Skip to content
IP Craft

Data Processing Agreement

Last updated: July 19, 2026 · Version 2026-07-19

This Data Processing Agreement forms part of your Agreement with Pipcast, Inc. and is accepted when you sign up for IP Craft. The current sub-processors are listed on our Sub-processors & providers page. Data-protection questions: privacy@ipcraft.co.

This Data Processing Agreement, including its Schedules (the “DPA”), forms part of the agreement, terms of service, order form, master subscription agreement, or other written agreement governing Customer’s access to or use of the Service (the “Agreement”) between Pipcast, Inc., a Delaware corporation (“Pipcast”), and the customer identified in the Agreement (“Customer”).

Pipcast and Customer are each a “Party” and together the “Parties.”


1. Purpose, scope, and precedence

1.1 Purpose

This DPA governs Pipcast’s Processing of Customer Personal Data on behalf of Customer in connection with Pipcast’s hosted IP Craft patent-prosecution and portfolio-management platform and related services (the “Service”).

1.2 Scope

This DPA applies only to Customer Personal Data. It does not reduce any confidentiality, security, or other obligations concerning Customer Content under the Agreement. Customer Content may contain confidential, privileged, proprietary, or technically sensitive information that is not Personal Data; those materials remain governed by the Agreement even where this DPA does not apply.

1.3 Order of precedence

For the subject matter of data protection, conflicts are resolved in the following order:

  1. the UK Addendum, for a UK Restricted Transfer;
  2. the EU SCCs, as supplemented by the Swiss Amendments where applicable;
  3. this DPA; and
  4. the Agreement.

The higher-ranking document prevails only to the extent of the conflict and only for the Processing or transfer to which it applies. The Agreement otherwise remains in effect, including its limitations and exclusions of liability, subject to Section 14.

1.4 Term

This DPA begins when the Agreement becomes effective, or when the Parties otherwise become legally bound by this DPA, and continues for as long as Pipcast Processes Customer Personal Data. Sections that by their nature should survive, including Sections 10, 11, 12, 14, and 15, survive termination.


2. Definitions and roles

2.1 Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement or applicable Data Protection Laws.

  • “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.
  • “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Process,” “Processing,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given in the EU GDPR and include materially equivalent terms under other Data Protection Laws, such as “business,” “service provider,” “contractor,” “consumer,” and “personal information” under the CCPA.
  • “Customer Personal Data” means Personal Data contained in Customer Content or otherwise Processed by Pipcast on behalf of Customer under the Agreement, as described in Schedule 1. Customer Personal Data excludes (a) Customer Account Data and (b) data that has been validly aggregated or deidentified so that it is no longer Personal Data under applicable Data Protection Laws, provided Pipcast does not attempt to reidentify it except to test the effectiveness of deidentification where legally permitted.
  • “Customer Account Data” means business-contact, account-registration, subscription, contracting, invoicing, payment-identifier, transaction, fraud-prevention, tax, and relationship-management data that Pipcast Processes as an independent Controller to establish, administer, secure, and account for its commercial relationship with Customer. Customer Account Data does not include Personal Data contained in Customer Content or Personal Data Processed solely on Customer’s behalf. Pipcast Processes Customer Account Data as an independent Controller under Pipcast’s own privacy notice and applicable law; such Processing is outside the scope of this DPA.
  • “Data Protection Laws” means laws and binding regulations applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable, the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), the CCPA, and other U.S. State Privacy Laws.
  • “DPA Effective Date” means the date this DPA becomes effective under Section 1.4 — that is, the date the Agreement becomes effective or the date the Parties otherwise become legally bound by this DPA, whichever applies.
  • “EU GDPR” means Regulation (EU) 2016/679.
  • “EU SCCs” means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914.
  • “Restricted Transfer” means a transfer of Personal Data for which applicable Data Protection Laws require an approved transfer mechanism because the recipient is located in, or the Personal Data is accessible from, a jurisdiction not recognized as providing adequate protection.
  • “Subprocessor” means a third party engaged by Pipcast to Process Customer Personal Data on Customer’s behalf.
  • “Swiss Amendments” means the adaptations in Schedule 4, Part C, for transfers governed by the FADP.
  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, issued by the UK Information Commissioner and in force from March 21, 2022, as revised under its terms.
  • “UK GDPR” has the meaning given in section 3 of the UK Data Protection Act 2018.
  • “U.S. State Privacy Laws” means U.S. state comprehensive privacy laws applicable to the Processing, including the CCPA and comparable controller-processor laws.

2.2 Roles

For Customer Personal Data:

  • where Customer determines the purposes and means of Processing, Customer is the Controller and Pipcast is the Processor; and
  • where Customer Processes Personal Data on behalf of another Controller, Customer is a Processor and Pipcast is Customer’s Subprocessor.

Customer is responsible for correctly identifying its role and obtaining all instructions, authorizations, consents, and contractual rights necessary to appoint Pipcast. Where Customer acts as a Processor, Customer represents that the relevant Controller has authorized Customer to appoint Pipcast and Pipcast’s Subprocessors in accordance with this DPA.

2.3 Independent Processing

Pipcast Processes Customer Account Data as an independent Controller for its own legitimate business administration, contracting, billing, taxation, legal-compliance, fraud-prevention, security, and relationship-management purposes. Each Party likewise acts as an independent Controller for other Personal Data it Processes for its own such purposes, to the extent that Processing is not performed on behalf of the other Party. This independent Processing is outside the scope of this DPA and is not subject to the Processor obligations, the return/deletion obligations in Section 11, or the Subprocessor obligations in Section 7 with respect to Customer Personal Data. Where the same data element is contained in Customer Content or is Processed solely on Customer’s behalf, it is Customer Personal Data and this DPA applies to that Processing. The classification of a data element depends on the purpose for which Pipcast Processes it: to the extent Pipcast Processes user identity, authentication, role, or security data solely to provide Customer-configured access to the Service, it is Customer Personal Data; to the extent Pipcast independently Processes the same or similar data for Pipcast’s account security, fraud prevention, legal compliance, contracting, or relationship administration, it is Customer Account Data.


3. Processing details and documented instructions

3.1 Processing details

The subject matter, duration, nature, purpose, frequency, categories of Data Subjects, and types of Customer Personal Data are described in Schedule 1.

3.2 Documented instructions

Pipcast will Process Customer Personal Data only on Customer’s documented instructions, except where applicable law requires otherwise (Section 3.3). Customer’s documented instructions comprise the Agreement, this DPA, Customer’s configuration and use of supported Service functionality, instructions submitted through the Service, and the Processing necessary to provide, secure, maintain, support, and administer the Service and its features as configured or initiated by Customer and its authorized users. These constitute Customer’s complete documented instructions; Customer may issue additional instructions under Section 3.4.

3.3 Legally required Processing

If applicable law requires Pipcast to Process Customer Personal Data other than on Customer’s instructions, Pipcast will inform Customer of the legal requirement before Processing unless the law prohibits notice on important grounds of public interest.

