— Legal
Data Processing Addendum
CHECKEDAGENT (BYNARS SEC, S.L.)
Last updated: 13 July 2026
This Data Processing Addendum (“DPA”) governs CHECKEDAGENT’s processing of Customer Data you provide to CHECKEDAGENT through CHECKEDAGENT’s API or any CHECKEDAGENT services for businesses (“Services”) under the terms of the CHECKEDAGENT Terms of Service, Enterprise Agreement, or other agreement between you and CHECKEDAGENT governing your use of the Services (the “Agreement”) and is hereby incorporated into the Agreement. If and to the extent language in this DPA conflicts with the Agreement, the conflicting terms in this DPA shall control.
CHECKEDAGENT and Customer each agree to comply with their respective obligations under applicable data privacy and data protection laws (collectively, “Data Protection Laws”) in connection with the Services. Data Protection Laws may include, depending on the circumstances, Cal. Civ. Code §§ 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 (the California Consumer Privacy Act) (“CCPA”), Colo. Rev. Stat. §§ 6-1-1301 et seq. (the Colorado Privacy Act) (“CPA”), Connecticut’s Data Privacy Act (“CTDPA”), Utah Code Ann. §§ 13-61-101 et seq. (the Utah Consumer Privacy Act) (“UCPA”), VA Code Ann. §§ 59.1-575 et seq. (the Virginia Consumer Data Protection Act) (“VCDPA”) (collectively “U.S. Privacy Laws”), and the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), and applicable subordinate legislation and regulations implementing those laws.
In connection with the Agreement, Customer is the person that determines the purposes and means for which Customer Data (as defined below) is processed (a “Data Controller”), whereas CHECKEDAGENT processes Customer Data in accordance with the Data Controller’s instructions and on behalf of the Data Controller (as a “Data Processor”). “Data Controller” and “Data Processor” are intended to include equivalent concepts under other Data Protection Laws. For purposes of the Agreement and this DPA, “Customer Data” means personal data (or equivalent concepts, as defined by Data Protection Laws) that Customer provides to the Services that CHECKEDAGENT processes on behalf of Customer. CHECKEDAGENT will process Customer Data as your Data Processor to provide or maintain the Services and for the purposes set forth in this DPA, the Agreement and/or in any other applicable agreements between you and CHECKEDAGENT. CHECKEDAGENT acknowledges that you are disclosing personal data for the aforementioned limited and specific purposes.
PROCESSING REQUIREMENTS
As a Data Processor, CHECKEDAGENT agrees to:
- Process Customer Data (i) for the purpose of providing, securing, maintaining and supporting CHECKEDAGENT’s services, including generating outputs, routing requests to selected models or infrastructure, providing insights, reporting, analytics, platform abuse prevention, trust and safety monitoring, debugging, service reliability, and compliance; (ii) to improve CHECKEDAGENT’s services only if and to the extent Customer expressly opts in to such improvement; (iii) in compliance with the instructions received from Customer; and (iv) where the CCPA applies, in a manner that provides no less than the level of privacy protection required by the CCPA.
- With respect to AI-enabled functionality, CHECKEDAGENT may process prompts, inputs, outputs, retrieved context, logs, telemetry, and related technical artifacts as necessary to provide, secure, maintain, and support the Services. Unless Customer expressly opts in or otherwise instructs CHECKEDAGENT in writing, CHECKEDAGENT will not use Customer Data to train foundation models made available to other customers or to the public. CHECKEDAGENT will not intentionally use Customer-specific content to generate outputs for another customer, provided that CHECKEDAGENT may use service metadata, operational logs, abuse signals, and de-identified or aggregated information to operate, secure, and improve the Services in accordance with this DPA and applicable law.
- Promptly inform you in writing if it cannot comply with the requirements of this DPA.
- Not provide you with remuneration in exchange for Customer Data from you. The parties acknowledge and agree that Customer has not “sold” (as such term is defined by the CCPA) Customer Data to CHECKEDAGENT.
- Not “sell” (as such term is defined by U.S. Privacy Laws) or “share” (as such term is defined by the CCPA) personal data.
- Inform you promptly if, in CHECKEDAGENT’s opinion, an instruction from you violates applicable Data Protection Laws.
