Material changes in this version are effective September 13, 2026 for new Customers and October 14, 2026 for existing Customers. The previous version applies to existing Customers through October 13, 2026.

Data Processing Addendum

Last Updated: September 13, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between the entity identified as “Customer” in the Agreement (“Customer”) and BuildFetch Inc. (“BuildFetch” or “Processor”). Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Definitions

  • “Personal Data” means any information that constitutes personal data, personal information, or analogous regulated information under applicable Data Protection Laws and that is Processed by BuildFetch on behalf of Customer in connection with the Services.
  • “Processing” (and “Process”) means any operation or set of operations performed on Personal Data, whether or not by automated means.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, to the extent such event is regulated as a personal data or personal information breach under applicable Data Protection Laws.
  • “Sub-processor” means any third party engaged by BuildFetch to Process Personal Data on behalf of Customer.
  • “Services” means the Cloud Services provided by BuildFetch under the Agreement.
  • “Customer Data” has the meaning set forth in the Agreement and may include Personal Data.
  • “Data Protection Laws” means all data protection and privacy laws and regulations applicable to the Processing under this DPA, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, CCPA/CPRA, and other applicable U.S. state privacy laws.
  • “SCCs” means the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.

2. Scope and Roles

2.1 This DPA applies to Processing of Personal Data by BuildFetch on behalf of Customer in connection with the Services.

2.2 Customer acts as a controller or processor of Personal Data, as applicable. BuildFetch acts as Customer’s processor or subprocessor, as applicable. Where applicable under U.S. state privacy laws, BuildFetch acts as a service provider or contractor with respect to Personal Data Processed on Customer’s behalf.

2.3 This DPA applies to Personal Data Processed through beta, preview, experimental, early access, evaluation, or similar Services to the same extent that it applies to generally available Services.

2.4 This DPA does not apply to information that has been irreversibly de-identified or aggregated such that it no longer constitutes Personal Data under applicable Data Protection Laws. BuildFetch will not attempt to re-identify such information where prohibited by applicable law.

3. Subject Matter, Nature, Purpose, and Duration of Processing

3.1 Subject matter. Processing of Personal Data in connection with Customer’s use of the Services.

3.2 Nature and purpose. BuildFetch will Process Personal Data solely as necessary to provide, operate, secure, maintain, troubleshoot, and support the Services, including hosting, storage, transmission, caching, analysis necessary for service operation, authentication, security, and related technical operations, and as otherwise documented in the Agreement or Customer’s lawful instructions.

3.3 Duration. BuildFetch will Process Personal Data for the Term of the applicable Subscription and thereafter only as necessary to comply with applicable law, complete permitted deletion or return activities, or as otherwise set forth in this DPA.

3.4 Lifecycle instructions. Customer instructs BuildFetch to retain, overwrite, delete, or otherwise manage Personal Data in accordance with the Agreement, applicable Subscription Plan, published documentation, Customer-configured settings, and the ordinary operation of the Services. Customer acknowledges that Personal Data may therefore be deleted before termination of the Agreement where permitted by those instructions and that deletion of Personal Data in accordance with such instructions does not constitute a breach of this DPA.

4. Categories of Personal Data and Data Subjects

4.1 Categories of Personal Data. Personal Data contained in Customer Data may include identifiers such as names, usernames, email addresses, IP addresses, authentication data, metadata, logs, technical data, and other content Processed through the Services.

4.2 Categories of Data Subjects. Customer’s employees, contractors, authorized Users, and other personnel (collectively, “Customer Personnel”) whose Personal Data is included in Customer Data; and other individuals solely to the extent their Personal Data is incidentally included in Customer Data pending removal in accordance with Section 4.3.

4.3 Restricted data. The Services are not intended for Customer to use to Process Personal Data relating to individuals other than Customer Personnel. Customer will not intentionally submit, store, transmit, or otherwise Process such Personal Data through the Services. If Customer becomes aware that such Personal Data has been incidentally included in Customer Data, Customer will promptly use available controls in the Services to delete or otherwise remove it. If Customer cannot reasonably do so through the Services, Customer will promptly notify BuildFetch at [email protected] and provide information reasonably sufficient to identify the affected Customer Data. Such notice constitutes a deletion request under Section 12.

BuildFetch does not undertake to inspect, monitor, or classify Customer Data to identify such Personal Data. Unless BuildFetch receives notice under this Section or otherwise becomes aware that particular Customer Data contains such Personal Data, BuildFetch may Process that Customer Data in accordance with Customer’s documented instructions and the ordinary operation of the Services, subject to this DPA.

