How this Addendum applies
This Data Processing Addendum (the “Addendum”) forms part of the Fyvie AI Terms of Service or, where the parties have entered into a Master Services Agreement or order form that incorporates this Addendum, that agreement (in either case, the “Agreement”), and governs Fyvie AI’s Processing of Customer Personal Data.
This Addendum applies where and to the extent that Fyvie AI Processes Customer Personal Data on Customer’s behalf in the course of providing the Services. It does not apply to Fyvie AI’s Processing of personal data as a controller, which is described in the Fyvie AI Privacy Policy and, in respect of trust and safety, in Section 6 below.
Products that run locally. Fyvie AI products that run locally process data entirely on Customer’s own hardware. Fyvie AI receives no Inputs or Outputs from them and has no access to the data they process, and this Addendum does not apply to that processing.
Acceptance. This Addendum is incorporated into the Agreement by reference and takes effect on the effective date of the Agreement. Where Customer requires a signed counterpart, Customer may execute the version published at this page and return it to legal@fyvie.ai; Fyvie AI will countersign.
Order of precedence. In the event of conflict, the following order applies: (a) the Standard Contractual Clauses and any UK transfer mechanism referred to in Section 14; (b) this Addendum; (c) the Agreement. Section 16 prevails over the remainder of this Addendum in respect of Processing subject to US State Privacy Laws.
Definitions
Capitalised terms not defined here have the meaning given in the Agreement or in Data Protection Law.
“Customer” means the entity that has entered into the Agreement with Fyvie AI.
“Customer Content” means Inputs submitted to the Services by or on behalf of Customer, and Outputs generated by the Services in response to those Inputs.
“Customer Personal Data” means personal data contained within Customer Content or otherwise Processed by Fyvie AI on Customer’s behalf under the Agreement.
“Data Protection Law” means all laws relating to the Processing of personal data applicable to a party, including: the UK GDPR and the Data Protection Act 2018; Regulation (EU) 2016/679 (the “EU GDPR”) and implementing national laws; the Swiss Federal Act on Data Protection; and the US State Privacy Laws.
“EU SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.
“Inputs” means prompts, files, images, audio, code, documents and other content submitted to the Services.
“Outputs” means content generated by the Services in response to Inputs.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
“Services” means the Fyvie AI API, developer platform, and business and enterprise offerings provided under the Agreement.
“Subprocessor” means any processor engaged by Fyvie AI to Process Customer Personal Data.
“UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
“UK IDTA” means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
“US State Privacy Laws” means the California Consumer Privacy Act as amended (the “CCPA”) and the comprehensive consumer privacy laws of other US states, in each case as applicable to the Processing.
“Controller”, “processor”, “data subject”, “Processing”, “personal data”, “special categories of personal data”, “sell”, “share”, “service provider” and “business” have the meanings given in the applicable Data Protection Law.
Roles of the parties
3.1 Processor role. In respect of Customer Personal Data, Customer is the controller (or, where Customer acts as a processor for a third party, the processor) and Fyvie AI is the processor (or subprocessor). Fyvie AI is a “service provider” in respect of Processing subject to the CCPA.
3.2 Customer as processor. Where Customer is itself a processor acting on behalf of a third-party controller, Customer warrants that it has that controller’s authorisation to engage Fyvie AI as a Subprocessor on the terms of this Addendum, and that the instructions it gives Fyvie AI are consistent with that controller’s instructions. References to Customer’s obligations as controller apply to that third-party controller as appropriate.
3.3 Fyvie AI as controller. Fyvie AI acts as an independent controller in respect of: (a) account, contact, billing and administrative data relating to Customer’s personnel; (b) usage data, telemetry and logs generated by Customer’s use of the Services, other than Customer Content; and (c) the trust, safety and security Processing described in Section 6. This Addendum does not apply to that Processing, which is governed by the Fyvie AI Privacy Policy.
3.4 Customer responsibilities. Customer is responsible for: (a) establishing and maintaining a lawful basis for the Processing it instructs; (b) providing all notices and obtaining all consents required from data subjects; (c) the accuracy, quality and legality of Customer Personal Data and of Customer’s instructions; (d) responding to data subject requests received from its own end users; and (e) configuring and using the Services appropriately for the sensitivity of the data it submits, including any available retention, access control and regional configuration options.
