Data Processing Agreement.
Last updated: September 2026 · Last reviewed: September 2026 · Next scheduled review: September 2027
1. Roles
The client is the Controller (or Business, under US state law) of its personal data. Foyla, Inc. is the Processor (or Service Provider). Foyla processes personal data only on the client's documented instructions and only for the purpose of designing, building, testing, deploying, and, where agreed, operating the software described in the Statement of Work. Foyla does not sell personal information, does not use it for cross-context behavioral advertising, and does not use it for any purpose outside that business purpose.
2. Scope and purpose
Foyla processes personal data to the extent needed to build and deliver the software described in the Software Development Agreement and its Statements of Work. Those documents, this DPA, and any written instruction the client gives during the engagement (including requirements, system access grants, and support tickets) together form the client's documented processing instructions. Foyla will notify the client if, in its opinion, an instruction infringes applicable data-protection law.
Where the delivered software runs in the client's own environment, the client operates it after handover and Foyla's processing ends, unless an operations phase is agreed in writing.
3. Categories of data and data subjects
- Data subjects: the client's employees, contractors, customers, suppliers, prospects, or partners, depending on the process the software automates.
- Categories: business contact information, communications content, operational and transactional data, documents the process depends on, usage metadata.
- Special categories (health, political opinions, biometric data, and similar) are not processed unless explicitly agreed in writing in the Statement of Work.
4. Confidentiality
Every Foyla employee and contractor who can access client data is bound by written confidentiality obligations and has completed annual security and privacy training.
5. Security measures
Technical and organizational measures are described on our Security page and form part of this DPA. Where software runs in the client's environment, the client's own controls apply to the running system and Foyla's controls apply to Foyla's access during the build. Measures are reviewed and updated at least annually.
6. Subprocessors
We rely on a short list of subprocessors. The current list is maintained at foyla.ai/legal/subprocessors and includes, at minimum, cloud infrastructure providers, foundation-model providers, and business tooling. Where the delivered software runs in the client's environment, foundation-model and infrastructure providers are chosen and contracted by the client and are not Foyla subprocessors. We give at least 30 days' notice of any new subprocessor. Clients may object on reasonable data-protection grounds, and we will work in good faith to resolve the objection or, if we cannot, allow termination of the affected work.
7. International transfers
Client data is processed in the United States by default. For EU/UK clients, processing in the EU is available on request. Where EU/UK personal data is transferred to the US or elsewhere outside the EEA/UK, the transfer is governed by the EU Standard Contractual Clauses (Module Two: controller-to-processor) and the UK International Data Transfer Addendum, or an equivalent approved mechanism.
8. Data subject requests
If a data subject contacts Foyla directly, we will forward the request to the client without responding substantively (unless legally required). We will assist the client in responding within applicable deadlines.
9. Security incidents
We will notify the client without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting client data in Foyla's possession or caused by Foyla's access, along with the information reasonably needed for the client to meet its own obligations under GDPR, US state breach-notification laws, and sector-specific rules where applicable.
10. Audits
On reasonable notice and no more than once per year (unless prompted by an incident), the client may audit our compliance with this DPA. In most cases we will satisfy the audit by providing our security documentation and answering a security questionnaire.
11. Return and deletion
On completion of the engagement or on written request, we will return or delete client personal data in Foyla's possession within 30 days, unless US federal, state, or (for EU clients) member-state law requires retention. Data that lives in the client's own environment is never in Foyla's possession and is unaffected.
12. Liability
Each party's liability under this DPA is subject to the limitations in the Software Development Agreement, except that each party's aggregate liability arising out of breach of this DPA is capped at the greater of (a) two times the fees paid or payable in the 12 months preceding the claim, or (b) US$500,000. The cap does not apply to a party's indemnification obligations, to amounts owed for breach of confidentiality, or to liability that cannot be limited under applicable law.
Contact
DPA questions: [email protected]
Privacy and data-subject requests: [email protected]