Data Processing Addendum
The terms that apply when Fous processes personal data on behalf of its customers, including the EU Standard Contractual Clauses.
Effective
When you use Fous to process personal data, you are the controller and Fous is your processor. We process that data only on your instructions, keep it confidential and secure, use only listed subprocessors, help with requests and incidents, and delete it when you are done. Unless you turn it off, Fous also uses records of your builds and requests to train its own AI, as a controller, and deletes them within 30 days after you turn it off. The EU Standard Contractual Clauses and their UK and Swiss equivalents cover international transfers. This addendum is part of the Terms automatically; no signature is needed. This summary is not part of the addendum.
On this page
1. Scope and how this addendum applies
This Data Processing Addendum (“DPA”) forms part of the Fous Terms of Service between Fous Technologies, Inc. (“Fous”) and the customer that accepted them (“Customer”). It applies whenever Fous processes Customer Personal Data as a processor or service provider. It applies automatically and needs no signature; a countersigned copy is available on request at [email protected].
Capitalized words not defined here have the meanings given in the Terms. If this DPA conflicts with the Terms on a data protection matter, this DPA prevails. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
2. Definitions
- Data Protection Laws: the laws on personal data that apply to the processing under this DPA, which may include the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), and other U.S. state privacy laws.
- Customer Personal Data: personal data in Customer Content that Fous processes on Customer’s behalf.
- Subprocessor: a third party that Fous engages to process Customer Personal Data.
- Standard Contractual Clauses: the clauses approved by European Commission Implementing Decision (EU) 2021/914. UK Addendum: the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- Controller, processor, data subject, personal data breach, processing, and supervisory authority have the meanings given in the GDPR, and service provider, sell, and share have the meanings given in the CCPA.
3. Roles
Customer is the controller of Customer Personal Data, or a processor acting for its own customers, in which case Fous is a subprocessor. Fous is Customer’s processor and service provider. Customer is responsible for the lawfulness of its instructions and of Customer Personal Data, including having a lawful basis and giving any notices required for personal data that its Workflows collect from Target Sites.
Fous is an independent controller of the personal data described in its Privacy Policy as processed for Fous’s own purposes, such as accounts, billing, security, analytics, and building and maintaining Fous Workflows with Fous’s own test data. This DPA does not apply to that data. Personal data from Customer’s calls to a Workflow, including a Fous Workflow, remains Customer Personal Data.
AI Training Data. Unless Customer turns off AI training data collection, Fous keeps records of the Builds, request checks, Workflow matching, and Router plans of Customer’s Organization, which can contain Customer Personal Data, and uses them to train, evaluate, and improve its own AI models and the Service, as the Terms and the Privacy Policy describe (“AI Training Data”). For an Organization that existed before this version of the DPA, collection starts on the date the Terms give. Fous does this as an independent controller. Customer authorizes this use and is responsible for giving any notice, and having any lawful basis, that Data Protection Laws require for it. For AI Training Data, Fous:
- designs its systems to remove Credentials and other secrets before storage, and identifies Customer’s Organization in stored records only by a random reference;
- applies the measures in Annex II and limits access to authorized personnel;
- includes inputs from another Organization’s failed calls only if that Organization has collection on; and
- deletes Customer’s AI Training Data within 30 days after Customer turns collection off or its Organization is deleted, and does not retrain models already trained with it.
Apart from this section, International transfers, and Annexes I and II, this DPA does not govern AI Training Data.
4. Processing on Customer’s instructions
Fous processes Customer Personal Data only on Customer’s documented instructions, unless the law requires otherwise, in which case Fous will tell Customer before processing unless the law prohibits it. Customer’s instructions are:
- the Terms and this DPA;
- Customer’s use and configuration of the Service, including Builds, Workflow calls, Router requests, Connected Accounts, and Actions;
- using inputs from Customer’s calls that fail or repeatedly return no data, with the errors they produced, to test and repair the Workflows that Customer calls, including Public Workflows and Fous Workflows, without showing those inputs to the Publisher; and
- other reasonable written instructions that are consistent with the Terms.
Fous will tell Customer if it believes an instruction infringes Data Protection Laws.
5. Confidentiality
Fous ensures that the people it authorizes to process Customer Personal Data are bound by confidentiality obligations.
