Data Processing Addendum

Last updated: September 10, 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service or other written agreement (the "Agreement") between Amend Solutions LLC ("Amend," "we," "us," "our") and the business customer identified in the Agreement ("Customer," "you"), governing Amend's Processing of Personal Data on your behalf.

This DPA applies automatically. You do not need to sign or return it. If your organization requires a countersigned copy, contact [email protected]. Where this DPA conflicts with the Agreement, this DPA controls as to the Processing of Personal Data. Capitalized terms not defined here have the meanings given in the Agreement or the Privacy Policy.

1. Definitions

2. Roles of the parties

With respect to Personal Data contained in Customer Data, you are the Controller (and, under the CCPA, the Business) and Amend is the Processor (and, under the CCPA, a Service Provider). You determine the purposes and means of Processing. Amend Processes Personal Data only as described in Section 3.

Amend is an independent Controller for the limited account, billing, support, and website data described in the Privacy Policy. That Processing is governed by the Privacy Policy and not by this DPA.

You are responsible for the accuracy and lawfulness of Personal Data you submit, for having a lawful basis for its Processing, and for providing any notices and obtaining any consents required from your own clients, employees, and contacts.

3. Scope and instructions

Amend Processes Personal Data only:

This DPA and the Agreement are your complete and final documented instructions. Amend will notify you if, in its opinion, an instruction infringes Applicable Data Protection Law.

Amend will not: sell or share Personal Data as those terms are defined under the CCPA; retain, use, or disclose Personal Data outside the direct business relationship with you or for any purpose other than performing the Service; or combine Personal Data with personal information received from another source, except as permitted under the CCPA. Amend certifies that it understands these restrictions and will comply with them.

4. Artificial intelligence features

Amend does not use Customer Data to train foundation models, and does not authorize its model providers to do so. AI features are provided through third-party model providers under enterprise terms that exclude content submitted through their APIs from model training. Personal Data submitted to an AI feature is Processed to generate output for you and, within the Customer's own tenant, may be retained as redacted written learnings that improve the assistant's responses for that Customer, as described in the Privacy Policy. Such learnings are encrypted per tenant, are never disclosed to or used for another Customer, are visible and deletable by the Customer in the Service, and are deleted on account deletion. All such Personal Data remains subject to the same obligations as all other Personal Data under this DPA. Model providers engaged for this purpose are listed as Subprocessors in Section 6.

5. Confidentiality

Amend treats Personal Data as confidential. Amend limits access to personnel who require it to perform the Service, binds those personnel to written confidentiality obligations that survive termination of their engagement, and maintains role-based access controls as described in Annex II.

Where Amend personnel access raw tenant data to provide support, that access requires a stated reason and is recorded in a hash-chained access log whose integrity can be independently verified.

6. Subprocessors

You provide general written authorization for Amend to engage Subprocessors. Amend imposes data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains fully liable to you for each Subprocessor's performance.

Amend's current Subprocessors are published in the Privacy Policy. Amend will give you at least thirty (30) days' notice before adding or replacing a Subprocessor that Processes Personal Data, by updating that list and notifying the account's administrative contact. If you reasonably object on data protection grounds within that period, the parties will work in good faith to find an alternative; if none is available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the terminated portion.

7. Security

Amend implements and maintains the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects. Amend may update those measures provided the overall level of security is not reduced.

Amend does not currently hold a SOC 2, ISO 27001, PCI DSS, or HIPAA certification or attestation, and makes no representation that it does. Annex II describes measures Amend actually operates.

8. Personal Data Breach

Amend will notify you without undue delay, and in any event within seventy-two (72) hours after confirming a Personal Data Breach affecting Personal Data Processed on your behalf. The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Amend will provide further information as it becomes available and will reasonably assist you in meeting your own notification obligations.

Amend's notification is not an acknowledgement of fault or liability.

9. Assistance with Data Subject rights

The Service provides administrative controls that allow you to access, correct, export, and delete Personal Data yourself. Those controls are your primary means of responding to Data Subject requests. Where a request cannot be fulfilled through them, Amend will provide reasonable assistance, taking into account the nature of the Processing.

If Amend receives a request directly from a Data Subject relating to your Customer Data, Amend will not respond to it substantively and will, unless prohibited by law, forward it to you without undue delay.

10. Data protection impact assessments

Amend will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the Processing and the information available to Amend.

11. Return and deletion

You may export Customer Data at any time through the Service. On termination or expiry of the Agreement, and on your written request, Amend will delete Customer Data in accordance with the retention practices described in the Privacy Policy.

Amend retains Personal Data where retention is required by law — including payroll, wage, and tax records subject to statutory retention periods — for the period the applicable law prescribes, after which it is deleted. Where Amend retains data on that basis, it will tell you what has been retained and why, and will continue to protect it under this DPA for as long as it is held. Residual copies may persist in backups for a limited period until those backups are overwritten in the ordinary cycle.

12. Audits and information rights

Amend will make available to you the information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire.

