Data Processing Addendum

    Introduction

    FUTUREPROOF TECH LTD ("Futureproof", "we", "us", "our") provides cloud-based sustainability and ESG software services, including Ella, an AI-powered sustainability platform operated by Futureproof (together, the "Services").

    This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Terms and Conditions, Terms of Service, order form, subscription agreement or other written or electronic agreement between you and Futureproof governing your use of the Services (the "Agreement").

    To the extent Futureproof processes Customer Personal Data (as defined below) on your behalf in connection with the provision of the Services, this DPA applies from the date you agree to the Agreement and remains in force for the duration of such processing.

    You acknowledge that, in relation to Customer Personal Data processed through the Ella platform or other parts of the Services on your behalf, you are the controller and Futureproof is the processor. You further acknowledge that Futureproof may separately process certain personal data as an independent controller, including website, demo request, waitlist, marketing and sales-related data. Information regarding our controller-side processing is set out in our Privacy Policy.

    You confirm that you have all necessary rights, consents, permissions and notices in place to enable the lawful transfer and processing of Customer Personal Data by Futureproof in accordance with the Agreement and this DPA.

    Interpretation

    In this DPA, save where the context requires otherwise, the following words and expressions have the following meaning:

    "Agreement" means the Terms and Conditions, Terms of Service, order form, subscription agreement or other agreement governing your use of the Services;

    "Customer Personal Data" means any personal data contained in Customer Content or otherwise made available by you or on your behalf to Futureproof in connection with the provision of the Services, including the personal data described in Annex A;

    "Customer Content" means any data, files, documents, prompts, messages, records, credentials or other content uploaded to, entered into, submitted to, generated through, or otherwise processed through the Services by you or your authorised users;

    "DPA" or "Data Processing Addendum" means this data processing addendum;

    "Data Protection Laws" means the GDPR, the Data Protection Act 2018, the UK GDPR, the Privacy and Electronic Communications Regulations where applicable, and any other applicable laws relating to the processing of personal data;

    "EEA" means the European Economic Area;

    "GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR as defined in the Data Protection, Privacy and Electronic Communications (Amendment Etc.) (EU Exit) Regulations 2019;

    "ICO" means the UK Information Commissioner's Office;

    "Restricted Transfer" means a transfer of Customer Personal Data to a country or recipient outside the UK or EEA where such transfer would be restricted in the absence of an applicable transfer mechanism under Data Protection Laws;

    "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data processed by Futureproof or its Sub-Processors;

    "Sub-Processor" means any third party engaged by Futureproof to process Customer Personal Data on its behalf in connection with the Services.

    The terms "controller", "processor", "data subject", "personal data", "process", "processing" and "supervisory authority" shall have the meanings given to them in the GDPR.

    1. Data Processing

    1.1. Futureproof will process Customer Personal Data only:

    (a) to provide, secure, support and improve the Services in accordance with the Agreement and this DPA;

    (b) on your documented instructions as set out in the Agreement, this DPA and your use and configuration of the Services; or

    (c) as otherwise required by applicable law, in which case Futureproof shall, to the extent legally permitted, inform you of that requirement before carrying out the processing.

    1.2. The Agreement, together with this DPA, constitutes your complete and final documented instructions to Futureproof in relation to the processing of Customer Personal Data, unless additional written instructions are agreed between the parties.

    1.3. Futureproof shall promptly inform you if, in its opinion, an instruction infringes applicable Data Protection Laws.

    1.4. You are responsible for ensuring that your instructions to Futureproof comply with applicable Data Protection Laws.

    1.5. You shall provide all necessary privacy notices to data subjects and obtain any consents or other lawful bases required for the lawful collection, use and disclosure of Customer Personal Data to Futureproof in connection with the Services.

    2. Sub-Processors

    2.1. You agree that Futureproof may engage Sub-Processors to process Customer Personal Data on its behalf in connection with the Services.

    2.2. Futureproof shall ensure that each Sub-Processor is bound by written terms that impose data protection obligations no less protective than those imposed on Futureproof under this DPA, to the extent applicable to the nature of the services provided by that Sub-Processor.

    2.3. The Sub-Processors approved as of the effective date of this DPA are listed in Annex A.

    2.4. Futureproof may update its list of Sub-Processors from time to time. Where we appoint a new Sub-Processor that will process Customer Personal Data, we will provide notice by updating the Sub-Processor list and, where reasonably appropriate, by written notice.