3.5 Restricted data. The Services are not designed for, and Customer must not submit, personal data that Customer knows to be: (a) protected health information subject to HIPAA, unless the parties have executed a business associate agreement; (b) payment card data subject to PCI DSS; (c) government-issued identification numbers, financial account credentials, or biometric identifiers used for unique identification; or (d) data subject to sector-specific regimes not addressed in the Agreement. Customer is solely responsible for any such data it submits. This restriction applies to the hosted Services only; it does not restrict the data Customer processes with Fyvie AI products that run locally, which never reaches Fyvie AI.
Processing of Customer Personal Data
4.1 Documented instructions. Fyvie AI will Process Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Fyvie AI is subject. Where such a legal requirement applies, Fyvie AI will inform Customer before Processing unless that law prohibits it on important grounds of public interest.
4.2 Scope of instructions. Customer’s instructions comprise: (a) the Agreement, including this Addendum; (b) Customer’s configuration and use of the Services, including submission of Inputs and requests for Outputs; and (c) any further written instructions agreed by the parties. Fyvie AI will Process Customer Personal Data only to provide, maintain and support the Services in accordance with those instructions.
4.3 Unlawful instructions. Fyvie AI will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law. Fyvie AI may suspend performance of the affected instruction until it is amended or confirmed, without liability for the resulting delay.
4.4 Additional instructions. Instructions falling outside the scope of the Services may be refused, or may be subject to agreement on cost and feasibility. Fyvie AI will not unreasonably withhold agreement to instructions necessary for Customer’s compliance with Data Protection Law.
4.5 Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of personal data and the categories of data subjects are set out in Annex 1.
Model training
5.1 No training on Customer Content. Fyvie AI will not use Customer Content to train, fine-tune, or otherwise develop or improve any machine learning or artificial intelligence model, whether a foundation model, a derivative model, or a classifier, except as expressly set out in Section 5.2.
5.2 Exceptions. Section 5.1 does not apply to: (a) content Customer or its authorised users affirmatively submit to Fyvie AI for a stated purpose that includes model development, such as participation in a research programme, evaluation exercise or red-teaming engagement, where that purpose was disclosed at the point of submission; and (b) aggregated or de-identified data that cannot reasonably be associated with Customer, any data subject, or any individual Input or Output, and which Fyvie AI will not attempt to re-identify.
5.3 Subprocessors. Fyvie AI will impose an equivalent restriction on each Subprocessor and will not authorise any Subprocessor to use Customer Content for model development.
5.4 Survival. This Section 5 survives termination of the Agreement indefinitely.
Trust, safety and security processing
6.1 Independent controller. Fyvie AI Processes limited Customer Content and associated metadata as an independent controller in order to: detect and prevent violations of its Usage Policy and the Agreement; detect and respond to fraud, abuse, security incidents and misuse of the Services; investigate and mitigate serious risks, including risks to physical safety and child safety; and comply with its own legal obligations.
6.2 Basis. Fyvie AI carries out this Processing to meet its own legal obligations and in its legitimate interests in operating a safe and secure platform. It is not carried out on Customer’s instructions, and Customer is not the controller of it.
6.3 Method. This Processing is primarily automated. Human review of Customer Content occurs only where automated systems have flagged a potential violation, or where required to investigate a suspected incident, and is limited to personnel with a need to access the material. Records of enforcement decisions are retained as described in the Fyvie AI Privacy Policy.
6.4 Zero retention. Where a zero data retention configuration has been agreed under Section 15.3, Fyvie AI performs abuse detection through real-time classification without persisting Customer Content, and Section 6.3 is modified accordingly.
Confidentiality
Fyvie AI will ensure that persons authorised to Process Customer Personal Data are subject to an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. Access is limited to personnel who require it to perform Fyvie AI’s obligations under the Agreement.
Security
8.1 Measures. Fyvie AI will implement and maintain the technical and organisational measures set out in Annex 2, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing, and the risks to data subjects.
8.2 Changes. Fyvie AI may update the measures in Annex 2 provided that the updates do not materially reduce the overall level of security.
8.3 Customer’s assessment. Customer is responsible for assessing whether the measures in Annex 2 are appropriate to the risk presented by the personal data it chooses to submit, and for using the security features made available in the Services.
Personal Data Breach
9.1 Notification. Fyvie AI will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
9.2 Content. The notification will describe, to the extent known: the nature of the breach including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the information is not available at once, it will be provided in phases without undue delay.