- Take commercially reasonable steps to require (i) persons employed by it and (ii) other persons engaged to perform on CHECKEDAGENT’s behalf to be subject to a duty of confidentiality with respect to the Personal Data and to comply with the data protection obligations applicable to CHECKEDAGENT under the Agreement and this DPA.
- Engage the subprocessors listed in Exhibit A to this Addendum to process Customer Data (each a “Subprocessor,” and the list at the foregoing URL, the “Subprocessor List”) to help CHECKEDAGENT satisfy its obligations in accordance with this DPA or to delegate all or part of the processing activities to such Subprocessors. Customer hereby consents to the use of such Subprocessors. In the event that CHECKEDAGENT seeks to use additional Subprocessors and update the Subprocessor List, CHECKEDAGENT will provide notice of such additional Subprocessors to you (which may be via email, a posting or notification on an online portal for our services or other reasonable means). In the event that you do not wish to consent to the use of such additional Subprocessor, you may notify CHECKEDAGENT that you do not consent within fifteen (15) days on reasonable grounds relating to the protection of Customer Data by following the instructions set forth in the Subprocessor List or contacting privacy@checkedagent.com. In such case, CHECKEDAGENT shall have the right to cure the objection through one of the following options: (i) CHECKEDAGENT will cancel its plans to use the Subprocessor with regards to processing Customer Data or will offer an alternative to provide its Services or services without such Subprocessor; (ii) CHECKEDAGENT will take the corrective steps requested by you in your objection notice and proceed to use the Subprocessor; (iii) CHECKEDAGENT may cease to provide, or you may agree not to use whether temporarily or permanently, the particular aspect or feature of the CHECKEDAGENT Services or services that would involve the use of such Subprocessor; or (iv) you may cease providing Customer Data to CHECKEDAGENT for processing. If none of the above options are commercially feasible, in CHECKEDAGENT’s reasonable judgment, and the objection(s) have not been resolved to the satisfaction of the parties within thirty (30) days of CHECKEDAGENT’s receipt of your objection notice, then either party may terminate any subscriptions, order forms or usage regarding the Services or CHECKEDAGENT services for cause and in such case, you will be refunded any pre-paid fees for the applicable subscriptions, order forms or usage to the extent they cover periods or terms following the date of such termination. Such termination right is your sole and exclusive remedy if you object to any new Subprocessor. For the avoidance of doubt, Customer may not object to a new Subprocessor, or exercise any related termination right, for reasons unrelated to data protection or information security concerns regarding Customer Data, and such right shall not constitute a general right to terminate the Agreement for convenience. CHECKEDAGENT shall enter into contractual arrangements with each Subprocessor binding them to provide the same level of data protection and information security to that provided for herein. Where a Subprocessor provides model inference, hosting, observability, or other AI-related functionality, CHECKEDAGENT may configure such Subprocessor in accordance with the applicable service configuration, security settings, and Customer instructions.
- Upon request, provide you with CHECKEDAGENT’s privacy and security policies and other such information necessary to demonstrate compliance with the obligations set forth in this DPA and applicable Data Protection Laws.
- Where required by law and upon reasonable notice and appropriate confidentiality agreements, cooperate with assessments, audits, or other steps performed by or on behalf of Customer that are necessary to confirm that CHECKEDAGENT is processing Personal Data in a manner consistent with this DPA. Where permitted by law, CHECKEDAGENT may instead make available to Customer a summary of the results of a third-party audit or certification reports relevant to CHECKEDAGENT’s compliance with this DPA.
- To the extent that CHECKEDAGENT received deidentified data derived from personal data subject to U.S. Privacy Laws from Customer, CHECKEDAGENT shall (i) adopt reasonable measures to prevent such deidentified data from being used to infer information about, or otherwise being linked to, a particular natural person or household; (ii) publicly commit to maintain and use such deidentified data in a deidentified form and to not attempt to re-identify the deidentified data, except that the recipient may attempt to re-identify the data solely for the purpose of determining whether its deidentification processes are compliant with U.S. Privacy Laws; and (iii) before sharing deidentified data with any other party, including Subprocessors, contractually obligate any such recipients to comply with the requirements of this provision.