Customer will not submit, store, transmit, or otherwise Process protected health information subject to HIPAA (“PHI”) through the Services unless (a) BuildFetch and Customer have executed a Business Associate Agreement (“BAA”) applicable to the relevant Services, and (b) Customer uses only those Services, configurations, and features that BuildFetch identifies as eligible for Processing PHI. Unless both conditions are satisfied, BuildFetch does not agree to provide the Services as a HIPAA business associate, Customer is not authorized to provide PHI through the Services, and the Services are not intended for PHI. This DPA does not constitute a BAA. Unless expressly agreed by BuildFetch in writing, Customer also will not intentionally provide cardholder data or sensitive authentication data subject to PCI DSS, or other Personal Data subject to sector-specific requirements that impose obligations on BuildFetch beyond those expressly accepted under the Agreement or this DPA.

5. Obligations of BuildFetch

BuildFetch shall:

(a) Process Personal Data only on documented instructions from Customer, including the Agreement, this DPA, applicable Subscription Plans, published documentation, Customer-configured settings, and Customer’s lawful use of the Services, unless otherwise required by applicable law;

(b) if applicable law requires BuildFetch to Process Personal Data other than on Customer’s documented instructions, inform Customer before such Processing unless the law prohibits such notice;

(c) where required by applicable Data Protection Laws, immediately inform Customer if, in BuildFetch’s opinion, a documented instruction from Customer infringes applicable Data Protection Laws;

(d) ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations;

(e) implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage;

(f) assist Customer, taking into account the nature of the Processing and information available to BuildFetch, with data subject requests and with Customer’s obligations under applicable Data Protection Laws to the extent required by law;

(g) notify Customer of a Personal Data Breach in accordance with Section 10 and provide reasonable information and cooperation to assist Customer in investigating, mitigating, and responding to the Personal Data Breach;

(h) upon termination or expiration of the Agreement or upon Customer’s valid deletion request, at Customer’s election, delete or return Personal Data then remaining in BuildFetch’s possession or control as provided in Section 12, except to the extent retention is required by applicable law; and

(i) make available to Customer information reasonably necessary to demonstrate compliance with this DPA and allow for audits as set forth in Section 11.

6. Sub-processors

6.1 Customer provides general written authorization for BuildFetch to engage Sub-processors. BuildFetch maintains a current list of its Sub-processors at https://buildfetch.com/subprocessors.

6.2 BuildFetch shall ensure that each Sub-processor that Processes Personal Data is bound by written data-protection and confidentiality obligations no less protective than those applicable to BuildFetch under this DPA. BuildFetch remains responsible to Customer for the performance of its Sub-processors to the extent required by applicable Data Protection Laws.

6.3 BuildFetch shall provide Customer with at least fifteen (15) days’ prior notice of any intended addition or replacement of a Sub-processor that Processes Personal Data. Customer may object to such change on reasonable data-protection grounds by providing written notice within ten (10) days after notice. The parties will work in good faith to resolve the objection. If they cannot resolve it, Customer may terminate the affected Services before the new Sub-processor begins Processing the affected Personal Data.

7. International Data Transfers

7.1 BuildFetch may transfer Personal Data internationally only where permitted by applicable Data Protection Laws and where any required transfer safeguards are in place.

7.2 EEA transfers. To the extent Customer transfers Personal Data subject to the GDPR to BuildFetch in a country that does not benefit from an applicable adequacy decision and another lawful transfer mechanism is not available, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (Controller to Processor) applies where Customer is a controller; Module Three (Processor to Processor) applies where Customer is a processor. Clause 7 (Docking Clause) applies. Clause 9 uses Option 2 (general written authorization) and the notice period in Section 6.3 applies. The optional language in Clause 11 does not apply. For Clauses 17 and 18, the law and courts of Ireland apply unless the SCCs require another eligible EU Member State based on the circumstances of the transfer.

7.3 SCC annex information. For purposes of the SCCs:

(a) Annex I.A — Parties. Customer is the data exporter and BuildFetch Inc. is the data importer. Customer’s legal name, main address, official registration number (if any), and applicable privacy or legal contact’s name, position, and contact details are those provided in the Agreement, applicable order, Customer account, or other written notice to BuildFetch. Customer shall provide any missing information reasonably required to complete the SCCs or UK Addendum and keep that information current. BuildFetch Inc. is a Wyoming corporation, filing ID 2025-001714727, with an address at 1021 E Lincolnway Suite #8618, Cheyenne, Wyoming 82001, United States. BuildFetch’s contact person is Artem (Tommy) Zinnatullin, CEO of BuildFetch Inc., at [email protected]. Customer acts as controller under Module Two and processor under Module Three; BuildFetch acts as processor under Module Two and subprocessor under Module Three. The relevant activities are the Processing described in Section 3. Each party’s execution or legally binding electronic acceptance of the Agreement or this DPA constitutes its signature and date for Annex I.A.

