Data Processing Agreement
Effective Date: August 25, 2026
Last Updated: August 25, 2026
Version 1.0
How this DPA applies. This Data Processing Agreement forms part of the FeedFrwd Terms of Service (or other written agreement) between FeedFrwd, Inc. and Customer. It applies automatically, without signature, whenever FeedFrwd processes Personal Data on Customer’s behalf and applicable Data Protection Law requires such terms. Customers who require a countersigned copy may request one at privacy@feedfrwd.ai.
This Data Processing Agreement (“DPA”) is entered into between FeedFrwd, Inc., a Delaware corporation (“FeedFrwd,” “Processor”), and the customer identified in the Agreement (“Customer,” “Controller”). FeedFrwd and Customer are each a “party” and together the “parties.”
This DPA is incorporated into and forms part of the FeedFrwd Terms of Service available at feedfrwd.ai/legal/terms, any Order Form referencing those Terms, or any other written agreement between the parties governing Customer’s use of the Service (the “Agreement”). Capitalized terms not defined in this DPA have the meanings given in the Agreement.
In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.
1. Definitions
“Applicable Data Protection Law” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection (“FADP”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other U.S. state privacy laws, in each case as amended or replaced from time to time.
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processing,” and “Supervisory Authority” have the meanings given in the GDPR. “Business,” “Service Provider,” “Sell,” “Share,” and “Consumer” have the meanings given in the CCPA.
“Customer Personal Data” means Personal Data contained within Customer Data that FeedFrwd Processes on Customer’s behalf in the course of providing the Service.
“Restricted Transfer” means a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the relevant authority.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
“Subprocessor” means any third party engaged by FeedFrwd to Process Customer Personal Data in connection with the Service.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2. Roles and Scope
2.1 Roles of the parties
With respect to Customer Personal Data, Customer is the Controller (or, where Customer itself acts as a processor for a third party, the processor acting on that third party’s behalf) and FeedFrwd is the Processor. Under the CCPA, Customer is the Business and FeedFrwd is a Service Provider.
2.2 FeedFrwd as Controller
FeedFrwd acts as an independent Controller with respect to Personal Data it collects for its own purposes, including account registration data, billing data, support communications, and website analytics. That Processing is described in the FeedFrwd Privacy Policy and is outside the scope of this DPA.
2.3 Subject matter and details
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I to this DPA.
2.4 Duration
FeedFrwd will Process Customer Personal Data for the duration of the Agreement and for any additional period during which FeedFrwd is required by law to retain it or during which it remains in routine backups pending purge in the ordinary course.
3. Processing Instructions
3.1 Documented instructions
FeedFrwd will Process Customer Personal Data only on Customer’s documented instructions, which consist of: (a) the Agreement, including this DPA; (b) Customer’s configuration of and use of the features of the Service; and (c) any further written instructions agreed by the parties. FeedFrwd will not Process Customer Personal Data for any other purpose.
3.2 Prohibited uses
FeedFrwd will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for any purpose other than performing the Service, except as permitted by Applicable Data Protection Law; or (c) combine Customer Personal Data with personal information received from another source, except as permitted for a Service Provider under the CCPA. FeedFrwd certifies that it understands and will comply with these restrictions.
3.3 AI Processing
FeedFrwd Processes Customer Personal Data using artificial intelligence and machine learning as core functionality of the Service. FeedFrwd will not use identifiable Customer Personal Data to train, fine-tune, or improve general-purpose or foundation AI models without Customer’s prior written consent, and contractually prohibits its AI Subprocessors from doing so. FeedFrwd may use aggregated or de-identified data derived from the Service in accordance with the Agreement, provided it does not attempt to re-identify that data.
3.4 Unlawful instructions
FeedFrwd will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so by law. FeedFrwd may suspend performance of the affected instruction until it is amended or confirmed.
3.5 Legally required disclosure
If FeedFrwd is required by law to Process Customer Personal Data other than on Customer’s instructions, it will inform Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest. FeedFrwd will challenge overbroad or unlawful requests where it has a reasonable basis to do so and will disclose only the minimum data legally required.
