RECEIVERX ← Back to ReceiverX

Legal

Data Processing Addendum

Effective Date: July 7, 2026 Last Updated: July 7, 2026

This Data Processing Addendum ("DPA") is entered into between ReceiverX LLC, a Texas limited liability company ("ReceiverX," "we," "Processor"), and the customer that has accepted our Terms of Service ("Customer," "you," "Controller"). It forms part of, and is governed by, the Terms of Service. This DPA reflects the parties' agreement regarding the Processing of Personal Data in connection with the Service.

If you require a counter-signed copy for your records, email legal@receiver-x.com.


1. Definitions

Capitalized terms not defined here have the meaning given in the Terms of Service or in the applicable Data Protection Law.

2. Roles and Scope

2.1 Roles. With respect to Personal Data Processed under the Service:

2.2 Subject matter and duration. The subject matter of Processing is the operation of the Service. The duration is the term of the Terms of Service plus any post-termination period required to return or delete Personal Data under Section 9.

2.3 Nature and purpose. Hosting, transmitting, displaying, and Processing Personal Data necessary to provide the Service, including AI-assisted analysis of images, report storage and rendering, magic-link delivery, authentication, security, and support. Billing and payment processing for website purchases are conducted by Paddle, our merchant of record, as an independent controller (with ReceiverX acting as an independent Controller for the limited billing records we retain), and are outside the processor scope of this DPA, except to the extent we link a Customer-supplied identifier to a Tenant-scoped record.

2.4 Categories of Data Subjects. Customer's authorized users; recipients of inspection reports; individuals depicted or named in Customer Content.

2.5 Categories of Personal Data. Identifiers (name, email, account ID, device ID, IP address, user-agent); authentication credentials (hashed); inspection-report content (which may include images, locations, and operational metadata); recipient access events.

2.6 Special-category / Sensitive Data. Customer should not submit special-category data under GDPR Art. 9 unless and until the parties agree on additional safeguards in writing. Customer is responsible for compliance with any sector-specific law (e.g., HIPAA) — the Service is not designed for protected health information unless the parties separately agree.

3. Customer Instructions and Compliance

3.1 Documented instructions. ReceiverX will Process Personal Data only on Customer's documented instructions, including those set out in the Terms of Service, this DPA, the in-product configuration Customer maintains (e.g., retention, sharing, location-grouping policies), and any other written instructions Customer provides that we accept.

3.2 Conflicts with law. If we believe an instruction infringes Data Protection Law, we will notify Customer (unless prohibited by law) and may suspend Processing under that instruction.

3.3 Customer responsibilities. Customer represents and warrants that (a) it has all necessary rights, consents, and lawful bases to provide Personal Data to us for Processing; (b) its instructions are lawful; (c) it has provided required notices to Data Subjects (including under GDPR Articles 13–14); and (d) it will not direct us to Process Personal Data in a manner that violates Data Protection Law.

3.4 Legal-compulsion notice. We will not Process Personal Data outside Customer's documented instructions except where required by Union or Member-State law (or other applicable law) to which we are subject; in that case, we will inform Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.

4. Confidentiality

We will ensure that personnel authorized to Process Personal Data are bound by appropriate written confidentiality obligations and have received appropriate training. Access is granted on a need-to-know basis under least-privilege principles.

5. Security (Article 32 / Technical and Organizational Measures)

5.1 We will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risk to Data Subjects. The current measures are described in Schedule 2 (Technical and Organizational Measures).

5.2 We may update our security measures provided they remain at least as protective as those described in Schedule 2.

6. Sub-processors

6.1 Authorization. Customer provides general authorization for us to engage Sub-processors to Process Personal Data on its behalf. The current list of Sub-processors is published at /legal/sub-processors.

6.2 Flow-down. Before engaging a Sub-processor, we will impose data-protection obligations on the Sub-processor that are no less protective than those in this DPA, including obligations regarding security, confidentiality, and breach notification.

6.3 Notice and objection. We will notify Customer of any new or replacement Sub-processor at least 30 days in advance by updating the sub-processor page and by sending email notice, by default, to all of Customer's Tenant administrative and legal contacts of record (Customer may register additional notification addresses with legal@receiver-x.com). Customer may object on reasonable, documented data-protection grounds within that period. We will work in good faith to provide an alternative; if we cannot, Customer may terminate the affected portion of the Service for material cause and receive a refund of prepaid, unused fees for the unused portion.

