Ravenna Legal

Our customer agreements, privacy practices, and website terms - all in one place.

Ravenna Legal

Our customer agreements, privacy practices, and website terms - all in one place.

Ravenna Software Cloud Services Agreement

Last Modified: Sept 03, 2026

This Cloud Services Agreement ("Agreement") is between Ravenna Software, Inc. ("Ravenna Software") and the customer accepting this Agreement ("Customer" or "You"). This Agreement allows Customer to purchase access to certain of Ravenna Software's services as specified under one or more Orders. Certain capitalized terms are defined in Exhibit A and others are defined contextually in this Agreement.

Please read this Agreement carefully before accessing or using the Services. By clicking through this Agreement, or otherwise entering into an Order referencing this Agreement for its terms, you accept and agree to be bound by this Agreement. If you do not agree to any of the terms or conditions of this Agreement, you must not use the Services. If you will be using the Services on behalf of a legal entity, you agree to the terms of this Agreement on behalf of that entity and you represent and warrant that you have the authority to bind that entity to this Agreement.

Cloud Service Agreement

Overview

Ravenna Software provides an enterprise ticketing and service management platform powered by artificial intelligence. The platform enables organizations to track, manage, and respond to internal service requests from their employees. Users can submit tickets, questions, prompts, or other inputs (“Requests”) through multiple channels, and the Services generate responsive outputs, including information, documents, and automated workflows (“Outputs”) using artificial intelligence, analytics, and integrations with the customer’s third-party applications.

  1. Services

    1.1 Ordering Process
    Services are purchased as stated in an Order in the manner established for each of the Services. Each Order will include the specific Services ordered by Customer, including, as applicable, the purchased Services, number of seats, and the time period for which such Order applies. If Customer exceeds a usage or seat limit in an Order, Ravenna Software may work with Customer usage so that it conforms to that limit. If, notwithstanding Ravenna Software’s efforts, Customer is unable or unwilling to abide by a seat or usage limit in an Order, Customer will execute an Order for additional quantities of the applicable Services promptly upon Ravenna Software’s request, and/or pay any invoice for excess seats or usage in accordance with the “Fees and Taxes” section below.

    1.2 Permitted Use
    During a Subscription Term, subject to Customer’s compliance with the terms of this Agreement, Customer may access and use the Services only for its internal business purposes in accordance with the Documentation, this Agreement, and any limitations set forth in an Order. In order to use certain features of the Service, Customer must be a licensed user of Slack.

    1.3 Users
    Only Users, using the mechanisms designated by Ravenna Software (“Log-in Credentials”), may access and use the Services. Each User must keep its Log-in Credentials confidential and not share them with anyone else. Customer is responsible for its Users’ compliance with this Agreement and all actions taken through their Log-in Credentials (excluding misuse of the Log-in Credentials caused by Ravenna Software’s breach of this Agreement). Customer will promptly notify Ravenna Software if it becomes aware of any compromise of any Log-in Credentials. Ravenna Software may Process Log-in Credentials in connection with Ravenna Software’s provision of the Services or for Ravenna Software’s internal business purposes.

    1.4 Restrictions
    Customer will not (and will not permit anyone else to) do any of the following: (a) provide access to, distribute, sell, or sublicense a Service to a third party (other than Users); (b) use a Service on behalf of, or to provide any product or service to, third parties; (c) use a Service to develop a similar or competing product or service; (d) reverse engineer, decompile, disassemble, or seek to access the source code or non-public APIs to a Service, except to the extent expressly permitted by Law (and then only with prior notice to Ravenna Software); (e) modify or create derivative works of a Service or copy any element of a Service; (f) remove or obscure any proprietary notices in a Service; (g) publish benchmarks or performance information about a Service; (h) interfere with the operation of a Service, circumvent any access restrictions, or conduct any security or vulnerability test of a Service; (i) transmit any viruses or other harmful materials to a Service; (j) take any action that risks harm to others or to the security, availability, or integrity of a Service; or (k) access or use a Service in a manner that violates any Law. Additionally, Customer must not use a Service with Prohibited Data or for High Risk Activities. If Customer requires processing of protected health information (as defined under HIPAA), the parties will execute a mutually agreed on Business Associate Agreement prior to such processing. Notwithstanding anything else in this Agreement, Ravenna Software has no liability for Prohibited Data or use of a Service for High Risk Activities.

  2. Support
    Unless otherwise stated in the Order, Ravenna Software will make commercially reasonable efforts to provide Customer with general support for its use of the Services including a dedicated support channel and an assigned support contact. Ravenna Software will use commercially reasonable efforts to respond to support requests based on the following target response times: Priority 1 (service unavailable): four (4) business hours; Priority 2 (service degraded): one (1) business day; Priority 3 (general inquiries): two (2) business days. For clarity, support is available during Ravenna Software’s standard business hours.

  3. Service Level Agreement
    Ravenna Software shall use commercially reasonable efforts to make access to the Services, available twenty-four (24) hours per day, seven (7) days a week with a minimum uptime level of ninety-nine point five percent (99.5%) measured on an aggregate monthly basis. Such service availability does not, however, include regularly scheduled maintenance or any unscheduled downtime due to failures beyond Ravenna Software’s control (such as errors or malfunctions due to the end user’s computer systems, local networks or Internet connectivity). If Ravenna Software fails to meet the 99.5% uptime target in any calendar month, Customer may request a service credit equal to 5% of the monthly fees for each full 1% below the target, up to a maximum of 25% of that month’s fees. Service credits must be requested within thirty (30) days of the month in which the downtime occurred and will be applied to the next invoice or, if no further invoices are due, refunded within thirty (30) days. Service credits are Customer’s sole and exclusive remedy for failure to meet the uptime target.

  4. Upgrades
    Ravenna Software may update and improve the Services from time to time, provided that no such update will materially degrade the functionality of the Services during a Subscription Term. Ravenna Software will provide reasonable notice of significant changes

  5. Data
    5.1 Use of Customer Data
    Customer grants Ravenna Software a limited, non-exclusive, worldwide license to use, copy, store, transmit, transfer, and modify Customer Data solely to provide, maintain, and evolve the Services during the Term. For clarity, by using the Services, Customer hereby grants a license to Ravenna Software to transfer, transmit, distribute, or otherwise make available Customer Data to LLMs and, as applicable, the providers of such LLMs set forth in Exhibit B, in accordance with this Agreement provided such parties are bound by obligations no less protective than those in this Agreement. For the sake of clarity, Ravenna Software will not use Customer Data to train, fine-tune, or otherwise develop any artificial intelligence or machine learning models. Ravenna Software uses hosted third party LLMs to provide the Services, and Customer Data processed by such LLMs is not used to train those models.

    5.2 Privacy and Security
    Ravenna Software will implement and maintain a written information security program that includes administrative, technical, and physical safeguards designed to protect Customer Data against unauthorized access, use, alteration, and disclosure. Such safeguards will include, as applicable, encryption of Customer Data in transit and at rest, access controls, logging and monitoring, vulnerability management, and employee confidentiality obligations including, as applicable, the measures set forth in the Data Security Requirements, which are attached hereto as Exhibit C. Ravenna Software will notify Customer without undue delay, and in any event within seventy-two (72) hours after confirming, any security incident affecting Customer Data, and will provide reasonably requested information regarding the nature of the incident, affected data, and remediation steps. Upon Customer’s written request (no more than once per calendar year), Ravenna Software will make available reasonable information regarding its security program and, if available, then-current third party audit reports or certifications, subject to confidentiality restrictions. To the extent applicable, each party will comply with its respective obligations as set forth in the Data Processing Addendum (including the U.S. Supplement), which is attached hereto as Exhibit B and incorporated herein by reference.

