This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement between File Business Inc. d/b/a BosAI ("BosAI" or "Processor") and the customer identified in the applicable agreement ("Customer" or "Controller") (the "Agreement"), and applies to the extent BosAI processes Personal Data on Customer's behalf in providing the Service. Capitalized terms not defined here have the meanings in the Agreement.
1. Definitions
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, EU Regulation 2016/679 ("GDPR"), the U.K. GDPR and Data Protection Act 2018, the Swiss FADP, and U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA"). "Personal Data" means personal data or personal information, as defined by Data Protection Laws, contained in Customer Content. "Processing," "Data Subject," "Controller," "Processor," "Business," "Service Provider," "Sell," and "Share" have the meanings given by Data Protection Laws. "Subprocessor" means a third party engaged by BosAI to process Personal Data on Customer's behalf. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
2. Roles; Scope of Processing
2.1 As between the parties, Customer is the Controller (or a processor acting for its own controllers, in which case Customer warrants it has the necessary authorizations) and BosAI is a Processor. For CCPA purposes, BosAI is a Service Provider.
2.2 BosAI will process Personal Data only (a) on Customer's documented instructions, which comprise the Agreement, this DPA, Customer's configuration of the Service (including autonomy levels, connections, templates, and schedules), and Customer's use of in-product controls; and (b) as required by law, in which case BosAI will notify Customer before processing unless legally prohibited. BosAI will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
2.3 CCPA certification. BosAI will not sell or share Personal Data; will not retain, use, or disclose Personal Data outside the direct business relationship with Customer or for any purpose other than the business purposes specified in the Agreement and this DPA; and certifies that it understands and will comply with these restrictions. BosAI will notify Customer if it can no longer meet its CCPA obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.
2.4 Details of processing are set out in Annex I.
3. Confidentiality
BosAI ensures that persons authorized to process Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and access Personal Data only as needed to perform the Service.
4. Security
BosAI will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing. BosAI may update Annex II from time to time, provided the updates do not materially reduce the overall security of the Service.
5. Subprocessors
5.1 Customer provides general written authorization for BosAI to engage Subprocessors, including those categories listed in Annex III. BosAI will maintain a current Subprocessor list and provide it on request and/or at a published URL.
5.2 BosAI will give Customer at least thirty (30) days' prior notice of the addition or replacement of a Subprocessor (by email or in-product notice). Customer may object on reasonable data-protection grounds within that period; the parties will discuss in good faith, and if no resolution is reached, Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees.
5.3 BosAI will impose data-protection obligations on Subprocessors that are no less protective in substance than this DPA and remains liable for its Subprocessors' performance.
5.4 AI Subprocessors. Without limiting the foregoing, BosAI contractually prohibits its AI model Subprocessors from using Personal Data submitted through the Service to train generalized AI models, absent Customer's explicit opt-in.
6. Assistance to Customer
6.1 Data subject requests. Taking into account the nature of the processing, BosAI will assist Customer by appropriate technical and organizational measures (including in-product export, correction, and deletion tools) in fulfilling Customer's obligations to respond to Data Subject requests. If a Data Subject contacts BosAI directly, BosAI will promptly forward the request to Customer and will not respond substantively except as legally required.
6.2 DPIAs and consultations. BosAI will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent required of Customer by Data Protection Laws and taking into account the information available to BosAI.
7. Personal Data Breach
BosAI will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data, and will provide information reasonably available to BosAI regarding the nature of the incident, the categories and approximate volume of affected data and Data Subjects, likely consequences, and measures taken or proposed. BosAI will take reasonable steps to contain and remediate the breach. BosAI's notification is not an acknowledgment of fault or liability.
8. Audits
Upon written request no more than once per twelve (12) months (or following a Personal Data Breach or a supervisory authority requirement), BosAI will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and security documentation, and will allow for and contribute to audits, including inspections, conducted by Customer or its mandated independent auditor, subject to reasonable advance notice (at least 30 days), confidentiality obligations, normal business hours, no access to other customers' data, and Customer bearing its own costs. The parties agree that review of documentation will be used to satisfy audit rights where reasonably sufficient.
