SafeBind.ai

Data Processing Addendum

Last updated: October 5, 2026

This Data Processing Addendum ("DPA") is part of the SafeBind Terms of Service (the "Terms") between the customer identified in an Order Form or in the online sign-up ("you") and SafeBind AI LLC ("SafeBind"). It is incorporated into the Terms by reference and applies whenever SafeBind processes personal information on your behalf in providing the Service, all under applicable U.S. State Privacy Laws and other data-processing laws. Capitalized terms not defined here have the meanings given in the Terms. No signature is required for this DPA to apply; if you would like a countersigned copy for your records, email contact@safebind.ai.

Definitions

As used in this DPA, the terms "personal information," "sell," "share," "service provider," "contractor," and "processor" have the meanings given to them by the applicable U.S. State Privacy Law that governs the relevant Customer Data.

"Applicable Privacy Law" (also referred to as "U.S. State Privacy Law") means the applicable U.S. state privacy and data-processing laws that govern the relevant Customer Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA/CPRA"), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), and other comparable U.S. state privacy statutes (for example, those of Nebraska, Iowa, Indiana, and Delaware), in each case as amended and as applicable to the processing of Customer Data under this DPA. This DPA does not incorporate, and the parties do not intend it to be governed by, any non-U.S. data-protection law.

1. Roles and scope

With respect to the personal information of Consumers contained in Customer Data — the information a Consumer enters on your forms, their interactions with the page, the disclosure and consent language shown, and the technical details of the session — you are the business or controller and SafeBind is your service provider, contractor, or processor under each applicable U.S. State Privacy Laws and data-processing law that governs the Customer Data. This DPA covers that processing. It does not cover personal information SafeBind collects for its own purposes as a business (for example, your account and billing details), which is described in our Privacy Policy.

2. Details of the processing

Subject matter. Capturing, sealing, storing, verifying, and screening evidence of Consumer consent on web forms where the SDK is installed, and making Records available to the parties you authorize.

Nature and purpose. To document the consent moment and provide you and your authorized Lead Buyers with a tamper-evident, independently timestamped record of it, together with verification and fraud signals, as described in the Terms.

Categories of data subjects. Consumers who interact with web forms on which the SDK is installed.

Categories of personal information. The information a Consumer enters on the form (typically name, contact details, and their answers to the form's questions); their interactions with the page, including clicks and the timing of inputs; the disclosure and consent language shown; the full address of the page, including any parameters after the question mark, which is shown to Record holders without those parameters; IP address; browser and device details, including a non-reversible device fingerprint used to detect automated submissions. The SDK is designed to redact Sensitive Data before it leaves the browser, as Section 6 of the Terms describes, and a redacted field's value is not transmitted to SafeBind; the customer is responsible for marking sensitive fields, and the Terms prohibit using the Service to collect biometric data or information protected under HIPAA or COPPA.

Duration. For the retention periods stated in Section 6 of the Terms and Section 10 of this DPA, and subject to legal holds and your deletion instructions.

3. Your instructions

SafeBind will process personal information only on your documented instructions. Your instructions are the Terms, this DPA, any Order Form, the settings you configure in the Service (including your consent-language and screening configuration, your Retention elections and deletion instructions, and the Lead Buyers you authorize), the support and quality-review authorization in Section 6 of the Terms, and any further written instructions you give that are consistent with them. The notice, consent, and deployment obligations in Section 8 of the Terms are yours as controller; SafeBind's processing assumes you have met them. You warrant that, before deploying the SDK and on an ongoing basis, you have established and will maintain a valid legal basis for the processing and have provided all notices and disclosures, and obtained and maintained all consents, authorizations, and permissions, required under Applicable Privacy Law for SafeBind to process the Customer Data as you instruct. You are solely responsible for the legality, accuracy, quality, relevance, and data minimization of the Customer Data you configure the Service to collect, and for correctly identifying and marking sensitive fields for redaction; SafeBind processes Customer Data as received and has no obligation to review, assess, or correct it. You further warrant that your instructions, your configuration of the Service, and your own data-handling practices comply with Applicable Privacy Law. SafeBind will inform you if, in its opinion, an instruction would violate any Applicable Privacy Law. SafeBind may, without liability and without being in breach of the Terms or this DPA, suspend, refuse, or cease any processing that it reasonably believes is unlawful, exceeds the scope of your instructions, or would expose SafeBind to liability under Applicable Privacy Law, until the matter is resolved to its reasonable satisfaction. Nothing in this DPA requires SafeBind to determine whether your instructions or your own practices comply with law; that responsibility remains yours, as the Terms state. SafeBind bears no obligation or liability for verifying, and makes no representation regarding, your compliance, or that of the Customer Data or your instructions, with Applicable Privacy Law, and no review, suggestion, or failure by SafeBind to object to an instruction relieves you of, or shifts to SafeBind, any of these responsibilities. An instruction that would require SafeBind to materially change its technical infrastructure or that is inconsistent with the Terms, this DPA, or the applicable Order Form is not a valid instruction unless agreed in a written amendment signed by both parties. SafeBind has no right to process personal information for its own purposes; any such processing is a material breach of the Terms and this DPA.