6.4 Emergency replacement. Where required to maintain security or continuity (for example, a Sub-processor breach or insolvency), we may engage a replacement on shorter notice and will inform Customer as soon as reasonably practicable.

6.5 Liability. As required by GDPR Article 28(4), we remain fully liable to Customer for the performance of each Sub-processor's data-protection obligations under this DPA. The aggregate monetary liability cap in the Terms of Service applies to claims arising under this Section, except where applicable Data Protection Law prohibits such limitation.

7. Data Subject Rights

7.1 Assistance. Taking into account the nature of the Processing, we will assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfil Customer's obligation to respond to Data Subject requests under Data Protection Law.

7.2 Direct requests. If we receive a Data Subject request directly that relates to Customer's Personal Data, we will, without undue delay, refer the Data Subject to Customer and notify Customer (unless prohibited by law).

7.3 Self-service tools. Customer can use the in-product administration tools to access, correct, export, and delete Personal Data without our involvement for many requests.

8. Security Incident Notification

8.1 We will notify Customer of a Security Incident affecting Customer's Personal Data without undue delay after becoming aware of it, and in any event in a manner that allows Customer to comply with its own notification obligations under Data Protection Law (and, where the GDPR applies, no later than is reasonably necessary to meet Article 33's 72-hour requirement on Customer where applicable).

8.2 The notification will include, to the extent then known: the nature of the incident, categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate harm.

8.3 We will cooperate with Customer's reasonable requests for information needed to fulfil Customer's notification obligations to authorities and affected individuals. Our notification of an incident is not an acknowledgment of fault or liability.

9. Return and Deletion

9.1 On termination or expiry of the Service, Customer may instruct us, in writing during the export window, to either return or delete the Personal Data. If Customer does not provide an instruction, we will delete the Personal Data after the export window in accordance with Section 9.3.

9.2 During the export window described in our Terms of Service, Customer may use the in-product tools to export Personal Data. On request to legal@receiver-x.com during that window, we will provide reasonable assistance with bulk export at our then-standard rates.

9.3 After the export window ends (and absent a written return instruction under Section 9.1), we will delete Personal Data from active systems within 30 days and from backups within 90 days, except to the extent we are required by applicable law to retain it (in which case we will continue to protect it under this DPA). On request, we will certify deletion in writing.

10. Data Protection Impact Assessments

We will, taking into account the nature of the Processing and the information available to us, provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities required under GDPR Articles 35–36.

11. Audits

11.1 Audit reports. We will, on Customer's reasonable request and no more than once per year (except after a Security Incident or where required by a regulator), make available to Customer (a) summary reports of independent third-party audits and certifications we have obtained (where available), and (b) responses to a reasonable security questionnaire.

11.2 On-site audits. Where the materials in Section 11.1 are insufficient to demonstrate compliance, Customer (or a mutually agreed independent third-party auditor under NDA) may conduct an on-site audit at Customer's expense, on at least 30 business days' written notice, during normal business hours, in a manner that does not unreasonably disrupt operations or breach the confidentiality or security of other customers.

12. International Data Transfers

12.1 Mechanism. Where ReceiverX Processes Personal Data of Data Subjects in the EEA, the UK, or Switzerland, the parties agree that the SCCs are incorporated into and form part of this DPA, with the modules and clauses populated as set out in Schedule 3 (International Transfers).

12.2 UK transfers. Transfers from the UK are governed by the UK Addendum, populated as set out in Schedule 3.

12.3 Swiss transfers. Transfers from Switzerland are governed by the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner.

12.4 Order of precedence. In the event of a conflict, the SCCs and the UK Addendum prevail over conflicting terms in this DPA solely to the extent necessary to provide adequate protection.

13. CCPA / U.S. State Law

13.1 Service-Provider role. With respect to Personal Information of California consumers, ReceiverX is a "service provider" (and an analogous "processor" under other U.S. state laws) acting on Customer's behalf as a "business" / "controller." With respect to Personal Information of consumers in Colorado, Connecticut, Virginia, Texas, Oregon, and other comparable U.S. state jurisdictions, ReceiverX is a "processor" acting on Customer's behalf.

