Upstream Bio Data Processing Addendum

Service Providers

This Upstream Bio Data Processing Addendum (the “Addendum”) is incorporated into the Agreement (as defined below) between Upstream Bio, Inc., a Delaware corporation with a place of business at 890 Winter St., Suite 200, Waltham, MA 02451, USA (“Upstream”) and the entity that has executed the Agreement together with its Affiliates (as applicable) (collectively, the “Service Provider”) (each, a “Party” and, collectively, the “Parties”), to the extent required by Applicable Data Protection Laws (as defined below), and describes the Parties’ obligations, including under applicable privacy, data security, and data protection laws, with respect to the processing and security of Upstream Personal Data (as defined below). This Addendum will be effective on the Addendum Effective Date (as defined below), and will replace any terms previously applicable to the processing and security of Upstream Personal Data.

1. Definitions

  • 1.1 For the purpose of interpreting this Addendum, the following terms (and their applicable cognates) shall have the meanings set out below:
    • (a)“Addendum Effective Date” means the date on which Service Provider accepted, or the Parties otherwise agreed to this Addendum (including by execution of an Agreement incorporating this Addendum by reference therein).
    • (b) “Agreement” means the Master Contract Services Agreement (“MCSA”) or other contract governing the terms and conditions of the provision of Services by Service Provider to Upstream, as applicable.
    • (c) “Affiliate” means any entity within a controlled group of companies that directly or indirectly, through one or more intermediaries, is controlling, controlled by, or under common control with one of the Parties.
    • (d) “Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Upstream Personal Data, including but not limited to the laws and regulations identified in the Jurisdiction Specific Terms as may be amended, modified, or supplemented from time to time, as applicable.
    • (e) “Contracted Processor” means any third party appointed by or on behalf of Service Provider to Process Upstream Personal Data in connection with the Services.
    • (f)“Data Exporter” and “Data Importer” shall have the same meanings assigned to them in the Details of Processing.
    • (g) “Details of Processing” means Appendix B to the MCSA, or the analogous section of the Agreement setting out the factual circumstances of the details of Personal Data Processing performed by Service Provider.
    • (h) “GDPR” means the EU GDPR and UK GDPR, as those terms are defined in the Jurisdiction Specific Terms, as applicable.
    • (i) “Jurisdiction Specific Terms” means all terms applicable to the Processing of Upstream Personal Data that apply to the extent that Service Provider Processes Upstream Personal Data originating from, or protected by, Applicable Data Protection Laws in one of the jurisdictions identified in these terms. The Jurisdiction Specific Terms are currently available online at https://upstreambio.com/wp-content/uploads/2026/06/Upstream-Bio-Jurisdiction-Specific-Terms-to-Universal-Vendor-Facing-DPA-website-version.pdf.
    • (j) “List of Contracted Processors” means Appendix D to the MCSA, or the analogous section of the Agreement listing the Contracted Processors.
    • (k) “Restricted Transfer” means any transfer of Upstream Personal Data protected by Applicable Data Protection Laws to a Third Country or an international organization in a Third Country (including data storage on foreign servers).
    • (l) “Services” means the services and other activities carried out by or on behalf of Service Provider for Upstream pursuant to the Agreement.
    • (m) “Standard Contractual Clauses” are the model clauses for Restricted Transfers adopted from time to time by the relevant authorities of the jurisdictions indicated in the Jurisdiction Specific Terms, insofar as their use is approved by the relevant authorities as an appropriate mechanism or safeguard for Restricted Transfers.
    • (n) “Sub-Processor” means a direct Processor of a Processor. For the avoidance of doubt, Contracted Processors are Sub-Processors.
    • (o) “TOMs” means Appendix C to the MCSA, or the analogous section of the Agreement setting out the technical and organizational security measures that shall be implemented and maintained by Service Provider to safeguard Upstream Personal Data.
    • (p) “Upstream Personal Data” means any Personal Data Processed by or on behalf of Service Provider to provide the Services in accordance with the Agreement.
  • 1.2 The terms “Controller”, “Data Protection Impact Assessment”, “Data Subject”, “Processor”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing”, “Supervisory Authority”, and “Third Country” shall have the same meanings as in the Applicable Data Protection Laws, and their cognate and corresponding terms shall be construed accordingly.
  • 1.3 Capitalized terms which are used but not defined herein shall have the meanings given to them in the Agreement. Except as modified or supplemented above, the definitions of the Agreement shall remain in full force and effect.

