Customer contact information shall be the information used by the Customer to register to the Services. These terms may be amended by JetStream from time to time in its sole discretion.

In Witness Whereof, the Parties hereto have caused this JetStream Master Subscription Agreement to be executed by their duly authorized officers or representatives as of the Effective Date of the Agreement.

CUSTOMER:JetStream Security Inc.
Signature:Signature:
Name (Print):Name (Print):
Title:Title:
Email:Email:
Date:Date:

Exhibit A

Data Protection Agreement

This Data Protection Agreement, including all appendices (“DPA”) forms a part of the JetStream Master Subscription Agreement (“Agreement”) between JetStream and the Customer. The Parties agree that this DPA sets forth their obligations with respect to the processing and security of Customer Data in connection with Customer’s use of the Services.

  1. OVERVIEW.
    1. This DPA applies only to the processing of Customer Data in environments controlled by JetStream (including JetStream Sub-processors), which includes Customer Data sent to JetStream Services but does not include data that remains on Customer’s premises or in any Customer-selected third-party operating environments. This DPA will be effective on the Effective Date of the Agreement and will replace any terms previously applicable to the processing and security of Customer Data. Capitalized terms used but not defined in this DPA have the meaning given to them in the Agreement.
  2. DEFINITIONS.
    1. “Party” or “Parties” means, individually or collectively, JetStream (acting as processor or sub-processor) and Customer (acting as controller or processor as applicable). References to “Parties” shall have the same meaning as set forth in the Agreement, except to the extent this DPA imposes specific obligations that differ based on each Party’s role as controller, processor, or sub-processor.
    2. “Applicable Data Protection Law” means, as applicable to the processing of Customer Data (including any personal data contained therein), any national, federal, European Union, state, provincial, or other privacy, data protection, or data security law or regulation.
    3. “Customer Data”, has the meaning ascribed to it in the Agreement, and includes Customer Personal Data as well as other data processed by JetStream on behalf of Customer.
    4. “Customer Personal Data” means the personal data contained within the Customer Data, including any special categories of personal data or sensitive data defined under Applicable Data Protection Law.
    5. “EU GDPR” means:
      1. “EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, as amended and/or replaced from time to time; and
      2. “UK GDPR” means the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419), as further amended and/or replaced from time to time, and as read together with the Data Protection Act 2018.
      Where this DPA refers to “GDPR” without further qualification, such reference shall mean the EU GDPR and/or the UK GDPR, as applicable to the relevant processing of Customer Personal Data. Where a provision applies specifically to EU Personal Data, it shall reference the “EU GDPR,” and where a provision applies specifically to UK Personal Data, it shall reference the “UK GDPR.”
    6. “Protected Area” means:
      1. With respect to Customer Personal Data subject to the EU GDPR (“EU Personal Data”), the member states of the EU and the EEA and any country, territory, sector or international organization in respect of which an adequacy decision under Art. 45 GDPR is in force; and
      2. With respect to Customer Personal Data subject to UK GDPR (“UK Personal Data”), the United Kingdom and any country, territory, sector or international organization in respect of which an adequacy decision under United Kingdom adequacy regulations is in force.
    7. “Security Breach” means a breach of JetStream’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
    8. “Standard Contractual Clauses” means:
      1. With respect to EU Personal Data, the standard contractual clauses for the transfer of personal data to third countries pursuant to the EU GDPR, adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, including the text from module 2 and/or 3 of such clauses (as applicable), as may be amended or replaced from time to time (“EU Standard Contractual Clauses”);
      2. With respect to UK Personal Data, the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner and laid before Parliament in accordance with s.119A of the Data Protection Act 2018 on 2 February 2022 (“UK Addendum”).
    9. “Subprocessor” means a third party authorized as another processor under this DPA to process Customer Personal Data in order to provide the Services.
    10. “Third Country” means any country or territory outside of the Protected Area.
    11. “Third-Party Request” means any request from a third party, including from a public authority or a law enforcement agency, made to JetStream and its affiliates, subsidiaries, contractors, subcontractors and its and their employees related to Customer Personal Data, including but not limited to a lawful search warrant, court order, subpoena, discovery request, complaint or any valid legal order, but excluding requests from Data Subjects.