(b) Annex I.B — Transfer details. The categories of data subjects and Personal Data are described in Section 4. The subject matter, nature, purposes, and duration of Processing are described in Sections 3 and 4. Transfers occur on a continuous or recurring basis during Customer’s use of the Services. Retention is governed by Sections 3 and 12. Where Customer includes special-category or other sensitive Personal Data under applicable Data Protection Laws in Customer Data, the restrictions in Section 4 and safeguards in Section 8 apply. Processing by a Sub-processor is limited to the services described for that Sub-processor in the list referenced in Section 6 and the duration of its engagement.

(c) Annex I.C — Supervisory authority. The competent supervisory authority is determined under Clause 13 of the SCCs: the authority for Customer’s EU establishment; if Customer has no EU establishment, the authority for Customer’s Article 27 representative; or, where applicable under Clause 13, the authority in the Member State where affected data subjects are located.

(d) Annex II — Security measures. The technical and organizational measures applicable to the transfer are described in Section 8, including the assistance measures in Section 8.13.

(e) Annex III — Sub-processors. Annex III does not apply. Clause 9 Option 2 applies under Section 7.2, and Sub-processors are governed by Section 6 and the Sub-processor list referenced there.

7.4 United Kingdom. For transfers subject to the UK GDPR that require a restricted-transfer mechanism, the SCCs are incorporated into this DPA for purposes of the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (the “UK Addendum”), whether or not the GDPR otherwise applies to the transfer, using the applicable module and selections specified in Section 7.2 and the annex information in Section 7.3. The SCCs apply together with the UK Addendum. For Part 1 of the UK Addendum:

(a) Table 1. The parties and key contacts are identified in Section 7.3(a). The start date is the date the UK Addendum first applies to the relevant restricted transfer under this DPA.

(b) Table 2. The applicable SCC modules and selections are specified in Section 7.2.

(c) Table 3. The appendix information is provided in Section 7.3 and the technical and organizational measures in Section 8.

(d) Table 4. Neither party may terminate the UK Addendum under Section 19 solely as a result of changes to the Approved Addendum.

Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

The UK Addendum controls to the extent of any conflict concerning a restricted transfer subject to the UK GDPR.

7.5 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection (“FADP”) that require contractual safeguards, the SCCs apply with the following adaptations: (a) the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) is the competent supervisory authority for transfers governed by the FADP and, where the GDPR also applies, acts in parallel with the competent EU supervisory authority identified under Section 7.3(c); (b) references to the GDPR are understood as references to the FADP to the extent the relevant transfer is governed by the FADP; (c) “Member State” in Clause 18(c) includes Switzerland so that data subjects habitually resident in Switzerland may bring proceedings in Switzerland; and (d) for contractual claims governed by the FADP, Swiss law applies under Clause 17 and Swiss courts have jurisdiction under Clause 18, while for claims governed by the GDPR the selections in Section 7.2 apply.

7.6 If a transfer mechanism described in this Section is invalidated, replaced, or no longer available, the parties will cooperate in good faith to implement another lawful transfer mechanism as reasonably necessary.

8. Security Measures

8.1 Security Program. BuildFetch shall implement and maintain commercially reasonable administrative, technical, organizational, and physical safeguards appropriate to the nature of the Personal Data and risks of Processing, including the measures described in this Section.

8.2 Access Control. Access to production systems and Personal Data is limited to authorized personnel based on role and operational need, protected by multi-factor authentication for critical systems, periodically reviewed, and revoked when no longer required.

8.3 Encryption and Secret Management. BuildFetch protects communications over public networks using encryption in transit and protects persistent production data and backups using encryption at rest. Cryptographic keys, credentials, and other secrets are access-controlled and managed through secure secret-management processes.

8.4 Tenant Isolation. BuildFetch maintains logical separation between Customers through platform authorization controls that enforce Customer-specific access to Customer Data.

8.5 Logging and Monitoring. BuildFetch maintains logging, monitoring, and alerting for production systems. Engineering controls and practices are used to limit sensitive information in logs, including credentials, secrets, authentication tokens, and Customer artifact contents, and logs are retained in accordance with defined retention periods.

8.6 Secure Development. BuildFetch uses version control, code review, automated testing, and continuous-integration checks, and monitors software dependencies and relevant vulnerabilities. Security-sensitive changes receive additional review as appropriate.

