Ennijo Data Processing Addendum

Effective Date: September 14, 2026
Version: 1.0

This Data Processing Addendum ("DPA") forms part of the applicable agreement governing use of Ennijo between 29in5 LLC, provider of the Ennijo product and service ("Ennijo," "Processor," "Service Provider," "Contractor," "we," "us," or "our"), and the applicable customer ("Customer," "Controller," "Business," "you," or "your").

The applicable agreement may include the Ennijo Beta Program Agreement and, when applicable, Ennijo's Terms of Service, order form, subscription agreement, or other agreement governing use of Ennijo.

This DPA governs Ennijo's processing of Customer Personal Data on behalf of Customer.

If there is a conflict between this DPA and another applicable agreement concerning the processing of Customer Personal Data, this DPA controls to the extent of that conflict.

1. Definitions

For purposes of this DPA:

"Applicable Data Protection Law" means privacy, data protection, and data security laws applicable to the processing of Customer Personal Data under this DPA, including, where applicable:

"Authorized User" means an individual permitted by Customer to access Customer's Ennijo account.

"Controller" means the person or organization that determines the purposes and means of processing Personal Data, including a "business" or similar responsible party under applicable U.S. privacy law.

"Customer Personal Data" means Personal Data processed by Ennijo on behalf of Customer in connection with Customer's use of Ennijo.

Customer Personal Data includes CRM Contact Data.

"CRM Contact Data" means Personal Data relating to prospects, clients, past clients, referral partners, vendors, professional contacts, sphere contacts, and other individuals whose information Customer enters, imports, synchronizes, receives, or maintains through Ennijo.

"Data Subject" means an identified or identifiable individual to whom Personal Data relates, including a "consumer" or similar term under applicable U.S. privacy law.

"Personal Data" means information relating to an identified or identifiable individual and includes "personal information," "personal data," and similar terms under Applicable Data Protection Law.

"Personal Data Breach" means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.

"Process," "Processing," and "Processed" have the meanings assigned under Applicable Data Protection Law.

"Processor" means an entity that processes Personal Data on behalf of a Controller, including a "service provider" or "contractor" where applicable.

"Service" means the Ennijo relationship management and customer relationship management product and related customer-facing features, tools, integrations, and support services provided by 29in5 LLC.

"Subprocessor" means a third party engaged by Ennijo to Process Customer Personal Data on behalf of Customer.

2. Roles of the Parties

For Customer Personal Data:

  1. Customer acts as the Controller, Business, or equivalent responsible party.
  2. 29in5 LLC, through Ennijo, acts as the Processor, Service Provider, Contractor, or equivalent party processing Personal Data on Customer's behalf.

Customer determines:

Ennijo processes Customer Personal Data to provide the Service and in accordance with Customer's documented instructions.

For information Ennijo processes for its own business purposes, such as account administration, billing, security records, and certain support information, 29in5 LLC may act as an independent Controller or Business as described in the Ennijo Privacy Policy.

3. Customer Instructions

Customer instructs Ennijo to Process Customer Personal Data as reasonably necessary to:

The applicable agreement, Customer's configuration and use of Ennijo, and written instructions submitted by authorized Customer representatives constitute Customer's documented instructions.

Ennijo will not Process Customer Personal Data for purposes materially inconsistent with those instructions unless required by applicable law.

If Ennijo is legally required to Process Customer Personal Data contrary to Customer's instructions, Ennijo will notify Customer before doing so unless applicable law prohibits that notice.

If Ennijo reasonably believes a Customer instruction violates Applicable Data Protection Law, Ennijo may suspend performance of that instruction and inform Customer of the concern.

4. Customer Responsibilities

Customer represents and warrants that:

Customer remains responsible for determining whether it has legal permission to contact a CRM Contact.

The availability of an Ennijo feature does not establish that Customer has legal permission to contact any particular person.

5. Processing Limitations

Ennijo will Process Customer Personal Data only:

  1. To provide the Service;
  2. For the limited and specified purposes described in this DPA and the applicable agreement;
  3. On Customer's documented instructions; or
  4. As otherwise permitted or required by Applicable Data Protection Law.

Ennijo will not:

Ennijo does not acquire ownership of Customer Personal Data.