- Where the personal data is subject to the CCPA, not (i) retain, use, disclose, or otherwise process personal data except as necessary for the business purposes specified in the Agreement or this Addendum; (ii) retain, use, disclose, or otherwise process personal data in any manner outside of the direct business relationship between CHECKEDAGENT and Customer; or (iii) combine any personal data with personal data that CHECKEDAGENT receives from or on behalf of any other third party or collects from CHECKEDAGENT’s own interactions with individuals, provided that CHECKEDAGENT may so combine personal data for a purpose permitted under the CCPA if directed to do so by Customer or as otherwise permitted by the CCPA.
- Where required by law, grant the Data Controller the rights to (i) take reasonable and appropriate steps to ensure that CHECKEDAGENT uses Customer Data in a manner consistent with Data Protection Laws and (ii) stop and remediate unauthorized use of Customer Data.
NOTICE TO CUSTOMER
CHECKEDAGENT will inform you if CHECKEDAGENT becomes aware of:
- Any legally binding request for disclosure of Customer Data by a law enforcement authority, unless CHECKEDAGENT is otherwise forbidden by law to inform you, for example to preserve the confidentiality of an investigation by law enforcement authorities.
- Any notice, inquiry or investigation by an independent public authority established by a member state pursuant to Article 51 of the GDPR (a “Supervisory Authority”) with respect to Customer Data.
- Any complaint or request (in particular, requests for access to, rectification or blocking of Customer Data) received directly from your data subjects. CHECKEDAGENT will not respond to any such request without your prior written authorization.
ASSISTANCE TO CUSTOMER
CHECKEDAGENT will provide reasonable assistance to Customer regarding:
- Any requests from your data subjects in respect of access to or the rectification, erasure, restriction, portability, objection, blocking or deletion of Customer Data that CHECKEDAGENT processes for you. In the event that a data subject sends such a request directly to CHECKEDAGENT, CHECKEDAGENT will promptly send such request to you.
- The investigation of any breach of CHECKEDAGENT’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Data processed by CHECKEDAGENT for you (a “Personal Data Breach”).
- Where appropriate, the preparation of data protection impact assessments with respect to the processing of Customer Data by CHECKEDAGENT and, where necessary, carrying out consultations with any supervisory authority with jurisdiction over such processing.
REQUIRED PROCESSING
- If CHECKEDAGENT is required by Data Protection Laws to process any Customer Data for a reason other than in connection with the Agreement, CHECKEDAGENT will inform you of this requirement in advance of any processing, unless CHECKEDAGENT is legally prohibited from informing you of such processing.
SECURITY
CHECKEDAGENT will:
- Maintain reasonable and appropriate organizational and technical security measures (including with respect to personnel, facilities, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, incident response, encryption, and logical segregation of customer environments and data where applicable) to protect against unauthorized or accidental access, loss, alteration, disclosure or destruction of Customer Data and to protect the rights of the subjects of that Customer Data. CHECKEDAGENT may update the specific measures set out in Exhibit C from time to time, provided that such updates do not materially reduce the overall level of security provided to Customer.
- Take appropriate steps to confirm that CHECKEDAGENT personnel are protecting the security, privacy and confidentiality of Customer Data consistent with the requirements of this DPA.
- Notify you of any Personal Data Breach by CHECKEDAGENT, its Subprocessors, or any other third parties acting on CHECKEDAGENT’s behalf without undue delay after CHECKEDAGENT becomes aware of such Personal Data Breach, and provide additional information in phases as it becomes available.
OBLIGATIONS OF CUSTOMER
- Customer represents, warrants and covenants that it has and shall maintain throughout the term all necessary rights, consents and authorizations to provide the Customer Data to CHECKEDAGENT and to authorize CHECKEDAGENT to use, disclose, retain and otherwise process that Customer Data as contemplated by this DPA, the Agreement and/or other processing instructions provided to CHECKEDAGENT.
- Customer shall comply with all applicable Data Protection Laws.
- Customer shall reasonably cooperate with CHECKEDAGENT to assist CHECKEDAGENT in performing any of its obligations with regard to any requests from Customer’s data subjects, including, without limitation by maintaining a record of which “completion ID” or similar numbers that are related to which data subjects in order to facilitate individual rights requests.