8.7 Incident Response. BuildFetch maintains documented incident-response procedures together with monitoring, on-call, escalation, investigation, and remediation processes.

8.8 Availability and Recovery. BuildFetch uses redundancy, replication, backups, and recovery procedures appropriate to the Services and tests restoration capabilities as appropriate.

8.9 Data Deletion and Retention. BuildFetch uses automated and controlled administrative procedures to delete Personal Data and Customer Data from active systems when no longer required. Residual data in backups and certain operational systems is deleted in accordance with applicable retention schedules.

8.10 Personnel and Supplier Security. Personnel with access to relevant systems are subject to confidentiality obligations and receive appropriate security and privacy awareness. BuildFetch evaluates relevant service providers and Sub-processors for security and compliance considerations.

8.11 Physical and Infrastructure Security. BuildFetch does not operate its own production data centers. Physical, environmental, and infrastructure protections for production systems are provided by cloud and data-center providers selected for the Services.

8.12 Security Review and Improvement. BuildFetch regularly reviews and updates its security measures in light of changes to the Services, technology, identified risks, and relevant security developments. BuildFetch may update the technical and organizational measures described in this Section from time to time, provided that such updates do not materially decrease the overall level of protection afforded to Personal Data under this DPA.

8.13 Assistance Measures. BuildFetch maintains processes to assist Customer with data subject requests, Personal Data Breaches, security obligations, deletion or return of Personal Data, and other compliance assistance required under this DPA, taking into account the nature of the Processing and the information available to BuildFetch.

8.14 Security Information. Upon reasonable request, BuildFetch will provide Customer with a high-level summary of its security measures or relevant third-party certifications, subject to appropriate confidentiality obligations.

9. Data Subject Requests and Assistance

9.1 To the extent legally permitted, BuildFetch shall promptly notify Customer if BuildFetch receives a request from a data subject relating to Personal Data that BuildFetch Processes on Customer’s behalf, unless Customer has authorized BuildFetch to respond directly.

9.2 Taking into account the nature of the Processing, BuildFetch will reasonably assist Customer in responding to such requests to the extent required by applicable Data Protection Laws. Customer is responsible for responding to data subjects where Customer is the applicable controller, unless otherwise required by law.

10. Personal Data Breach Notification

10.1 BuildFetch shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on Customer’s behalf and, where reasonably practicable, within seventy-two (72) hours of becoming aware.

10.2 The notification shall include, to the extent then known and reasonably available, a description of the nature of the Personal Data Breach, the categories and approximate number of affected data subjects and Personal Data records, the likely consequences, and the measures taken or proposed to address the Personal Data Breach. BuildFetch may provide information in phases as it becomes available.

10.3 BuildFetch’s notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability.

11. Audits and Compliance

11.1 Information and Reports. Upon Customer’s reasonable written request, BuildFetch shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA and applicable Data Protection Laws. BuildFetch may satisfy this obligation by providing one or more current summaries of independent third-party audit reports, together with additional information reasonably necessary for Customer to verify compliance, subject to appropriate confidentiality obligations.

11.2 Right to Audit. Where Data Protection Laws grant Customer an audit right, and to the extent information provided under Section 11.1 is not reasonably sufficient, Customer or its designated independent auditor may conduct an audit of BuildFetch’s policies, procedures, and records relevant to Processing under this DPA, subject to the following conditions:

(a) Frequency. Audits may be conducted no more than once in any twelve (12) month period unless required by a competent supervisory authority or reasonably necessary due to a Personal Data Breach affecting Customer Data.

(b) Notice and Timing. Customer shall provide at least thirty (30) days’ prior written notice. The parties will cooperate in good faith on a mutually reasonable date, scope, duration, and security and confidentiality controls. Audits shall occur during normal business hours and minimize disruption.

(c) Independent Auditor. A third-party auditor must be appropriately qualified, independent, not a competitor of BuildFetch, and subject to confidentiality obligations reasonably acceptable to BuildFetch. BuildFetch may reasonably object to an auditor that does not satisfy these requirements.

(d) Scope and Access. The audit shall be limited to what is reasonably necessary to verify compliance with this DPA and shall not include access to production systems, source code, or other customers’ Personal Data except where strictly necessary and agreed in writing in advance.

(e) Cost. Customer bears its audit costs and BuildFetch’s reasonable costs of facilitating a Customer-initiated audit, which BuildFetch will identify in advance where practicable, except to the extent prohibited by applicable law.

(f) Findings. Customer shall provide BuildFetch with a written summary of material findings. Information obtained through an audit is BuildFetch Confidential Information.

