Pricing Vision Careers
Log in Sign up

Data Processing Addendum

Cinchapi, Inc.

Effective Date: July 14, 2026

  • 1. Scope and Applicability
  • 2. Roles and Processing Instructions
  • 3. Customer Responsibilities
  • 4. Confidentiality and Security
  • 5. Subprocessors
  • 6. Data-Subject and Consumer Requests
  • 7. Security Incidents
  • 8. Compliance Assistance
  • 9. Return and Deletion
  • 10. Information and Audits
  • 11. International Data Transfers
  • 12. U.S. State Privacy Terms
  • 13. Model Training
  • 14. Liability
  • 15. General
  • Schedule 1 — Processing Details
  • Schedule 2 — Security Measures
  • Contact Information

Source: https://cinchapi.com/legal/dpa

1. Scope and Applicability

This Data Processing Addendum (“DPA”) forms part of the agreement between Cinchapi, Inc. (“Cinchapi”) and the customer that governs the customer’s use of the Services (the “Agreement”). This DPA applies when Cinchapi processes Customer Personal Data on behalf of Customer in connection with the Services.

This DPA is automatically incorporated into the Agreement when applicable and does not require a separate signature. If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls. If Customer and Cinchapi have entered into a separate negotiated data processing agreement, that agreement controls over this DPA to the extent of any conflict for the processing it covers. Nothing in this paragraph changes the mandatory precedence of applicable standard contractual clauses or international data transfer addenda. Capitalized terms not defined here have the meanings given in the Agreement.

“Customer Personal Data” means personal data, personal information, or similarly regulated information contained in Customer Data that Cinchapi processes on behalf of Customer. Customer Personal Data does not include personal information for which Cinchapi determines the purposes and means of processing, such as information used for Cinchapi’s own account administration, billing, legal compliance, or security purposes.

“Data Protection Laws” means privacy and data-protection laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the EU GDPR as incorporated into United Kingdom law (“UK GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other applicable U.S. state privacy laws.

2. Roles and Processing Instructions

As between the parties, Customer is the controller or business and Cinchapi is the processor or service provider for Customer Personal Data. If Customer is itself a processor, Cinchapi acts as Customer’s subprocessor. Each party will comply with its obligations under applicable Data Protection Laws.

Cinchapi will process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Customer’s use and configuration of the Services, authorized support requests, and other written instructions accepted by Cinchapi, unless applicable law requires different processing. If applicable law requires Cinchapi to process Customer Personal Data contrary to Customer’s instructions, Cinchapi will notify Customer before processing unless the law prohibits notice.

Cinchapi will promptly inform Customer if, in Cinchapi’s reasonable opinion, an instruction violates applicable Data Protection Laws. Cinchapi may suspend the affected processing until the parties resolve the issue.

3. Customer Responsibilities

Customer is responsible for the lawfulness of Customer Personal Data and its processing instructions, including providing required notices, obtaining required consents or other lawful bases, responding to data-subject requests, and ensuring that Customer has the right to make Customer Personal Data available to Cinchapi.

Customer must obtain Cinchapi’s express written agreement before submitting Restricted Regulated Data as defined in Section 7 of the Terms of Use, subject to any separate negotiated agreement governing the relevant data. That agreement must authorize the data and establish any required safeguards or additional terms. This restriction does not limit Cinchapi’s obligations under this DPA or applicable law.

4. Confidentiality and Security

Cinchapi will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as needed to perform their responsibilities.

Cinchapi will maintain reasonable administrative, technical, organizational, and physical safeguards designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current categories of safeguards are described in Schedule 2. Cinchapi may update safeguards as technology and risks evolve, provided that updates do not materially reduce the overall protection of Customer Personal Data during the applicable subscription term.

5. Subprocessors

Customer generally authorizes Cinchapi to engage subprocessors to process Customer Personal Data in connection with the Services. Cinchapi will maintain a current list identifying its subprocessors, their processing functions, and the countries in which they process Customer Personal Data. The list is available upon request to privacy@cinchapi.com.

Cinchapi will provide Customer with at least fifteen (15) days’ prior written notice before adding or replacing a subprocessor that will process Customer Personal Data for Customer. Notice will identify the subprocessor, its processing function, and the relevant processing locations and will be sent to Customer’s designated privacy contact or, if none is designated, its account administrator. Customer is responsible for keeping those contact details current.

Customer may object in writing within fifteen (15) days after notice on reasonable grounds relating to the protection of Customer Personal Data. Cinchapi will work with Customer in good faith to address a timely objection, which may include offering a commercially reasonable alternative or modifying the affected Services.

If the parties cannot resolve the objection, either party may terminate the affected Services by written notice. Customer will not incur an early-termination charge solely because of that termination, and Cinchapi will refund unused prepaid subscription fees for the terminated portion of the Services. Unused Purchased Credits, if any, will be handled under the Agreement. Unaffected Services will continue.

