Data Processing Agreement

Last Updated: August 31, 2026

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or Terms of Service (the "Agreement") between the subscribing entity ("Customer," "Controller") and Ohh BeeHave, LLC d/b/a Stinger Industries ("Stinger," "Processor"), a Florida limited liability company located in Port St. Lucie, Florida, for the provision of the Stinger Command Center platform and related services (the "Services").

This DPA applies to the extent that Stinger processes Personal Data on behalf of Customer in connection with the Services. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to data processing matters.

1. Definitions

For purposes of this DPA, the following terms have the meanings set forth below. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

2. Scope and Purpose of Processing

Stinger shall Process Personal Data solely for the purpose of providing the Services to Customer as described in the Agreement, including:

Stinger shall not Process Personal Data for any purpose other than as set forth in this DPA and the Agreement, or as required by Applicable Data Protection Law. Where Stinger is required by law to Process Personal Data for another purpose, Stinger shall inform Customer of that legal requirement before Processing, unless prohibited by law from doing so.

3. Roles of the Parties

Customer as Controller. Customer is the Controller of Personal Data and determines the purposes and means of Processing. Customer is responsible for ensuring that it has a lawful basis for Processing Personal Data and for providing any required notices to, and obtaining any required consents from, Data Subjects.

Stinger as Processor. Stinger is the Processor of Personal Data and shall Process Personal Data only on behalf of and in accordance with Customer's documented instructions. Stinger shall not independently determine the purposes or means of Processing Personal Data.

Each party shall comply with its respective obligations under Applicable Data Protection Law in connection with the Processing of Personal Data under this DPA.

4. Types of Personal Data Processed

The categories of Personal Data Processed under this DPA include, but are not limited to:

5. Data Subject Categories

The Data Subjects whose Personal Data may be Processed under this DPA include:

6. Obligations of the Processor

Stinger shall:

6.1 Processing Instructions

Process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by Applicable Data Protection Law. In such a case, Stinger shall inform Customer of that legal requirement before Processing, unless the law prohibits such notification on important grounds of public interest.

6.2 Confidentiality

Ensure that all persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Stinger shall limit access to Personal Data to those employees, agents, and contractors who need access to fulfill Stinger's obligations under the Agreement and this DPA.

6.3 Security Measures

Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as further described in Section 8 of this DPA. Stinger shall regularly test, assess, and evaluate the effectiveness of these measures.

6.4 Sub-processor Engagement

Not engage another Processor (Sub-processor) without prior specific or general written authorization of Customer, subject to the terms set forth in Section 7 of this DPA.

6.5 Data Subject Rights

Taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising Data Subject rights under Applicable Data Protection Law, as further described in Section 11.

6.6 Assistance with Compliance

Assist Customer in ensuring compliance with the obligations related to security of Processing, notification of Data Breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of Processing and the information available to Stinger.

6.7 Data Breach Notification

Notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Data Breach involving Personal Data Processed on behalf of Customer, as further described in Section 10.

6.8 Deletion and Return

At the choice of Customer, delete or return all Personal Data to Customer after the end of the provision of Services relating to Processing, and delete existing copies unless Applicable Data Protection Law requires storage of the Personal Data. Deletion shall be completed within thirty (30) days of termination, as further described in Section 13.

6.9 Audit Cooperation

Make available to Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, as further described in Section 12.

6.10 Notification of Conflicting Instructions

Immediately inform Customer if, in Stinger's opinion, an instruction from Customer infringes Applicable Data Protection Law. Stinger shall not be required to assess the legality of Customer's instructions but shall flag instructions that, based on Stinger's knowledge, appear to conflict with Applicable Data Protection Law.

7. Sub-processors

7.1 Authorized Sub-processors

Customer hereby provides general written authorization for Stinger to engage Sub-processors for the Processing of Personal Data in connection with the Services. As of the effective date of this DPA, the following Sub-processors are authorized:

7.2 Obligations Regarding Sub-processors

Where Stinger engages a Sub-processor, Stinger shall:

7.3 New Sub-processors

Stinger shall notify Customer in writing (including by email) at least thirty (30) days prior to engaging any new Sub-processor or replacing an existing Sub-processor. The notification shall include the Sub-processor's name, location, and the nature of the Processing to be performed.

Customer may object to the engagement of a new Sub-processor by notifying Stinger in writing within thirty (30) days of receiving Stinger's notification. The objection must be based on reasonable grounds relating to data protection. If Customer objects, Stinger shall use commercially reasonable efforts to make available to Customer a change in the Services or recommend a commercially reasonable change to Customer's configuration or use of the Services to avoid Processing of Personal Data by the objected-to Sub-processor. If Stinger is unable to make such a change within a reasonable period (not to exceed thirty (30) days), either party may terminate the portion of the Services that cannot be provided without the use of the objected-to Sub-processor by providing written notice to the other party.

8. Security Measures

Stinger shall implement and maintain the following technical and organizational security measures, which may be updated from time to time to reflect changes in technology and industry best practices:

8.1 Encryption

8.2 Access Controls

8.3 Audit Logging

8.4 Infrastructure Security

8.5 Employee Training

9. Data Transfers

9.1 Processing Locations

Stinger primarily Processes Personal Data within the United States. Stinger shall not transfer Personal Data to a country outside the United States or the European Economic Area ("EEA") without ensuring that adequate safeguards are in place as required by Applicable Data Protection Law.

