CUSTOMER DATA PROCESSING ADDENDUM

Effective Date: August 13, 2026. Last revised: September 14, 2026.

This Customer Data Processing Addendum, including its exhibits and appendices (the “Addendum”) is entered into between Aesthetix CRM LLC, a limited liability company incorporated under the laws of South Carolina, United States (“Aesthetix CRM,” “Company,” “we,” “us,” “our”), and the counterparty accepting this Addendum (“Customer”) (each, a “Party” and, collectively, the “Parties”) by virtue of the Customer signing and accepting the Terms of Service Agreement (the “Agreement”).

As of the effective date of the Agreement (the “Effective Date”), the terms of this Addendum shall be incorporated by reference and be part of the Agreement. In case of any conflict between this Addendum and the Agreement with respect to the Processing of Customer Personal Data, this Addendum takes precedence to the extent of such conflict; the Agreement governs all other matters. The Standard Contractual Clauses prevail over any other term of this Addendum.

1. Definitions

“Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data, including the GDPR, UK GDPR, CCPA/CPRA, and other laws identified in Exhibit B, as amended.

“Controller” means the natural or legal person which determines the purposes and means of the Processing of Personal Data.

“Customer Personal Data” means Personal Data contained within Customer Data that Aesthetix CRM Processes on behalf of Customer to provide the Services. Does not include Customer’s Account information.

“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.

“Infrastructure Providers” means HighLevel Inc. (CRM platform), Twilio Inc. (communications), DigitalOcean LLC (hosting), Vercel Inc. (application hosting), and Supabase Inc. (database services), with whom Aesthetix CRM maintains Business Associate Agreements and appropriate data protection terms.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

“Processing” means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.

“Processor” means a natural or legal person which Processes Personal Data on behalf of the Controller.

“SCCs” means the Standard Contractual Clauses adopted by the European Commission or other relevant authorities for Restricted Transfers.

“Sub-Processor” means a direct Processor engaged by Aesthetix CRM to Process Customer Personal Data.

2. Scope and Applicability

This Addendum applies to the Processing of all Customer Personal Data, regardless of country of origin, for the duration that Personal Data is Processed pursuant to the Agreement. This Addendum includes: Exhibit A (Details of Processing and Technical Measures), Exhibit B (Jurisdiction Specific Terms), and Exhibit C (Sub-Processors).

3. Processing of Customer Personal Data

3.1 Roles. Aesthetix CRM acts as Processor. Customer acts as Controller. Where Customer is a Processor to other parties, Aesthetix CRM acts as Sub-Processor.

3.2 Obligations. Aesthetix CRM shall: (i) comply with Applicable Data Protection Laws; (ii) Process Customer Personal Data only on Customer’s documented instructions unless required by law; (iii) immediately inform Customer if an instruction infringes Applicable Data Protection Laws; (iv) ensure authorized persons are subject to confidentiality obligations.

3.3 Infrastructure. Aesthetix CRM utilizes Infrastructure Providers (HighLevel, Twilio, DigitalOcean, Vercel, Supabase) to deliver the Services. Aesthetix CRM maintains Business Associate Agreements with each Infrastructure Provider and has enabled HIPAA compliance configuration across all customer accounts on HighLevel and Twilio. Aesthetix CRM does not own, operate, or control the underlying systems, servers, APIs, or processing logic maintained by Infrastructure Providers. With respect to the availability, performance, features, uptime, and outages of Infrastructure Provider systems, and any change, deprecation, or discontinuation of them, Aesthetix CRM’s obligations are limited to its own acts and omissions in configuring, deploying, and supporting the Platform. Responsibility for Sub-Processors’ compliance with their data protection obligations is governed solely by Section 6.4 and is not limited by this Section 3.3.

4. Personnel

Aesthetix CRM shall ensure: (i) the reliability of employees, agents, or contractors with access to Customer Personal Data; (ii) access is strictly limited to those who need it; (iii) all such individuals are subject to confidentiality obligations.

5. Security of Processing

Aesthetix CRM shall implement and maintain the administrative, technical, and organizational security measures identified in Exhibit A, Appendix I, ensuring a level of security appropriate to the risk of Processing.