Cinchapi will enter into a written agreement with each subprocessor imposing data- protection obligations substantially equivalent to those applicable to its processing under this DPA. Cinchapi remains responsible for the subprocessor’s performance of those obligations as required by applicable Data Protection Laws. Nothing in this Section limits any additional requirements of applicable standard contractual clauses or international data transfer addenda.

6. Data-Subject and Consumer Requests

Taking into account the nature of the processing, Cinchapi will provide reasonable assistance to Customer through available Service functionality and, where necessary, other reasonable measures so Customer can respond to requests to exercise privacy rights. If Cinchapi receives a request relating to Customer Personal Data directly from an individual, Cinchapi will direct the individual to Customer or notify Customer, unless applicable law requires Cinchapi to respond directly.

Customer is responsible for determining whether a request is valid and for communicating with the requester. Cinchapi may charge reasonable fees for assistance that is unusually burdensome, repetitive, or outside standard Service functionality, except where applicable law prohibits such fees.

7. Security Incidents

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Cinchapi. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as blocked attacks, scans, pings, or failed login attempts.

Cinchapi will notify Customer without undue delay after becoming aware of a Security Incident. Cinchapi will provide information reasonably available to it that Customer needs to meet applicable notification obligations, including the nature of the incident, affected data and individuals where known, likely consequences, and mitigation measures. Cinchapi may provide information in phases as its investigation proceeds.

Cinchapi will take reasonable steps to contain, investigate, and mitigate a Security Incident. Notification of a Security Incident is not an admission of fault or liability. Customer is responsible for determining whether to notify regulators, affected individuals, or others, except to the extent applicable law imposes a direct obligation on Cinchapi.

8. Compliance Assistance

Taking into account the nature of processing and information available to Cinchapi, Cinchapi will provide reasonable assistance to Customer with data-protection impact assessments, prior consultations, security obligations, and legally required regulatory inquiries relating to Cinchapi’s processing of Customer Personal Data.

If a regulator or government authority requests Customer Personal Data directly from Cinchapi, Cinchapi will notify Customer unless prohibited by law. Where legally permitted, Cinchapi will reasonably redirect the authority to Customer and challenge requests that Cinchapi reasonably believes are unlawful or overbroad.

9. Return and Deletion

During the term, Customer may retrieve Customer Data using available Service functionality and any retrieval rights in the Agreement. At Customer’s written choice made within the applicable retrieval period, and subject to the Agreement, Cinchapi will return Customer Personal Data using its then-available export functionality or delete it. If Customer does not make a timely choice, Cinchapi will delete Customer Personal Data in accordance with the Agreement and Privacy Policy, including the stated deletion timeline.

Cinchapi may retain Customer Personal Data where required by applicable law, provided that Cinchapi continues to protect it under this DPA and processes it only for the required purpose. Copies in routine backups may remain until deleted through ordinary backup rotation and will remain protected and isolated from ordinary use.

10. Information and Audits

Cinchapi will make available information reasonably necessary to demonstrate compliance with this DPA. Cinchapi may satisfy audit requests by providing current third-party audit reports, certifications, summaries, or responses to reasonable security questionnaires, where available and subject to confidentiality restrictions.

If that information is reasonably insufficient, Customer may conduct an audit no more than once in any twelve-month period, unless a Security Incident, regulator, or reasonable evidence of material noncompliance requires an additional audit. Audits must occur during normal business hours, on reasonable advance notice, under appropriate confidentiality terms, without disrupting Cinchapi’s operations or accessing other customers’ information. Customer will bear its audit costs unless the audit finds material noncompliance by Cinchapi.

11. International Data Transfers

Customer authorizes Cinchapi to process Customer Personal Data in the United States and other countries where Cinchapi or its subprocessors operate, subject to the safeguards required by applicable Data Protection Laws.

11.1 European Economic Area

If Customer Personal Data protected by the EU GDPR is transferred to Cinchapi in a country that does not provide an adequate level of protection and no other lawful transfer mechanism applies, the parties incorporate the European Commission’s Standard Contractual Clauses adopted by Decision 2021/914 (“EU SCCs”). Module Two applies when Customer is a controller and Cinchapi is a processor. Module Three applies when Customer is a processor and Cinchapi is a subprocessor.

For the EU SCCs: Clause 7 applies; Option 2 in Clause 9 applies with a fifteen-day notice period; the optional language in Clause 11 does not apply; the governing law under Clause 17 is the law of Ireland; and the courts under Clause 18 are the courts of Ireland. The competent supervisory authority is determined under Clause 13. The Agreement and Schedule 1 complete Annex I, Schedule 2 completes Annex II, and Cinchapi’s current subprocessor information completes Annex III.

