NETRIDIUM DATA PROCESSING ADDENDUM
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Netridium Terms of Service or other written agreement between Netridium, LLC, a Michigan limited liability company ("Netridium," "Processor"), and the customer identified in the applicable Plan or agreement ("Customer," "Controller") (together, the "Agreement"). This DPA applies to the extent that Netridium Processes Personal Data on behalf of Customer in the course of providing the Service.
Capitalized terms not defined in this DPA have the meanings given in the Agreement. In the event of a conflict between this DPA and the remainder of the Agreement regarding the Processing of Personal Data, this DPA controls.
Effective date: This DPA is effective on the earlier of Customer's acceptance of the Agreement or the date Netridium begins Processing Personal Data on Customer's behalf.
1. DEFINITIONS
1.1 "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into the law of the United Kingdom ("UK GDPR") together with the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"); and other U.S. state privacy laws, in each case as amended or superseded.
1.2 "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," "Special Categories of Personal Data," and "Supervisory Authority" have the meanings given in the GDPR, and their equivalents ("business," "service provider," "consumer," "personal information," "sale," "share," etc.) under the CCPA/CPRA apply where that law governs.
1.3 "Customer Personal Data" means Personal Data contained within Customer Data that Netridium Processes on Customer's behalf in providing the Service, including Personal Data that the Service retrieves from Customer Systems on Customer's instruction and Personal Data contained in Prompts, Scripts, Output, or logs.
1.4 "Restricted Transfer" means a transfer of Customer Personal Data to a country or recipient not benefiting from an adequacy decision or equivalent mechanism under Applicable Data Protection Law.
1.5 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914 of 4 June 2021, as amended or replaced.
1.6 "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018.
1.7 "Subprocessor" means any third party engaged by Netridium to Process Customer Personal Data in connection with the Service.
2. ROLES AND SCOPE
2.1 Roles of the Parties. As between the Parties, with respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller), and Netridium is the Processor. Where Customer is itself a Processor acting for one or more third-party Controllers — including where Customer is a consultancy, accounting firm, or managed service provider using the Client Manager console — Netridium is a subprocessor, and Customer represents that it is authorized by each such Controller to engage Netridium on the terms of this DPA and to give the instructions set out in it.
2.2 Scope. This DPA applies only to Netridium's Processing of Customer Personal Data as a Processor. It does not apply to Personal Data for which Netridium is an independent Controller, which is governed by the Netridium Privacy Policy (for example, account registration data, billing contact data, and website telemetry described in Section 8.3).
2.3 Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex A.
2.4 BYOK Processing. Where Customer elects Bring Your Own Key ("BYOK") under the Agreement, Prompt content and associated context selected by Customer Logic are transmitted to the applicable Model Provider under Customer's own account and agreement with that Model Provider. In that configuration, the Model Provider is not a Netridium Subprocessor with respect to that processing, and Customer is responsible for its own agreement with, and any data protection terms of, that Model Provider. Netridium remains a Processor as to Customer Personal Data that it stores, transmits, or logs within the Service.
3. PROCESSING OBLIGATIONS
3.1 Processing on Instructions. Netridium will Process Customer Personal Data only on Customer's documented instructions, including with respect to Restricted Transfers, unless required to do otherwise by law to which Netridium is subject, in which case Netridium will inform Customer of that legal requirement before Processing unless the law prohibits it. Customer's documented instructions comprise the Agreement, this DPA, and Customer's configuration and operation of the Service — including Customer Logic, Connections, Authorized Operations, and account settings. The Service executes whatever Customer Logic Customer configures; Customer's configuration of what data the Service reads, writes, transmits, or deletes is itself a processing instruction to Netridium.
3.2 Lawfulness of Instructions. Customer is responsible for the accuracy, quality, and lawfulness of Customer Personal Data and of the means by which Customer acquired it, and warrants that it has all rights, consents, and lawful bases necessary for Netridium and its Subprocessors to Process Customer Personal Data as contemplated by the Agreement. Netridium will inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law; Netridium is not obligated to conduct a legal review of Customer's instructions.
3.3 Special Categories; Restricted Data. Consistent with Section 11.4 of the Terms of Service, Customer will not cause the Service to Process Special Categories of Personal Data, government identification numbers, payment card data subject to PCI-DSS, protected health information subject to HIPAA, biometric data, or children's data, unless expressly agreed in writing in a Plan or separate addendum. Netridium has no liability arising from Customer's submission of such data in breach of this Section.
