Legal
Data Processing Addendum
IQ8 Technology, Inc. · Version Date: July 2, 2026
This Data Processing Addendum (“DPA”) forms part of the IQ8 Subscription Agreement or other written or electronic subscription agreement (the “Agreement”) between IQ8 Technology, Inc. (“IQ8”) and the customer identified in the Agreement (“Customer”) for the provision of the Platform. This DPA reflects the parties’ agreement on the processing of Personal Data. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.
1. Definitions
“Applicable Data Protection Law” means all privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), other U.S. state privacy laws, and, where applicable, the EU General Data Protection Regulation (“GDPR”) and the UK GDPR.
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “processing,” and “personal data breach” have the meanings given in Applicable Data Protection Law. “Business,” “Service Provider,” and “sell” have the meanings given in the CCPA.
“Customer Personal Data” means Personal Data that IQ8 processes on behalf of Customer in connection with providing the Platform.
“Subprocessor” means any third party engaged by IQ8 to process Customer Personal Data in connection with the Platform.
2. Roles and Scope
With respect to Customer Personal Data, Customer is the Controller (or Business) and IQ8 is the Processor (or Service Provider). IQ8 will process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement and this DPA, and as necessary to provide the Platform, unless otherwise required by applicable law.
As a Service Provider under the CCPA, IQ8 will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than performing the Platform, or as otherwise permitted by the CCPA; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with Personal Data from other sources, except as permitted by the CCPA.
IQ8 will provide at least the same level of privacy protection with respect to Customer Personal Data as required of Customer under the CCPA to the extent applicable to IQ8’s role as Service Provider. IQ8 will notify Customer if IQ8 determines it can no longer meet its obligations under Applicable Data Protection Law. Customer may take reasonable and appropriate steps to help ensure that IQ8 uses Customer Personal Data in a manner consistent with Customer’s obligations under Applicable Data Protection Law and to stop and remediate unauthorized use.
The Parties intend this DPA to include all terms required of a processor or service provider under Applicable Data Protection Law, including the comprehensive consumer privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, and other U.S. states. IQ8’s obligations under this DPA apply for the benefit of Customer as Controller (or Business) regardless of the specific terminology a given law uses, and the obligations set out in this Section 2 apply to the equivalent roles and restrictions under each such law.
The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects are described in Schedule 1 (Details of Processing).
3. Customer Obligations
Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it was acquired. Customer represents that it has provided all required notices and obtained all necessary rights, consents, and authorizations for IQ8 to process Customer Personal Data as contemplated by the Agreement and this DPA.
4. Confidentiality
IQ8 will ensure that personnel authorized to process Customer Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory, and have received appropriate training on their responsibilities.
5. Security
IQ8 will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the processing and the risks involved. A description of those measures is set out in Schedule 2 (Security Measures). IQ8 may update its security measures from time to time, provided that such updates do not materially reduce the overall level of protection.
6. Subprocessors
Customer provides general authorization for IQ8 to engage Subprocessors to process Customer Personal Data in connection with the Platform. IQ8 may add or replace Subprocessors at any time in accordance with this Section. IQ8 currently engages the Subprocessors listed at iq8.ai/subprocessors (or a successor URL), which IQ8 will keep current.
IQ8 will impose data protection obligations on each Subprocessor that are substantially the same as, and no less protective than, those set out in this DPA, and IQ8 remains responsible for each Subprocessor’s performance of its obligations.
Notice and objection. IQ8 will provide notice of any intended addition or replacement of a Subprocessor (including by updating the Subprocessor list and, where Customer has subscribed, by an email or in-product notification mechanism) at least thirty (30) days before authorizing the new Subprocessor to process Customer Personal Data. If Customer has a reasonable, good-faith objection based on data protection grounds, Customer may notify IQ8 in writing within that period. The parties will work together in good faith to resolve the objection. If the parties cannot reach a resolution, Customer may, as its sole and exclusive remedy, terminate the affected Platform by providing written notice to IQ8.
Customer agrees that the foregoing notice-and-objection process satisfies any requirement for prior specific authorization of Subprocessors under Applicable Data Protection Law.
As of the effective date of this DPA, IQ8 engages the Subprocessors listed below which may access both Customer Data and metadata. The current and complete list of Subprocessors is maintained at iq8.ai/subprocessors. The table below is a snapshot as of the Order Effective Date and may be updated in accordance with this Section.
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure |
| Anthropic, PBC | AI and machine-learning model processing |
| Atlassian Pty Ltd | Engineering, issue tracking, and collaboration |
| Google LLC | Cloud infrastructure and workspace services |
| Microsoft Corporation | Cloud infrastructure and productivity services |
| OpenAI, L.L.C. | AI and machine-learning model processing |
The current list of Subprocessors, including any additions, is maintained at iq8.ai/subprocessors. In the event of any conflict between the table above and that list, the list maintained at iq8.ai/subprocessors controls.
7. Assistance to Customer
Taking into account the nature of the processing, IQ8 will provide reasonable assistance to Customer, through appropriate technical and organizational measures and insofar as commercially reasonable, to enable Customer to: (a) respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law; and (b) meet its obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
Data Subject Requests.As between the Parties, Customer, as Controller, is solely responsible for receiving, evaluating, verifying the identity of the requester for, and responding to requests from Data Subjects to exercise their rights (each, a “Data Subject Request”) with respect to Customer Personal Data. IQ8 has no obligation to assess the validity of, or to respond substantively to, a Data Subject Request.