    12. “Transfer Impact Assessment” means the assessment required prior to transferring EU Personal Data or UK Personal Data to a Third Country, as applicable.
    13. “US Privacy Laws” / “Data Privacy Laws” means all laws, regulations, regulatory requirements, guidance, codes of practice and self-regulatory principles applicable to the processing of Customer Personal Data including without limitation: the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 along with any associated regulations (“CCPA”); the Virginia Consumer Data Protection Act (“VCDPA”); the Colorado Privacy Act; and any similar U.S. State or Federal laws governing data privacy and security once effective.
    14. The terms “personal data”, “data subject”, “controller”, and “processor” as used in this DPA have the meanings given by Applicable Data Protection Law or, absent any such meaning or law, by the EU GDPR.
    15. The terms “personal data”, “data subject”, “controller”, and “processor” include “personal information”, “consumer”, “business”, and “service provider”, respectively, as required by Applicable Data Protection Law.
  3. LEGAL COMPLIANCE AND JURISDICTION-SPECIFIC TERMS.
    1. Roles of the Parties. JetStream is a processor or sub-processor and Customer is a controller or processor, as applicable, of Customer Data. JetStream is a “Service Provider” as defined by California Privacy Law.
    2. Compliance with Law. Each Party will comply with its obligations related to the processing of Customer Data under Applicable Data Protection Law.
  4. PROCESSING OF CUSTOMER DATA.
    1. Summary of the Processing. The subject matter and details of the processing of Customer Data are described in Appendix 1 (Details of Processing of Customer Data).
    2. JetStream Obligation. JetStream shall: (a) not process Customer Data other than to provide the Services in accordance with this Agreement (including as set forth in this DPA and as described in Appendix 1 to this DPA) and applicable law (the “Permitted Purpose”); and (b) promptly notify Customer if, in JetStream’s opinion, Applicable Data Protection Law prohibits JetStream from complying with the Permitted Purpose or JetStream is otherwise unable to comply with the Permitted Purpose.
    3. Customer Instructions and Obligation. Customer hereby: (a) instructs JetStream to process Customer Data for the Permitted Purpose; (b) warrants and represents that it is and will at all relevant times remain duly and effectively authorized to give the instruction set out herein on behalf of each relevant controller of Customer Data; and (c) warrants and represents that the relevant controller of Customer Data has provided all notices and obtained all consents required by Applicable Data Protection Law to provide Customer Data to JetStream under the Agreement.
  5. SECURITY.
    1. Technical and Organizational Measures. JetStream will implement and maintain the technical and organizational measures (“TOMs”) set forth in Appendix 2 hereto applicable to the specific Services purchased by Customer. JetStream may update the TOMs from time to time provided that such updates do not result in a reduction of the security of the Services or JetStream’s obligations under the Agreement.
    2. Customer’s Security Responsibilities. Without prejudice to JetStream’s obligations under Section 5.1 (Technical and Organizational Measures) and elsewhere in the Agreement, Customer is responsible for its use of the Services, including: (a) using the Services to ensure a level of security appropriate to the risk to Customer Data; (b) securing the authentication credentials, systems, and devices Customer uses to access the Services; and (c) backing up its Customer Data as appropriate.
    3. Customer’s Security Assessment. Customer agrees that the Services and Security Measures implemented and maintained by JetStream provide a level of security appropriate to the risk to Customer Data.
    4. Confidentiality. JetStream shall ensure that its personnel engaged in the processing of Customer Data (a) will process such data only on instructions from Customer or as described in this DPA, and (b) will be obligated to maintain the confidentiality and security of such data even after their engagement ends. JetStream shall take reasonable steps to ensure the reliability of any individual who may have access to Customer Personal Data, ensuring that access is limited to those individuals who need to know or access the relevant Customer Personal Data as necessary for the purposes of the Agreement. JetStream shall provide periodic and mandatory data privacy and security training and awareness to its employees in accordance with Applicable Data Protection Law and industry standards.
    5. Security Breaches.
      1. Notification. JetStream shall notify Customer without unreasonable delay, and in any event within seventy-two (72) hours, upon becoming aware of a Security Breach, and promptly take reasonable steps to minimize harm and secure Customer Data. Such notification shall be made via email to Customer’s designated contact, and where the Security Breach is material, also by telephone.