    5.3 Use of Customer Data
    Ravenna Software may Process Usage Data and Aggregated Data for internal business purposes, such as to: (a) track use of Services for billing purposes; (b) provide support for Services; (c) monitor the performance and stability of the Services; (d) prevent or address technical issues with the Services; (e) to improve Services, its other products and services, and to develop new products and services; and (f) for all other lawful business practices, such as analytics, benchmarking, and reports (“Limited Purposes”). Ravenna Software may not disclose Usage Data to third parties. Ravenna may only disclose Aggregated Data to its third party service providers for the Limited Purposes and subject to obligations of confidentiality. To the extent any Usage Data incorporates or is derived from Customer Data, such Usage Data will be treated as Customer’s Confidential Information under this Agreement. For clarity, Ravenna Software shall not sell, disclose, or otherwise commercialize Usage Data or Aggregated Data in a manner that identifies Customer or reveals Customer’s confidential information.

    Suspension of Service
    Ravenna Software may suspend Customer’s access to any or all of the Services upon five (5) business days’ written notice if Customer materially breaches this Agreement, provided that Customer fails to cure such breach within such notice period. Ravenna Software may suspend access immediately and without prior notice if necessary to prevent a security threat, illegal activity, or material harm to Ravenna Software or other customers. Any suspension will be limited to the affected portions of the Services where practicable. Ravenna Software will not suspend Services for non-payment of fees that are subject to a good-faith dispute, provided Customer has notified Ravenna Software of the dispute in writing.

  6. Customer Systems
    Customer will provide and maintain any Customer Systems.

  7. Third-Party Platforms; LLMs
    7.1 Third-Party Platforms
    Ravenna Software may make available one or more integrations through the Services that enable Customer to import or export information to or from Customer’s account on a Third-Party Platform. Ravenna Software may enable Customer to import or export such information, including Customer Data, by linking Customer’s account on the Services with an account on the Third-Party Platform. If Customer directs Ravenna Software to transmit data to, or receive data from, a Third-Party Platform on Customer’s behalf (including by enabling the applicable integration in the settings of the Services), then Customer authorizes Ravenna Software to collect, access, use, disclose, transfer, transmit, store, or otherwise process (“Process”) any such data (including Customer Data) in connection with the applicable integration, in a manner consistent with the functionality of the Services requested by Customer and the permissions granted to Ravenna Software by the relevant integration (which Processing may include performing queries on the data held by the Third-Party Platform). Use of Third-Party Platforms is subject to Customer’s agreement with the relevant provider and not this Agreement. In such case, Customer is responsible for the terms and costs of its own LLM provider, and Ravenna Software will cooperate in reasonable configuration efforts Ravenna Software does not control and has no liability for any Third-Party Platform, including their security, functionality, operation, availability, or interoperability with the Services or how the Third-Party Platforms, including any LLMs, or their providers, use Customer Data or Customer’s Requests.

    7.2 LLMs; Outputs
    Ravenna Software uses LLMs to provide the Services and generate Outputs. For the sake of clarity, Outputs will not be used to train, fine-tune, or otherwise develop any artificial intelligence or machine learning models. Before using the Services, Customer acknowledges that it has reviewed and agrees to comply with the acceptable use policies of the LLMs, including the policies set forth in Exhibit D. Customer is responsible for its compliance with such policies, and Ravenna Software has no responsibility for any interruptions to the Services caused by Customer’s violation of such policies. Ravenna Software may suspend or terminate Customer’s use of all or part of the Services if Ravenna Software becomes aware that Customer is violating any such policy. Customer acknowledges that certain features of the Services use machine learning or large language model technologies to generate Outputs and that such Outputs may be probabilistic in nature and may contain inaccuracies. Customer remains responsible for reviewing Outputs before using them in production, compliance, legal, employment, financial, or other high-impact contexts. Ravenna Software will use commercially reasonable efforts to configure and provide the Services in a manner consistent with the Documentation and applicable Order. Ravenna Software is responsible for the performance of the Services as provided by Ravenna Software, but is not responsible for decisions made by Customer or its users in reliance on Outputs without reasonable human review where such review is appropriate under the circumstances. Notwithstanding the foregoing and for the sake of clarity, Ravenna Software will not use, and will not permit any third party to use or rely on Customer Data to fine tune, improve or otherwise develop any artificial intelligence tools or LLM.

  8. Customer Obligations
    By enabling an integration with a Third-Party Platform on the Services, Customer represents and warrants that Customer has the necessary licenses, rights, consents, and permissions to authorize Ravenna Software to access Customer’s Customer Data on such Third-Party Platform and exercise the licenses granted by Customer in this Agreement in the manner contemplated by Ravenna Software, the Services, and this Agreement. Customer will be responsible for enabling Ravenna Software to access and use each item of Customer Data, including to the extent they are stored on a Third-Party Platform. Customer retains responsibility for its contractual obligations with respect to Customer Data, including Ravenna Software’s access to the materials on a Third-Party Platform. Customer is responsible for its Customer Data, including its content and accuracy. Customer represents and warrants that it has made all disclosures, provided all notices, and has obtained all rights, consents, and permissions necessary for Ravenna Software to Process Customer Data as contemplated by this Agreement without violating or infringing applicable Laws, third-party rights, or terms, notices, or policies that apply to Customer Data.

  9. Commercial Terms
    9.1 Subscription Term
    Except as set forth in an Order, each Subscription Term will automatically renew for successive periods equal to the initial Subscription Term unless either party provides written notice of non-renewal at least thirty (30) days before the end of the then-current Subscription Term.

    9.2 Fees and Taxes
    Fees for the Services are described in each Order (“Fees”). All Fees will be paid in US dollars unless otherwise provided in an Order. Fees are invoiced as described on the schedule in the Order. Unless the Order provides otherwise, all Fees are due within 30 days of the invoice date. Fees for renewal Subscription Terms are at Ravenna Software’s then-current rates, regardless of any discounted pricing in a prior Order. Late payments are subject to a service charge of 1.5% per month or the maximum amount allowed by Law, whichever is less. All Fees are non-refundable except as may be set out in Section 10.2 (Warranty Remedy) and Section 14.4 (Mitigation). Customer is responsible for any sales, use, GST, value-added, withholding, or similar taxes or levies that apply to Orders, whether domestic or foreign, other than Ravenna Software’s income tax (“Taxes”). Fees are exclusive of all Taxes.

  10. Warranties and Disclaimers

    10.1 Limited Warranty
    Ravenna Software warrants to Customer that each of the Services will perform materially as described in its Documentation and Ravenna Software will not materially decrease the overall functionality of the Service (“Limited Warranty”) during a Subscription Term (“Warranty Period”).

    10.2 Warranty Remedy
    If Ravenna Software breaches the Limited Warranty during the applicable Warranty Period and Customer makes a reasonably detailed warranty claim in the manner required by Ravenna Software within 30 days of discovering a breach of the Limited Warranty, then Ravenna Software will use reasonable efforts to correct the non-conformity. If Ravenna Software cannot do so within 30 days of receipt of Customer’s warranty claim, either party may terminate the affected Order as it relates to the non-conforming Service. Ravenna Software will then refund to Customer any pre-paid, unused fees for the terminated portion of the applicable Subscription Term. This Section sets forth Customer’s exclusive remedy and Ravenna Software’s entire liability for breach of the Limited Warranty. These warranties do not apply to: (a) issues caused by Customer’s or Users’ misuse of or unauthorized modifications to the applicable Service; (b) issues in or caused by Third-Party Platforms or other third-party systems; (c) use of the applicable Service other than according to the Documentation; or (d) Trials and Betas or other free or evaluation use.

