Back to Foundable

Data Processing Addendum

How to execute this DPA

This Data Processing Addendum ("DPA") supplements our Terms of Service (or any separately signed Master Services Agreement). This public page provides the review form; authorized representatives of both parties complete and countersign the account-specific version to make it effective.

To request an executable DPA (often required by enterprise procurement teams), email privacy@foundable.com with your company name, signing authority, processing role, and required transfer mechanism. We will confirm the available form and next steps during intake.

1. Definitions

Unless otherwise defined here, capitalised terms have the meaning given in our Terms of Service or in the GDPR.

  • "Customer" (also "you") means the entity that has agreed to the Terms of Service.
  • "Foundable" (also "we," "us") means Autono Labs, Inc., a Delaware corporation, which operates the Foundable service. ("Foundable" is the product name; the contracting legal entity is Autono Labs, Inc.)
  • "Customer Personal Data" means personal data within Customer Content that Foundable processes on Customer's behalf as part of providing the Service.
  • "Data Protection Laws" means the EU GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA, and any other applicable data-protection or privacy law.
  • "SCCs" means the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner.
  • "Subprocessor" means any third party engaged by Foundable to process Customer Personal Data, as listed at /subprocessors.

2. Roles and scope

For Customer Personal Data, Customer is the "controller" (or, if Customer is itself acting as a processor for an upstream controller, Customer is a "processor"), and Foundable is a "processor" (or "subprocessor," as applicable).

For account data and product telemetry that Foundable collects to operate, secure, and improve the Service (described in our Privacy Policy), including Customer Content captured in selective session replay for Foundable's own product improvement, Foundable is a controller in its own right. That controller-side processing is out of scope for this DPA but is governed by our Privacy Policy. This does not change Foundable's processor role when the same Customer Content is otherwise processed to provide the Service on Customer's instructions.

3. Processing on documented instructions

Foundable processes Customer Personal Data only on Customer's documented instructions. The Terms of Service, the Service's feature configuration in Customer's business, and Customer's interactions with the Service constitute Customer's instructions.

If Foundable is required by law to process Customer Personal Data outside those instructions, we will (where legally permitted) inform Customer before processing.

4. Categories of data and data subjects

The categories of data subjects, personal data, and processing activities covered by this DPA are described in Annex I (below). The duration of processing is the term of the Terms of Service plus the retention period described in our Privacy Policy.

5. Confidentiality

Personnel authorised to process Customer Personal Data are subject to confidentiality obligations and receive role-appropriate security and privacy guidance.

6. Security measures

Foundable implements appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure. The measures are described in Annex II (below) and on our Security page.

7. Subprocessors

Customer authorises Foundable to engage Subprocessors to process Customer Personal Data, subject to the terms of this Section 7. The current list of Subprocessors is at /subprocessors and is incorporated into this DPA.

Foundable will:

  • Use written provider terms that include data-protection obligations required for the applicable processing;
  • Remain liable to Customer for the acts and omissions of its Subprocessors;
  • Keep the public registry current and provide change notice using the method and period stated in the countersigned DPA.

The countersigned copy defines any objection right, cure process, notice period, and termination remedy. The public registry remains the current source for provider changes.

8. Data subject rights

Taking into account the nature of the processing, Foundable will assist Customer (by appropriate technical and organisational measures, where possible) to fulfil Customer's obligations to respond to requests by data subjects exercising their rights under Data Protection Laws. Owners and admins can export foundable data and operators can request account deletion through the product. Contact privacy@foundable.com for authenticated assistance with broader or downstream-provider requests.

If a data subject contacts Foundable directly with a rights request, we will (where lawful) forward it to Customer rather than respond ourselves.

9. Data breach notification

Foundable will notify the customer contact identified in an effective DPA without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Available information may be provided in phases. The notice will include, to the extent known at that time:

  • The nature and scope of the breach;
  • The categories and approximate number of data subjects and records affected;
  • The likely consequences and the measures taken or proposed to address the breach.

We will provide material updates as the investigation progresses. A specific contractual outer limit, if required, must be stated in the countersigned copy and supported by the agreed notice method.

10. Data Protection Impact Assessments

Foundable will provide reasonable assistance to Customer in conducting Data Protection Impact Assessments and prior consultations with supervisory authorities, where required by Data Protection Laws and taking into account the information available to Foundable.

11. Audits

Foundable will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. On reasonable request and no more than once per 12-month period (unless required by a regulator or following a material security incident), Foundable will:

  • Respond to a security questionnaire reasonable in scope and timing;
  • Provide relevant security-assurance materials under NDA, where available;
  • Permit a proportionate audit of Foundable-controlled records, systems, and personnel where the information above is insufficient, subject to confidentiality, security, reasonable notice, non-disruption, and reasonable cost terms in the countersigned DPA. Provider facilities are covered through the applicable provider's assurance materials.