4. Service-provider and processor commitments

SafeBind will:

SafeBind certifies that it understands these restrictions and will comply with them, and has no reason to believe that the CCPA or any comparable U.S. State Privacy Law prevents it from providing the Service. Each party will promptly notify the other of a change in law that materially affects its ability to perform under the Terms or this DPA.

5. Record holders

A Record is designed to travel with the Lead it evidences. By delivering or offering a Lead with its Record, you instruct SafeBind, as your service provider, to open that Record when a Lead Buyer presents it, to analyze it, including against that buyer’s own screening rules, and to return the results to that buyer, so that you can sell the Lead with its evidence. Providing your Customer Data contained in a Record to the holder of that Record — for example, a Lead Buyer to whom you have authorized or shared it, in accordance with the Record's authorization and the buyer's own account status — is a disclosure SafeBind makes on your instruction as your service provider, not a use for SafeBind's own purposes; whether your own transfer of the Lead or the Record to that holder is a sale, a share, or (as applicable) a targeted advertising or other processing event under any applicable U.S. State Privacy Law is for you to determine. Each account that holds a Record is an independent controller of the personal information in the copy it holds (or, where it holds the Record on behalf of another business, that business's processor), including any copy it exports from the Service, and is responsible for honoring consumer privacy requests as to that copy and for cooperating with other holders as applicable law requires (Terms Section 7). Each holder's copy within the Service is independent: one holder's erasure does not reach another holder's copy.

6. Subprocessors

You authorize SafeBind to engage the following subprocessors to process personal information on its behalf in providing the Service. SafeBind will bind each of them by a written contract to data-protection obligations no less protective than those in this DPA and no less protective than those required by applicable U.S. State Privacy Law, remains responsible to you for their performance, and will notify you by email to your account at least thirty (30) days before adding a new subprocessor. If you object on reasonable data-protection grounds and the parties cannot resolve the objection, you may terminate your account or the affected Order Form as the Terms allow. Google (Google Analytics 4 and Google Ads conversion tracking) is used only for SafeBind's own marketing-website visitor analytics and does not process any Customer Data, and is therefore not a subprocessor under this DPA. If you do not object on reasonable data-protection grounds in writing within the thirty (30) day notice period described above, you will be deemed to have consented to the new subprocessor and SafeBind may engage it. SafeBind's responsibility and liability for the acts and omissions of any subprocessor it engages is limited to the extent SafeBind would be responsible and liable for its own acts and omissions under this DPA and the Terms, and in no event exceeds the limitations of liability set forth in the Terms. SafeBind is not responsible or liable for any subprocessor, third-party service, integration, or provider that you direct SafeBind to use or that operates under your own account, credentials, or instructions — including, without limitation, any MaxMind account you connect — and any processing by such a provider is carried out on your instruction and at your risk as controller.