    10.3 Disclaimers
    Except as expressly provided in Section 10.1 (Limited Warranty), the Services and all other Ravenna Software services are provided “AS IS”. Ravenna Software, on its own behalf and on behalf of its suppliers and licensors, makes no other warranties, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, title, or noninfringement. Ravenna Software does not warrant that Customer’s use of the Services will be uninterrupted or error-free, that Ravenna Software will review Customer Data for accuracy, or that it will maintain Customer Data without loss. Ravenna Software is not liable for delays, failures, or problems inherent in use of the Internet and electronic communications or other systems outside Ravenna Software’s control. Customer may have other statutory rights, but any statutorily required warranties will be limited to the shortest legally permitted period.

  11. Warranties and Disclaimers
    11.1 Term
    The term of this Agreement (the “Term”) starts on the Effective Date and continues until expiration or termination of all Subscription Terms.

    11.2 Termination
    Either party may terminate this Agreement (including any or all Orders) if the other party: (a) fails to cure a material breach of this Agreement (including a failure to pay fees) within 30 days after notice; (b) ceases operation without a successor; or (c) seeks protection under a bankruptcy, receivership, trust deed, creditors’ arrangement, composition, or comparable proceeding, or if such a proceeding is instituted against that party and not dismissed within 60 days.

    11.3 Effect of Termination
    Upon expiration or termination of an Order, Customer’s access to and Ravenna Software’s obligations to provide the Services described in the Order and any Software will cease. During a Subscription Term and for the twelve (12) months period immediately following the date of expiration or earlier termination of the applicable Subscription Term, Customer may export data or information that Customer (including its Users) submits to the Services, including from Third-Party Platforms from the applicable Service using the export features described in the applicable Documentation. After that twelve (12) month period, Ravenna Software will be under no obligation to store or retain the applicable Customer Data and may delete the applicable Customer Data at any time in its sole discretion. Customer Data and other Confidential Information, as defined in Section 15, may be retained in Recipient’s standard backups notwithstanding any obligation to delete the applicable Confidential Information but will remain subject to this Agreement’s confidentiality restrictions. Notwithstanding the foregoing, Customer may request earlier deletion at any time, and Ravenna Software will comply within thirty (30) days of such request.

    11.4 Survival
    These Sections survive expiration or termination of this Agreement: 1.4 (Restrictions), 5.3 (Usage Data; Aggregated Data), 8 (Customer Obligations), 9.2 (Fees and Taxes), 10.3 (Disclaimers), 11.3 (Effect of Termination), 11.4 (Survival), 12 (Ownership), 13 (Limitations of Liability), 14 (Indemnification), 15 (Confidentiality), 16 (Required Disclosures), 19 (General Terms), and Exhibit A (Definitions). Except where an exclusive remedy is provided in this Agreement, exercising a remedy under this Agreement, including termination, does not limit other remedies a party may have.

  12. Ownership
    Neither party grants the other any rights or licenses not expressly set out in this Agreement. Except as expressly provided in this Agreement, as between the parties, Customer retains all intellectual property rights and other rights in Customer Data provided to Ravenna Software. Except for Customer’s use rights in this Agreement, Ravenna Software and its licensors retain all intellectual property rights and other rights in the Services, Software, Documentation, Usage Data, and Ravenna Software technology, templates, formats, and dashboards, including any modifications or improvements to these items made by Ravenna Software. If Customer provides Ravenna Software with feedback or suggestions regarding the Services or other Ravenna Software offerings, Ravenna Software may use the feedback or suggestions without restriction or obligation.

  13. Limitations of Liability
    13.1 Consequential Damages Waiver
    Except for Excluded Claims (as defined below) neither party (nor its suppliers or licensors) will have any liability arising out of or related to this Agreement for any loss of use, lost data, lost profits, failure of security mechanisms, interruption of business, or any indirect, special, incidental, reliance, or consequential damages of any kind, even if informed of their possibility in advance.

    13.2 Liability Cap
    Except for Excluded Claims, each party’s (and its suppliers’ and licensor’s) entire liability arising out of or related to this Agreement will not exceed in aggregate the amounts paid or payable by Customer to Ravenna Software pursuant to this Agreement during the 12 months prior to the date on which the applicable claim giving rise to the liability arose under this Agreement.

    13.3 Data Security Limitation
    Notwithstanding the foregoing or anything to the contrary, each party’s aggregate liability for claims arising out of or related to breaches of confidentiality or data security including (a) breaches of confidentiality obligations under Section 16, (b) breaches of data protection obligations under Exhibit B, or (c) security breaches caused by such party, will not exceed three times (3x) the amounts paid or payable by Customer to Ravenna Software during the twelve (12) month period prior to the event giving rise to the liability.

    13.4 Excluded Claims
    “Excluded Claims” means: (a) Customer’s breach of Sections 1.4 (Restrictions) or 8 (Customer Obligations); (b) either party’s breach of Section 15 (Confidentiality) (but excluding claims relating to Customer Data); or (c) amounts payable to third parties under the indemnifying party’s obligations in Section 14 (Indemnification).

    13.5 Nature of Claims and Failure of Essential Purpose
    The waivers and limitations in this Section 13.4 apply regardless of the form of action, whether in contract, tort (including negligence), strict liability or otherwise and will survive and apply even if any limited remedy in this Agreement fails of its essential purpose.

  14. Indemnification
    14.1 Indemnification by Ravenna Software
    Ravenna Software will defend Customer from and against any third-party claim to the extent alleging that a Service as operated by Ravenna Software, when used by Customer as permitted under the applicable Order infringes or misappropriates a third-party’s U.S. patent, copyright, trademark, or trade secret, and will indemnify and hold harmless Customer against any damages and costs awarded against Customer (including reasonable attorneys’ fees) or agreed in a settlement by Ravenna Software resulting from the claim.

    14.2 Indemnification by Customer
    Customer will defend Ravenna Software from any actual or threatened third party claim arising out of or based upon Customer’s use of the Services, Customer’s breach of any of the provisions of this Agreement, or Customer’s dispute with any Third-Party Platform (including any LLM). Customer will indemnify and hold harmless Ravenna Software against any damages and costs awarded against Ravenna Software (including reasonable attorneys’ fees) or agreed in a settlement by Customer resulting from the claim. Notwithstanding the foregoing, Customer’s indemnification obligations under this Section shall not apply to the extent any claim arises from Ravenna Software’s gross negligence, willful misconduct, or violation of applicable law.

    14.3 Procedures
    The indemnifying party’s obligations in this Section 14 are subject to it receiving: (a) prompt written notice of the claim; (b) the exclusive right to control and direct the investigation, defense, and settlement of the claim; and (c) all reasonably necessary cooperation of the indemnified party, at the indemnifying party’s expense for reasonable out-of-pocket costs. The indemnifying party may not settle any claim without the indemnified party’s prior consent if settlement would require the indemnified party to admit fault or take or refrain from taking any action (other than relating to use of the Services, when Ravenna Software is the indemnifying party). The indemnified party may participate in a claim with its own counsel at its own expense.

    14.4 Mitigation
    In response to an actual or potential infringement or misappropriation claim or otherwise relating to violation of intellectual property rights, if required by settlement or injunction or as Ravenna Software determines necessary to avoid material liability, Ravenna Software may at its option: (a) procure rights for Customer’s continued use of the applicable Service; (b) replace or modify the allegedly infringing portion of the applicable Service to avoid infringement or misappropriation without reducing the Service’s overall functionality; or (c) terminate the affected Order and refund to Customer any pre-paid, unused fees for the terminated portion of the Subscription Term.

