ExeFast Data Processing Addendum (DPA)

Last Updated: July 15, 2026 Incorporated by reference into the ExeFast Terms of Service

This Data Processing Addendum ("DPA") forms part of the ExeFast Terms of Service (the "Terms") between EXEFAST INC, a Florida benefit corporation ("ExeFast") and the customer agreeing to the Terms ("Customer," "you"). It applies where, and to the extent that, ExeFast processes Customer Personal Data on your behalf as a processor in connection with your use of the ExeFast Platform, AI Agents, Gig, or the ExeFast API. Capitalized terms not defined here have the meaning given in the Terms.

In the event of a conflict, for the processing it covers, this DPA prevails over the Terms and the Privacy Policy.

1. Definitions

2. Roles and Scope

For Customer Personal Data, you are the controller (or a processor acting for another controller) and ExeFast is the processor (or sub-processor). In the typical case where you use the Services for your own purposes, ExeFast acts as your processor (SCC Module Two); ExeFast acts as a sub-processor (SCC Module Three) only where you are yourself a processor acting on behalf of a third-party controller. Each party complies with its obligations under Data Protection Laws. ExeFast processes Customer Personal Data only to provide and support the Services and as further described in Annex I, whether inference is delivered by transiently routing to third-party model providers or by an ExeFast-operated model hosted on cloud infrastructure. Where ExeFast processes personal data as a controller (for example, account, billing, payout-verification, and security data described in the Privacy Policy), the Privacy Policy - not this DPA - governs that processing.

3. Processing Instructions

ExeFast processes Customer Personal Data only on your documented instructions, including as set out in this DPA and the Terms, unless required by law (in which case ExeFast will inform you, unless legally prohibited). Your use of the Services constitutes your instructions. ExeFast will inform you if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

ExeFast ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and process the data only as instructed.

5. Security

ExeFast implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data, as described in Annex II, including encryption in transit and at rest where feasible, access controls, logging and monitoring, per-user/session isolation of runtime environments to the extent technically feasible, and vendor due diligence.

6. Sub-processors

You provide general authorization for ExeFast to engage sub-processors to process Customer Personal Data. ExeFast's current sub-processors include the providers identified in the Privacy Policy and Annex III (for example, payment and payout providers, cloud infrastructure, and inference/model providers accessed via OpenRouter on a transient, no-retention basis). ExeFast imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for its sub-processors' performance. ExeFast will give notice of intended additions or replacements of sub-processors (for example, via the Platform or email) and you may object on reasonable data-protection grounds; if the parties cannot resolve the objection, you may terminate the affected Services.

7. Data Subject Requests

Taking into account the nature of the processing, ExeFast will assist you by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests to exercise their rights under Data Protection Laws. If ExeFast receives such a request directly relating to Customer Personal Data, it will, unless legally required to act, refer the data subject to you.

8. Assistance

Taking into account the nature of processing and the information available to ExeFast, ExeFast will assist you in ensuring compliance with your obligations regarding security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities (Articles 32-36 GDPR).

9. Personal Data Breach

ExeFast will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to help you meet your breach-notification obligations.

10. Deletion or Return

On termination or expiry of the Services, ExeFast will, at your choice, delete or return Customer Personal Data and delete existing copies, unless law requires storage. De-identified, aggregated, and routine backup data may be retained and is overwritten or deleted in the ordinary course.

11. Audits and Information

ExeFast will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, frequency limits, and ExeFast's security and operational requirements. ExeFast may satisfy audit requests by providing third-party certifications or reports where available.

12. International Transfers

Where ExeFast transfers Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the SCCs (and the UK Addendum, and Swiss amendments, as applicable) are incorporated by reference and apply, with ExeFast as data importer and you as data exporter. The relevant module is Module Two (controller-to-processor) or Module Three (processor-to-processor), as applicable. Annex I and Annex II of this DPA populate the corresponding annexes of the SCCs; the docking, optional, and governing-law/jurisdiction selections are completed in Annex IV.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms.

14. Term

This DPA takes effect when you accept the Terms (or first process Customer Personal Data through the Services) and continues until ExeFast has ceased all processing of Customer Personal Data.

Annex I - Description of Processing

Annex II - Technical and Organizational Measures

Encryption in transit and at rest where feasible; access controls and least-privilege; logging and monitoring; per-user/session runtime isolation (Cloud Run native gVisor or successor) to the extent technically feasible; transient, no-retention routing to inference providers; vendor due diligence and data-processing agreements; incident response; and personnel confidentiality and training.

Annex III - Sub-processors

Current sub-processors include those identified in the Privacy Policy, for example: Stripe and Thunes (payments/payouts); Mercury (operational banking); Google Cloud (hosting, and infrastructure for any ExeFast-operated model); OpenRouter and underlying model providers (transient, no-retention inference for pass-through models); identity/verification partners; and messaging/voice providers where you use those channels. A current list is available on request at legal@exefast.ai.

Annex IV - SCC Elections

Contact: legal@exefast.ai