6. Confidentiality

Ennijo will ensure that personnel authorized to Process Customer Personal Data:

Customer Personal Data will be treated as Customer's confidential information.

These obligations survive termination of the applicable agreement for as long as Ennijo retains Customer Personal Data or as otherwise required by law.

7. Security

Taking into account the nature of Processing, information available to Ennijo, implementation costs, the state of available technology, and risks to individuals, Ennijo will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data.

Current security measures are described in Schedule B.

Ennijo may update its security measures as technology and the Service evolve, provided that Ennijo does not materially reduce the overall level of protection for Customer Personal Data during the applicable service term.

No electronic system can guarantee absolute security.

8. Personal Data Breaches

Ennijo will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

Where reasonably available, the notification will include:

Information may be provided in phases as the investigation develops.

Ennijo will take reasonable steps to investigate, contain, mitigate, and remediate the incident.

Notification does not constitute an admission of fault or liability.

Customer remains responsible for determining whether notices must be provided to Data Subjects, regulators, clients, insurers, or other parties unless Applicable Data Protection Law provides otherwise.

Ennijo will provide reasonable assistance with legally required notifications, taking into account the nature of Processing and information available to Ennijo.

9. Data Subject Requests

Taking into account the nature of Processing, Ennijo will provide reasonable assistance to Customer in responding to verified Data Subject requests where required by Applicable Data Protection Law.

Requests may concern:

If Ennijo receives a request directly from a Data Subject concerning Customer-controlled Customer Personal Data, Ennijo may:

  1. Refer the individual to Customer;
  2. Notify Customer of the request; or
  3. Respond as directed by Customer or required by law.

Ennijo will not independently decide the substantive merits of a Customer-controlled privacy request unless authorized by Customer or required by law.

10. Regulatory and Compliance Assistance

Taking into account the nature of Processing and information available to Ennijo, Ennijo will provide reasonable assistance with obligations concerning:

Customer will reimburse Ennijo for extraordinary assistance requiring substantial resources unless the assistance is necessary because of Ennijo's breach of this DPA or Applicable Data Protection Law.

11. Subprocessors

Customer provides general authorization for Ennijo to engage Subprocessors.

Ennijo maintains its current Subprocessor and service-provider list at:

https://ennijo.com/subprocessors

Ennijo will require each Subprocessor that materially Processes Customer Personal Data on Ennijo's behalf to enter into a written agreement containing data protection obligations appropriate to the services performed and materially consistent with the applicable obligations imposed on Ennijo under this DPA.

Ennijo remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.

Notice of Changes

Ennijo will provide at least 30 days' notice before engaging a new material Subprocessor or replacing an existing material Subprocessor.

Notice may be provided by:

Objections

Customer may object within the 30-day notice period on reasonable and documented data protection grounds.

The parties will work in good faith to address the objection.

If a valid objection cannot reasonably be resolved, Ennijo may:

Customer may not require Ennijo to redesign the Service or incur commercially unreasonable costs.

12. Artificial Intelligence Processing

Ennijo uses Anthropic as the Subprocessor supporting Ennijo's AI Coach functionality.

AI-assisted features may include:

Depending on the feature used, Ennijo may transmit limited Customer Personal Data to Anthropic, including information such as:

Where reasonably possible, Ennijo seeks to minimize Personal Data transmitted to AI providers.

Ennijo does not authorize Customer Personal Data to be used for third-party general-purpose foundation-model training.

Customer remains responsible for reviewing AI-generated output before relying on it.

13. Google Workspace Integration

Where authorized by Customer or Customer's Google Workspace administrator, Ennijo may access limited Google Workspace information to provide Customer-requested functionality.

For Gmail activity logging, Ennijo currently accesses limited email header information, including:

Ennijo does not access or store the email body through this Gmail activity-logging workflow.

Where a sent email is matched to a CRM Contact, Ennijo may store an activity record associated with that contact, including the email subject.

Email subject lines may contain Personal Data.

Google Workspace authorization may be provided through administrator-approved domain-wide delegation.

Customer's Google Workspace administrator controls the underlying authorization and may remove or modify it through Google administrative controls.

Information received through Google APIs is handled in accordance with applicable Google API Services User Data Policy requirements and the Ennijo Privacy Policy.

