Data Processing Addendum for Open Factor.
Version 1.0 · 21 August 2026
The undersigned customer (Customer) and Open Factor (Provider) (each a Party and collectively the Parties) enter into this Data Processing Addendum (including the annexes attached hereto, this DPA) as of the date the Customer accepts the Agreement and forms part of the Terms of Use and any applicable customer agreement or order form between the Parties (as amended, the Agreement). This is Version 1.0, last revised 21 August 2026. By entering into the Agreement or using the Services, Customer agrees to this DPA. A countersigned copy is available upon request through /contact.
The following terms have the meanings set out below for purposes of this DPA. Any capitalized terms not defined in this DPA have the meanings given in the Agreement.
Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract, or otherwise.
Applicable Data Protection Laws means the privacy, data protection, and data security laws and regulations applicable to Provider's Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws and GDPR.
Controller means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, including, as applicable, any "business" or "controller" as such term is defined by the California Consumer Privacy Act (the CCPA) or other State Privacy Laws.
Customer Data means information provided or otherwise made available by or on behalf of Customer to Provider for Processing on Customer's behalf to perform the Services.
Data Subject means the identified or identifiable natural person to whom Personal Data relates.
EEA means the European Economic Area.
FADP means the Swiss Federal Act on Data Protection of 25 September 2020 (as amended and in force from 1 September 2023) and any applicable implementing legislation and ordinances, and, to the extent applicable, its predecessor of 19 June 1992.
FDPIC means Swiss Federal Data Protection and Information Commissioner.
GDPR means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended) (UK GDPR), including any applicable national implementing or supplementary legislation (for example, the UK Data Protection Act 2018), and any successor, amendment, or re-enactment.
Information Security Incident means a breach of Provider's security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Provider's possession, custody, or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
Personal Data means Customer Data that constitutes "personal data," "personal information," or "personally identifiable information" defined in Applicable Data Protection Laws or information of a similar character regulated thereby, provided that Personal Data does not include such information pertaining to Customer's business contacts who are Customer personnel or such information that Provider receives, collects, or generates independently of the Services and not from or on behalf of Customer.
Process or Processing means any operation or set of operations which is performed by Provider (or on Provider's behalf) for Customer under the Agreement on Personal Data or on sets of Personal Data, whether or not by automated means.
Processor means the entity that Processes Personal Data on behalf of the Controller, including, as applicable, any "service provider" or "contractor" as those terms are defined by the CCPA.
Restricted Transfer means the disclosure, grant of access, or other transfer of Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an EU Restricted Transfer); (ii) in the context of the UK, any country or territory outside the UK which does not benefit from an adequacy decision from the UK Government (a UK Restricted Transfer); and (iii) in the context of Switzerland, a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss Government (a Swiss Restricted Transfer), in each case, which would be prohibited without a legal basis under applicable data protection law.
SCCs means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914.
Security Measures has the meaning given in Section 4 (Provider Security Measures).
Services has the meaning given in the Agreement.
State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws (and any implementing regulations) currently in effect and applicable to Provider's Processing of Personal Data under the Agreement.
Subprocessors means Provider's Affiliates and third parties that Provider engages to Process Personal Data in relation to the Services.
Supervisory Authority means any entity with the authority to enforce Applicable Data Protection Laws, including the relevant authority under the EU GDPR, the UK Information Commissioner's Office, and the FDPIC.
UK Transfer Addendum means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof.
This DPA will remain in effect so long as Provider Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
Processing of Personal Data subject to the GDPR shall be subject to Annex 2 (European Annex). Processing of Personal Data subject to the State Privacy Laws with respect to which Customer is a Business, Controller, Processor, or Service Provider shall be subject to Annex 3 (State Privacy Laws Annex) to this DPA.
