Legal

Data Processing Addendum

Version: 2026-09-23

This Data Processing Addendum (“DPA”) supplements the service agreement between Airbrx, Inc. (“Airbrx”) and the Customer identified in Schedule 1 (“Agreement”). It takes effect through both parties’ authorized acceptance of an Order expressly incorporating this version and its schedules, with the required customer-specific entries. Preparing or publishing this text does not itself put a DPA or transfer mechanism into effect; that requires an accepted Order as described here.

1. Scope and roles

“Customer Personal Data” means personal data contained in Customer Data that Airbrx processes on Customer’s behalf in providing the Service. “Applicable Data Protection Law” means privacy and data-protection laws applicable to that processing, including the EU GDPR, UK GDPR, and California Consumer Privacy Act as amended (“CCPA”), where applicable. Other data-protection terms have the meanings given by the applicable law.

Customer is the controller or business for Customer Personal Data, or a processor authorized to engage Airbrx on a controller’s behalf. Airbrx acts as Customer’s processor, subprocessor, service provider, or contractor, as applicable. If Customer is a processor, it is responsible for obtaining the upstream authorization needed for this engagement and communicating the controller’s lawful instructions.

Airbrx’s independent processing of business contacts, invoices, and its own relationship-administration records is governed by applicable law and its Privacy Policy. Authentication and user-access processing performed on Customer’s behalf are covered by this DPA. The same identifier may be used in separate activities with different roles; a label such as account information or telemetry does not alone determine the role or remove applicable protections. This exclusion does not permit Airbrx to treat Customer’s SQL, query results, or identifiable query-activity records as its own independent dataset.

2. Instructions and authorized purposes

Airbrx will process Customer Personal Data only on documented instructions from Customer, consisting of this DPA, the Agreement, its schedules, authorized configurations and requests, and other written instructions agreed within the Service’s scope. Schedule 1 specifies the processing operations and purposes. Airbrx will not repurpose the data for unrelated advertising, resale, profiling, or general-purpose AI-model training.

Airbrx will promptly inform Customer if an instruction appears to violate Applicable Data Protection Law and may suspend the affected processing while the issue is resolved. If a law binding on Airbrx requires other processing, Airbrx will notify Customer before processing unless legally prohibited, restrict the processing to what is required, and comply with applicable transfer safeguards. Nothing in this provision authorizes a disclosure prohibited by Applicable Data Protection Law.

Customer is responsible for its lawful basis, required notices, the scope and accuracy of its instructions, and ensuring that it is entitled to provide the data. Airbrx remains responsible for its own statutory and contractual duties. Each party will promptly advise the other if it cannot meet its obligations for the agreed processing.

Customer may connect its own AI client or other tool through Airbrx’s MCP integration. Authorized tool requests and return of permitted data to that client are Customer’s instructions. Customer determines and contracts for any independently selected AI provider and is responsible for its processing and any resulting transfer requirements. Such a provider does not become Airbrx’s subprocessor merely by receiving Customer-authorized MCP responses. Airbrx remains responsible for its own processing, access enforcement, and any provider it engages to perform its obligations.

3. Personnel and security

Airbrx will limit access to authorized persons who need it to perform the agreed work and are subject to enforceable confidentiality duties or an appropriate statutory duty. Access will be appropriate to their role and removed when no longer needed.

Airbrx will implement and maintain measures appropriate to the risk, considering the data, processing, state of the art, and implementation costs, including the measures and allocations in Schedule 2. It will assess and test relevant safeguards at appropriate intervals and correct identified material weaknesses. Changes must not materially reduce the agreed overall protection.

Customer will implement the controls assigned to it in Schedule 2, including suitable warehouse permissions and cache-sharing rules. That allocation does not excuse Airbrx from securing the components, personnel, or copies it controls.

4. Subprocessors

Customer authorizes only the initial subprocessors identified in Schedule 3, for its stated scope and subject to its requirements for documenting applicable downstream processing. Airbrx will provide their legal identities, services, data access, and processing locations. Listing a provider on a public privacy page alone does not constitute authorization under this DPA.