    2.5. You may object to the appointment of a new Sub-Processor on reasonable data protection grounds by giving written notice within fourteen (14) days of our notice. Your objection must describe your reasonable grounds in sufficient detail.

    2.6. If you object, Futureproof will use reasonable efforts to make available a commercially reasonable change to the Services or recommend a commercially reasonable workaround to avoid the use of the objected-to Sub-Processor. If Futureproof cannot do so within a reasonable period, either party may terminate the affected part of the Services on written notice, without liability for the terminated portion other than fees due for Services already provided.

    2.7. Futureproof remains responsible for the acts and omissions of its Sub-Processors to the extent required by applicable Data Protection Laws.

    3. International Transfers

    3.1. Futureproof shall not make a Restricted Transfer of Customer Personal Data unless it has taken such measures as are required under applicable Data Protection Laws to ensure the transfer is lawful.

    3.2. Such measures may include, where applicable:

    (a) transfer to a country or recipient that is subject to an adequacy decision or adequacy regulation;

    (b) transfer under the European Commission's Standard Contractual Clauses, including the 2021 modular clauses where relevant;

    (c) the UK International Data Transfer Addendum or another transfer mechanism approved by the ICO;

    (d) the EU-US Data Privacy Framework, the UK extension to it, or another recognised adequacy or certification mechanism, where applicable; or

    (e) another valid transfer mechanism permitted under Data Protection Laws.

    3.3. You acknowledge that certain Sub-Processors used in connection with the Services may process Customer Personal Data outside the UK or EEA, including in the United States, as described in Annex A.

    4. Security Measures and Security Incidents

    4.1. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons, Futureproof shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against Security Incidents.

    4.2. Such measures include, where applicable to the Services:

    (a) encryption in transit;

    (b) encryption at rest at the infrastructure level;

    (c) role-based access controls;

    (d) row-level security and company-level data segregation within the application database;

    (e) private storage buckets for customer documents and files;

    (f) authentication and JWT-based session controls;

    (g) secret management for sensitive credentials and API keys;

    (h) audit logging of significant user and system actions; and

    (i) restriction of access to Customer Personal Data to authorised personnel and authorised service providers who are subject to confidentiality obligations.

    4.3. Futureproof will regularly review and may update its security measures from time to time, provided that such updates do not materially reduce the overall security of the Services.

    4.4. If Futureproof becomes aware of a Security Incident affecting Customer Personal Data, Futureproof will:

    (a) notify you without undue delay;

    (b) investigate the Security Incident and take reasonable steps to mitigate its effects and reduce the risk of recurrence; and

    (c) provide you with reasonably available information to help you assess the impact of the Security Incident and meet any obligations you may have under Data Protection Laws.

    4.5. Futureproof's notification of or response to a Security Incident shall not be construed as an admission of fault or liability.

    5. Audits and Information Rights

    5.1. Futureproof shall make available to you information reasonably necessary to demonstrate compliance with this DPA.

    5.2. Futureproof may satisfy its obligations under paragraph 5.1 by providing documentation, security summaries, architecture information, responses to reasonable security questionnaires, copies of relevant policies, or other materials that Futureproof makes generally available to customers.

    5.3. To the extent required by applicable Data Protection Laws, and only where the information provided under paragraphs 5.1 and 5.2 is not sufficient to satisfy your reasonable compliance requirements, Futureproof shall allow for and contribute to a reasonable audit by you or your mandated independent auditor, subject to the following conditions:

    (a) audits shall be conducted no more than once in any twelve (12) month period, unless required by a Security Incident or a supervisory authority;

    (b) audits must be conducted on reasonable prior written notice and during normal business hours;

    (c) audits must be limited in scope to information relevant to Futureproof's compliance with this DPA and must not unreasonably interfere with Futureproof's business operations;

    (d) audits must be conducted subject to appropriate confidentiality obligations and must not compromise the confidentiality, privacy or security of Futureproof's systems, other customers, or third-party confidential information;

    (e) Futureproof may satisfy audit obligations through remote review, written responses, documentary evidence, or virtual meetings instead of onsite access;

    (f) onsite audits shall only be permitted where required by applicable Data Protection Laws or where documentary and remote review options are insufficient and the parties agree the onsite audit is reasonably necessary;

    (g) you shall bear your own costs and reimburse Futureproof for its reasonable external and internal costs incurred in supporting any audit, except where the audit reveals a material breach of this DPA by Futureproof.

