← Back to Home

Data Processing Addendum

This Data Processing Addendum (the "DPA") is incorporated into the Engagement Agreement between NextAIForge, LLC, a Delaware limited liability company operating the NextAIForge brand ("Provider"), and the customer identified in the applicable order ("Client"). Capitalized terms not defined here have the meanings in the Engagement Agreement.

Provider's registered office in Delaware is 131 Continental Dr, Suite 305, Newark, Delaware 19713, New Castle County. Provider's registered agent at that address is Legalinc Corporate Services Inc.

1. Scope and roles

This DPA applies only to personal data that Provider processes on Client's behalf to provide the Services ("Client Personal Data"). For Client Personal Data, Client is the controller/business and Provider is the processor/service provider, unless the parties expressly document different roles in an Order.

Provider is an independent controller/business for Provider account administration, billing, fraud prevention, security, legal compliance, service improvement using aggregated or de-identified data, and Provider's own business operations.

The Services are intended to measure companies and public business information. Client must not provide sensitive personal data, children's data, consumer reports, health information, financial account data, government identifiers, or other regulated data unless expressly approved in a signed Order.

2. Processing details

Subject matter: AI visibility measurement, reporting, consulting, content and schema support, account administration, billing coordination, and related services.

Duration: the term of the applicable Order plus the deletion, return, backup, legal hold, and retention periods described in this DPA or the Agreement.

Categories of data subjects: Client personnel and business contacts, website visitors who submit forms, authorized users, and any other individuals whose data Client provides or approves for processing.

Categories of personal data: business contact details, account records, communications, public URLs, client materials, approved prompts, usage metadata, support records, billing metadata, and measurement evidence. Payment card data is processed by Stripe and not stored by Provider.

Processing operations: collection, hosting, storage, retrieval, use, analysis, transmission, disclosure to subprocessors, deletion, de-identification, and return where feasible.

3. Client instructions

Provider will process Client Personal Data only on documented Client instructions, including the Agreement, Order, this DPA, and Client's authorized configuration or written requests. Provider will promptly inform Client if, in Provider's reasonable opinion, an instruction violates applicable data protection law, unless prohibited by law.

Client is responsible for the lawfulness, accuracy, transparency, rights, notices, consents, and legal basis for Client Personal Data and Client instructions.

4. Provider obligations

Provider will:

  • ensure personnel authorized to process Client Personal Data are bound by

confidentiality obligations;

  • implement commercially reasonable administrative, technical, and organizational

safeguards appropriate to the nature of the data and Services;

  • restrict access to personnel and subprocessors with a business need;
  • assist Client with data-subject or consumer privacy requests to the extent

required by applicable law and reasonably possible;

  • assist Client with security, breach, assessment, and consultation obligations

to the extent required by applicable law and reasonably possible;

  • delete or return Client Personal Data at termination or on written request,

unless retention is required by law, legitimate records retention, backup integrity, dispute resolution, security, or compliance obligations;

  • make available information reasonably necessary to demonstrate compliance with

this DPA, subject to confidentiality and reasonable limits.

5. Security measures

Provider's security measures include, as applicable:

  • encryption in transit;
  • least-privilege access controls;
  • credential and secret management;
  • audit logging and access review;
  • production access restrictions;
  • backup, integrity, and recovery practices;
  • vendor review appropriate to vendor risk;
  • incident response procedures;
  • deletion, compaction, or de-identification controls where feasible.

Provider may update security measures over time, provided updates do not materially reduce overall protection for Client Personal Data.

6. Security incidents

Provider will notify Client without undue delay after confirming a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data (a "Security Incident"). Where feasible, Provider will target notice within 72 hours after confirmation.

Provider's notice will include available information reasonably needed for Client to meet legal obligations. Provider's notice is not an admission of fault or liability.

7. Subprocessors

Client authorizes Provider to use subprocessors to provide the Services. Provider will impose written obligations on subprocessors that are materially protective of Client Personal Data and appropriate to the services they provide. Provider remains responsible for subprocessors' performance of their data processing obligations.