Airbrx may propose an additional or replacement subprocessor with at least 30 days’ advance written notice to Customer’s designated contact, describing the proposed processing. Customer may object during that period on reasonable data-protection grounds. Airbrx will not give the proposed subprocessor Customer Personal Data before the notice period expires or while a timely objection remains unresolved.

The parties will work in good faith on an alternative. If no reasonable solution is available, either party may terminate the affected Service before the proposed processing begins; Airbrx will refund prepaid subscription fees for its unused portion. Until then, Airbrx must continue with the existing lawful arrangement or suspend the affected processing if it cannot do so safely or lawfully. This procedure does not permit an undisclosed emergency substitution.

Airbrx will assess each subprocessor’s ability to protect the data, enter into a binding agreement imposing equivalent applicable processing protections, and remain responsible to Customer for the subprocessor’s performance of those obligations. Customer-selected warehouses and storage are classified according to the actual relationship and processing role; a customer-owned account does not automatically resolve whether a provider is a subprocessor.

5. Requests, assessments, and assistance

Airbrx will promptly forward requests it receives from individuals concerning Customer Personal Data and will not respond substantively except on Customer’s instructions or as required by law. Taking account of the processing, Airbrx will provide reasonable technical and organizational assistance for Customer to fulfill access, correction, deletion, restriction, portability, objection, and other applicable rights requests within legal deadlines.

Airbrx will also provide assistance required by law with security obligations, breach notifications, impact and risk assessments, and consultation with regulators, taking account of the processing and information available to Airbrx. Customer must give sufficient information and instructions to identify the relevant records without unnecessarily disclosing additional personal data.

Routine assistance is included in the Service. Any fees for exceptional additional work must be agreed in advance and permitted by law; they cannot prevent timely mandatory assistance. Airbrx will not charge Customer for remediation or assistance required because of Airbrx’s own breach.

6. Personal data breaches

Airbrx will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data in Airbrx’s or its subprocessors’ control. Notice will be sent to the incident contact in Schedule 1 and, if necessary, the account administrator. Airbrx will not wait for a completed investigation to give the initial notice.

As information becomes available, Airbrx will describe the nature of the incident, affected data and individuals and approximate numbers where known, likely consequences, containment and remedial steps, and a contact for follow-up. It will provide material updates, preserve appropriate evidence, take reasonable steps to contain and remedy the incident, and cooperate with Customer’s response.

Customer determines notifications to individuals and authorities for which it is responsible. Airbrx will not make such notifications on Customer’s behalf without instructions unless legally required; where permitted, it will coordinate with Customer first. Notification is not an admission of liability. Unsuccessful attempts that do not compromise Customer Personal Data are not themselves a personal data breach.

7. Information and audit rights

Airbrx will provide information reasonably necessary to demonstrate compliance with this DPA and permit and contribute to audits, including inspections, by Customer or an independent auditor acting for it. Existing relevant documentation and assurance reports may be used first where sufficient; this does not represent that any certification or report already exists.

Ordinary audits should use reasonable advance notice, business hours, confidentiality protections, and measures to protect other customers and avoid unnecessary disruption. These arrangements must not prevent an audit required by law, a regulator, a material incident, or reasonable evidence of noncompliance. They do not restrict a regulator’s powers.

Each party bears its ordinary participation costs. Extra services outside required cooperation require advance agreement. Airbrx bears the reasonable costs of correcting its noncompliance and will provide a remediation plan for material findings. Customer may take reasonable, appropriate steps to stop and remedy unauthorized processing.

8. Locations and international transfers

Schedule 3 identifies the authorized hosting locations and the procedure for documenting permitted support, administrative, and downstream access. Customer authorizes only processing within that documented scope, subject to applicable law. A storage region does not by itself establish the location of all processing or remote access.

Schedule 5 incorporates the applicable Standard Contractual Clauses (“SCCs”) and UK or Swiss provisions when this DPA is validly accepted and the instrument applies. Before a restricted transfer, the parties must supply the required exporter information, assess the transfer, and implement any necessary supplementary measures. Neither use of the Service nor a subprocessor’s certification establishes Airbrx’s participation in a transfer framework.

