Data Processing Addendum
Last updated: July 28, 2026
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you (the "Customer") and Deal Flow Xchange Inc, a Delaware corporation operating DFX Intelligence and The General ("DFX"), and applies to the extent DFX processes Customer Personal Data on the Customer's behalf in providing the Services.
It applies automatically, without signature, when the Customer uses the Services to process personal data about third parties. Where the Customer requires a signed copy, or requires the Standard Contractual Clauses executed separately, write to hello@dfxintel.com. Capitalized terms not defined here have the meaning given in the Terms of Service.
In this DPA, "Data Protection Law" means all laws applicable to the processing of personal data, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA"). "Customer Personal Data" means personal data contained in Your Content or accessed, collected, or generated through the Services on the Customer's instructions.
1. Roles of the parties
With respect to Customer Personal Data, the Customer is the controller (or business, or, where the Customer is itself a processor for its own clients, the processor) and DFX is the processor (or service provider). DFX processes Customer Personal Data only on the Customer's documented instructions, which consist of the Terms of Service, this DPA, the settings and configurations the Customer chooses in the Services, and the tasks, missions, routines, approvals, and other instructions the Customer or its users give through the Services.
With respect to personal data about the Customer's own personnel, account and billing data, and data DFX collects through its own websites, demonstrations, and marketing, DFX acts as an independent controller as described in the Privacy Policy, and this DPA does not apply to that processing.
DFX will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend processing of an instruction that DFX reasonably believes is unlawful. The Customer is responsible for the lawfulness of its instructions, for having a valid legal basis for the processing it directs (including sourcing, enrichment, profiling, and outreach), and for providing all required notices to and obtaining all required consents from data subjects.
2. Details of the processing
Subject matter and nature. Provision of the Services described in the Terms of Service, which include research, sourcing, enrichment and verification, data organization and storage, drafting and generation of content, classification and triage of communications, sending and receiving communications, placing and receiving calls, capture and transcription of calls and meetings, browser and connected-account operation, and automated decisioning about whether an action requires the Customer's approval.
Purpose. To perform the Services and the work the Customer requests, and to secure, support, and maintain the Services.
Duration. For the term of the Terms of Service, plus the retention periods described in the Privacy Policy and in the Deletion and return section below.
Categories of data subjects may include: the Customer's personnel and users; the Customer's contacts, prospects, leads, customers, donors, recipients, and counterparties; individuals whose information appears in the Customer's connected accounts, uploaded documents, or in pages the Customer directs the Services to work on; the Customer's website visitors and callers; and participants in calls and meetings the Customer records.
Categories of personal data may include: identifiers and contact details (name, email address, telephone number, postal address, online identifiers, IP address); employment and professional details (employer, role, seniority, public profile information); communications content and metadata (email, messages, text messages, call and meeting audio, transcripts, summaries, reply and outcome data); consent, opt-in, and opt-out records; CRM and record data the Customer maintains; content of pages the Customer directs browser work on, including screenshots; and any other personal data the Customer chooses to submit or direct the Services to collect.
Sensitive and special-category data. The Services are not designed or offered for special-category personal data under Article 9 GDPR, sensitive personal information under U.S. state privacy laws, protected health information, payment-card data, financial account data subject to the Gramm-Leach-Bliley Act, consumer report data subject to the Fair Credit Reporting Act, biometric identifiers, precise geolocation, government identification numbers, children's data, or criminal-offense data, and the Customer must not submit or direct the Services to collect it. Where the Customer does so in breach of the Terms of Service, the Customer bears all resulting risk and liability.
3. Confidentiality and personnel
DFX will treat Customer Personal Data as confidential, will limit access to personnel who need it to provide the Services, support, or security, and will ensure those personnel are bound by appropriate confidentiality obligations and receive appropriate training.
4. Security measures
DFX implements and maintains technical and organizational measures appropriate to the risk, which currently include:
- +encryption of data in transit using TLS, and encryption at rest of sensitive credentials (such as connected-account passwords, application passwords, OAuth tokens, and API keys) using AES-256-GCM, decrypted only server-side to perform requested work;
- +storage of browser-connection tokens as hashes rather than plain text, and short-lived session tokens;
- +logical separation of customers into tenants, with access controls, row-level database policies, and per-member scoping of requests;
- +role-based access control, authentication through a managed identity provider, and least-privilege service credentials;
- +logging of access to sensitive credentials and of actions taken in customer workspaces, and retention of activity and evidence records;
- +rate limiting, abuse detection, secret scanning in source control, and dependency and configuration review;
- +restricted-domain and scope controls on browser operation, refusal to execute server-supplied script in customer pages, and approval gates on irreversible actions;
- +backups of production data, and recovery procedures tested from time to time.
These measures may be updated as the Services evolve, provided that the level of security is not materially reduced. The Customer is responsible for the security measures within its own control, including the security of its devices, browsers, browser profiles, credentials, connected systems, team access, and its configuration of scopes, approvals, autonomy settings, and limits.