    14.6 Exclusive Remedy
    This Section 14 sets out Customer’s exclusive remedy and Ravenna Software’s entire liability regarding infringement or misappropriation of third-party intellectual property rights.

  15. Confidentiality

    15.1 Definition
    “Confidential Information” means information disclosed to the receiving party (“Recipient”) under this Agreement that is designated by the disclosing party (“Discloser”) as proprietary or confidential or that should be reasonably understood to be proprietary or confidential due to its nature and the circumstances of its disclosure. Ravenna Software’s Confidential Information includes the terms and conditions of this Agreement, Usage Data and Aggregated Data, and any technical or performance information about the Services.

    15.2 Obligations
    As Recipient, each party will: (a) hold Confidential Information in confidence and not disclose it to third parties except as permitted in this Agreement, including Section 5.1 (Use of Customer Data); and (b) only use Confidential Information to fulfill its obligations and exercise its rights in this Agreement. At Discloser’s request, Recipient will delete all Confidential Information, except, in the case where Ravenna Software is the Recipient, Ravenna Software may retain the Customer’s Confidential Information to the extent required to continue to provide the Services. Recipient may disclose Confidential Information to its employees, agents, contractors, and other representatives having a legitimate need to know (including, for Ravenna Software, the subcontractors referenced in Section 19.9), provided it remains responsible for their compliance with this Section 15 and they are bound to confidentiality obligations no less protective than this Section 15.

    15.3 Exclusions
    These confidentiality obligations do not apply to information that Recipient can document: (a) is or becomes public knowledge through no fault of the receiving party; (b) it rightfully knew or possessed prior to receipt under this Agreement; (c) it rightfully received from a third party without breach of confidentiality obligations; or (d) it independently developed without using Confidential Information.

    15.4 Remedies
    Unauthorized use or disclosure of Confidential Information may cause substantial harm for which damages alone are an insufficient remedy. Each party may seek appropriate equitable relief, in addition to other available remedies, for breach or threatened breach of this Section.

  16. Required Disclosures
    Nothing in this Agreement prohibits either party from making disclosures, including of Customer Data and other Confidential Information, if required by Law, subpoena, or court order, provided (if permitted by Law) it notifies the other party in advance and cooperates in any effort to obtain confidential treatment.

  17. Trials and Betas
    If Customer receives access to Services or features thereof on a free or trial basis or as an alpha, beta, or early access offering (“Trials and Betas”), use is permitted only for Customer’s internal evaluation during the period designated by Ravenna Software (or if not designated, 30 days). Trials and Betas are optional and either party may terminate Trials and Betas at any time for any reason. Trials and Betas may be inoperable, incomplete, or include features that Ravenna Software may never release, and their features and performance information are Ravenna Software’s Confidential Information. Notwithstanding anything else in this Agreement, Ravenna Software provides no warranty, indemnity or support for Trials and Betas, and its liability for Trials and Betas will not exceed US$50.

  18. Publicity
    Neither party may publicly announce that the parties have entered into this Agreement, except with the other party’s prior consent or as required by Laws. However, Ravenna Software may include Customer and its trademarks in Ravenna Software’s customer lists and promotional materials but will cease further use at Customer’s written request.

  19. General Terms
    19.1 Assignment
    Neither party may assign this Agreement without the prior consent of the other party, except that either party may assign this Agreement in connection with a merger, reorganization, acquisition, or other transfer of all or substantially all its assets or voting securities to the other party involved in such transaction. Any non-permitted assignment is void. This Agreement will bind and inure to the benefit of each party’s permitted successors and assigns.

    19.2 Governing Law, Jurisdiction and Venue
    This Agreement is governed by the laws of the State of Delaware and the United States without regard to conflicts of laws provisions that would result in the application of the laws of another jurisdiction and without regard to the United Nations Convention on the International Sale of Goods. The jurisdiction and venue for actions related to this Agreement will be the state and United States federal courts located in King County, Washington and both parties submit to the personal jurisdiction of those courts.

    19.3 Attorneys’ Fees and Costs
    The prevailing party in any action to enforce this Agreement will be entitled to recover its attorneys’ fees and costs in connection with such action.

    19.4 Notices
    Except as set out in this Agreement, any notice or consent under this Agreement must be in writing to the addresses on the first page and will be deemed given: (a) upon receipt if by personal delivery; (b) upon receipt if by certified or registered U.S. mail (return receipt requested); or (c) one day after dispatch if by a commercial overnight delivery service. Notices may not be sent via email unless otherwise expressly permitted elsewhere in this Agreement. Either party may update its address with notice to the other party. Ravenna Software may also send operational notices to Customer by email or through the Services.

    19.5 Entire Agreement
    This Agreement (which includes all Orders) is the parties’ entire agreement regarding its subject matter and supersedes any prior or contemporaneous agreements regarding its subject matter. In this Agreement, headings are for convenience only and “including” and similar terms are to be construed without limitation. This Agreement may be executed in counterparts (including electronic copies and PDFs), each of which is deemed an original and which together form one and the same agreement.

    19.6 Amendments
    Unless the parties have agreed otherwise, Ravenna Software may revise and update this Agreement from time to time in its sole discn. All changes are effective immediately when posted, and apply to all access to and use of the Services thereafter. Customer’s continued use of the Services following the posting of revised or modified Agreement means that Customer accepts and agrees to the changes. Customer is expected to check this page from time to time so Customer is aware of any changes, as they are binding on Customer. The terms in any Customer purchase order or business form will not amend or modify this Agreement and are expressly rejected by Ravenna Software; any of these Customer documents are for administrative purposes only and have no legal effect.

    19.7 Waivers and Severability
    Waivers must be signed by the waiving party’s authorized representative and cannot be implied from conduct. If any provision of this Agreement is held invalid, illegal, or unenforceable, it will be limited to the minimum extent necessary so the rest of this Agreement remains in effect.

    19.8 Force Majeure
    Neither party is liable for any delay or failure to perform any obligation under this Agreement (except for a failure to pay fees) due to events beyond its reasonable control, such as a strike, blockade, war, pandemic, act of terrorism, riot, Internet or utility failures, refusal of government license, or natural disaster.

    19.9 Subcontractors
    Ravenna Software may use subcontractors and permit them to exercise Ravenna Software’s rights, but Ravenna Software remains responsible for their compliance with this Agreement and for its overall performance under this Agreement.

    19.10 Independent Contractors
    The parties are independent contractors, not agents, partners, or joint venturers.

    19.11 Export
    Customer will comply with all relevant U.S. and foreign export and import Laws in using any Service. Customer: (a) represents and warrants that it is not listed on any U.S. government list of prohibited or restricted parties or located in (or a national of) a country that is subject to a U.S. government embargo or that has been designated by the U.S. government as a “terrorist supporting” country; (b) agrees not to access or use Services in violation of any U.S. export embargo, prohibition, or restriction; and (c) will not submit to the Services any information controlled under the U.S. International Traffic in Arms Regulations.

Exhibit A
Definations

1.1 Affiliate
means an entity directly or indirectly owned or controlled by a party, where “ownership” means the beneficial ownership of 50% or more of an entity’s voting equity securities or other equivalent voting interests and “control” means the power to direct the management or affairs of an entity.

1.2 Aggregated Data
means Customer Data that has been deidentified or aggregated with other data such that the resulting data no longer reasonably identifies Customer or a specific individual.

1.3 Customer Data
means any data or information that: (a) Customer (including its Users) submits to the Services, including from Third-Party Platforms; and (b) is Processed by Ravenna Software to provide the Services to Customer. For clarity, Customer Data includes any Outputs the Service generates in response to Requests submitted by Customer.