7. Security

SafeBind maintains reasonable administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the personal information and as required by applicable U.S. State Privacy Laws, designed to protect personal information against unauthorized access, disclosure, alteration, and loss, including: encryption in transit (TLS); encryption at rest by our storage providers and, for the archived copy of sealed evidence, under per-Record keys that SafeBind controls; evidence that is cryptographically signed, hash-sealed, and independently timestamped shortly after capture, so that alteration is detectable; a write-once archive for sealed evidence; automatic redaction in the SDK of Sensitive Data fields as Section 6 of the Terms describes; role-based access to your account, with multi-factor authentication available to every account and enforced for your account when you ask; and a sealed, hash-chained audit log of account actions. Further detail is on our Security page, which SafeBind updates as its safeguards evolve. You acknowledge, as the Terms state, that no security measure is perfect, that the safeguards described in this Section are reasonable and appropriate but do not constitute a guarantee against every unauthorized access, disclosure, alteration, or loss, and that SafeBind does not warrant that the Service or any personal information will be free from all Security Incidents. You are responsible for the security of your own systems, networks, devices, and applications; for safeguarding your account credentials, API keys, and access tokens and for promptly notifying SafeBind of any suspected compromise of them; for managing user access to your account, including provisioning and de-provisioning Users, enforcing the available multi-factor authentication, and applying the principle of least privilege; and for correctly configuring the Service for your use case, including marking and redacting Sensitive Data and other sensitive fields so that they are not transmitted to SafeBind. To the maximum extent permitted by applicable law, SafeBind is not responsible or liable for any Security Incident or other loss to the extent it arises from your failure to properly configure the Service, from your failure to secure your credentials or to manage access to your account, from your own systems or software, or from personal information you instructed the Service to collect or that you configured the Service to capture. SafeBind is pursuing a SOC 2 Type II examination covering the trust service criteria for security; upon completion, SafeBind will make the report available under Section 11 of this DPA.

8. Security incidents

If SafeBind becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information it processes for you (a "Security Incident"), SafeBind will notify you without undue delay after becoming aware of it, and in any event within seventy-two (72) hours of that awareness, by email to your account's owners. If a specific shorter period is required by an applicable U.S. state breach-notification statute that governs SafeBind as a processor or service provider, SafeBind will comply with that statute's timeline. For purposes of this Section, 'awareness' means the point at which SafeBind has a reasonable basis to believe that a Security Incident has occurred, not mere suspicion of anomalous activity. A first notice may be preliminary, giving what is then known, with further information provided as the investigation proceeds. The notice will describe the nature of the incident, the categories and approximate volume of personal information and data subjects affected so far as known, the measures taken or proposed, and a point of contact. SafeBind will cooperate reasonably with your own investigation and with your notification obligations under all applicable U.S. state breach-notification and U.S. State Privacy Laws. SafeBind's notification obligation does not apply to unsuccessful or attempted incidents, or to events that do not compromise the security, confidentiality, or integrity of personal information SafeBind processes for you, including pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial-of-service attacks, and similar events that do not result in access to, or loss, alteration, or unauthorized disclosure of, Customer Data. SafeBind has no obligation to notify you of, or to investigate, respond to, cooperate on, or bear the cost of, any Security Incident to the extent it is caused by you, your Users, your systems, integrations, credentials, or configurations, your instructions, or your failure to meet the notice, consent, deployment, or security obligations that are yours as controller; and where a Security Incident is so caused, SafeBind may recover from you its reasonable costs of assistance, investigation, response, and cooperation. Notification of, or response to, a Security Incident is not an acknowledgment or admission of fault or liability by SafeBind.

9. Consumer requests and assistance

If SafeBind receives a request from a Consumer to exercise a consumer or data-subject right under any applicable U.S. State Privacy Law relating to personal information it processes for you, SafeBind will refer the request to you within ten (10) business days, or within any shorter period applicable law or a regulator sets, and will not respond on its own behalf except to confirm that the request has been referred, unless the law requires otherwise. SafeBind may tell the Consumer which business to contact and give the contact details you have provided for that purpose. SafeBind will notify you in the same period of any complaint, notice, or regulatory inquiry it receives that relates to personal information it processes for you. Taking into account the nature of the processing and the information available to it, SafeBind will reasonably assist you in responding to consumer and data-subject rights requests under any applicable U.S. State Privacy Law, in meeting your obligations regarding the security of the processing and the notification of incidents, and in any data-protection assessment or regulator inquiry that concerns SafeBind's processing. Where the Service lets you fulfil a request yourself — for example, exporting or deleting a Record's evidence — SafeBind's assistance is to provide that function. Where a Record is held by more than one account, SafeBind acts on each holder's erasure instruction as to that holder's copy only; an erasure by one holder does not reach the copy of another holder, which remains that holder's responsibility as an independent controller. Copies exported from the Service are outside any erasure within the Service and remain the responsibility of the holder that made them.