9.3 Assistance. Fyvie AI will take reasonable steps to mitigate the effects of the breach and will provide Customer with reasonable assistance in meeting Customer’s own notification obligations to supervisory authorities and data subjects.
9.4 No admission. Notification under this Section is not an acknowledgement of fault or liability.
9.5 Contact. Notifications will be sent to the security contact designated in Annex 1. Customer is responsible for keeping that contact current.
Subprocessors
10.1 General authorisation. Customer grants Fyvie AI general authorisation to engage Subprocessors, subject to this Section.
10.2 Current Subprocessors. The Subprocessors engaged as at the effective date are listed in Annex 3. A current list is available on request from privacy@fyvie.ai.
10.3 Terms. Fyvie AI will impose on each Subprocessor data protection obligations that are no less protective than those in this Addendum, including the restriction in Section 5.3, and will remain fully liable to Customer for the performance of each Subprocessor’s obligations.
10.4 Changes. Fyvie AI will give Customer at least 30 days’ notice before a new Subprocessor begins Processing Customer Personal Data, by email to Customer’s contact designated in Annex 1, and will update the on-request list at the same time.
10.5 Objection. Customer may object to a new Subprocessor on reasonable data protection grounds by notifying privacy@fyvie.ai within the notice period. The parties will discuss the objection in good faith. If Fyvie AI is unable to make a reasonable alternative available within 30 days, Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees for the terminated portion of the term.
10.6 Emergency changes. Fyvie AI may engage a new Subprocessor without advance notice where necessary to address a security, availability or legal emergency, and will notify Customer as soon as reasonably practicable.
Data subject requests
11.1 Self-service. The Services provide functionality enabling Customer to access, correct, export and delete Customer Personal Data. Customer will use that functionality to respond to data subject requests in the first instance.
11.2 Assistance. Where Customer cannot fulfil a request through the Services, Fyvie AI will provide reasonable assistance, taking into account the nature of the Processing and the information available to it.
11.3 Requests received by Fyvie AI. If Fyvie AI receives a request from a data subject relating to Customer Personal Data, it will not respond substantively except to confirm that the request should be directed to Customer, and will inform Customer of the request without undue delay unless prohibited by law.
11.4 Cost. Assistance under 11.2 is provided at no charge unless the request is manifestly unfounded, excessive, or repetitive, in which case Fyvie AI may charge a reasonable fee agreed in advance.
Impact assessments and prior consultation
Taking into account the nature of the Processing and the information available to it, Fyvie AI will provide Customer with reasonable assistance in carrying out data protection impact assessments and any prior consultation with a supervisory authority. Fyvie AI’s obligation is satisfied by making available the information in this Addendum, Annex 2, and its security documentation, and by responding to reasonable further enquiries.
Demonstrating compliance and audits
13.1 Documentation. Fyvie AI will make available to Customer the information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR and EU GDPR, comprising: (a) its then-current security documentation and, if and when obtained, third-party certifications and audit reports, subject to a confidentiality undertaking; (b) a completed standard security questionnaire; and (c) responses to reasonable written enquiries relating to the Processing, no more than once per twelve-month period except where required by a supervisory authority or following a Personal Data Breach.
13.2 Satisfaction of audit rights. The parties agree that, save as provided in Section 13.3, the materials and responses provided under Section 13.1 satisfy Fyvie AI’s obligations to allow for and contribute to audits under Article 28(3)(h) of the UK GDPR and EU GDPR, and any equivalent obligation under other Data Protection Law.
13.3 Inspection. Where the materials provided under Section 13.1 are demonstrably insufficient for Customer to comply with a specific obligation under Data Protection Law, or where a supervisory authority requires an inspection, Customer or an independent auditor mandated by Customer and reasonably acceptable to Fyvie AI may conduct an on-site audit of the facilities used to Process Customer Personal Data. Any such audit is subject to: at least 30 days’ written notice; execution of a confidentiality agreement; conduct during business hours in a manner that does not disrupt Fyvie AI’s operations or compromise the security or confidentiality of other customers’ data; a scope limited to the Processing of Customer Personal Data; a maximum of one audit per twelve-month period, save following a Personal Data Breach; and payment by Customer of Fyvie AI’s reasonable costs. Fyvie AI may exclude access to multi-tenant infrastructure, source code, and information relating to other customers.