- Customer acknowledges and agrees that it, rather than CHECKEDAGENT, is responsible for certain configurations and design decisions for the services and that Customer, and not CHECKEDAGENT, is responsible for implementing those configurations and design decisions in a secure manner that complies with applicable Data Protection Laws. Without limitation to the foregoing, Customer represents, warrants and covenants that it shall only transfer Customer Data to CHECKEDAGENT using secure, reasonable and appropriate mechanisms.
- Customer shall not provide Customer Data to CHECKEDAGENT except through agreed mechanisms. For example, Customer shall not include Customer Data other than technical contact information, or in technical support tickets, transmit user Customer Data to CHECKEDAGENT by email.
- Customer shall not take any action that would (i) render the provision of Customer Data to CHECKEDAGENT a “sale” under U.S. Privacy Laws or a “share” under the CCPA; or (ii) render CHECKEDAGENT not a “service provider” under the CCPA.
STANDARD CONTRACTUAL CLAUSES
- CHECKEDAGENT will process Customer Data that originates in the European Economic Area in accordance with the standard contractual clauses adopted by the EU Commission on June 4, 2021 (“EU SCCs”) which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows:
- Module Two (Controller to Processor) of the EU SCCs apply when Customer is a controller and CHECKEDAGENT is processing Customer Data as a processor.
- Module Three (Processor to Sub-Processor) of the EU SCCs apply when Customer is a processor and CHECKEDAGENT is processing Customer Data as a sub-processor.
- For each module of the EU SCCs, where applicable, the following applies:
- The optional docking clause in Clause 7 does not apply.
- In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of sub-processor changes shall be thirty (30) days.
- In Clause 11, the optional language does not apply.
- All square brackets in Clause 13 are hereby removed.
- In Clause 17 (Option 1), the EU SCCs will be governed by the EU member state where the data exporter is located.
- In Clause 18(b), disputes will be resolved before the courts of the EU member state where the data exporter is located.
- Exhibit B to this DPA contains the information required in Annex I and Annex III of the EU SCCs.
- Exhibit C to this DPA contains the information required in Annex II of the EU SCCs.
- With respect to Customer Data originating from the United Kingdom, the parties will comply with the terms of Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the Information Commissioner’s Office and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses (the “UK Addendum”). The parties also agree (i) that the information included in Part 1 of the UK Addendum is as set out in Annex I of Appendix A to this DPA and (ii) that either party may end the UK Addendum as set out in Section 19 of the UK Addendum.
- For each module of the EU SCCs, where applicable, the following applies:
TERM. DATA RETURN AND DELETION
- This DPA shall remain in effect as long as CHECKEDAGENT carries out Customer Data processing operations on your behalf or until the termination of the Agreement (and all Customer Data has been returned or deleted in accordance with this DPA). On the termination of the data processing services, upon your reasonable request, and in any case at least once every thirty (30) days, CHECKEDAGENT shall, and shall direct each Subprocessor to, return to you or delete the Customer Data, unless Data Protection Laws prevent CHECKEDAGENT from returning or destroying all or part of the Customer Data. For clarity, deletion obligations shall apply to Customer Data retained in active systems and, where applicable, to prompts, completions, retrieved context, embeddings, caches, and similar technical artifacts maintained on behalf of Customer, subject in each case to CHECKEDAGENT’s standard backup retention, legal retention, disaster recovery, security logging, and business continuity practices. CHECKEDAGENT may continue to process information derived from Customer Data that has been aggregated or stored in a manner that does not identify individuals or customers to operate, secure, analyze, and improve CHECKEDAGENT’s systems and services.
EXHIBIT A
LIST OF AUTHORIZED SUBPROCESSORS
As of the effective date of this DPA, the following Sub-processors are authorized to Process Personal Data on behalf of the Customer. CHECKEDAGENT will update this Annex and notify the Customer of any changes in accordance with Section 6.1.
| Recipient Category | Countries | Purpose of Transfer | Data Types Transferred |
|---|---|---|---|
| AWS | Ireland (AWS eu-west-1) Ireland | Product Cloud Infrastructure | Account/customer identifiers, authentication data, usage & application logs and services, and any personal data persisted by the product |
| Attio | USA | CRM | Business-contact data: names, email addresses, job titles, company, communication history |
| Framer | USA | Website hosting | Website-visitor data: IP address, device/browser data, page-usage/analytics |
| Formspree | USA | Webforms | Contact-form submissions: name, email address, message content, and any other submitted form fields |
| Google Workspace (global infrastructure) | USA | email, documents | Email content and metadata, documents, calendar entries, contact data of correspondents |
| Auth0 | EU | User ID details for verification | Name, email |
EXHIBIT B
A. LIST OF PARTIES
- Data exporter(s): the Customer identified on the applicable Services registration documents
- Data importer(s):
Name: BYNARS SEC, S.L.