3.4 Additional instructions

Additional instructions must be agreed in writing. Pipcast may charge reasonable fees for additional assistance or instructions that exceed the Service or Pipcast’s obligations under Data Protection Laws. Pipcast may decline an instruction to the extent it is unlawful, technically infeasible, would materially change the Service, would require Pipcast to violate another customer’s rights, or would create an unreasonable security risk. Pipcast will explain the basis for declining the instruction to the extent legally permitted.

3.5 Unlawful instructions

Pipcast will inform Customer without undue delay if, in Pipcast’s reasonable opinion, an instruction infringes applicable Data Protection Laws. Pipcast may suspend the affected Processing until the Parties resolve the issue.

3.6 AI use limitation

Pipcast will not use Customer Content or Customer Personal Data to train, fine-tune, or otherwise improve any shared or general-purpose artificial-intelligence or machine-learning model, and will not permit a Subprocessor or model provider to do so. This restriction does not prohibit: (a) inference necessary to provide AI-assisted Service features; or (b) retrieval-augmented generation, indexing, and Customer-specific configuration using Customer-isolated data that do not train or modify model weights. Customer-specific model training or fine-tuning is permitted only under a separate written AI addendum specifying the training data, purposes, model ownership and isolation, retention and deletion, evaluation data, applicable Subprocessors, Processing locations, and security measures. Pipcast may use deidentified and aggregated Service telemetry that does not contain Customer Content or Personal Data to operate, secure, and improve the Service.

Pipcast will Process Customer Personal Data through its managed AI provider (Amazon Bedrock) only using a model and interface combination for which either: (a) AWS expressly documents that request and response content supplied to the inference service is not stored by the Bedrock inference service and is not shared with the model provider; or (b) the effective account or project data-retention configuration is zero-retention (the none mode) and the selected model and interface support that configuration. Pipcast will not permit provider_data_share, default, or any other configuration under which Customer Personal Data is stored or shared with a model provider for the provider’s own purposes. Where the none configuration applies, Pipcast will use account, project, IAM, or service-control-policy controls designed to prevent a less-protective mode from applying to Customer Personal Data. Pipcast will not use a model or interface to Process Customer Personal Data unless its documented and effective data-handling configuration satisfies this paragraph. A model provider that Processes data for its own purposes is not a Subprocessor and cannot be treated as one merely by being listed in Schedule 3; Pipcast will not enable such Processing of Customer Personal Data without Customer’s express written authorization and all legally required disclosures, transfer safeguards, and contractual arrangements (see Schedule 3).

For clarity, the content-handling configuration above governs retention and use by the Amazon Bedrock inference service and the model provider; it does not by itself govern Pipcast-controlled application logging or Amazon Bedrock model-invocation logging that may capture prompt or output content. Pipcast will keep logging of prompt and output content in application logs and Bedrock model-invocation logs disabled by default. Pipcast may temporarily enable minimized content logging only where reasonably necessary to investigate a specific security or support incident, or at Customer’s documented request. Any such logging will be limited to the minimum content and duration necessary, protected by appropriate access controls, subject to a documented retention period not exceeding thirty (30) days unless applicable law requires otherwise, and deleted under the obligations in Section 11. Persistent content logging requires express disclosure in Schedule 2 or a written amendment to this DPA.


4. Customer responsibilities

4.1 Lawfulness

Customer is responsible for:

  • the lawfulness, fairness, and transparency of its collection and use of Customer Personal Data;
  • providing legally required privacy notices;
  • establishing a valid legal basis and obtaining required consents or authorizations;
  • ensuring its instructions comply with Data Protection Laws;
  • the accuracy, quality, and relevance of Customer Personal Data;
  • determining whether the Service is appropriate for Customer’s intended Processing; and
  • responding to Data Subjects and regulators except to the extent this DPA requires Pipcast’s assistance.

4.2 Customer configuration and security

Customer is responsible for its user accounts, roles, permissions, authentication credentials, endpoints, integrations, and Service configuration, and for promptly disabling access that is no longer authorized.

4.3 Sensitive data

The Service is not designed for routine or large-scale Processing of special-category Personal Data under Article 9 EU GDPR, criminal-conviction data, regulated financial-account credentials, government identification numbers, or other highly sensitive data. Customer will not intentionally submit such data unless it is reasonably necessary for the patent or invention matter and Customer has a lawful basis to Process it, and will not initiate recurring or large-scale Processing of such data without first executing a written addendum with Pipcast.

The Service is not offered as a HIPAA-compliant service, and Customer will not submit protected health information subject to HIPAA unless the Parties have first executed a HIPAA-compliant Business Associate Agreement and Pipcast has confirmed in writing that the applicable Service configuration is authorized for that use. A generic data-protection or sensitive-data addendum is not a Business Associate Agreement.

Where such data appears incidentally, Pipcast applies the safeguards described in Schedule 2, including strict purpose limitation, tenant-scoped access controls, encryption at rest and in transit as described in Schedule 2, logging of relevant administrative actions and audit events as described in Schedule 2, restriction of onward transfer to the listed Subprocessors, the AI-use restrictions in Section 3.6, and the deletion obligations in Section 11.


5. Confidentiality and personnel

5.1 Confidentiality

Pipcast will ensure that personnel authorized to Process Customer Personal Data:

  • are bound by an appropriate contractual or statutory duty of confidentiality;
  • receive access only on a need-to-know basis;
  • Process Customer Personal Data only as authorized by Pipcast and consistent with Customer’s instructions; and
  • remain subject to confidentiality obligations after their authorization ends.

5.2 Access limitation

Pipcast will take reasonable steps to ensure that access privileges are appropriate to personnel responsibilities and are revoked or adjusted when no longer required.


6. Security of Processing

6.1 Security program

Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and risks to Data Subjects, Pipcast will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

6.2 Measures

The measures maintained by Pipcast and the measures required to be implemented no later than the DPA Effective Date are described in Schedule 2. Pipcast may modify them as technologies and risks evolve, provided the modifications do not materially reduce the overall level of protection during the term.

6.3 Security limitations

No system is completely secure. Pipcast’s obligations are obligations to maintain appropriate measures, not a warranty that a Personal Data Breach or security incident will never occur.


7. Subprocessing

7.1 General authorization

Customer grants Pipcast general written authorization to engage Subprocessors. The current Subprocessors are listed in Schedule 3, Part A. (Schedule 3, Part B lists other material providers that are not Subprocessors under this DPA.)

Where Customer acts as a Processor, Customer confirms that the relevant Controller has provided any general or specific authorization required for Pipcast’s appointment of Subprocessors. Customer will promptly notify Pipcast if that authorization is withdrawn or limited.

