Data Processing Addendum

GDPR Article 28 terms for processing customer personal data.

Last updated May 12, 2026. This DPA supplements the FactPattern Terms of Service and applies whenever FactPattern processes personal data on behalf of a Customer.

Processor role

Customer is the controller of personal data submitted to FactPattern. FactPattern acts as the processor and processes the data only on documented instructions from the controller.

Security measures

Encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege production access, MFA, continuous logging and vulnerability management.

1. Definitions

Capitalized terms have the meaning given in the Terms of Service or in applicable Data Protection Laws (including the EU GDPR, UK GDPR, Swiss FADP, and US state privacy statutes such as the CCPA/CPRA).

2. Roles and scope

For Customer Personal Data, Customer is the Controller and FactPattern Systems LLCis the Processor. FactPattern processes Customer Personal Data only to provide the service in accordance with documented instructions from the Customer, including those embedded in the platform's configuration.

3. Nature, purpose and categories

  • Nature & purpose — ingest, correlate and analyze security telemetry; generate investigation cases, briefs, and compliance evidence; route approval-gated response actions.
  • Data subjects — Customer personnel and authenticated end-users referenced in security events (employees, contractors, service principals).
  • Data categories — identifiers (email, account IDs, device IDs, IPs), authentication metadata, security event metadata, audit log entries, analyst notes.
  • Sensitive data — not required; Customer is responsible for not forwarding special-category data unnecessarily.

4. Processor obligations

  • Process Customer Personal Data only on documented instructions.
  • Ensure persons authorized to process Customer Personal Data are bound by confidentiality.
  • Maintain the technical and organizational measures described in the Security Annex.
  • Engage sub-processors only under written terms providing protections equivalent to this DPA.
  • Assist the Controller with data-subject requests, DPIAs and prior consultations to the extent reasonably required.
  • Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach.
  • Delete or return Customer Personal Data on termination.

7. AI sub-processing

When Customer enables live AI features, prompts and minimum required context are sent to the contracted LLM gateway and underlying model providers. Customer Personal Data is not used to train FactPattern or third-party foundation models.

9. Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service, except for amounts that cannot be excluded under applicable Data Protection Laws.

Annex A — Security measures

  • Encryption: TLS 1.2+ in transit; AES-256 at rest; key rotation managed via cloud KMS.
  • Access control: SSO + MFA on production; least-privilege RBAC; quarterly access reviews.
  • Logging & monitoring: immutable audit logs; SIEM-monitored production access; 24×7 alerting.
  • Vulnerability management: continuous dependency scanning; quarterly external penetration testing; coordinated disclosure program.
  • Resilience: cross-AZ deployment; daily encrypted backups; documented DR runbook tested annually.
  • People: background checks where lawful; mandatory annual security and privacy training.

Contact