Data Processing Addendum
1. Scope, roles, and order of precedence
This DPA applies where Findrix processes Customer Personal Data on your behalf in the course of providing the Service. In this DPA, "Customer Personal Data" means personal data contained in Customer Content or otherwise processed by Findrix on your behalf; "Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other applicable data-protection law; and the terms controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the GDPR.
For Customer Personal Data, you are the controller (or a processor acting for another controller) and Findrix is the processor. Findrix is an independent controller for the limited data described in our Privacy Policy as controller data (your account, billing, and marketing/support interactions and product-usage telemetry); this DPA does not govern that processing.
This DPA is incorporated into and forms part of the Terms of Service (the "Agreement"). If there is a conflict between this DPA and the rest of the Agreement about the processing of Customer Personal Data, this DPA prevails. Except as amended here, the Agreement remains in full force.
2. Details of the processing (Article 28(3))
The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex I below.
- Subject matter: Findrix's processing of Customer Personal Data to provide the Service.
- Duration: for the term of the Agreement, plus the post-termination period in Section 9 and the retention schedule in the Privacy Policy.
- Nature and purpose: auditing websites for AI-search readiness, measuring how AI assistants and answer engines reference brands, generating recommendations and reports, and — where you connect a site — deploying changes you approve.
3. Findrix's obligations as processor
Findrix will:
- Process only on documented instructions. Process Customer Personal Data only on your documented instructions — including the Agreement, this DPA, and your configuration and use of the Service — unless required to do otherwise by law, in which case we will inform you first unless the law prohibits it. If we believe an instruction infringes Data Protection Law, we will tell you.
- Confidentiality. Ensure that personnel authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality and process it only as needed to perform their role.
- Security (Article 32). Implement and maintain the technical and organizational measures in Annex II, appropriate to the risk.
- Sub-processors. Engage sub-processors only under Section 5.
- Assistance. Assist you as described in Sections 6 and 7.
- Deletion or return. Delete or return Customer Personal Data as described in Section 9.
- Audits. Make available the information and audit rights described in Section 8.
4. Security measures
Findrix maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These are summarized in Annex II and include, at a minimum: encryption of data in transit (TLS) and at rest (provider-managed AES-256); role-based access controls on a least-privilege basis; an audit log of administrative actions; scoped, short-lived credentials for site deployments; SSRF protection with address validation on outbound fetches; rate limiting and abuse mitigation; and secure software-development and change-management practices. Findrix may update its measures over time provided the level of protection is not materially reduced.
5. Sub-processors
You give Findrix general written authorization to engage sub-processors to process Customer Personal Data. Our current sub-processors, with the service each provides, the region, the data categories, and a link to its privacy policy, are listed on our sub-processor page, which forms part of this DPA. That page covers the vendors that process Customer Personal Data on our behalf; infrastructure suppliers that receive no personal data are not sub-processors and are described there for transparency.
Findrix imposes on each sub-processor data-protection obligations that are, in substance, no less protective than those in this DPA, and remains responsible to you for a sub-processor's performance. We will give you at least 30 days' notice before adding or replacing a sub-processor that processes Customer Personal Data — by updating the sub-processor page and, where you have subscribed, by email or in-app notice. You may object on reasonable, documented data-protection grounds within that notice period; we will work in good faith to address the objection, and if we cannot, you may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees as your sole remedy.
6. Assisting you with data-subject requests
Taking into account the nature of the processing, Findrix will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). Where a data subject makes such a request directly to Findrix, we will, unless legally required to respond, refer them to you or forward the request to you without undue delay. The Service also provides self-service export and deletion controls you can use to satisfy many requests directly.
7. Assisting you with security, breach, and impact assessments
Taking into account the nature of the processing and the information available to Findrix, we will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR, namely: security of processing (Art. 32); notification of a personal data breach to the supervisory authority (Art. 33) and communication to data subjects (Art. 34); data protection impact assessments (Art. 35); and prior consultation with the supervisory authority (Art. 36).
Personal data breach. Findrix will notify you without undue delay, and in any event no later than 72 hours after Findrix confirms a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for more information; we will provide further details as they become available. Notification is not an acknowledgement of fault or liability.
