1 Scope and order of precedence
This DPA is between Fold33, LLC ("Fold33", "we"), and the Customer named in the Agreement. It is incorporated into the Terms of Service by reference and needs no separate signature.
If this DPA conflicts with the rest of the Agreement on the processing of Customer Personal Data, this DPA prevails. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.
2 Definitions
Words defined in the Terms have the same meaning here. In addition:
- Data Protection Law
- The laws on personal data that apply to the processing under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as it forms part of UK law ("UK GDPR") and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act ("CCPA").
- Customer Personal Data
- Personal Data in Customer Data that we process on the Customer's behalf.
- Personal Data, controller, processor, data subject, processing, supervisory authority
- Have the meanings given in the GDPR. "Personal Data" includes "personal information" under US state privacy laws.
- Personal Data Breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data that we process.
- Standard Contractual Clauses
- The clauses adopted by the European Commission in Decision 2021/914, and the UK International Data Transfer Addendum, where separately agreed and completed for the relevant transfer under section 12.
- Subprocessor
- A third party we engage to process Customer Personal Data.
3 Roles
The Customer is the controller of Customer Personal Data, and we are its processor. Where the Customer is itself a processor for someone else, we are its subprocessor, and the Customer confirms that its instructions are authorised by its controller.
We are an independent controller for our own business data: our Customers' business contacts and billing, and the security of our own systems. Our Privacy Policy covers that data, not this DPA.
The Customer's Microsoft 365 or Google Workspace, where its Documents, Markup and people list are kept, is the Customer's own provider under the Customer's own agreement. It is not our Subprocessor.
The Customer is responsible for having a lawful basis for the processing, for the notices it gives its Authorised Users, and for the lawfulness of its instructions.
4 Processing instructions
We process Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise. If it does, we will tell the Customer before processing, unless the law forbids that.
The Agreement, and the Customer's use and configuration of the Service (including its Settings and Protections), are the Customer's complete instructions. Further instructions must be agreed in writing.
We will tell the Customer if we believe an instruction breaks Data Protection Law. We will not follow that instruction unless the concern is resolved lawfully. The Customer must not instruct us to process data unlawfully.
The details of processing are in Annex 1.
5 Confidentiality
We make sure that everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, and has access only as far as their role needs. The Service is built so that our own staff need no access to Documents, Markup or the Customer's people list to run it.
6 Security
We implement and maintain the technical and organisational measures in Annex 2, taking into account the state of the art, the cost, and the nature, scope, context and purposes of the processing, and the risks to data subjects.
We may update those measures, provided that the update does not materially lower the overall protection of Customer Personal Data.
The Customer is responsible for the security measures in its own control: its Customer Storage, its identity provider, its Settings and Protections, the accounts of its Admins and Authorised Users, and the devices they use.
7 Subprocessors
The Customer gives general authorisation for us to engage Subprocessors. Our current Subprocessors are listed on our Subprocessors page.
We give each Subprocessor data protection obligations that are no less protective than this DPA, and we remain responsible to the Customer for its performance.
We will give at least 30 days' notice before adding or replacing a Subprocessor, by updating the Subprocessors page and emailing the Customer's Admins or notice contact.
The Customer may object on reasonable data protection grounds within that notice period. We will then work in good faith to address the objection. If we cannot, the Customer may end the affected part of the Service by written notice, and we will refund Fees paid in advance for the period after it ends.
8 Assistance
If help under this section goes beyond what the Service provides and is more than minimal, we may charge for it at reasonable rates agreed in advance.
9 Personal Data Breach
We will notify the Customer of a Personal Data Breach without undue delay after becoming aware of it, using the Admin or notice contact on file. We do not wait for a completed investigation before giving the initial notice.
The notice will describe, as far as we then know, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot give everything at once, we will give it in phases as we learn it.
We will take reasonable steps to contain the breach and reduce its effects, and cooperate with the Customer's investigation. Notifying a breach is not an admission of fault.
10 Deletion and return
When the Agreement ends, we remove the Customer's active portal data within 30 days: its Activity Log, session, suspension and trial seat records, Settings (including direct access grants and email hashes), and logo. The Customer may request return or deletion of Customer Personal Data in our control, subject to section 10.3. Documents, notes and the people list already remain in Customer Storage.
