ExeFast Data Processing Addendum (DPA)
Last Updated: July 15, 2026 Incorporated by reference into the ExeFast Terms of Service
This Data Processing Addendum ("DPA") forms part of the ExeFast Terms of Service (the "Terms") between EXEFAST INC, a Florida benefit corporation ("ExeFast") and the customer agreeing to the Terms ("Customer," "you"). It applies where, and to the extent that, ExeFast processes Customer Personal Data on your behalf as a processor in connection with your use of the ExeFast Platform, AI Agents, Gig, or the ExeFast API. Capitalized terms not defined here have the meaning given in the Terms.
In the event of a conflict, for the processing it covers, this DPA prevails over the Terms and the Privacy Policy.
1. Definitions
- Customer Personal Data means personal data that ExeFast processes on your behalf and on your instructions in providing the Services - for example, personal data about your own customers, contacts, or end-users that you submit to, or have an agent process through, the Services (including over messaging or voice channels).
- Data Protection Laws means all laws applicable to the processing of Customer Personal Data under this DPA, including the EU GDPR, the UK GDPR, the Swiss FADP, and applicable US state privacy laws.
- Controller, processor, sub-processor, data subject, personal data, processing, and supervisory authority have the meanings given in the GDPR.
- SCCs means the European Commission's Standard Contractual Clauses (Decision 2021/914), and, for the UK, the UK Addendum issued by the Information Commissioner's Office.
2. Roles and Scope
For Customer Personal Data, you are the controller (or a processor acting for another controller) and ExeFast is the processor (or sub-processor). In the typical case where you use the Services for your own purposes, ExeFast acts as your processor (SCC Module Two); ExeFast acts as a sub-processor (SCC Module Three) only where you are yourself a processor acting on behalf of a third-party controller. Each party complies with its obligations under Data Protection Laws. ExeFast processes Customer Personal Data only to provide and support the Services and as further described in Annex I, whether inference is delivered by transiently routing to third-party model providers or by an ExeFast-operated model hosted on cloud infrastructure. Where ExeFast processes personal data as a controller (for example, account, billing, payout-verification, and security data described in the Privacy Policy), the Privacy Policy - not this DPA - governs that processing.
3. Processing Instructions
ExeFast processes Customer Personal Data only on your documented instructions, including as set out in this DPA and the Terms, unless required by law (in which case ExeFast will inform you, unless legally prohibited). Your use of the Services constitutes your instructions. ExeFast will inform you if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality
ExeFast ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and process the data only as instructed.
5. Security
ExeFast implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data, as described in Annex II, including encryption in transit and at rest where feasible, access controls, logging and monitoring, per-user/session isolation of runtime environments to the extent technically feasible, and vendor due diligence.
6. Sub-processors
You provide general authorization for ExeFast to engage sub-processors to process Customer Personal Data. ExeFast's current sub-processors include the providers identified in the Privacy Policy and Annex III (for example, payment and payout providers, cloud infrastructure, and inference/model providers accessed via OpenRouter on a transient, no-retention basis). ExeFast imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for its sub-processors' performance. ExeFast will give notice of intended additions or replacements of sub-processors (for example, via the Platform or email) and you may object on reasonable data-protection grounds; if the parties cannot resolve the objection, you may terminate the affected Services.
7. Data Subject Requests
Taking into account the nature of the processing, ExeFast will assist you by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests to exercise their rights under Data Protection Laws. If ExeFast receives such a request directly relating to Customer Personal Data, it will, unless legally required to act, refer the data subject to you.
8. Assistance
Taking into account the nature of processing and the information available to ExeFast, ExeFast will assist you in ensuring compliance with your obligations regarding security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities (Articles 32-36 GDPR).
9. Personal Data Breach
ExeFast will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to help you meet your breach-notification obligations.
10. Deletion or Return
On termination or expiry of the Services, ExeFast will, at your choice, delete or return Customer Personal Data and delete existing copies, unless law requires storage. De-identified, aggregated, and routine backup data may be retained and is overwritten or deleted in the ordinary course.
11. Audits and Information
ExeFast will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, frequency limits, and ExeFast's security and operational requirements. ExeFast may satisfy audit requests by providing third-party certifications or reports where available.
12. International Transfers
Where ExeFast transfers Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the SCCs (and the UK Addendum, and Swiss amendments, as applicable) are incorporated by reference and apply, with ExeFast as data importer and you as data exporter. The relevant module is Module Two (controller-to-processor) or Module Three (processor-to-processor), as applicable. Annex I and Annex II of this DPA populate the corresponding annexes of the SCCs; the docking, optional, and governing-law/jurisdiction selections are completed in Annex IV.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
14. Term
This DPA takes effect when you accept the Terms (or first process Customer Personal Data through the Services) and continues until ExeFast has ceased all processing of Customer Personal Data.
Annex I - Description of Processing
- Subject matter: provision of the ExeFast Platform, AI Agents, Gig, and the ExeFast API.
- Duration: for the term of the Services, plus deletion/return as in Section 10.
- Nature and purpose: hosting, executing, and transiently routing inputs/outputs to deliver inference and agent functionality, including actions you direct an agent to take.
- Categories of data subjects: your customers, contacts, end-users, and other individuals whose personal data you submit to or process through the Services.
- Categories of personal data: as determined and controlled by you through your Inputs, configurations, and instructions; you must not submit special-category data except as permitted by the Terms and AUP and with a lawful basis.
- Special-category data: not intended; you are responsible if you choose to submit it.
- Frequency: continuous, for the duration of the Services.
Annex II - Technical and Organizational Measures
Encryption in transit and at rest where feasible; access controls and least-privilege; logging and monitoring; per-user/session runtime isolation (Cloud Run native gVisor or successor) to the extent technically feasible; transient, no-retention routing to inference providers; vendor due diligence and data-processing agreements; incident response; and personnel confidentiality and training.
Annex III - Sub-processors
Current sub-processors include those identified in the Privacy Policy, for example: Stripe and Thunes (payments/payouts); Mercury (operational banking); Google Cloud (hosting, and infrastructure for any ExeFast-operated model); OpenRouter and underlying model providers (transient, no-retention inference for pass-through models); identity/verification partners; and messaging/voice providers where you use those channels. A current list is available on request at legal@exefast.ai.
Annex IV - SCC Elections
- Module: Two (controller-to-processor) or Three (processor-to-processor), as applicable to your use.
- Clause 7 (docking): applies.
- Clause 9 (sub-processors): Option 2 (general written authorization); notice period as in Section 6.
- Clause 11 (redress): optional language does not apply.
- Clause 17 (governing law): Ireland (Irish law) for EU transfers.
- Clause 18 (forum and jurisdiction): the courts of Ireland for EU transfers.
- UK Addendum: incorporated for UK transfers; tables completed by reference to this DPA's Annexes.
Contact: legal@exefast.ai