Eyeclone
  • Features
  • Pricing
  • About us
  • Media hub
  • FAQs
  • Contact
Select Page

Eyeclone Data Processing Addendum

Last Updated: May 1, 2026
This Data Processing Addendum (“DPA”) is entered into between Eyeclone LLC (“Processor” or “Eyeclone”) and the entity or individual that has accepted the Subscription Terms of Service (“Controller” or “Customer”). This DPA is incorporated into and forms part of the Subscription Terms of Service (the “Agreement”) and is effective as of the date Customer electronically accepts the Agreement (the “Effective Date”). Customer’s electronic acceptance of the Agreement, by clicking “I Agree,” “Accept,” “Subscribe,” “Register,” “Create Account,” or any similar button, or by completing the checkout process, or by accessing or using the Platform in any manner following presentation of the Agreement, constitutes Customer’s legally binding acceptance of this DPA. If Customer does not agree to this DPA, Customer must not accept the Agreement or access or use the Platform. This DPA applies to the extent that Eyeclone processes Personal Data on behalf of Customer in connection with the provision of the Services.

DEFINITIONS

As used in this DPA, the following terms have the meanings set forth below:

  • “Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under this DPA, including: (a) in the United States: the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Virginia Consumer Data Protection Act (VCDPA), the Texas Data Privacy and Security Act (TDPSA), and any other applicable U.S. state or federal privacy laws; (b) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation; (c) Australia’s Privacy Act 1988; (d) South Africa’s Protection of Personal Information Act, 2013 (POPIA); and (e) any other applicable national, state, or local privacy or data protection laws, in each case as amended, supplemented, or replaced from time to time.
  • “Controller” means the entity that determines the purposes and means of the processing of Personal Data. For purposes of this DPA, Customer is the Controller with respect to Customer Personal Data.
  • “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
  • “Personal Data” means any information relating to an identified or identifiable natural person that is included in Customer Data and processed by Eyeclone on behalf of Customer under this DPA. “Personal Data” includes “personal information” as defined under applicable U.S. state privacy laws.
  • “Personal Data Breach” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by Eyeclone.
  • “Processing” / “Process” means any operation or set of operations performed on Personal Data, including collection, recording, storage, adaptation, retrieval, use, disclosure, transmission, or deletion.
  • “Processor” means the entity that processes Personal Data on behalf of the Controller. For purposes of this DPA, Eyeclone is the Processor.
  • “Security Measures” has the meaning given to it in Section 7 of this DPA.
  • “Sub-processor” means any Processor engaged by Eyeclone to process Personal Data on Eyeclone’s behalf in connection with the Services.

SCOPE AND ROLES

Scope.

This DPA applies to all Personal Data processed by Eyeclone on behalf of Customer in connection with the provision of the Services under the Agreement. The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Schedule 1 (Data Processing Details) attached hereto.

Roles.

The parties acknowledge and agree that:

  • Customer is the Controller of Personal Data processed under this DPA and determines the purposes and means of such processing;
  • Eyeclone is the Processor of such Personal Data and processes it only on behalf of and at the direction of Customer, in accordance with this DPA and the Agreement; and
  • Eyeclone may also process certain personal data as a Controller in its own right (e.g., account information, billing data, and Usage Data) — such processing is governed by Eyeclone’s Privacy Policy and not by this DPA.

Customer’s Obligations as Controller.

Customer, as Controller, represents and warrants that:

  • Customer has a valid legal basis under Applicable Data Protection Law for processing and transferring Personal Data to Eyeclone;
  • Customer has provided all required notices and obtained all required consents from Data Subjects to the extent required by Applicable Data Protection Law;
  • Customer’s instructions to Eyeclone for the processing of Personal Data comply with Applicable Data Protection Law; and
  • Customer is solely responsible for the accuracy, quality, and lawfulness of Personal Data submitted to the Services.

3. PROCESSING INSTRUCTIONS

Documented Instructions.

Eyeclone shall process Personal Data only on documented instructions from Customer, including as set forth in this DPA and the Agreement. The Agreement and this DPA constitute Customer’s complete and final instructions to Eyeclone regarding the processing of Personal Data. Any additional or modified instructions must be agreed to in writing by both parties.

Prohibited Processing.

Eyeclone shall not:

  • sell or share Personal Data as those terms are defined under Applicable Data Protection Law;
  • process Personal Data for any purpose other than as specified in this DPA and the Agreement;
  • process Personal Data for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects on Data Subjects, except as expressly authorized by Customer; or
  • retain, use, or disclose Personal Data outside of the direct business relationship with Customer, except as required by law.