      2. Details of Notification. JetStream’s notification of a Security Breach will describe: (a) the nature of the Security Breach including the Customer resources impacted; (b) the measures JetStream has taken, or plans to take, to address the Security Breach and mitigate its potential risk; (c) the measures, if any, JetStream recommends that Customer take to address the Security Breach; and (d) the details of a contact point where more information can be obtained. If it is not possible to provide all such information at the same time, JetStream’s initial notification will contain the information then available and further information will be provided without undue delay as it becomes available.
      3. Remedial Actions. If a Security Breach gives rise to a need to provide notification to public authorities, individuals, or other persons, or undertake other remedial measures (including notice, credit monitoring services, or the establishment of a call center to respond to inquiries), JetStream will reasonably cooperate with Customer and, at Customer’s reasonable request, undertake such remedial actions with response to Customer Personal Data.
      4. Information Security Program. Jetstream will implement, maintain, and comply with a written information security program (“Information Security Program”), which will include policies, procedures, and technical and physical controls to (i) ensure the security, availability, integrity, and confidentiality of JetStream’s systems and Customer Data; (ii) identify and protect against potential threats or hazards to such systems and Customer Data; (iii) protect against unauthorized access to, alteration of, or destruction of such systems and Customer Data; (iv) ensure secure disposal of Customer Data; and (v) ensure that Customer is notified as required herein in the event of a Security Incident. JetStream will monitor, evaluate, and adjust, as appropriate, the Information Security Program in light of relevant changes in technology, industry security standards, and applicable law. The Information Security Program shall include the measures described in Appendix 2 to this DPA. No Acknowledgement of Fault or Liability. JetStream’s notification of or response to a Security Breach under this Section will not be construed as an acknowledgement by JetStream of any fault or liability with respect to the Security Breach.
  6. SUBPROCESSING.
    1. Specific Consent. Customer specifically authorizes JetStream to engage as Subprocessors those entities listed as of the effective date of this DPA at the URL specified in Section 6.2 (Subprocessor Details). In addition, and without prejudice to Section 6.3 (Engagement of New Subprocessors), Customer generally authorizes the engagement as Subprocessors of any other third parties (each a “New Subprocessor”).
    2. Subprocessor Details. Information about Subprocessors, including their functions and locations, will be available at https://www.JetStream.inc/subprocessors (as may be updated by JetStream from time to time in accordance with this DPA). Currently, the only subprocessor used by JetStream is Amazon Web Services. JetStream will provide details of each Subprocessor’s identity and its processing activities, including location(s) of where such processing of Customer Personal Data takes place.
    3. Engagement of New Subprocessors. When any New Subprocessor is engaged while this DPA is in effect, JetStream shall provide Customer at least thirty (30) days’ prior written notice of the engagement of any New Subprocessor, including details of the processing to be undertaken by the New Subprocessor. If, within fifteen (15) days of receipt of that notice, Customer notifies JetStream in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on that New Subprocessor’s inability to adequately safeguard Customer Data, then: (a) JetStream shall work with Customer in good faith to address Customer’s objections regarding the New Subprocessor; and (b) where Customer’s concerns cannot be resolved within thirty days from JetStream’s receipt of Customer’s notice, notwithstanding anything in the Agreement, Customer may, by providing JetStream with a written notice with immediate effect, terminate the Purchase Order(s) with respect to only those aspects which cannot be provided by JetStream without the use of the New Subprocessor.
    4. Subprocessor Due Diligence Requirements. With respect to each Subprocessor, JetStream shall: (a) before the Subprocessor first processes Customer Data, carry out adequate due diligence to ensure that the Subprocessor is capable of performing the obligations subcontracted to it in accordance with the Agreement (including this DPA); (b) periodically reassess the Subprocessor to ensure it remains capable of performing the obligations subcontracted to it in accordance with the Agreement (including this DPA); (c) ensure that the processing of Customer Data by the Subprocessor is governed by a written contract including terms no less protective of Customer Data than those set out in this DPA, including that the applicable data protection obligations in this DPA are imposed on the Subprocessor; and (d) remain fully liable for all obligations subcontracted to, and all acts and omissions of, the Subprocessor.
  7. US PRIVACY LAWS.
