DPA

Effective date: 1 October 2026

This Data Processing Addendum ("DPA") is part of the Databar Terms of Service (the "Terms") between Databar, Inc. ("Databar", "we", "us") and the customer that accepted the Terms ("Customer", "you"). It applies whenever Data Protection Laws apply to Personal Data that we process on your behalf in providing the Service. Capitalized terms not defined here have the meanings in the Terms.

1. Definitions

"Customer Personal Data" means Personal Data in Customer Data and in Enrichment Output held in your Workspace, which we process on your behalf. It does not include Personal Data about you and your Permitted Users that we process for our own purposes (which the Privacy Policy covers), or any copy of Third-Party Data we keep for our own purposes (Section 2.3).

"Data Protection Laws" means the laws that apply to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), and "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

"Sub-processor" means a third party we engage to process Customer Personal Data on your behalf.

"Security Incident" has the meaning in Section 16.2 of the Terms.

"Controller", "Processor", "Data Subject", "Personal Data", "processing", "Business", "Service Provider", "sell" and "share" have the meanings in the applicable Data Protection Laws.

2. Roles and scope

2.1 Customer Personal Data. For Customer Personal Data you are the Controller (or Business) and we are your Processor (or Service Provider). Where you act as a Processor for your own client, we are your Sub-processor, you confirm that your client has authorized our engagement, and you are our only point of contact.

2.2 Details of processing. Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects.

2.3 Outside this DPA. This DPA does not apply to Personal Data we process as a Controller. That includes information about your account and users, and any Third-Party Data we keep for our own purposes such as preventing abuse. The Privacy Policy describes that processing and how Data Subjects may exercise rights over it. Data Providers, AI Providers and other services you connect are not Sub-processors; your use of their data or services is governed by the Terms and by their own terms.

2.4 Your obligations. You are responsible for the lawfulness of Customer Personal Data and of your instructions, including for having a lawful basis, giving any notices and obtaining any consents that Data Protection Laws require for the data you submit and the Connectors you run, and for not submitting the categories of data that Section 4.4 of the Terms excludes.

3. Our obligations as Processor

3.1 Instructions. We will process Customer Personal Data only on your documented instructions, which are: the Terms, this DPA, your use of the Service and its features, and any other written instruction we agree to. We may process Customer Personal Data where required by law, in which case we will tell you before processing unless the law prohibits it. If we believe an instruction breaches Data Protection Laws, we will tell you and may suspend that instruction until it is resolved.

3.2 Confidentiality. We will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.

3.3 Security. We will implement the technical and organizational measures described in Annex 2. We may update them from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data. We do not warrant that these measures will prevent all unauthorized access to or use of Customer Personal Data.

3.4 Assistance. Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), primarily through the features of the Service and this DPA. We may charge for assistance beyond that.

3.5 Records and information. On request we will provide the information reasonably necessary to demonstrate our compliance with this DPA, subject to and in the manner described in Section 8.

4. Data Subject requests

If we receive a request from a Data Subject relating to Customer Personal Data, we are not required to respond to it, other than to tell the Data Subject that we process Personal Data on behalf of our customers, unless the law requires otherwise. You are responsible for responding, and the Service's export, edit and delete features are the primary means by which we assist you.

5. Security Incidents

We will notify you without undue delay after we confirm a Security Incident affecting Customer Personal Data, by notice under Section 24.2 of the Terms, with the information we then have. Section 16.2 of the Terms applies. Notification is not an admission of fault. You are responsible for any notification to authorities or Data Subjects that the law requires of you.

6. Sub-processors

6.1 General authorization. You authorize us to engage Sub-processors to provide the Service. Annex 3 lists the categories of Sub-processors we use and the principal providers in each category at the effective date.

6.2 Changes. We may add or replace Sub-processors at any time. We will notify you of a change that materially affects Customer Personal Data by notice in the Service or by updating Annex 3. You may object on reasonable data-protection grounds within 30 days of the notice by emailing info@databar.ai. If you object, your remedy is to stop using the affected feature or to cancel the affected Subscription under the Terms; Section 10.4 of the Terms governs refunds.

6.3 Flow-down. We will impose on each Sub-processor data-protection obligations that are no less protective of Customer Personal Data than those in this DPA, taking into account the nature of the services it provides.