Notification of Illegal Instructions.

If Eyeclone reasonably determines that any instruction from Customer would violate Applicable Data Protection Law, Eyeclone shall promptly notify Customer. Eyeclone may suspend processing of the affected Personal Data pending resolution of the issue. If Customer does not modify the instruction within a reasonable time, Eyeclone may terminate this DPA and the Agreement upon written notice.

CONFIDENTIALITY OF PERSONAL DATA

Eyeclone shall ensure that all Eyeclone personnel authorized to process Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are trained on data protection requirements applicable to their role. Access to Personal Data shall be limited to personnel who require such access to perform the Services.

SUB-PROCESSORS

Authorization; List.

Customer grants Eyeclone general written authorization to engage Sub-processors to process Personal Data in connection with the Services, subject to the requirements of this Section 5. Eyeclone uses the following Sub-processors (the “Sub-processor List”), each subject to data protection terms no less protective than those in this DPA:

  • Stripe — payment processing
  • OpenAI — transaction categorization and search
  • Anthropic — AI processing
  • Microsoft Azure — hosting and infrastructure
  • Postmark — transactional email delivery

Sub-processor Changes; Objection Right.

Eyeclone will provide Customer with at least thirty (30) days’ prior written notice (by email or by updating the Sub-processor List and notifying Customer) before adding or replacing a Sub-processor that will process Personal Data. Customer may object to a new or replacement Sub-processor within fourteen (14) days of receiving notice by providing written notice to Eyeclone describing the reasonable, data protection-based grounds for the objection. If Customer objects and the parties are unable to resolve the objection within thirty (30) days, Customer may terminate the Agreement and this DPA upon written notice, and Eyeclone will refund any prepaid Fees for the unused portion of the Subscription Term. If Customer does not object within the notice period, Customer is deemed to have accepted the new Sub-processor.

Sub-processor Obligations.

Eyeclone shall:

  • enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those set out in this DPA, to the extent applicable to the Sub-processor’s scope of processing;
  • remain liable to Customer for the Sub-processor’s performance of its data protection obligations;
  • ensure that Sub-processors process Personal Data only as necessary for the services they provide to Eyeclone; and
  • Sub-processors that provide AI model or machine learning services shall not use Customer Personal Data, prompts, queries, or outputs derived from Customer Personal Data to train, fine-tune, or improve their general-purpose AI models or any model made available to third parties.

DATA SUBJECT RIGHTS

Assistance with Requests.

Eyeclone shall, taking into account the nature of the processing, assist Customer by implementing appropriate technical and organizational measures to fulfill Customer’s obligation to respond to Data Subject rights requests under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection. Eyeclone shall promptly forward to Customer any Data Subject request received by Eyeclone that relates to Customer’s Personal Data, and shall not respond to any such request without Customer’s prior written authorization, except as required by Applicable Data Protection Law.

Timing.

Eyeclone shall promptly notify Customer, and in any event within five (5) business days, upon receiving a Data Subject request relating to Customer’s Personal Data, to enable Customer to respond within applicable legal deadlines.

Costs.

Eyeclone shall provide reasonable cooperation in responding to Data Subject requests. Where Eyeclone’s cooperation requires substantial effort beyond the ordinary course of the Services, Eyeclone reserves the right to charge Customer reasonable fees for such additional assistance, with advance notice.

SECURITY MEASURES

Technical and Organizational Measures.

Eyeclone shall implement and maintain appropriate technical and organizational security measures (“Security Measures”) designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or disclosure, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Such Security Measures include, at a minimum, the measures described in Schedule 2 (Security Measures) attached hereto.

Updates to Security Measures.

Eyeclone may update or modify the Security Measures from time to time, provided that any updates do not materially reduce the overall level of protection provided to Personal Data. Eyeclone will notify Customer of any material reduction in Security Measures.

Customer Responsibilities.

Customer is responsible for implementing and maintaining appropriate security measures for its own systems, networks, and devices used to access the Services, including securing Customer’s credentials, access controls, and network perimeter.

PERSONAL DATA BREACH NOTIFICATION

Notification Obligation.

Eyeclone shall notify Customer of a confirmed Personal Data Breach without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, to the extent required by Applicable Data Protection Law. Eyeclone shall provide notification to the email address designated by Customer for security notices, or if none, to the email address on file for Customer’s account.