4. Customer Obligations
Customer represents and warrants that:
(a) it has provided all required notices to, and obtained all required consents or established another valid lawful basis in respect of, Data Subjects for the Processing contemplated by the Agreement;
(b) its instructions to FeedFrwd comply with Applicable Data Protection Law;
(c) it is solely responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it acquired that data;
(d) it will not provide FeedFrwd with special categories of Personal Data under Article 9 GDPR, criminal conviction data, or the categories of restricted data listed in the Agreement, except as expressly agreed in writing or where such data appears incidentally in free-text End User feedback and Customer has a lawful basis for it; and
(e) it has implemented appropriate configuration, access management, and retention settings within the Service for its own risk profile and legal obligations.
5. Confidentiality and Personnel
FeedFrwd will ensure that any person authorized to Process Customer Personal Data is subject to a binding duty of confidentiality, receives appropriate data protection and security training, and has access only to the Customer Personal Data necessary for their role. FeedFrwd limits access to Customer Personal Data to personnel with a documented business need and revokes access promptly on role change or departure.
6. Security
6.1 Technical and organizational measures
FeedFrwd will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing. Those measures are described in Annex II.
6.2 Changes to measures
FeedFrwd may update its security measures from time to time provided the updated measures do not materially reduce the overall level of protection afforded to Customer Personal Data.
7. Personal Data Breach
FeedFrwd will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.
FeedFrwd will provide Customer with reasonable cooperation and information to enable Customer to meet its own notification obligations to Supervisory Authorities and Data Subjects. FeedFrwd’s notification of a breach is not an acknowledgement of fault or liability.
8. Assistance to Customer
8.1 Data Subject requests
The Service provides functionality enabling Customer to access, correct, export, restrict, and delete Customer Personal Data. Taking into account the nature of the Processing, FeedFrwd will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligations to respond to Data Subject requests. If FeedFrwd receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively but will, without undue delay, direct the Data Subject to Customer and inform Customer of the request.
8.2 DPIAs and prior consultation
FeedFrwd will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities relating to the Processing, taking into account the nature of the Processing and the information available to FeedFrwd.
8.3 Fees
Assistance under this Section is provided at no additional charge where the request is reasonable in scope and frequency. FeedFrwd may charge a reasonable fee for assistance that is manifestly unfounded, excessive, or requires materially more than commercially reasonable effort, on prior written notice to Customer.
9. Subprocessors
9.1 General authorization
Customer provides FeedFrwd with general written authorization to engage Subprocessors to Process Customer Personal Data. A current list of Subprocessors, including the name, location, and purpose of each, is maintained at feedfrwd.ai/legal/subprocessors and is reproduced in Annex III as at the date of this DPA.
9.2 Notice of changes
FeedFrwd will provide notice of the addition or replacement of a Subprocessor at least thirty (30) days before that Subprocessor begins Processing Customer Personal Data, by updating the Subprocessor page and notifying Customers who have subscribed to notifications there. Customers are responsible for subscribing to receive those notifications.
9.3 Objection
Customer may object to a new Subprocessor on reasonable data protection grounds by written notice to privacy@feedfrwd.ai within the thirty (30) day notice period. The parties will discuss the objection in good faith. If FeedFrwd is unable to make available an alternative arrangement within a reasonable period, Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of the then-current Subscription Term. Termination on this basis is Customer’s sole remedy.
9.4 Subprocessor obligations
FeedFrwd will impose on each Subprocessor, by written contract, data protection obligations that are no less protective than those in this DPA. FeedFrwd remains fully liable to Customer for the performance of each Subprocessor’s obligations.
9.5 Emergency replacement
FeedFrwd may replace a Subprocessor without the notice period in Section 9.2 where the change is required urgently to protect the security or continuity of the Service. FeedFrwd will notify Customer of any such change as soon as reasonably practicable.