7. International transfers

7.1 Location. We are established in the United States and process Customer Personal Data there and in the other countries where our Sub-processors operate.

7.2 EEA transfers. Where you transfer Customer Personal Data to us from the European Economic Area, and the transfer is not otherwise permitted by an adequacy decision or another valid mechanism, the SCCs are incorporated into this DPA and apply with the following selections: you are the data exporter and we are the data importer; Clause 7 (docking clause) is included; in Clause 9, Option 2 (general written authorization) applies and Section 6.2 sets out how we inform you of changes and how you may object; the optional language in Clause 11 is not included; in Clause 13, the supervisory authority is that of the EU member state in which you are established or, if you are not established in the EU, that of your EU representative or, failing that, the Irish Data Protection Commission; in Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; in Clause 18, disputes are resolved by the courts of Ireland; Annex 1 of this DPA is Annex I of the SCCs, Annex 2 is Annex II, and Annex 3 is Annex III.

7.3 UK transfers. Where you transfer Customer Personal Data to us from the United Kingdom, the SCCs as completed in Section 7.2 apply as varied by the UK Addendum, which is incorporated into this DPA; the parties' details and Annexes are as set out in this DPA, Table 4 of the UK Addendum is completed so that only the data importer may end it as set out there, and any conflict is resolved in favor of the UK Addendum.

7.4 Conflicts. If the SCCs or UK Addendum conflict with the rest of this DPA or the Terms, the SCCs or UK Addendum prevail for the transfer concerned.

8. Audits and information

8.1 Information. We will respond to reasonable written requests for information about our processing of Customer Personal Data and our security measures, no more than once in any 12-month period unless a Security Incident or a supervisory authority requires otherwise. Where we hold a third-party audit report or certification covering the Service, we may provide it, or a summary, under confidentiality in place of further information. This Section 8.1 applies only to customers on a Subscription billed by Databar.

8.2 Audits. Where Data Protection Laws give you a right to audit that written information cannot satisfy, you (or an independent auditor bound by confidentiality and reasonably acceptable to us) may audit our processing of Customer Personal Data once in any 12-month period, on at least 30 days' written notice, during business hours, in a manner that does not disrupt the Service or access other customers' data, and at your expense. We may require a written audit plan, may charge you for our time and costs of supporting the audit, and the results are our Confidential Information. Where we hold a third-party audit report or certification covering the Service, providing it under Section 8.1 satisfies your audit right unless Data Protection Laws require otherwise. Audit rights under this Section 8.2 are likewise available only to customers on a Subscription billed by Databar, not to plans obtained through a partner, marketplace, reseller, promotion, program, free plan or trial (Section 12 of the Terms).

9. Return and deletion

9.1 During the term. You can export, correct and permanently delete Customer Data in the Service at any time, and permanent deletion is irreversible.

9.2 On termination. You are responsible for exporting Customer Data before the Agreement ends or you delete a Workspace. After that, we will delete Customer Personal Data in that Workspace, except to the extent the law requires us to keep it. Residual copies in backups are overwritten in the ordinary course and remain subject to this DPA until then.

10. CCPA and US state laws

To the extent the CCPA or a similar US state law applies to Customer Personal Data, we act as your Service Provider (or Processor or contractor, as those laws define it). We will not sell or share Customer Personal Data; retain, use or disclose it for any purpose other than the business purposes in Annex 1 and as permitted by those laws; retain, use or disclose it outside our direct business relationship with you; or combine it with Personal Data we receive from other sources, except as those laws permit. We will comply with the obligations those laws place on Service Providers and provide the same level of protection they require, will notify you if we determine that we can no longer meet those obligations, and you may take reasonable steps to stop and remediate unauthorized use of Customer Personal Data as those laws provide. We certify that we understand these restrictions.

11. General

11.1 Liability and indemnity. Each party's liability under this DPA, including under the SCCs, is subject to the exclusions and limitations in Section 19 of the Terms, except where Data Protection Laws do not allow that. Your indemnity in Section 18 of the Terms applies to claims arising from your instructions, from Customer Personal Data or from your failure to comply with Data Protection Laws.

11.2 Precedence and changes. Section 24.6 of the Terms governs conflicts between this DPA and the Terms. We may update this DPA under Section 22 of the Terms, including to reflect changes in Data Protection Laws, approved transfer mechanisms or the Service.