Where Applicable Data Protection Law entitles you to audit, you may do so no more than once in any twelve (12) month period, on at least fourteen (14) days' prior written notice, during normal business hours, without unreasonably interfering with Amend's operations, and subject to confidentiality obligations. You bear the cost of the audit and are responsible for your auditor's conduct. These limits do not apply where an audit is required by a supervisory authority or follows a confirmed Personal Data Breach affecting your Personal Data.

13. International transfers

Customer Data is stored and Processed in the United States, in Google Cloud's us-west1 region. Where Personal Data protected by the GDPR or UK GDPR is transferred to Amend in a country without an adequacy decision, the parties agree that the Standard Contractual Clauses apply and are incorporated by reference, with Module Two (Controller to Processor) applying, you as data exporter and Amend as data importer. For the purposes of the SCCs: the optional docking clause applies; the supervisory authority is that of the exporter's establishment; the governing law and forum are those of Ireland unless the exporter's law requires otherwise; Annex I is populated by Annex I below; and Annex II is populated by Annex II below. Where the UK GDPR applies, the UK International Data Transfer Addendum applies with the SCCs.

14. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party's obligations to a Data Subject under Applicable Data Protection Law.

15. Term

This DPA takes effect when you accept the Agreement and continues until Amend has ceased all Processing of Personal Data on your behalf. Sections that by their nature should survive — including confidentiality, retention, and liability — survive termination for as long as Amend holds Personal Data.

Annex I — Details of Processing

A. Parties. Data exporter: the Customer identified in the Agreement, a business using the Service to operate its own business. Data importer: Amend Solutions LLC, a California limited liability company providing an AI-native business management platform. Contact for both roles: [email protected].

B. Categories of Data Subjects. The Customer's own clients and prospective clients; the Customer's employees, crew, and contractors who are given access to the Service; the Customer's vendors and suppliers; and individuals whose details appear in documents, messages, or files the Customer uploads.

C. Categories of Personal Data. Names and business names; email addresses, telephone numbers, and postal addresses; job, estimate, invoice, payment, and scheduling records; documents and files uploaded by the Customer, including plans, photographs, and signed agreements; messages and call records where the Customer enables communication features; employee payroll and wage data, including tax identifiers, where the Customer uses payroll features; bank account and transaction data where the Customer connects a financial account; and location and check-in data where the Customer enables field tracking and its personnel consent.

D. Sensitive data. The Service is not designed for and should not be used to Process special categories of personal data under Article 9 GDPR, or personal data relating to criminal convictions. Where the Customer uses payroll features, government identifiers are Processed as necessary for that feature and are encrypted at rest as described in Annex II.

E. Frequency. Continuous, for the duration of the Agreement.

F. Nature and purpose. Hosting, storage, organization, retrieval, transmission, and display of Customer Data in order to provide the Service; generation of AI output at the Customer's direction; and delivery of communications the Customer initiates.

G. Duration. For the term of the Agreement and thereafter as set out in Section 11.

H. Subprocessors. As published in the Privacy Policy, including cloud infrastructure and hosting, AI model processing, content delivery and object storage, payment processing, and transactional email delivery.

Annex II — Technical and Organizational Measures

The following measures are in operation. They describe what Amend does; they are not a certification and do not claim conformity with any standard.

Encryption at rest. Sensitive fields are encrypted with AES-256-GCM before being written to disk, under a key derived uniquely for each Customer from a master secret using HKDF-SHA256. The master secret is held only in the runtime environment and is not present in Amend's source code. One Customer's key cannot decrypt another Customer's data.

Cryptographic tenant separation. Each encrypted record is cryptographically bound to the Customer it belongs to, so a record cannot be moved between accounts without the change being detected on decryption. This operates in addition to, not instead of, row-level scoping.

Encryption in transit. Data in transit is protected with industry-standard TLS.

Access control. Least-privilege, role-based access is enforced on the server rather than in the interface, so limits cannot be bypassed through the client or through the AI assistant. Financial, document, and payment functions are restricted to appropriate roles.

Authentication. Two-factor authentication and passkey (WebAuthn) sign-in are available. Repeated failed sign-in attempts are rate-limited. Changing a password or a user's access revokes that user's existing sessions immediately rather than allowing them to expire.

Actions requiring human approval. Actions that move money, send communications outside the Customer's organization, or are otherwise irreversible require explicit approval from an authorized user. Approvals are cryptographically bound to the specific action proposed.

Accountability logging. Amend staff access to raw tenant data requires a stated reason and is written to an append-only access log in which each entry cryptographically commits to its predecessor, so that any subsequent edit, deletion, or reordering is detectable by verification.

Backups and resilience. Automated off-site backups run on a schedule over encrypted transport, with sensitive data remaining encrypted at rest within the backup.

Segregation. Customer Data is logically segregated by Customer. Every query is scoped to the requesting Customer, and that scoping is exercised by automated tests on every code change.

Secure development. Changes are subject to automated testing, dependency vulnerability scanning, and secret scanning before release. Dependencies with known high-severity vulnerabilities block a release.

Deletion. Customer Data is deleted on request except where retention is required by law, as set out in Section 11.

Questions about this DPA: [email protected].