6. Sub-Processors

6.1 Authorization. Customer authorizes Aesthetix CRM to engage the Sub-Processors listed in Exhibit C and to appoint additional Sub-Processors, subject to this Section.

6.2 Notification. Aesthetix CRM will provide Customer with written notice at least thirty (30) days in advance of authorizing a new Sub-Processor. Where a Sub-Processor is engaged by an Infrastructure Provider rather than directly by Aesthetix CRM, Aesthetix CRM will provide notice promptly after receiving that provider’s notice to Aesthetix CRM, and the objection period in Section 6.3 runs from Aesthetix CRM’s notice to Customer. The current list is at https://aesthetixcrm.com/sub-processors.

6.3 Objection. Customer has thirty (30) days from notice to object to a new Sub-Processor. If no objection is received, Customer is deemed to have consented. If Customer objects and no resolution is reached, Customer may terminate the Agreement with no further fees due.

6.4 Requirements. Each Sub-Processor shall be bound by written obligations providing at least the same protection as this Addendum. Aesthetix CRM remains liable for Sub-Processor performance.

7. Data Subject Rights

Aesthetix CRM shall assist Customer in responding to Data Subject requests by: (i) promptly notifying Customer of requests received directly; (ii) not responding except on Customer’s instructions or as required by law; (iii) implementing appropriate measures to enable Customer to respond.

8. Personal Data Breaches

8.1 Response. If Aesthetix CRM becomes aware of a Personal Data Breach, it will: (i) immediately implement measures to stop unauthorized access; (ii) notify Customer without undue delay and within seventy-two (72) hours of becoming aware.

8.2 Information. Notification shall include: the nature of the breach, categories and approximate number of affected Data Subjects and records, likely consequences, measures taken or proposed, and assistance in meeting Customer’s notification obligations.

9. Data Protection Assessments

Aesthetix CRM shall provide relevant information and assist Customer in complying with data protection impact assessments and prior consultations with Supervisory Authorities, solely regarding Customer Personal Data Processed by Aesthetix CRM.

10. Deletion or Return of Personal Data

Upon termination or Customer’s request: (i) Aesthetix CRM will permanently delete all Customer Personal Data from active systems within thirty (30) days after the export period (90 days), or, at Customer’s written request, return Customer Personal Data by making it available for export in a machine-readable format under Section 15B of the Terms; (ii) backups will be cycled out within ninety (90) days; (iii) upon request, Aesthetix CRM will provide written confirmation of deletion; (iv) Customer is responsible for exporting data prior to termination. Where Customer requests that Aesthetix CRM perform an export on Customer’s behalf, that work is chargeable at the professional services rates set out in Section 13 of the Terms.

11. Audit Rights

Aesthetix CRM shall allow for and contribute to audits by Customer or Customer’s mandated auditor regarding Processing of Customer Personal Data, subject to this Section. (i) Audits are conducted no more than once in any twelve (12) month period, except following a Personal Data Breach affecting Customer Personal Data or where a Supervisory Authority makes a documented demand. (ii) In the first instance, Aesthetix CRM will respond by remote or document-based review. Aesthetix CRM will make available its own security documentation together with such Infrastructure Provider attestations as those providers make available for general distribution, including SOC 3 reports and ISO certificates. Reports that an Infrastructure Provider makes available only under restricted distribution terms, including SOC 2 reports, are obtained by Customer directly from the relevant Infrastructure Provider under that provider’s access terms; Aesthetix CRM does not redistribute them. (iii) Customer shall provide reasonable notice and audits shall be conducted during normal business hours with minimal disruption. (iv) Customer’s auditor must be bound by written confidentiality obligations and may not be a competitor of Aesthetix CRM or of any Infrastructure Provider. (v) Customer reimburses Aesthetix CRM for time spent responding to and supporting an audit at the professional services rates set out in Section 13 of the Terms.

12. Restricted Transfers

12.1 General. Restricted Transfers shall be conducted in accordance with Exhibit B and Applicable Data Protection Laws, subject to the Standard Contractual Clauses or other approved safeguards.