Because deleting a consent record can impair your ability to defend a claim, SafeBind retains consent evidence by default and acts on your explicit deletion instruction as controller, as Section 6 of the Terms describes. Whether specific evidence must be retained to establish, exercise, or defend legal claims is your decision. As between the parties, you retain primary responsibility for receiving, verifying the identity of the requester, and responding to consumer and data-subject rights requests relating to personal information SafeBind processes for you, and for meeting all response deadlines applicable law imposes. SafeBind's assistance under this Section is limited to what is technically feasible, taking into account the nature of the processing and the information available to it, and does not extend to legal analysis of, or decisions on, the validity or handling of any request. SafeBind may charge you a reasonable fee, agreed in advance, for assistance that goes beyond the self-service functions the Service makes available or that is manifestly unfounded, repetitive, disproportionate, or excessive. SafeBind is not responsible or liable for your failure to respond to any consumer, data-subject, complaint, or regulatory request within the time required by applicable law, or for the adequacy of any response you elect to give.

10. Retention, return, and deletion

SafeBind retains personal information for the retention periods stated in Section 6 of the Terms, which are fixed by SafeBind and not configurable by customers. At the end of the applicable period, or earlier on your written instruction, SafeBind will delete the active copies of the personal information and destroy the encryption keys that protect the copy held in its write-once archive, which renders that copy permanently unreadable; the archive lock is a technical control against alteration, not a basis for retaining readable data. Deletion is subject to any legal hold, to retention required by applicable law, and to technical feasibility. Encrypted database backups are deleted 90 days after they are made, rather than edited to remove individual records. Notwithstanding any deletion instruction, SafeBind may retain personal information to the extent, and for so long as, required by applicable law or reasonably necessary to establish, exercise, or defend legal claims. A prospective change to a retention period never shortens a period already running for a Record. Before deletion you may export the evidence through the Service; you are responsible for exporting any data you wish to retain, and SafeBind has no liability for your failure to export before deletion. You are responsible for your deletion instructions and for the consequences of them, including any resulting inability to establish, exercise, or defend a claim. On termination of the Terms, these commitments survive for as long as SafeBind holds the personal information. Any de-identified or aggregated data SafeBind derives from the personal information, as permitted by Section 6 of the Terms, is not subject to this deletion obligation, and SafeBind will maintain and use that data only in de-identified form, will not attempt to re-identify it, and will contractually obligate any recipient to do the same, consistent with its commitments in Section 6 of the Terms.

11. Audit

On written request, no more than once per year unless following a Security Incident, SafeBind will make available information reasonably necessary to demonstrate its compliance with this DPA, including its then-current security documentation and, where SafeBind holds a third-party audit report such as a SOC 2 report, a copy under a confidentiality obligation. If that information does not reasonably address your concern, you may, on thirty (30) days' notice and at your own expense, conduct an audit by written questionnaire limited to what is reasonably necessary to verify compliance with this DPA. Where applicable law entitles you to a reasonable assessment of SafeBind's processing, you may conduct one, remotely or on site, no more than once per year on thirty (30) days' notice, during business hours, under a confidentiality obligation, limited in scope to what is reasonably necessary to verify compliance with this DPA, and conducted so as not to disrupt SafeBind's operations, at your own expense; where SafeBind holds a current report of an independent assessment that satisfies the requirements applicable law sets for such a substitute — including its framework, scope, frequency, and who bears its cost — SafeBind may, with your consent where the law requires it, satisfy that assessment by providing that report. Following a Security Incident, SafeBind shall cooperate with one additional audit within a reasonable time, on no less than ten (10) business days' notice. If a regulator directs an audit, SafeBind shall cooperate on no less than ten (10) business days' notice unless the regulator requires otherwise. These post-incident and regulator audits are in addition to, and do not count toward, the annual audit described above. Any assessment or audit under this Section is further subject to the following conditions: (a) any third-party auditor you engage must not be a competitor of SafeBind and must execute a non-disclosure agreement reasonably acceptable to SafeBind before being granted any access; (b) no audit or assessment will extend to the personal information, Customer Data, confidential information, or environments of SafeBind's other customers, or to SafeBind's proprietary systems, source code, security keys, or trade secrets; (c) you bear your own costs and, in addition, will reimburse SafeBind for the reasonable costs of the time and resources its personnel devote to preparing for and supporting any audit, assessment, or questionnaire, and SafeBind may charge its then-current reasonable fees for such support; and (d) all information made available or observed in connection with an audit or assessment is SafeBind's confidential information and may be used solely to verify SafeBind's compliance with this DPA.

