This Data Processing Addendum ("DPA") is entered into between ReceiverX LLC, a Texas limited liability company ("ReceiverX," "we," "Processor"), and the customer that has accepted our Terms of Service ("Customer," "you," "Controller"). It forms part of, and is governed by, the Terms of Service. This DPA reflects the parties' agreement regarding the Processing of Personal Data in connection with the Service.
If you require a counter-signed copy for your records, email legal@receiver-x.com.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service or in the applicable Data Protection Law.
- "Data Protection Law" means all laws relating to the protection of Personal Data applicable to a party's Processing under this DPA, including (as applicable) the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss FADP, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), the Colorado Privacy Act, the Virginia CDPA, the Connecticut CTDPA, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and analogous U.S. state laws.
- "Personal Data" means any information relating to an identified or identifiable natural person Processed by us on Customer's behalf under the Service. This includes "Personal Information" under the CCPA.
- "Processing," "Controller," "Processor," and "Data Subject" have the meanings given in the GDPR (or, for U.S. state laws, the analogous concepts of "business," "service provider," and "consumer").
- "Sub-processor" means a third party engaged by us to Process Personal Data on Customer's behalf.
- "Standard Contractual Clauses" or "SCCs" means the European Commission's Decision 2021/914 of 4 June 2021 (Module 2 controller-to-processor and Module 3 processor-to-processor), as amended.
- "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner's Office.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by us under this DPA.
2. Roles and Scope
2.1 Roles. With respect to Personal Data Processed under the Service:
- Processor relationship. Customer is the Controller and ReceiverX is the Processor in respect of Personal Data that Customer (or its end users) submits to the Service, including Customer Content, recipient email addresses, address-book entries, and inspection-report content.
- Independent-Controller activities. ReceiverX acts as an independent Controller for: account/billing data of Customer's authorized users that Customer's users provide to us directly during sign-up; security, fraud-prevention, and abuse-detection logs (including recipient magic-link access logs to the extent we use them for those purposes); aggregated and de-identified product analytics; and any data we Process to comply with our own legal obligations.
2.2 Subject matter and duration. The subject matter of Processing is the operation of the Service. The duration is the term of the Terms of Service plus any post-termination period required to return or delete Personal Data under Section 9.
2.3 Nature and purpose. Hosting, transmitting, displaying, and Processing Personal Data necessary to provide the Service, including AI-assisted analysis of images, report storage and rendering, magic-link delivery, authentication, security, and support. Billing and payment processing for website purchases are conducted by Paddle, our merchant of record, as an independent controller (with ReceiverX acting as an independent Controller for the limited billing records we retain), and are outside the processor scope of this DPA, except to the extent we link a Customer-supplied identifier to a Tenant-scoped record.
2.4 Categories of Data Subjects. Customer's authorized users; recipients of inspection reports; individuals depicted or named in Customer Content.
2.5 Categories of Personal Data. Identifiers (name, email, account ID, device ID, IP address, user-agent); authentication credentials (hashed); inspection-report content (which may include images, locations, and operational metadata); recipient access events.
2.6 Special-category / Sensitive Data. Customer should not submit special-category data under GDPR Art. 9 unless and until the parties agree on additional safeguards in writing. Customer is responsible for compliance with any sector-specific law (e.g., HIPAA) — the Service is not designed for protected health information unless the parties separately agree.
3. Customer Instructions and Compliance
3.1 Documented instructions. ReceiverX will Process Personal Data only on Customer's documented instructions, including those set out in the Terms of Service, this DPA, the in-product configuration Customer maintains (e.g., retention, sharing, location-grouping policies), and any other written instructions Customer provides that we accept.
3.2 Conflicts with law. If we believe an instruction infringes Data Protection Law, we will notify Customer (unless prohibited by law) and may suspend Processing under that instruction.
3.3 Customer responsibilities. Customer represents and warrants that (a) it has all necessary rights, consents, and lawful bases to provide Personal Data to us for Processing; (b) its instructions are lawful; (c) it has provided required notices to Data Subjects (including under GDPR Articles 13–14); and (d) it will not direct us to Process Personal Data in a manner that violates Data Protection Law.