6. Security
Fous implements the technical and organizational measures in Annex II, which are designed to give a level of security appropriate to the risk. Fous may update these measures as long as the overall level of protection is not materially reduced. Customer is responsible for its own security, including protecting its API keys, managing its Members, and choosing which accounts to connect.
7. Subprocessors
Customer gives Fous general authorization to engage Subprocessors. The current Subprocessors are listed on the Subprocessors page. Fous will update that page, and email customers who have subscribed there, at least 15 days before a new Subprocessor starts processing Customer Personal Data, except where an urgent replacement is needed for security or continuity, in which case Fous will give notice as soon as possible.
Customer may object to a new Subprocessor on reasonable data protection grounds within that notice period by writing to [email protected]. The parties will discuss the objection in good faith. If they cannot resolve it, Customer may stop using the affected part of the Service and receive a refund of unused purchased Credits.
Fous will bind each Subprocessor by a written contract to data protection obligations that are, in substance, no less protective than those in this DPA, and remains liable to Customer for its Subprocessors’ performance of those obligations. Target Sites and other services that Customer directs a Workflow to access are not Subprocessors.
8. Requests from individuals
If Fous receives a request from a data subject about Customer Personal Data, it will promptly refer the data subject to Customer, or pass the request to Customer, and will not otherwise respond unless the law requires it. Taking into account the nature of the processing, Fous will help Customer respond through appropriate technical and organizational measures. Customer can delete Workflows, disconnect Connected Accounts, and delete its Organization in Studio, and can ask for other help at [email protected].
9. Personal data breaches
Fous will notify Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 72 hours after becoming aware of it. The notice will include the information required by Article 33(3) of the GDPR as far as it is available, with further information provided as it becomes available. Fous will take reasonable steps to contain and remedy the breach. A notice is not an admission of fault.
10. Impact assessments and consultations
Taking into account the nature of the processing and the information available to it, Fous will give Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities that relate to Customer’s use of the Service.
11. Return and deletion
Customer can delete Customer Personal Data in Studio as described in the Privacy Policy, and can ask Fous to return it by exporting Customer Content as the Terms describe. AI Training Data is deleted as described in Roles. After the Terms end, Fous will delete Customer Personal Data within 90 days, except data that the law requires Fous to keep; data in backups, until they are overwritten in the normal course; and Public Workflows, which Fous holds under the license in the Terms. Fous processes data it keeps only for the purpose for which it keeps it, and the terms of this DPA continue to apply to it.
12. Information and audits
Fous will make available the information reasonably needed to show that it complies with this DPA, including this DPA, the Security page, and answers to a reasonable security questionnaire once a year. If that information is not enough to show compliance, or a supervisory authority requires it, Customer may audit Fous’s compliance once in any 12-month period, with at least 30 days’ written notice, during business hours, under confidentiality obligations, and at Customer’s cost, itself or through an independent auditor that is not a competitor of Fous.
13. International transfers
Fous may process Customer Personal Data in the United States and in other countries where Fous or its Subprocessors operate. Where Data Protection Laws require a transfer mechanism for a transfer to Fous, the following apply, and Customer’s acceptance of the Terms counts as signature of them:
- European Economic Area. The Standard Contractual Clauses are incorporated into this DPA, with Customer as data exporter and Fous as data importer. Module 2 applies where Customer is a controller, and Module 3 where Customer is a processor. Module 1 applies to AI Training Data, which Fous receives as a controller. Clause 7 applies. Under Clause 9, option 2 applies, with the notice period in the Subprocessors section. The optional wording in Clause 11 does not apply. Under Clause 17, the clauses are governed by the law of Ireland, and under Clause 18, the courts of Ireland have jurisdiction. Annexes I and II below complete the clauses’ annexes, and the Subprocessors page completes Annex III.
- United Kingdom. The UK Addendum is incorporated. Table 1 is completed with the parties in Annex I; Table 2 with the modules and options above; Table 3 with Annexes I and II and the Subprocessors page; and in Table 4, either party may end the UK Addendum as its section 19 allows.
- Switzerland. The Standard Contractual Clauses apply as above, with these changes where the Swiss Federal Act on Data Protection applies: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; references to a Member State include Switzerland, so that data subjects in Switzerland can bring claims there; and references to the GDPR include the Swiss act.