The parties will preserve the accepted instruments and their completed annex information without altering mandatory protections. Airbrx will provide information and cooperation reasonably necessary for the relevant transfer assessment and will impose required safeguards on onward transfers. It will notify Customer if it cannot maintain those safeguards and suspend affected transfers until lawfully resolved.

Airbrx will assess government demands, challenge unlawful demands where there are reasonable grounds to do so, disclose no more than legally required, and give notice to Customer to the extent permitted. Applicable mandatory transfer clauses prevail over conflicting provisions of the Agreement, including law, venue, audit, and liability provisions.

9. Retention, return, and deletion

Airbrx will retain Customer Personal Data only for the agreed processing period and lawful purposes in Schedule 4. On Customer’s instruction or the end of the relevant processing, Airbrx will, at Customer’s choice, return the remaining data in the agreed reasonably usable format or delete it, and delete remaining copies after return, subject only to lawful retention requirements and the agreed, legally permissible backup retirement process.

Schedule 4 sets the active-system deadlines and maximum retirement period for backups, replicas, and historical versions. Pending retirement, residual copies must be isolated from routine use, protected, and accessed only for a permitted recovery or legal purpose. If restored, the applicable deletion instructions must be reapplied. Technical locks or default infrastructure settings do not independently authorize extended retention.

Where retention is required by law, Airbrx will identify the basis and affected records to Customer unless prohibited, minimize the retained data, protect it, and delete it when that requirement ends. Expired credentials will not continue to be used merely because their stored records remain. Credential revocation, cache invalidation, and physical deletion are distinct operations.

For customer-controlled storage, the parties will carry out the deletion and access-removal responsibilities assigned in Schedule 4. Airbrx must still remove copies it controls. Airbrx will obtain corresponding subprocessor performance and, on request, confirm completion of agreed deletion in writing, identifying any remaining lawful retention or scheduled backup retirement.

This DPA remains effective for as long as Airbrx or a subprocessor retains Customer Personal Data. No omitted Order detail authorizes indefinite retention or processing outside the agreed scope.

10. California processing

Where the CCPA applies, Customer discloses Customer Personal Data only for the specific business purposes in Schedule 1. Airbrx acts as a service provider or contractor and certifies that it understands and will comply with the applicable restrictions.

Airbrx will not sell or share the data; retain, use, or disclose it outside the specified purposes or direct business relationship; or combine it with data from other customers or its own consumer interactions, except where expressly permitted by the CCPA. Airbrx will provide the same level of protection the CCPA requires, maintain reasonable security, support applicable consumer requests and compliance assessments, and impose corresponding terms on subcontractors.

Customer may take reasonable, appropriate steps to verify compliance and, on notice, stop and remediate unauthorized use. Airbrx will promptly notify Customer if it determines that it can no longer meet its CCPA obligations. These protections apply only where consistent with more protective restrictions elsewhere in this DPA.

11. Liability and amendment

The Agreement’s allocation of liability applies between the parties, subject to mandatory law and any binding transfer clauses. Nothing limits an individual’s statutory rights, a regulator’s powers, or liability that cannot lawfully be limited. No audit, customer instruction, or shared-responsibility provision shifts Airbrx’s nonwaivable duties to Customer.

Changes to this DPA require agreement by authorized representatives, except subprocessor changes made under Section 4. Operational schedule changes may be agreed in writing, but cannot reduce mandatory protections. A privacy-policy or website update does not amend this DPA.

Schedule 1 — Parties and processing description

The accepted Order supplies Customer’s legal identity, address, authorized representative, and designated contacts. Those entries form part of this schedule without being repeated here. An authorized representative may update a contact by written notice without changing the processing scope.

