Data Processing Addendum | Clear Showings

Clear Showings

Clear Showings Data Processing Addendum

Clear Showings LLC — Version 4 (supersedes Version 3) — Last updated [July 15, 2026]

This Data Processing Addendum ("DPA") supplements and forms part of the agreement between Clear Showings LLC ("Clear Showings," "we," "us") and the customer that has accepted the Clear Showings Terms of Service or signed an Order Form ("Customer," "you") (the "Agreement"). It governs the handling of personal information in connection with Customer's use of the Clear Showings identity and trust verification services ("Services"). If there is a conflict between this DPA and the Agreement on data-protection matters, this DPA controls.

Effective Date: the date Customer accepts the Agreement.

1. Definitions

"Applicable Data Protection Law" means all privacy, data-protection, biometric-privacy, and consumer-protection laws applicable to the processing under this DPA, including state privacy statutes, the Illinois Biometric Information Privacy Act (BIPA) where applicable, the Fair Credit Reporting Act (FCRA) where applicable, the Fair Housing Act, and, where relevant, the GDPR.

"Clear Show ID" means the Services tier that performs identity document verification and automated face matching only, without watchlist, AML/PEP, deceased-records, or registry screening of any kind.

"Clear Show 360" means the Services tier that includes all Clear Show ID functionality plus: phone confirmation via one-time passcode; AML/PEP (anti-money-laundering, sanctions, and politically exposed person) watchlist screening; a United States deceased-records check; and, for identity documents issued by a supported country, Global ID Confirmation (validation of the presented document against the issuing government's own registry, as described in Clear Showings' published Privacy Policy). Clear Show 360 does not include criminal-history or criminal/public- records screening of any kind.

"Verification Data" means personal information of a Data Subject collected and processed through the verification flow — including identity-document images, selfie photographs, facial geometry and other biometric data, a phone number entered in-session for one-time passcode delivery, and, for Clear Show 360 sessions, AML/PEP screening inputs, deceased-records check inputs, and registry-validation queries for supported countries — together with the Verification Summary derived from it.

"Verification Summary" means the outputs delivered to Customer upon completion of a verification session. For Clear Show ID sessions: the Data Subject's name, face-match similarity and confidence scores, the selfie photograph captured during verification, the portrait extracted from the identity document, and PII-masked images of the identity document. For Clear Show 360 sessions: the foregoing, plus the Assessment, a yes/no AML/PEP watchlist match flag, the phone-confirmation completion status, the deceased-records check outcome, and, where Global ID Confirmation was performed, the registry-validation outcome. The Verification Summary does not include, and Customer has no access to, any biometric template, unmasked identity document image, or underlying screening record.

"Assessment" means the Green / Yellow / Red output, delivered together with the specific reason for its color, generated from the verification checks performed in a Clear Show 360 session and delivered to Customer for Clear Show 360 sessions only. The Assessment is not generated for Clear Show ID sessions, does not incorporate AML/

PEP results (which are reported separately as a yes/no match flag), and is not derived from criminal-history data, which Clear Showings does not collect or process.

"Customer Data" means personal information that Customer or its authorized users submit to the Services that Customer controls — for example, the contact details Customer provides to initiate a verification, and Customer account and user records.

"Data Subject" means the individual undergoing verification (e.g., a prospective property visitor).

"Controller," "Processor," "Subprocessor," and "process/processing" have the meanings given under Applicable Data Protection Law.

2. Roles of the Parties

2.1 Verification Data — Clear Showings as independent Controller

With respect to Verification Data, Clear Showings acts as an independent Controller. Clear Showings determines the purposes and means of processing Verification Data, obtains the Data Subject's consent directly through its own consent flow — including consent to disclosure of the Verification Summary to Customer — maintains the applicable written biometric data policy, and sets retention and destruction. Customer does not direct, and is not responsible for, Clear Showings' processing of Verification Data.

2.2 Customer Data — Clear Showings as Processor

With respect to Customer Data, Clear Showings acts as a Processor on Customer's behalf and processes Customer Data only on Customer's documented instructions, except where law requires otherwise.

2.3 No joint control

The parties are not joint Controllers. Each party is independently responsible for its own compliance with Applicable Data Protection Law in its respective role.

3. Customer Obligations and Acceptable Use

Customer represents, warrants, and agrees that:

3.1 Lawful basis to initiate. Customer has a legitimate, lawful basis to request verification of each Data Subject and will not request verification for any unlawful, harassing, retaliatory, or pretextual purpose.

3.2 Reliance on Clear Showings' consent flow. Customer acknowledges that consent for biometric and identity processing — including consent to disclosure of the Verification Summary to Customer — is obtained by Clear Showings directly from the Data Subject. Customer will not represent to any Data Subject that Customer is collecting or storing their biometric data.

3.3 Fair Housing. Customer will use the Services and all verification outputs in compliance with the Fair Housing Act and all applicable fair-housing and anti-discrimination laws. Customer will not use the Verification Summary, the Assessment, or any verification result to discriminate against any person on the basis of race, color, religion, sex, disability, familial status, national origin, or any other protected characteristic.