11.3 Term. This DPA lasts for as long as we process Customer Personal Data on your behalf.

11.4 Contact. Data-protection requests and notices to us go to info@databar.ai from the Workspace owner's email address.

Databar, Inc.
8 The Green, Ste B, Dover, DE 19901
United States
Email: info@databar.ai
Website: https://www.databar.ai

Annex 1 — Details of processing

Parties. Data exporter: the Customer, a business using the Service, acting as Controller (or as Processor for its own clients). Data importer: Databar, Inc., 8 The Green, Ste B, Dover, DE 19901, United States, acting as Processor. Contact for both purposes: info@databar.ai for Databar; the Workspace owner's email address for the Customer.

Subject matter. The provision of the Service under the Terms: a platform on which the Customer builds, enriches, stores, analyzes and exports business data.

Duration. The term of the Agreement and any period afterwards until Customer Personal Data is deleted under Section 9.

Nature and purpose. Hosting, storage, retrieval, transmission, transformation, enrichment through Connectors the Customer selects (including sending Customer inputs to Data Providers and AI Providers at the Customer's instruction), export to destinations the Customer selects, display to the Customer's users, and related support, security and operation of the Service.

Categories of Data Subjects. Individuals whose data the Customer submits to, imports into or generates in the Service, typically business contacts, prospects, customers, employees and representatives of companies.

Types of Personal Data. Business contact and professional information such as names, job titles, employers, business email addresses and telephone numbers, professional profile links, company information and location; any other Personal Data the Customer chooses to submit. Sensitive or special-category data is excluded by Section 4.4 of the Terms and is not intended to be processed.

Frequency. Continuous, as the Customer uses the Service.

Retention. For the duration in Section 9 of this DPA.

Transfers to Sub-processors. As described in Annex 3, for the purposes stated there, for the same duration.

Competent supervisory authority. As determined under Section 7.2.

Annex 2 — Technical and organizational measures

Databar maintains the following measures for Customer Personal Data, appropriate to the nature of the data and the size of our business. They describe our measures at the effective date; we may update or substitute them under Section 3.3.

Encryption. Connections to the Service are encrypted in transit using TLS 1.2 or higher. Production databases and object storage are hosted on managed cloud services that provide encryption at rest.

Access control. Access to production systems is limited to authorized personnel with individual credentials. Customer-facing access is controlled through Workspace roles, logins and API keys.

Tenant isolation. Customer Data is logically separated by Workspace, and application-level controls are designed to scope requests to the authenticated Workspace.

Logging, monitoring and backups. Application and infrastructure logging, error tracking and operational monitoring are in place. Production databases are hosted on managed services with automated backups.

Personnel and sub-processors. Personnel with access to Customer Personal Data are bound by confidentiality obligations. Sub-processors are engaged under written terms.

Incident response and deletion. Security Incidents are handled under Section 5 of this DPA and Section 16.2 of the Terms. Customer-initiated permanent deletion takes effect at the application layer; residual copies in backups are handled under Section 9.2.

Annex 3 — Sub-processors

Sub-processors at the effective date. The current list is available on request to info@databar.ai. Data Providers, AI Providers and other services that the Customer selects or connects are not Sub-processors (Section 2.3). Providers that process information about the Customer's own account and users, rather than Customer Personal Data, are described in the Privacy Policy.


Category

Provider

Purpose

Primary location

Cloud hosting, databases and object storage

DigitalOcean, LLC

Application hosting, managed database, file storage

United States

Message queue

CloudAMQP (84codes AB)

Background task queuing

United States / EU

Error monitoring

Functional Software, Inc. (Sentry)

Error tracking and diagnostics

United States

Primary locations are the provider regions we have selected at the effective date. Providers may also process data in other locations under their own terms, for example for support or resilience.

Get Started with Databar Today

Unlock the full potential of your data with the world’s most comprehensive no-code API tool. Whether you’re looking to enrich your data, automate workflows, or drive smarter decisions, Databar has you covered.

Get Started with Databar Today

Unlock the full potential of your data with the world’s most comprehensive no-code API tool. Whether you’re looking to enrich your data, automate workflows, or drive smarter decisions, Databar has you covered.