9. International Transfers
9.1 To the extent processing involves a transfer of Personal Data from the EEA to a country without an adequacy decision, the SCCs, Module Two (controller-to-processor), or Module Three where Customer is a processor, are incorporated by reference, with BosAI as data importer and Customer as data exporter; Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 30 days); Clause 11 optional language omitted; Clause 17 governed by the law of Ireland; Clause 18 courts of Ireland; Annexes I and II of the SCCs completed by Annexes I and II of this DPA.
9.2 For transfers from the U.K., the U.K. International Data Transfer Addendum to the SCCs applies, with tables deemed completed by the details in this DPA; for Switzerland, the SCCs apply as adapted for the FADP (references to the GDPR read as the FADP; supervisory authority: FDPIC).
10. Return and Deletion
Upon termination or expiration of the Agreement, BosAI will, at Customer's election made within thirty (30) days, return Customer Content containing Personal Data in a commonly used format and/or delete it, and thereafter delete remaining copies within thirty (30) days, except that (a) residual copies in encrypted backups will be overwritten in the ordinary course within thirty-five (35) additional days, and (b) BosAI may retain Personal Data to the extent required by law, subject to continued protection under this DPA and processing for no other purpose.
11. Liability; Order of Precedence; Term
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where prohibited by Data Protection Laws. In case of conflict, the order of precedence is: the SCCs (for transfers they govern), then this DPA, then the Agreement. This DPA is effective as long as BosAI processes Personal Data on Customer's behalf.
Annex I: Details of Processing
A. Parties. Data exporter: Customer (contact as set out in the account). Data importer: File Business Inc. d/b/a BosAI, [registered address], info@file.business.
B. Subject matter and duration. Provision of the BosAI Service under the Agreement, for the term of the Agreement plus the wind-down period in Section 10.
C. Nature and purpose. Hosting, storage, retrieval, analysis, and generation of text and structured data; execution of Customer-configured business-administration tasks (invoice reminders, email triage and drafting, scheduling, estimates, deadline monitoring); production of the Brief and Receipts; support and security.
D. Categories of Data Subjects. Customer's personnel and Seats; Customer's own customers, prospects, vendors, and other business contacts appearing in Connected Services or Customer Content.
E. Categories of Personal Data. Names, business and personal contact details, email content and metadata, calendar data, invoice and transaction data (amounts, status, payer identity), communications history, and other personal data contained in Customer Content. Sensitive data: not intentionally collected; may be incidentally present in Customer Content (e.g., in email text); protected via the measures in Annex II.
F. Frequency. Continuous, as directed by Customer's configuration.
G. Competent supervisory authority. Determined per Clause 13 SCCs based on the data exporter's establishment.
Annex II: Technical and Organizational Measures
Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256); pseudonymization where feasible; OAuth-scoped, revocable connections to Connected Services (no storage of Connected Service passwords); logical tenant isolation; role-based access controls on a least-privilege, need-to-know basis with mandatory SSO/MFA for personnel; comprehensive action logging (Receipts) and centralized security logging with alerting; vulnerability management including periodic penetration testing [frequency/vendor to be documented]; secure software development lifecycle with code review and dependency scanning; personnel confidentiality agreements and security training; vendor risk assessment for all Subprocessors; documented incident response plan with defined severities and escalation; business continuity and encrypted backups with periodic restoration testing; physical security provided by enterprise cloud infrastructure providers; data minimization defaults (access limited to scopes granted; retention as configured).
Annex III: Authorized Subprocessor Categories
Cloud infrastructure and storage provider [e.g., Amazon Web Services / Google Cloud, confirm]; AI model providers for text generation and analysis [e.g., Anthropic, confirm current list]; payment processor (billing data only) [e.g., Stripe, confirm]; transactional email and notification delivery; customer support tooling; first-party-configured analytics. The current named list is available on request at info@file.business and will be maintained at a published URL.
To execute this DPA as a standalone signed document, or to request the SCCs, contact info@file.business (Attn: Legal).