3.4 Legal-compulsion notice. We will not Process Personal Data outside Customer's documented instructions except where required by Union or Member-State law (or other applicable law) to which we are subject; in that case, we will inform Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
4. Confidentiality
We will ensure that personnel authorized to Process Personal Data are bound by appropriate written confidentiality obligations and have received appropriate training. Access is granted on a need-to-know basis under least-privilege principles.
5. Security (Article 32 / Technical and Organizational Measures)
5.1 We will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risk to Data Subjects. The current measures are described in Schedule 2 (Technical and Organizational Measures).
5.2 We may update our security measures provided they remain at least as protective as those described in Schedule 2.
6. Sub-processors
6.1 Authorization. Customer provides general authorization for us to engage Sub-processors to Process Personal Data on its behalf. The current list of Sub-processors is published at /legal/sub-processors.
6.2 Flow-down. Before engaging a Sub-processor, we will impose data-protection obligations on the Sub-processor that are no less protective than those in this DPA, including obligations regarding security, confidentiality, and breach notification.
6.3 Notice and objection. We will notify Customer of any new or replacement Sub-processor at least 30 days in advance by updating the sub-processor page and by sending email notice, by default, to all of Customer's Tenant administrative and legal contacts of record (Customer may register additional notification addresses with legal@receiver-x.com). Customer may object on reasonable, documented data-protection grounds within that period. We will work in good faith to provide an alternative; if we cannot, Customer may terminate the affected portion of the Service for material cause and receive a refund of prepaid, unused fees for the unused portion.
6.4 Emergency replacement. Where required to maintain security or continuity (for example, a Sub-processor breach or insolvency), we may engage a replacement on shorter notice and will inform Customer as soon as reasonably practicable.
6.5 Liability. As required by GDPR Article 28(4), we remain fully liable to Customer for the performance of each Sub-processor's data-protection obligations under this DPA. The aggregate monetary liability cap in the Terms of Service applies to claims arising under this Section, except where applicable Data Protection Law prohibits such limitation.
7. Data Subject Rights
7.1 Assistance. Taking into account the nature of the Processing, we will assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfil Customer's obligation to respond to Data Subject requests under Data Protection Law.
7.2 Direct requests. If we receive a Data Subject request directly that relates to Customer's Personal Data, we will, without undue delay, refer the Data Subject to Customer and notify Customer (unless prohibited by law).
7.3 Self-service tools. Customer can use the in-product administration tools to access, correct, export, and delete Personal Data without our involvement for many requests.
8. Security Incident Notification
8.1 We will notify Customer of a Security Incident affecting Customer's Personal Data without undue delay after becoming aware of it, and in any event in a manner that allows Customer to comply with its own notification obligations under Data Protection Law (and, where the GDPR applies, no later than is reasonably necessary to meet Article 33's 72-hour requirement on Customer where applicable).
8.2 The notification will include, to the extent then known: the nature of the incident, categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate harm.
8.3 We will cooperate with Customer's reasonable requests for information needed to fulfil Customer's notification obligations to authorities and affected individuals. Our notification of an incident is not an acknowledgment of fault or liability.
9. Return and Deletion
9.1 On termination or expiry of the Service, Customer may instruct us, in writing during the export window, to either return or delete the Personal Data. If Customer does not provide an instruction, we will delete the Personal Data after the export window in accordance with Section 9.3.
9.2 During the export window described in our Terms of Service, Customer may use the in-product tools to export Personal Data. On request to legal@receiver-x.com during that window, we will provide reasonable assistance with bulk export at our then-standard rates.
9.3 After the export window ends (and absent a written return instruction under Section 9.1), we will delete Personal Data from active systems within 30 days and from backups within 90 days, except to the extent we are required by applicable law to retain it (in which case we will continue to protect it under this DPA). On request, we will certify deletion in writing.
10. Data Protection Impact Assessments
We will, taking into account the nature of the Processing and the information available to us, provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities required under GDPR Articles 35–36.
11. Audits
11.1 Audit reports. We will, on Customer's reasonable request and no more than once per year (except after a Security Incident or where required by a regulator), make available to Customer (a) summary reports of independent third-party audits and certifications we have obtained (where available), and (b) responses to a reasonable security questionnaire.
11.2 On-site audits. Where the materials in Section 11.1 are insufficient to demonstrate compliance, Customer (or a mutually agreed independent third-party auditor under NDA) may conduct an on-site audit at Customer's expense, on at least 30 business days' written notice, during normal business hours, in a manner that does not unreasonably disrupt operations or breach the confidentiality or security of other customers.