Address:
Carrer 5, nº 36
08757 Corbera de Llobregat (Barcelona)
Spain
Activities relevant to the data transferred under these Clauses: The performance of the services described in the agreement to which this is attached.
B. DESCRIPTION OF TRANSFER
- Categories of data subjects whose personal data is transferred:
Data subjects whose characteristics are present in content uploaded by the Customer.
- Categories of personal data transferred
The categories of personal data processed may include:
- Internally by CHECKEDAGENT: Customer account data, user identifiers, username, business email address, authentication and access data, usage data, application logs, and Customer-submitted content to the extent provided through the Services.
- Externally transferred to subprocessors: limited account and user identifiers, including username and business email address, and technical/usage data necessary to provide, host, secure and support the Services.
- Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
None
- The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
On a continuous basis.
- Nature of the processing
The provision of the services described in the services agreement to which this DPA is attached, including hosting, storage, retrieval, transmission, access management, security monitoring, support, diagnostics, maintenance and administration of the Services. Where Customer Data is processed in connection with AI-enabled functionality, such processing is limited to what is necessary to operate, secure, maintain and support the Services, and does not imply that CHECKEDAGENT hosts or provisions large language model infrastructure.
.
- Purpose(s) of the data transfer and further processing
The provision of the services described in the services agreement to which this DPA is attached, including processing necessary to host, analyze, transmit, retrieve, transform, and generate outputs from Customer-submitted content, and to maintain, secure, support, and administer the Services.
- The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
During the term of the agreement, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Laws.
- For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
The subject matter, nature, and duration of processing by Subprocessors are limited to the extent necessary for them to provide hosting, infrastructure, model inference, observability, support, security, and related services to CHECKEDAGENT for the term of the Agreement and any applicable deletion or retention period described in this DPA.
C. COMPETENT SUPERVISORY AUTHORITY
- Identify the competent supervisory authority/ies.
The data protection authority of the EU Member State in which the exporter is established.
The data protection authority of the UK is the UK Information Commissioner.
EXHIBIT C
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
1. Tenant isolation
- Each customer is provisioned a logically isolated Tenant with a unique Tenant identifier propagated through every layer of the platform;
- Application-layer authorization checks ensure every read, write, query, and retrieval operation is scoped to a single Tenant;
- Database-layer isolation through tenant-scoped schemas, row-level security, or per-tenant database instances;
- Per-tenant encryption keys are supported where the underlying storage technology allows
2. Access control
- Multi-factor authentication for all employees with access to systems Processing Personal Data;
- ABAC/RBAC access controls with least-privilege principle;
- Access to production Personal Data limited to a small number of named personnel, listed and reviewed quarterly;
3. Encryption
- Encryption in transit: TLS 1.2 or above for all data transmissions;
- Encryption at rest: AES-256 or equivalent for stored Personal Data;
- Key management: keys stored in a dedicated secrets management system.
4. Network and infrastructure
- Hosting on hardened cloud infrastructure with security controls of major cloud providers;
- Segmented network architecture with private subnets for components Processing Personal Data;
- Web application firewall and DDoS protection at edge;
- Hosting Region enforced through cloud provider region restrictions; no cross-region replication of Tenant Personal Data.
5. Logging, monitoring and audit
- Application and infrastructure logging with retention aligned to Applicable Data Protection Law;
- Audit trail of access to and operations on Personal Data, scoped per Tenant;
6. Personnel and organizational
- Confidentiality undertakings binding on all personnel and contractors;
- Documented incident response plan, with the breach notification process described in Section 8.
7. Business continuity and resilience
- Documented backup and restore procedures, with backups encrypted and stored within the Hosting Region.