10. International Transfers
10.1 Transfer mechanism
FeedFrwd is established in the United States and Processes Customer Personal Data in the United States and, through its Subprocessors, in other jurisdictions listed in Annex III. Where a Restricted Transfer occurs, the parties agree to the transfer mechanisms set out below.
10.2 EU Standard Contractual Clauses
For transfers of Customer Personal Data subject to the GDPR, the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows:
-
Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is itself a processor acting on behalf of a third-party controller.
-
Clause 7 (docking clause) applies.
-
In Clause 9, Option 2 (general written authorization) applies, with a notice period of thirty (30) days as set out in Section 9.2.
-
In Clause 11, the optional independent dispute resolution language does not apply.
-
In Clause 17, the Clauses are governed by the law of Ireland.
-
In Clause 18(b), disputes will be resolved before the courts of Ireland.
-
Annex I, Annex II, and Annex III to the Standard Contractual Clauses are populated by Annex I, Annex II, and Annex III to this DPA respectively.
10.3 UK transfers
For transfers subject to the UK GDPR, the Standard Contractual Clauses apply as amended by the UK Addendum. In Table 1 of the UK Addendum, the parties and their details are as set out in Annex I. In Table 2, the version of the Approved EU SCCs is the module and options identified in Section 10.2. In Table 3, the Appendix Information is as set out in Annexes I to III. In Table 4, neither party may terminate the UK Addendum under Section 19 of the Mandatory Clauses.
10.4 Swiss transfers
For transfers subject to the FADP, the Standard Contractual Clauses apply with the following modifications: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term “member state” does not exclude Swiss Data Subjects from bringing claims in their place of habitual residence; and the Clauses also protect the data of legal entities until the FADP is amended to remove that protection.
10.5 Alternative mechanisms
If FeedFrwd adopts an alternative lawful transfer mechanism, including certification under a framework recognized as providing adequacy, that mechanism will apply instead of the Standard Contractual Clauses to the extent it lawfully covers the transfer, on notice to Customer.
10.6 Government access
FeedFrwd has no reason to believe that laws applicable to it prevent it from fulfilling its obligations under the Standard Contractual Clauses. FeedFrwd maintains a policy for handling government and law enforcement requests for Customer Personal Data, will challenge requests that are unlawful or overbroad, and will publish or provide on request aggregate information about such requests to the extent permitted by law.
11. Audit and Compliance
11.1 Information and documentation
FeedFrwd will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including its then-current security documentation, security questionnaire responses, penetration test summaries, and any third-party audit reports or certifications it holds.
11.2 Audits
Where the information provided under Section 11.1 is not sufficient to demonstrate compliance, Customer may, no more than once in any twelve (12) month period and on at least thirty (30) days’ prior written notice, conduct an audit of FeedFrwd’s Processing. Audits will be conducted during normal business hours, will not unreasonably interfere with FeedFrwd’s operations, will be subject to FeedFrwd’s confidentiality and security requirements, and will not extend to the data or systems of other customers. Customer bears its own costs and FeedFrwd’s reasonable costs of supporting an on-site audit. An additional audit may be conducted where required by a Supervisory Authority or following a confirmed Personal Data Breach affecting Customer Personal Data.
12. Return and Deletion
During the Subscription Term, Customer may export Customer Personal Data using the functionality of the Service. On expiry or termination of the Agreement, FeedFrwd will, at Customer’s written request made within thirty (30) days, make Customer Personal Data available for export.
After that period, FeedFrwd will delete or render permanently unrecoverable all Customer Personal Data within ninety (90) days, except to the extent that retention is required by applicable law or the data is held in routine encrypted backups that are purged on their ordinary cycle. Any Customer Personal Data retained in backups remains subject to this DPA until deleted. FeedFrwd will confirm deletion in writing on request.
13. CCPA and U.S. State Privacy Laws
To the extent FeedFrwd Processes Personal Data of California residents as a Service Provider, the parties agree that: FeedFrwd is prohibited from Selling or Sharing that Personal Data; FeedFrwd will not retain, use, or disclose it for any purpose other than performing the Service specified in the Agreement, or as otherwise permitted by the CCPA; FeedFrwd will not combine it with personal information from other sources except as permitted for a Service Provider; and FeedFrwd will comply with the obligations applicable to Service Providers under the CCPA, including providing the level of privacy protection the CCPA requires.