7.2 Written terms and responsibility

Before a Subprocessor Processes Customer Personal Data, Pipcast will enter into a written agreement requiring the Subprocessor to protect the data through obligations that are, in substance, no less protective than those applicable to Pipcast under this DPA, to the extent relevant to the Subprocessor’s services. Pipcast remains responsible to Customer for the Subprocessor’s performance of those obligations to the extent required by Data Protection Laws.

For Processing subject to the EU SCCs or the UK Addendum, the Subprocessor terms will also include the obligations, third-party-beneficiary protections, and direct return-or-erasure rights required by Clause 9 of the applicable Module — including the exporter’s ability, where the importer has factually or legally disappeared or become insolvent, to terminate the Subprocessor contract and require return or erasure of the transferred Personal Data — or the Subprocessor will validly accede to an applicable transfer instrument that provides equivalent rights.

7.3 Changes and notice

Pipcast will deliver written notice to Customer’s designated account or privacy contact, by email or in-Service notice, at least thirty (30) days before an intended addition or replacement of a Subprocessor begins Processing Customer Personal Data. Pipcast may also maintain a Subprocessor webpage or subscription mechanism, but posting alone does not replace the direct notice required by this Section or by an applicable transfer mechanism.

Module Three notices. Before Module Three of the EU SCCs applies to a Restricted Transfer, Customer will identify the underlying Controller and provide the Controller’s current notice contact, or represent and warrant that the Controller has expressly authorized Customer to receive and administer the Controller’s Clause 9 intended-Subprocessor notices and objections as the Controller’s agent. Pipcast will deliver each notice required by Module Three either directly to the Controller or to Customer in its expressly authorized agency capacity, and Customer will promptly communicate the Controller’s decision or objection to Pipcast. If Customer does not provide the required Controller information or agency authorization, Customer will not initiate a Module Three Restricted Transfer through the Service.

7.4 Objections

Customer may object within fifteen (15) days after notice on reasonable grounds specifically relating to the protection of Customer Personal Data. The Parties will work in good faith to resolve the objection, including by considering commercially reasonable alternative configurations or safeguards.

If the objection cannot be resolved and Pipcast cannot provide the affected Service through a commercially reasonable alternative, Customer may terminate the affected Service. If the affected Service is material to the Agreement, Customer may terminate the Agreement. Pipcast will refund prepaid fees allocable to the terminated Service for the period after termination. Termination does not affect accrued rights or liabilities or rights that cannot lawfully be waived.

SCC- and UK-covered Processing. For Customer Personal Data subject to the EU SCCs or the UK Addendum, Pipcast will not permit the proposed Subprocessor to begin Processing that Customer Personal Data while a timely objection remains unresolved. If the Parties cannot resolve the objection through commercially reasonable safeguards or alternatives, either Party may terminate the affected Service, and Pipcast may discontinue the affected Processing, before the proposed Subprocessor begins Processing the covered Customer Personal Data. This paragraph does not grant Customer a right to require Pipcast to continue providing a Service without a Subprocessor that Pipcast reasonably determines is necessary.

Module Three objection rights. For Processing subject to Module Three of the EU SCCs, the underlying Controller’s objection rights are those provided by the EU SCCs and are not narrowed by the “reasonable grounds specifically relating to the protection of Customer Personal Data” standard in this Section, which applies to objections outside the transfer mechanism.

Country changes and transfer-mechanism replacement. A material addition of a country in which a Subprocessor will store Customer Personal Data, or from which a Subprocessor will remotely access or materially Process Customer Personal Data, in connection with adding or replacing a Subprocessor is subject to the ordinary notice and objection rights in Sections 7.3–7.4 (including, for SCC- and UK-covered Processing, the pre-engagement hold above). For a material addition of a processing country that is not tied to a Subprocessor addition or replacement, Pipcast will provide reasonable advance notice where practicable, and the Parties will discuss a substantiated transfer-risk concern in good faith. Pipcast may replace or supplement a transfer mechanism with another valid mechanism upon reasonable notice under Section 12.5, provided the replacement validly covers the transfer and does not materially reduce the overall protection of Customer Personal Data; a transfer-mechanism replacement alone does not create a Subprocessor objection right.

7.5 Emergency changes

Where an urgent security, legal, availability, or operational risk requires a shorter implementation period, Pipcast may shorten the notice period only to the extent permitted by applicable Data Protection Laws, will provide notice as soon as reasonably practicable, and Customer retains the objection rights in Section 7.4. This Section does not override any requirement under the EU SCCs or the UK Addendum to give notice before a Subprocessor begins Processing covered Personal Data and to provide a meaningful opportunity to object before engagement.


8. Data Subject and consumer requests

8.1 Assistance

Taking into account the nature of the Processing, Pipcast will provide reasonable assistance through appropriate technical and organizational measures and available Service functionality to enable Customer to respond to requests to exercise rights under Data Protection Laws, including access, correction, deletion, restriction, portability, objection, and rights concerning automated decision-making where applicable.

8.2 Requests received by Pipcast

If Pipcast receives a request from a Data Subject concerning Customer Personal Data, Pipcast will not substantively respond unless Customer authorizes it or applicable law requires it. Pipcast may acknowledge receipt or direct the requester to Customer. To the extent legally permitted, Pipcast will promptly notify Customer and provide the request or relevant details.

8.3 Costs

Pipcast may charge reasonable fees for assistance that is unusually burdensome, repetitive, technically infeasible through standard Service functionality, or beyond Pipcast’s legal obligations, after giving Customer advance notice. Pipcast will not charge for assistance to the extent prohibited by Data Protection Laws.


9. Personal Data Breaches and regulatory assistance

9.1 Breach notice

Pipcast will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. An initial notice may be based on information then available and may be supplemented as the investigation progresses.

9.2 Notice contents

To the extent known and reasonably available, Pipcast’s notice will include:

  • the nature of the Personal Data Breach;
  • the categories and approximate number of affected Data Subjects and records;
  • likely consequences;
  • measures taken or proposed to contain, investigate, mitigate, and remediate the breach; and
  • a contact point for further information.

Pipcast will take reasonable steps to contain, investigate, mitigate, and remediate the Personal Data Breach and will provide material updates as appropriate.

9.3 No admission

A notice or response under this Section is not an admission of fault or liability.

9.4 Customer notifications

Customer is responsible for determining whether notice to a Supervisory Authority, Data Subject, customer, client, or other person is required and for the content and timing of that notice. Pipcast will not notify third parties concerning a Customer Personal Data Breach without Customer’s approval unless legally required.

9.5 Article 32–36 assistance

Taking into account the nature of the Processing and information available to Pipcast, Pipcast will provide reasonable assistance with Customer’s obligations concerning security of Processing, breach notifications, data protection impact assessments, prior consultations, and comparable risk-assessment or regulator-engagement duties.

Pipcast may charge reasonable fees for assistance that exceeds Service functionality or Pipcast’s obligations under Data Protection Laws, except to the extent the assistance is required because of Pipcast’s material breach of this DPA.