12. International Data Transfers
12.1 Mechanism. Where ReceiverX Processes Personal Data of Data Subjects in the EEA, the UK, or Switzerland, the parties agree that the SCCs are incorporated into and form part of this DPA, with the modules and clauses populated as set out in Schedule 3 (International Transfers).
12.2 UK transfers. Transfers from the UK are governed by the UK Addendum, populated as set out in Schedule 3.
12.3 Swiss transfers. Transfers from Switzerland are governed by the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner.
12.4 Order of precedence. In the event of a conflict, the SCCs and the UK Addendum prevail over conflicting terms in this DPA solely to the extent necessary to provide adequate protection.
13. CCPA / U.S. State Law
13.1 Service-Provider role. With respect to Personal Information of California consumers, ReceiverX is a "service provider" (and an analogous "processor" under other U.S. state laws) acting on Customer's behalf as a "business" / "controller." With respect to Personal Information of consumers in Colorado, Connecticut, Virginia, Texas, Oregon, and other comparable U.S. state jurisdictions, ReceiverX is a "processor" acting on Customer's behalf.
13.2 Specific business purposes. Personal Information is disclosed to ReceiverX for the limited and specified business purposes set out in Schedule 1 and the Terms of Service: hosting and operating the Service, AI-assisted analysis at Customer's request, report rendering and delivery, authentication, security and fraud prevention, and support. (Billing and payment processing are handled outside processor scope — see §2.3.) We will Process Personal Information solely for those purposes and as necessary to comply with applicable law.
13.3 Restrictions. We will not (a) sell or share Personal Information (as those terms are defined under the CCPA); (b) retain, use, or disclose Personal Information for any purpose other than the specific business purposes described in this DPA, or for any commercial purpose other than the business purposes specified, including in the servicing of a different business; (c) retain, use, or disclose Personal Information outside the direct business relationship between us and Customer; or (d) combine Personal Information received from Customer with Personal Information received from or on behalf of any other person, or collected from our own interaction with the consumer, except as expressly permitted by Cal. Civ. Code §1798.140(ag)(1) and CCPA Regulations §7051.
13.4 Same level of privacy protection. We will provide the same level of privacy protection to Personal Information as is required by the CCPA (and analogous U.S. state laws) of "businesses" / "controllers."
13.5 Compliance assistance. We will assist Customer in responding to verifiable consumer requests to know, delete, correct, opt out of sale/sharing, opt out of targeted advertising, opt out of profiling, and limit the use of sensitive Personal Information, taking into account the nature of Processing and the information available to us.
13.6 Right to take steps and audit. Customer has the right, on reasonable notice, to take reasonable and appropriate steps to ensure that we Process Personal Information in a manner consistent with Customer's CCPA obligations, and to stop and remediate any unauthorized use of Personal Information. The audit mechanisms in Section 11 satisfy this right.
13.7 Cybersecurity and risk-assessment cooperation. We will provide reasonable assistance to Customer with cybersecurity audits and data-protection assessments required by U.S. state law, including by responding to security questionnaires and providing the information described in Section 11.
13.8 Notice on inability to comply. We will notify Customer if we determine we can no longer meet our service-provider/processor obligations and, on reasonable notice, will permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.
13.9 Subcontracting. Our engagement of Sub-processors complies with the CCPA's requirements for service-provider subcontracting (Cal. Civ. Code §1798.140(ag)(2)) and analogous U.S. state laws.
14. Liability
The liability of each party arising under or in connection with this DPA, including the SCCs, is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits a Data Subject's rights under the SCCs or any non-waivable right under Data Protection Law.
15. General
15.1 Order of precedence. In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to Processing of Personal Data.
15.2 Changes. We may update this DPA from time to time as required by changes in Data Protection Law or our operational practices, provided no update will materially diminish the protection of Personal Data. Material changes will be notified per the Terms of Service.