Content of Notification.

The notification shall include, to the extent then known and ascertainable:

  • a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • the name and contact details of the data protection contact or other point of contact where more information can be obtained;
  • a description of the likely consequences of the Personal Data Breach; and
  • a description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

Where all required information is not available at the time of initial notification, Eyeclone may provide information in phases without undue further delay.

Limitations.

Eyeclone’s notification obligations under this Section 8 do not apply to: (a) security incidents caused solely by Customer’s own acts or omissions; (b) incidents affecting only Eyeclone’s systems without compromising Personal Data; or (c) incidents subject to notification restrictions imposed by applicable law or law enforcement. Notification by Eyeclone is not an acknowledgement of fault, liability, or violation of any obligation.

Regulatory Notifications.

Customer is solely responsible for determining whether it is required to notify any data protection authority or Data Subjects of any Personal Data Breach and for making any required notifications. Eyeclone shall provide reasonable cooperation and assistance to Customer in connection with such notifications.

DATA PROTECTION IMPACT ASSESSMENTS AND PRIOR CONSULTATION

Eyeclone shall, upon reasonable written request and to the extent it is able and legally permitted to do so, provide Customer with reasonable assistance in connection with:

  • data protection impact assessments (DPIAs) required under Applicable Data Protection Law, where such assessments relate to Eyeclone’s processing of Personal Data; and
  • prior consultations with supervisory authorities required under Applicable Data Protection Law, to the extent that such consultations arise directly from Eyeclone’s processing activities;

Such assistance is limited to information and documentation within Eyeclone’s reasonable control and may be subject to reasonable fees where the scope of assistance is material.

AUDITS AND INSPECTIONS

Audit Rights.

Upon Customer’s written request, and no more than once per calendar year absent a reasonable belief of non-compliance, Eyeclone shall:

  • make available to Customer all information reasonably necessary to demonstrate compliance with Eyeclone’s obligations under this DPA; and
  • allow for, and contribute to, audits and inspections conducted by Customer or an independent third-party auditor mandated by Customer, subject to the conditions set forth in Section 10.2.

Audit Conditions.

Any audit or inspection under this Section 10 is subject to the following conditions:

  • Customer must provide at least thirty (30) days’ prior written notice specifying the scope of the audit, except that: (i) where a supervisory authority requires an audit or inspection within a shorter timeframe, Customer shall provide notice as promptly as reasonably practicable; and (ii) where Customer requests an audit in connection with a confirmed or reasonably suspected Personal Data Breach attributable to Eyeclone, Customer must provide at least fifteen (15) days’ prior written notice; in all cases the notice must describe the scope of the audit with reasonable specificity;
  • audits must be conducted during normal business hours and in a manner that minimizes disruption to Eyeclone’s operations;
  • the auditor must enter into a confidentiality agreement satisfactory to Eyeclone before receiving access to any Eyeclone systems or documentation;
  • Customer shall bear all costs and expenses associated with any audit, including fees charged by third-party auditors;
  • Where available, Eyeclone may satisfy its audit obligations by providing Customer with the results of a third-party audit or certification (such as SOC 2 Type II or ISO 27001) conducted by a qualified independent assessor within the preceding twelve (12) months. Customer shall treat such third-party reports as prima facie evidence of compliance with Eyeclone’s security obligations for the relevant period. Notwithstanding the foregoing, Customer retains the right to conduct an on-site audit in accordance with this Section 10 where the third-party report reveals material concerns or where Customer has reasonable grounds to believe a Personal Data Breach has occurred.

INTERNATIONAL DATA TRANSFERS

Acknowledgment of Cross-Border Processing.

  • Customer acknowledges that Eyeclone is a U.S.-based company and that Personal Data processed under this DPA may be transferred to, stored in, and processed in the United States and in other jurisdictions in which Eyeclone or its Sub-processors operate. By instructing Eyeclone to process Personal Data, Customer authorizes such transfers, subject to the safeguards set forth in this Section 11 and elsewhere in this DPA.

Transfer Mechanism.

For transfers of Personal Data to the United States or to any other country in which Eyeclone or its Sub-processors operate, the parties shall rely on the contractual protections set forth in this DPA, including Eyeclone’s processing obligations under Section 4, the Sub-processor obligations under Section 5, the Security Measures under Section 7 and Schedule 2, the Personal Data Breach obligations under Section 9, and the jurisdiction-specific obligations set forth in the applicable Schedules, as the lawful transfer mechanism, to the extent permitted by Applicable Data Protection Law.