ItemAgreed description
AirbrxAirbrx, Inc., trading as Airbrx. Legal address: 68685 E Huckleberry Dr, Welches, OR 97067, United States. Mailing address for correspondence and notices: 3300 NW 185th Ave, #343, Portland, OR 97229, United States. Privacy contact: Privacy Team, privacy@airbrx.ai. Security contact: Security Team, security@airbrx.ai.
CustomerThe legal entity, trading name if different, registered or principal address, and registration number if applicable identified in the accepted Order.
RolesCustomer acts as controller/business for its own data and as processor for data processed on an upstream controller’s behalf. Airbrx acts as processor/subprocessor. Customer identifies any upstream controller and relevant additional instructions in the Order or a written processing instruction before the affected processing.
Agreement and effective dateThe service agreement and Order that expressly incorporate DPA version 2026-09-23. The effective date is the date of the last party’s acceptance of that Order, unless the Order states a later date.
Customer privacy and incident contactsThe designated privacy and security contacts in the Order. If separate contacts are not designated, Customer’s authorized business contact is both contacts, with the account administrator as an additional incident recipient. Customer must keep these contact channels current.
Airbrx responsibility and escalationThe CTO oversees security, access, key management, and incident response; the CEO is the escalation contact if the CTO is unavailable. Privacy and security mailboxes route matters to the responsible team.
Subject matter and durationProvision of the selected warehouse gateway and related functions throughout the Service period, followed by limited return, deletion, and lawful retention under Schedule 4.
OperationsReceive and transmit authorized warehouse and MCP requests; authenticate users; execute authorized requests and collect results; cache and serve permitted results; apply cache and invalidation rules; record and report query activity; troubleshoot; secure the Service; and return or delete records. Optional monitoring checks running warehouses.
PurposesFulfill Customer’s requests; reuse eligible query results for Customer; provide Customer’s activity and usage reports; resolve support issues; and maintain the security and reliability of those operations. No unrelated advertising, resale, profiling, or general-purpose model training is authorized.
Enabled functionsOnly functionality purchased in the Order and enabled by Customer’s authorized configuration. Monitoring credential storage requires Customer to enable that option. MCP access is limited to the configured tools and permissions; Customer supplies any connected AI client or provider. Background cache refresh and future warehouse redirection are outside this version’s agreed scope.
Data subjectsCustomer’s users, employees, and contractors; and individuals represented in Customer’s permitted warehouse data, including customers, prospects, suppliers, and their personnel, as applicable to the selected datasets.
Data categoriesNames, email addresses, profile images where supplied, identity-provider and user/tenant identifiers; connection and authentication information; SQL and parameters; query results and selected business-record fields; query IDs, timestamps, performance and usage metrics, errors, and support records. Warehouse fields are limited to Customer’s authorized queries and configured access. Materially different categories require a written update before use.
Sensitive dataNo GDPR Article 9 special-category data, criminal-offence data, protected health information requiring a business associate agreement, or payment-card authentication data is authorized by default. Any agreed exception requires a written schedule specifying categories, lawful instructions, access limits, and additional safeguards. Personal data actually received remains protected even if submitted contrary to this restriction.
FrequencyRepeated transfers and processing as authorized users and clients submit requests. Enabled monitoring operates periodically while its credential remains valid and its authorization remains in force; the Service configuration determines the interval.
Customer-directed recipientsCustomer’s connected warehouse and storage accounts and any MCP client or AI provider that Customer independently selects and authorizes. Connection configuration and written instructions identify these recipients and permissions. An Airbrx-engaged provider is not reclassified as Customer-engaged merely because Customer enables a feature.

Schedule 2 — Technical and organizational measures

These are contractual requirements to be maintained for covered processing. They do not assert that Airbrx holds an independent certification or that a particular recovery objective has been agreed.