14. Government and Legal Requests

If Ennijo receives a legally binding request from a government authority or other third party for Customer Personal Data, Ennijo will, unless legally prohibited:

Nothing in this Section requires Ennijo to violate applicable law or obstruct a lawful request.

15. Return, Export, and Deletion

Upon cancellation, termination, or expiration of Customer's use of Ennijo, Customer will have 30 days to export available Customer Data.

During that period, Ennijo will provide Customer with either:

After the 30-day export period, Ennijo will begin deleting Customer Personal Data from active production systems.

Ennijo intends to complete deletion from active production systems no later than 60 days after cancellation, termination, or expiration, unless longer retention is:

Backups

Customer Personal Data remaining only in backups may be retained until those backups expire through their normal lifecycle.

Backup data remains subject to this DPA while retained and will not be restored except as reasonably necessary for disaster recovery, security, or system restoration.

Current backup practices may be described in the Ennijo Privacy Policy or applicable security documentation and may change as Ennijo's infrastructure develops.

Subprocessor Retention

Customer Personal Data Processed by a Subprocessor may remain subject to that Subprocessor's applicable backup or deletion lifecycle after Ennijo initiates deletion, provided the Subprocessor remains subject to applicable contractual and legal safeguards.

16. Audits and Compliance Information

Upon reasonable written request, Ennijo will make available information reasonably necessary to demonstrate compliance with this DPA and applicable Processor obligations.

Ennijo may satisfy this obligation through materials such as:

Where Applicable Data Protection Law requires an audit:

Except where required by law or following a material security incident affecting Customer Personal Data, Customer may not conduct more than one audit in any 12-month period.

Nothing restricts a competent regulator's lawful audit authority.

17. International Data Transfers

Customer acknowledges that 29in5 LLC is based in the United States and that Customer Personal Data may be Processed in the United States or other countries in which authorized Subprocessors operate.

Where Applicable Data Protection Law requires an international transfer mechanism, the parties will use an applicable recognized mechanism.

European Economic Area

Where Customer transfers Personal Data subject to the EU GDPR to Ennijo and the transfer requires safeguards under Chapter V of the EU GDPR, the parties incorporate the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914.

Unless another module applies based on the parties' actual roles:

If the Standard Contractual Clauses conflict with another provision of this DPA, the Standard Contractual Clauses control for the restricted transfer.

United Kingdom

Where UK Data Protection Law applies and an international transfer safeguard is required, the parties will use the applicable UK International Data Transfer Addendum to the EU Standard Contractual Clauses or another mechanism recognized under UK law.

18. U.S. State Privacy Requirements

Where Ennijo qualifies as a Service Provider, Contractor, or Processor under applicable U.S. state privacy law, Ennijo agrees to comply with obligations applicable to that role.

California

Where the CCPA applies:

  1. Customer discloses Customer Personal Data to Ennijo only for the limited and specified business purposes identified in this DPA.
  2. Ennijo will not sell or share Customer Personal Data as those terms are defined under the CCPA.
  3. Ennijo will not retain, use, or disclose Customer Personal Data for purposes other than:
    • The limited and specified purposes in this DPA
    • Another purpose permitted by the CCPA
    • A purpose required by law
  4. Ennijo will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except where permitted by law.
  5. Ennijo will comply with applicable CCPA obligations and provide the legally required level of privacy protection for Customer Personal Data.
  6. Customer may take reasonable and appropriate steps to help ensure Ennijo uses Customer Personal Data consistently with Customer's CCPA obligations.
  7. Ennijo will notify Customer if Ennijo determines it can no longer meet its applicable CCPA obligations.
  8. Where permitted by law, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
  9. Ennijo will not combine Customer Personal Data received from Customer with Personal Data received from another person or collected through Ennijo's own interaction with a Data Subject except where permitted by the CCPA.

19. Aggregated and De-Identified Data

Ennijo may create aggregated or de-identified information derived from Customer Data where the resulting information cannot reasonably identify Customer or an individual Data Subject.

Where required by Applicable Data Protection Law, Ennijo will:

Aggregated and de-identified information may be used for:

20. Liability

Liability arising under this DPA is subject to the limitation-of-liability provisions in the applicable agreement governing Customer's use of Ennijo, except where Applicable Data Protection Law prohibits application of those limitations.