12. International transfers

For a restricted transfer from the EEA, UK, or Switzerland, the countersigned DPA completes the applicable mechanism and its required party, contact, role, authority, selection, and signature details:

  • EEA transfers: the parties may execute the 2021 Standard Contractual Clauses using the module appropriate to their roles, together with completed SCC annexes and the competent supervisory authority.
  • UK transfers: the parties may execute the UK Addendum with all mandatory Part 1 table selections completed and the mandatory clauses incorporated.
  • Swiss transfers: an executed SCC arrangement may be adapted for the Swiss FADP and FDPIC where applicable.

13. Return or deletion of data

Subscription termination does not itself delete an account. Owners and admins can export a JSON copy of certain foundable data, and an operator can initiate account deletion through the product or by an authenticated request. Access is disabled immediately, followed by a 30-day recovery window. Permanent deletion then begins for eligible data. Provider-held copies, financial records, legally retained records, and backups follow their applicable schedules. The countersigned DPA can define any additional return or deletion service level.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws.

15. Order of precedence

In the event of any conflict, the order of precedence is: (1) the SCCs (where applicable); (2) this DPA; (3) the Terms of Service or any separately-signed master agreement.

Annex I: Description of processing

  • Subject matter: provision of an AI-powered operations platform ("Foundable") that processes messages and connected-service data on Customer's instruction.
  • Nature and purpose: hosting, transmitting, displaying, and analysing Customer Content; generating and retrieving AI output; building and previewing app source and backends; creating embeddings and reranking retrieved data; carrying out enabled research, email, social, creative, and domain workflows; and calling third-party integrations Customer has connected.
  • Categories of data subjects: Customer's authorised users (operators, admins), Customer's employees and contractors mentioned in Customer Content, third parties whose data Customer chooses to send through the Service.
  • Categories of personal data: names, email addresses, phone or messaging identifiers, professional profile and prospect data, message and outreach content, files and media, generated app source and backend data, social-account and campaign data, domain-registration data, integration credentials, and any other personal data Customer chooses to include in Customer Content.
  • Special category data: Foundable is designed for general business data and does not request special-category data. Customer must not include it in free-form Customer Content without a separate written agreement that expressly permits the processing.
  • Frequency of transfer: continuous, as Customer uses the Service.
  • Retention period: for the active account or foundable, followed by the recovery, scheduled-deletion, provider-cleanup, and backup-rotation process described in our Privacy Policy).
  • Subprocessors and recipients: see /subprocessors.
  • Competent supervisory authority (SCC Clause 13): completed in the executable SCC package based on the parties and transfer before signature.

Annex II: Technical and organisational measures

Foundable maintains the technical and organisational measures described on our Security page, which include (at minimum):

  • Encryption: HTTPS with TLS in transit; AES-256 at rest in the database; AES-256-GCM at the application layer for OAuth tokens and Integration credentials.
  • Access control: authenticated company routes enforce current membership; cross-company platform-admin triage uses explicit read-only view-as; platform-admin mutations require a TOTP-verified multi-factor session.
  • Resilience: multi-machine production deploy; point-in-time recovery for Foundable's primary production database; project-specific backup and recovery controls for app databases; ECS deployment circuit breakers and a documented manual rollback procedure.
  • Monitoring: error tracking and performance traces via Sentry (with redaction of authorization/cookie headers, URL credentials, structured PII, and known secret fields); uptime via Better Stack; deploy events posted to internal channels.
  • Personnel: personnel authorised to process Customer Personal Data are subject to confidentiality obligations and receive role-appropriate security and privacy guidance.
  • Incident response: notice without undue delay under Section 9, with material investigation updates as more information becomes available.

Annex III: Subprocessors

The authorised Subprocessors processing Customer Personal Data on Foundable's behalf as of the date at the top of this page are:

ProviderScope and purposeData processedPrimary storage / processing locations
Anthropic, PBCCore AI: Claude inference for Ted, workers, and primary build agentsCustomer Content, including chat messages, attached files, retrieved context, and tool inputs and outputsStored in the United States; processing may occur in the United States, Europe, Asia, and Australia unless a separate arrangement narrows it
Agnost Tech Inc.AI quality analytics: AI conversation analytics and product-quality monitoringProjected chat and tool inputs and outputs; tool status; operator and thread identifiers; operator display name and email. Onboarding public-profile source details are omitted before transmission.Provider and subprocessor locations under the applicable service terms; contact Foundable for account-specific details
Exa Labs Inc.Research features: Public-web research, audience discovery, and professional-profile searchDerived search queries, requested public URLs and page content, and limited onboarding identity hints. Full email addresses and locally generated email-username hints are not sent for onboarding search.Provider and subprocessor locations; no single processing region is asserted by Foundable
OpenAIPurpose-specific AI: Embeddings, structured extraction, and audio transcriptionSelected company records or Customer Content submitted for embedding or structured extraction; audio submitted for transcriptionUnited States and other OpenAI or subprocessor locations unless a separate data-residency arrangement applies
Cohere Inc.Purpose-specific AI: Reranking search results and retrieved company contextThe search query and candidate text passages selected for rerankingAccount and subprocessor locations under the applicable Cohere agreement; no single region is asserted by Foundable
Supabase, Inc.Core infrastructure: Managed Postgres database, authentication, and object storageAccount data, Customer Content, authentication data, and encrypted integration credentialsFoundable's primary project is in AWS us-west-1; support and subprocessor processing may occur elsewhere under Supabase's DPA
Amazon Web Services, Inc.Core infrastructure: API hosting, worker runtime, network protection, and service logsRequests in transit, runtime data needed to execute work, and application, security, and infrastructure logsAWS us-west-1 for Foundable's API and worker infrastructure; other AWS locations may support the service
Daytona Platforms Inc.Build features: Isolated cloud sandboxes and previews for building appsBuild instructions, generated or uploaded app source and files, build output, logs, and preview artifactsProvider infrastructure selected for the Foundable tenant; contact Foundable for account-specific details
fal.aiCreative features: Image and video generationCreative prompts, reference media, generated outputs, and request metadataProvider and model infrastructure locations; no single processing region is asserted by Foundable
AgentMail, Inc.Email features: Managed inboxes and customer-directed email outreachSender and recipient addresses, subjects, message bodies, attachments, replies, and delivery eventsUnited States and European Union under AgentMail's current subprocessor list
ZERNIO SOFTWARE SLSocial features: Connection and publishing to social networksConnected-account credentials and identifiers, post copy and media, publishing status, and engagement analyticsSpain / European Union and provider subprocessor locations
PostHog, Inc.Product analytics: First-party product analytics, feature flags, and selective session replay for operational debugging and product improvementOperator and pseudonymous session identifiers, bounded operator role, page and route families, interaction and product events, performance and limited network diagnostic metadata, replay page structure, ordinary interface text outside designated private regions, and Customer Content in submitted chat with Ted replies as displayed. Input values and unsent drafts are masked; media and designated private regions are blocked; recorded URLs are sanitized; request and response header and body contents are omitted.United States (Foundable uses PostHog Cloud US); provider support and subprocessor processing may occur elsewhere under PostHog's DPA and subprocessor list
Functional Software, Inc. (Sentry)Error monitoring: Error monitoring and performance tracingStack traces, request URLs, user identifiers, and diagnostic context. Sensitive headers, URL credentials, known secret fields, and structured PII are redacted, but diagnostic context can still incidentally contain Customer Content.United States ingestion region
Stripe, LLC and applicable Stripe affiliatesBilling: Payment processing and subscription administration where Stripe acts for FoundableBilling contact and address, payment-method metadata, invoices, subscriptions, transaction history, and fraud or dispute information. Full card numbers are entered directly with Stripe.Stripe and payment-network locations under the applicable agreement
Plus Five Five, Inc. (Resend)Transactional email: Delivery of login links, notices, and receiptsRecipient addresses, message content, attachments where applicable, and delivery metadataUnited States and subprocessor locations under Resend's DPA
Vercel, Inc.Web application: UI hosting and edge deliveryWeb requests, IP and device metadata, static assets, and data transmitted through the UI; Customer Content is not intentionally stored in the UI hosting layerPrimary processing in the United States with global edge and support processing
Cloudflare, Inc.Selected infrastructure features: Turnstile bot protection, browser rendering, and DNS management for applicable customer domainsChallenge, device, and network data; rendered page or preview content; and domain names and DNS records for domains managed through CloudflareGlobal network
Hunter Web Services, Inc.Grow email features: Email finding and verification performed on customer-submitted inputsNames, company domains, email addresses, and verification or lookup inputs. Hunter separately acts as a controller for the professional Profile Data it maintains and returns.Primary servers in Belgium, with other European Union and United States service providers
LoopMessageText-message channel: Delivery and receipt of customer-directed iMessage or SMS conversationsMessage content, sender and recipient identifiers, replies, thread and delivery metadata, webhooks, and diagnostic recordsUnited States hosting; message and API history may be retained for up to six months under the current public policy

The canonical, continuously-updated list lives at /subprocessors. Changes and any objection right follow Section 7 and the notice method and period completed in the countersigned DPA.

Miscellaneous

Order of precedence. In the event of a conflict between this DPA and the Terms, this DPA controls for the subject matter it covers. Where the SCCs apply, they prevail over both for transfers within their scope.

Assignment. Neither party may assign this DPA without the other's prior written consent, except that either party may assign it to an affiliate or in connection with a merger, acquisition, or sale of substantially all of its assets, in each case on notice to the other party. Any attempted assignment in breach of this section is void.

Severability. If any provision of this DPA is held unenforceable, the remaining provisions remain in effect, and the parties will replace the unenforceable provision with one that achieves, as closely as legally permissible, the original intent.

No third-party beneficiaries. Except for data subjects' rights under the SCCs and GDPR (which the parties acknowledge), this DPA creates no rights in any third party.

Need a counter-signed copy?

Email privacy@foundable.com with your company name, signing authority, and requested transfer mechanism. We will confirm the available form and next steps during intake.

Questions about this document? privacy@foundable.com

Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.

Continue to footer navigation