AreaMeasures and allocation
Hosting and storageAirbrx-managed processing and storage use AWS in us-east-1 (Northern Virginia) and us-west-2 (Oregon). The Service uses S3 for stored objects and service records and AWS compute for gateway, API, and related workloads. AWS IAM, Secrets Manager, KMS, and logging services support operation and protection where applicable. Both regions are authorized; this does not mean every object is replicated or backed up in both. Customer-controlled buckets remain subject to the allocation below.
Personnel and privileged accessUse individually attributable workforce accounts, role-based least privilege, documented access authorization, and MFA for interactive privileged production access. Use restricted workload identities for machine access. Review production privileges at least annually and on material role changes; promptly revoke access when duties end. Personnel with access must have confidentiality obligations and security training.
Tenant and cache boundariesEnforce tenant-aware authorization and configured identity, role, and session boundaries on access to stored results. Customer chooses permitted cache sharing and warehouse access; Airbrx implements those controls and validates changes that affect access. A matching query alone does not authorize access across customers.
EncryptionRequire TLS 1.2 or later on public service connections and encrypted transport across untrusted networks. Encrypt stored Customer Personal Data in Airbrx-controlled S3 using AWS server-side encryption with AES-256 or KMS-backed encryption. Restrict bucket access and block unintended public access. Encrypt credential values persisted in execution or monitoring records at the application layer using AES-256-GCM and the configured encryption key.
Keys and secretsAirbrx’s CTO is responsible for Airbrx-managed keys and secret access. Keep keys separate from encrypted data in restricted secret/configuration storage; grant decryption access only to necessary workloads and authorized personnel. Enable automatic annual rotation for Airbrx-managed symmetric KMS keys that support it. Review application-key access and rotation arrangements at least annually; replace exposed keys promptly and handle affected ciphertext safely. A missing or unusable application encryption key must prevent persistence of a warehouse credential rather than permit plaintext storage. Customer manages keys in customer-controlled infrastructure unless the Order assigns that task to Airbrx.
Request credentialsUse the caller-supplied credential only through the active authorized request cycle, including asynchronous completion and result retrieval. Do not reuse it as a standing credential for later independent queries. Restrict persisted execution state and apply Schedule 4 after completion, cancellation, failure, or abandonment.
Monitoring credentialsStore a credential only when Customer enables monitoring. Encrypt it with the configured key, restrict use to the authorized monitoring purpose, and stop use on expiry, known revocation, or withdrawal of authorization. A credential remaining valid does not override Customer’s disabling instruction. Apply Schedule 4 to the stored record.
Logging and developmentRecord relevant security and operational events with restricted access. Exclude raw credentials from logs; minimize SQL, results, and personal data in diagnostic records. Review code changes, assess dependencies and vulnerabilities, prioritize remediation by risk, and track material issues to resolution. Use synthetic or de-identified development data unless Customer separately authorizes protected production-data use.
RecoveryMaintain documented recovery procedures for configuration and service state needed to resume the Service. Protect any retained recovery copies with access controls and encryption and test recovery procedures at least annually. This DPA does not promise a copy of every query result, cross-region failover, or a recovery-time/recovery-point SLA. Customer retains its authoritative warehouse data and independent backups.
Incidents and assuranceMaintain an incident-response process covering intake, escalation, investigation, containment, evidence preservation, recovery, and Section 6 notifications. Test the response process at least annually. Review these measures at least annually and after material incidents or changes. Support the information, assistance, and audit rights in Sections 5–7.
DeletionEngineering owns the deletion process. Use documented manual or automated procedures covering current objects, saved request state, credentials, historical versions, replicas, and subprocessor records. Verify completion and reapply deletion instructions following recovery. A cache TTL, delete marker, or disabled account alone is not verification of physical deletion.
Customer-controlled systemsCustomer manages its warehouse permissions, users, client configuration, appropriately scoped credentials, and storage lifecycle. Airbrx remains responsible for its own software, personnel, service records, and copies. Before removing Airbrx’s access, the parties coordinate any deletion work assigned to Airbrx.

No additional sensitive-data processing is approved by this schedule. Any exception must specify safeguards before it is enabled.

Schedule 3 — Authorized subprocessors and locations

The following initial providers are authorized upon acceptance of this DPA. A provider’s authorization is limited to its stated function and the data reasonably necessary for that function.

ProviderFunction and dataAuthorized hosting
Amazon Web Services, Inc.Infrastructure, compute, object storage, secret/key management, and operational logging supporting the Service. May process the Customer Personal Data described in Schedule 1 according to the systems using that infrastructure.United States: us-east-1 (Northern Virginia) and us-west-2 (Oregon).
Descope Inc.Authentication performed on Customer’s behalf: name, email, profile image if supplied, identity-provider information, authentication/session identifiers, and relevant login/security records. Warehouse SQL, query results, and warehouse credentials are outside this authorization.The Descope US project region, Northern Virginia on AWS.