13.4 Confidentiality. Materials provided and findings generated under this Section are Fyvie AI’s confidential information and may be used only to assess Fyvie AI’s compliance and to respond to a supervisory authority.
International transfers
14.1 Fyvie AI’s location. Fyvie AI is established in the United Kingdom. Personal data transferred from the EEA to the United Kingdom is subject to the European Commission’s adequacy decisions for the UK, and does not require an additional transfer mechanism for so long as those decisions remain in force.
14.2 EEA transfers. Where Fyvie AI Processes Customer Personal Data subject to the EU GDPR in a country that is not the subject of an adequacy decision, the EU SCCs are incorporated into this Addendum and apply as set out in Annex 4, with Module Two (controller to processor) or Module Three (processor to processor) applying as appropriate to the parties’ roles.
14.3 UK transfers. Where Fyvie AI transfers Customer Personal Data subject to the UK GDPR to a country not covered by UK adequacy regulations, the UK Addendum applies to the EU SCCs as set out in Annex 4. Alternatively, where Customer executes a signed counterpart of this Addendum, the parties may instead enter into the UK IDTA, in which case the law of Scotland will be selected in Table 2 of the UK IDTA.
14.4 Swiss transfers. Where the Swiss FADP applies, the EU SCCs apply with the amendments set out in Annex 4.
14.5 Transfer risk assessment. Fyvie AI will provide Customer with the information reasonably required for Customer to carry out a transfer risk assessment, including information about the legal regimes applicable to its Subprocessors.
14.6 Government access requests. Fyvie AI will, to the extent legally permitted, notify Customer of any legally binding request from a public authority for disclosure of Customer Personal Data, challenge requests it considers unlawful or overbroad, and disclose only the minimum amount of data required.
14.7 Alternative mechanisms. If a transfer mechanism relied on under this Section is invalidated or superseded, the parties will work in good faith to implement an alternative without undue delay.
Retention, return and deletion
15.1 Standard retention. Fyvie AI retains Customer Content for up to 60 days for the purposes described in Section 6, after which it is deleted, unless a longer period is required by law or Customer has enabled a feature of the Services that requires longer storage.
15.2 Deletion on request. Customer may delete Customer Personal Data at any time using the functionality of the Services.
15.3 Zero data retention. Fyvie AI may offer a zero data retention configuration for eligible Customers, under which Customer Content is not persisted to durable storage and is retained only transiently in memory for the duration of the request. Customers may request this configuration from privacy@fyvie.ai; eligibility, scope and any excluded Services will be agreed in writing. Certain features are incompatible with zero data retention, and enablement may limit Fyvie AI’s ability to provide support, investigate errors, or perform retrospective abuse investigation.
15.4 End of term. On expiry or termination of the Agreement, Fyvie AI will delete Customer Personal Data within 90 days, save to the extent that retention is required by law. Customer may request return of Customer Personal Data in a machine-readable format before deletion, provided the request is made within 30 days of termination.
15.5 Backups. Customer Personal Data in backup systems is deleted in accordance with Fyvie AI’s backup rotation cycle of approximately 30 days. Until deletion, it remains subject to the security measures in Annex 2 and is not accessed for any purpose other than restoration.
15.6 Certification. Fyvie AI will certify deletion in writing on Customer’s request.
US state privacy laws
This Section applies to Processing of Customer Personal Data subject to US State Privacy Laws and prevails over the remainder of this Addendum in respect of that Processing.
16.1 Service provider status. Fyvie AI Processes Customer Personal Data as a service provider (or, where applicable, a processor) on behalf of Customer as a business (or controller).
16.2 Restrictions. Fyvie AI will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than providing the Services, except as permitted by US State Privacy Laws;
- retain, use or disclose Customer Personal Data outside the direct business relationship between the parties; or
- combine Customer Personal Data with personal data received from, or on behalf of, another person, or collected from its own interactions with a consumer, except as permitted by US State Privacy Laws.
16.3 Certification. Fyvie AI certifies that it understands the restrictions in Section 16.2 and will comply with them.
16.4 Compliance and notice. Fyvie AI will comply with its obligations as a service provider under applicable US State Privacy Laws, will provide the same level of privacy protection as required of Customer, and will notify Customer promptly if it determines that it can no longer meet those obligations. Customer may, on notice, take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data.
