1. Legal
  2. Data Processing Addendum

Data Processing Addendum

Effective date:
August 30, 2026
Last updated:
September 30, 2026

This Data Processing Addendum (this “DPA”) supplements the Platform Agreement by and between Flux Cap. Corporation, a Delaware corporation (“Provider”) and the customer identified in the applicable Order Form (“Customer”), and governs Provider’s Processing of Personal Data on Customer’s behalf in connection with the Services. This DPA is incorporated into and forms part of the Platform Agreement. In the event of any conflict between this DPA and the Platform Agreement with respect to the Processing of Personal Data or Customer’s rights and obligations as Controller, this DPA shall control. Capitalized terms used but not defined herein have the meanings given to them in the Platform Agreement.

1.SCOPE AND APPLICABILITY

1.1Scope. This DPA applies wherever Provider Processes Personal Data on Customer’s behalf in connection with the Services, including Platform License Services and Managed Services described in the applicable Order Form. This DPA sets forth the rights and obligations of the parties with respect to such Processing and supplements, but does not replace, the data security obligations set forth in the Security Addendum.

1.2Anonymized and Aggregated Data. This DPA does not apply to anonymized, de-identified, or aggregated data from which no individual can reasonably be identified, provided that Provider’s anonymization or de-identification process satisfies applicable Data Protection Laws and Provider maintains reasonable documentation of that process. Provider shall not attempt to re-identify any de-identified data provided by Customer, except for the sole purpose of determining whether de-identification processes comply with applicable Data Protection Laws.

1.3Updates. Provider may update this DPA from time to time during an active Order Form term only to reflect changes in applicable Data Protection Laws or Provider’s data processing practices, and no update shall materially reduce Customer’s or Data Subjects’ protections without Customer’s prior written consent.

2.DEFINITIONS

As used in this DPA, the following terms have the meanings set forth below:

2.1“Account Information” means Personal Data that relates to Provider’s relationship with Customer, including the names or contact information of individuals, login credentials of individuals authorized to use the Services, and information used to handle administrative matters including billing and technical or product support. For the sake of clarity, Account Information does not include Customer Data or Content.

2.2“CCPA” means the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020 (Proposition 24), and as implemented by regulations issued by the California Privacy Protection Agency.

2.3“Data Protection Laws” means all applicable U.S. state and federal laws and regulations governing the Processing of Personal Data, as in force and as amended from time to time, including the CCPA, and any implementing legislation, regulations, or binding guidance issued by a competent Supervisory Authority thereunder.

2.4“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Provider on Customer's behalf.

2.5“Sub-processor” means any Processor engaged by Provider to Process Personal Data on behalf of Customer, including Provider’s affiliates where they act in that capacity.

2.6“Supervisory Authority” means an independent public authority responsible for monitoring the application of Data Protection Laws.

2.7“Usage Personal Data” means Personal Data included in Usage Data (as defined in the Platform Agreement).

2.8The terms “Personal Data”, “Data Subject”, “Controller”, “Processor”, “Process” and “Processing” have the meanings given under applicable Data Protection Laws.

3.DATA PROCESSING ROLES

3.1Customer as Controller; Provider as Processer. Customer is the Controller of Personal Data uploaded or otherwise provided to Provider in connection with the Services, except where Customer acts as Processor for a third-party Controller, in which case Customer represents that it has all necessary authorizations to appoint Provider as Sub-processor. Provider acts as Processor or Sub-processor, as applicable, and will Process Personal Data only on Customer’s documented instructions, including this DPA, the Platform Agreement, and applicable Order Forms, unless required by law.

3.2Instructions. Provider will promptly notify Customer if Provider reasonably believes an instruction violates applicable Data Protection Laws. Provider may suspend the disputed instruction pending Customer’s written confirmation, clarification, or withdrawal. Provider’s notification under this Section shall not constitute legal advice, and Customer is responsible for ensuring that its instructions comply with Data Protection Laws.

3.3Managed Services. For Managed Services, Provider’s Legal Engineers shall Process Personal Data at the direction of Counsel or other authorized persons or roles as documented in the applicable Order Form.

3.4Confidentiality. All Provider personnel authorized to Process Personal Data are subject to binding confidentiality obligations and may Process Personal Data only as necessary for their assigned functions.

3.5Customer Obligations. Customer shall not provide Personal Data to Provider except through the agreed mechanisms. Customer shall not include Personal Data in technical support tickets, emails, or other communications outside the Platform.