FeedFrwd will notify Customer if it determines that it can no longer meet its obligations under the CCPA. Customer may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data. The same commitments apply, with equivalent effect, where FeedFrwd acts as a “processor” under other U.S. state privacy laws, including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Washington.
14. Liability
Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. Any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits the rights of Data Subjects under Applicable Data Protection Law or under the Standard Contractual Clauses.
15. General
This DPA takes effect on the effective date of the Agreement and terminates automatically on termination of the Agreement, except that provisions which by their nature should survive — including Sections 10, 12, 13, and 14 — continue to apply for as long as FeedFrwd holds Customer Personal Data.
FeedFrwd may update this DPA from time to time where necessary to reflect changes in Applicable Data Protection Law, guidance from Supervisory Authorities, or the adoption of new transfer mechanisms, provided the update does not materially reduce Customer’s protections. FeedFrwd will give at least thirty (30) days’ notice of material updates.
This DPA is governed by the law specified in the Agreement, except where Applicable Data Protection Law or the Standard Contractual Clauses require otherwise. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force and effect.
Data protection enquiries and requests under this DPA should be sent to privacy@feedfrwd.ai.
Annex I — Description of Processing
A. List of Parties
Data Exporter
Name: The Customer identified in the Agreement.
Address: As set out in the Customer’s Account or Order Form.
Contact: The administrative or privacy contact identified in the Customer’s Account.
Activities relevant to the transfer: Use of the FeedFrwd Service to ingest, analyze, prioritize, and act on customer feedback.
Role: Controller (or processor acting for a third-party controller).
Data Importer
Name: FeedFrwd, Inc.
Address: As published at feedfrwd.ai/legal.
Contact: Privacy Team — privacy@feedfrwd.ai
Activities relevant to the transfer: Provision of the FeedFrwd Service, including AI-based analysis, hosting, storage, and support.
Role: Processor (or sub-processor).
B. Description of Transfer
Categories of Data Subjects: Customer’s Authorized Users (employees, contractors, and agents); Customer’s own customers, prospects, and end users whose feedback, reviews, support interactions, survey responses, or similar content is submitted to or connected with the Service.
Categories of Personal Data: Authorized User data: name, business email address, job title, company, profile image, authentication identifiers, IP address, device and browser data, and product usage logs. End User data: name, email address, account or customer identifier, company, and any personal data contained in free-text feedback, reviews, support tickets, survey responses, transcripts, and metadata submitted by Customer or ingested from connected Third-Party Services.
Special categories of data: FeedFrwd does not require or request special categories of Personal Data. Customer is contractually prohibited from deliberately submitting such data. Special categories may appear incidentally in free-text End User feedback; where they do, FeedFrwd applies the same technical and organizational measures described in Annex II and does not treat such data differently for analysis purposes.
Frequency of the transfer: Continuous, for the duration of the Agreement.
Nature of the Processing: Collection, receipt, import, storage, hosting, organization, structuring, de-duplication, clustering, semantic and sentiment analysis, scoring and prioritization, generation of recommendations and actions, retrieval, display, export, transmission to connected Third-Party Services at Customer’s direction, backup, erasure, and destruction.
Purpose of the Processing: To provide, secure, maintain, and support the FeedFrwd Service to Customer in accordance with the Agreement and Customer’s instructions.
Retention period: For the duration of the Agreement, plus the export window and deletion period set out in Section 12 of this DPA, plus any period required by applicable law or during which data remains in routine backups pending purge.
Subprocessor transfers: As set out in Annex III, for the duration of and for the purposes described in that Annex.