2. Duration and Scope

  • 2.1 Duration. This Addendum shall take effect on the Addendum Effective Date and shall continue concurrently for the duration that Upstream Personal Data is Processed by Service Provider pursuant to the Agreement.
  • 2.2 Scope. This Addendum will apply to the Processing of all Upstream Personal Data, regardless of country of origin, place of Processing, location of Data Subjects, or any other factor. Processing of data by the Service Provider which does not constitute Personal Data or Upstream Personal Data is outside the scope of this Addendum.
  • 2.3 Appendices to the Agreement. All references to any appendices, exhibits, or other addenda to the Agreement made in this Addendum shall refer to either the specific named Appendices of the MCSA or the equivalent instruments to the Agreement, each as applicable.

3. Processing of Upstream Personal Data

  • 3.1 Upstream acts as a Controller and Service Provider acts as a Processor.
  • 3.2 Service Provider shall:
    • (a) comply with all Applicable Data Protection Laws in the Processing of Upstream Personal Data;
    • (b) not Process Upstream Personal Data other than in accordance with Upstream’s relevant documented instructions (including with regard to Restricted Transfers), unless such Processing is required by Applicable Data Protection Laws to which the relevant Processing activity(ies) are subject, in which case Service Provider shall, to the extent permitted by Applicable Data Protection Laws, inform Upstream of that legal requirement before the respective act of Processing of that Upstream Personal Data; and
    • (c) immediately inform Upstream in the event that, in Service Provider’s reasonable opinion, a Processing instruction given by Upstream may infringe Applicable Data Protection Laws.
  • 3.3 All necessary information relating to the details of the Processing is set out in Details of Processing. Upstream shall be entitled to update the Details of Processing from time to time by sending an updated version to Service Provider. Service Provider will be considered to have accepted any such update unless it provides Upstream with written notice of non-acceptance within fourteen (14) days following receipt. If Service Provider issues such notice of non-acceptance, the Parties will cooperate and negotiate in good faith regarding any required updates to the Details of Processing.
  • 3.4 Upstream instructs Service Provider (and authorizes Service Provider to instruct each Contracted Processor it engages) to Process Upstream Personal Data and, in particular, transfer Upstream Personal Data to any country or territory (subject to the requirements of Applicable Data Protection Laws governing Restricted Transfers), only as reasonably necessary for the provision of the Services and consistent with the Agreement and this Addendum.
  • 3.5 Restrictions on Use of Upstream Personal Data with AI Technology.
    • (a)Service Provider shall not use, and shall not permit any third party to use, any Upstream Personal Data to train, customize, validate, update, improve, develop or modify any of Service Provider’s or a third party’s AI Technology for itself or for the benefit of any person or entity other than Upstream, without Upstream’s prior written consent, which may be withheld or withdrawn at Upstream’s sole and absolute discretion.
    • (b) Upstream solely owns all Upstream Input and Upstream Output.
    • (c) Service Provider will comply with all applicable laws and regulations applicable to the development, creation, training, improving, and any other use of its AI Technology including regarding collection and processing of personal data.
    • (d) Service Provider shall maintain compliance with all applicable laws and regulations for the ethical and responsible use of AI Technology, including for transparency, human interpretability, mitigation of bias, and oversight of data input into the AI Technology used in the Service Provider’s products and services.
    • (e) For the purpose of this Section 3.5:
      • i. “AI Technology” means any and all artificial intelligence technologies, including machine learning, deep learning, statistical learning algorithms, models (including large language models), neural networks, and all software implementations of any of the foregoing.
      • ii. “Upstream Input” means Upstream’s information, data, materials, text, images, prompts, or other content that is input, entered, or otherwise provided or made available for processing by AI Technology for the benefit of or by or on behalf of Upstream.
      • iii. “Upstream Output” means information, data, materials, text, images, or other content generated or otherwise output by AI Technology based on Upstream Input.