Canada.

Transfers of Personal Data of Canadian Data Subjects (including residents of Quebec) to the United States or other jurisdictions outside Canada are made in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including, where applicable, the Act respecting the protection of personal information in the private sector (Quebec Law 25). Eyeclone shall maintain contractual safeguards with Sub-processors providing comparable protection to that required under PIPEDA and applicable provincial law. Where required by Quebec Law 25, Eyeclone shall reasonably cooperate with Customer’s preparation of any privacy impact assessment relating to the cross-border communication of Personal Data of Quebec residents.

South Africa.

Transfers of Personal Data of South African Data Subjects outside the Republic of South Africa are conducted in accordance with Section 72 of the Protection of Personal Information Act, 2013 (“POPIA”). Eyeclone shall ensure that the recipient of any such transfer (including any Sub-processor) is bound by binding contractual obligations, binding corporate rules, or applicable law that provides an adequate level of protection for the Personal Data substantially similar to the conditions for lawful processing under POPIA. Additional terms specific to the processing of Personal Data of South African Data Subjects are set forth in Schedule 4 (POPIA Addendum).

Australia.

Transfers of personal information (as defined in the Privacy Act 1988 (Cth)) of Australian Data Subjects outside Australia are conducted in accordance with Australian Privacy Principle 8 (cross-border disclosure of personal information). Eyeclone shall take reasonable steps, by way of the contractual obligations in this DPA and the Sub-processor requirements of Section 5, to ensure that overseas recipients (including Sub-processors) handle such personal information in a manner consistent with the Australian Privacy Principles. Additional terms specific to the processing of personal information of Australian Data Subjects are set forth in Schedule 5 (Australia Addendum).

U.S. State Privacy Laws.

To the extent Applicable Data Protection Law includes U.S. state privacy laws (including CCPA/CPRA), the parties acknowledge that Eyeclone is a “service provider” or “processor” (as applicable) under such laws and processes Personal Data only for the business purposes specified in this DPA. Eyeclone shall not process Personal Data received from Customer for any purpose other than as specified herein, and certifies that it understands and will comply with the applicable restrictions. The parties’ obligations under this DPA are intended to satisfy the contractual requirements for Processors/Service Providers under applicable U.S. state privacy laws.

Updates to Transfer Arrangements.

If Applicable Data Protection Law requires the parties to adopt a specific cross-border transfer mechanism (including, for example, a designated standard contractual clause, model agreement, or other prescribed instrument) that is not addressed in this Section 11, the parties shall negotiate in good faith and execute such mechanism without undue delay, and any such mechanism shall be incorporated into this DPA by reference upon execution. Customer acknowledges that the absence of any such prescribed mechanism in this DPA as of the Effective Date reflects the parties’ understanding that no such mechanism is required as a precondition to lawful transfer under the Applicable Data Protection Laws then in force in the jurisdictions Eyeclone serves.

RETENTION AND DELETION

Retention During Term.

Eyeclone shall retain Personal Data for the duration of the Agreement and this DPA, as necessary to provide the Services, and shall not retain Personal Data beyond what is necessary for the specified purposes.

Deletion Following Termination.

Upon expiration or termination of the Agreement, and subject to Customer’s right to export Personal Data pursuant to the Agreement, Eyeclone shall, at Customer’s election and within sixty (60) days of receiving written instructions from Customer:

  • return to Customer a complete copy of all Customer Personal Data in a standard machine-readable format; and/or
    • securely delete and destroy all Customer Personal Data in Eyeclone’s possession or control, including all copies maintained by Sub-processors.

Eyeclone shall certify in writing to Customer the completion of deletion upon request. Notwithstanding the foregoing, Eyeclone may retain Personal Data: (a) in encrypted backup or archival systems for up to one-hundred and eighty (180) days following termination, provided that such retained data is protected by the Security Measures and is not actively processed; and (b) to the extent and for the duration required by applicable law, regulation, audit requirement, or legal hold obligation, in which case Eyeclone shall notify Customer of such retention and the applicable legal basis.

Anonymized Data.

For the avoidance of doubt, Eyeclone’s obligations under Section 12.2 do not apply to Usage Data (anonymized, aggregated data) that does not constitute Personal Data.