10. Compliance information and audits

10.1 Information

Pipcast will make available to Customer information reasonably necessary to demonstrate Pipcast’s compliance with this DPA and applicable processor or service-provider obligations.

10.2 Documentation-first review

Customer will first use current security summaries, completed questionnaires, third-party reports or certifications if available, architecture information, policies, and other relevant documentation Pipcast makes available. Pipcast may redact information where reasonably necessary to protect security, privilege, other customers, or third-party confidentiality.

10.3 Audit right

If the materials in Section 10.2 are insufficient to demonstrate compliance, or Customer has reasonable grounds to believe Pipcast is materially noncompliant, Pipcast will allow and contribute to an audit, including an inspection where required by applicable Data Protection Laws, conducted by Customer or a qualified independent auditor that:

  • is not a competitor of Pipcast;
  • is bound by written confidentiality obligations;
  • has appropriate expertise; and
  • complies with reasonable security and safety requirements.

10.4 Audit conditions

Except following a Personal Data Breach, at the direction of a Supervisory Authority, or where Customer has reasonable evidence of material noncompliance, an audit may occur no more than once in any twelve-month period and on at least thirty (30) days’ prior written notice. Audits must occur during normal business hours, minimize disruption, avoid access to other customers’ data, and not require disclosure of information that would create a material security risk, violate law, waive privilege, or breach another party’s confidentiality.

10.5 Costs and findings

Customer bears its audit costs and will reimburse Pipcast’s reasonable internal and third-party costs, unless the audit identifies material noncompliance by Pipcast, in which case Pipcast will bear its own reasonable costs and promptly develop a remediation plan. The Parties will discuss audit findings in good faith, and Customer will keep the findings confidential except where disclosure is required by law or to a Supervisory Authority.

10.6 Nonwaivable rights

Nothing in this Section limits audit, inspection, or information rights that cannot lawfully be limited under the EU SCCs, UK Addendum, FADP, CCPA, or other Data Protection Laws.


11. Return and deletion

11.1 During the term

During the term, Customer may use available Service functionality to export, correct, or delete Customer Personal Data.

11.2 End of Services

Upon termination or expiry of the Agreement, Pipcast will, at Customer’s choice, (a) return a copy of Customer Personal Data and then delete existing copies, or (b) delete Customer Personal Data and existing copies, in each case within sixty (60) days, unless applicable law requires continued retention. Customer must request return within thirty (30) days after termination and cooperate with reasonable export procedures; if Customer does not timely request return, Customer is deemed to have selected deletion. This Section does not require deletion of Customer Account Data, which Pipcast retains as an independent Controller under its applicable privacy notice and retention obligations.

11.3 Certification

On written request, Pipcast will provide written confirmation of the deletion completed under Section 11.2. The confirmation will identify any Customer Personal Data retained because applicable law requires storage, the applicable legal basis, the limited continued purpose, and the expected deletion date, and will identify routine backups pending automatic expiration by category and expected expiration date where reasonably available. Pipcast will not certify unconditional deletion while known copies remain.

11.4 Backups

Customer Personal Data in routine backups will be deleted or overwritten according to Pipcast’s backup-retention cycle. Until deletion, backup data remains subject to this DPA, is not used for ordinary business purposes, and is restored only where reasonably necessary for controlled backup-restoration, disaster-recovery, or business-continuity testing, or for actual recovery. If restored, applicable deletion requests will be re-applied where reasonably practicable.

11.5 Legally required retention

Where law requires retention, Pipcast will isolate the retained Customer Personal Data from further Processing except as required by law and will continue to protect it under this DPA.

11.6 Append-only integrity and audit records

During the term, certain prosecution-event and audit records may be maintained on an append-only basis under Customer’s documented instructions for the Service’s integrity, security, and audit functions. Pipcast will apply Customer-directed correction or deletion to those records through the mechanism implemented for that purpose and described in current Service documentation, including irreversible anonymization where appropriate. Notwithstanding the foregoing, upon termination or expiry Pipcast will delete or return all Customer Personal Data contained in those records within the period in Section 11.2, unless applicable law requires continued storage. Pipcast may retain non-personal cryptographic hashes, signatures, or integrity digests only where they cannot reasonably be used to identify a Data Subject or to reconstruct Customer Content.


12. International data transfers

12.1 Processing locations

Customer authorizes Pipcast and its Subprocessors to Process Customer Personal Data in the United States and other locations identified in Schedule 3, subject to this Section 12.

12.2 EU Restricted Transfers

Where Customer transfers Customer Personal Data to Pipcast in a manner subject to Chapter V EU GDPR, the transfer is not covered by an adequacy decision or another valid mechanism, and the EU SCCs are legally available for the transfer, the EU SCCs apply as completed in Schedule 4:

  • Module Two applies where Customer is a Controller and Pipcast is a Processor.
  • Module Three applies where Customer is a Processor and Pipcast is a Subprocessor.

12.3 UK Restricted Transfers

For a UK Restricted Transfer, the UK Addendum applies to the EU SCCs as completed in Schedule 4, Part B.

12.4 Swiss Restricted Transfers

For a Restricted Transfer governed by the FADP, the EU SCCs apply with the Swiss Amendments in Schedule 4, Part C.

12.5 Alternative mechanisms

Where another lawful transfer mechanism validly covers a transfer—such as an applicable adequacy decision, a data-privacy framework certification that covers Pipcast and the transferred data, binding corporate rules, or another approved mechanism—Pipcast may rely on that mechanism upon reasonable notice. The EU SCCs, UK Addendum, or Swiss Amendments continue to apply until the alternative mechanism validly covers the transfer and may continue as a supplemental safeguard where lawful.

12.6 Transfer assessments

Pipcast will provide information reasonably available to it that Customer needs to conduct a transfer impact assessment or similar legally required assessment. Customer remains responsible for determining whether its transfer is lawful and whether supplementary measures are required.

12.7 Government access requests

To the extent legally permitted, Pipcast will notify Customer of a legally binding request from a public authority seeking Customer Personal Data. Pipcast will review the request for legal validity, challenge requests where it reasonably concludes there are lawful grounds to do so, and disclose only the minimum data legally required. The EU SCCs and UK Addendum control where they impose more specific obligations.


13. U.S. State Privacy Laws

13.1 California role

To the extent Customer Personal Data is “personal information” subject to the CCPA and Customer is a “business,” Customer discloses the personal information to Pipcast solely for the limited and specified business purposes in Section 13.2. Pipcast acts as a service provider or contractor, as applicable.

13.2 Specific business purposes

The limited and specified business purposes are:

  1. hosting, storing, organizing, backing up, transmitting, and making Customer Personal Data available through the Service;
  2. authenticating users, administering accounts, enforcing tenant isolation, permissions, and access controls;
  3. performing Customer-directed patent, document, workflow, docketing, search, analytics, and AI-assisted drafting or analysis functions;
  4. sending Customer-configured transactional notifications and communications;
  5. providing technical support, troubleshooting, error monitoring, service maintenance, security monitoring, abuse prevention, fraud prevention, incident response, and service continuity; and
  6. complying with applicable law and valid legal process to the extent permitted for service providers and contractors.