4. Service Provider Personnel

Service Provider shall ensure:

  • 4.1 the reliability of any of its officers, directors, employees, agents, or contractors who may have access to Upstream Personal Data;
  • 4.2 that access to Upstream Personal Data is strictly limited to those individuals who need to know or access it, as strictly necessary to fulfill the documented Processing instructions given to Service Provider by Upstream or to comply with Applicable Data Protection Laws; and
  • 4.3 that all such individuals are subject to formal confidentiality undertakings, professional obligations of confidentiality, or statutory obligations of confidentiality, which shall continue to endure after the termination of the Services.

5. Security of Processing

  • 5.1 Service Provider shall implement and maintain appropriate technical and organizational security measures, including (without limitation) those identified in the TOMs, which ensure a level of security appropriate to the risk of Processing and take into account: (i) the state of the art, costs of implementation, and the nature and purposes of Processing; (ii) the risk of varying likelihood and severity to the rights and freedoms of natural persons; and (iii) the risks presented by the Processing activities, particularly those risks related to Personal Data Breaches.
  • 5.2 Service Provider shall also assist Upstream with regard to ensuring Upstream’s compliance with its own obligations related to its security measures.

6. Sub-Processing

  • 6.1 Authorization for Existing Contracted Processors: Upstream authorizes Service Provider to continue using those Contracted Processors already engaged by Service Provider as of the Addendum Effective Date and set out in the List of Contracted Processors, and further authorizes Service Provider and its Contracted Processors to appoint additional Contracted Processors, provided the obligations of this Section 6 (and any respective obligations outlined in the List of Contracted Processors) are met.
  • 6.2 Authorization for the Appointment of Additional Contracted Processors: To appoint additional Contracted Processors, Service Provider must provide Upstream with prior written notice to Upstream by email to ambrose@upstreambio.com and experts@verasafe.com, including the details of the Processing to be undertaken by that respective Contracted Processor.
  • 6.3 Objection to Contracted Processors.
    • (a) If Upstream does not explicitly notify Service Provider in writing of any objections to the proposed appointment within fourteen (14) days of the receipt of such notice, Upstream shall be deemed to have consented to the proposed appointment. Upstream may object to the appointment of a Contracted Processor by providing a written objection, which shall include the name of the objected-to Contracted Processor and a reasonable statement of objection.
    • (b) If an objection is received, the Parties will, for a period of no more than thirty (30) days from the date of Upstream’s refusal, work together in good faith to attempt to find a commercially reasonable solution for Upstream that avoids the use of the objected-to Contracted Processor. If no solution can be found, Upstream, upon written notice to Service Provider, may terminate the Agreement immediately (or upon such date as Upstream selects), with no further fees due, other than what has been accrued up to and including the date of termination. Upon termination of the Agreement, Service Provider shall cease to Process Upstream Personal Data.
  • 6.4 Requirements for Appointing Contracted Processors. With respect to each Contracted Processor, Service Provider shall:
    • (a) before the Contracted Processor first Processes Upstream Personal Data (or, where relevant, in accordance with Section 1), carry out adequate due diligence to ensure that the Contracted Processor is capable of providing the level of protection and security for Upstream Personal Data required by this Addendum, the Agreement, and Applicable Data Protection Laws;
    • (b) disclose the results of that due diligence, with documentation sufficient to support Service Provider’s findings, to Upstream upon request of Upstream;
    • (c) restrict the Contracted Processor’s access to Upstream Personal Data only to what is necessary to assist Service Provider in providing or maintaining the Services, and prohibit the Contracted Processor from accessing Upstream Personal Data for any other purpose; and
    • (d) ensure that the arrangement between Service Provider and the prospective Contracted Processor is governed by a written contract that includes terms which offer at least the same level of protection for Upstream Personal Data as those set out in this Addendum, and that such terms meet the requirements of Applicable Data Protection Laws.
  • 6.5 Processors whereby, in the event the Service Provider has factually disappeared, ceased to exist in law, or has become insolvent, Upstream shall have the right to terminate the arrangement with the Contracted Processor and to instruct the Contracted Processor to erase or return the Upstream Personal Data.
  • 6.6 Where any Contracted Processor fails to fulfil its data protection obligations under such written contract (or in the absence thereof, as the case may be), Service Provider shall remain fully liable to Upstream for the performance of the respective Contracted Processors’ data protection obligations under such contract and/or Applicable Data Protection Laws.