15.3 Survival. Sections that by their nature should survive (including Sections 9–13) will survive termination.
Schedule 1 — Description of Processing
| Item | Detail |
|---|---|
| Subject matter | Processing necessary to provide the Service |
| Duration | Term of the Terms of Service + post-termination return/deletion period |
| Nature and purpose | Hosting, AI-assisted image analysis, report rendering and delivery, authentication, security, support (billing/payment processing is handled outside processor scope — see §2.3) |
| Categories of Data Subjects | Customer's users; report recipients; individuals depicted or named in Customer Content |
| Categories of Personal Data | Identifiers (name, email, IP, UA, device ID); hashed credentials; report content (images, captions, locations); recipient access events |
| Sensitive data | Not intended; do not submit unless separately agreed in writing |
| Frequency | Continuous, on Customer's instruction |
Schedule 2 — Technical and Organizational Measures (Article 32)
We maintain measures appropriate to the risk, including the following (current as of the Effective Date; we may update them provided protection is not diminished):
Encryption and key management
- TLS 1.2+ for data in transit.
- AES-256-GCM for sensitive credentials at rest (e.g., TOTP secrets).
- bcrypt password hashing.
- Provider-managed key rotation; no plaintext secrets in source control.
Access control
- MFA required for all personnel with access to production systems.
- Least-privilege role-based access; access reviewed when personnel changes occur and at least annually.
- Production access actions are audit-logged.
Network and infrastructure
- Cloud-provider hardened baselines (Vercel, Neon, Cloudflare, AWS).
- Logically segregated tenant data; tenant-scoped queries.
- Rate limiting and abuse detection (Upstash).
- Dependency vulnerability scanning; secret scanning in CI.
Application security
- Secure SDLC: code review, automated SAST (Semgrep), secret scanning (TruffleHog).
- OWASP-aligned controls; routine dynamic scanning where applicable (OWASP ZAP).
- Threat-model maintained per major component.
Logging and monitoring
- Centralized logging of authentication, administration, and audit events with restricted write access.
- Audit-log retention up to 24 months on the managed-database tier; we are progressively hardening logs against tampering, including immutable export pipelines for high-sensitivity events.
Backup and recovery
- Managed-database point-in-time recovery (Neon).
- Restoration is exercised when functional changes warrant it and at least annually.
Personnel
- Written confidentiality obligations.
- Security awareness applicable to role.
Sub-processor management
- Due-diligence and contractual flow-down (Section 6).
Physical security
- Provided by underlying cloud providers under their certifications (e.g., ISO 27001).
Schedule 3 — International Transfers (SCCs and UK Addendum)
For transfers from the EEA, the parties incorporate the EU Standard Contractual Clauses approved by Commission Decision 2021/914 of 4 June 2021, populated as follows:
- Module: Module 2 (controller-to-processor) where Customer is Controller; Module 3 (processor-to-processor) where Customer acts as Processor for an upstream Controller.
- Clause 7 (Docking): included.
- Clause 9 (Sub-processors): Option 2 — general written authorization with the notice mechanism in Section 6 of this DPA (30 days).
- Clause 11 (Redress): the optional independent dispute resolution body is not opted in.
- Clause 17 (Governing law): the law of Ireland.
- Clause 18 (Forum and jurisdiction): the courts of Ireland.
- Annex I.A (Parties): Customer (data exporter) and ReceiverX LLC (data importer); the data exporter's contact details are those provided by Customer in its account or applicable order form, and the data importer's contact details are info@receiver-x.com / privacy@receiver-x.com / ReceiverX LLC, c/o Texan Registered Agent LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA.
- Annex I.B (Description of transfer): as set out in Schedule 1.
- Annex I.C (Competent supervisory authority): the Irish Data Protection Commission, or such other authority as is competent under Clause 13.
- Annex II (TOMs): as set out in Schedule 2.
- Annex III (Sub-processors): as published at /legal/sub-processors.
For transfers from the UK, the UK Addendum (B.1.0) is incorporated, completed as follows:
- Table 1 (Parties): as in Annex I.A above.
- Table 2 (Approved EU SCCs): the SCCs incorporated above, with the modules and selections noted.
- Table 3 (Annexes): Annexes I, II, III as set out above.
- Table 4 (Termination on changes): neither party.
For transfers from Switzerland, the SCCs apply with the following adaptations: references to GDPR include the Swiss FADP; the competent authority is the Swiss FDPIC; the governing law is Swiss law to the extent required by the FADP.
ReceiverX LLC — by accepting the Terms of Service or by entering into an order form referencing this DPA, the parties have executed this DPA.