14. U.S. state privacy laws
Where the CCPA or a similar state law applies, Fous acts as Customer’s service provider or processor. Fous will not sell or share Customer Personal Data; will not keep, use, or disclose it for any purpose other than the business purposes set out in the Terms and this DPA, or outside its direct business relationship with Customer; will not combine it with other personal data except as those laws allow; will give it the level of privacy protection those laws require; and will tell Customer if it can no longer meet these obligations, in which case Customer may take reasonable steps to stop and remedy unauthorized use. Using AI Training Data to build and improve the Service, as described in Roles, is one of those business purposes, and Customer can stop it at any time by turning off AI training data collection.
15. Liability
Each party’s liability under this DPA is subject to the limitations of liability in the Terms, except where the Standard Contractual Clauses or Data Protection Laws do not allow such a limitation.
Annex I: Description of the processing
A. Parties
Data exporter: Customer, as identified in its account, acting as controller or processor; contact: the owners of its Organization. Data importer: Fous Technologies, Inc., 2261 Market Street, STE 86843, San Francisco, CA 94114, United States, acting as processor; contact: [email protected]. Activities: the Service described in the Terms.
B. Description of the transfer
| Item | Description |
|---|---|
Data subjects | Customer’s Members and users, and individuals whose personal data appears in Customer’s prompts and inputs, in Target Site content, in Output, or in Connected Accounts, as Customer determines. |
Categories of personal data | Any personal data Customer chooses to process, which may include names, contact details, identifiers, online account details and Credentials for Connected Accounts, and the content of web pages and online accounts. |
Sensitive data | Only if Customer chooses to process it, in which case Customer is responsible for doing so lawfully. Safeguards: the encryption and access controls in Annex II. |
Frequency | Continuous, as Customer uses the Service. |
Nature of the processing | Collection through automated browsers and requests, storage, transmission, structuring, transformation with AI models, and return to Customer. |
Purpose | Providing the Service under the Terms: building, running, testing, and repairing Workflows; the Router; Connected Accounts and Actions; and support. |
Duration and retention | The term of the Terms and the deletion period in the Return and deletion section. Specific retention periods are in the Privacy Policy. |
Transfers to Subprocessors | As listed on the Subprocessors page, for the same purposes and duration. |
C. AI Training Data (Module 1)
| Item | Description |
|---|---|
Parties | Data exporter: Customer, as in A. Data importer: Fous, as in A, acting as controller. |
Data subjects and categories of personal data | Those in B that appear in AI Training Data. Credentials are designed to be removed before storage. |
Purpose | Training, evaluating, and improving Fous’s AI models and the Service, as the Terms and the Privacy Policy describe. |
Duration and retention | While AI training data collection is on for Customer’s Organization, and at most 5 years after collection. Deleted within 30 days after collection is turned off or the Organization is deleted. |
Transfers onward | To the storage and other Providers listed on the Subprocessors page, for the same purpose. |
D. Competent supervisory authority
The supervisory authority determined under Clause 13 of the Standard Contractual Clauses: where Customer is established in the EEA, the authority of its Member State of establishment; where Customer is not established in the EEA but has appointed a representative under Article 27 of the GDPR, the authority of the Member State where the representative is established; and otherwise the authority of the Member State where the relevant data subjects are located.
Annex II: Technical and organizational measures
Fous’s measures are described on the Security page and include:
- encryption in transit with TLS, and application-level encryption of Credentials, Connected Account sessions, idempotent results, Router plans, inputs from failed calls, results of Actions, Build recordings, and large payloads;
- API keys and session tokens stored only as hashes, optional two-factor authentication, and role-based access within Organizations;
- isolated sandboxes for Workflow code, with no access to private networks, and short-lived, limited access to Credentials;
- separate least-privilege database roles, an append-only Credit ledger, and audit logs;
- limited retention periods, as set out in the Privacy Policy;
- sanitized error messages and no logging of prompts or search text;
- for AI Training Data, removal of detected Credentials and other secrets before storage, private encrypted storage, and random references in place of Organization identities; and
- access to production systems limited to personnel who need it.
Annex III: Subprocessors
The Subprocessors authorized under this DPA are listed on the Subprocessors page.