TERM AND TERMINATION

This DPA takes effect on the Effective Date (as defined in the Introduction to this DPA) and continues until the expiration or termination of the Agreement, unless terminated earlier in accordance with its terms. Termination of the Agreement automatically terminates this DPA. Obligations that by their nature should survive termination (including data deletion, confidentiality, international transfer obligations, and audit rights) shall survive termination of this DPA.

LIABILITY

The limitation of liability provisions set forth in the Agreement apply to this DPA and to all claims arising under or in connection with this DPA, including claims relating to Personal Data processing and Personal Data Breaches. Notwithstanding the foregoing, each party’s liability arising out of or related to this DPA shall be subject to the aggregate liability cap set forth in the Agreement, except to the extent such limitations are not permitted under Applicable Data Protection Law with respect to the processing of Personal Data.

Where both parties contribute to damage suffered by a Data Subject, liability shall be apportioned between the parties as set forth in Applicable Data Protection Law providing for apportionment of liability among controllers and processors. For the avoidance of doubt, any regulatory fines, penalties, or sanctions imposed on Customer by a data protection authority in respect of Customer’s own obligations as Controller are Customer’s sole responsibility and are not subject to indemnification by Eyeclone, except to the extent attributable to Eyeclone’s breach of its obligations under this DPA.

GENERAL PROVISIONS

Order of Precedence.

In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.

Amendments.

Eyeclone may update this DPA from time to time to reflect changes in Applicable Data Protection Law or guidance from supervisory authorities, and such updates shall take effect upon thirty (30) days’ written notice to Customer via email or by posting a revised DPA on Eyeclone’s website, unless a shorter period is required to comply with mandatory law. For any amendment that: (a) expands the categories of Personal Data processed; (b) introduces a new processing purpose; (c) changes the legal basis for processing; (d) modifies the applicable cross-border transfer mechanism; or (e) adds or changes a Sub-processor in a manner that materially affects the protection of Personal Data, the amendment shall not take effect without Customer’s prior written consent. Customer’s continued use of the Services following notice of a non-material amendment shall constitute acceptance of that amendment. In the event Customer does not consent to a material amendment within thirty (30) days of notice, either party may terminate this DPA and the Agreement upon written notice, and Eyeclone shall issue a pro-rated refund of prepaid Fees for the unused Subscription Term.

Severability.

If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect and the parties shall negotiate in good faith to replace the invalid provision with one that achieves the same purpose.

Entire Agreement.

This DPA, together with the Agreement and its Schedules, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior discussions, agreements, or understandings relating thereto.

Governing Law.

This DPA shall be governed by the laws of the State of Florida, without regard to its conflict of laws provisions, except to the extent that Applicable Data Protection Law requires a different governing law (in which case that law shall apply to the extent required).

Contact.

Questions regarding this DPA or data protection matters should be directed to Eyeclone at: privacy@eyeclone.io, or by mail to Eyeclone LLC, 9011 Dulcetto Ct, Boca Raton, Florida 33496, Attention: Privacy / Data Protection.

SCHEDULE 1
DATA PROCESSING DETAILS

This Schedule describes the processing of Personal Data carried out by Eyeclone on behalf of Customer under this DPA and serves as Annex I to the SCCs where applicable.

A. List of Parties

  Controller (Customer) Processor (Eyeclone)
Name As specified in Customer’s account registration Eyeclone LLC
Address As specified in Customer’s account registration 9011 Dulcetto Ct, Boca Raton, Florida 33496, USA
Contact As specified in Customer’s account registration privacy@eyeclone.io
Role Controller Processor
Signature / Acceptance Electronic acceptance of the Agreement and this DPA Execution of the Agreement