Airbrx personnel. Direct support and administrative access by Airbrx personnel is authorized from the United States. Any additional country must be identified in the accepted Order or agreed in writing before access, with applicable transfer safeguards. This is a contractual location restriction, not an assertion that every current worker’s location has been independently checked.

Vendor access and downstream providers. A US hosting region is not a promise that every vendor support or delivery activity occurs in the United States. The AWS register identifies service-specific infrastructure and support providers. The Descope register identifies US/EU cloud infrastructure, global Cloudflare delivery/security infrastructure, US/EU Twilio services, and support affiliates in the US, UK, Australia, India, and Israel. These registers describe possible vendor processing, not a finding that all listed providers receive Airbrx data.

Before covered processing, Airbrx will document and make available to Customer the applicable downstream providers, access countries, functions, and safeguards for its selected vendor configuration. Any applicable global-delivery footprint must be expressly described; a country left unspecified is not automatically authorized. Airbrx will not submit Customer Personal Data into optional vendor support or other functions outside that documented scope. Changes affecting covered processing follow Section 4, including required notice and objection handling. A later change to a vendor webpage alone does not expand Customer’s authorization.

Cloudflare, Azure, and Google Cloud Storage are not authorized as direct Airbrx subprocessors by this schedule. A vendor’s separately documented downstream use of one of them is a distinct relationship. Independently Customer-selected warehouses, storage, MCP clients, and AI providers are handled under Schedule 1 and Section 2.

Subprocessor notices go to Customer’s Schedule 1 privacy contact. Airbrx will maintain the vendor contracts and processing inventory needed to support this schedule and provide relevant information under Section 7.

Schedule 4 — Retention, return, and deletion

“Deletion Trigger” means the end of the relevant Service, Customer’s valid instruction to delete the relevant data, or the end of the authorized processing purpose, whichever occurs first. Applicable law, a binding transfer clause, or an expressly agreed shorter period may require earlier action. Deadlines run from that trigger, not from the time an internal deletion job is opened.

Data or activityDuring the ServiceRequired disposition
Hosted query-result cachesRetain only while needed to provide Customer’s configured cache service and in accordance with its instructions and applicable storage lifecycle. Cache freshness and eligibility are separate from physical object retention.Stop ordinary serving/use when authorization ends. Delete active objects within 60 days of the Deletion Trigger; remove residual copies within the 90-day absolute limit below.
Query logs and customer-specific reportsRetain while reasonably needed for Customer’s enabled reporting and troubleshooting during the Service. Customer may instruct deletion or a shorter retention period. No independent cross-customer reuse is authorized.Delete active records within 60 days of the Deletion Trigger; residual limit 90 days. This row covers identifiable query activity even if called telemetry.
Execution state and request credentialsMaintain as needed through the active request cycle. On completion, cancellation, failure, or a determination of abandonment, stop using the credential for that request.Remove the credential-bearing active execution record or irreversibly erase its credential field within 7 days of that event, or sooner if required by a deletion instruction or security response. Any noncredential records follow the applicable row above. Inaccessible residual ciphertext remains subject to the 90-day limit.
Optional monitoring credentialsRetain only while monitoring is enabled, the credential is valid, and Customer’s instruction remains in force.Stop use immediately on disabling or withdrawal of authorization, expiry, or known revocation. Remove active credential records within 7 days of that event. Residual ciphertext is subject to the 90-day limit measured from the same event.
Customer-directed identity and access recordsRetain only while needed to authenticate authorized users and manage the relevant access. A user may have separately authorized access for more than one customer.Revoke the affected access promptly when instructed. Remove Customer-specific records from Airbrx and instruct Descope’s corresponding deletion within 60 days of the Deletion Trigger. Preserve only separately authorized records needed for a different active relationship; remove the terminated Customer’s associations and data. Apply the residual limit to the terminated Customer’s data.
Support, diagnostic, and security records containing Customer Personal DataRetain only for the relevant support/security purpose. Security-only events may be retained for up to 365 days from creation during the Service. Do not use that period to extend query-content or credential retention.Delete or effectively anonymize the covered personal data within 60 days of the Deletion Trigger, even if an ordinary log-retention setting is longer. Residual limit 90 days. Separately required legal retention is governed by the final row.
Backups, replicas, object versions, and other residual copiesKeep only copies necessary for authorized resilience or operation. Replicas available for normal use count as active systems. An ordinary historical version is not exempt merely because a delete marker hides it.Delete or render irreversibly inaccessible all residual copies no later than 90 days after the applicable Deletion Trigger. This is an overall limit, not 90 additional days after the active-data deadline. During retirement, isolate copies from ordinary use; permit only necessary recovery or legal handling; reapply deletions after restoration.
Customer-controlled storageCustomer establishes its lifecycle and remains responsible for objects it controls. The Order or written instructions may assign specified deletion work to Airbrx.Airbrx performs assigned work within the agreed access window, reports completion or failures, and removes its own copies on this schedule. Customer then removes access and performs any remaining storage deletion. Lack of access does not authorize Airbrx to retain its own copies.
Subprocessor copiesAirbrx must instruct and oversee corresponding processing and deletion at AWS, Descope, and any later authorized provider.The applicable deadlines above cover the subprocessor chain. Terminating one Customer’s Service does not depend on Airbrx terminating its entire vendor account. Airbrx must obtain operationally supported arrangements for individual-customer deletion and residual retirement.
Return at terminationCustomer may request a return of data still available during the first 30 days after termination. An earlier deletion instruction prevails.Provide the available data through secure delivery within the 60-day active-data window: stored result objects in their maintained format and available configuration/log records in JSON, CSV, or another mutually agreed usable format. Do not export warehouse credentials. Manual assistance may be used; this is not a promise of a self-service export feature. Delete remaining copies on the deadlines above.
Records required by lawNo blanket seven-year or other extended retention exception is agreed.If a binding law requires retention, identify the affected records, legal basis, and duration unless prohibited, restrict use to that requirement, and delete within 30 days after it ends unless law requires earlier deletion. Internal policy, evidentiary convenience, a certification target, or a technical storage lock is not by itself a legal retention requirement.

