← Back to playbook
Compliance · 02

Data Processing Agreement

Last updated: May 27, 2026

This document is provided for informational purposes. Consult qualified counsel for binding agreements.

1. Parties and Scope

This Data Processing Agreement ("DPA") supplements the Terms of Service between Equiforge, Inc. ("Processor") and the customer ("Controller"). It governs the Processing of Personal Data by Processor on behalf of Controller in connection with the Service.

2. Roles

Controller is the controller of Personal Data submitted to the Service. Processor processes Personal Data only on documented instructions from Controller, including with respect to international transfers.

3. Processor Instructions

Controller's use of the Service constitutes its instruction to Processor to Process Personal Data as necessary to provide the Service, comply with these Terms, and meet legal obligations.

4. Confidentiality

Processor will ensure that personnel authorized to Process Personal Data are subject to written confidentiality obligations.

5. Security Measures

See Annex II below.

6. Sub-processors

Controller authorizes Processor to engage the sub-processors listed in Annex III. Processor will notify Controller of new sub-processors at least thirty (30) days in advance.

7. Data Subject Rights

Processor will provide reasonable assistance to Controller in responding to verified requests from Data Subjects to exercise their rights under applicable Data Protection Laws.

8. Personal Data Breach

Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach.

9. International Transfers

Where Processing involves a transfer of Personal Data outside the EEA, UK, or Switzerland to a country not deemed adequate, the parties incorporate the EU Standard Contractual Clauses (Module Two) and the UK Addendum as applicable.

10. Audits

Processor will make available to Controller information reasonably necessary to demonstrate compliance, including SOC 2 Type II and ISO 27001 reports under NDA. On-site audits may be arranged with reasonable prior notice during business hours, not more than once per year except where required by a supervisory authority.

11. Term and Termination

This DPA applies for the term of the Terms of Service. Upon termination, Processor will, at Controller's choice, delete or return Personal Data within ninety (90) days, except where retention is required by law.

Annex I — Processing Details

  • Subject matter: Provision of the EquiForge platform, Strategist, and related services.
  • Duration: Term of the Terms of Service plus required retention.
  • Nature and purpose: Hosting, processing AI prompts, authentication, analytics, support.
  • Categories of Personal Data: Identifiers, contact info, authentication metadata, usage data, content submitted to the Strategist.
  • Categories of Data Subjects: Authorized users of Controller's account.

Annex II — Technical and Organizational Measures

See the Security & Compliance page for the full list of measures, including encryption, access control, SDLC, incident response, and certifications.

Annex III — Sub-processors

Sub-processorPurposeLocation
Supabase, Inc.Managed database, authentication, storageUnited States
Cloudflare, Inc.Edge compute, CDN, DDoS protectionGlobal
Google LLCOAuth identity provider and AI model inference (Gemini)United States
OpenAI, L.L.C.AI model inferenceUnited States

Questions: dpo@equiforge.ai

LEGAL
Terms of ServicePrivacy PolicyCookie PolicyPatent Portfolio
COMPLIANCE
Security & ComplianceData Processing AgreementAcceptable Use Policy
CONTACT
legal@equiforge.aidpo@equiforge.aisecurity@equiforge.ai
CERTIFICATIONS
SOC 2 Type IIISO 27001ISO 42001PCI-DSS v4.0
© 2026 Equiforge, Inc. All rights reserved.v1.0