9.2 Transfer Mechanisms

To the extent that the Processing of Personal Data involves a transfer of Personal Data from the EEA, the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, the parties shall rely on the following transfer mechanisms, as applicable:

9.3 Additional Safeguards

Stinger shall implement supplementary technical and organizational measures as necessary to ensure that the transferred Personal Data is afforded a level of protection that is essentially equivalent to that guaranteed within the EEA.

10. Data Breach Notification

10.1 Notification to Customer

Stinger shall notify Customer without undue delay, and in any event no later than seventy-two (72) hours after becoming aware of a Data Breach. The notification shall include, to the extent available:

10.2 Cooperation

Stinger shall cooperate with Customer and take such commercially reasonable steps as Customer may direct to assist in the investigation, mitigation, and remediation of the Data Breach, including:

10.3 Record of Breaches

Stinger shall maintain a record of all Data Breaches, including the facts relating to the breach, its effects, and the remedial actions taken, regardless of whether notification to Customer was required.

11. Data Subject Rights

Stinger shall assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction of Processing, data portability, and objection.

If Stinger receives a request directly from a Data Subject, Stinger shall promptly redirect the Data Subject to Customer and notify Customer of the request, unless otherwise instructed by Customer. Stinger shall not respond to a Data Subject request directly unless authorized by Customer or required by Applicable Data Protection Law.

Stinger shall implement appropriate technical and organizational measures to enable Customer to fulfill Data Subject requests, including the ability to search for, export, correct, and delete Personal Data within the Services. Where such functionality is not available through the Services, Stinger shall provide reasonable assistance to Customer upon request.

12. Audits

12.1 Audit Rights

Stinger shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.

12.2 Audit Procedures

Customer shall provide Stinger with at least thirty (30) days' prior written notice of any audit, unless a shorter notice period is required by a supervisory authority or Applicable Data Protection Law. Audits shall be conducted during normal business hours, shall not unreasonably interfere with Stinger's business operations, and shall be subject to reasonable confidentiality obligations.

12.3 Audit Costs

Customer shall bear the costs of any audit initiated by Customer. If an audit reveals material non-compliance by Stinger with this DPA, Stinger shall bear the reasonable costs of the audit and shall promptly remediate the non-compliance at its own expense.

12.4 Third-Party Certifications

Stinger may satisfy Customer's audit requests by providing relevant third-party certifications, audit reports (such as SOC 2 Type II reports), or other documentation demonstrating compliance with the obligations set forth in this DPA. Customer shall consider such documentation in good faith before requesting an on-site audit.

13. Duration and Termination

13.1 Duration

This DPA shall remain in effect for the duration of the Agreement and shall automatically terminate upon expiration or termination of the Agreement, except that the provisions of this DPA relating to confidentiality, data deletion, and liability shall survive termination.

13.2 Data Deletion or Return

Upon termination or expiration of the Agreement, Customer may request the return or deletion of Personal Data. Stinger shall:

13.3 Retention Exceptions

Stinger may retain Personal Data to the extent required by Applicable Data Protection Law, provided that Stinger shall (a) maintain the confidentiality of such Personal Data, (b) Process it only for the purpose required by law, and (c) delete it as soon as the legal obligation requiring retention has expired.

14. CCPA-Specific Terms

To the extent that the CCPA applies to Stinger's Processing of Personal Data on behalf of Customer, the following additional terms shall apply:

14.1 Service Provider Designation

Stinger is a "service provider" as defined in the CCPA (Cal. Civ. Code § 1798.140(ag)). Stinger shall Process Personal Data only for the specific business purposes set forth in this DPA and the Agreement.

14.2 Prohibited Activities

Stinger shall not:

14.3 Same Level of Privacy Protection

Stinger shall provide the same level of privacy protection as required by the CCPA and shall notify Customer if it determines that it can no longer meet its obligations under the CCPA. Customer has the right to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data upon notice.

14.4 Compliance Certification

Stinger certifies that it understands and will comply with the restrictions and obligations set forth in this Section 14 and will treat Personal Data in accordance with the CCPA's requirements for service providers.

15. Liability

15.1 Liability Cap

Each party's total aggregate liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Agreement. Nothing in this DPA shall be construed to limit or exclude either party's liability for damages arising from willful misconduct, gross negligence, or breaches of confidentiality obligations with respect to Personal Data.

15.2 Indemnification

Each party shall indemnify, defend, and hold harmless the other party from and against any third-party claims, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising from the indemnifying party's breach of this DPA or Applicable Data Protection Law, to the extent caused by the indemnifying party's acts or omissions.

15.3 No Limitation on Data Subject Rights

Nothing in this DPA shall limit the rights of Data Subjects under Applicable Data Protection Law.

16. Contact Information

For questions, concerns, or requests related to this DPA or the Processing of Personal Data, please contact:

Ohh BeeHave, LLC d/b/a Stinger Industries
Port St. Lucie, Florida
Email: ohhbeehave35@gmail.com
Phone: (772) 529-4144

Stinger shall respond to all data protection inquiries within a reasonable time frame, not to exceed thirty (30) days from receipt.