11.2 United Kingdom

For transfers governed by the UK GDPR, the EU SCCs as completed above are modified by and incorporate the then-current International Data Transfer Addendum issued by the UK Information Commissioner. The parties and selections identified in the Agreement and this DPA complete the applicable tables of that addendum. For Table 4, both the Importer and Exporter may end the addendum in accordance with Section 19.

11.3 Switzerland

For transfers governed by Swiss data-protection law, references in the EU SCCs to the EU GDPR include the Swiss Federal Act on Data Protection, references to a Member State include Switzerland, and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

12. U.S. State Privacy Terms

To the extent the CCPA or another applicable U.S. state privacy law applies to Customer Personal Data, Cinchapi acts as Customer’s service provider, contractor, or processor. Customer discloses Customer Personal Data to Cinchapi only for the limited and specified business purposes described in the Agreement and Schedule 1.

Cinchapi will not:

  • Sell or share Customer Personal Data
  • Retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for purposes other than the limited and specified purposes in the Agreement, except as permitted by applicable law
  • Combine Customer Personal Data with personal information received from another person or collected from Cinchapi’s own interactions with an individual, except as permitted by applicable law

Cinchapi will provide the same level of privacy protection required of Customer under applicable U.S. state privacy law, will notify Customer if Cinchapi determines it can no longer meet its obligations, and will allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use. The audit and assistance provisions of this DPA provide Customer’s monitoring and consumer-request assistance rights.

13. Model Training

Cinchapi’s processing of Customer Personal Data for artificial-intelligence or machine-learning model training is governed by the Customer Data and Model Training provisions of the Agreement. Cinchapi will not use Customer Personal Data for Model Training unless Customer affirmatively enrolls through authorized controls or provides documented instructions in a separate written agreement. Customer Personal Data from an Enterprise Offering or API Offering will not be used to train a Shared Model.

14. Liability

Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits liability to the extent it cannot be limited under applicable law.

15. General

This DPA terminates automatically when Cinchapi no longer processes Customer Personal Data on Customer’s behalf, except for provisions that must survive to protect retained Customer Personal Data or comply with applicable law. Amendments to this DPA will be handled under the Agreement, provided that no amendment will materially reduce the protection of Customer Personal Data during an existing subscription term unless required by applicable law.

Questions about this DPA or requests for subprocessor information may be sent to privacy@cinchapi.com.

Schedule 1 — Processing Details

Subject Matter and Duration

Processing Customer Personal Data to provide, operate, maintain, secure, support, and troubleshoot the Services for the duration of the Agreement and any permitted retention period.

Nature and Purpose

Receiving, accessing, collecting, recording, organizing, structuring, hosting, storing, synchronizing, transforming, indexing, retrieving, consulting, analyzing, transmitting, displaying, returning, and deleting Customer Personal Data as necessary to provide the Services and follow Customer’s documented instructions. This includes providing AI inference, data synchronization and warehousing functionality, search, retrieval, automation, support, security, and related Service functionality.

Categories of Data Subjects

Customer’s users, personnel, contractors, customers, prospective customers, end users, business contacts, and other individuals whose personal data Customer submits to or processes through the Services.

Categories of Customer Personal Data

Identifiers and contact information; account and profile information; employment and business information; communications; documents, files, prompts, inputs, outputs, and other content contained in Customer Data; records retrieved from connected systems; usage and transaction information contained in Customer Data; and other personal data Customer chooses to process through the Services in accordance with the Agreement.

Sensitive Data

Restricted Regulated Data described in Section 3 is not intended unless expressly authorized by a separate written agreement establishing the applicable safeguards. Customer is responsible for avoiding unauthorized submission of such data.

Frequency

Continuous or intermittent, depending on Customer’s use, configuration, and instructions.

Schedule 2 — Security Measures

  • Access controls designed to limit access to authorized personnel based on business need
  • Authentication measures appropriate to the Services and access risk
  • Encryption in transit and infrastructure-level encryption at rest for data stored in Google Cloud
  • Encryption of connector credentials at rest
  • Logging, monitoring, assessment, and testing measures appropriate to identified risks
  • Incident-response procedures for detecting, investigating, and mitigating incidents
  • Service-resilience, backup, and recovery measures appropriate to the applicable Service, without creating a recovery-time or recovery-point commitment unless stated in the Agreement
  • Personnel confidentiality obligations and security awareness measures
  • Subprocessor diligence and contractual data-protection requirements
  • Processes designed to delete or return Customer Personal Data in accordance with the Agreement and this DPA

Contact Information

Cinchapi, Inc.
1175 Peachtree St NE
Atlanta, GA 30361
Email: privacy@cinchapi.com
Website: https://cinchapi.com

Operational AI for Work Across Systems

© 2026 Cinchapi Privacy Policy Terms of Use