This Data Processing Addendum ("DPA") forms part of the Terms of Service, or of any written agreement for the dotDash platform (the "Service") between FluentData, Inc., a Delaware corporation ("FluentData", "we", "us") and the customer organisation ("Customer", "you"). It governs our processing of personal data contained in Customer Content.
Where this DPA conflicts with the Terms of Service on the subject of data processing, this DPA prevails.
1. Roles of the parties
For personal data in Customer Content, you are the controller and FluentData is the processor. You determine the purposes and means of processing; we process only on your instructions.
Where you are yourself a processor for another controller, we act as a sub-processor, and your instructions to us must be consistent with that controller's.
For information we process for our own purposes — your administrators' contact details, billing records, and the operational telemetry we need to run and secure the Service — FluentData is the controller and the Privacy Policy applies.
2. Scope and details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the dotDash platform |
| Duration | The term of your subscription, plus the deletion period in section 10 |
| Nature and purpose | Hosting, storing, indexing, retrieving, transmitting and analysing Customer Content so the Service can run workflows, answer questions, hold conversations and produce dashboards on your instructions |
| Types of personal data | Whatever you choose to put into, or connect to, a workspace. Typically: names and contact details of your users; the content of documents, files and messages; conversation transcripts from connected channels; records retrieved from systems you connect |
| Categories of data subjects | Your personnel and authorised users, and any individuals appearing in Customer Content — which may include your own customers, prospects and suppliers |
| Special categories | Not requested or required by the Service. If you choose to submit them, you are responsible for having a lawful basis and for any additional measures your law requires |
3. Our obligations as processor
We will:
- process personal data only to provide the Service, on your documented instructions, and as described in this DPA — never for our own independent purposes;
- not use Customer Content to train, fine-tune or improve any machine learning model, and require the same of our model providers;
- not sell Customer Content or disclose it for cross-context behavioural advertising;
- ensure that personnel with access are subject to confidentiality obligations that survive the end of their engagement, and grant access only on a need-to-know basis;
- implement and maintain the technical and organisational measures described in section 4;
- tell you promptly if, in our opinion, an instruction from you would infringe applicable data protection law; and
- tell you promptly if we receive a request from an authority for Customer Content, unless legally prohibited from doing so, and not disclose it unless legally compelled.
4. Security measures
We maintain measures appropriate to the risk, including:
- Separation between customers. Each organisation's data is segregated and access is constrained at the database layer, so a request executed for one organisation cannot reach another's records.
- Encryption. In transit over TLS, and at rest for the database, object storage and backups. Integration credentials are encrypted with a separate key before storage.
- Access control. Role-based permissions within and across workspaces, multi-factor authentication available to all users and enforceable organisation-wide, and least-privilege access for our own personnel.
- Auditability. Privileged and data-affecting actions are recorded to an append-only audit trail attributable to an actor, available to your administrators.
- Read-only access to connected databases. Queries our agents compose against a database you connect execute inside a read-only transaction, with statement, row and time bounds.
- Traceability of generated output. Agent steps, tool calls and model responses are logged, so any answer the Service produces can be traced to the tools and sources behind it.
- Resilience. Managed, replicated infrastructure with automated backups and point-in-time recovery.
- Change management. Peer-reviewed changes, automated testing, and dependency vulnerability monitoring.
We may update these measures over time, provided we do not materially reduce their overall level of protection.
5. Subprocessors
You give general authorisation for us to engage subprocessors. Each is bound by a written agreement imposing data protection obligations no less protective than this DPA, and we remain responsible for their performance.
Our current subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google LLC | Application hosting, database, file storage and generative models (Google Cloud Platform, Vertex AI) | United States (us-central1) |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| Plus Five Five, Inc. (Resend) | Transactional and workflow email delivery | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States |
Systems you choose to connect — your own cloud project, databases, messaging channels or business applications — are not our subprocessors. You are the controller of that processing and responsible for the credentials and scopes you provide.
We will give you notice before adding or replacing a subprocessor. You may object on reasonable data protection grounds within 30 days, in which case we will work with you in good faith on an alternative; if none is available you may terminate the affected part of the Service without penalty for the unexpired term.
6. International transfers
The Service is hosted in the United States, in Google Cloud's us-central1 region. Where you transfer
personal data to us from the European Economic Area, the United Kingdom or Switzerland, the parties
agree that:
- the European Commission's Standard Contractual Clauses (Decision 2021/914), controller-to-processor Module Two, are incorporated into this DPA by reference, with FluentData as data importer and you as data exporter;
- for the United Kingdom, the UK International Data Transfer Addendum applies to those Clauses; and
- for Switzerland, references to the GDPR are read as references to the Swiss FADP and the supervisory authority as the FDPIC.
For those Clauses: the Annex I details are in section 2, the Annex II measures in section 4, and the Annex III subprocessors in section 5. The governing law and forum are those stated in the Terms of Service, to the extent the Clauses permit.
7. Assisting you
Taking into account the nature of the processing, we will provide reasonable assistance with:
- Data subject requests. The Service gives your administrators the means to search, export, correct and delete Customer Content directly. Where you cannot fulfil a request through the Service, we will help. If we receive a request directly from one of your data subjects, we will refer them to you rather than respond on your behalf.
- Impact assessments and consultations, where required by applicable law.
8. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Content. The notice will describe what we know of the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. We will keep you updated as we learn more, and assist you in meeting your own notification obligations.
Notification is not an acknowledgement of fault or liability.
9. Audits
On reasonable written request, and no more than once a year unless a breach or a regulator requires otherwise, we will make available the information necessary to demonstrate compliance with this DPA. We may satisfy an audit request by providing a current third-party report or certification where one exists. Any on-site audit must be scheduled in advance, conducted during business hours without unreasonable disruption, be subject to confidentiality, and not extend to other customers' data or to our multi-tenant infrastructure.
10. Deletion and return
You may export Customer Content at any time during the subscription term through the Service or its API.
On termination or expiry, we will delete Customer Content within 30 days, except where retention is required by law, in which case the retained data stays subject to this DPA. Backups are overwritten in the ordinary retention cycle, within 90 days. On written request we will confirm deletion.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or the applicable written agreement.
12. Contact
For any question about this DPA, or to raise a data protection matter:
Data Protection OfficeFluentData, Inc.
14681 Biscayne Blvd, # 115
North Miami Beach, Florida 33181
United States of America
Email: info@fluentdata.ai
Telephone: +1 (305) 465-0957
Customers requiring a signed copy of this DPA, or their own paper with the Standard Contractual Clauses attached, should contact us at the address above.