B. Description of Processing

Element Details
Subject matter of processing Processing of Personal Data submitted by Customer to the Eyeclone Platform in the course of Customer’s use of the Services.
Duration of processing For the duration of the Agreement and this DPA, plus any retention period specified in Section 12.
Nature and purpose of processing Providing, operating, maintaining, and improving the Eyeclone financial intelligence platform, including: processing Customer Data to generate analyses, reports, and Customer Outputs; enabling Authorized Users to access and use the Platform; providing customer support; ensuring security and integrity of the Services; and complying with legal obligations.
Types of Personal Data May include: (a) Contact and identity data: names, email addresses, phone numbers, job titles, business contact information of Authorized Users and Customer representatives; (b) Account and authentication data: user credentials, login data, access logs; (c) Financial and operational data: financial records, transaction data, business intelligence data, and related information submitted by Customer to the Platform; (d) Usage and technical data: IP addresses, device identifiers, browser information, platform usage logs to the extent this constitutes Personal Data; (e) Communications data: support tickets, correspondence between Customer and Eyeclone personnel.
Categories of Data Subjects May include: (a) Customer’s Authorized Users (employees, contractors, advisors); (b) Customer’s clients, customers, or business partners whose Personal Data Customer submits to the Platform; (c) Customer’s employees or personnel whose data is processed as part of Customer’s financial or operational data.
Sensitive / Special Categories of Personal Data Eyeclone does not intentionally process sensitive personal data (e.g., health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, criminal history) as part of the Services. Customer must not submit sensitive personal data to the Platform without Eyeclone’s express prior written consent and execution of appropriate additional terms.
Frequency of transfer On a continuous basis as Customer and Authorized Users use the Services during the Term.
Onward transfers Personal Data may be transferred to Sub-processors listed on the Sub-processor List maintained at https://eyeclone.io/data-processing-agreement

For transfers of South African Personal Data: the Information Regulator of South Africa (www.inforegulator.org.za)

SCHEDULE 2
TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

This Schedule describes Eyeclone’s Security Measures as referenced in Section 7 of this DPA and serves as Annex II to the SCCs where applicable. Eyeclone may update these measures from time to time provided the overall level of protection is not materially reduced.

Security Domain Measures Implemented
Access Control Role-based access controls (RBAC) limiting access to Personal Data to authorized personnel on a need-to-know basis; unique user authentication credentials; multi-factor authentication (MFA) for administrative access; privileged access management; regular access reviews and de-provisioning of terminated accounts.
Encryption Encryption of Personal Data in transit using TLS 1.2 or higher; encryption of Personal Data at rest using AES-256 or equivalent; encryption of backup data; key management procedures.
Network Security Firewalls; network segmentation; monitoring of network traffic for anomalies; DDoS protection; VPN for remote administrative access.
Physical Security Personal Data processed in Microsoft Azure cloud infrastructure, which maintains SOC 2 Type II, ISO 27001, and other relevant certifications; physical access controls at Azure data center facilities are managed by Microsoft in accordance with Microsoft’s security commitments; no processing of Personal Data on unsecured physical media.
Incident Response Documented incident response plan; designated incident response team; procedures for detecting, reporting, investigating, and remediating security incidents; Personal Data Breach notification procedures as set forth in Section 8 of this DPA.
Vulnerability Management Regular vulnerability scanning and penetration testing; patch management procedures; tracking and remediation of identified vulnerabilities; security code review for Platform updates.
Availability and Resilience Redundant infrastructure; data backups with tested restoration procedures; business continuity and disaster recovery plan; monitoring of Platform availability.
Personnel and Training Data protection training for all personnel with access to Personal Data; background checks for personnel in sensitive roles to the extent permitted by law; confidentiality obligations for all personnel; disciplinary procedures for security policy violations.
Sub-processor Management Due diligence review of Sub-processors’ security practices; contractual security obligations imposed on Sub-processors; periodic review of Sub-processor compliance.
Data Minimization Processing only Personal Data necessary for the specified purposes; pseudonymization or anonymization where appropriate; data retention limits as specified in this DPA.
Audit and Logging Audit logs of access to and processing of Personal Data; monitoring of administrative actions; log retention for security investigation purposes; regular review of audit logs.

SCHEDULE 3
U.S. STATE PRIVACY LAW ADDENDUM

This Schedule sets out additional terms applicable to the processing of Personal Data subject to U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).

A. California (CCPA/CPRA)

To the extent Eyeclone processes “personal information” of California residents on behalf of Customer:

(a)   Eyeclone is a “service provider” or “contractor” (as defined under CCPA/CPRA) with respect to such processing;

(b)   Eyeclone shall not sell or share California personal information as those terms are defined under CCPA/CPRA;

(c)   Eyeclone shall not retain, use, or disclose California personal information for any commercial purpose other than providing the Services to Customer or as otherwise permitted by CCPA/CPRA;

(d)   Eyeclone shall not retain, use, or disclose California personal information outside of the direct business relationship between Eyeclone and Customer;

(e)   Eyeclone shall not combine California personal information received from Customer with personal information received from other sources or collected from Eyeclone’s own interactions with consumers, except as permitted under CCPA/CPRA;

(f)   Eyeclone certifies that it understands the restrictions in this Section and will comply with them; and

(g)   Eyeclone shall cooperate reasonably with Customer to honor consumer rights requests under CCPA/CPRA, including requests to know, delete, correct, and opt out of sale or sharing.