Provider will Process Personal Data only in accordance with Customer's documented instructions to Provider, including as set out in this DPA, the Agreement, any applicable order form(s), and any other written instructions provided by Customer from time to time that are consistent with the Agreement and this DPA. To the extent Customer requests instructions that are outside the scope of the Services or that would require Provider to materially change the Services or undertake additional work not contemplated by the Agreement, the Parties will agree to such instructions in a mutually executed amendment to this DPA or other written agreement. By entering into this DPA, Customer instructs Provider to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The parties agree that the details of Provider's Processing of Personal Data are as described in Annex 1 (Data Processing Details) to the DPA.
Provider will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data as described in Annex 4 (the Security Measures), taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing and the risks to Data Subjects. Provider may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.
Provider will require that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.
Provider will notify Customer without undue delay of any Information Security Incident of which Provider becomes aware. Such notifications will describe, to the extent then known, available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Provider recommends Customer take to address the Information Security Incident. Provider's notification of or response to an Information Security Incident will not be construed as Provider's acknowledgement of any fault or liability with respect to the Information Security Incident. Provider will reasonably cooperate with Customer and take such commercially reasonable steps, to the extent within Provider's control, as may be reasonably requested by Customer and mutually agreed in good faith by the Parties to assist in the investigation of any such Information Security Incident. Customer is solely responsible for complying with notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Information Security Incident.
Customer agrees that, without limitation of Provider's obligations under this Section 4, Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (b) securing the account authentication credentials, systems, and devices Customer uses to access the Services; (c) securing Customer's systems and devices that Customer provides or makes available for Provider to access in order to provide the Services; and (d) backing up Personal Data, as applicable.
Customer acknowledges that it has evaluated the Services, the Security Measures, and Provider's commitments under this DPA and, based on information made available by Provider, determines that they are adequate to meet Customer's needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.
Provider will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (Data Subject Requests) with respect to Personal Data in Provider's possession or control. Customer will compensate Provider for any such assistance, to the extent such assistance requires work beyond the Services, at Provider's then-current professional services rates, which shall be made available to Customer upon request.
If Provider receives a Data Subject Request, Provider will (i) promptly notify Customer (unless prohibited by applicable law); and (ii) advise the Data Subject to submit the request to Customer. Customer will be solely responsible for responding to any such request, unless otherwise required by applicable law.
Customer will ensure (and is solely responsible for ensuring) that it has provided all notices to, and obtained all consents and permissions from, third parties (including Data Subjects), and has reserved all necessary rights, in each case, as may be required under Applicable Data Protection Laws for Provider to Process Personal Data as contemplated by the Agreement.
Customer represents and warrants to Provider that Customer Data does not and will not contain any social security numbers or other government-issued identification numbers, protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; health insurance information; biometric information; passwords or other credentials for third-party online accounts (other than credentials created for and used solely to access the Services); credentials to any financial accounts; tax return data; any payment card information subject to the Payment Card Industry Data Security Standard; personal data of children under 16 years of age; or any other information that falls within any special categories of data (as defined in Applicable Data Protection Laws) (Restricted Data).
Customer shall ensure that there is, and will be throughout the term of the Agreement, a valid legal basis for the Processing by Provider of Personal Data in accordance with this DPA and the Agreement. Customer will ensure that all Data Subjects have been presented with all required notices and statements and provided all required consents relating to the Processing by Provider of Personal Data.
Customer specifically authorizes the engagement of Provider's Affiliates as Subprocessors and generally authorizes Provider to engage third parties as Subprocessors in accordance with this Section 7. Information about Subprocessors, including their functions and locations, is available in Annex 5 of this DPA. Provider may continue to use those Subprocessors already engaged by Provider as of the effective date of this DPA. Current or updated Subprocessor information is also available upon request through /contact.
When engaging any Subprocessor, Provider will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Provider shall remain responsible for the performance of all obligations subcontracted to the Subprocessor and shall be liable for all acts and omissions of the Subprocessor to the same extent as Provider would have been had it performed the Processing itself.