12.2 Updated Standard Contractual Clauses. If the European Commission, the UK Information Commissioner’s Office, the Swiss Federal Data Protection and Information Commissioner, or another competent authority adopts a new or revised version of the Standard Contractual Clauses or of an approved transfer mechanism applicable to a Restricted Transfer under this Addendum, the Parties are deemed to have executed that new or revised version as of the date it becomes applicable to the transfer, and Aesthetix CRM may update Exhibits A and B to reflect it without further action by either Party.

12.3 Alternative Transfer Mechanism. Aesthetix CRM may adopt an alternative lawful transfer mechanism for Restricted Transfers, including the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, binding corporate rules, or an approved certification or code of conduct. Aesthetix CRM will notify Customer of the alternative mechanism, and upon that notice the alternative mechanism applies to the relevant Restricted Transfers in place of the Standard Contractual Clauses, to the extent permitted by Applicable Data Protection Laws.

13. No Selling of Customer Personal Data

Aesthetix CRM does not receive Customer Personal Data as consideration for Services. Customer retains all rights. Aesthetix CRM will not sell, share, or make available Customer Personal Data except as necessary to provide Services or as required by law.

14. Liability

Each Party’s liability under this Addendum is subject to the exclusions and limitations of liability set out in the Agreement, including the twelve (12) month fee cap, except where prohibited by Applicable Data Protection Laws.

15. General Terms

15.1 Contact. Data Protection Contact: privacy@aesthetixcrm.com

15.2 Amendment. Aesthetix CRM may update this Addendum with written notice to Customer. If Customer does not object in writing within thirty (30) days of that notice, Customer is deemed to have consented to the update. If Customer objects within that period and the Parties do not reach a resolution, Customer may terminate the affected Services with no further fees due. Aesthetix CRM may correct typographical errors and formatting, resolve ambiguities, and add jurisdictions without notice, provided such changes do not reduce Customer’s rights or Aesthetix CRM’s obligations under this Addendum.

15.3 Governing Law. This Addendum is governed by the laws of the State of South Carolina, except where Applicable Data Protection Laws require otherwise and subject to the governing law and forum provisions of Exhibit B with respect to Restricted Transfers.

15.4 Notice of Non-Compliance. If Aesthetix CRM determines that it can no longer meet its obligations under this Addendum or under the Standard Contractual Clauses, it will notify Customer without undue delay. Following such notice, Aesthetix CRM will either remediate the non-compliance within a reasonable period or cease the affected Processing, and Customer may suspend the transfer of Customer Personal Data or terminate the affected Services with no further fees due.

15.5 Disclosure to Supervisory Authorities. Either Party may disclose this Addendum, including the Standard Contractual Clauses and its Exhibits, to a Supervisory Authority upon that authority’s request.

EXHIBIT A: DETAILS OF PROCESSING

Item

Description

Data Exporter

Customer as specified in the Agreement

Data Importer

Aesthetix CRM LLC, Greenville, SC 29609

Contact

privacy@aesthetixcrm.com

Roles

Customer is Controller; Aesthetix CRM is Processor (or Sub-Processor where Customer is Processor)

Subject Matter

CRM, marketing automation, communication, and related services

Nature/Purpose

Contact management, marketing campaigns (SMS, email), appointment scheduling, pipeline management, communication logging, AI-powered automation, analytics, and reporting; and data warehousing, analytics, audience segmentation, and campaign activation in connection with Aesthetix Activate (for enrolled customers only)

Aesthetix CRM does not store payment card numbers.

Duration

Duration of Services plus retention periods in the Agreement

Data Subjects

Patients/customers, leads/prospects, Customer employees/users, website visitors

Categories of Data

Contact info (names, email, phone, address); communication content (SMS, email, call recordings); marketing data; transaction data; appointment history; website behavior; social media data. Where the Customer uses AX Pay, Aesthetix CRM's optional integrated payment facility provided by Nuvei Technologies Inc. under a merchant agreement between the Customer and Nuvei, or connects a payment account held in the Customer's own name with another payment provider, the categories also include patients' transaction data (transaction reference or token, amount, currency, date, status, and cardholder name and billing address where returned by the provider). Card numbers, expiry dates and security codes are entered into and held by the payment provider under its own terms and PCI DSS environment and are not received or stored by Aesthetix CRM. The Customer is not required to use any payment facility and no such data is processed by Aesthetix CRM unless it does.