7. Rights of the Data Subjects

  • 7.1 Taking into account the nature of the Processing, Service Provider shall assist Upstream by implementing appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise rights of the Data Subjects under Applicable Data Protection Laws.
  • 7.2 With regard to the rights of the Data Subjects within the scope of this Section 7, Service Provider shall:
    • (a) promptly notify Upstream if it or any Contracted Processor receives a request from a Data Subject under any Applicable Data Protection Laws with respect to Upstream Personal Data;
    • (b) not respond to that request, except on the documented instructions of Upstream or as required by Applicable Data Protection Laws, in which case Service Provider shall, to the extent permitted by Applicable Data Protection Laws, inform Upstream of that legal requirement before it or the Contracted Processor responds to the request; and promptly comply with any documented instructions from Upstream regarding

8. Personal Data Breach

  • 8.1 Service Provider will maintain a reasonable and appropriate Personal Data Breach response program.
  • 8.2 Breach Response. If Service Provider discovers, is notified of, or has reason to suspect a Personal Data Breach affecting Upstream Personal Data under its or any of its Contracted Processors’ control, Service Provider will: (i) immediately implement measures to stop the unauthorized access; (ii) secure the Upstream Personal Data; and (iii) notify Upstream without undue delay and, in any event, within twenty-four (24) hours of becoming aware of such suspected Personal Data Breach.
  • 8.3 Breach Obligations. Immediately upon providing notice of a Personal Data Breach, Service Provider shall:
    • (a) describe to Upstream in as much detail as reasonably possible: (i) the nature of the Personal Data Breach; (ii) where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (iii) the impact of such Personal Data Breach upon Upstream and the Data Subjects; (iv) the measures taken or proposed to be taken by Service Provider to address the Personal Data Breach; and (v) relevant individuals who will be available (24 hours per day, 7 days per week) until the Parties mutually agree that the Personal Data Breach has been resolved;
    • (b) provide and supplement notifications as and when information becomes available;
    • (c) assist Upstream in meeting its respective obligations pursuant to Applicable Data Protection Laws, including any obligations to notify Supervisory Authorities or Data Subjects of a Personal Data Breach; and
    • (d) in cooperation with Upstream, use its best efforts (at Service Provider’s expense) to investigate, mitigate, and remediate each such Personal Data Breach and prevent a recurrence of such Personal Data Breach.
  • 8.4 Where a Personal Data Breach arises due to the negligence or willful misconduct of Service Provider, Service Provider will promptly reimburse Upstream for all costs reasonably incurred by Service Provider in connection with the Personal Data Breach including, but not limited to, costs related to Upstream’s provision of notice of the Personal Data Breach to supervisory authorities or affected Data Subjects and costs related to offering credit monitoring services to affected Data Subjects (if determined appropriate by Upstream or required by Applicable Data Protection Laws).
  • 8.5 Service Provider represents and warrants that it is not, and has never been, subject to civil or criminal litigation, government investigation, or a consent decree, judgment, or order regarding data protection, privacy, or information security, and that it has not suffered any material security breach or, if it has, that it has disclosed information regarding such security breach(es) to Upstream.

9. Data Protection Impact Assessment and Prior Consultation

Service Provider shall provide Upstream with relevant information and documentation, and assist Upstream in complying with its obligations with regard to any Data Protection Impact Assessments or prior consultations with Supervisory Authorities when Upstream determines that such Data Protection Impact Assessments or prior consultations are required pursuant to Applicable Data Protection Laws, but in each such case solely with regard to Upstream Personal Data Processed by Service Provider, and taking into account the nature of the Processing and information available to the respective Contracted Processors.