When Provider engages any new Subprocessor after the effective date of the DPA, Provider will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating Annex 5 and providing written notice (including by email) to Customer's designated contact for Services-related communications, or by other written means. If Customer objects to such engagement in a written notice to Provider within 15 days after receipt of such notice on reasonable grounds relating to the protection of Personal Data, Customer and Provider will work together in good faith to find a mutually acceptable resolution to address such objection. If the Parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by providing written notice to Provider and pay Provider for all amounts due and owing under the Agreement as of the date of such termination.
Customer may audit Provider's compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct such additional audit or a competent Supervisory Authority with jurisdiction over Customer requires it, in each case upon Customer's written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Provider will contribute to such audits by providing Customer with the information and assistance reasonably necessary to conduct the audit.
If a third party is to conduct the audit, Provider may object to the auditor if the auditor is, in Provider's reasonable opinion, not independent, a competitor of Provider, or otherwise manifestly unsuitable. To request an audit, Customer must submit a proposed audit plan to Provider at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the Parties. If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST, or similar audit report performed by a qualified third-party auditor within 12 months of Customer's audit request and Provider has confirmed there have been no known material changes in the controls audited since the date of such report, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures. Any audits are at Customer's sole expense.
Upon the date of cessation of any Services involving the Processing of Personal Data (the Cessation Date), Provider will promptly cease all Processing of Personal Data for any purpose other than for storage and Processing necessary to effect the return, deletion, or anonymization of such Personal Data, or as otherwise permitted or required under this DPA or applicable law.
To the extent technically feasible in the circumstances, on written request to Provider (to be made within 30 days after the Cessation Date (the Post-cessation Storage Period)), Provider will, within a commercially reasonable period following receipt of such request, as elected by Customer in such request, either (i) return a complete copy of all Personal Data within Provider's possession to Customer by secure file transfer or other commercially reasonable secure method, promptly following which Provider shall delete or anonymize all other copies of such Personal Data, or (ii) delete or anonymize all Personal Data within Provider's possession.
If, during the Post-cessation Storage Period, Customer does not instruct Provider in writing to either delete or return Personal Data, Provider will, within a commercially reasonable time after the expiry of the Post-cessation Storage Period, either (at its option) delete or anonymize all Personal Data then within Provider's possession, custody, or control to the fullest extent technically feasible in the circumstances. Provider may retain Personal Data to the extent permitted or required by applicable law, for no longer than such applicable law requires, provided that Provider will maintain the confidentiality of all such Personal Data and protect it in accordance with the Security Measures.
Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether the Provider's own or a third party's, unless (a) such use is reasonably necessary to provide the Services in accordance with the Customer's documented instructions, or (b) expressly authorized by the Customer in writing.
Provider will prohibit its Subprocessors, including any AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as expressly authorized by the Customer in writing.
If the Services involve automated decision-making that produces legal or similarly significant effects on Data Subjects, Provider will: (a) disclose the existence of such processing to the Customer; (b) to the extent reasonably available to the Provider, provide meaningful information about the logic involved without requiring disclosure of the Provider's trade secrets or confidential information; and (c) reasonably cooperate with the Customer, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights under such laws relating to automated decision-making.
Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the Parties acknowledge and agree that Provider's access to Personal Data does not constitute part of the consideration exchanged by the Parties in respect of the Agreement. Notices required or permitted to be given by Provider to Customer under this DPA may be given in accordance with any notice clause of the Agreement, to Customer's contact details for data protection set out in Annex 1, to Provider's primary points of contact with Customer, or through /contact.
Provider agrees to cooperate in good faith with Customer to consider any amendments that may be reasonably necessary to address compliance with the Applicable Data Protection Laws. Provider may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, provided that any such variation will not materially reduce the protections afforded to Personal Data or materially increase Customer's obligations under this DPA without Customer's written agreement.
To the extent permitted by Applicable Data Protection Laws and the SCCs (if and as they apply), the total aggregate liability of either Party to the other Party, however arising, under or in connection with this DPA and the SCCs will under no circumstances exceed any limitations or caps on, and will be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement; provided that nothing in this Section 11 will affect any person's liability to Data Subjects under the third-party beneficiary provisions of the SCCs.
