Legal

Data Processing Agreement (DPA)

Effective

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between Meikasa Properties, LLC, operating as FactHound (“FactHound”, “Processor”, “we”, or “us”), and the business or agency using our services (“Customer”, “Controller”, or “you”).

By accepting the FactHound Terms of Service, the Customer enters into this DPA.

1. Scope and Applicability

This DPA applies whenever FactHound processes Personal Data on behalf of the Customer in the course of providing the FactHound app, API, and related services (the “Service”). This DPA ensures compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).

2. Roles of the Parties

2.1. The Customer acts as the Data Controller. The Customer determines the purposes and means of the processing of Personal Data.

2.2. FactHound acts as the Data Processor. FactHound will process Personal Data solely on behalf of the Customer and in accordance with the Customer’s documented instructions, including this DPA and the Agreement.

3. Customer Obligations

The Customer warrants that it has all necessary rights, consents, and lawful bases to transfer Personal Data to FactHound and to authorize FactHound to process it for the purposes of providing the Service. The Customer is responsible for ensuring that the public publication of any facts or business profiles via FactHound complies with applicable privacy laws.

4. FactHound Obligations

4.1. Processing Instructions: FactHound will only process Personal Data as necessary to provide the Service, or as required by applicable law.

4.2. Confidentiality: FactHound ensures that personnel authorized to process Personal Data have committed themselves to confidentiality.

4.3. Data Subject Rights: If FactHound receives a request from a Data Subject (e.g., access, deletion, correction) regarding data controlled by the Customer, FactHound will promptly notify the Customer and provide reasonable assistance to help the Customer respond.

5. Security of Processing

FactHound will implement and maintain appropriate technical and organizational measures (TOMs) to protect Personal Data against unauthorized or accidental access, loss, alteration, or disclosure. These measures include TLS encryption in transit, hashed storage of sensitive credentials, encrypted storage of access tokens, and role-based access controls.

6. Sub-processing

6.1. Authorized Sub-processors: The Customer grants FactHound general authorization to engage Sub-processors. The current list of approved Sub-processors is set out in Annex III.

6.2. Notice of Changes: FactHound will notify the Customer via email or in-app notification at least 14 days before adding or replacing any Sub-processor, giving the Customer the opportunity to object.

7. Personal Data Breach Notification

In the event of a confirmed Personal Data Breach affecting the Customer’s data, FactHound will notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware of the breach. FactHound will provide sufficient information to allow the Customer to meet any obligations to report the breach to authorities or individuals.

8. International Data Transfers

To the extent that FactHound processes Personal Data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland in a country not recognized as providing an adequate level of protection, the parties agree that the Standard Contractual Clauses (SCCs) approved by the European Commission will apply and are incorporated into this DPA by reference.

9. Deletion of Personal Data

Upon termination of the Agreement, or upon the Customer’s written request, FactHound will securely delete or de-identify all Customer Personal Data within a reasonable period, unless further storage is required by applicable law.

10. Contact

All legal and privacy-related notices under this DPA should be directed to privacy@facthound.co.

Annex I: Details of Processing

Annex II: Technical & Organizational Measures (Security)

Annex III: Approved Sub-processors

  1. Cloudflare: Hosting, DNS, File Storage (R2), Workers AI (Search embeddings).
  2. Neon: Postgres database.
  3. Logto: Sign-in and authentication.
  4. Resend: Sending transactional and invitation emails.