Current subprocessors:

SubprocessorPurposeTypical location
StripePayments, invoices, and billing recordsUS/EU
VercelHosting, deployment, logs, and availabilityUS/global
CloudflareDNS, domain security, and network protectionUS/global
OpenAIAI measurement queries and response analysis where approvedUS/global
PerplexityAI/search measurement queries where approvedUS/global
Google GeminiAI measurement queries and response analysis where approvedUS/global
AnthropicAI measurement queries and response analysis where approvedUS/global
ResendProgrammatic outbound email, reports, and notificationsUS/global
MigaduMailbox hosting and email routing for nextaiforge.comSwitzerland/EU/global

Provider will give reasonable notice of material subprocessor changes by email, policy update, or another commercially reasonable method. Client may object on reasonable data protection grounds within 10 business days after notice. The parties will work in good faith to resolve objections; if unresolved, Client may terminate the affected Order as its exclusive remedy.

8. U.S. state privacy law terms

Where U.S. state privacy laws apply and Provider acts as a processor, service provider, or contractor, Provider will not:

  • sell or share Client Personal Data;
  • retain, use, or disclose Client Personal Data outside the business purposes

described in the Agreement and Order;

  • combine Client Personal Data with personal data from other sources except as

permitted by applicable law;

  • process Client Personal Data for targeted advertising or profiling in

furtherance of solely automated decisions with legal or similarly significant effects unless expressly instructed and lawfully documented by Client.

Provider will support Client's reasonable and legally required consumer rights requests, deletion requests, opt-out obligations, and assessments to the extent the requested action relates to Client Personal Data processed by Provider.

9. European, UK, and Swiss data protection terms

If GDPR, UK GDPR, Swiss FADP, or similar laws apply, Provider will process Client Personal Data as a processor under Client's documented instructions and will provide the assistance required by Articles 28 and 32-36 of the GDPR to the extent applicable and reasonably possible.

For transfers of Client Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism, such as the EU Standard Contractual Clauses, the UK Addendum, or another lawful mechanism. The parties will complete transfer impact assessments where required.

10. Measurement of natural persons

Client must not ask Provider to measure, score, rank, profile, or persist a named natural person as the measurement subject unless the parties first document in writing:

  • the lawful basis and purpose;
  • whether consent is required and how it was obtained;
  • whether the processing involves sensitive data;
  • the retention period;
  • data-subject rights handling;
  • whether a data protection assessment, legitimate-interest assessment, or other

risk assessment is required;

  • safeguards such as minimization, redaction, pseudonymization, or deletion.

Provider may refuse or suspend processing that Provider reasonably believes creates unlawful, unsafe, discriminatory, reputational, or disproportionate risk.

11. Audits

Client may request information reasonably necessary to verify Provider's compliance with this DPA no more than once per year, unless required by law or after a confirmed Security Incident. Audits must be conducted during normal business hours, with reasonable notice, without disrupting Provider's operations, and subject to confidentiality, security, and trade secret protections. Provider may satisfy audit requests through summaries, questionnaires, policies, certifications, or third-party reports where appropriate.

12. De-identified and aggregated data

Provider may create and use aggregated, anonymized, or de-identified data for analytics, benchmarking, security, and service improvement, provided Provider does not attempt to re-identify the data except to test or validate de-identification or as permitted by law. Provider will use reasonable measures designed to prevent re-identification and will contractually require recipients to do the same where required by law.

13. Return and deletion

Upon termination of the applicable Order or upon Client's written request, Provider will delete or return Client Personal Data within a commercially reasonable period, unless retention is required or permitted for legal, accounting, tax, security, backup, dispute, compliance, or legitimate business records purposes. Backup copies will be deleted according to normal backup rotation unless restored earlier.

14. Liability

Liability arising from this DPA is subject to the limitations, exclusions, and remedies in the Engagement Agreement.