16.5 Deidentified data. Where Fyvie AI Processes deidentified data, it will maintain the data in deidentified form, will not attempt to reidentify it except as permitted to test deidentification, and will contractually obligate any recipient to the same.
16.6 Assistance. Fyvie AI will provide reasonable assistance in responding to verifiable consumer requests, in the manner described in Section 11.
Liability
17.1 Limitations. Each party’s liability arising out of or in connection with this Addendum, including the Standard Contractual Clauses, is subject to the limitations and exclusions of liability set out in the Agreement.
17.2 No cumulative recovery. Liability under this Addendum and under the Standard Contractual Clauses forms part of, and does not increase, the aggregate liability cap in the Agreement.
17.3 Data subject rights unaffected. Nothing in this Section limits the rights of data subjects under Data Protection Law or under the Standard Contractual Clauses, or either party’s liability to a supervisory authority.
General
18.1 Term. This Addendum takes effect with the Agreement and continues until Fyvie AI has deleted all Customer Personal Data in accordance with Section 15. Sections 5, 7, 16 and 17 survive termination.
18.2 Changes. Fyvie AI may update this Addendum where necessary to reflect a change in Data Protection Law, a new certification or transfer mechanism, or a change to the Services, provided the update does not materially diminish Customer’s rights. Material changes will be notified at least 30 days in advance.
18.3 Severability. If any provision is held invalid, the remainder continues in effect.
18.4 Governing law. This Addendum is governed by and construed in accordance with the law of Scotland, and the parties submit to the exclusive jurisdiction of the Scottish courts, except where the Standard Contractual Clauses or the UK Addendum require otherwise, in which case those requirements prevail.
18.5 Third party rights. Save as expressly provided in the Standard Contractual Clauses, no person other than the parties has any right to enforce this Addendum under the Contract (Third Party Rights) (Scotland) Act 2017.
Annex 1 — Details of Processing
A. Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer, as identified in the Agreement or order form | Fyvie AI |
| Address | As identified in the Agreement or order form | Suite 1.2, 8 Elliot Street, Skypark, Glasgow, United Kingdom, G3 8EP |
| Contact | As identified in the Agreement or order form | privacy@fyvie.ai |
| Security contact | As identified in the Agreement or order form | security@fyvie.ai |
| Activities relevant to the transfer | Use of the Services | Provision of the Services |
| Role | Controller or processor | Processor or subprocessor |
B. Description of Processing
Subject matter. Provision of the Services under the Agreement.
Duration. The term of the Agreement, plus the retention periods in Section 15.
Nature and purpose. Receiving Inputs, generating and returning Outputs, storing and transmitting Customer Content as necessary to provide the Services, providing support, and maintaining the availability, security and integrity of the Services.
Categories of data subjects. Determined by Customer. May include Customer’s employees, contractors, end users, customers, suppliers, and any individual whose personal data Customer includes in an Input.
Categories of personal data. Determined by Customer. May include any personal data contained in Inputs or Outputs, together with account, contact and authentication data relating to Customer’s authorised users.
Special categories of personal data. Not required by the Services and not requested. Customer determines whether to include such data in Inputs. Where included, it is Processed under the same measures as other Customer Personal Data, with access restricted as described in Annex 2.
Frequency. Continuous, for the duration of the Agreement.
Retention. As set out in Section 15.
Subprocessor Processing. As set out in Annex 3, for the duration of their engagement.
C. Competent supervisory authority
Where the EU SCCs apply, the competent supervisory authority is: the authority of the member state in which the data exporter is established; where the exporter is not established in the EEA but has appointed a representative under Article 27 of the EU GDPR, the authority of the member state in which that representative is established; or where the exporter is subject to the EU GDPR under Article 3(2) without a representative, the authority of a member state in which the relevant data subjects are located. For enterprise agreements executed as signed counterparts, the competent authority may be specified in the order form.
Annex 2 — Technical and Organisational Measures
Access control. Role-based access control on the principle of least privilege. Mandatory multi-factor authentication for all personnel access to production systems. Access reviewed at least quarterly and revoked within 48 hours of role change or departure. Privileged access requires approval.
Encryption. Customer Personal Data encrypted in transit using TLS 1.2 or above, and at rest using AES-256 or equivalent. Key management through Google Cloud KMS with documented rotation.
Pseudonymisation. Applied to telemetry and analytics data where it does not defeat the purpose of the Processing.