11.3 Remediation. If an audit reveals material non-compliance with this DPA, BuildFetch shall take appropriate remedial action within a reasonable timeframe.

12. Deletion and Return of Personal Data

12.1 Customer acknowledges and instructs that Personal Data may be deleted, overwritten, or otherwise removed during the Term in accordance with Section 3.4. BuildFetch has no obligation to restore Personal Data deleted in accordance with those documented instructions.

12.2 Upon termination or expiration of the Agreement or upon Customer’s valid written request, BuildFetch will, at Customer’s election, delete or return Personal Data then remaining in BuildFetch’s possession or control and delete active copies after any return. Where return is not available through the ordinary functionality of the applicable Services, BuildFetch and Customer will reasonably cooperate on an appropriate method and format for return to the extent required by applicable Data Protection Laws. In all cases, BuildFetch may retain Personal Data to the extent required by applicable law. BuildFetch will use commercially reasonable efforts to complete the applicable deletion or return within thirty (30) calendar days after the request or termination, subject to the ordinary operation of backup and disaster-recovery systems.

12.3 Personal Data retained only in backups or disaster-recovery systems after deletion from active systems will remain protected under this DPA, will not be used for other purposes, and will be deleted in accordance with BuildFetch’s ordinary backup-retention cycle, unless applicable law requires longer retention.

12.4 Upon Customer’s reasonable request, BuildFetch will confirm completion of deletion or return required under this Section.

13. Term and Termination

This DPA remains in effect for as long as BuildFetch Processes Personal Data on Customer’s behalf under the Agreement. Sections that by their nature are intended to survive, including Sections 5, 7, 10, 11, 12, 14, and 15, survive termination to the extent applicable.

14. Miscellaneous

14.1 In the event of any conflict between this DPA and the Agreement, this DPA controls solely with respect to the Processing of Personal Data on Customer’s behalf.

14.2 Except to the extent superseded by the SCCs or another mandatory transfer mechanism, this DPA is governed by the law specified in the Agreement. Applicable Data Protection Laws continue to apply according to their terms.

14.3 This DPA, together with the Agreement and any incorporated transfer terms or referenced policies, constitutes the agreement between the parties with respect to its subject matter.

14.4 BuildFetch may update this DPA from time to time. For existing Customers, BuildFetch will provide at least thirty (30) calendar days’ prior notice of material changes by email or in-Service notice. Material changes take effect on the date stated in the notice unless Customer affirmatively accepts the revised DPA earlier, in which case the revised DPA takes effect for Customer upon acceptance, except that changes required to comply with applicable law may take effect on the date stated in the notice and Sub-processor changes are governed by Section 6.3. If a material change reduces Customer’s data-protection rights and Customer does not agree to it, Customer may terminate the affected Services before the change takes effect for Customer.

14.5 Except to the extent prohibited by applicable Data Protection Laws or the SCCs, each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement.

15. U.S. State Privacy Terms

To the extent applicable U.S. state privacy law treats BuildFetch as a service provider, contractor, or processor with respect to Personal Data Processed on Customer’s behalf:

(a) Limited purposes. Customer discloses such Personal Data to BuildFetch only for the limited and specified purposes of providing, operating, securing, maintaining, troubleshooting, and supporting the Services, including hosting, storage, transmission, caching, analysis necessary for service operation, authentication, security, and related technical operations. BuildFetch will Process such Personal Data only for those purposes or as otherwise permitted by applicable law.

(b) Use restrictions. BuildFetch will not sell or share such Personal Data, retain, use, or disclose it for an unrelated commercial purpose or outside the direct business relationship with Customer, or combine it with personal information received from or on behalf of another person or collected from BuildFetch’s own interaction with an individual, except as permitted by applicable law.

(c) Privacy protection and assistance. BuildFetch will comply with applicable obligations imposed on service providers, contractors, and processors, provide the level of privacy protection required by applicable law, maintain the safeguards described in Section 8, and assist Customer with applicable consumer requests as provided in Section 9.

(d) Compliance notice. BuildFetch will notify Customer if BuildFetch determines that it can no longer meet an applicable obligation under this Section.

(e) Monitoring and remediation. Customer may take reasonable and appropriate steps permitted by applicable law, including the review and audit mechanisms in Section 11, to verify BuildFetch’s compliance and to stop and remediate unauthorized use of Personal Data.

(f) Subcontractors. Any Sub-processor engaged to Process such Personal Data is subject to Section 6 and applicable requirements of this Section.

(g) CCPA contractor certification. To the extent BuildFetch acts as a contractor under the CCPA, BuildFetch certifies that it understands the restrictions applicable to its Processing of Personal Data under this Section and will comply with them.