3.4 Confidentiality. Netridium will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality and are subject to access on a need-to-know basis.
4. SECURITY
4.1 Security Measures. Netridium will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Personal Data Breaches, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects. Netridium's current measures are described in Annex B.
4.2 Evaluation. Netridium may update or modify the security measures in Annex B from time to time, provided that such updates do not materially reduce the overall level of protection for Customer Personal Data during the term of the Agreement.
5. SUBPROCESSORS
5.1 General Authorization. Customer provides general written authorization for Netridium to engage Subprocessors to Process Customer Personal Data, subject to this Section 5. Netridium's current Subprocessors are listed in Annex C.
5.2 Subprocessor Obligations. Netridium will impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA to the extent applicable to the nature of the Subprocessor's services. Netridium remains responsible to Customer for the performance of each Subprocessor's obligations.
5.3 Changes. Netridium will maintain the list of Subprocessors in Annex C (or at a URL referenced there) and will notify Customer of any intended addition or replacement of a Subprocessor at least ten (10) days in advance, by email to Customer's designated contact or by in-product or website notice with an option to subscribe to updates. Customer may object on reasonable, documented data-protection grounds within that period. If Customer objects, the Parties will work in good faith to resolve the objection; if they cannot, Customer may, as its sole and exclusive remedy, terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees for the terminated portion of the Subscription Term.
6. DATA SUBJECT RIGHTS
6.1 Assistance. Taking into account the nature of the Processing, Netridium will provide reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection).
6.2 Requests Received by Netridium. If Netridium receives a request from a Data Subject relating to Customer Personal Data, Netridium will, unless legally prohibited, promptly forward the request to Customer and will not respond to it directly except on Customer's documented instruction. Customer is responsible for responding to Data Subject requests. To the extent Customer's Users can exercise these functions directly through the Service (for example, by locating, exporting, correcting, or deleting records), Customer will use those functions in the first instance.
7. PERSONAL DATA BREACH
7.1 Notification. Netridium will notify Customer without undue delay, and in any event within the period required by Applicable Data Protection Law, after becoming aware of a Personal Data Breach affecting Customer Personal Data within systems controlled by Netridium or its Subprocessors.
7.2 Information and Cooperation. Such notification will describe, to the extent then known and as it becomes available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Netridium will provide reasonable cooperation to assist Customer in meeting its own breach-notification obligations. Netridium's notification is not an acknowledgment of fault or liability.
7.3 Customer-Side Breaches. Consistent with Section 11.6 of the Terms of Service, a security incident originating from compromised Customer credentials, over-scoped Credentials, Customer Logic, or Customer's own environment is not a Netridium Personal Data Breach.
8. DATA PROTECTION IMPACT ASSESSMENTS
8.1 Taking into account the nature of the Processing and the information available to Netridium, Netridium will provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with Supervisory Authorities that Customer is required to carry out under Applicable Data Protection Law in respect of the Service. Netridium may charge its reasonable costs for assistance that exceeds the information already available in the Documentation, this DPA, and Netridium's security materials.
9. RETURN AND DELETION
9.1 Return and Deletion. Upon expiration or termination of the Agreement, Netridium will, at Customer's election, return and/or delete Customer Personal Data in accordance with Section 9.6 of the Terms of Service (Data Export and Deletion). After the export period described there, Netridium will delete Customer Personal Data in the ordinary course, subject to routine, non-targeted backup retention cycles and any retention required by law, during which such data remains subject to this DPA.
9.2 Certification. Netridium will confirm deletion in writing upon Customer's reasonable request.
10. AUDITS AND INFORMATION
10.1 Information. Netridium will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, primarily through its Documentation, security overview, subprocessor list, and any third-party audit reports, certifications, or questionnaire responses Netridium maintains.
10.2 Audits. Where Applicable Data Protection Law grants Customer an audit right and the information described in Section 10.1 is insufficient, Netridium will allow for and contribute to an audit no more than once per twelve (12) months, conducted by Customer or an independent auditor Customer mandates, subject to reasonable advance notice (at least thirty (30) days), confidentiality obligations, and scheduling that avoids disruption to Netridium's operations and does not grant access to other customers' data or to Netridium's multi-tenant infrastructure in a manner that would compromise security. Customer bears its own and Netridium's reasonable costs of any audit exceeding the materials in Section 10.1. This Section does not expand any audit right beyond what Applicable Data Protection Law requires.
