Findrix

Data Processing Addendum

1. Scope, roles, and order of precedence

This DPA applies where Findrix processes Customer Personal Data on your behalf in the course of providing the Service. In this DPA, "Customer Personal Data" means personal data contained in Customer Content or otherwise processed by Findrix on your behalf; "Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other applicable data-protection law; and the terms controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the GDPR.

For Customer Personal Data, you are the controller (or a processor acting for another controller) and Findrix is the processor. Findrix is an independent controller for the limited data described in our Privacy Policy as controller data (your account, billing, and marketing/support interactions and product-usage telemetry); this DPA does not govern that processing.

This DPA is incorporated into and forms part of the Terms of Service (the "Agreement"). If there is a conflict between this DPA and the rest of the Agreement about the processing of Customer Personal Data, this DPA prevails. Except as amended here, the Agreement remains in full force.

2. Details of the processing (Article 28(3))

The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex I below.

3. Findrix's obligations as processor

Findrix will:

4. Security measures

Findrix maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These are summarized in Annex II and include, at a minimum: encryption of data in transit (TLS) and at rest (provider-managed AES-256); role-based access controls on a least-privilege basis; an audit log of administrative actions; scoped, short-lived credentials for site deployments; SSRF protection with address validation on outbound fetches; rate limiting and abuse mitigation; and secure software-development and change-management practices. Findrix may update its measures over time provided the level of protection is not materially reduced.

5. Sub-processors

You give Findrix general written authorization to engage sub-processors to process Customer Personal Data. Our current sub-processors, with the service each provides, the region, the data categories, and a link to its privacy policy, are listed on our sub-processor page, which forms part of this DPA. That page covers the vendors that process Customer Personal Data on our behalf; infrastructure suppliers that receive no personal data are not sub-processors and are described there for transparency.

Findrix imposes on each sub-processor data-protection obligations that are, in substance, no less protective than those in this DPA, and remains responsible to you for a sub-processor's performance. We will give you at least 30 days' notice before adding or replacing a sub-processor that processes Customer Personal Data — by updating the sub-processor page and, where you have subscribed, by email or in-app notice. You may object on reasonable, documented data-protection grounds within that notice period; we will work in good faith to address the objection, and if we cannot, you may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees as your sole remedy.

6. Assisting you with data-subject requests

Taking into account the nature of the processing, Findrix will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). Where a data subject makes such a request directly to Findrix, we will, unless legally required to respond, refer them to you or forward the request to you without undue delay. The Service also provides self-service export and deletion controls you can use to satisfy many requests directly.

7. Assisting you with security, breach, and impact assessments

Taking into account the nature of the processing and the information available to Findrix, we will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR, namely: security of processing (Art. 32); notification of a personal data breach to the supervisory authority (Art. 33) and communication to data subjects (Art. 34); data protection impact assessments (Art. 35); and prior consultation with the supervisory authority (Art. 36).

Personal data breach. Findrix will notify you without undue delay, and in any event no later than 72 hours after Findrix confirms a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for more information; we will provide further details as they become available. Notification is not an acknowledgement of fault or liability.

8. Audits and information

Findrix will make available to you the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, primarily through its documentation, security overview, and any third-party audit reports or certifications it holds. Where that information is not sufficient to demonstrate compliance, Findrix will allow for and contribute to a reasonable audit, including inspections, conducted by you or an independent auditor you mandate, subject to reasonable notice, confidentiality obligations, no more than once per year (unless required by a supervisory authority or following a breach), during business hours, and in a manner that does not disrupt the Service or compromise other customers' data.

9. Deletion or return of data

On termination or expiry of the Agreement, and at your choice, Findrix will delete or return all Customer Personal Data, and delete existing copies, unless the law requires it to be stored. For a transitional period after termination you may export Customer Content from the Service as described in the Agreement; after that period Findrix deletes or de-identifies Customer Personal Data on the schedule in the Privacy Policy. Residual copies in routine backups are deleted on their normal rolling cycle and remain protected by this DPA until then.

10. International transfers

Customer Personal Data is stored primarily in the European Union. Where Findrix or a sub-processor processes Customer Personal Data outside the EEA, the UK, or Switzerland, the transfer is made under an appropriate safeguard, and the parties agree that the following apply as relevant:

Where there is a conflict between the SCCs and this DPA, the SCCs prevail for the transfers they govern. You can request details of the safeguards from dpo@findrix.ai.

11. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the limitations and exclusions of liability in the Terms of Service, and any reference in those Terms to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits any liability that cannot be limited under applicable Data Protection Law, including a data subject's rights.

12. Duration and changes

This DPA takes effect when it is incorporated into the Agreement and continues for as long as Findrix processes Customer Personal Data on your behalf. We may update this DPA to reflect changes in law, guidance, or our practices; for material changes we will give reasonable notice, and changes will not reduce the level of protection for Customer Personal Data.

Annex I — Description of the processing

Annex II — Technical and organizational measures

Contact

To request a countersigned copy of this DPA, or for any question about it, contact dpo@findrix.ai. This DPA applies on its terms once incorporated into the Agreement, whether or not it is separately signed.

Data Processing Addendum · Findrix