    1. In performing its obligations under the Agreement and this DPA, JetStream shall comply with its obligations under US Privacy Laws, including by providing the level of privacy protection as is required by US Privacy Laws to Customer Personal Data subject to the US Privacy Laws. JetStream will not: (1) “sell” or “share” for purposes of “cross-context behavioral advertising” or “targeted advertising” (as defined by applicable US Privacy Laws) any Customer Personal Data; (2) retain, use, or disclose Customer Personal Data for any purpose other than the contractual business purpose set forth herein or as otherwise permitted under US Privacy Laws or outside of the direct business relationship between JetStream and the Customer; or (3) attempt to re-identify any pseudonymized, anonymized, aggregate, or de-identified Customer Personal Data.
    2. JetStream will (1) comply with any applicable restrictions under applicable US Privacy Laws on combining Customer Personal Data with Personal Data that JetStream receives from, or on behalf of, another person or persons; and (2) promptly notify Customer if JetStream determines that it (i) can no longer meet its obligations under this DPA or applicable US Privacy Laws; or (ii) in JetStream’s opinion, an instruction from Customer infringes applicable US Privacy Laws. Upon such notice, Customer may suspend processing of Customer Personal Data by JetStream.
    3. To the extent required under US Privacy Laws, Customer may take reasonable and appropriate steps to help to ensure that JetStream uses Customer Personal Data in a manner consistent with Customer’s obligations under US Privacy Laws and in order to stop and remediate unauthorized use of the Customer Personal Data.
    4. JetStream certifies that it understands its obligations set forth in this Section 7. The Parties agree that Appendix 1 hereto shall satisfy any requirement under applicable U.S. Privacy Law to provide details regarding the nature of the Processing activities related to Customer Personal Data.
    5. Third-Party Requests.
      1. Unless prohibited by law, JetStream will (i) notify Customer promptly, and in any event within five (5) business days, upon receipt of a Third-Party Request (and prior to any response to or any disclosure of Customer Personal Data to the third party), and (ii) provide Customer with the information required for Customer to evaluate, quash, limit, and/or respond to the Third-Party Request.
      2. JetStream shall not respond to any Third-Party Request unless (i) JetStream is explicitly authorized by Customer in writing to do so; or (ii) where JetStream has a mandatory obligation under applicable law to respond directly, in which case JetStream shall notify Customer at the same time as making the initial notification pursuant to Section 7.5(i) above and shall comply with Customer’s reasonable requests in responding to, and dealing with, any such Third-Party Request. Should JetStream be legally required to respond to a Third-Party Request, JetStream, after consultation with Customer, shall only disclose the minimum amount of Customer Personal Data necessary to comply with law or judicial process.
      3. In the event that a Third-Party Request for Customer Personal Data processed by JetStream is served on Customer, JetStream will provide Customer with access to such information within five (5) business days of receipt of any request by Customer for such access or copies, unless a shorter timeline is requested by Customer to comply with such Third-Party Request.
  8. TRANSFERS OF DATA.
    1. Transfers to countries that offer adequate level of data protection. Personal Data may be transferred from the EU Member States, the three EEA member countries (Norway, Liechtenstein and Iceland) (collectively, “EEA”) and the United Kingdom to countries that offer adequate level of data protection under or pursuant to the adequacy decisions published by the relevant data protection authorities of the EEA, the Union, the Member States or the European Commission (“Adequacy Decisions”), without any further safeguard being necessary.
    2. Transfers to other countries. If the Processing of Personal Data includes transfers from the EEA or the United Kingdom to countries outside the EEA or United Kingdom which are not subject to an Adequacy Decision (“Third Countries”), the Parties shall comply with the Standard Contractual Clauses, which are incorporated herein by reference, with Customer as the ‘data exporter’ and JetStream as the ‘data importer’. For purposes of the Standard Contractual Clauses: (i) Appendix 1 to this DPA shall serve as Annex I(B) (description of the transfer); (ii) Appendix 2 shall serve as Annex II (technical and organisational measures); (iii) the Subprocessor information referenced in Section 6.2 shall serve as Annex III; (iv) for Clause 9, Option 2 (general written authorisation) shall apply, with the notice period set forth in Section 6.3; (v) the optional language in Clause 11 shall not apply; (vi) for Clauses 17 and 18, the governing law and forum shall be Ireland, and the competent supervisory authority under Clause 13 shall be determined in accordance with Annex I(C), in each case unless Applicable Data Protection Law requires otherwise; and (vii) with respect to UK Personal Data, the UK Addendum shall be deemed completed with the information set forth in this DPA and its Appendices.
    3. Transfer Impact Assessments. To the extent required by Applicable Data Protection Law, JetStream shall cooperate with Customer in conducting Transfer Impact Assessments prior to any transfer of EU Personal Data or UK Personal Data to a Third Country.