4.PROCESSING PURPOSES AND RESTRICTIONS

4.1Purpose. Provider shall Process Personal Data only as necessary to perform the Services, as described in the Platform Agreement and the applicable Order Form, and in accordance with Customer’s instructions.

4.2Customer Compliance. Customer shall not use the Platform to process, store, or transmit Personal Data in a manner that violates any applicable Data Protection Laws or this DPA. Customer is solely responsible for ensuring that it has obtained all necessary consents, authorizations, and lawful bases required under applicable Data Protection Laws for the processing of Personal Data through the Platform.

4.3Independent Controller. Where Provider Processes Account Information or Usage Personal Data for account administration, billing, security, support, internal reporting, or product strategy, Provider acts as an independent Controller and will Process such data in accordance with applicable Data Protection Laws and the Privacy Policy.

4.4Disclosure Restrictions. Provider shall not disclose Personal Data to any third party without Customer’s prior written consent, except: (a) to Sub-processors in accordance with Section 6; (b) as required by applicable law or binding legal process, in which case Provider shall promptly notify Customer to the extent permitted by law; or (c) where necessary to prevent imminent harm to persons or property and the exigency of the circumstances prevents prior Customer notification.

4.5No Cross-Context Behavioral Advertising. Provider shall not use Personal Data to serve targeted advertising to individuals based on their Personal Data obtained from Customer, nor shall Provider share Personal Data with any third party for the purpose of cross-context behavioral advertising, as those terms are defined under the CCPA and comparable state privacy laws.

4.6No Commingling. Provider shall not combine Personal Data provided by Customer with Personal Data received from or on behalf of a third party, or collected from Provider’s own interactions with individuals, except as permitted by applicable Data Protection Laws or as directed by Customer.

4.7CCPA Service Provider Limitation. To the extent applicable under the CCPA, Provider shall Process Personal Information solely for the business purpose of providing the Services to Customer as a “service provider” within the meaning of Cal. Civ. Code § 1798.140(ag), and for no other commercial purpose. Provider shall not retain, use, or disclose Personal Information outside the direct business relationship with Customer, except as expressly permitted under CCPA service provider provisions (including using Personal Information for the service provider's own internal use to build or improve the quality of its services, provided that no data is disclosed to a third party and no Personal Information is used in a manner prohibited by the CCPA).

5.DATA SECURITY, AI AND DATA PROTECTION

5.1Technical and Organizational Measures. Provider shall implement and maintain appropriate technical and organizational security measures designed to protect Personal Data against accidental or unlawful loss, alteration, or unauthorized access, more fully described in the Security Addendum, which is incorporated into this DPA by reference. In the event of a conflict between this Section and the Security Addendum with respect to Provider’s technical security obligations, the Security Addendum shall control.

5.2AI Processing. Provider’s commitments regarding the use of Customer Data in connection with AI model training are set forth in the Platform Agreement.

5.3DPIA. Where Customer is required under applicable Data Protection Laws to conduct a Data Protection Impact Assessment (“DPIA”) in connection with Customer’s use of the Services, Provider shall provide reasonable assistance to Customer in conducting such assessment.

6.SUB-PROCESSOR MANAGEMENT

6.1General Authorization. Customer provides Provider with general written authorization to engage Sub-processors to assist in the delivery of the Services, subject to the requirements of this Section. The current list of Sub-processors engaged by Provider to Process Personal Data on Customer’s behalf is maintained on Provider’s website.

6.2New Sub-processors. Provider shall notify Customer at least thirty (30) days prior to authorizing any new Sub-processor to Process Personal Data or materially changing an existing Sub-processor’s Processing scope. If Customer subscribes to receive notifications, Customer may, within fifteen (15) days of receiving such notice, reasonably object to Provider’s use of the new Sub-processor on reasonable grounds relating to the protection of Personal Data. In such case, Provider shall have the right to cure the objection through one of the following options: (i) Provider will offer an alternative to provide its Services without such Sub-processor; (ii) Provider will take the corrective steps requested by Customer and proceed to use the Sub-processor; (iii) Provider may cease to provide, or Customer may agree not to use, the particular aspect of the Services that would involve the use of such Sub-processor; or (iv) Customer may cease providing Personal Data to Provider for Processing. If none of the above options are commercially feasible, in Provider’s reasonable judgment, and the objection has not been resolved to the satisfaction of the parties within thirty (30) days, either party may terminate the affected Services for cause and Customer will be refunded any prepaid but unused fees for the post-termination period. Other than accepting such cure as may be offered by Provider, such termination right is Customer’s sole and exclusive remedy if Customer objects to any new Sub-processor.