There is little to return, because Documents, Markup and the people list stay in the Customer Storage throughout. Before the end date, Admins can export the Activity Log as a CSV file.
Residual copies may remain in protected backups for approximately 37 days under the standard 30-day retention and 7-day soft-delete settings, restricted to recovery and security purposes and removed through the backup cycle. We may retain records where the law requires, confidentially and only for that purpose. Our Azure operational-log retention is up to 30 days; other provider logs follow their documented policies. Business and billing records handled as an independent controller follow our Privacy Policy.
11 Audits and information
We will make available to the Customer the information reasonably needed to show that we meet this DPA. We do this first through written answers to reasonable security and privacy questionnaires, and through documentation of our measures.
If that information is insufficient to meet the Customer's obligations under Data Protection Law, the Customer or an independent auditor bound by confidentiality may audit relevant processing. Routine audits are limited to once a year, with 30 days' notice, during business hours and without unnecessary disruption. Extra or faster audits are allowed where required by law, an authority or a relevant Personal Data Breach. We agree reasonable safeguards for other customers' information. The Customer normally pays its audit costs; this does not restrict legally required cooperation or a supervisory authority's access.
12 International transfers
We process Customer Personal Data in the United States, and our Subprocessors process it in the locations on the Subprocessors page. The data we store is kept in the Microsoft Azure region of our deployment: Central US (Iowa) unless the Order says otherwise.
Before processing that requires a restricted-transfer safeguard for EEA, UK, Swiss or other protected data, the Customer must notify us and the parties must put the required arrangement in place. Where Standard Contractual Clauses are needed, they must be separately agreed and completed with the correct modules, annexes and any UK or Swiss provisions. This DPA does not by itself execute or complete them. Do not enable that processing until the arrangement is in place. If we cannot establish a lawful arrangement, we will not undertake the affected processing.
We will use a lawful safeguard for Subprocessor onward transfers where Data Protection Law requires one. We do not claim our own Data Privacy Framework certification. If an applicable safeguard is no longer valid, we will work with the Customer on an alternative or stop the affected processing.
13 US state privacy laws
Where the CCPA or a similar US state law applies, we are the Customer's service provider or processor. We process Customer Personal Data only for the business purposes in the Agreement.
We will not sell or share Customer Personal Data (as those laws define the words), retain, use or disclose it outside our direct business relationship with the Customer or for any purpose other than the Agreement, or combine it with personal data we receive from others, except as those laws allow.
We will tell the Customer if we can no longer meet these obligations, and the Customer may take reasonable steps to stop and remedy unauthorised processing. We certify that we understand these restrictions and will comply with them.
14 Liability and term
Each party's liability under this DPA is subject to the limits and exclusions in the Terms, except where Data Protection Law or the Standard Contractual Clauses do not allow it.
This DPA lasts for as long as we process Customer Personal Data, and ends when that data is deleted.
A1 Annex 1 · Details of processing
| Subject matter | Providing RedlinerHQ, a browser-based portal in which the Customer's Authorised Users review PDF documents and audio recordings kept in the Customer's own SharePoint or Google shared drives. |
|---|---|
| Duration | The term of the Agreement and the deletion, residual-backup and legally required retention periods described in section 10. |
| Nature of processing |
|
| Purpose | To provide, secure and support the Service under the Agreement, and to count Active Users for billing. |
| Data subjects |
|
| Categories of data we store |
|
| Content processed outside the Service database |
|
| Data processed transiently |
|
| Special categories | The Customer determines the content and is responsible for a lawful basis and any additional consent needed for sensitive data or recordings. Workloads requiring a specific agreement, certification or handling arrangement must be agreed in writing before use, under Terms section 6.3. Passing data through the Service is still processing, even without a permanent content archive. |
| Frequency | Continuous, while the Service is used. |
| Retention | Activity Log: 24 months by default, 6 to 120 months as the Customer sets, or until a legal hold is lifted. Other stored data: until changed or until offboarding. |
| Subprocessors | As listed on the Subprocessors page. |
A2 Annex 2 · Security measures
Keeping little
- We do not keep a permanent archive of Documents. They are read from Customer Storage and passed to the browser. PDF exports are made in memory and written to Customer Storage. Preparing an audio review copy also uses a private temporary output file, deleted after processing, including failed conversions.