Customer discloses Customer Personal Data to Pipcast only for these purposes and the Processing details in Schedule 1. These purposes do not authorize Pipcast to use Customer Personal Data for cross-context behavioral advertising or unrelated commercial profiling.

13.3 Restrictions

Pipcast will not, except as expressly permitted by the CCPA:

  • sell or share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data for a purpose other than the purposes in Section 13.2;
  • retain, use, or disclose Customer Personal Data for an unrelated commercial purpose;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer; or
  • combine Customer Personal Data with Personal Data received from another person or collected from Pipcast’s own interaction with a consumer, except as permitted by the CCPA and its regulations.

13.4 Required protections and remediation

Pipcast will comply with applicable CCPA obligations and provide the same level of privacy protection required of service providers and contractors. Pipcast will notify Customer after determining that it can no longer meet those obligations. Customer may take reasonable and appropriate steps to ensure compliant use and, upon notice, to stop and remediate unauthorized use.

Subject to Section 10, Pipcast will provide information or permit assessments reasonably necessary for Customer to verify that Pipcast’s use is consistent with Customer’s CCPA obligations.

13.5 Consumer requests

Pipcast will enable Customer to comply with consumer requests through available Service functionality or reasonable assistance. Customer will inform Pipcast of requests requiring Pipcast’s action and provide information reasonably necessary for Pipcast to comply.

13.6 Cybersecurity audits and risk assessments

To the extent applicable, Pipcast will cooperate with Customer: (a) in Customer’s completion of a cybersecurity audit, including by making available to Customer’s auditor all relevant information the auditor requests to complete the audit that is in Pipcast’s possession, custody, or control, and by not misrepresenting any fact the auditor deems relevant; and (b) in Customer’s completion of a risk assessment, including by making available to Customer all facts necessary to conduct the assessment that are in Pipcast’s possession, custody, or control, and by not misrepresenting any fact necessary to conduct the assessment. Such cooperation is subject to reasonable confidentiality, security, privilege, and tenant-isolation safeguards that do not prevent compliance with applicable law.

13.7 Subcontractors

Pipcast will require each Subprocessor that qualifies as a service provider, contractor, or processor under applicable U.S. State Privacy Laws to comply with applicable statutory and contractual restrictions.

13.8 Certification

Pipcast certifies that it understands and will comply with the restrictions in this Section 13.

13.9 Other U.S. State Privacy Laws

To the extent another U.S. State Privacy Law applies and requires a contract between a Controller and Processor, the Parties agree that:

  • Pipcast will Process Customer Personal Data only on Customer’s documented instructions and for the purposes in this DPA;
  • each person Processing the data is subject to confidentiality;
  • Pipcast will maintain appropriate security measures;
  • Pipcast will assist Customer with applicable consumer-rights, security, breach, risk-assessment, and regulator obligations, taking into account the nature of Processing and information available;
  • Pipcast will delete or return Personal Data as required by Section 11;
  • Pipcast will bind Subprocessors to applicable data-protection duties; and
  • Pipcast will make information available and allow reasonable assessments or audits as required by Section 10 and applicable law.

14. Liability

14.1 Agreement limitations

Each Party’s and its affiliates’ aggregate liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent application of an exclusion or limitation would contradict or undermine Clause 12 of the EU SCCs, the corresponding provisions of the UK Addendum or Swiss Amendments, or the rights of Data Subjects under those instruments. Liability under the Agreement and this DPA is aggregated and not cumulative, and the Parties intend the Agreement’s limitations to remain effective to the maximum extent permitted by law and by any applicable transfer mechanism.

14.2 Mandatory rights

Nothing in the Agreement or this DPA limits:

  • liability to Data Subjects under the EU SCCs, UK Addendum, or applicable law to the extent such liability cannot lawfully be limited;
  • a Supervisory Authority’s powers; or
  • any right or remedy that cannot lawfully be waived.

15. General

15.1 Governing law and jurisdiction

Except for matters governed by the EU SCCs, UK Addendum, Swiss Amendments, or mandatory Data Protection Laws, this DPA is governed by the law and jurisdiction specified in the Agreement.

15.2 Amendments

Pipcast may amend this DPA on reasonable notice solely to reflect changes in Data Protection Laws, binding regulatory guidance, approved transfer mechanisms, or factual updates to the Service and Subprocessors, provided the amendment does not materially reduce the overall protection of Customer Personal Data or materially expand Pipcast’s Processing purposes. Subprocessor changes remain governed by Section 7. Any other material amendment requires the Parties’ written agreement.

15.3 Severability

If a provision is invalid or unenforceable, it will be interpreted or replaced to most closely achieve its lawful purpose, and the remaining provisions continue in effect.

15.4 Notices

Notices under this DPA must be given as provided in the Agreement. Data-protection notices to Pipcast may also be sent to privacy@ipcraft.co. Customer is responsible for maintaining current notice and account contacts.

15.5 Acceptance and counterparts

The Parties may enter into this DPA by signature, electronic acceptance, clickwrap acceptance of the Agreement that incorporates this DPA, or another legally binding method. Electronic signatures and counterparts are effective as originals.

15.6 Entire agreement concerning Processing

This DPA and the Agreement are the Parties’ complete agreement concerning Pipcast’s Processing of Customer Personal Data and supersede prior or contemporaneous terms on that subject, except a signed agreement that expressly states it overrides this DPA.


Schedule 1 — Details of Processing and SCC Annex I

A. Parties

Data exporter

  • Name: Customer identified in the Agreement.
  • Address: Customer’s address stated in the Agreement, Order Form, or Customer account.
  • Contact: Customer’s account owner, privacy contact, data protection officer, or other contact designated to Pipcast.
  • Activities: use of the Service for patent-prosecution, portfolio-management, document, workflow, docketing, administrative, and related business purposes.
  • Role under Module Two: Controller.
  • Role under Module Three: Processor acting on behalf of one or more Controllers.
  • Signature/date: acceptance of the Agreement and this DPA constitutes signature on the applicable effective date.

Data importer

  • Name: Pipcast, Inc.
  • Address: 5889 Fleet St, San Jose, CA 95120, USA.
  • Company type: Delaware corporation, headquartered and resident in California.
  • Contact: privacy@ipcraft.co.
  • Activities: provision, hosting, security, maintenance, support, and administration of the Service.
  • Role under Module Two: Processor.
  • Role under Module Three: Processor/Subprocessor.
  • Signature/date: acceptance of the Agreement and this DPA constitutes signature on the applicable effective date.

