Data Processing Agreement
This Data Processing Agreement (“DPA”) governs the processing of personal data by Fenlo on behalf of our customers.
1. Definitions
This DPA forms part of the Terms of Service between Fenlo (“Processor”) and the Customer (“Controller”).
- Personal Data: Information relating to an identifiable natural person.
- Subprocessor: A third-party data processor engaged by Fenlo.
- Security Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, or disclosure of personal data.
2. Processing Scope
2.1 Subject Matter
Processing of organizational knowledge, including documents, communications, project management data, code, and other content from the Customer's connected tools, to provide the Fenlo enterprise search and knowledge management platform.
2.2 Nature and Purpose
Collection, storage, indexing, retrieval, and analysis of data via AI models to provide unified enterprise search, AI-powered chat with cited answers, and knowledge management features. Content is chunked, embedded into vector representations, and indexed for semantic and keyword search.
2.3 Data Subjects
Customer's employees, contractors, collaborators, and other authorized users utilizing the platform.
2.4 Data Isolation
Each Customer organization is provisioned a dedicated PostgreSQL schema. All data, including documents, user accounts, chat sessions, and indexes, is stored within this schema. Cross-tenant data access is not possible at the database level. Document-level access controls are enforced by syncing permission structures from connected source applications.
3. Roles and Obligations
3.1 Controller (You)
- Ensure lawful basis for processing.
- Provide necessary notices to data subjects.
- Do not upload sensitive data (health/biometric) without prior agreement.
3.2 Processor (Us)
- Process data only on documented instructions.
- Ensure persons authorized to process data are committed to confidentiality.
- Assist Controller with Data Subject Rights requests.
- Notify Controller of any Security Breach without undue delay (max 72h).
4. Sub-Processors
You authorize us to engage the following sub-processors to provide the Service:
| Sub-Processor | Service / Purpose | Location |
|---|---|---|
| Neon Database | Primary PostgreSQL database | USA (Azure East US 2) |
| Vespa / OpenSearch | Vector search and document indexing | USA |
| Redis | Celery task broker, caching, distributed locks, and rate limiting | USA |
| OpenAI | AI processing and embeddings | USA |
| Anthropic | AI processing | USA |
| Google Gemini | AI processing | USA |
| AssemblyAI | Audio transcription | USA |
| SendGrid | Transactional email | USA |
| Polar.sh | Payment processing (Merchant of Record) | EU |
We will notify you of any intended changes concerning the addition or replacement of other processors at least 30 days in advance via email.
5. Security Measures (TOMs)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
- Encryption: Data is encrypted in transit using TLS 1.3 and at rest using AES-256. OAuth tokens and connector credentials are encrypted at the application level.
- Tenant Isolation: Each Customer organization has a dedicated PostgreSQL schema. Cross-tenant queries are prevented at the database engine level.
- Access Control: Strict role-based access control (RBAC) and Multi-Factor Authentication (MFA) for all internal staff access. Document-level permissions are synced from connected source applications.
- Vulnerability Management: Regular security scans and dependency updates.
- Physical Security: We rely on our cloud providers who maintain ISO 27001/SOC 2 certified data centers.
- Disaster Recovery: Daily encrypted backups with 30-day retention and regular restoration testing.
6. International Transfers
- Data Location: Primary processing occurs in the United States.
- Safeguards: For transfers from the EEA/UK to countries not deemed adequate, we rely on the Standard Contractual Clauses (SCCs). By executing this DPA, the SCCs are incorporated by reference.
7. Data Retention & Deletion
- During Term: Data is retained for as long as your account is active. Content from connected sources is periodically synced and pruned when removed from the source.
- Termination: Upon termination of the Service, you may retrieve your data. All Personal Data will be deleted within 30 days of account deletion, except where required by law.
- Backups: Backups are overwritten on a rolling 30-day basis.
8. Audits
You may audit our compliance with this DPA up to once per year. Such audits must be conducted during regular business hours, with at least 30 days' prior written notice, and without disrupting our business operations.
9. Contact
For privacy and security inquiries:
team@fenlo.io