Data Processing Addendum
Last updated: July 20, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and AlpineDataWorks.AI ("Processor") for the provision of the API and connector Services (the "Agreement"). It applies to the extent AlpineDataWorks.AI processes Personal Data on the Controller's behalf that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), or comparable data-protection laws. Where this DPA conflicts with the Agreement on the subject of data protection, this DPA controls.
A countersigned copy is available on request. To execute this DPA, email [email protected].
1. Definitions
"Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Supervisory Authority" have the meanings given in applicable Data Protection Law. "Subprocessor" means any third party engaged by the Processor to process Personal Data.
2. Roles & Scope of Processing
- Roles. The Controller is the controller and AlpineDataWorks.AI is the processor of Personal Data processed under the Agreement. For CCPA purposes, AlpineDataWorks.AI acts as a "service provider."
- Subject matter. Provision of agent-ready data products via API and AI connectors.
- Duration. The term of the Agreement, plus the retention periods described in the Privacy Policy.
- Nature & purpose. Authenticating requests, metering and billing usage, delivering requested data, and securing the Services.
- Categories of Data Subjects. The Controller's authorized users and administrators.
- Categories of Personal Data. Account identifiers (name, work email, company), API keys (hashed), OAuth authorization grants, and request metadata (endpoint, timestamp, status). The Services are not intended for special-category data.
3. Processor Obligations
AlpineDataWorks.AI shall:
- Process Personal Data only on the Controller's documented instructions, including the Agreement and this DPA, unless required by law (in which case it will notify the Controller unless the law prohibits it).
- Ensure persons authorized to process Personal Data are bound by confidentiality.
- Implement the technical and organizational measures in Section 6.
- Not "sell" or "share" Personal Data as those terms are defined under the CCPA/CPRA, and not retain, use, or disclose it for any purpose other than performing the Services.
- Assist the Controller, taking into account the nature of processing, in responding to Data Subject requests and in meeting its obligations under Articles 32–36 GDPR.
4. Subprocessors
The Controller provides general authorization for AlpineDataWorks.AI to engage the subprocessors listed on our Security page (currently cloud hosting / edge compute, transactional email, and payment processing). AlpineDataWorks.AI imposes data-protection obligations on each subprocessor no less protective than those in this DPA and remains liable for their performance. We will give the Controller notice of any intended addition or replacement of a subprocessor and a reasonable opportunity to object on legitimate grounds.
5. International Transfers
Where processing involves transfer of Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the applicable European Commission Standard Contractual Clauses (and the UK International Data Transfer Addendum) by reference, which are deemed completed with the parties, roles, and details set out in this DPA and the Agreement.
6. Security Measures
AlpineDataWorks.AI maintains technical and organizational measures appropriate to the risk, including:
- TLS encryption for all data in transit.
- API keys hashed at rest; OAuth grants encrypted at rest.
- Access to production systems restricted to named personnel.
- Salted, non-reversible hashing of IP addresses retained for audit.
- Automated secret scanning and dependency monitoring in the software supply chain.
- Logging and monitoring for abuse and availability.
Further detail is published on our Security page.
7. Personal Data Breach
AlpineDataWorks.AI will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and will provide information reasonably required for the Controller to meet its own notification obligations.
8. Return & Deletion
On termination of the Agreement, AlpineDataWorks.AI will, at the Controller's choice, delete or return the Personal Data it processes on the Controller's behalf, and delete existing copies unless retention is required by law. Retention periods are described in the Privacy Policy.
9. Audits
AlpineDataWorks.AI will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits, and satisfiable through up-to-date documentation and questionnaires where appropriate.
To execute this DPA or request our subprocessor list, contact [email protected]. This DPA is provided for convenience and does not constitute legal advice.