Underlying Controller for Module Three

Before Module Three applies to a Restricted Transfer, Customer will identify the underlying Controller and provide its current notice contact, or represent and warrant that the Controller has expressly authorized Customer to receive and administer the Controller’s Clause 9 intended-Subprocessor notices and objections as its agent (DPA §7.3). Customer represents that it is authorized to provide instructions and to appoint Pipcast and Pipcast’s Subprocessors on the Controller’s behalf. If Customer does not provide this information or authorization, Customer will not initiate a Module Three Restricted Transfer through the Service.

B. Description of Processing and transfer

Subject matter

Processing of Customer Personal Data to provide, secure, maintain, support, and administer the Service.

Duration

The term of the Agreement, plus the return, deletion, backup, and legally required retention periods in Section 11.

Nature and purpose

  • document intake, upload, parsing, organization, storage, retrieval, export, and deletion;
  • hosted computation and transmission;
  • Customer-directed AI inference, drafting, summarization, classification, search, and analysis;
  • docketing, deadline, portfolio, matter, workflow, and notification functions;
  • account creation, authentication, authorization, and audit logging;
  • technical support, troubleshooting, security monitoring, error monitoring, and service maintenance; and
  • other Processing initiated by Customer through supported Service functionality.

Categories of Data Subjects

  • Customer’s authorized users, including patent attorneys, patent agents, paralegals, docketing personnel, in-house counsel, administrators, and support personnel;
  • inventors, applicants, assignees, owners, representatives, witnesses, experts, and other persons identified in patent matters or related correspondence;
  • Customer’s clients and their personnel where Customer is a law firm or service provider;
  • counterparties and persons identified in public or uploaded patent records; and
  • other individuals whose Personal Data appears in Customer Content.

Categories of Personal Data

  • Identity and contact data: names, signatures, email addresses, telephone numbers, postal addresses, and similar identifiers;
  • Professional and matter data: employer, firm, title, role, practitioner registration information, inventor or applicant status, client/matter identifiers, and matter assignments;
  • Account and authentication data: usernames, email addresses, password verifiers or hashes rather than plaintext passwords, identity-provider identifiers, roles, permissions, session and authentication metadata;
  • Content data: invention disclosures, application drafts, claims, specifications, figures, prior-art materials, office actions, correspondence, notes, assignments, and other uploaded or generated documents that may contain Personal Data together with confidential technical content;
  • Usage, support, and audit data: activity logs, audit records, timestamps, device/browser and diagnostic information, support communications, and security events.

Payment-card data is not included in this Annex I.B: card numbers and security codes are entered on Stripe-hosted pages and are not stored or Processed by Pipcast as importer (see Schedule 3, Part B). Business-contact, billing, and subscription data is Customer Account Data under Section 2.3 and is not Processed under this DPA.

Sensitive or special-category data

Such data is not intentionally required by the Service. It may appear incidentally in patent or invention materials, particularly in life-sciences matters. Customer is responsible for ensuring a lawful basis and compliance with Section 4.3. The safeguards in Schedule 2 apply; additional safeguards must be agreed before recurring or large-scale sensitive-data Processing.

Frequency

Continuous and on demand, as initiated by Customer and its users during the term.

Retention

For the term and the periods in Section 11, subject to Customer instructions, backup cycles, and legally required retention.

Onward transfers

To the Subprocessors and locations in Schedule 3, subject to Sections 7 and 12.

C. Competent Supervisory Authority

For the EU SCCs, the competent Supervisory Authority is determined under Clause 13:

  1. if Customer is established in an EU Member State, the authority responsible for Customer’s compliance concerning the transfer;
  2. if Customer is not established in the EU but is subject to Article 3(2) EU GDPR and has appointed an Article 27 representative, the authority of the Member State where the representative is established; or
  3. if Customer is subject to Article 3(2) EU GDPR and is not required to appoint a representative, the authority of a Member State where relevant Data Subjects are located.

Before an EU Restricted Transfer begins, Customer will identify the specific competent Supervisory Authority determined under this Part C, and the identified authority is deemed inserted into Annex I.C for that transfer. If more than one authority is competent because multiple exporters or establishments are involved, Customer will identify each applicable authority. Pipcast will retain the identified authority with the accepted transfer package. For UK Restricted Transfers, the Information Commissioner is the competent authority. For transfers governed by the FADP, the FDPIC is competent for FADP compliance, in parallel with any competent EU authority where both regimes apply.


Schedule 2 — Technical and Organizational Measures (SCC Annex II)

Except where a measure is expressly stated as an obligation effective no later than the DPA Effective Date (for example, the Amazon Bedrock content-handling configuration in §7 and the data-subject-rights measures in §14), Pipcast maintains the measures below as of the last-updated date. Pipcast will not make this DPA effective until each measure stated as an Effective-Date obligation has been implemented and verified. Descriptions are scoped to the stated controls and are not certifications or guarantees.

1. Encryption and transport protection

  • Public browser and external Service traffic uses HTTPS/TLS, with HTTP redirected to HTTPS at the load balancer.
  • Internal application traffic is confined to private, access-controlled network segments. This statement does not represent that every internal protocol or database connection independently enforces TLS.
  • Managed PostgreSQL storage, block storage, and object storage are encrypted at rest using AWS-managed or KMS-supported encryption.
  • A dedicated non-exportable KMS key is used to sign audit-export integrity manifests.

2. Tenant isolation

  • PostgreSQL row-level security is enabled in FORCE mode on tenant tables and keyed to tenant identifiers.
  • Application queries use a restricted, non-owner database role subject to row-level policies.
  • Tenant context is derived from validated authentication claims and is not accepted from an untrusted client override.
  • Policies deny tenant-table access when valid tenant context is absent.

3. Identity and access management

  • Authentication uses a self-hosted OpenID Connect identity provider and signed bearer tokens.
  • Per-tenant role-based access controls restrict user permissions.
  • Application workloads use scoped workload identity instead of shared static cloud keys.
  • Human cloud access uses AWS identity-center roles, and database access uses scoped roles.
  • Access is limited on a need-to-know and least-privilege basis.

4. Network security

  • Application workloads and databases operate in private subnets; databases are not publicly accessible.
  • Workload-level ingress and egress policies are default-deny with explicit allow rules.
  • A controlled internet-facing load balancer is the principal public entry point.

5. Auditability and integrity

  • Prosecution-event and administrative audit records use append-only controls, including database-level restrictions against ordinary update or deletion.
  • Audit records are hash-chained and periodically sealed to object-lock storage to provide tamper evidence during the configured retention period. Object-lock governance controls may be bypassable by specifically authorized privileged principals and are not represented as immutable statutory WORM retention.
  • Tenant audit exports are cryptographically signed.
  • AWS CloudTrail and GuardDuty support cloud-account activity logging and threat detection.