10. Deletion or Return of Personal Data

  • 10.1 Service Provider shall promptly, following the date of cessation of Services, at the choice of Upstream, delete or return all Upstream Personal Data (including any copies) to Upstream. Service Provider shall provide Upstream with the technical means, consistent with the way the Services are provided, to request the return or deletion of Upstream Personal Data. In the event that Upstream has not specified its choice, Service Provider shall return all Upstream Personal Data to Upstream.
  • 10.2 Service Provider shall also cause all Contracted Processors that have received any Upstream Personal Data to delete or return, as applicable, all such Upstream Personal Data without undue delay.
  • 10.3 Sections 1 and 10.2 shall not apply to the extent that applicable law requires Service Provider or its Contracted Processor, as applicable, to retain any Upstream Personal Data. In those instances, Service Provider or Contracted Processor, as applicable, shall specify the applicable law requiring such retention and the period it shall retain Upstream Personal Data. The Service Provider’s obligations under this Addendum shall continue for the full period the Upstream Personal Data is retained.
  • 10.4 Sections 1 and 10.2 do not apply to Upstream Personal Data that has been archived on back-up systems, which Upstream or its Contracted Processors, as applicable, shall securely isolate and protect from any further Processing, except to the extent required by applicable law.

11. Audit Rights

  • 11.1 Upstream may request, and Service Provider will provide (subject to obligations of confidentiality), a current SOC 2 Type II audit report, ISO 27001 certificate, or other substantially similar independent third-party audit report issued to Service Provider, and any related documentation that Upstream may request, to confirm Service Provider’s compliance with the Applicable Data Protection Laws.
  • 11.2 If Upstream, after having reviewed such audit report(s) and related documentation, still requires additional information (for example, Service Provider’s policies and procedures regarding data protection, information from Service Provider’s Contracted Processors, or any other relevant information), Service Provider shall further assist and make available to Upstream all such additional information and/or documentation (including relevant provisions of contracts with Contracted Processors) necessary to demonstrate compliance with this Addendum and/or Applicable Data Protection Laws.
  • 11.3 In addition, Service Provider shall allow for and contribute to audits, including remote and onsite inspections of the Services, by Upstream (on behalf of itself or its clients) or an auditor mandated by Upstream (on behalf of itself or its clients) with regard to the Processing of the Upstream Personal Data by its Contracted Processors.

12. Jurisdiction Specific Terms

  • 12.1 To the extent Service Provider Processes Upstream Personal Data originating from, or protected by, Applicable Data Protection Laws in one of the jurisdictions listed in the Jurisdiction Specific Terms, then the terms and definitions specified in the Jurisdiction Specific Terms with respect to the applicable jurisdiction(s) shall apply in addition to the terms of this Addendum.
  • 12.2 Upstream may update the Jurisdiction Specific Terms from time to time to reflect changes in or additions to Applicable Data Protection Laws to which relevant Processing operations are subject. If Upstream updates the Jurisdiction Specific Terms, it will notify Service Provider in writing. If Service Provider does not object to the updated the Jurisdiction Specific Terms within fourteen (14) days of receipt, Service Provider will be deemed to have consented to the updated the Jurisdiction Specific Terms. Without limiting the generality of the foregoing, if the execution of a new version of Standard Contractual Clauses adopted by the relevant authorities in a jurisdiction governing the processing of Upstream Personal Data is later required in order for the Parties to rely on said Standard Contractual Clauses as a lawful transfer mechanism for Restricted Transfers, the Parties are deemed to have agreed to the new version of the applicable Standard Contractual Clauses by signing this Addendum, and, if necessary, Upstream shall be entitled to update the Details of Processing and the Jurisdiction Specific Terms accordingly.
  • 12.3 In case of any conflict or ambiguity between the Jurisdiction Specific Terms and any other terms of this Addendum, the applicable Jurisdiction Specific Terms will prevail.