12. Location of processing

SafeBind processes personal information in the United States. The Service is offered for United States traffic only, as the Terms state, and this DPA does not provide for international transfers of personal information.

13. Customer indemnity and allocation of liability

You will indemnify, defend, and hold harmless SafeBind and its affiliates, and their respective officers, directors, employees, and agents, from and against any third-party claim, and any regulatory fine, penalty, assessment, loss, liability, damage, cost, or expense (including reasonable attorneys' fees), to the extent arising out of or relating to: (i) your instructions or your configuration of the Service; (ii) the content, legality, or accuracy of Customer Data; (iii) your failure to obtain a lawful basis or any required consent, or to provide any required notice, for the processing of Customer Data; (iv) your use of the Service in violation of the Terms, this DPA, or applicable law; and (v) any disclosure SafeBind makes on your instruction, including any disclosure of Customer Data contained in a Record to a Lead Buyer or other Record holder you authorize. Any regulatory fine, penalty, or third-party claim that is caused by or attributable to your instructions, your configuration of the Service, or Customer Data is allocated to you as the business or controller, and you will reimburse SafeBind for, and as between the parties are responsible for contribution to SafeBind for, any such fine, penalty, or claim that SafeBind incurs to the extent attributable to your conduct or Customer Data. For the avoidance of doubt, SafeBind's total aggregate liability arising out of or relating to this DPA remains subject to, and in all cases does not exceed, the limitations of liability set forth in the Terms, and nothing in this Section expands that cap or creates any separate or additional liability of SafeBind.

14. Precedence, term, and changes

This DPA forms part of the Terms and applies for as long as SafeBind processes personal information on your behalf. As to the processing of personal information under applicable U.S. State Privacy Laws, this DPA controls over any conflicting provision of the Terms; in all other respects the Terms, including their limitations of liability, apply to this DPA. Privacy Policy descriptions of Customer Data processing are informational summaries of the commitments in this DPA and these Terms; to the extent of any conflict, the DPA controls. An Order Form modifies this DPA only where it expressly identifies the provision of this DPA that it modifies. Changes to this DPA are made in the manner Section 21 of the Terms provides, and SafeBind will not reduce the protections in Section 4 without your consent. For the avoidance of doubt, SafeBind's total aggregate liability arising out of or relating to this DPA, including any liability arising from a Security Incident or any breach of SafeBind's data-protection obligations, is in all cases subject to, and does not exceed, the single aggregate limitation of liability set forth in the Terms; no provision of this DPA — and no separate liability-allocation, indemnity, reimbursement, or damages-allocation section of this DPA — creates, or shall be construed to create, any separate, additional, second, standalone, or uncapped liability of SafeBind, or any data-breach supercap; and the exclusions of indirect, incidental, special, consequential, exemplary, and punitive damages, the single aggregate cap, and the one-year limitations period set forth in the Terms apply to all claims under or relating to this DPA, including any claim under any liability-allocation, indemnification, or customer-obligations section of this DPA and any claim arising from a Security Incident. The customer indemnity, reimbursement, and liability-allocation obligations set forth in this DPA, together with all of your obligations and responsibilities as the business or controller — including your lawful-basis, notice-and-consent, accuracy, data-minimization, and instruction responsibilities — are expressly carried through and apply in full to all claims under or relating to this DPA. Your indemnification, reimbursement, and liability obligations to SafeBind survive any termination or expiration of the Terms and this DPA and, to the fullest extent permitted by applicable law, are not subject to the exclusions, the limitations of liability, or the aggregate cap set forth in the Terms.

15. Contact

Questions about this DPA, requests for a countersigned copy, and privacy inquiries: contact@safebind.ai.