6. Secrets management

  • Application secrets are stored in AWS Secrets Manager and injected into workloads at runtime through managed mechanisms.
  • Secrets are not intentionally stored in source control.
  • AI inference is invoked through Amazon Bedrock under Pipcast’s AWS account using IAM-authenticated workload identity and approved U.S. regions.
  • A Bedrock guardrail is applied to inference calls and is designed to detect or block certain unsafe inputs and redact configured classes of sensitive identifiers. Guardrails reduce risk but are not guaranteed to identify every prompt attack or sensitive value.
  • AI output is advisory and remains subject to human review before legally operative action.
  • Tenant-level AI usage or spend controls are applied.
  • Pipcast does not use Customer Content or Customer Personal Data to train, fine-tune, or improve any shared or general-purpose model, and does not permit a Subprocessor or model provider to do so (§3.6).
  • Pipcast’s use of Amazon Bedrock for Customer Personal Data is governed by §3.6 and Schedule 3: Pipcast uses only a model and interface for which AWS documents that inference content is not stored or shared with the model provider, or for which the effective account/project retention configuration is zero-retention (none); prevents provider_data_share, default, or another less-protective mode through account, project, IAM, or service-control-policy controls; and keeps prompt/output content logging disabled by default (§3.6).

8. Environment isolation

  • Production, development, and management environments are segregated into separate AWS accounts.
  • Deployment safeguards and organization-level policies reduce the risk of deployment to the wrong account or unapproved region.

9. Backup and resilience

  • Managed database automated backups and point-in-time recovery are configured with a rolling seven-day retention window.
  • The core application runs multiple replicas and uses a pod-disruption budget.
  • These measures do not represent Multi-AZ database deployment, cross-region disaster recovery, or a guaranteed recovery-time or recovery-point objective unless separately committed in the Agreement.

10. Vulnerability and change management

  • Automated dependency-vulnerability monitoring is enabled across code repositories.
  • Pre-merge tests and formatting gates support controlled software changes.
  • Workloads use minimal, hardened host images.

11. Container and workload hardening

  • Application containers run as a non-root user with read-only root filesystems where configured.
  • Linux capabilities are dropped, privilege escalation is disabled, and the RuntimeDefault seccomp profile is used.

12. Monitoring and diagnostic minimization

  • Application errors are monitored through Sentry.
  • Sentry is configured with server-side scrubbing, IP-address scrubbing, custom masking of designated sensitive fields, and client-side default-PII collection disabled.
  • These controls are designed to minimize Personal Data in diagnostic events but do not guarantee that diagnostic data can never contain Customer Personal Data.
  • Liveness and readiness checks support service-health monitoring.

13. Personnel and organizational controls

  • Personnel access is limited by role and need to know.
  • Authorized personnel are subject to confidentiality obligations.
  • Production and infrastructure access uses controlled identities rather than shared static administrator credentials.
  • Software changes are subject to repository access controls, review processes, and automated testing described above.

14. Assistance with data-subject rights

Pipcast will assist Customer’s response to data-subject and consumer requests through the following measures:

  • Record identification: tenant-scoped data isolation (§2) supports identification of records associated with Customer’s tenant.
  • Rights actions: Pipcast will enable export, correction, and deletion of Customer Personal Data through available Service functionality and, where a capability is not available through self-service, reasonable support-assisted handling, acting on Customer’s (or, under Module Three, the controller’s) documented instructions.
  • Deletion effect: deletion is applied to primary data stores, with backup data aging out under the backup-retention cycle (DPA §11.4) and subject to the retention of append-only integrity and audit records described in DPA §11.
  • Logging: relevant administrative actions, audit events, and cloud-account activity are logged as described in §§3, 5, and 12.

Specific capabilities, export formats, and whether a given action is self-service or support-assisted are as implemented and described in current Service documentation. Pipcast does not represent capabilities beyond those implemented.

15. Security evolution

Pipcast may replace a measure with an alternative that provides materially equivalent or better protection, consistent with Section 6.2.


Schedule 3 — Subprocessors and Other Material Providers

Part A — Subprocessors

The following third parties Process Customer Personal Data on Customer’s behalf as Subprocessors:

SubprocessorServices and roleCustomer Personal DataProcessing location
Amazon Web Services, Inc.Cloud hosting and infrastructure, including EKS compute, managed PostgreSQL databases, S3 object storage, SES transactional email, Amplify hosting/CDN, KMS, monitoring/security services, and Amazon Bedrock managed AI inference.Potentially all categories in Schedule 1, depending on Customer’s use.United States — primary AWS Region us-east-1; Bedrock restricted by Pipcast to approved U.S. regions.
Functional Software, Inc. (Sentry)Application error monitoring and diagnostic telemetry, configured to minimize Personal Data.Diagnostic and error information; not intended to contain Customer Content but may incidentally contain Customer Personal Data.United States data region.
Google LLC (Google Workspace)Corporate support and business email. Applies only where Customer sends Personal Data or Customer Content to a Pipcast email address or Pipcast uses email to provide support.Support correspondence, contact information, and content Customer chooses to send by email.Storage/access locations and applicable transfer safeguards are as identified on Pipcast’s Subprocessor-and-providers page (§12.1), verified from Google Workspace account configuration and terms.

Part B — Other Material Providers Not Acting as Subprocessors Under This DPA

The following provider is disclosed for transparency but does not Process Customer Personal Data on Customer’s behalf and is not a Subprocessor under this DPA or an Annex III / UK Table 3 sub-processor:

ProviderRoleDataProcessing location
Stripe, LLCSubscription and payment administration. Stripe Processes Customer Account Data under Pipcast’s instructions to provide the Stripe platform and related services, and separately acts as an independent Controller for the purposes identified in Stripe’s applicable DPA and terms, including payment-network operation, fraud and loss prevention, legal compliance, and service administration. Because the relevant data is Customer Account Data rather than Customer Personal Data, Stripe is not a Subprocessor under this DPA and does not Process Customer Content on Customer’s behalf.Customer Account Data (billing-contact name/email; customer, subscription, transaction, and invoice identifiers). Card numbers and security codes are collected on Stripe-hosted pages and are not stored by Pipcast.As identified on Pipcast’s Subprocessor-and-providers page (§12.1), verified from Stripe’s terms and account configuration.

Processing-location transparency

Pipcast will maintain, at https://ipcraft.co/legal/subprocessors, a current, versioned list identifying, for each Subprocessor and Part B provider, the contracting entity, service, primary storage region, countries of material remote access/support or onward Processing, transfer mechanism, and effective date/version. That page is incorporated into this Schedule for location transparency (§12.1), and a material change to the countries in which a Subprocessor Processes Customer Personal Data is subject to the notice requirement in Section 7. The version of the page effective on the DPA Effective Date is incorporated into this Schedule; later versions apply only after notice and, where applicable, completion of the objection process under Section 7. Pipcast will retain, for each version, an immutable copy together with its cryptographic hash, or an equivalent tamper-evident archival record that preserves the complete text, associated with Customer’s acceptance and subsequent notices.