C. Competent Supervisory Authority
Where the GDPR applies, the competent Supervisory Authority is the authority of the EU member state in which Customer is established, or, where Customer is not established in the EU, the authority of the member state in which Customer’s EU representative under Article 27 GDPR is established. Where the UK GDPR applies, the competent authority is the UK Information Commissioner’s Office. Where the FADP applies, the competent authority is the Swiss Federal Data Protection and Information Commissioner.
Annex II — Technical and Organizational Measures
FeedFrwd maintains the following measures to ensure the security of Customer Personal Data. These measures apply to the production environment in which the Service operates.
Encryption: Personal Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 or an equivalent industry-standard algorithm. Encryption keys are managed through the cloud provider’s managed key service with restricted administrative access.
Access control: Access to production systems and Customer Personal Data is restricted to authorized personnel on a documented least-privilege, need-to-know basis. Role-based access control is enforced, multi-factor authentication is required for administrative access, and access is reviewed periodically and revoked promptly on role change or departure.
Tenant isolation: The Service is multi-tenant. Customer Data is logically segregated and access is scoped to the authenticated tenant at the application and data layers, so that one customer cannot access another customer’s data.
Network and infrastructure security: Production systems run on established cloud infrastructure providers within hardened, access-controlled network boundaries. Administrative interfaces are not exposed to the public internet without authentication, and network traffic is filtered and monitored.
Logging and monitoring: Security-relevant events, administrative actions, and access to Customer Personal Data are logged. Logs are retained and monitored for anomalous activity, and alerting is configured for suspected security events.
Secure development: Changes to the Service follow a documented development lifecycle including peer code review, automated testing, and dependency vulnerability scanning before deployment. Separate development, staging, and production environments are maintained.
Vulnerability management: Dependencies and infrastructure are monitored for known vulnerabilities. Security patches are prioritized by severity and applied within a risk-based timeframe.
Backup and resilience: Customer Data is backed up on a regular schedule. Backups are encrypted, access-restricted, and purged on a defined cycle. Restoration procedures are documented and periodically exercised.
Incident response: FeedFrwd maintains a documented incident response plan covering detection, triage, containment, eradication, recovery, notification, and post-incident review, with defined internal escalation paths and the customer notification commitments in Section 7 of this DPA.
Personnel: Personnel with access to Customer Personal Data are subject to written confidentiality obligations, complete security and data protection awareness training, and are subject to background screening to the extent permitted by applicable law.
Subprocessor management: Subprocessors are assessed for security and data protection maturity before engagement, are bound by written data protection terms no less protective than this DPA, and are subject to periodic review.
Data minimization and deletion: The Service is designed to collect only the data necessary to deliver its functionality. Retention settings are available to Customer, and deletion is performed in accordance with Section 12 of this DPA.
AI-specific controls: AI Subprocessors are contractually prohibited from using Customer Personal Data to train or improve their own models. AI processing requests are made over encrypted channels, and FeedFrwd configures zero-retention or minimum-retention options with its AI providers where such options are offered.
Business continuity: FeedFrwd maintains recovery procedures for the production environment appropriate to the nature and scale of the Service.
Annex III — Subprocessors
The following Subprocessors are authorized to Process Customer Personal Data as at the effective date of this DPA. The authoritative and current list is maintained at feedfrwd.ai/legal/subprocessors.
Cloud hosting and infrastructure provider: Hosting of the production environment, compute, storage, and managed database services. Processing location: United States.
Managed database and storage provider: Persistent storage of Customer Data and backups. Processing location: United States.
Generative AI provider(s): Semantic analysis, clustering, summarization, and generation of insights, recommendations, and actions. Contractually prohibited from training on Customer Data. Processing location: United States.
Authentication provider: User authentication, session management, and single sign-on. Processing location: United States.
Payment processor: Subscription billing and payment processing. Processes billing contact data only; does not receive Customer Data. Processing location: United States.
Transactional email provider: Delivery of account, security, and service notification emails. Processing location: United States.
Customer support platform: Handling of support requests and related communications. Processing location: United States.
Product analytics and error monitoring: Usage analytics, performance monitoring, and error reporting. Processing location: United States.
.png)