Special Categories

Customer Data may include health-related information processed on behalf of Customers that are HIPAA Covered Entities; such Processing is governed by the Business Associate Agreement between the parties. Special category data under the GDPR or UK GDPR is not otherwise anticipated. A Customer established in the United Kingdom or the EEA that is not a HIPAA Covered Entity must notify Aesthetix CRM before Processing health data or other special category data through the Services. On such notice, the parties will discuss in good faith and may agree in writing appropriate restrictions and safeguards for that Processing. Customer, as Controller, is solely responsible for establishing the condition for processing under Article 9 of the GDPR or UK GDPR and for satisfying any applicable requirement under Schedule 1 to the Data Protection Act 2018. Aesthetix CRM’s obligations in respect of such data are limited to the technical and organizational measures set out in Appendix I.

APPENDIX I: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

Measure

Description

Encryption at Rest

AES-256 CBC via HighLevel (Google Cloud Platform infrastructure)

Encryption in Transit

TLS v1.2+ enforced; SSL certificates and HTTPS

Access Controls

RBAC; encrypted signed tokens; MFA for employee access

Infrastructure Security

HighLevel infrastructure (Google Cloud Platform); network ACLs; firewalls

Data Backup

Daily backups with point-in-time recovery; 7-day retention; monitored execution

Vulnerability Management

Regular scans; annual penetration testing; automated patch management

Logging & Monitoring

Comprehensive event logging; centralized storage; SOC monitoring via MSSP

Employee Security

Background checks; security training; confidentiality obligations; endpoint protection

Data Minimization

Minimum data requirements; optional fields; customer-controlled retention

Incident Response

Documented breach procedures; 72-hour notification commitment

Certifications and Assurance

As of September 4, 2026, HighLevel Inc. holds ISO/IEC 27001:2022 certification (InterCert, registration IC-IS-2509398, surveillance validity September 22, 2026), the scope of which covers HighLevel Inc. (Dallas, Texas) and HighLevel India Pvt. Ltd. (New Delhi, India), and makes a SOC 2 attestation report available through its trust center under its own access terms. Aesthetix CRM does not itself hold a SOC 2 attestation or an ISO certification. This row states third-party certification status as of the date shown and is not a warranty by Aesthetix CRM that any certification will be obtained or maintained.

EXHIBIT B: JURISDICTION SPECIFIC TERMS

1. European Economic Area (EEA)

For Restricted Transfers of Customer Personal Data from the EEA, the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated into this Addendum by reference and form part of it, completed as follows.

Modules. Module Two (Controller to Processor) applies where Customer acts as a Controller. Module Three (Processor to Processor) applies where Customer acts as a Processor on behalf of a third-party controller.

Clause 7 (Docking clause). The optional docking clause applies.

Clause 9 (Use of sub-processors). Option 2 (general written authorisation) applies. The time period for prior notice of Sub-Processor changes is the period set out in Section 6.2 of this Addendum, and Customer’s right to object is as set out in Section 6.3.

Clause 11 (Redress). The optional language providing for an independent dispute resolution body does not apply.

Clause 13 (Supervision). The competent supervisory authority is: (i) where Customer is established in an EU Member State, the supervisory authority of that Member State; (ii) where Customer is not established in an EU Member State but has appointed a representative under Article 27 of the GDPR, the supervisory authority of the Member State in which that representative is established; and (iii) where Customer is not established in an EU Member State and has not appointed such a representative, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located.

Clause 17 (Governing law). Option 1 applies. The EU SCCs are governed by the law of Ireland.

Clause 18 (Choice of forum and jurisdiction). Disputes arising from the EU SCCs are resolved before the courts of Ireland.