    4. Restricted Area Transfers. Except for EU Personal Data or UK Personal Data (which is addressed in Section 8.2), if JetStream processes any other Customer Personal Data that is subject to transfer restrictions under local Data Privacy Laws requiring additional provisions for the transfer of such data, then the parties agree that the terms of the EU Standard Contractual Clauses and the applicable module per Section 8.2 shall apply to such transfers. In such cases, governing law for the Standard Contractual Clauses shall be set forth in the Agreement unless applicable Data Privacy Law requires a specific jurisdiction to serve as governing law.
  9. COOPERATION.
    1. Individual Rights. Taking into account the nature of the processing, JetStream shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer’s obligations, as reasonably understood by Customer, to respond to requests to exercise individuals’ rights under Applicable Data Protection Law.
    2. Individual Requests. JetStream shall: (a) promptly notify Customer if JetStream receives a request from an individual Applicable Data Protection Law with respect to Customer Data to the extent that JetStream recognizes the request as relating to Customer; and (b) ensure that JetStream does not respond to that request except on the documented instructions of Customer or as required by applicable law, in which case JetStream shall to the extent permitted by applicable law inform Customer of that legal requirement before JetStream responds to the request.
    3. Impact Assessments and Consultation. To the extent JetStream is required by Applicable Data Protection Law, JetStream shall (taking into account the nature of the processing and the information available to JetStream) provide reasonable assistance to Customer with any impact assessments or consultations with data protection regulators by providing information in accordance with Section 9.4 (Audits and Records).
    4. Audits and Records. JetStream shall make available to Customer upon request information necessary to demonstrate compliance with Applicable Data Protection Law and this DPA in accordance with the following procedures: (a) JetStream will provide Customer with the most recent certifications and/or summary audit report(s) which JetStream has procured to regularly test, assess, and evaluate the effectiveness of the Security Measures; (b) JetStream will reasonably cooperate with Customer by providing available additional information concerning the Security Measures to help Customer better understand the Security Measures; and (c) if further information is required by Customer to comply with its own or other controller’s audit obligations or a competent supervisory authority’s request, Customer will inform JetStream and the Parties shall discuss in good faith the content and delivery of the required information. In addition, to the extent the information made available pursuant to (a)–(c) is insufficient to satisfy Customer’s audit rights under Applicable Data Protection Law (including Article 28(3)(h) of the GDPR and Clause 8.9 of the Standard Contractual Clauses), JetStream shall allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer (which shall not be a competitor of JetStream), subject to reasonable prior written notice, not more than once in any twelve-month period except following a Security Breach or where required by a competent supervisory authority, during normal business hours, and subject to appropriate confidentiality obligations.
  10. DATA PROCESSING LOCATIONS.
    1. u. Taking into account the safeguards set forth in this DPA, Customer Data may be processed in the United States or any other country in which JetStream or its Subprocessors operate.
  11. DATA DELETION.
    1. Deletion Upon Termination. JetStream shall promptly and in any event within sixty days of the date of cessation of providing any Services involving the processing of Customer Data (the “Cessation Date”), delete all copies of Customer Data, unless applicable law requires storage.
    2. Certification of Deletion. JetStream shall provide written certification to Customer that it has complied with this Section within ten days of receiving Customer’s written request to receive such certification.
  12. GENERAL TERMS.
    1. Interpretation. With regard to the subject matter of this DPA, in the event of inconsistencies between the provisions of this DPA and any other agreements between the Parties, including the Agreement and including (except where explicitly agreed otherwise in writing, signed on behalf of the Parties) agreements entered into or purported to be entered into after the date of this DPA, the provisions of this DPA shall prevail.
    2. Liability. Any liability associated with failure to comply with this DPA will be subject to the limitations of liability provisions stated in the Agreement.
    3. Invalid or Unenforceable Provisions. Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (a) amended as necessary to ensure its validity and enforceability, while preserving the Parties intentions as closely as possible, or if this is not possible, (b) construed in a manner as if the invalid or unenforceable part had never been contained therein.

