This Data Processing Agreement ("DPA") is part of the Terms of Service between you ("Customer", the data controller) and feat labs, inc. ("feat", the data processor). It applies whenever feat processes Personal Data on your behalf in connection with the Service.
Plain-English summary: when you push end-user data through feat (e.g. targeting context attributes), you remain the controller; feat is your processor. We process that data only on your documented instructions, keep it confidential, secure it, help you respond to data-subject requests, list our sub-processors transparently, and delete the data when you ask. This summary is informational; the sections below control.
1. Definitions
Capitalised terms used but not defined have the meaning in the GDPR (Regulation (EU) 2016/679), the UK GDPR, the LGPD, or the CCPA/CPRA, as applicable.
2. Roles and subject-matter
Customer is the controller and feat is the processor. The subject-matter is Customer's use of the Service. The duration matches the Term of the Terms of Service.
3. Customer instructions
feat will process Personal Data only on Customer's documented instructions, including those given via the Service's UI, APIs, and support channels. feat will inform Customer if an instruction infringes applicable law.
4. Confidentiality
feat will ensure that personnel with access to Personal Data are bound by confidentiality obligations and have received appropriate privacy training.
5. Security
feat will implement and maintain the technical and organisational measures described at /security, including encryption in transit and at rest, access controls, vulnerability management, logging, and incident response.
6. Sub-processors
Customer authorises feat to engage the sub-processors listed at /legal/subprocessors. feat will give at least 30 days' notice of any addition or replacement (via the subscribe form on that page) and Customer may object on reasonable grounds. feat remains liable for sub-processor acts and omissions.
7. International transfers
Where Personal Data is transferred out of the EU/EEA, UK, or Switzerland, the parties rely on the EU-US Data Privacy Framework (where applicable) and the European Commission's Standard Contractual Clauses (Module 2, controller-to-processor) as a fallback. The UK Addendum and the Swiss addendum are incorporated where relevant.
8. Data subject requests
feat will reasonably assist Customer in responding to requests from data subjects exercising their rights (access, rectification, erasure, portability, restriction, objection), within the timeframes required by applicable law. Requests received directly by feat will be redirected to Customer.
9. Personal data breaches
feat will notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach, with the information needed to comply with Customer's notification obligations.
10. Audits
feat will make available the information necessary to demonstrate compliance with Article 28 GDPR, including security reports and certifications when available. On-site audits are limited to once per twelve-month period, on at least 30 days' notice, at Customer's expense.
11. Deletion or return
On termination feat will, at Customer's choice, return or delete Personal Data within 30 days, except where retention is required by law.
12. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where applicable law disallows such limitation.
13. Order of precedence
To the extent of any conflict between this DPA and the Terms of Service on a data-protection matter, this DPA controls.
14. Annexes
The categories of data subjects, types of Personal Data, processing purposes, and security measures are set out in the Security and Sub-processors pages, which are incorporated by reference. Updated annexes published on those URLs automatically replace prior versions.
15. Contact
DPA-related notices and questions go to support@feat.so.