Our data terms for business customers.
Version 1.0 — 17 June 2026
1. Roles & scope
For personal data within agreements you create and send ("Customer Personal Data"), you are the Controller / Business and FRIENDA is the Processor / Service Provider, processing solely on your documented instructions to provide the service. For data we collect to run your account and the platform, FRIENDA is an independent controller, governed by our Privacy Policy. This DPA covers the former. "Data Protection Laws" includes the EU/UK GDPR, the Swiss FADP, the California CCPA/CPRA, and Japan's APPI, as applicable.
2. Processing instructions
FRIENDA processes Customer Personal Data only to (a) provide, secure, and maintain the service, (b) follow your reasonable documented instructions, and (c) comply with law. We will tell you if an instruction appears to violate Data Protection Laws. We do not sell or share Customer Personal Data, and do not use it for cross-context behavioral advertising or for any purpose outside our direct business relationship with you (CCPA service-provider terms, Cal. Civ. Code § 1798.140).
3. Confidentiality & security
Personnel with access to Customer Personal Data are bound by confidentiality obligations. We maintain technical and organizational measures appropriate to the risk, including: TLS in transit and encryption at rest; HMAC-based, purpose-bound, short-lived access tokens; a tamper-evident audit trail; least-privilege production access; and session revocation. Our current security posture is summarized at ndafriend.com/trust.
4. Sub-processors
You provide general authorization for FRIENDA to engage the sub-processors listed at ndafriend.com/subprocessors. We impose data-protection obligations on each sub-processor no less protective than this DPA and remain responsible for their performance. We give at least 30 days' notice of any new or replacement sub-processor; you may object on reasonable data-protection grounds, and if we can't resolve the objection you may terminate the affected service.
5. Assisting with data-subject rights
Taking into account the nature of the processing, FRIENDA will assist you, by appropriate measures, in responding to data-subject requests (access, rectification, erasure, portability, restriction, objection) — including self-service export and deletion in the app. If a data subject contacts FRIENDA directly about Customer Personal Data, we'll refer them to you where appropriate.
6. Personal-data breaches
FRIENDA will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information you reasonably need to meet your own notification duties (GDPR Art. 33/34's 72-hour clock; APPI Art. 26; and applicable U.S. state breach laws), and will assist your response.
7. International transfers
FRIENDA stores and processes Customer Personal Data in the United States. Where Customer Personal Data of EEA/UK/Swiss data subjects is transferred to the U.S., the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller-to-processor) and, for onward transfers, Module Three (processor-to-processor); the UK International Data Transfer Addendum; and the Swiss amendments — each incorporated by reference and deemed executed on acceptance, together with our infrastructure provider's EU–US Data Privacy Framework certification. For Japan, see the APPI Art. 28 cross-border disclosure in our Privacy Policy.
8. Deletion & return
On termination, or on your request, FRIENDA will delete or return Customer Personal Data, subject to (a) executed agreements retained as the counterparty's legal record and (b) retention required by law or held in routine backups for a limited period, in each case kept confidential and protected by this DPA until deleted.
9. Audits
On reasonable written request (no more than annually, except after a breach or where a supervisory authority requires), FRIENDA will make available the information necessary to demonstrate compliance with this DPA — including, when available, third-party certifications/attestations — and contribute to audits in a manner that doesn't compromise other customers' confidentiality.
10. General
Where this DPA conflicts with the Terms on the subject of data protection, this DPA (and any applicable Standard Contractual Clauses, which take precedence over it) controls. This DPA terminates with the Terms but its obligations survive as to any retained data.
Contact
To request a counter-signed copy, raise a sub-processor objection, or ask a data-protection question — hi@frienda.chat.