APPENDIX 1:

DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA
  1. Subject matter and duration of processing
    JetStream will process Customer Data, including any personal data contained therein, exclusively to provide the Services pursuant to the Agreement, including any retention period(s) purchased by Customer for specific Services.
  2. Nature and purpose of processing
    JetStream will process Customer Data only for the Permitted Purpose.
  3. Categories of Data
    The specific nature of Customer Data processed by JetStream depends upon the Services Customer purchases, but broadly relates to the following categories of data:
    • Identification and business contact data (e.g., name, email address)
    • Network and network usage data (e.g., IP address, URLs)
    • Keys associated with customers AI Model providers (provided by the Customer for use by JetStream to create virtual keys to manage key sprawl)
    • AI activity and usage data processed through the Services (e.g., user prompts, agent workflow execution data, model interaction metadata, and AI usage logs), which may contain any category of personal data included in such content by or on behalf of Customer.
  4. Special categories of data
    The Services are not intended to process special categories of personal data, and special categories of personal data are not required to deliver the Services to Customer. Notwithstanding the foregoing, when Customer controls the data sent to JetStream, or in specific services engagements, JetStream may process special categories of personal data on behalf of Customer. The nature and scope of the special categories of sensitive personal data that is transferred may not be known until after the processing has taken place but may include: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
  5. Data subjects
    Data subjects include the individuals about whom data is provided to JetStream via the Services by (or at the direction of) Customer, and may include employees, contractors, consultants, or other individuals belonging to Customer, Customer’s customers or clients, and Customer’s partners’ workforce.