Annexes. Annex I.A (List of Parties) and Annex I.B (Description of Transfer) are as set out in Exhibit A. Annex I.C (Competent supervisory authority) is as set out above. Annex II (Technical and organisational measures) is as set out in Appendix I to Exhibit A. Annex III (List of Sub-Processors), where applicable under Module Three, is as set out in Exhibit C.

2. United Kingdom

For Restricted Transfers of Customer Personal Data from the United Kingdom, the EU SCCs apply as modified and supplemented by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (the “UK Addendum”), which is incorporated into this Addendum by reference. References in the EU SCCs to the GDPR are read as references to the UK GDPR, and references to Member State law are read as references to the law of the United Kingdom. The tables of the UK Addendum are completed as follows.

Table

Completed by the Parties as follows

Table 1: Parties

The Parties are the data exporter and data importer identified in Exhibit A. The Parties’ key contact details are the contacts stated in Exhibit A. The start date is the Effective Date of the Agreement.

Table 2: Selected SCCs, Modules and Selected Clauses

The version of the Approved EU SCCs to which the UK Addendum is appended is the EU SCCs incorporated in Section 1 of this Exhibit B, including the Appendix Information, with Module Two (Controller to Processor) or Module Three (Processor to Processor) applying as set out in Section 1. Clause 7 (docking clause) applies. Clause 9 Option 2 (general written authorisation) applies, with the notice period set out in Section 6.2 of this Addendum and the objection right set out in Section 6.3. The optional language in Clause 11 does not apply.

Table 3: Appendix Information

Annex 1A (List of Parties): as set out in Exhibit A. Annex 1B (Description of Transfer): as set out in Exhibit A. Annex II (Technical and organisational measures): as set out in Appendix I to Exhibit A. Annex III (List of Sub-Processors): as set out in Exhibit C.

Table 4: Ending this Addendum when the Approved Addendum changes

Neither Party may end the UK Addendum as set out in Section 19 of the UK Addendum.

The competent supervisory authority for Restricted Transfers from the United Kingdom is the UK Information Commissioner’s Office. The UK Addendum and the EU SCCs as modified by it are governed by the law of England and Wales, and disputes are resolved before the courts of England and Wales.

3. Switzerland

For Restricted Transfers of Customer Personal Data from Switzerland, the EU SCCs apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner (the “FDPIC”): (i) the competent supervisory authority is the FDPIC; (ii) references to the GDPR are read as references to the Swiss Federal Act on Data Protection (the “FADP”) to the extent the transfer is subject to the FADP; (iii) the term “Member State” is not interpreted so as to exclude data subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c); (iv) until the entry into force of the revised FADP, the EU SCCs also protect the personal data of legal entities; and (v) the EU SCCs as modified by this Section are governed by the law of Switzerland, and disputes are resolved before the courts of Switzerland.

4. United States

Aesthetix CRM acts as a “Service Provider” under applicable US privacy laws (CCPA, CPRA, and similar state laws). Aesthetix CRM will not sell or share Customer Personal Data, will not retain or use data except to provide Services or as permitted by law, and certifies understanding of these restrictions.

5. Brazil

Brazilian Standard Contractual Clauses (ANPD) apply where required for international transfers under the LGPD.

6. Australia

Aesthetix CRM will comply with applicable requirements under the Australian Privacy Act (1988) and Australian Privacy Principles for overseas disclosure.

7. Canada

Aesthetix CRM will comply with applicable cross-border transfer requirements under PIPEDA.

EXHIBIT C: LIST OF SUB-PROCESSORS

The Sub-Processors listed below are authorized under Section 6.1 as of the publication date shown. The current list is maintained at https://aesthetixcrm.com/sub-processors and is incorporated into this Addendum by reference. In the event of any difference between this Exhibit and that page, the page as published at the relevant time controls. Changes to the list are governed by Sections 6.2 and 6.3.

Published: September 14, 2026. Version: 2026.09.2.