8. Audits and information
Findrix will make available to you the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, primarily through its documentation, security overview, and any third-party audit reports or certifications it holds. Where that information is not sufficient to demonstrate compliance, Findrix will allow for and contribute to a reasonable audit, including inspections, conducted by you or an independent auditor you mandate, subject to reasonable notice, confidentiality obligations, no more than once per year (unless required by a supervisory authority or following a breach), during business hours, and in a manner that does not disrupt the Service or compromise other customers' data.
9. Deletion or return of data
On termination or expiry of the Agreement, and at your choice, Findrix will delete or return all Customer Personal Data, and delete existing copies, unless the law requires it to be stored. For a transitional period after termination you may export Customer Content from the Service as described in the Agreement; after that period Findrix deletes or de-identifies Customer Personal Data on the schedule in the Privacy Policy. Residual copies in routine backups are deleted on their normal rolling cycle and remain protected by this DPA until then.
10. International transfers
Customer Personal Data is stored primarily in the European Union. Where Findrix or a sub-processor processes Customer Personal Data outside the EEA, the UK, or Switzerland, the transfer is made under an appropriate safeguard, and the parties agree that the following apply as relevant:
- The European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor), which are hereby incorporated into this DPA by reference and completed by the information in the Annexes, with the docking clause and the option under Clause 17 for the law of Ireland and Clause 18 for the courts of Ireland, unless otherwise required;
- for transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs;
- for transfers subject to the Swiss FADP, the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner; and
- the EU-US Data Privacy Framework (and its UK extension and Swiss-US framework) where the recipient is certified.
Where there is a conflict between the SCCs and this DPA, the SCCs prevail for the transfers they govern. You can request details of the safeguards from dpo@findrix.ai.
11. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the limitations and exclusions of liability in the Terms of Service, and any reference in those Terms to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits any liability that cannot be limited under applicable Data Protection Law, including a data subject's rights.
12. Duration and changes
This DPA takes effect when it is incorporated into the Agreement and continues for as long as Findrix processes Customer Personal Data on your behalf. We may update this DPA to reflect changes in law, guidance, or our practices; for material changes we will give reasonable notice, and changes will not reduce the level of protection for Customer Personal Data.
Annex I — Description of the processing
- Data exporter / controller: the Customer identified in the Agreement.
- Data importer / processor: Findrix Corp., a Delaware corporation (registered agent for service of process: Corporate Consulting Ltd., 605 Geddes Street, Wilmington, Delaware 19805, USA), and its authorized sub-processors.
- Categories of data subjects: the Customer's authorized users; and individuals whose personal data appears in the Customer's websites, content, or connected platforms that the Customer directs the Service to process.
- Categories of personal data: account and contact details of authorized users (name, email, organization, role); identifiers and content contained in the URLs, domains, brand and topic information, prompts, and site content the Customer submits or connects; and technical data generated in the course of providing the Service (logs, configurations, and deployment metadata).
- Special categories of data: not intended or required. The Customer must not submit special-category data, and the Acceptable Use Policy prohibits it (see Prohibited data).
- Frequency of processing: continuous, for the term of the Agreement.
- Nature and purpose: as described in Section 2.
- Retention: as described in Section 9 and the per-data-class schedule in the Privacy Policy.
- Sub-processors: as listed on the sub-processor page.
Annex II — Technical and organizational measures
- Encryption of data in transit (TLS) and at rest (AES-256, provider-managed);
- Role-based access control on a least-privilege basis, with authentication for administrative access;
- An audit log of administrative and security-relevant actions;
- Scoped, short-lived credentials for site deployments — no broad, long-lived credentials stored;
- SSRF protection with address validation on all outbound fetches;
- Rate limiting, abuse detection, and bot mitigation;
- Data hosted primarily in the EU with reputable infrastructure providers;
- Backups with a defined rolling retention and restoration procedures;
- Secure software-development, code-review, and change-management practices; and
- Vendor due diligence and contractual data-protection terms for sub-processors.
Contact
To request a countersigned copy of this DPA, or for any question about it, contact dpo@findrix.ai. This DPA applies on its terms once incorporated into the Agreement, whether or not it is separately signed.