13. Restricted Transfers

  • 13.1 Restricted Transfers of Upstream Personal Data within the scope of this Addendum shall be conducted in accordance with the applicable terms and requirements set out in the Jurisdiction Specific Terms and Applicable Data Protection Laws.
  • 13.2 If the relevant authorities adopt a new version of Standard Contractual Clauses as a lawful mechanism for Restricted Transfers in a jurisdiction governing the processing of Upstream Personal Data, the Parties are deemed to have agreed to the execution of the new version of the Standard Contractual Clauses by signing this Addendum, and, if necessary, Upstream shall be entitled to update the Details of Processing and the Jurisdiction Specific Terms
  • 13.3 If an alternative transfer mechanism is adopted by Upstream during the term of the Agreement (an “Alternative Mechanism”), and Upstream notifies Service Provider that some or all Restricted Transfers can be conducted in compliance with Applicable Data Protection Laws pursuant to the Alternative Mechanism, the Parties will rely on the Alternative Mechanism instead of the transfer mechanisms in the Jurisdiction Specific Terms for Restricted Transfers to which the Alternative Mechanism applies.

14. Liability

  • 14.1 Notwithstanding anything to the contrary in the Agreement, Service Provider shall be fully liable for any breach of the Addendum or Applicable Data Protection Laws. In no event does this Addendum restrict or limit the rights of any Data Subject under the Applicable Data Protection Laws.
  • 14.2 Service Provider shall be fully liable to Upstream for any breach of the Agreement or this Addendum, and the obligations set out therein (including by means of additional contract, as the case may be), by any Contracted Processor, without prejudice to the liability of Service Provider in accordance with Applicable Data Protection Laws.

15. Indemnification

Service Provider agrees to indemnify, defend, and hold harmless Upstream and its officers, directors, employees, agents, Affiliates, successors, and permitted assigns against any and all losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards, penalties, fines, costs, or expenses of whatever kind which Upstream may sustain as a consequence of any breach by Service Provider (or the Contracted Processors, as the case may be) of the provisions of this Addendum.

16. General Terms

  • 16.1 Notice. The Parties shall use the data protection contacts provided in the Details of Processing as contact points for all matters related to this Addendum, including notice of a Personal Data Breach and inquiries pursuant to rights of the Data Subjects.
  • 16.2 Prior Existing Agreement. This Addendum supersedes and replaces all prior and contemporaneous proposals, statements, sales materials or presentations, and agreements, oral and written, with regard to the subject matter of this Addendum, including any prior data processing addenda entered into between Service Provider and Upstream in connection with the Agreement.
  • 16.3 Conflicts. All clauses of the Agreement that are not explicitly amended or supplemented by the clauses of this Addendum remain in full force and effect and shall apply, as long as this does not contradict compulsory requirements of Applicable Data Protection Laws. In the event of any conflict between the Agreement (including any annexures, exhibits, and appendices thereto) and this Addendum, the provisions of this Addendum shall prevail, except in such cases where the applicable Jurisdiction Specific Terms will apply and take precedence.
  • 16.4 Severability. Should any provision of this Addendum be found legally invalid or unenforceable, then the invalid or unenforceable provision will be deemed superseded by a valid, enforceable provision that most closely matches the intent of the original provision, and the remainder of this Addendum will continue in effect.
  • 16.5 Non-Compliance. If Service Provider determines that it can no longer meet any of its obligations in this Addendum, Applicable Data Protection Laws, or the Standard Contractual Clauses (where applicable), it shall: (i) promptly notify Upstream of that determination and (ii) cease the Processing or immediately take other reasonable and appropriate steps to remediate the lack of compliance.
  • 16.6 Disclosure to Supervisory Authority. Service Provider acknowledges that Upstream may disclose this Addendum and any relevant privacy provisions in the Agreement to Supervisory Authorities, or any other judicial or regulatory body upon their request.
  • 16.7 This Addendum shall be governed by the laws specified in the Agreement; in the absence of such specification, it shall be subject to and interpreted in accordance with the laws of the State of Delaware.
  • 16.8 Any disputes arising out of or in connection with this Addendum shall be subject to the exclusive jurisdiction of the courts specified in the Agreement; in the absence of such specification, any such disputes shall be subject to the exclusive jurisdiction of the courts of the State of Delaware.