In the event of any conflict or inconsistency between (i) this DPA and the Agreement, this DPA will prevail, or (ii) any SCCs entered into pursuant to Annex 2 and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.
Name: Open Factor
Address / notices: Available upon request through /contact. Website: openfactor.ai.
Contact details for data protection: Privacy inquiries via /contact. See also our Privacy Policy.
Provider activities: Provider of software products and online services, including AI-powered workspaces and related digital properties.
Role: Processor (or Subprocessor, as applicable).
Name: The entity or other person who is a counterparty to the Agreement.
Customer's address and data protection contact: As provided by Customer in the Agreement, order form, or account.
Customer activities: Customer's activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Role: Controller or Processor (as applicable).
Categories of Data Subjects: Relevant Data Subjects include any Data Subjects whose Personal Data Customer causes Provider to Process in connection with the Services, including end-users and other users of Customer's products and services, and Customer's personnel (including employees and contractors) and other business contacts or representatives of Customer.
Categories of Personal Data: Relevant Personal Data includes any categories of Personal Data Customer causes Provider to Process as part of the provision of the Services, including personal details (name and contact information); authentication details (usernames, passwords or PIN codes used to access the Services, security questions, authentication tokens, and other access protocols); and technological details (IP addresses, unique identifiers, location data, internet / application / program activity data, and device IDs).
Sensitive categories of data: None. As noted in Section 6 of the DPA, Customer agrees that Restricted Data, which includes sensitive data as defined in Clause 8.7 of the SCCs, must not be submitted to the Services without the Parties' prior written agreement.
Frequency of transfer: Ongoing, as initiated by Customer in and through its use, or use on its behalf, of the Services.
Nature and purpose of the Processing: Processing operations required in order to provide the Services and perform Provider's obligations in accordance with the Agreement and this DPA, as initiated by Customer in its use thereof.
Duration of Processing / retention period: For the period determined in accordance with the Agreement and this DPA, including Section 9 of the DPA.
Transfers to subprocessors: Transfers to Subprocessors are as, and for the purposes, described from time to time in Annex 5.
Where Provider receives an instruction from Customer that, in its reasonable opinion, infringes the GDPR, Provider shall inform Customer. Customer acknowledges and agrees that any instructions issued by Customer with regards to the Processing of Personal Data by or on behalf of Provider shall be in strict compliance with the GDPR and all other applicable laws.
Provider, taking into account the nature of the Processing and the information available to Provider, shall provide reasonable assistance to Customer, at Customer's cost, upon Customer's written request, to the extent reasonably necessary and technically feasible, with any data protection impact assessments and prior consultations with Supervisory Authorities as may be required of Customer under Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Personal Data by Provider.
To the extent that any Processing of Personal Data under this DPA involves an EU Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed populated in accordance with Attachment 1 to this Annex 2 and entered into by the Parties and incorporated by reference into this DPA.
To the extent that any Processing of Personal Data under this DPA involves a UK Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs as varied by the UK Transfer Addendum, which are hereby deemed entered into by the Parties and incorporated by reference into this DPA. Table 4 to the UK Transfer Addendum is completed by the box labelled "Data Importer" being deemed to have been ticked, and the Parties agree to be bound by the Mandatory Clauses.
To the extent that any Processing of Personal Data under the DPA involves a Swiss Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs as varied to address the requirements of the FADP: "GDPR" means the FADP; "European Union," "Union," and "Member State(s)" each mean Switzerland; and "supervisory authority" means the FDPIC. Nothing in any applicable SCCs should be interpreted to limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject's place of habitual residence.
Provider may, on notice, vary this DPA and replace the relevant SCCs with any new form of the relevant SCCs or another valid transfer mechanism that Provider reasonably determines is necessary to maintain compliance with Chapter V of the GDPR, provided that any such replacement does not materially decrease the overall protection of Personal Data.