Airbrx will provide written confirmation on request, identifying completed active deletion, any residual-copy retirement still underway and its deadline, and any specific legally required exception. Records already deleted under the authorized lifecycle need not be reconstructed for return. Truly anonymized information is outside this DPA only if it is no longer personal data under applicable law and its creation and use otherwise comply with the Agreement.

Schedule 5 — International transfer arrangements

A. Applicability and acceptance

Customer is the exporter and Airbrx, Inc. is the importer for Customer Personal Data sent to Airbrx in the United States under this DPA. Transfers are repeated for the purposes, data, individuals, and duration in Schedule 1, with retention under Schedule 4 and onward processing limited by Schedule 3. Customer records its applicable transfer jurisdiction and any additional exporter information in the Order.

The instruments below are incorporated by reference and accepted together with this DPA when legally applicable. They are not executed merely by preparing or publishing this text. Their mandatory provisions prevail over conflicting terms, including the Agreement’s liability limits. If an instrument cannot lawfully cover a transfer, the parties must establish another valid mechanism before that transfer; this schedule does not deem the deficiency cured. No Airbrx Data Privacy Framework certification is represented.

B. EU/EEA transfers

Where required and legally available, the parties incorporate the unmodified clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, available through the Commission’s publications, with these selections:

SelectionAgreed entry
ModuleModule 2 where Customer is controller; Module 3 where Customer is processor. Each applies separately to the relevant processing. Modules 1 and 4 do not apply.
Clause 7Optional docking clause applies.
Clause 9(a)Option 2: general written authorization; advance notice period 30 days, with Section 4’s objection procedure.
Clause 11Optional independent dispute-resolution provision does not apply.
Clause 17Option 1; Irish law.
Clause 18(b)Courts of Ireland, without restricting individuals’ rights under Clause 18(c).
Annex I.AParties, contacts, roles, and activities: Schedule 1. Acceptance of the incorporating Order constitutes the parties’ signatures and dates.
Annex I.BSchedule 1’s processing and transfer description and Schedule 4’s retention limits; subprocessing purpose and duration follow Schedule 3 and the Service period.
Annex I.CCustomer’s competent supervisory authority under Clause 13, identified by name in the Order before an EU transfer. Irish governing law does not itself select that authority.
Annex IISchedule 2 and the assistance measures in Sections 5–7.
Subprocessor informationSchedule 3 supplies the agreed register for Clause 9. Annex III is not separately required under the selected general authorization option.