Requests received by IQ8.If IQ8 receives a Data Subject Request relating to Customer Personal Data, IQ8 will, where legally permitted, redirect the Data Subject to Customer or notify Customer of the request without undue delay, and will not otherwise respond to the request except to confirm that the data is processed on behalf of, and subject to the instructions of, IQ8’s customer. IQ8 is not required to identify the relevant customer to the Data Subject where doing so is unnecessary or would itself disclose Personal Data.
Self-service tools.Customer acknowledges that the Platform provides functionality that enables Customer to access, correct, export, restrict, and delete Customer Personal Data. Customer will use this functionality to fulfill Data Subject Requests where it is reasonably able to do so. IQ8’s assistance obligation is satisfied where the Platform makes the necessary functionality available to Customer.
Additional assistance.Where a Data Subject Request cannot reasonably be fulfilled through the self-service functionality of the Platform, IQ8 will, upon Customer’s documented and verified instruction, provide reasonable assistance to Customer within a commercially reasonable period, and in any event within thirty (30) days of IQ8’s receipt of that instruction (unless a shorter period is required by Applicable Data Protection Law). IQ8 will act only on instructions received from Customer’s authorized contacts and will not act on a Data Subject’s request directly.
Costs. IQ8 will provide routine assistance with Data Subject Requests at no additional charge. Where assistance is excessive, repetitive, or requires material engineering or manual effort beyond the self-service functionality of the Platform, IQ8 may charge Customer its then-current professional services rates, on prior notice to Customer.
8. Personal Data Breach
IQ8 will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide Customer with information reasonably available to IQ8 to assist Customer in meeting its breach-notification obligations. IQ8’s notification is not an acknowledgment of fault or liability.
9. Audits
IQ8 will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. IQ8 may satisfy this obligation by providing third-party audit reports (such as a SOC 2 report) under confidentiality obligations. Where Applicable Data Protection Law entitles Customer to conduct an audit, the parties will agree in advance on the reasonable scope, timing, and cost of any such audit, which will be conducted no more than once per year (absent a personal data breach or regulatory requirement), during business hours, and subject to confidentiality.
10. International Transfers
IQ8 may transfer and process Customer Personal Data in the United States and other countries. Where Customer Personal Data subject to the GDPR or UK GDPR is transferred to a country that does not provide an adequate level of protection, the parties will rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Agreement or Addendum, which are incorporated into this DPA by reference where applicable.
11. Return or Deletion
Upon termination or expiration of the Agreement, IQ8 will delete Customer Personal Data within the same timeframe, and using the same export-then-delete process, that the Agreement specifies for deletion of Customer Data (or, if the Agreement specifies no such timeframe, within a commercially reasonable period), or, where the Agreement expressly so provides, return it at Customer’s election, in each case unless retention is required by applicable law. Following the applicable retention period, IQ8 will delete remaining copies of Customer Personal Data, except as retained in routine backups that are deleted, or rendered inaccessible and put beyond use, as they are overwritten in the ordinary course.
12. Liability; Term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on the effective date of the Agreement and continues until IQ8 has ceased all processing of Customer Personal Data.
Schedule 1 — Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the IQ8 Platform under the Agreement. |
| Duration | The term of the Agreement, plus any period of return or deletion. |
| Nature and purpose | Hosting, storage, and processing of Customer Personal Data to provide and support the Platform. |
| Categories of Data Subjects | Authorized Users; Customer administrators; Customer employees and contractors; Customer Affiliates’ personnel; Customer clients or customers; counterparties; vendors and suppliers; applicants; witnesses; contract signatories; outside counsel and other professional advisors; internal business stakeholders; regulators; claims participants; and other individuals whose Personal Data is submitted to or generated within the Platform by Customer or its Authorized Users. |
| Types of Personal Data | Names; business email addresses; business contact details; job titles; employer or organization names; user IDs; account status; role and permission information; administrator status; authentication settings; MFA status; invitation records; seat assignments; user preferences; login times; IP addresses; device and browser information; session data; features accessed; Platform actions; prompts or requests submitted; Credit consumption; model/action usage; timestamps; error logs; audit logs; security logs; performance telemetry; support tickets; emails to support; chat transcripts; call notes; screenshots; diagnostic logs; uploaded examples; document contents; workflow records; task assignments; comments; uploaded files; extracted text; metadata; matter/project names; contracts; policies; emails; and AI-generated Output that contains Personal Data. |
| Sensitive or specially regulated data | Customer may not submit sensitive, regulated, or restricted data except as expressly permitted by the Agreement or applicable Order Form. |
Schedule 2 — Security Measures
IQ8 maintains an information security program that includes administrative, technical, and physical safeguards designed to protect Customer Personal Data. The program includes, at a minimum, the following measures, which IQ8 may update provided the overall level of protection is not materially reduced:
Access Controls
- Role-based access control and the principle of least privilege for systems that process Customer Personal Data.
- Unique user credentials, and multi-factor authentication for administrative and remote access.
- Timely revocation of access upon role change or termination.
Encryption
- Encryption of Customer Personal Data in transit over public networks using industry-standard protocols.
- Encryption of Customer Personal Data at rest using industry-standard algorithms.
Operational Security
- Network protections, including firewalls and segmentation, and logging and monitoring of relevant systems.
- Vulnerability management, patching, and periodic security testing.
- Formal change-management and secure software-development practices.
Resilience and Continuity
- Regular backups and documented business-continuity and disaster-recovery procedures.
Governance and Personnel
- Written security policies, security awareness training, and confidentiality obligations for personnel.
- A documented incident-response process and vendor/Subprocessor risk management.
- Independent assessment of the security program (such as a SOC 2 examination), with reports available to Customer under confidentiality.