Where the SCCs apply, each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs. Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right. Module Three of the SCCs applies to any EU Restricted Transfer, UK Restricted Transfer, and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person.
The optional Docking Clause in Clause 7 is not used. In Clause 9, Option 2 (general written authorisation) applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the notice period set out in Section 7 of the DPA (currently fifteen (15) days). Option 1 (specific prior authorisation) is not used. In Clause 11, the optional language is not used. In Clause 17, Option 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer. For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland.
Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 to the DPA, with Customer being data exporter and Provider being data importer. Annex II is populated by reference to Section 4 of the DPA and Annex 4 (Security Measures).
For purposes of this Annex 3, the terms "business," "controller," "processor," "commercial purpose," "sell," "share," "service provider," and "contractor" shall have the respective meanings given thereto in the applicable State Privacy Laws, and "personal information" shall mean Personal Data to the extent it constitutes "personal information" or "personal data" governed by the State Privacy Laws.
It is the Parties' intent that with respect to any personal information, Provider is a service provider, contractor, and/or processor, as applicable under the State Privacy Laws. Provider (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Provider's Processing of personal information is consistent with Customer's obligations under the State Privacy Laws; (d) will notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
Provider will not (a) sell or share any personal information; (b) retain, use, or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use, or disclose the personal information outside of the direct business relationship between Provider and Customer; or (d) combine personal information received under the Agreement with personal information received from or on behalf of another person, or collected from Provider's own interaction with any Data Subject, except as and to the extent permitted by the State Privacy Laws and necessary as part of Provider's provision of the Services. Provider hereby certifies that it understands its obligations under this Annex 3 and will comply with them.
Giving Customer notice of Subprocessor engagements in accordance with Section 7 of the DPA will satisfy Provider's obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements. Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Provider's use of personal information is consistent with Provider's obligations under the State Privacy Laws.
Provider maintains the following technical and organizational measures:
Organizational management and personnel with assigned responsibility for the development, implementation, and maintenance of Provider's information security program.
Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Provider's organization, monitoring and maintaining compliance with Provider's policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
Data security controls which include, at a minimum, logical segregation of data, restricted (for example, role-based) access and monitoring, and utilization of commercially available industry-standard encryption technologies (or materially equivalent safeguards) for Personal Data when transmitted over public networks or when transmitted wirelessly or at rest.
Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, including granting access on a need-to-know and least-privilege basis, use of unique user IDs and appropriate authentication credentials, and periodic review and revoking or changing access promptly when employment terminates or changes in job functions occur.
Password controls designed to manage and control password strength, expiration, and usage, including prohibiting users from sharing passwords and requiring multi-factor authentication as appropriate.
System audit or event logging and related monitoring procedures to proactively record user access and system activity.
Physical and environmental security of data centers, server room facilities, and other areas containing Personal Data designed to protect information assets from unauthorized physical access and to guard against environmental hazards.
Operational procedures and controls to provide for the secure configuration, monitoring, and maintenance of technology and information systems, including secure disposal of systems and media.
Change management procedures and tracking mechanisms designed to test, approve, and monitor all material changes to Provider's technology and information assets that may affect the security of Personal Data.
Incident management procedures designed to allow Provider to investigate, respond to, mitigate, and provide notifications in accordance with this DPA.
Network security controls designed to protect systems from intrusion and limit the scope of any successful attack, including the use of firewalls and network segmentation.
Vulnerability assessment, patch management, and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
Business resiliency, continuity, and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters.
Customer approves Provider's engagement of the following Subprocessors to provide services pursuant to the Agreement. An updated list is available upon request through /contact.
| Subprocessor | Location(s) | Description of Processing / Services Performed |
|---|---|---|
| PostHog | United States and EEA | Product analytics and related event processing |
| Stripe | United States | Payment processing |
| Vercel | United States | Application hosting and content delivery |
| Cloud infrastructure and AI model providers engaged to perform the Services | Various, including the United States | Hosting, inference, and related processing as needed to provide the Services |