The parties must check the instrument’s scope, including whether Airbrx’s relevant processing is already subject to GDPR Article 3. This schedule does not expand the permitted scope of Decision 2021/914. The Commission’s guidance describes this limitation.

C. United Kingdom transfers

For restricted transfers under UK law, the parties incorporate the ICO International Data Transfer Addendum, version B1.0, in force 21 March 2022, including its Part 2 mandatory provisions as revised under that instrument. Its Part 1 is completed as follows:

TableAgreed entry
1 — PartiesExporter: Customer; importer: Airbrx. Party details, registration numbers if applicable, key contacts, and acceptance are supplied by Schedule 1 and the accepted Order. Start date: DPA effective date.
2 — SCCsDecision 2021/914 clauses with the modules and choices in Part B above. Module 4’s combining-data question is not applicable.
3 — AppendixAnnex I.A and I.B: Schedule 1 and Schedule 4; Annex II: Schedule 2; subprocessor information: Schedule 3.
4 — ChangesBoth importer and exporter may exercise the termination right under Section 19 of the UK Addendum, subject to its conditions.

The UK instrument’s rules determine supervision, governing law, courts, and precedence for UK transfers. No different UK jurisdiction is selected here.

D. Switzerland transfers

For Swiss transfers requiring contractual safeguards, Part B applies with these adaptations for processing governed by the Swiss Federal Act on Data Protection (“FADP”): GDPR references mean the FADP; the FDPIC is the competent supervisory authority; Clause 17 is governed by Swiss law; and Clause 18(b) designates the competent courts of Zurich, Switzerland. References to a Member State must permit Swiss residents to enforce rights in their habitual-residence courts under Clause 18(c). Where both EU and Swiss law apply, the EU regime remains unchanged for EU-law processing and the Swiss adaptations apply to Swiss-law processing. These adaptations follow the FDPIC’s recognized-clause framework.

E. Assessment and onward transfers

Before relying on a transfer instrument, the parties will document the necessary assessment of the actual transfer, destination law and practices, access risks, and measures. Airbrx’s privacy/security team supplies information about architecture, vendors, government-demand handling, and technical measures; Customer supplies the relevant data and exporter context. Reassess after material changes or information affecting the assessment. Signing a DPA does not itself complete that assessment.

Measures include Schedule 2’s encryption, controlled access, minimization, and separation of keys and data, together with Section 8’s government-demand safeguards. The Service requires authorized access to readable requests and results; ordinary transport or storage encryption does not establish that Airbrx or a hosting provider can never access plaintext. The assessment must address this operational reality and any additional safeguards needed for the particular transfer. Suspend a transfer if adequate safeguards cannot be maintained.

AWS and Descope require their own binding downstream arrangements and, where applicable, transfer instruments. Customer–Airbrx SCCs do not by themselves bind an unsigned vendor or validate all downstream transfers. For other jurisdictions, agree the applicable mechanism before restricted processing begins.

Acceptance

This DPA, version 2026-09-23, and Schedules 1–5 are accepted through an Order that expressly incorporates them and records both parties’ authorized acceptance. That record supplies the parties’ signature and date information for the incorporated instruments. Airbrx will preserve an accessible copy of the accepted DPA, Order, applicable standard instruments, and any agreed processing amendments.

A website visit, an individual user’s general Terms acknowledgment, or this text alone does not establish organizational acceptance. Customer-specific information required by Schedule 1 or Schedule 5 must be supplied before the affected processing begins.

Contact

Data-processing and privacy requests: privacy@airbrx.ai. Legal notices: legal@airbrx.ai.

Airbrx, Inc.
Mailing address: 3300 NW 185th Ave, #343
Portland, OR 97229, United States

Related. The Privacy Policy describes Airbrx’s information practices, the Security & data handling page describes the mechanics and deployment-dependent controls, and the Terms of Service set out the overall agreement this DPA supplements.