B. Other State Privacy Laws

To the extent Eyeclone processes Personal Data of residents of other U.S. states with applicable privacy laws (including Colorado, Connecticut, Virginia, Texas, and other states), the parties acknowledge that Eyeclone acts as a “processor” under such laws. Eyeclone shall process such Personal Data only for the purposes described in this DPA, shall assist Customer in responding to consumer rights requests as required by applicable law, and shall enter into any additional contractual terms required by such laws upon Customer’s reasonable request.

C. Data Sharing Prohibition

Eyeclone shall not sell, share, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate Personal Data subject to U.S. state privacy laws to any third party for monetary or other valuable consideration, or for cross-context behavioral advertising, without Customer’s express written authorization.

SCHEDULE 4
SOUTH AFRICA (POPIA) ADDENDUM

This Schedule sets out additional terms applicable to the processing of Personal Data subject to the Protection of Personal Information Act, 2013 (South Africa) (“POPIA”).

A. Roles

To the extent Eyeclone processes personal information of South African data subjects on behalf of Customer in connection with the Services, the parties acknowledge that Customer is the “Responsible Party” and Eyeclone is the “Operator” as those terms are defined in POPIA.

B. Operator Obligations

Eyeclone, as Operator, shall:

(a) process Personal Data of South African data subjects only with the knowledge or authorization of Customer as Responsible Party, and only for the purposes set out in this DPA and the Agreement;

(b) implement appropriate technical and organizational security measures to secure the integrity and confidentiality of Personal Data in accordance with POPIA Condition 7 and the Security Measures in Schedule 2;

(c) notify Customer without undue delay, and in any event within seventy-two (72) hours, upon becoming aware of a compromise or reasonably suspected compromise of Personal Data of South African data subjects, to enable Customer to fulfill its notification obligations to the Information Regulator and affected data subjects under POPIA Section 22;

(d) not disclose Personal Data of South African data subjects to any third party without Customer’s authorization, except as required by applicable law;

(e) ensure that any Sub-processor processing Personal Data of South African data subjects is bound by written obligations no less protective than those in this Schedule; and

(f) assist Customer in responding to requests from South African data subjects exercising their rights under POPIA, including the right to access, correction, and objection to processing.

C. Cross-Border Transfers

Transfers of Personal Data of South African data subjects outside of South Africa are conducted only where the recipient country or organization provides an adequate level of protection consistent with POPIA Section 72. Eyeclone relies on contractual protections, including the obligations in this DPA and the Standard Contractual Clauses (where applicable), as the mechanism for such transfers. Upon Customer’s request, Eyeclone will provide information about the transfer mechanisms applicable to specific Sub-processors processing South African personal data.

D. Information Regulator

Customer, as Responsible Party, is solely responsible for registering with the Information Regulator of South Africa (where required), responding to complaints from South African data subjects, and notifying the Information Regulator of Personal Data Breaches as required by POPIA Section 22. Eyeclone shall provide reasonable cooperation and assistance to Customer in connection with such obligations.

SCHEDULE 5
AUSTRALIA — PRIVACY ACT ADDENDUM

This Schedule sets out additional terms applicable to the processing of Personal Data subject to the Privacy Act 1988 (Cth) (Australia) and the Australian Privacy Principles (“APPs”) contained therein.

A. Scope and Roles

To the extent Eyeclone processes personal information (as defined in the Privacy Act 1988 (Cth)) of individuals located in Australia on behalf of Customer in connection with the Services, the terms of this Schedule apply. Customer acknowledges that it is the entity that collects and controls the personal information submitted to the Platform, and that Eyeclone processes such information on Customer’s behalf and in accordance with Customer’s instructions, consistent with the processor role described in Section 2 of this DPA.