Network security. Segmented network architecture, firewalling, intrusion detection, and DDoS protection. Administrative interfaces are not publicly exposed.
Physical security. Processing takes place in Google Cloud data centres holding ISO/IEC 27001 and SOC 2 certification, with controlled physical access, environmental controls and redundant power.
Availability and resilience. Redundant infrastructure across multiple availability zones. Documented backup schedule with restoration testing at least annually.
Logging and monitoring. Access to Customer Personal Data logged and retained for 24 months. Automated alerting on anomalous access patterns. Logs protected against alteration.
Secure development. Code review required for all changes. Static analysis and dependency scanning in the build pipeline. Segregated development, staging and production environments, with production data not used in non-production environments.
Vulnerability management. Regular scanning, and third-party penetration testing at least annually. A vulnerability disclosure programme at security@fyvie.ai.
Personnel. Background screening where legally permitted, confidentiality undertakings, and security and data protection training on joining and at least annually thereafter.
Subprocessor management. Security assessment before engagement, contractual security obligations, and periodic reassessment.
Incident response. Documented incident response plan with defined roles, escalation paths and notification procedures, tested at least annually.
Measures specific to the Services. Tenant isolation between customers. Content submitted by one customer is not accessible to another. Human access to Customer Content is restricted to the circumstances described in Section 6.3 and is logged.
Annex 3 — Subprocessors
A current list is available on request from privacy@fyvie.ai. As at the effective date:
| Subprocessor | Entity location | Processing location | Purpose | Data categories |
|---|---|---|---|---|
| Google Cloud (Google LLC) | United States | United Kingdom, EEA and United States regions | Cloud hosting and compute | All Customer Content |
| Isambard | United Kingdom | United Kingdom | Compute for model inference | Inputs and Outputs |
| Nebius B.V. | Netherlands | EEA and United States regions | GPU compute for model inference | Inputs and Outputs |
| CoreWeave, Inc. | United States | United States and EEA regions | GPU compute for model inference | Inputs and Outputs |
| Stripe | United States / Ireland | United States and EEA | Payment processing and billing | Billing and contact data; no Customer Content |
| Loops | United States | United States | Transactional and marketing email | Account and contact data; no Customer Content |
| Cloudflare, Inc. | United States | Global edge network | Content delivery network and network security | Customer Content in transit; connection metadata |
| Google Analytics (Google LLC) | United States | United States | Site and product usage analytics | Usage and telemetry data only; Customer Content excluded by configuration |
| PostHog, Inc. | United States | United States | Product usage analytics | Usage and telemetry data only; Customer Content excluded by configuration |
Support is handled by Fyvie AI directly at support@fyvie.ai, and observability is operated on Fyvie AI’s own infrastructure; neither involves a Subprocessor.
Annex 4 — Transfer Mechanisms
A. EU Standard Contractual Clauses
Where the EU SCCs apply under Section 14.2, they are incorporated by reference and completed as follows:
| Item | Selection |
|---|---|
| Module | Module Two (controller to processor) where Customer is a controller; Module Three (processor to processor) where Customer is a processor |
| Clause 7 (docking) | Applies |
| Clause 9 (subprocessors) | Option 2, general written authorisation, with the notice period in Section 10.4 |
| Clause 11 (redress) | Optional independent dispute resolution language does not apply |
| Clause 17 (governing law) | The law of Ireland |
| Clause 18 (forum) | The courts of Ireland |
| Annex I | Annex 1 of this Addendum |
| Annex II | Annex 2 of this Addendum |
| Annex III | Annex 3 of this Addendum |
B. UK Addendum
Where the UK Addendum applies under Section 14.3:
| Table | Entry |
|---|---|
| Table 1: Parties | As set out in Annex 1, Part A |
| Table 2: Selected SCCs | The EU SCCs as completed in Part A above |
| Table 3: Appendix Information | Annexes 1, 2 and 3 of this Addendum |
| Table 4: Ending the Addendum | Neither party may end the Addendum when the Approved Addendum changes |
C. Swiss amendments
Where the Swiss FADP applies: references to the GDPR are read as references to the FADP; the competent authority is the Federal Data Protection and Information Commissioner; the term “member state” does not prevent data subjects in Switzerland from bringing proceedings in Switzerland; and the SCCs protect the data of legal entities until the relevant provisions of the FADP are amended.