6.3Sub-processor Obligations. Provider shall enter into contractual commitments with each Sub-processor binding them to data protection obligations that are materially equivalent to, and no less protective than, those imposed on Provider under this DPA. Provider will remain liable to Customer for the performance of each Sub-processor to the extent the Sub-processor fails to fulfill its data protection obligations under the applicable data processing agreement with Provider with regard to Personal Data, subject to the limitation of liability provisions of the Platform Agreement.

7.DATA SUBJECT RIGHTS

7.1Assistance. Provider shall provide Customer with commercially reasonable assistance in responding to Data Subject requests and consumer rights requests under applicable Data Protection Laws. If Provider receives a request directly, Provider will notify Customer and, unless Customer authorizes otherwise, not respond substantively except to direct the requester to Customer.

7.2Costs. Provider shall provide ordinary-course Data Subject request assistance at no additional charge, but may charge reasonable, documented incremental costs for extraordinary requests requiring disproportionate technical effort or resources, provided that Provider provides an advance cost estimate approved by Customer in writing.

8.DATA RETENTION AND DELETION

8.1Deletion and Return. Upon termination or expiration of the Platform Agreement or any applicable Order Form or Customer’s written request, Provider shall, at Customer’s election: (a) securely delete or destroy all Personal Data Processed on Customer’s behalf; or (b) return all such Personal Data to Customer within thirty (30) days of Customer’s election. During the Term, Provider will make available functionality or commercially reasonable assistance enabling Customer to access, export, and delete Personal Data in a manner consistent with the functionality of the Services.

8.2Legal Holds and Backup. Provider may retain Personal Data to the extent required by law, legal hold, regulatory investigation, Provider’s legitimate compliance or legal defense purposes, or Provider’s standard bona fide backup and disaster-recovery procedures. Any Personal Data so retained will remain subject to this DPA, be Processed only for the applicable retention purpose, and be deleted from routine operational backups in accordance with Provider’s standard backup rotation schedule unless longer retention is legally required.

8.3Active-Term Retention. During the Term, Provider shall retain Customer Data only for as long as necessary to provide the Services in accordance with the Platform Agreement and the applicable Order Form.

8.4Post-Termination Deletion. Upon termination or expiration of the Platform Agreement or any applicable Order Form, Provider shall, within thirty (30) days, make Customer Data available for Customer's export or download and, thereafter, shall securely delete Customer Data unless Provider is required by law to retain such data.

8.5Backup Retention. Customer Data residing in Provider's automated backup or disaster-recovery systems at the time of deletion from active production systems shall be deleted in accordance with Provider's standard backup rotation schedule. Provider shall not affirmatively access, restore, or reconstitute any backup or disaster-recovery system for the purpose of accessing Customer Data after deletion from active systems has been completed.

8.6Legal Holds and Retention Exceptions. Notwithstanding the foregoing, Provider may retain Customer Data to the extent and for the duration required by (a) applicable law, regulation, or binding governmental order; (b) a litigation hold or legal-preservation obligation applicable to Provider; (c) Provider's legitimate compliance, audit, or legal-defense purposes; or (d) an executed Business Associate Addendum with respect to PHI. Any Customer Data retained under this Section shall remain subject to the confidentiality, security, and use restrictions of the Platform Agreement, this DPA, and the Security Addendum, and shall be Processed only for the applicable retention purpose.

8.7Secure Deletion Standard. Deletion of Customer Data under this Section shall be performed using methods designed to render the data permanently unrecoverable, consistent with industry-standard practices for secure data destruction. Provider shall securely destroy encryption keys associated with deleted Customer Data in accordance with the Security Addendum.

9.THIRD-PARTY REPORTS

9.1Third-Party Report. Upon Customer’s reasonable request, Provider will provide Customer with a copy of its most recent SOC 2 Type II audit report, ISO 27001 certificate, and, where applicable, surveillance audit report, or an equivalent independent report covering the relevant data protection and security controls.

9.2Confidentiality. Any non-public information obtained by Customer in connection with such reports shall be treated as Provider’s Confidential Information under the Platform Agreement. Customer shall not disclose audit findings to any third party without Provider’s prior written consent, except as required by applicable law.

