Legal

Data Processing Addendum

Effective date: June 19, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Fathomkey ("Processor") and the customer entity agreeing to the Terms of Service ("Controller") for the processing of personal data in connection with Product Investment Intelligence (the "Service"). This DPA supplements and forms part of the Terms of Service and Privacy Policy.

1. Definitions

Terms such as "personal data", "processing", "data subject", "controller", and "processor" have the meanings given in applicable data protection law, including the EU GDPR, UK GDPR, and India DPDP Act 2023. "Customer Content" means all data, including personal data, submitted by or on behalf of the Controller to the Service.

2. Roles and scope

For Customer Content containing personal data, the Controller is the data controller and Fathomkey is the data processor. Fathomkey will process personal data only on documented instructions from the Controller, including as set out in the Terms of Service and this DPA, unless required by applicable law.

3. Processing details

  • Subject matter: provision of Product Investment Intelligence decision intelligence services.
  • Duration: for the term of the subscription plus any retention period specified herein.
  • Nature and purpose: hosting, storing, analyzing, and displaying Customer Content to deliver the Service.
  • Categories of data subjects: Controller's employees, contractors, and end users whose data is included in Customer Content.
  • Types of personal data: names, work emails, roles, authentication identifiers, and any personal data contained in evidence, transcripts, tickets, and documents uploaded by the Controller.

4. Processor obligations

Fathomkey will:

  • Process personal data only on documented instructions from the Controller.
  • Ensure persons authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures as described in our Security page and Privacy Policy.
  • Not engage sub-processors without the Controller's authorization, subject to Section 5.
  • Assist the Controller in responding to data subject requests, to the extent legally permitted and technically feasible.
  • Assist the Controller with data protection impact assessments and prior consultations where required by law.
  • Delete or return all personal data upon termination, subject to Section 8.
  • Make available information necessary to demonstrate compliance and allow audits as described in Section 9.

5. Sub-processors

The Controller authorizes Fathomkey to engage sub-processors for cloud hosting, model providers, observability, payments, email delivery, and customer support. A current list is available on request to choudhary[@]fathomkey.pro. Fathomkey will impose data protection obligations on sub-processors that are no less protective than this DPA and will remain liable for sub-processor performance.

6. International transfers

Where personal data is transferred outside its country of origin, Fathomkey relies on appropriate safeguards including the EU Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, and equivalent mechanisms under applicable law, together with supplementary technical and organizational measures.

7. Security measures

Fathomkey maintains an information security program aligned with ISO/IEC 27001 and SOC 2, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access, MFA for production access, segregated environments, continuous logging and monitoring, vulnerability management, and an incident response plan. See our Security page for details.

8. Deletion and return

Upon termination of the Service, Fathomkey will delete or return Customer Content containing personal data within thirty (30) days, unless applicable law requires retention. The Controller may export Customer Content prior to termination using available export features.

9. Audits

Fathomkey will make available SOC 2 reports, security documentation, and compliance questionnaires upon request. The Controller may conduct audits no more than once per year with thirty (30) days' notice, subject to confidentiality obligations and reasonable scope limitations.

10. Data breach notification

Fathomkey will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Content. Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

11. AI processing

Fathomkey does not use Customer Content to train foundation models. AI processing is limited to delivering the Service for the Controller, with human-in-the-loop review required for business decisions. See our Privacy Policy for full AI governance details.

12. Contact

Fathomkey
Hyderabad, Telangana
Data Protection: choudhary[@]fathomkey.pro