APPENDIX 2:

TECHNICAL AND ORGANISATIONAL MEASURES

Description of the technical and organisational measures implemented by the data importer to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

JetStream, Inc. (“JetStream“) maintains a documented information security program designed to protect personal data processed through its Security-First AI Governance (SAIG) Platform against unauthorized access, disclosure, alteration, loss, misuse, or destruction. Personal data is processed only on the documented instructions of the data exporter (controller), kept logically separated between customers, and deleted on request or upon termination. The measures below are supported by written policies that are reviewed at least annually and are subject to independent SOC 2 examination.

  1. Organizational Security Measures
    Security Governance. A documented information security program assigns organizational roles, oversight responsibilities, and executive ownership, supported by an annual risk assessment conducted against a recognized framework (ISO 31000 / ISO 27005 / AICPA) and ongoing control monitoring.
    Business Continuity and Disaster Recovery. A documented BC/DR plan supports continued availability and timely restoration of systems and data; production data is replicated across geographically separate AWS Availability Zones, and the plan is reviewed and tested at least annually.
  2. Administrative Security Measures
    Personnel Security and Training. Personnel are screened before employment, bound by confidentiality agreements, and receive security-awareness training at onboarding and at least annually, with completion tracked; a documented disciplinary process addresses non-compliance.
    Risk Management. Documented processes identify, assess, and address risks to the confidentiality, integrity, and availability of personal data, including fraud risk and segregation of duties.
    Third-Party / Sub-Processor Oversight. Vendors and sub-processors are risk-tiered, subject to due diligence before access, contractually bound to security controls, and reviewed at least annually.
  3. Technical Security Measures
    Access Controls and Authentication. Access is granted on a least-privilege, role-based basis with documented approval, and is reviewed at least annually and revoked within 24 hours of termination or role change. Users are uniquely identified and authenticate with username, password, and multi-factor authentication; remote and privileged access to production is restricted to authorized personnel over an encrypted VPN with MFA.
    System and Network Security. Physical and logical network segmentation, firewalls, IDS/IPS, DLP, host-based firewalls, and endpoint anti-malware protect systems from unauthorized access and malicious activity.
    Security Monitoring and Logging. Security-relevant events, privileged actions, and access attempts are logged, protected from tampering with synchronized clocks, and monitored with alerting to support investigation and incident response.
    Security Testing. Vulnerability scans are performed on a defined cadence with severity-based remediation SLAs, and independent penetration testing is performed at least annually.
  4. Physical Security Measures
    Facility Security. Production infrastructure is hosted at AWS data centers, which restrict access to authorized personnel, monitor facilities 24/7, and provide fire suppression, environmental monitoring, and uninterruptible power; JetStream reviews the AWS SOC 2 report annually. JetStream offices are protected by badge-controlled access, reception controls, video monitoring, visitor logging, and environmental controls, with physical access revoked within 24 hours of termination or role change.
  5. Data Transmission and StorageEncryption and Data Protection. Data stores housing sensitive customer data are encrypted at rest using AES via AWS KMS; confidential and sensitive data is encrypted in transit over public networks using secure protocols with strong hashing (SHA-2 256 or greater). Information transfers are restricted to approved, authenticated, encrypted channels (corporate email, corporate cloud storage, SFTP, VPN). Encryption keys are managed across their lifecycle with least-privilege access, segregation of duties, audit logging, and defined rotation and revocation. Data masking, pseudonymisation, and anonymisation are applied to conceal personal data where appropriate.
  6. Data Minimization, Retention, and DisposalData is classified by sensitivity, with handling standards defined for data at rest and in transit. Retention periods are established per legal, regulatory, and classification criteria, and customer data is deleted on request or upon termination. Secure-disposal services and deletion software render data unrecoverable; returned devices are sanitized and reimaged.
  7. Backup and ResilienceAutomated backups of customer data run daily, are encrypted at rest via AWS KMS, and are stored redundantly across multiple AWS Availability Zones, with cross-Region replication where warranted. Restore capability is tested at least annually, with documented results retained.
  8. Incident Response and AccountabilityIncident Management. A documented incident response plan covers detection, analysis, containment, eradication, recovery, and reporting; incidents are classified by severity with defined response-start times, and critical/high incidents receive post-mortems. Customer-reported incidents are handled through a defined support channel with communication through resolution.
    Audit and Continuous Improvement. JetStream undergoes independent SOC 2 examination across Security, Availability, and Confidentiality; control owners perform documented self-assessments of design and operating effectiveness at least annually, with deficiencies tracked to resolution.
  9. Sub-Processor MeasuresWhere sub-processors process personal data on JetStream’s behalf, they are subject to due diligence and contractually required to implement appropriate technical and organisational measures, independent control validation, incident-response responsibilities with defined SLA timing, background screening, data return or destruction on termination, and geographic limits on data storage and transmission.

Adopt AI With Confidence

Request a Demo
Explore the Platform
footer-logo
Platform
Trust Center
Partner
Insights
About Us
Support

Copyright © 2026
5201 Great America Parkway
Suite 346
Santa Clara, CA 95054
Ph. (832) 288-8867


Privacy Policy Terms of Use Data Processing Agreement
Consent(Required)
JetStream Security Inc. will use your business email address solely to send our newsletter. You may withdraw consent at any time via the unsubscribe link in any email. See our Privacy Policy. We will not share your information with third parties for their own marketing purposes without your separate consent. Content does not constitute legal advice. April 2026 | JetStream Security Inc. | 5201 Great America Parkway Suite 346, Santa Clara, CA 95054