- Markup and the people list live in the Customer Storage, not with us.
- Our storage holds ids, not names: the Activity Log refers to people and documents by id and to folders by hashed key. Email addresses in portal access records are kept as hashes; application intake, support and billing records have the separate handling described in the Privacy Policy.
- Weekly digests carry counts and folder labels, never document names. Support messages are retained in our support mailbox, outside the portal database.
Least privilege on the Customer Storage
- On SharePoint, the Service asks for Microsoft Graph
Sites.Selected, orFiles.SelectedOperations.Selectedfor a single folder: read on the source, write on the workspace, for server access to connected locations. Admin setup tools separately use delegated permissions to browse sites or drives the Admin can access; those permissions may include Microsoft Sites.Read.All or Google drive.readonly. On Google, the Customer adds our service account to two shared drives: Viewer on the source, Content manager on the workspace. - The source is never written to. A layout where the workspace sits inside the source is refused.
- Customers relying on portal restrictions must remove reviewers' direct storage permissions and bypass sharing links. Storage owners and Admins can retain their own administrative access; that access is outside portal restrictions. Reviewer content routes do not return direct storage links.
- A check flags sharing links, invitations and direct grants on the source that would bypass the portal.
Credentials and secrets
- The Service reaches Microsoft Graph with a managed identity and a federated credential, and Google through workload identity federation from the same identity. These production storage connections do not use a stored service-account private key or Graph client secret. Other integrations, including billing and webhooks, use secrets protected by access controls; platform secrets use Azure Key Vault.
- Table Storage and email are reached with the same managed identity; shared-key and local authentication are turned off.
Tenant isolation and access control
- Customer selection is checked against the verified identity and that Customer's configured access rules; a portal address alone does not grant access. Records are kept per Customer.
- A document id resolves only within the folders the person was given; anything else is refused. Every storage path is checked.
- Microsoft tokens must be RS256, from the Customer's own tenant, for our API, unexpired and with the delegated scope. Google tokens must be for our client and carry a verified email. Admin rights require the configured Microsoft group, verified invited setup-admin identity, or approved hashed Google admin list.
- Per-folder roles (viewer, annotator, exporter) and end dates are enforced by the server on every request. Admins can suspend a person, which takes effect on the next request.
- Protections the Customer turns on are enforced by the server where they can be: downloads, printing, the confidentiality terms, one session per person and the bulk-open pause. Copy blocking, the watermark and hiding the page are deterrents in the browser.
- Rate limits apply per person and per Customer.
A tamper-evident activity log
- Each Customer's records form a hash chain: every record carries the hash of the one before, so editing or deleting one is detectable.
- Retention removes old records as one block from the start of the chain and keeps a checkpoint, so what remains still verifies. A legal hold stops removal.
- The Customer can send each event, signed with HMAC, to its own security tools.
In transit and in the browser
- HTTPS only, with TLS 1.2 or later and HSTS.
- A strict Content Security Policy. The app uses Microsoft and Google for sign-in, directory and storage selection, and Stripe-hosted pages for payments; its fonts are bundled.
- API responses are not cached and cannot be framed. Errors return a reference, never internal detail.
- Sign-in tokens are kept in session storage, which clears when the tab closes.
- Markup is rebuilt from an allowed list of mark types and limits, with the author stamped from the sign-in, before it is stored or served.
Our own access
- Our operations console runs on a separate service from the customer portal, with no operations routes on the customer address. It requires sign-in to our own tenant as a member of a restricted admins group, and is restricted at the network edge.
- The console shows ids, status, counts, health and billing only: no documents, markup, people or activity records.
- Every change made through the console is written to a platform log kept apart from every Customer's. Offboarding requires the Customer's id to be typed back.
Hosting
- Hosted on Microsoft Azure and Cloudflare (see the Subprocessors page). Storage is encrypted at rest by the provider, with a delete lock on the storage account.
- Application telemetry is not collected. Operational logs are kept for up to 30 days.