11. INTERNATIONAL TRANSFERS
11.1 Transfer Mechanism. To the extent Netridium's Processing of Customer Personal Data involves a Restricted Transfer, the Parties agree that the applicable transfer mechanism in Annex D applies and is incorporated into this DPA by reference.
11.2 SCCs. Where the SCCs apply, they are deemed entered into between the Parties (and completed as set out in Annex D), with Netridium as "data importer" and Customer as "data exporter," and Annexes A, B, and C of this DPA populate the corresponding annexes of the SCCs. Where the UK Addendum applies, it is incorporated and completed as set out in Annex D. For transfers subject to the FADP, references in the SCCs are interpreted as required to protect transfers governed by Swiss law.
11.3 Alternative Mechanisms. If any transfer mechanism in Annex D is invalidated or superseded, the Parties will cooperate in good faith to implement an alternative lawful transfer mechanism.
12. CALIFORNIA / U.S. STATE PRIVACY LAW TERMS
12.1 Service Provider Status. With respect to Customer Personal Data governed by the CCPA/CPRA (or an equivalent U.S. state law), Netridium acts as a service provider (or processor, where that term applies) and Processes such Personal Data solely to perform the Service under the Agreement (the "business purpose").
12.2 Restrictions. Netridium will not: (a) sell or share Customer Personal Data (as "sell" and "share" are defined under the CCPA/CPRA); (b) retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose it outside the direct business relationship with Customer; or (d) combine it with personal information received from other sources, except as permitted by the CCPA/CPRA for a service provider. Netridium certifies that it understands and will comply with these restrictions.
12.3 Assistance. Netridium will assist Customer in responding to verifiable consumer requests and will notify Customer if it determines it can no longer meet its obligations as a service provider.
13. LIABILITY
13.1 Each Party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability set out in the Agreement (including Section 14 of the Terms of Service), and any reference in the Agreement to a Party's liability means the aggregate liability of that Party under the Agreement and this DPA together.
14. GENERAL
14.1 Term. This DPA continues in effect for as long as Netridium Processes Customer Personal Data, notwithstanding expiration or termination of the Agreement.
14.2 Conflict. In the event of a conflict, the order of precedence is: (a) the SCCs or UK Addendum (as to Restricted Transfers); (b) this DPA; (c) the remainder of the Agreement.
14.3 Changes. Netridium may update this DPA to reflect changes in Applicable Data Protection Law, guidance from Supervisory Authorities, or Netridium's Subprocessors or security measures, provided such updates do not materially reduce the protections for Customer Personal Data.
14.4 Governing Law and Venue. Except where Applicable Data Protection Law or an applicable transfer mechanism requires otherwise, this DPA is governed by the law and venue provisions of the Agreement.
ANNEX A — DETAILS OF PROCESSING
A.1 Subject matter. Netridium's provision of the Service to Customer, comprising a governed, multi-tenant execution and access-control environment in which Customer authors and runs Prompts, Scripts, and Agents that read from and, where enabled, write to Customer Systems.
A.2 Duration. For the term of the Agreement, plus the export and deletion periods described in Section 9 of this DPA and Section 9.6 of the Terms of Service.
A.3 Nature and purpose. Hosting, storage, transmission, retrieval, execution, logging, and display of Customer Data and Customer Logic; transmission of Prompt content to Model Providers for inference and return of Output; and provision of related support, security, and billing functions, in each case to deliver the Service.
A.4 Categories of Data Subjects. As determined by Customer's data and Customer Logic. These may include Customer's personnel and Users; Customer's own clients and their personnel; and the individuals whose records exist within the Customer Systems Customer connects — for example, customers, vendors, contacts, employees, and account holders represented in ERP, CRM, accounting, billing, HRIS, and related systems.
A.5 Types of Personal Data. As determined by Customer's data and Customer Logic. These may include names, business and personal contact details, account and user identifiers, authentication metadata, role and permission data, transactional and financial records (such as invoices, payments, subscriptions, and ledger entries), customer and vendor master data, communications content, and any other Personal Data contained in the records Customer connects or in the Prompts, Scripts, Output, and logs Customer generates. Customer controls what Personal Data enters the Service; Netridium does not require or predetermine any particular category.
A.6 Sensitive data. Not permitted except as expressly agreed under Section 3.3.
A.7 Frequency. Continuous and/or on Customer's initiation and schedule, for the duration of the Agreement.