Managed AI clarification

Pipcast invokes Amazon Bedrock through AWS under Pipcast’s AWS account and IAM controls, in approved U.S. regions. AWS states that Bedrock inputs and outputs are not used to train base models. As set out in §3.6, Pipcast will Process Customer Personal Data through Amazon Bedrock only using a model and interface for which AWS documents that inference content is not stored by the inference service or shared with the model provider, or for which the effective account/project retention configuration is zero-retention (none); will use account, project, IAM, or service-control-policy controls to prevent provider_data_share, default, or another less-protective mode from applying to Customer Personal Data; and will not use a model or interface whose documented and effective data-handling configuration does not satisfy §3.6 to Process Customer Personal Data. Pipcast will not enable a configuration under which a model provider Processes Customer Personal Data for the provider’s own purposes unless Customer expressly authorizes the specific Processing in writing and Pipcast first implements all legally required disclosures, transfer safeguards, and contractual arrangements; a provider Processing data for its own purposes is not a Subprocessor and will not be characterized as one solely by being added to this Schedule.

Not separate Subprocessors

  • Keycloak is self-hosted within Pipcast’s AWS environment and is not a separate hosted vendor.
  • USPTO Open Data Portal and PatentsView are public data sources queried for public patent information; they are not engaged to Process Customer Personal Data on Pipcast’s behalf.

Schedule 4 — International Transfer Terms

Part A — EU SCC selections

For an EU Restricted Transfer covered by Section 12.2:

  1. Modules. Module Two applies to Controller-to-Processor transfers. Module Three applies to Processor-to-Processor transfers.
  2. Clause 7. The optional docking clause applies.
  3. Clause 9(a). Option 2, general written authorization, applies. The notice period is thirty (30) days, given before the Subprocessor begins Processing and with a meaningful opportunity to object before engagement. Section 7.5 does not modify this SCC requirement.
  4. Clause 11(a). The optional independent dispute-resolution language does not apply.
  5. Clause 13 and Annex I.C. The competent Supervisory Authority is determined under Schedule 1, Part C, and the specific authority is identified and deemed inserted into Annex I.C before the EU Restricted Transfer begins.
  6. Clause 17. Option 1 applies, and the EU SCCs are governed by the law of Ireland.
  7. Clause 18. Disputes are resolved by the courts of Ireland, without limiting a Data Subject’s rights under Clause 18(b).
  8. Annex I.A and I.B. Schedule 1 completes the list of Parties and description of transfer.
  9. Annex II. Schedule 2 completes the technical and organizational measures.
  10. Annex III. The Parties use general authorization, so Annex III is not required to constitute specific prior authorization. Schedule 3, Part A identifies the current Subprocessors for transparency and for any instrument that requires the list; Schedule 3, Part B lists other material providers that are not Subprocessors.
  11. Module Three controller authorization and notices. Customer confirms that the underlying Controller has authorized Pipcast and Pipcast’s Subprocessors as required. Before Module Three applies, Customer will either provide the underlying Controller’s current notice contact so that Pipcast can deliver Clause 9 intended-Subprocessor notices to the Controller, or represent and warrant that the Controller has expressly authorized Customer to receive and administer those notices and objections as the Controller’s agent (§7.3). Customer will provide the Controller with the EU SCCs and relevant notices, will promptly communicate the Controller’s decision or objection to Pipcast, and will not initiate a Module Three Restricted Transfer if it has not provided the required Controller information or agency authorization. The underlying Controller’s Clause 9 objection rights are not narrowed by the “reasonable grounds” standard in §7.4.
  12. Signatures. Acceptance of the Agreement and this DPA constitutes signature of Annex I.A and the EU SCCs.

Part B — UK Addendum, Version B1.0, Part 1 Tables

The Parties incorporate Part 2: Mandatory Clauses of the UK Addendum, Version B1.0, as revised under its Section 18.

Table 1 — Parties

  • Start date: the effective date of this DPA or the date of the relevant UK Restricted Transfer, whichever is later.
  • Exporter: Customer identified in the Agreement. Details and key contact are those in Schedule 1 and Customer’s account.
  • Importer: Pipcast, Inc., 5889 Fleet St, San Jose, CA 95120, USA (Delaware corporation). Key contact: privacy@ipcraft.co. Further details as in Schedule 1.
  • Signatures: acceptance of the Agreement and this DPA is a legally binding method of entering into the UK Addendum for purposes of its Section 2.

Table 2 — Selected SCCs, Modules, and Clauses

  • Approved EU SCCs: the EU SCCs incorporated through this DPA and completed by Part A.
  • Modules in operation: Module Two and/or Module Three, according to the Parties’ roles.
  • Clause 7: applies.
  • Clause 11 option: does not apply.
  • Clause 9(a): general authorization.
  • Clause 9(a) time period: thirty (30) days, given before the Subprocessor begins Processing; Section 7.5 does not modify this requirement.
  • Combining data received from Importer: not applicable to Modules Two and Three for this transfer.

Table 3 — Appendix Information

  • Annex 1A, List of Parties: Schedule 1, Part A.
  • Annex 1B, Description of Transfer: Schedule 1, Part B.
  • Annex II, Technical and Organizational Measures: Schedule 2.
  • Annex III, List of Subprocessors: Schedule 3, Part A.

Table 4 — Ending the Addendum if the Approved Addendum changes

Both the Importer and Exporter may end the UK Addendum under Section 19 of the Mandatory Clauses. Ending the UK Addendum does not authorize continued UK Restricted Transfers without another valid safeguard.

Part C — Swiss Amendments

For a Restricted Transfer governed by the FADP:

  1. The term “Swiss Personal Data” means Personal Data whose Processing is governed by the FADP.
  2. References in the EU SCCs to the EU GDPR will be interpreted to include the FADP to the extent the transfer is governed by the FADP. Where a transfer is governed exclusively by the FADP, references to the EU GDPR are understood as references to the FADP.
  3. References to “Member State” will not be interpreted to exclude Data Subjects in Switzerland from exercising rights or bringing proceedings in Switzerland at their place of habitual residence where the FADP permits.
  4. The FDPIC is the competent Supervisory Authority for compliance with the FADP. Where the transfer is also governed by the EU GDPR, the competent EU Supervisory Authority identified under Clause 13 remains competent for EU GDPR matters, and the FDPIC remains competent for FADP matters.
  5. For a transfer governed exclusively by the FADP, Clause 17 is governed by Swiss law and Clause 18 disputes between the Parties may be brought before competent courts in Switzerland. Where the EU GDPR also applies, the Clause 17 and 18 selections in Part A govern EU GDPR contractual claims, without limiting the FDPIC’s statutory authority or Data Subjects’ FADP rights.
  6. References to “personal data” include Swiss Personal Data, and references to “special categories of personal data” include “sensitive personal data” as defined by the FADP.
  7. The Parties will interpret and supplement the EU SCCs consistently with FDPIC-recognized adaptations then applicable to the EU SCCs.

End of DPA