Core Infrastructure Sub-Processors

Entity NameDescription of ProcessingLocationEngaged Via
HighLevel Inc.Core CRM platform infrastructure and servicesUnited StatesDirect
Google Cloud PlatformCloud hosting and data storageUnited StatesVia HighLevel
Amazon Web ServicesCloud hosting and data storageUnited StatesVia upstream Infrastructure Providers
Cloudflare Inc.CDN, security, DNS, and performance servicesUnited StatesVia upstream Infrastructure Providers
DigitalOcean LLCCloud hosting and infrastructureUnited StatesDirect
Vercel Inc.Application hosting and deploymentUnited StatesDirect
Supabase Inc.Database and backend servicesUnited StatesDirect

Communication Sub-Processors

Entity NameDescription of ProcessingLocationEngaged Via
Twilio Inc.SMS, voice, and communication servicesUnited StatesDirect
Mailgun TechnologiesEmail delivery servicesUnited StatesVia HighLevel

AI Sub-Processors

Entity NameDescription of ProcessingLocationEngaged Via
OpenAIAI-powered content and automation featuresUnited StatesVia HighLevel
BotPressAI chatbot functionalityUnited StatesVia HighLevel
RetellAIVoice AI servicesUnited StatesVia HighLevel
SynthflowAI provider servicesUnited StatesVia HighLevel

Payment Sub-Processors

Entity NameDescription of ProcessingLocationEngaged Via
Stripe Inc.Payment processing of Customer billing information for Aesthetix CRM subscription, credit and service chargesUnited StatesDirect
Nuvei Technologies Inc.Payment processing for Aesthetix CRM's own billing where used. AX Pay, Aesthetix CRM's optional integrated payment facility, is provided by Nuvei under a merchant agreement entered into directly between the Customer and Nuvei; when a Customer uses AX Pay, Nuvei processes the Customer's patients' payment data as the Customer's own payment provider under that agreement, and Aesthetix CRM processes only transaction references, amounts, status and tokens returned by Nuvei. Aesthetix CRM does not receive or store card numbers.United StatesDirect
Authorize.net (Visa Inc.)Legacy payment processing of Customer billing information for Aesthetix CRM charges; no longer used for new CustomersUnited StatesDirect

Data Infrastructure Sub-Processors

Entity NameDescription of ProcessingLocationEngaged Via
CorralData, Inc.Data warehousing, analytics, and patient reactivation audience processing for Aesthetix Activate. Applies only to customers enrolled in Aesthetix Activate.United StatesDirect
Fivetran, Inc.Data pipeline (ETL) services supporting Aesthetix Activate. Applies only to customers enrolled in Aesthetix Activate.United StatesVia CorralData

Other Sub-Processors

Entity NameDescription of ProcessingLocationEngaged Via
Zapier Inc.Workflow automation and integrationsUnited StatesDirect
Freshworks Inc.Customer support servicesUnited StatesDirect
GleapCustomer support servicesUnited StatesDirect
Nightly Data, Inc. DBA RubieCustomer import data servicesUnited StatesDirect
Pendo.ioProduct analyticsUnited StatesDirect
ChartMogulSubscription analyticsUnited StatesDirect
HighLevel India Pvt. Ltd.Support services provided under HighLevel’s access controls and security programIndiaVia HighLevel
LeadConnector LLCCommunication services and supportUnited StatesVia HighLevel

Entities marked Via HighLevel, Via CorralData, or Via upstream Infrastructure Providers are engaged by those providers under our agreements with them and are listed here for transparency. Their appearance on this page reflects the provider’s disclosure and is not a new engagement by Aesthetix CRM.

Data Privacy Framework Status

HighLevel Inc., together with its covered entity LeadConnector LLC, is listed on the U.S. Department of Commerce Data Privacy Framework List as an active participant in the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework for non-HR data (original certification September 29, 2023; listing reviewed September 4, 2026). Onward transfers of Customer Personal Data to HighLevel Inc. are made in reliance on that certification. HighLevel has undertaken to notify Aesthetix CRM if it determines that it can no longer meet the DPF Principles, and any such notice will be handled under Section 15.4 of this Addendum.

Start Growing Your Practice

Join aesthetic practices of all sizes using Aesthetix CRM to accelerate practice growth.