1.4 Customer Systems
means Customer’s hardware, software, other technology, and infrastructure that Customer is required to provide and maintain in order for Customer to access and use the Services.

1.5 Documentation
means the then-current version of Ravenna Software’s usage guidelines and standard technical documentation for the Services that Ravenna Software makes generally available to its customers that it provides the applicable Services to, the current version of which are at https://docs.ravenna.ai/.

1.6 High Risk Activities
means activities where use or failure of a Service could lead to death, personal injury, or environmental damage, including life support systems, emergency services, nuclear facilities, autonomous vehicles, or air traffic control.

1.7 Laws
means all applicable relevant local, state, federal and international laws, regulations and conventions, including those related to data privacy and data transfer, international communications, and export of data.

1.8 LLM
means any third party or Ravenna Software language learning model that are used by Ravenna Software to provide the Services and generate the Outputs.

1.9 Order
means an order that describes the Services being purchased by Customer that is executed by the parties and references this Agreement.

1.10 Prohibited Data
means any: (a) special categories of data enumerated in European Union Regulation 2016/679, Article 9(1) or any successor legislation; (b) patient, medical, or other protected health information regulated by the Health Insurance Portability and Accountability Act (as amended and supplemented) (“HIPAA”); (c) credit, debit, or other payment card data subject to the Payment Card Industry Data Security Standard; (d) other information subject to regulation or protection under specific Laws such as the Children’s Online Privacy Protection Act or Gramm-Leach-Bliley Act (or related rules or regulations); (e) social security numbers, driver’s license numbers, or other government ID numbers; or (f) any data similar to the above protected Laws.

1.11 Service or Services
means the then-current version of Ravenna Software’s proprietary cloud service and other services that are identified in the relevant Order. Each of the Services includes the Software and Documentation for the Service.

1.12 Software
means the period during which Customer’s subscription to access and use the Services is in effect, as identified in the applicable Order.

1.13 Subscription Term
means the period during which Customer’s subscription to access and use the Services is in effect, as identified in the applicable Order.

1.14 Third-Party Platform
means any third-party platform, add-on, service, or product not provided by Ravenna Software that Customer elects to integrate or enable for use with any Service, including Slack and any LLM.

1.15 Updates
means any updates, modifications, or bug fixes to the Services or Documentation that Ravenna Software provides free of additional charge to its customers using a Service.

1.16 Upgrades
means additions, enhancements, upgrades, new services, or modules that include new features and substantial increases in functionality to the Services that Ravenna Software makes available to its customers for an additional fee.

1.17 Usage Data
means information generated from the use of the Services, which data does not identify Users, any other natural human persons, or Customer, such as technical logs, data, and learnings about Customer’s use of the Services, but excluding any identifiable Customer Data.

1.18 User

means any employee or contractor of Customer or its Affiliates that Customer allows to use the Services on Customer’s behalf.

Exhibit B

GDPR Data Processing Addendum

Pursuant to the Agreement, the parties hereby adopt this GDPR Data Processing Addendum (“DPA”) for so long as Ravenna Software Processes Customer Personal Data (as defined herein) on behalf of Customer pursuant to the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the subject matter of this DPA, the provisions of this DPA will control to the extent of such conflict.

  1. Definitions
    Capitalized terms used in this DPA and not otherwise defined in this DPA will have the meaning given to them in the Agreement. As used in this DPA:

    1.1 “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processor,” and “Supervisory Authority” have the meaning given to them by the GDPR;

    1.2 “Customer Personal Data” means Customer Data that constitutes Personal Data subject to Data Protection Law, for which Customer or Third-Party Controller is the Controller and which is Processed by Ravenna Software to provide the Services to Customer.

    1.3 “Data Protection Law” means the General Data Protection Regulation (EU) 2016/679 (“GDPR”), and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC), their national implementations in the European Economic Area (“EEA”), and all other data protection laws of the EEA including laws of the European Union (“EU”), the data protection laws of the United Kingdom (“UK”) and Switzerland, each as applicable, and as may be amended or replaced from time to time;

    1.4Data Subject Rights” means all rights granted to Data Subjects by Data Protection Law, including the right to information, access, rectification, erasure, restriction, portability, objection, the right to withdraw consent, and the right not to be subject to automated individual decision-making;

    1.5 “International Data Transfer” means any disclosure of Customer Personal Data by an organization subject to Data Protection Law to another organization located outside the EEA, the UK, or Switzerland;

    1.6Personnel” means any natural person acting under the authority of Ravenna Software;

    1.7Sensitive Data” means any type of Customer Personal Data that is designated as a sensitive or special category of Personal Data, or otherwise subject to additional restrictions under Data Protection Law or other laws to which the Controller is subject;

    1.8 “Subprocessor” means a Processor engaged by Ravenna Software to carry out Processing of Customer Personal Data on behalf of Ravenna Software;

    1.9 “SCCs” means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (OJ L 199, 7.6.2021, p. 31-61), as amended or replaced from time to time;

    1.10 “Third-Party Controller” means a Controller for which Customer is a Processor; and

    1.11 “UK Addendum” means the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022).


  2. Scope and Applicability

    2.1 This DPA applies to Processing of Customer Personal Data by Ravenna Software to provide the Services to Customer.

    2.2 The subject matter, nature, and purpose of the Processing, the types of Customer Personal Data and categories of Data Subjects are set out in Annex I, the Agreement, and any applicable Services Order or statement of work.

    2.3 Customer is a Controller and appoints Ravenna Software as a Processor on Customer’s behalf. Customer is responsible for compliance with the requirements of Data Protection Law applicable to Controllers.

    2.4 To the extent Customer is a Processor on behalf of a Third-Party Controller, Customer engages Ravenna Software as a Subprocessor to Process Customer Personal Data on behalf of that Third-Party Controller. When Customer is acting on behalf of Third-Party Controller(s), then Customer is the single point of contact for Ravenna Software; must obtain all necessary authorizations from such Third-Party Controller(s); undertake to issue all instructions and exercise all rights on behalf of such Third-Party Controller(s); and are responsible for compliance with the requirements of Data Protection Law applicable to Processors.

    2.5 Customer acknowledges that Ravenna Software may process Customer Personal Data relating to the operation, support, or use of the Services for its own business purposes, such as billing, account management, data analysis, benchmarking, technical support, and product development. Ravenna Software is the Controller for such Processing and will Process such data in accordance with Data Protection Law.

  3. Instructions
    3.1 Ravenna Software will Process Customer Personal Data to provide the Services and in accordance with Customer’s documented instructions.

    3.2 Customer’s instructions are documented in this DPA, the Agreement, and any applicable statement of work.

    3.3 Customer may reasonably issue additional instructions as necessary to comply with Data Protection Law. Ravenna Software may charge a reasonable fee to comply with any additional instructions.

    3.4 Unless prohibited by applicable law, Ravenna Software will inform Customer if Ravenna Software is subject to a legal obligation that requires Ravenna Software to Process Customer Personal Data in contravention of Customer’s documented instructions.


  4. Personnel
    4.1 Ravenna Software will take steps to ensure that all Personnel authorized by Ravenna Software to Process Customer Personal Data are subject to an obligation of confidentiality.

  5. Security and Personal Data Breaches
    5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Ravenna Software will implement appropriate technical and organizational security measures as set forth in Annex II.

    5.2 Ravenna Software will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Customer Personal Data. If Ravenna Software’s notification is delayed, it will be accompanied by reasons for the delay.

  6. Subprocessing
    6.1 Customer hereby authorizes Ravenna Software to engage Subprocessors. A list of Ravenna Software’s current Subprocessors is included in Annex III.

    6.2 Ravenna Software will enter into a written agreement with Subprocessors which imposes materially the same obligations as required by applicable Data Protection Law.