3.4 Use of verification outputs; no adverse-action delegation. The Verification Summary is informational and supports — but does not make — Customer's decisions. Customer will use the Verification Summary solely for

deciding whether to proceed with a specific real estate showing, open house, or property tour. Customer is solely responsible for any decision it makes regarding property access. No verification output is a consumer report or a substitute for one, and Customer will not use any verification output for any purpose governed by the FCRA, including decisions regarding employment, tenancy, credit, insurance, or eligibility for any benefit.

3.5 No redistribution, extraction, or re-identification. Customer will access the Verification Summary only through the secure Clear Showings dashboard and will not copy, screenshot, download, export, publish, post, share, or otherwise redistribute the Verification Summary or any component of it — including the Data Subject's selfie photograph, identity document images, face-match scores, Assessment, or AML/PEP flag — outside the dashboard. Customer will not attempt to derive, reconstruct, or re-identify any biometric template, unmasked identity-document data, or underlying screening records from the Verification Summary, and will not retain any component of the Verification Summary beyond the retention periods described in Clear Showings' published privacy policy.

3.6 Customer Data accuracy and rights. Customer Data that Customer submits is accurate and lawfully provided, and Customer has the authority to provide it to Clear Showings for processing.

3.7 Credential security. Customer is responsible for safeguarding its account credentials and for all activity under its account, including any access to Verification Summaries by Customer's authorized users.

4. Clear Showings' Obligations as Processor (Customer Data)

With respect to Customer Data processed as a Processor, Clear Showings will:

4.1 process Customer Data only on Customer's documented instructions, unless required by law;

4.2 ensure that personnel authorized to process Customer Data are bound by confidentiality;

4.3 implement and maintain appropriate technical and organizational security measures (see Section 8);

4.4 reasonably assist Customer in responding to Data Subject rights requests relating to Customer Data;

4.5 notify Customer without undue delay after becoming aware of a security breach affecting Customer Data or any personal, biometric, identity, or Verification Data processed in connection with Customer’s account, and in no event later than 72 hours after Clear Showings confirms that such an incident materially affects information processed in connection with Customer’s account; and

4.6 on termination, delete or return Customer Data at Customer's choice, except where retention is required by law.

Verification Data is governed by Clear Showings' own privacy and biometric policies in its capacity as Controller.  However, Clear Showings' security incident notification obligations under Section 4.5 apply to a security incident involving Verification Data processed in connection with Customer's account.  Clear Showings will provide continuing updates as material information becomes available, preserve relevant evidence, reasonably cooperate with Customer's investigation and response, and provide information reasonably necessary for Customer to satisfy its own legal, regulatory, contractual, and individual notification obligations.

4.7 Legal Holds and Required Retention. Notwithstanding any deletion or return obligation under this DPA, Clear Showings may retain information to the extent and for the period reasonably necessary to comply with applicable law, a valid legal process, regulatory obligation, litigation hold, fraud or security investigation, or the establishment, exercise, or defense of legal claims. Any information retained under this provision will remain subject to the applicable confidentiality and security obligations of this DPA and will not be processed for any unrelated purpose.

5. Subprocessors

5.1 Customer grants Clear Showings general authorization to engage Subprocessors to process Customer Data. Current Subprocessors of Customer Data include: Bubble.io (application platform; AWS as Bubble's subprocessor for hosting), Stripe (payments), Google (authentication), and Didit (Didit Identity, Inc.), to the extent Didit processes Customer Data such as Data Subject contact details that Customer submits to initiate a verification. Clear Showings will maintain a current, controlling list of all Subprocessors that process Customer Data or Verification Data in connection with the Services, including WorkOS, Postmark, and any other applicable service providers identified in Clear Showings' Privacy Policy.

For transparency, Clear Showings also discloses the service providers that process Verification Data in Clear Showings' capacity as independent Controller: Didit (identity and biometric verification; AML/PEP watchlist screening; one-time passcode delivery for phone confirmation; the United States deceased-records check; and orchestration of Global ID Confirmation), and, for Clear Show 360 sessions involving an identity document issued by a supported country, the issuing government's registry services — currently Mexico's national population and electoral registry services (CURP validation with electoral-registry fallback), Colombia's connected national registry

services, and Brazil's Receita Federal (CPF status check), in each case where available and as described in Clear Showings' published Privacy Policy. NatCrim (criminal/watchlist screening) and OpenAI (risk-score processing), disclosed in prior versions of this DPA, have been removed and are no longer used; Clear Showings does not use any criminal-records or background-records provider. Processing of Verification Data by these providers is governed by Clear Showings' published privacy and biometric data policies rather than by Sections 4 and 6 of this DPA.

5.2 Clear Showings imposes data-protection obligations on each Subprocessor substantially similar to those in this DPA and remains responsible for their performance with respect to Customer Data.

5.3 Clear Showings will provide notice of any new Subprocessor at least thirty (30) days before the new Subprocessor begins processing Customer Data or Verification Data in connection with Customer's account.  Customer may object during that period on reasonable and documented data-protection grounds.  The parties will work in good faith to address the objection, including through commercially reasonable alternative measures where available.