10.DATA BREACH NOTIFICATION

10.1Provider Notification. Provider shall notify Customer of a Personal Data Breach in accordance with the timeframe and requirements set out in the Security Addendum. Provider shall provide Customer with information about the Personal Data Breach required by applicable Data Protection Laws, including the nature of the breach, its likely consequences, mitigation measures taken or proposed, and a contact point for Provider. Provider shall supplement preliminary notifications with additional information as it becomes available. Any such notifications or responses do not constitute an admission by Provider of fault or liability with respect to the breach.

10.2Mitigation. Provider shall take reasonable steps to mitigate, to the extent practicable, harmful effects known to Provider resulting from unauthorized Processing, use, or disclosure of Personal Data.

10.3Customer Notification. Customer remains solely responsible for determining and complying with its own notification obligations under applicable law. Provider shall cooperate with Customer in connection with Customer’s assessment of and compliance with its obligations.

11.PRIVACY LAW COMPLIANCE

11.1Compliance. To the extent applicable, Provider will comply with its processor, service-provider, and contractor obligations under the Data Protection Laws, including obligations not to sell or share Personal Information, not to Process Personal Data outside the permitted business purposes and direct business relationship except as legally permitted, to assist Customer with consumer rights requests, and to Process sensitive Personal Data only on Customer’s documented instructions. Provider will not process, store, or transmit information in a manner that violates any applicable Data Protection Laws. For the avoidance of doubt, “selling” Personal Data includes disclosing Personal Data to a third party for monetary or other valuable consideration in a manner that constitutes a “sale” under applicable law.

11.2DPAs under State Law. This DPA together with the Platform Agreement constitutes the written contract between Customer (as controller or business) and Provider (as processor or service provider) required by applicable U.S. State Privacy Laws and satisfies the processor/service-provider agreement requirements of such U.S. State Privacy Laws with respect to Personal Data Processed on Customer’s behalf by Provider.

11.3Heightened Sensitivity. If Customer uses the Services to Process biometric, precise geolocation, health, children’s, or other sensitive Personal Data, Customer is responsible for providing notices, obtaining consents, satisfying any heightened requirements applicable to Customer’s use of the Services, and providing appropriate instructions to Provider.

11.4Future Regulations. If new AI-specific laws or regulations materially affect the Services subject to this DPA, the parties will review and negotiate revisions to this DPA in good faith. If the Services become infeasible in compliance with such new laws or regulations, either party may terminate on written notice, without relieving the pre-termination obligations set forth in the Platform Agreement, this DPA, and the other applicable schedules and addenda incorporated therein.

12.GENERAL

12.1Precedence. To the extent of any conflict between this DPA and the Platform Agreement (including its schedules and exhibits, other than the Security Addendum) with respect to the Processing of Personal Data, the protection of Data Subjects’ rights, or Customer's obligations as Controller, this DPA shall control. The Security Addendum shall control over this DPA with respect to technical security measures where both instruments address the same obligation. If an executed Business Associate Addendum applies, it shall control solely with respect to PHI and HIPAA-required protections.

12.2Amendment. No amendment to this DPA shall be effective unless in writing and signed by authorized representatives of both parties, except as provided in Section 1.3.

12.3Governing Law. This DPA is governed in accordance with the law specified in the Platform Agreement, except where applicable Data Protection Laws otherwise require.

12.4Liability. Liability arising under this DPA is subject to the limitation of liability provisions set forth in the Platform Agreement or applicable Order Form, except to the extent prohibited by Data Protection Laws. For the avoidance of doubt, claims arising from a Personal Data Breach caused by Provider’s breach of its obligations under this DPA or the Security Addendum are subject to the Data Breach Cap as defined in the Platform Agreement, rather than the general Liability Cap.

12.5Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain effective and the invalid provision shall be modified to the minimum extent necessary to preserve its intent.

12.6Signatures. This DPA may be executed in counterparts, each of which shall constitute an original and all of which, taken together, constitute the same instrument. Electronic signatures shall be deemed valid and binding to the same extent as originals.

12.7Entire Agreement on Data Processing. This DPA, together with the Platform Agreement (including the Security Addendum and any applicable Order Forms), constitutes the entire agreement between the parties with respect to the Processing of Personal Data by Provider on Customer’s behalf, and supersedes all prior and contemporaneous agreements, understandings, negotiations, representations, and warranties of any kind relating to such Processing. If an executed Business Associate Addendum applies, the Business Associate Addendum controls over this DPA solely with respect to PHI and HIPAA-required protections.

© 2026 FluxCap. All rights reserved.