    6.3 Ravenna Software will inform Customer prior to any intended change to Subprocessors. Customer may object to the addition of a Subprocessor based on reasonable grounds relating to a potential or actual violation of Data Protection Law by providing written notice detailing the grounds of such objection within thirty (30) days following Ravenna Software’s notification of the intended change. Customer and Ravenna Software will work together in good faith to address Customer’s objection. If Ravenna Software chooses to retain the Subprocessor, Ravenna Software will inform Customer at least thirty (30) days before authorizing the Subprocessor to Process Customer Personal Data, and Customer may immediately discontinue using the relevant parts of the Services and may terminate the relevant parts of the Services within thirty (30) days.

  7. Assistance
    7.1 Taking into account the nature of the Processing and the information available to Ravenna Software, Ravenna Software will assist Customer, including, as appropriate, by implementing technical and organizational measures, with the fulfilment of Customer’s own obligations under Data Protection Law designed to: (i) comply with requests to exercise Data Subject Rights; (ii) conduct data protection impact assessments, (iii) engage in prior consultations with Supervisory Authorities, and (iv) to notify a Personal Data Breach.

    7.2 Ravenna Software may charge Customer a reasonable fee for assistance under this Section 7.

  8. Audit
    8.1 Ravenna Software must make available to Customer information in Ravenna Software’s possession reasonably necessary to demonstrate Ravenna Software’s compliance with its obligations under this DPA and allow for and contribute to audits, including inspections, to the extent required by a Supervisory Authority or reasonably requested by Customer and performed by an independent auditor as agreed upon by Customer and Ravenna Software.

    8.2 Ravenna Software will inform Customer if Ravenna Software believes that Customer’s instruction under Section 8.1 infringes Data Protection Law. Ravenna Software may suspend the audit or inspection or withhold requested information until Ravenna Software has modified or confirmed the lawfulness of the instructions in writing.

    8.3 Ravenna Software may charge Customer a reasonable fee for assistance under this Section 7.

  9. International Data Transfers

    9.1 Customer hereby authorizes Ravenna Software to perform International Data Transfers:

    a) To any country subject to a valid adequacy decision of the European Commission or the competent authorities, as appropriate;

    b) To the extent authorized by Supervisory Authorities on the basis of an organization’s binding corporate rules;

    c) on the basis of adequate safeguards in accordance with Data Protection Law; and

    d) to any data importer with whom Ravenna Software has entered into SCCs and the UK Addendum referred to in Sections 9.2 and 9.3.

    9.2 By signing this DPA, the parties hereby agree to conclude the provisions of module two (Controller to Processor) and, to the extent Customer is a Processor on behalf of a Third-Party Controller, module three (Processor to Subprocessor) of the SCCs, which are hereby incorporated into this DPA and completed as follows: the “data exporter” is Customer; the “data importer” is Ravenna Software; the optional docking clause in Clause 7 is implemented; Clause 9(a) option 2 is implemented and the time period therein is specified as thirty (30) days; the optional redress clause in Clause 11(a) is struck; the competent Supervisory Authority in Clause 13(a) is the Supervisory Authority indicated in Annex I.C; Clause 17 option 1 is implemented and the governing law is the law of Ireland; the courts in Clause 18(b) are the Courts of Dublin, Ireland; Annexes I and II to the SCCs are Annexes I and II to this DPA respectively.

    9.3 By signing this DPA, Customer and Ravenna Software conclude the UK Addendum, which is hereby incorporated herein and applies to International Data Transfers outside the UK. Part 1 of the UK Addendum is completed as follows: (i) in Table 1, the “Exporter” is Customer and the “Importer” is Ravenna Software, their details are set forth in this DPA, and the Agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are the SCCs referred to in Section 9.2 of this DPA; (iii) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Annex I and II respectively; and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.

    9.4 If Ravenna Software’s compliance with Data Protection Law applicable to International Data Transfers is affected by circumstances outside of Ravenna Software’s control, including if a legal instrument for International Data Transfers is invalidated, amended, or replaced, then Customer and Ravenna Software will work together in good faith to reasonably resolve such non-compliance. In the event that additional, replacement or alternative standard contractual clauses or UK standard contractual clauses are approved by Supervisory Authorities, Ravenna Software reserves the right to amend the Agreement and this DPA by adding to or replacing, the standard contractual clauses or UK standard contractual clauses that form part of it at the date of signature in order to ensure continued compliance with Data Protection Law.

  10. Notifications
    10.1 Customer will send all notifications, requests, and instructions under this DPA to Ravenna Software via email to privacy@ravenna.ai

    10.2 Ravenna Software will send all notifications under this DPA to Customer’s contact as provided by Customer.

  11. Liability
    For the sake of clarity, this DPA is incorporated into the Agreement and subject to the limitations of liablity set forth therein..

  12. Termination and Return or Deletion
    12.1 Customer may request return of Customer Personal Data up to thirty (30) days after termination of the Agreement. Unless required or permitted by applicable law, Ravenna Software will delete all remaining copies of Customer Personal Data within thirty (30) days after returning Customer Personal Data to Customer. Ravenna Software support will notify Customer prior to deletion.

  13. Invalidity and Severability.
    13.1 If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision will not affect any other provision of this DPA, and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

ANNEX I
DESCRIPTION OF THE TRANSFER

A. LIST OF PARTIES
Data exporter:

  • Name: Customer

  • Customer Address: Address provided by Customer.

  • Contact person’s name, position, and contact details: Contact information as provided by Customer

  • Activities relevant to the data transferred under these Clauses: Receiving the Services as described in the Agreement

  • Role (controller/processor): Controller, or Processor on behalf of Third-Party Controller

Data exporter:

  • Name: Ravenna Software, Inc.

  • Address: 3333 Wallingford Avenue N, Suite C-1, Seattle, WA 98103

  • Contact person’s name, position, and contact details: Kevin Coleman, COO, kevin@ravenna.ai

  • Activities relevant to the data transferred under these Clauses: Providing the Services as described in the Agreement

  • Role (controller/processor): Processor on behalf of data exporter or Subprocessor on behalf of Third-Party Controller

B. DESCRIPTION OF INTERNATIONAL DATA TRANSFER
Categories of Data Subjects whose Customer Personal Data is transferred:

#

Category of Data Subjects

1

End-Users

2

End-Users’ customers or users, as applicable

3

Other individuals whose personal data is contained in Customer Personal Data

Categories of Customer Personal Data transferred

#

Category of Personal Data

1

Name and contact information

2

IP address

3

Billing address

The following categories of Sensitive Data are transferred:

#

Category of Sensitive Data

Applied restrictions or safeguards

1

None

N/A

  • The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): The data is transferred on a continuous basis.

  • Nature of the Processing: The Processing concerns the provision of Services as set out in the Agreement.

  • Purpose(s) of the data transfer and further Processing: To provide the Services as described in the Agreement.

  • The period for which Customer Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.

  • For transfers to (Sub)Processors, also specify subject matter, nature, and duration of the Processing: For the subject matter and nature of the Processing, reference is made to the Agreement and this DPA. The Processing will take place for the duration of the Agreement.

C. COMPETENT SUPERVISORY AUTHORITY

  • The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in the EEA is the Supervisory Authority a) of Customer’s country of establishment, or, where not applicable, b) of the country where Customer’s EU data protection representative is located, or, where not applicable, c) of one of the EEA countries where the Data Subjects are located.

  • The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in the UK is the UK Information Commissioner.

  • The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.

ANNEX II
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Ravenna Software will implement commercially reasonable security measures to protect Customer Personal Data in its possession or control, including the security measures outlined in the Data Security Requirements in Exhibit C.