13.2 Specific business purposes. Personal Information is disclosed to ReceiverX for the limited and specified business purposes set out in Schedule 1 and the Terms of Service: hosting and operating the Service, AI-assisted analysis at Customer's request, report rendering and delivery, authentication, security and fraud prevention, and support. (Billing and payment processing are handled outside processor scope — see §2.3.) We will Process Personal Information solely for those purposes and as necessary to comply with applicable law.

13.3 Restrictions. We will not (a) sell or share Personal Information (as those terms are defined under the CCPA); (b) retain, use, or disclose Personal Information for any purpose other than the specific business purposes described in this DPA, or for any commercial purpose other than the business purposes specified, including in the servicing of a different business; (c) retain, use, or disclose Personal Information outside the direct business relationship between us and Customer; or (d) combine Personal Information received from Customer with Personal Information received from or on behalf of any other person, or collected from our own interaction with the consumer, except as expressly permitted by Cal. Civ. Code §1798.140(ag)(1) and CCPA Regulations §7051.

13.4 Same level of privacy protection. We will provide the same level of privacy protection to Personal Information as is required by the CCPA (and analogous U.S. state laws) of "businesses" / "controllers."

13.5 Compliance assistance. We will assist Customer in responding to verifiable consumer requests to know, delete, correct, opt out of sale/sharing, opt out of targeted advertising, opt out of profiling, and limit the use of sensitive Personal Information, taking into account the nature of Processing and the information available to us.

13.6 Right to take steps and audit. Customer has the right, on reasonable notice, to take reasonable and appropriate steps to ensure that we Process Personal Information in a manner consistent with Customer's CCPA obligations, and to stop and remediate any unauthorized use of Personal Information. The audit mechanisms in Section 11 satisfy this right.

13.7 Cybersecurity and risk-assessment cooperation. We will provide reasonable assistance to Customer with cybersecurity audits and data-protection assessments required by U.S. state law, including by responding to security questionnaires and providing the information described in Section 11.

13.8 Notice on inability to comply. We will notify Customer if we determine we can no longer meet our service-provider/processor obligations and, on reasonable notice, will permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.

13.9 Subcontracting. Our engagement of Sub-processors complies with the CCPA's requirements for service-provider subcontracting (Cal. Civ. Code §1798.140(ag)(2)) and analogous U.S. state laws.

14. Liability

The liability of each party arising under or in connection with this DPA, including the SCCs, is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits a Data Subject's rights under the SCCs or any non-waivable right under Data Protection Law.

15. General

15.1 Order of precedence. In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to Processing of Personal Data.

15.2 Changes. We may update this DPA from time to time as required by changes in Data Protection Law or our operational practices, provided no update will materially diminish the protection of Personal Data. Material changes will be notified per the Terms of Service.

15.3 Survival. Sections that by their nature should survive (including Sections 9–13) will survive termination.


Schedule 1 — Description of Processing

Item Detail
Subject matter Processing necessary to provide the Service
Duration Term of the Terms of Service + post-termination return/deletion period
Nature and purpose Hosting, AI-assisted image analysis, report rendering and delivery, authentication, security, support (billing/payment processing is handled outside processor scope — see §2.3)
Categories of Data Subjects Customer's users; report recipients; individuals depicted or named in Customer Content
Categories of Personal Data Identifiers (name, email, IP, UA, device ID); hashed credentials; report content (images, captions, locations); recipient access events
Sensitive data Not intended; do not submit unless separately agreed in writing
Frequency Continuous, on Customer's instruction

Schedule 2 — Technical and Organizational Measures (Article 32)

We maintain measures appropriate to the risk, including the following (current as of the Effective Date; we may update them provided protection is not diminished):

Encryption and key management

Access control

Network and infrastructure

Application security

Logging and monitoring

Backup and recovery

Personnel

Sub-processor management

Physical security


Schedule 3 — International Transfers (SCCs and UK Addendum)

For transfers from the EEA, the parties incorporate the EU Standard Contractual Clauses approved by Commission Decision 2021/914 of 4 June 2021, populated as follows:

For transfers from the UK, the UK Addendum (B.1.0) is incorporated, completed as follows:

For transfers from Switzerland, the SCCs apply with the following adaptations: references to GDPR include the Swiss FADP; the competent authority is the Swiss FDPIC; the governing law is Swiss law to the extent required by the FADP.


ReceiverX LLC — by accepting the Terms of Service or by entering into an order form referencing this DPA, the parties have executed this DPA.