    5.4. Nothing in this clause requires Futureproof to disclose information that would compromise the security of the Services, breach confidentiality obligations owed to other customers or third parties, or reveal internal security details beyond what is reasonably necessary.

    6. Data Subject Requests and Government Requests

    6.1. Taking into account the nature of the processing, Futureproof shall provide reasonable assistance to you, insofar as possible, to enable you to respond to requests from data subjects to exercise their rights under applicable Data Protection Laws.

    6.2. Where a data subject makes a request directly to Futureproof relating to Customer Personal Data, Futureproof shall, unless prohibited by law, promptly notify you and shall not respond to the request except on your documented instructions or as required by law.

    6.3. Futureproof shall notify you, unless prohibited by law, if it receives a legally binding request from a governmental, regulatory or law enforcement authority for disclosure of Customer Personal Data.

    6.4. You acknowledge that the Services currently provide certain self-service functionality for access, rectification, download and deletion of specific categories of Customer Personal Data, but do not currently provide universal self-service account deletion or a single full portability export across all data categories.

    7. Assistance

    7.1. Taking into account the nature of the processing and the information available to Futureproof, Futureproof shall provide reasonable assistance to you with:

    (a) data protection impact assessments, where required under applicable Data Protection Laws; and

    (b) consultations with supervisory authorities, where required and where such consultation relates specifically to Futureproof's processing of Customer Personal Data on your behalf.

    7.2. Unless otherwise required by law, such assistance shall be provided on a reasonable endeavours basis and Futureproof may charge reasonable fees for substantial, repetitive or unusually burdensome assistance requests.

    8. Duration and Deletion or Return of Data

    8.1. This DPA shall remain in force for as long as Futureproof processes Customer Personal Data on your behalf.

    8.2. On termination or expiry of the Services, Futureproof shall, subject to paragraph 8.4, delete or return Customer Personal Data in accordance with the Agreement and this DPA.

    8.3. You acknowledge that the Services currently support export or download of certain categories of Customer Content and Customer Personal Data, including specific files, data exports and generated outputs, but do not currently provide a single automated "export all data" function.

    8.4. Unless otherwise agreed in writing, Futureproof may retain Customer Personal Data for a limited period after termination or expiry, typically up to ninety (90) days where reasonably practicable, to allow retrieval, operational offboarding, support, dispute handling, backup cycling and service administration. You acknowledge that this is a target retention window and not an automated deletion workflow currently implemented across all systems.

    8.5. Futureproof and its Sub-Processors may retain Customer Personal Data to the extent required by applicable law, for the establishment, exercise or defence of legal claims, for fraud prevention or security purposes, to honour backup retention cycles, or where temporary retention is technically unavoidable.

    8.6. Where Customer Personal Data has been indexed or stored in third-party systems used to deliver the Services, including vector stores or similar AI retrieval systems, deletion may require separate technical steps and may be completed on a rolling or manual basis rather than instantaneously.

    9. Confidentiality

    9.1. Futureproof shall ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

    9.2. Futureproof shall treat Customer Personal Data as your confidential information and shall not disclose it to any third party except:

    (a) as permitted by the Agreement or this DPA;

    (b) as necessary to provide the Services through authorised Sub-Processors; or

    (c) as required by law.

    10. Liability

    10.1. The liability of each party arising under or in connection with this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement.

    10.2. Nothing in this DPA limits either party's liability where such limitation is prohibited by applicable law.

    ANNEX A

    Details of Processing

    Subject matter of processing:

    Provision of the Services, including Ella, a product operated by Futureproof Tech Ltd.

    Duration of processing:

    For the duration of the customer's subscription to the Services and any limited post-termination retention period in accordance with the Agreement and this DPA.