ANNEX B — TECHNICAL AND ORGANIZATIONAL MEASURES
Netridium maintains a written information security program with measures appropriate to the nature of the Service. Current measures include:
B.1 Access control and tenant isolation. Multi-tenant isolation enforced at the database layer through row-level security (RLS); role-based access control separating authors (Builder Users/Administrators) from Runners; scoped administrative access using an assume-role (impersonation) pattern; and least-privilege principles for internal access.
B.2 Encryption. Encryption of Customer Data in transit (TLS) and at rest; encrypted storage of Credentials and connection secrets; and centralized secrets management for internal system credentials.
B.3 Authentication. Support for customer single sign-on (SSO/SAML) where offered; enforcement of authentication controls for Users; and availability of multi-factor authentication where offered.
B.4 Execution guardrails. Per-run limits (including maximum cost, tokens, connector calls, and duration) enforced mid-run on a fail-closed basis; budgets and cost-center controls; and per-tenant usage controls designed to contain runaway or anomalous execution.
B.5 Logging and monitoring. Audit logging of execution and administrative actions; retention of execution history and results within the tenant; and operational monitoring of the Service.
B.6 Resilience. Use of managed cloud infrastructure with provider-level redundancy; routine, non-targeted backups; and separation of production from non-production (staging) environments.
B.7 Software security. Secure development practices, including tenant-isolation and security-invariant testing; prompt-injection defenses and hardened prompt templates; and dependency and secrets hygiene.
B.8 Organizational. Confidentiality obligations on personnel; access on a need-to-know basis; and incident response procedures.
Netridium may update these measures provided the overall level of protection is not materially reduced.
ANNEX C — SUBPROCESSORS
The following are Netridium's current Subprocessors for the Processing of Customer Personal Data. The current list is maintained at https://netridium.com/legal/subprocessors.html and controls if it differs from the table below.
| Subprocessor | Service provided | Processing location |
|---|---|---|
| Supabase | Managed Postgres database, authentication, and application data hosting | United States (US East — Ohio) |
| Render | Application, API, and background-worker compute hosting | United States (US East — Ohio) |
| Postmark (ActiveCampaign) | Transactional and authentication email delivery | United States |
| Maxio | Subscription billing and metered usage processing | United States |
| Anthropic | Model Provider — inference for Netridium-Supplied AI (not engaged where Customer uses BYOK) | United States |
Notes. - Where Customer elects BYOK, the applicable Model Provider Processes Prompt content under Customer's own account and is not a Netridium Subprocessor for that processing (see Section 2.4). - Customer Systems that Customer connects to the Service (for example, Xero, Salesforce, QuickBooks Online, Maxio, and other ERP/CRM/accounting/billing systems) are Customer's own systems and data sources, not Netridium Subprocessors. - Netridium contracts with its Model Provider Subprocessor(s) on terms that do not permit training of generally available foundation models on Customer's inputs or outputs, consistent with Section 4.6 of the Terms of Service.
ANNEX D — TRANSFER MECHANISMS
D.1 European Economic Area. For Restricted Transfers subject to the GDPR, the SCCs apply as follows: - Module: Module Two (Controller to Processor) where Customer is a Controller; Module Three (Processor to Processor) where Customer acts as a Processor for a third-party Controller. - Clause 7 (Docking): applies. - Clause 9 (Subprocessors): Option 2 (general written authorization); the notice period is as stated in Section 5.3 of this DPA. - Clause 11 (Redress): the optional independent dispute-resolution language does not apply. - Clause 17 (Governing law): the law of the EU Member State of the data exporter, or the Republic of Ireland where the exporter is not established in an EU Member State. - Clause 18 (Forum): the courts of that same Member State (or Ireland, as applicable). - Annexes: Annex A (this DPA) populates SCC Annex I; Annex B populates SCC Annex II; Annex C populates the SCC subprocessor list.
D.2 United Kingdom. For Restricted Transfers subject to the UK GDPR, the UK Addendum applies, with the SCCs as completed in D.1 forming the "Approved EU SCCs," and Tables 1–3 of the UK Addendum completed with the information in Annexes A–C. The "start date" is the effective date of this DPA, and either Party may end the UK Addendum as permitted by its Section 19.
D.3 Switzerland. For Restricted Transfers subject to the FADP, the SCCs apply with references to the GDPR understood as references to the FADP where required, the Swiss Federal Data Protection and Information Commissioner as competent authority, and Data Subjects in Switzerland afforded rights under the FADP.
Netridium, LLC · 2222 W Grand River Ave, Ste A, Okemos, MI 48864 · legal@netridium.com · privacy@netridium.com
Version: August 16, 2026