The measures in the Data Security Requirements apply to all transfers of Customer Personal Data described in this DPA. Where Ravenna Software acts as (sub-) processor, the specific technical and organizational measures taken by Ravenna Software to provide assistance to Customer, or the Third-Party Controller are described in Section 7 of this DPA.

ANNEX III
LIST OF SUBPROCESSORS

The table below contains a list of Ravenna Software’s current Subprocessors, pursuant to the general authorization provided by Customer in Section 6.1.

#

Name

Address

Description of Processing

1

Amazon Web Services

410 Terry Avenue North, Seattle, WA 98109-5210

Ravenna uses Amazon Relational Database as our primary Data Store. Ravenna also uses Amazon CloudWatch to process system logs

2

Sentry

132 Hawthorne Street, San Francisco, CA 94107

Ravenna uses Sentry to track software errors that occur in production systems.

3

Grafana Labs

29 Broadway, New York, NY

Ravenna uses Grafana to process and visualize System logs.

4

Langfuse North America

156 2nd St, Suite 305, San Francisco, CA 94105, USA

Ravenna uses Langfuse as an LLM observability provider.

5

PostHog

2261 Market Street #4008, San Francisco, CA 94114

Ravenna uses PostHog to track software usage and visualize analytics.

6

OpenAI

3180 18th St, Suite 100, San Francisco, CA 94110

Ravenna uses hosted LLMs from OpenAI.

7

Google

1600 Amphitheatre Parkway, Mountain View, CA 94043

Ravenna uses hosted LLMs from Google.

8

Anthropic

548 Market St, PMB 90375, San Francisco, CA 94104

Ravenna uses hosted LLMs from Anthropic.

9

LaunchDarkly

1999 Harrison Street, Suite 1100, Oakland, CA 94612

Ravenna uses LaunchDarkly to manage and control feature flag rollouts.

10

Vercel

440 N Barranca Ave PMB 4133, Covina, CA 91723

Ravenna uses Vercel as a cloud infrastructure and deployment platform for hosting and serving the Services.

11

E2B

166 Geary St, 5th FloorSan Francisco, CA 94108

Ravenna uses E2B to execute code in secure sandboxed environments for AI agent workflows.

12

Cohere

530 Lytton Ave, Palo Alto, CA 94301

Ravenna uses hosted LLMs from Cohere.

13

Retool (self-hosted)

1550 Bryant Street, San Francisco, CA 94103

Ravenna uses Retool as a self-hosted internal tooling platform for operational workflows. AsRetool is self-hosted by Ravenna, Customer Data does not leave Ravenna's infrastructure in connection with this subprocessor.

14

Plain

3rd Floor, 1 Ashley Road, Altrincham, Cheshire, WA14 2DT, United Kingdom

Customer Support.

U.S. SUPPLEMENT TO EXHIBIT B

U.S. Privacy Law Data Processing Addendum

Ravenna Software and Customer hereby adopt this U.S. Privacy Law Data Processing Addendum (“U.S. DPA”) for so long as Ravenna Software processes Customer Personal Information (as defined herein) on Customer’s behalf pursuant to the Agreement. In the event of a conflict between this U.S. DPA and the Agreement with respect to the subject matter of this U.S. DPA, this U.S. DPA will prevail to the extent of such conflict.

  1. Definitions.

    Capitalized terms used in this U.S. DPA and not defined herein will have the meanings given to them by the Agreement. As used in this U.S. DPA--

    1. “CCPA” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020.

    2. “Consumer” means a natural person. Where applicable, Consumer shall be interpreted consistent with the same or similar term under the U.S. Privacy Laws.

    3. "Controller” means a person or entity that collects individuals’ Personal Information and alone, or jointly with others, determines the purposes and means of the Processing of such Personal Information. Where applicable, Controller shall be interpreted consistent with the same or similar term under the U.S. Privacy Laws.

    4. “Customer Personal Information” means Customer Data that constitutes Personal Information subject to U.S. Privacy Laws.

    5. “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person. Where applicable, Personal Information shall be interpreted consistent with the same or similar term under U.S. Privacy Laws

    6. “Processor” means “Processor,” “Service Provider,” or “Contractor” as those terms are defined in U.S. Privacy Laws.

    7. “Sale” and “Selling” have the meaning defined in the U.S. Privacy Laws.

    8. “Share,” “Shared,” and “Sharing” have the meaning defined in the CCPA.

    9. U.S. Privacy Laws” means, collectively, all U.S. federal and state privacy laws and their implementing regulations, as amended or superseded from time to time, that apply generally to the Processing of individuals' Personal Information and that do not apply solely to specific industry sectors (e.g., financial institutions), specific demographics (e.g., children), or specific classes of information (e.g., health or biometric information), in each case where applicable to the Processing of Customer Personal Information by Ravenna Software pursuant to the Agreement. U.S. Privacy Laws may include, but are not limited to, the CCPA. In the event of a conflict in the meanings of defined terms in U.S. Privacy Laws, the meaning from the law applicable to the state of residence of the relevant Consumer applies.


  2. Scope, Roles, and Termination.

    1. Applicability - This U.S. DPA applies only to Ravenna Software’s Processing of Customer Personal Information for the nature, purposes, and duration set forth in Annex I.

    2. Roles of the Parties - For the purposes of the Agreement and this U.S. DPA, Customer is the party responsible for determining the purposes and means of Processing Customer Personal Information as the Controller and appoints Ravenna Software as a Processor to Process Customer Personal Information on Customer’s behalf for the limited and specific purposes set forth in Annex I.

    3. Obligations at Termination - Upon termination of the Agreement, except as set forth therein or herein, Ravenna Software will discontinue Processing and destroy or return Customer Personal Information in its or its subcontractors’ and sub-processors’ possession without undue delay. Ravenna Software may retain Customer Personal Information to the extent required by law but only to the extent and for such period as required by such law and always provided that Ravenna Software shall take steps to ensure the confidentiality of all such Customer Personal Information


  3. Compliance

    1. Compliance with Obligations – Ravenna Software will take steps to ensure that its employees, agents, subcontractors, and sub-processors: (i) comply with applicable obligations of U.S. Privacy Laws, (ii) provide the level of privacy protection for Customer Personal Information required by applicable U.S. Privacy Laws, and (iii) provide Customer with reasonable assistance to enable Customer to fulfill Customer’s own obligations under applicable U.S. Privacy Laws. Upon Customer’s reasonable request, Ravenna Software shall make available to Customer information in Ravenna Software’s possession necessary to demonstrate Ravenna Software’s compliance with this subsection.

    2. Compliance Assurance – Customer has the right to take reasonable and appropriate steps to ensure that Ravenna Software uses Customer Personal Information consistent with Customer’s obligations under applicable U.S. Privacy Laws.

    3. Compliance Monitoring - No more than once per calendar year, Ravenna Software will provide to Customer, upon Customer’s written request, information and documentation in Ravenna Software’s possession and control necessary to demonstrate Ravenna Software’s compliance with its obligations under this U.S. DPA.

    4. Compliance Remediation – Ravenna Software shall notify Customer if it determines that it can no longer meet its obligations under applicable U.S. Privacy Laws. Upon receiving notice from Ravenna Software in accordance with this subsection, Customer may direct Ravenna Software to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.

    5. Security - The parties shall implement and maintain no less than commercially reasonable security procedures and practices, appropriate to the nature of the information, designed to protect Customer Personal Information from unauthorized access, destruction, use, modification, or disclosure, which will include, at a minimum, those set forth in the Data Security Requirements in Exhibit C.