Nothing in this DPA creates liability that would not otherwise exist under the applicable agreement or law.

21. Term and Survival

This DPA begins when Ennijo first Processes Customer Personal Data on behalf of Customer and remains effective for as long as Ennijo Processes Customer Personal Data.

Provisions concerning confidentiality, security, deletion, international transfers, regulatory cooperation, audit rights, and obligations that logically survive termination remain effective for as long as required by law or while Ennijo retains Customer Personal Data.

22. Changes to this DPA

29in5 LLC may update this DPA where reasonably necessary to reflect:

Ennijo will provide reasonable notice of material changes that reduce Customer's contractual data protection rights.

23. Order of Precedence

For matters involving Processing of Customer Personal Data, the following order of precedence applies:

  1. Mandatory international transfer terms
  2. This DPA
  3. The applicable agreement governing Customer's use of Ennijo, including the Beta Program Agreement and, when applicable, the Terms of Service or subscription agreement
  4. The Ennijo Privacy Policy

The Privacy Policy remains controlling for independent Processing where 29in5 LLC acts as Controller rather than Processor.

24. Contact

Ennijo
A product of 29in5 LLC
4648 S Biltmore Ln
Madison, WI 53718
United States

Privacy: privacy@ennijo.com

Support: support@ennijo.com

Schedule A — Details of Processing

Subject Matter

Ennijo Processes Customer Personal Data to provide relationship management and customer relationship management functionality.

Duration

Processing begins when Customer begins using Ennijo or provides Customer Personal Data to the Service.

Processing continues during Customer's use of Ennijo and for the limited retention periods described in this DPA.

Nature and Purpose

Processing may include:

Purposes include:

Categories of Data Subjects

Customer Personal Data may relate to:

Categories of Personal Data

Customer may Process information such as:

Highly Sensitive Data

Ennijo is not intended as a repository for highly sensitive Personal Data.

Customer should not intentionally store information such as:

Schedule B — Technical and Organizational Measures

Ennijo maintains safeguards appropriate to the current nature and scale of the Service.

This Schedule describes categories of safeguards and does not guarantee that every control applies to every system or that a particular implementation will remain unchanged.

Access Control

Measures may include:

Application and Database Security

Measures may include:

Encryption and Transmission Security

Ennijo uses secure protocols designed to protect Personal Data during transmission.

Managed infrastructure providers may also provide encryption at rest.

Infrastructure

Ennijo uses managed infrastructure and hosting providers identified on the public Subprocessor page.

Ennijo relies in part on the physical, environmental, and infrastructure security controls maintained by those providers.

Logging and Monitoring

Ennijo maintains operational and security logs as part of operating, troubleshooting, and protecting the Service.

Depending on the function and event being logged, those records may contain technical information, account identifiers, or Customer Personal Data.

Ennijo reviews its logging practices as the Service develops and may reduce or modify logged fields where appropriate for security, troubleshooting, privacy, or operational purposes.

Development and Change Management

Measures may include:

Backups and Resilience

Ennijo uses managed database backup functionality to support recovery from certain failures.

Backups are not intended to replace Customer's own business continuity or record-retention practices.

Incident Response

Ennijo maintains procedures designed to:

Vendor Management

Ennijo evaluates service providers that materially Process Customer Personal Data and requires contractual privacy and security obligations appropriate to the services provided.

Data Minimization

Ennijo seeks to limit Processing to information reasonably necessary for the applicable functionality.

AI Processing

Ennijo uses Anthropic for authorized AI Coach functionality.

Ennijo does not authorize Customer Personal Data to be used for third-party general-purpose foundation-model training.

Google Workspace Controls

Where Google Workspace functionality is enabled:

Personnel Confidentiality

Personnel authorized to access Customer Personal Data are expected to maintain confidentiality and use information only for authorized purposes.

Schedule C — Subprocessors

Customer provides general authorization for Ennijo to use the Subprocessors identified at:

https://ennijo.com/subprocessors

The current online Subprocessor and service-provider list is incorporated into this DPA by reference.

Ennijo will provide notice and an opportunity to object to material Subprocessor changes as described in Section 11.