Data Processing Agreement

Our data terms for business customers.

Version 1.0 — 17 June 2026

Plain-language summary: When you use FRIENDA to send NDAs containing other people's personal data, you're the controller and FRIENDA is your processor. This DPA sets out how we handle that data on your behalf — security, confidentiality, sub-processors, international transfers, breach notice, and deletion. It's incorporated into our Terms; by accepting the Terms you accept this DPA, and the parties are deemed to have entered into the Standard Contractual Clauses referenced below where they apply. This is a starting template — have it reviewed by your counsel before relying on it for a regulated or high-volume use case.

1. Roles & scope

For personal data within agreements you create and send ("Customer Personal Data"), you are the Controller / Business and FRIENDA is the Processor / Service Provider, processing solely on your documented instructions to provide the service. For data we collect to run your account and the platform, FRIENDA is an independent controller, governed by our Privacy Policy. This DPA covers the former. "Data Protection Laws" includes the EU/UK GDPR, the Swiss FADP, the California CCPA/CPRA, and Japan's APPI, as applicable.

2. Processing instructions

FRIENDA processes Customer Personal Data only to (a) provide, secure, and maintain the service, (b) follow your reasonable documented instructions, and (c) comply with law. We will tell you if an instruction appears to violate Data Protection Laws. We do not sell or share Customer Personal Data, and do not use it for cross-context behavioral advertising or for any purpose outside our direct business relationship with you (CCPA service-provider terms, Cal. Civ. Code § 1798.140).

3. Confidentiality & security

Personnel with access to Customer Personal Data are bound by confidentiality obligations. We maintain technical and organizational measures appropriate to the risk, including: TLS in transit and encryption at rest; HMAC-based, purpose-bound, short-lived access tokens; a tamper-evident audit trail; least-privilege production access; and session revocation. Our current security posture is summarized at ndafriend.com/trust.

4. Sub-processors

You provide general authorization for FRIENDA to engage the sub-processors listed at ndafriend.com/subprocessors. We impose data-protection obligations on each sub-processor no less protective than this DPA and remain responsible for their performance. We give at least 30 days' notice of any new or replacement sub-processor; you may object on reasonable data-protection grounds, and if we can't resolve the objection you may terminate the affected service.

5. Assisting with data-subject rights

Taking into account the nature of the processing, FRIENDA will assist you, by appropriate measures, in responding to data-subject requests (access, rectification, erasure, portability, restriction, objection) — including self-service export and deletion in the app. If a data subject contacts FRIENDA directly about Customer Personal Data, we'll refer them to you where appropriate.

6. Personal-data breaches

FRIENDA will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information you reasonably need to meet your own notification duties (GDPR Art. 33/34's 72-hour clock; APPI Art. 26; and applicable U.S. state breach laws), and will assist your response.

7. International transfers

FRIENDA stores and processes Customer Personal Data in the United States. Where Customer Personal Data of EEA/UK/Swiss data subjects is transferred to the U.S., the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller-to-processor) and, for onward transfers, Module Three (processor-to-processor); the UK International Data Transfer Addendum; and the Swiss amendments — each incorporated by reference and deemed executed on acceptance, together with our infrastructure provider's EU–US Data Privacy Framework certification. For Japan, see the APPI Art. 28 cross-border disclosure in our Privacy Policy.

8. Deletion & return

On termination, or on your request, FRIENDA will delete or return Customer Personal Data, subject to (a) executed agreements retained as the counterparty's legal record and (b) retention required by law or held in routine backups for a limited period, in each case kept confidential and protected by this DPA until deleted.

9. Audits

On reasonable written request (no more than annually, except after a breach or where a supervisory authority requires), FRIENDA will make available the information necessary to demonstrate compliance with this DPA — including, when available, third-party certifications/attestations — and contribute to audits in a manner that doesn't compromise other customers' confidentiality.

10. General

Where this DPA conflicts with the Terms on the subject of data protection, this DPA (and any applicable Standard Contractual Clauses, which take precedence over it) controls. This DPA terminates with the Terms but its obligations survive as to any retained data.

Contact

To request a counter-signed copy, raise a sub-processor objection, or ask a data-protection question — hi@frienda.chat.