6. Data Subject Requests

6.1 For requests concerning Customer Data, Clear Showings will assist Customer in responding.

6.2 For requests concerning Verification Data, Clear Showings responds directly as Controller through its published privacy and biometric policy; Customer will refer such requests to Clear Showings at contact@clearshowings.com.6. 3 Governmental and Legal Requests If Clear Showings receives a subpoena, court order, warrant, regulatory request, or other legally binding demand relating to Customer Data, Clear Showings may disclose information to the extent reasonably necessary to comply with that demand. Where legally permitted and reasonably practicable, Clear Showings will notify Customer before disclosing Customer Data and will reasonably cooperate with Customer regarding an appropriate response. Clear Showings is not required to challenge a lawful governmental request or incur material expense in connection with such a challenge unless Customer agrees to reimburse the reasonable costs of doing so.

7. International Transfers

Where Applicable Data Protection Law restricts cross-border transfers (e.g., GDPR), the parties will rely on a recognized transfer mechanism, including the EU Standard Contractual Clauses, where applicable.  If the EU Standard Contractual Clauses or another transfer agreement is required, the parties will execute the applicable module and complete and maintain the required party information, transfer details, annexes, categories of data subjects and personal data, processing purposes, Subprocessor information, and technical and organizational security measures.  Customer acknowledges that certain Verification Data is hosted primarily in the European Economic Area and is processed in the United States, under appropriate transfer mechanisms.

In addition, for Clear Show 360 sessions involving an identity document issued by a supported country, Clear Showings performs Global ID Confirmation: an outbound validation query transmitting only the minimum data required to validate the presented document to the issuing government's own registry services. These validation queries operate within the verification consent presented to the Data Subject, are limited to countries where a lawful, consent-based validation path exists, and are subject on the registry side to the data-protection law of the issuing country, as described in Clear Showings' published Privacy Policy. Documents from all other countries receive document authentication only, with no query to the issuing government.

8. Security Measures

Clear Showings maintains administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest (AES-256), role-based access controls, contractual data-protection obligations on Subprocessors, and automated deletion with destruction logging. Clear Showings' verification Subprocessor maintains independent certifications (including SOC 2, ISO/IEC 27001, and iBeta PAD), available to Customer under NDA on request.

No Absolute Security Guarantee. Clear Showings will maintain the safeguards required by this DPA and Applicable Data Protection Law; however, no security program can eliminate all risk of unauthorized access, acquisition, disclosure, alteration, loss, or destruction. The occurrence of a security incident, standing alone, will not establish that Clear Showings failed to comply with its obligations under this DPA.

9. Audit

On reasonable prior written notice (not less than 30 days), and no more than once per 12-month period, Clear Showings will make available information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through Subprocessor certifications and reports.

10. Liability and Precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. This DPA does not expand either party's aggregate liability beyond the limits in the Agreement, except where Applicable Data Protection Law does not permit such limitation.

11. Term

This DPA takes effect on the Effective Date and continues for the term of the Agreement. Provisions that by their nature should survive — including confidentiality, deletion, and audit — survive termination as required by Applicable Data Protection Law.

Clear Showings LLC · 615 River Highway, Suite 1008, Mooresville, NC 28117 · contact@clearshowings.com | 844-771-6606 Governing law: State of North Carolina | Venue: Iredell County, North Carolina

Exhibit A — Details of Processing

1. Subject Matter and Purpose of Processing.

Clear Showings processes personal information to provide identity and trust verification services for real estate showings, open houses, and property tours, administer customer accounts, provide verification results, maintain the security and integrity of the Services, respond to requests, and comply with applicable law.

2. Duration of Processing.

Processing continues for the term of the Agreement and for the applicable retention periods stated in the Agreement, this DPA, the Privacy Policy, and the Biometric Data Policy, except where a longer period is required by applicable law or reasonably necessary for the establishment, exercise, or defense of legal claims.

3. Categories of Data Subjects.

Data Subjects may include Customer's authorized users, requesting real estate professionals, prospective property visitors, individuals undergoing identity verification, and individuals whose information is submitted through the Services.

4. Categories of Personal Information.

Personal information may include names, email addresses, telephone numbers, account information, identity-document images and data, selfie photographs, facial geometry and other biometric information, face-match similarity and confidence scores, masked identity-document images, verification results, Assessment results, AML/PEP flags, deceased-record check outcomes, registry-validation outcomes, device information, log information, and associated verification metadata.

5. Categories of Processing.

Processing may include collection, recording, organization, structuring, storage, hosting, retrieval, consultation, comparison, authentication, analysis, transmission, disclosure, masking, restriction, deletion, and destruction.

6. Security Measures.

Clear Showings and its applicable vendors will maintain administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the information processed, including encryption in transit and at rest, role-based access controls, credential controls, personnel confidentiality obligations, logging, data minimization, retention controls, deletion procedures, incident response procedures, and contractual data-protection obligations for applicable vendors and Subprocessors.

Clear Showings LLC — Data Processing Addendum v4 — Last updated [July 15, 2026]

Clear Showings LLC · contact@clearshowings.com · clearshowings.com