  4. Restrictions on Processing.

    1. Limitations on Processing - Ravenna Software will Process Customer Personal Information as instructed in the Agreement. Except as expressly permitted by U.S. Privacy Laws, Ravenna Software is prohibited from (i) Selling or Sharing Customer Personal Information, (ii) retaining, using, or disclosing Customer Personal Information for any purpose other than for the specific purpose of performing the services specified in Annex I, (iii) retaining, using, or disclosing Customer Personal Information outside of the direct business relationship between the parties, and (iv) combining Customer Personal Information with Personal Information obtained from, or on behalf of, sources other than Customer, except as expressly permitted under applicable U.S. Privacy Laws.

    2. Confidentiality - Ravenna Software shall take steps to ensure that its employees, agents, subcontractors, and sub-processors are subject to a duty of confidentiality with respect to Customer Personal Information.

    3. Subcontractors: Sub-processors –Ravenna Software shall notify Customer of any intended changes concerning the addition or replacement of subcontractors or sub-processors. Further, Ravenna Software shall take steps to ensure that Ravenna Software’s subcontractors or sub-processors who Process Customer Personal Information on Ravenna Software’s behalf agree in writing to the same or materially equivalent restrictions and requirements that apply to Ravenna Software in this U.S. DPA and the Agreement with respect to Customer Personal Information, as well as to comply with U.S. Privacy Laws.

    4. Right to Object – Customer may object in writing to Ravenna Software’s appointment of a new subcontractor or sub-processor on reasonable grounds by notifying Ravenna Software in writing within 30 calendar days of receipt of notice. In the event Customer objects, the parties shall discuss Customer’s concerns in good faith with a view to achieving a commercially reasonable resolution.


  5. Consumer Rights.

    1. Ravenna Software shall provide commercially reasonable assistance to Customer for the fulfillment of Customer’s obligations to respond to U.S. Privacy Law-related Consumer rights requests regarding Customer Personal Information.

    2. Where applicable, Customer shall inform Ravenna Software of any Consumer rights request made pursuant to U.S. Privacy Laws with which Ravenna Software must comply with. Customer shall provide Ravenna Software with the information necessary for Ravenna Software to comply with the request.

    3. Ravenna Software shall not be required to delete any Customer Personal Information to comply with a Consumer’s rights request directed by Customer if retaining such information is specifically permitted by applicable U.S. Privacy Laws; provided, however, that in such case, Ravenna Software shall not use Customer Personal Information retained for any purpose other than provided for by that exception

  6. Exemptions.

    1. Notwithstanding any provision to the contrary in the Agreement or this U.S. DPA, the terms of this U.S. DPA shall not apply to Ravenna Software’s Processing of Customer Personal Information that is exempt from applicable U.S. Privacy Laws.

  7. Changes to Applicable Privacy Laws.
    1. The parties agree to cooperate in good faith to enter into additional terms to address any modifications, amendments, or updates to applicable statutes, regulations or other laws pertaining to privacy and information security, including, where applicable, U.S. Privacy Laws.

Exhibit C

Data Security Requirements

Capitalized terms used but not defined in these Data Security Requirements will have the meanings given to them by the Agreement. Ravenna Software and Customer will apply at least the following types of security measures to Customer Data, as applicable:

  1. Physical access control

Technical and organizational measures designed to prevent unauthorized persons from gaining access to the premises and facilities (including databases, application servers and related hardware) where Customer Data is Processed, such as:

  • Establishing security areas, restriction of access paths;

  • Establishing access authorizations for employees and third parties;

  • Access control system (ID reader, magnetic card, chip card);

  • Key management, card-keys procedures;

  • Door locking (electric door openers, etc.);

  • Security staff, janitors;

  • Surveillance facilities, video/CCTV monitor, alarm system; and

  • Securing decentralized data processing equipment and personal computers.

  1. Virtual access control
    Technical and organizational measures designed to prevent systems used to Process Customer Data from being used by unauthorized persons, such as:

  • User identification and authentication procedures;

  • ID/password security procedures (special characters, minimum length, change of password);

  • Automatic blocking (e.g., password or timeout);

  • Monitoring of break-in-attempts and automatic turn-off of the user ID upon several erroneous password attempts;

  • Creation of one master record per user, user-master data procedures per data processing environment; and

  • Encryption of archived data media.

  1. Data access control
    Technical and organizational measures designed to ensure confidentiality and that persons entitled to use a data processing system gain access only to such Customer Data in accordance with their access rights, and that Customer Data cannot be read, copied, modified, or deleted without authorization, such as:

  • Internal policies and procedures;

  • Control authorization schemes;

  • Default configuration;

  • Differentiated access rights (profiles, roles, transactions, and objects);

  • Monitoring and logging of access;

  • Disciplinary action against employees who access Customer Data without authorization;

  • Reports of access;

  • Access procedure;

  • Change procedure;

  • Deletion procedure; and

  • Encryption.

  1. Disclosure control
    Technical and organizational measures designed to ensure that Customer Data cannot be read, copied, modified, or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities to whom Customer Data is disclosed, such as:

  • Encryption/pseudonymization/tunneling;

  • Logging; and

  • Transport security.

  1. Entry control
    Technical and organizational measures designed to monitor whether Customer Data has been entered, changed, or removed (deleted), and by whom, from data processing systems, such as:

  • Logging and reporting systems; and

  • Audit trails and documentation.

  1. Control of Instructions
    Technical and organizational measures designed to ensure that Customer Data is Processed solely in accordance with the instructions of the Customer, such as:

    • Unambiguous wording of the contract;

    • Formal commissioning (request form); and

    • Criteria for selecting the processor.

  2. Availability control
    Technical and organizational measures designed to ensure the integrity, availability and resilience of the Processing systems, and that Customer Data is protected against accidental destruction or loss (physical/logical) such, as:

    • Backup procedures;

    • Mirroring of hard disks (e.g. RAID technology)

    • Uninterruptible power supply (UPS);

    • Remote storage;

    • Antivirus/firewall systems; and

    • Disaster recovery plan, in the event of a physical or technical incident.

  3. Separation control
    Technical and organizational measures designed to ensure that Customer Data collected for different purposes can be Processed separately, such as:

    • Separation of databases;

    • “Internal client” concept / limitation of use;

    • Segregation of functions (production/testing); and


  4. Testing controls
    Technical and organizational measures to test, assess, and evaluate the effectiveness of the technical and organizational measures implemented designed to ensure the security of the Processing, such as:

    • Periodic review and testing of disaster recovery plan;

    • Testing and evaluation of software updates before they are installed;

    • Authenticated (with elevated rights) vulnerability scanning; and

    • Test bed for specific penetration tests and red team attacks.

  5. IT governance
    Technical and organizational measures to improve the overall management of IT and ensure that the activities associated with information and technology are aligned with the compliance efforts, such as:

    • Certification/assurance of processes and products;

    • Processes for data minimization;

    • Processes for data quality;

    • Processes for limited data retention;

    • Processes for ensuring accountability; and

    • Data subject rights policies.

Exhibit D

LLM Acceptable Use Policies

Ravenna Software uses the following third-party large language model (“LLM”) providers as subprocessors to provide the Services. Customer’s use of the Services is subject to compliance with the acceptable use policies of each applicable LLM provider listed below, as required under Section 7.2 of the Agreement.

#

LLM Provider

Applicable Policy

Policy URL

1

OpenAI

Usage Policies

https://openai.com/policies/usage-policies/

2

Anthropic

Usage Policy

https://www.anthropic.com/legal/aup

3

Google

Google Cloud Platform Acceptable Use Policy

https://cloud.google.com/terms/aup


Questions about this document?

Reach our legal team at legal@ravenna.ai, or visit the Trust Center for security and compliance documentation.