Data Processing Agreement

Last Updated: August 9, 2026
GDPR Compliant

This Data Processing Agreement (“DPA”) governs the processing of personal data by Fenlo on behalf of our customers.

1. Definitions

This DPA forms part of the Terms of Service between Fenlo (“Processor”) and the Customer (“Controller”).

  • Personal Data: Information relating to an identifiable natural person.
  • Subprocessor: A third-party data processor engaged by Fenlo.
  • Security Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, or disclosure of personal data.

2. Processing Scope

2.1 Subject Matter

Processing of organizational knowledge, including documents, communications, project management data, code, and other content from the Customer's connected tools, to provide the Fenlo enterprise search and knowledge management platform.

2.2 Nature and Purpose

Collection, storage, indexing, retrieval, and analysis of data via AI models to provide unified enterprise search, AI-powered chat with cited answers, and knowledge management features. Content is chunked, embedded into vector representations, and indexed for semantic and keyword search.

2.3 Data Subjects

Customer's employees, contractors, collaborators, and other authorized users utilizing the platform.

2.4 Data Isolation

Each Customer organization is provisioned a dedicated PostgreSQL schema. All data, including documents, user accounts, chat sessions, and indexes, is stored within this schema. Cross-tenant data access is not possible at the database level. Document-level access controls are enforced by syncing permission structures from connected source applications.

3. Roles and Obligations

3.1 Controller (You)

  • Ensure lawful basis for processing.
  • Provide necessary notices to data subjects.
  • Do not upload sensitive data (health/biometric) without prior agreement.

3.2 Processor (Us)

  • Process data only on documented instructions.
  • Ensure persons authorized to process data are committed to confidentiality.
  • Assist Controller with Data Subject Rights requests.
  • Notify Controller of any Security Breach without undue delay (max 72h).

4. Sub-Processors

You authorize us to engage the following sub-processors to provide the Service:

Sub-ProcessorService / PurposeLocation
Neon DatabasePrimary PostgreSQL databaseUSA (Azure East US 2)
Vespa / OpenSearchVector search and document indexingUSA
RedisCelery task broker, caching, distributed locks, and rate limitingUSA
OpenAIAI processing and embeddingsUSA
AnthropicAI processingUSA
Google GeminiAI processingUSA
AssemblyAIAudio transcriptionUSA
SendGridTransactional emailUSA
Polar.shPayment processing (Merchant of Record)EU

We will notify you of any intended changes concerning the addition or replacement of other processors at least 30 days in advance via email.

5. Security Measures (TOMs)

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:

  • Encryption: Data is encrypted in transit using TLS 1.3 and at rest using AES-256. OAuth tokens and connector credentials are encrypted at the application level.
  • Tenant Isolation: Each Customer organization has a dedicated PostgreSQL schema. Cross-tenant queries are prevented at the database engine level.
  • Access Control: Strict role-based access control (RBAC) and Multi-Factor Authentication (MFA) for all internal staff access. Document-level permissions are synced from connected source applications.
  • Vulnerability Management: Regular security scans and dependency updates.
  • Physical Security: We rely on our cloud providers who maintain ISO 27001/SOC 2 certified data centers.
  • Disaster Recovery: Daily encrypted backups with 30-day retention and regular restoration testing.

6. International Transfers

  • Data Location: Primary processing occurs in the United States.
  • Safeguards: For transfers from the EEA/UK to countries not deemed adequate, we rely on the Standard Contractual Clauses (SCCs). By executing this DPA, the SCCs are incorporated by reference.

7. Data Retention & Deletion

  • During Term: Data is retained for as long as your account is active. Content from connected sources is periodically synced and pruned when removed from the source.
  • Termination: Upon termination of the Service, you may retrieve your data. All Personal Data will be deleted within 30 days of account deletion, except where required by law.
  • Backups: Backups are overwritten on a rolling 30-day basis.

8. Audits

You may audit our compliance with this DPA up to once per year. Such audits must be conducted during regular business hours, with at least 30 days' prior written notice, and without disrupting our business operations.

9. Contact

For privacy and security inquiries:

team@fenlo.io