    Nature and purpose of processing:

    Hosting, storage, organisation, analysis, retrieval, transmission, generation, security, support and other processing necessary to provide the Services, including:

    • user authentication and account management
    • storage and management of company, sustainability and ESG data
    • document upload, storage, extraction and parsing
    • AI-assisted chat, summarisation, analysis and document generation
    • vector search and retrieval across uploaded documents
    • carbon calculation support and emissions-factor lookup
    • questionnaire, framework and compliance workflow support
    • audit logging and system monitoring
    • transactional email delivery
    • limited browser automation for customer-configured B Corp related workflows where enabled

    Categories of personal data:

    Depending on how you use the Services, Customer Personal Data may include:

    • first name and last name
    • email address
    • phone number
    • user role or job title
    • profile image or avatar
    • company membership and permissions data
    • company name, website, industry, employee count, revenue range, reporting currency and reporting year-end
    • uploaded files and documents, which may contain employee data, supplier data, stakeholder data, signatures, contact details or other personal data provided by you
    • chat prompts, user messages and AI-generated responses
    • questionnaire responses, framework metrics, compliance responses and evidence materials
    • supplier, employee, stakeholder and data request contact information provided by you
    • invitation records, including invitee email and permissions
    • encrypted third-party credentials, where you choose to configure them, such as B Corp login credentials stored using secret-management infrastructure
    • audit logs and usage metadata associated with user actions

    For clarity, the application does not explicitly collect or store IP addresses in application code, although certain infrastructure providers may log IP addresses at the infrastructure level outside the application code.

    Categories of data subjects:

    • your employees, workers and authorised users
    • supplier representatives
    • stakeholder contacts
    • individuals named in uploaded files and documents
    • invitation recipients
    • any other individuals whose personal data you choose to upload or process through the Services

    Special categories of personal data:

    The Services are not intended to require special category personal data. To the extent you choose to upload special category personal data or other sensitive data, you are responsible for ensuring you have a lawful basis to do so and that such processing is necessary and proportionate.

    Approved Sub-Processors

    App Sub-Processors that may process Customer Personal Data

    Entity: Supabase, Inc.

    • Processing activity: Database hosting, authentication, storage, edge-function runtime and related application infrastructure
    • Role: Sub-Processor
    • Entity location / processing region: AWS eu-west-2 (London)
    • Used in: Authenticated app

    Entity: OpenAI, L.L.C.

    • Processing activity: AI chat completions, vector store indexing, document retrieval, metric and framework assistance, data chat and related AI processing
    • Role: Sub-Processor
    • Entity location / processing region: United States
    • Used in: Authenticated app

    Entity: Lovable Aps / Lovable AI Gateway

    • Processing activity: AI routing, document generation, summarisation, enrichment, categorisation, parsing, project chat and related AI processing
    • Role: Sub-Processor
    • Entity location / processing region: Lovable infrastructure, with onward routing to Google Gemini and related providers as configured
    • Used in: Authenticated app

    Entity: Google LLC / Google Cloud

    • Processing activity: Gemini-based AI processing and, where configured, Cloud Run infrastructure supporting browser automation or related processing
    • Role: Sub-Processor
    • Entity location / processing region: Region depends on provider configuration, may include processing outside the UK or EEA
    • Used in: Authenticated app

    Entity: Resend, Inc.

    • Processing activity: Transactional email delivery, including invitations, welcome emails, password resets and signature requests
    • Role: Sub-Processor
    • Entity location / processing region: United States
    • Used in: Authenticated app

    Entity: Browserbase, Inc.

    • Processing activity: Browser session infrastructure for customer-enabled B Corp workflow automation
    • Role: Sub-Processor
    • Entity location / processing region: United States
    • Used in: Authenticated app

    Entity: Mistral AI SAS

    • Processing activity: AI processing where enabled as an alternative model provider for data chat or related functions
    • Role: Sub-Processor
    • Entity location / processing region: France / EEA
    • Used in: Authenticated app, if enabled

    Entity: Climatiq Ltd

    • Processing activity: Emissions factor lookup and carbon calculation support
    • Role: Service provider, generally not expected to receive Customer Personal Data except to the extent such data is included by you in activity descriptions
    • Entity location / processing region: UK / EU
    • Used in: Authenticated app

    Controller-side tools not generally acting as Sub-Processors for Customer Personal Data under this DPA

    These tools may be used by Futureproof as an independent controller for marketing, sales or website operations, rather than as Sub-Processors of Customer Personal Data under this DPA:

    Entity: Apollo.io

    • Processing activity: Marketing website visitor identification and analytics on public pages
    • Role: Futureproof controller-side tool, not an app Sub-Processor for Customer Personal Data
    • Entity location / processing region: United States
    • Used in: Public marketing website only