DFX will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to DFX so that the Customer can meet its own notification obligations. DFX's notification is not an acknowledgement of fault or liability.
5. Sub-processors
The Customer grants DFX general authorization to engage sub-processors to provide the Services. DFX imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors' performance of those obligations.
Sub-processors currently include providers of AI language and voice models (Anthropic, OpenAI, ElevenLabs), telephony and messaging (Twilio), email delivery (Resend), meeting capture and transcription, contact-data enrichment and email finding (Apollo, Hunter), payment and payout processing (Stripe), authentication (Clerk), cloud database and hosting (Supabase, Vercel), and Google services where the Customer connects them. A current list is available at hello@dfxintel.com on request.
DFX will provide notice before adding or replacing a sub-processor that processes Customer Personal Data, by updating the list it makes available and, where the Customer has subscribed to notifications, by email. The Customer may object on reasonable data-protection grounds within fifteen (15) days of notice, in which case the parties will work in good faith to find a resolution; if none is available, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused subscription fees for the terminated portion.
6. Data subject requests and assistance
The Services provide the Customer with controls to access, correct, export, and delete Customer Personal Data. Where a data subject contacts DFX directly with a request concerning Customer Personal Data, DFX will not respond on the merits and will refer the request to the Customer where it can identify the relevant Customer.
Taking into account the nature of the processing and the information available to it, DFX will provide reasonable assistance to the Customer in responding to data subject requests, in carrying out data protection impact assessments, and in prior consultations with supervisory authorities. DFX may charge a reasonable fee for assistance that is not provided through the Services' own controls and that is disproportionate in scope.
7. International transfers
DFX processes Customer Personal Data in the United States and may process it in other countries where DFX or its sub-processors operate.
Where the Customer transfers personal data subject to the GDPR to DFX, the Standard Contractual Clauses approved by the European Commission (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated into this DPA by reference and apply, with: the Customer as data exporter and DFX as data importer; the optional docking clause included; the supervisory authority being that of the Customer's place of establishment; the governing law and forum being Ireland, or, where the exporter is in another Member State, that Member State; the general authorization for sub-processors under Clause 9(a) option 2 with the notice period stated above; and Annexes I, II, and III populated by the "Details of the processing", "Security measures", and "Sub-processors" sections of this DPA.
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with the tables completed by reference to this DPA. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
DFX applies supplementary measures including encryption in transit and at rest, access controls, and a policy of challenging unlawful or overbroad government access requests and, where legally permitted, notifying the Customer of any binding request for Customer Personal Data.
8. U.S. state privacy laws
With respect to personal information subject to the CCPA and comparable U.S. state privacy laws, DFX is a service provider or processor. DFX does not sell or share personal information, does not retain, use, or disclose it for any purpose other than performing the Services specified in the Terms of Service (or as otherwise permitted by law), does not combine it with personal information received from other sources except as permitted for a service provider, and does not use it outside the direct business relationship between DFX and the Customer.
DFX will comply with applicable obligations of a service provider or processor and will notify the Customer if it determines it can no longer meet them. The Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of personal information, including by using the controls in the Services or by contacting DFX.
9. Audit
DFX will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, which may take the form of written responses to a reasonable security questionnaire, a description of its technical and organizational measures, and any third-party attestations or reports it holds.
Where Data Protection Law grants an audit right that the foregoing does not satisfy, the Customer may, no more than once in any twelve-month period and on at least thirty (30) days' written notice, conduct an audit limited to information relevant to the processing of Customer Personal Data, at the Customer's expense, during business hours, without disrupting operations, subject to confidentiality obligations, and excluding access to other customers' data, DFX's source code, or the systems and premises of DFX's providers. An additional audit may be conducted where required by a supervisory authority or following a personal data breach affecting the Customer.
10. Deletion and return
The Customer may export or delete Customer Personal Data at any time using the controls in the Services. On termination, and subject to the export window described in the Terms of Service, DFX will delete or de-identify Customer Personal Data within a reasonable period, except to the extent retention is required by law or for the establishment, exercise, or defense of legal claims, and except for copies held in routine backups, which expire on their own cycle and remain protected by this DPA until they do.
11. Liability, order of precedence, and general
Each party's liability arising out of or relating to this DPA, including under the Standard Contractual Clauses, is subject to the limitations and exclusions of liability in the Terms of Service, to the maximum extent permitted by Data Protection Law.
In the event of a conflict, the Standard Contractual Clauses prevail over this DPA with respect to transfers to which they apply, this DPA prevails over the Terms of Service with respect to the processing of Customer Personal Data, and the Terms of Service govern all other matters. DFX may update this DPA to reflect changes in law, in its sub-processors, or in the Services, provided the update does not materially reduce the protections it provides.
Questions, signed copies, and sub-processor notification requests: hello@dfxintel.com.