B. Eyeclone’s Obligations

To the extent required by the Privacy Act 1988 (Cth) and the APPs, Eyeclone shall:

(a) process personal information of Australian individuals only in accordance with Customer’s documented instructions and the purposes described in this DPA and the Agreement, and not for any purpose that would be inconsistent with the APPs;

(b) implement and maintain Security Measures consistent with APP 11, designed to protect personal information against misuse, interference, loss, and unauthorized access, modification, or disclosure;

(c) upon written request from Customer, assist Customer in responding to requests from Australian individuals exercising their rights of access (APP 12) and correction (APP 13) with respect to their personal information processed within the Platform;

(d) promptly notify Customer upon becoming aware of a data breach affecting personal information of Australian individuals that is likely to result in serious harm to any individual, to enable Customer to assess its notification obligations under the Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act 1988 (Cth)). Eyeclone’s notification to Customer under this paragraph shall be treated as a Personal Data Breach notification under Section 8 of this DPA and shall be subject to the same timing, content, and limitation provisions set forth therein;

(e) not disclose personal information of Australian individuals to any Sub-processor located outside Australia unless Eyeclone has taken reasonable steps, by way of the contractual obligations in this DPA and the sub-processor requirements of Section 5, to ensure that the overseas recipient handles such personal information in a manner consistent with the APPs, as required by APP 8.2. Customer acknowledges and agrees that Eyeclone’s compliance with Section 5 of this DPA (including imposing data protection obligations on Sub-processors no less protective than those in this DPA) constitutes the reasonable steps required by APP 8.2 with respect to Sub-processor transfers; and

(f) upon termination of the Agreement, delete or return personal information of Australian individuals in accordance with Section 12 of this DPA.

C. Customer’s Acknowledgment (APP 8.1 Overseas Disclosure)

Customer acknowledges that, by subscribing to the Platform and authorizing Eyeclone to process personal information of Australian individuals in the United States (and in other countries where Eyeclone’s Sub-processors operate), Customer is authorizing the cross-border disclosure of that personal information as permitted by APP 8.1. Prior to authorizing such disclosure, Customer confirms that it has provided individuals with notice that their personal information may be transferred to and processed in overseas countries, and that overseas recipients are contractually required to handle it consistently with the APPs, as described in Eyeclone’s Privacy Policy.

Where Customer authorizes disclosure under APP 8.1, Customer (not Eyeclone) is responsible for ensuring the individual has been given the required notice under APP 1 and APP 5, and Customer bears the accountability for the overseas recipient’s handling under APP 8.1.

D. Sub-processor Transfers (APP 8 Compliance)

Where Eyeclone engages Sub-processors that receive personal information of Australian individuals (including Anthropic, OpenAI, Microsoft Azure, and other Sub-processors listed on the Sub-processor List), Eyeclone shall ensure that such Sub-processors are contractually required to handle Australian personal information in a manner consistent with the APPs. Eyeclone’s contractual obligations under Section 5.3 of this DPA are intended to satisfy Eyeclone’s “reasonable steps” obligation under APP 8.2 with respect to Sub-processor transfers.

E. Complaints and Regulatory Cooperation

If Eyeclone receives a complaint or inquiry from an Australian individual or the Office of the Australian Information Commissioner (OAIC) relating to the processing of personal information under this DPA, Eyeclone shall promptly notify Customer and shall cooperate with Customer in responding to such complaint or inquiry to the extent within Eyeclone’s reasonable control. Customer, as the entity responsible for collecting and controlling the personal information, is primarily responsible for handling complaints from Australian individuals and for any required engagement with the OAIC.

F. Conflict

In the event of a conflict between this Schedule and the body of this DPA with respect to the processing of personal information of Australian individuals, this Schedule 5 shall control to the extent of the conflict.

ACCEPTANCE

This DPA is incorporated into and forms part of the Agreement. For standard subscriptions, no separate execution is required, Customer’s electronic acceptance of the Agreement constitutes Customer’s legally binding acceptance of this DPA as of the Effective Date, as described in the Introduction to this DPA. Eyeclone’s timestamp and acceptance records serve as conclusive evidence of Customer’s acceptance.

FOR ENTERPRISE OR NEGOTIATED AGREEMENTS ONLY.

Where Eyeclone and Customer have separately agreed in writing that this DPA requires manual execution, the parties may execute below. Manual execution is not required for, and does not affect the validity of, click-through acceptances under the standard subscription process.

© 2026 Eyeclone LLC. All Rights Reserved.

A vision of A vision by Trigger

Quick links

  • Home
  • Features
  • Pricing
  • FAQs
  • About us
  • Media hub
  • Contact
  • Become an EYECLONE PARTNER

Location

252 NW 29th Street,
9th Floor, Miami, Florida
USA

Contact details

  • +1 561 418 1807
Data Processing Agreement
|
Acceptable Use Policy
|
Usage Limits
|
Terms of Service
|
Privacy Policy
|
Disclaimer
Eyeclone Linkedin
© 2026 eyeclone. All Rights Reserved