This Data Processing Addendum ("DPA") forms part of the agreement between Rhycon, Corp. ("Rhycon") and the customer that uses the Rhycon Service ("Customer"). It applies when Rhycon processes Customer Personal Data on Customer's behalf. Capitalized terms not defined here have the meanings in the Terms of Service or the applicable order.
1. Definitions and roles
"Applicable Data Protection Law" means privacy or data-protection law that applies to the relevant processing, including the GDPR, UK GDPR, and the California Consumer Privacy Act as amended by the CPRA. "Customer Personal Data" means personal information contained in Customer Content that Rhycon processes for Customer as a processor, service provider, or contractor. "Data Subject", "Controller", "Processor", "Process", and "Personal Data Breach" have the meanings given by applicable law.
Customer is the Controller or business and Rhycon is its Processor or service provider for Customer Personal Data. Each party remains independently responsible for personal information it processes for its own purposes, such as Rhycon's account administration, billing, security, and legal-compliance records.
2. Customer instructions and obligations
Rhycon will process Customer Personal Data only on Customer's documented instructions, including the agreement, Customer's configuration and use of the Service, and other written instructions consistent with the Service. Rhycon will inform Customer if it believes an instruction violates Applicable Data Protection Law, unless prohibited from doing so. If law requires other processing, Rhycon will notify Customer before processing unless that law prohibits notice.
Customer is responsible for the lawfulness, fairness, and accuracy of Customer Personal Data and its instructions; providing required notices; responding to Data Subjects; and establishing a valid legal basis for collection, enrichment, profiling, outreach, CRM use, and connected-account actions. Customer will not instruct Rhycon to process sensitive or special-category data unless the parties have expressly agreed that the Service supports it and Customer has satisfied all additional legal requirements.
For prospecting and outbound communications, Customer will document any consent, legitimate-interests assessment, or other legal basis it relies on; provide source and other transparency information when required; maintain those records for the legally required period; and capture and honor objections, opt-outs, and suppression requests. Rhycon does not independently determine whether a particular person may lawfully be contacted for Customer's use case.
3. Confidentiality and personnel
Rhycon will limit access to Customer Personal Data to personnel and contractors who need it to provide, secure, or support the Service. Rhycon will ensure those persons are subject to confidentiality obligations and receive appropriate privacy and security instructions for their work.
4. Security
Taking into account the state of the art, implementation cost, and the nature, scope, context, and risks of the processing, Rhycon will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Those measures include controls for network transport, authentication, workspace and database access, operational monitoring, incident handling, and service-provider access. Customer is responsible for configuring the Service appropriately, limiting user access, and protecting its own systems and credentials.
5. Subprocessors
Customer gives Rhycon general written authorization to use subprocessors to provide the Service. Current provider categories and examples are identified in Section 8 of the Privacy Policy. Rhycon will impose data-protection obligations on a subprocessor that are appropriate to the services it performs and will remain responsible for the subprocessor's performance of those obligations to the extent required by law.
Rhycon will provide reasonable notice of a new subprocessor that materially affects Customer Personal Data where required. Customer may object on reasonable data-protection grounds by contacting Rhycon promptly after notice. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate the affected Service, and Customer's sole remedy is a pro rata refund of prepaid fees for the terminated period.
6. Data Subject requests
Taking into account the nature of the processing, Rhycon will provide reasonable assistance through Service functionality or other measures so Customer can respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Rhycon receives a request relating to Customer-controlled data, it may direct the requester to Customer and will not respond on Customer's behalf unless instructed or legally required. Customer is responsible for the substance and timeliness of its response. Additional work outside ordinary Service functionality may be subject to reasonable fees where permitted by law.
7. Assistance and incidents
Rhycon will provide information reasonably available to it to assist Customer with required security, notification, data-protection impact assessment, and regulator-consultation obligations, taking into account the nature of processing and information available to Rhycon. Rhycon will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and will provide available information reasonably needed for Customer's legal assessment. Notification is not an admission of fault or liability.
8. Return and deletion
During the term, Customer may use available Service features to access or export Customer Personal Data. At the end of the Service, Rhycon will delete or return Customer Personal Data on request, unless law requires retention. Deletion from backups and distributed systems follows ordinary retention cycles. Rhycon may retain limited billing, security, suppression, dispute, and compliance records where needed for its own lawful purposes.
9. Information and audits
Rhycon will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. No more than once annually, unless a regulator or confirmed incident reasonably requires more, Customer may request relevant security documentation and submit reasonable written questions. If that information is insufficient, Customer may request an audit by an independent qualified auditor, subject to reasonable advance notice, confidentiality, security, scope, and non-disruption requirements. Customer bears its audit costs, and an audit may not expose another customer's data or Rhycon's confidential or security-sensitive information.
10. International transfers
Customer authorizes Rhycon and its subprocessors to process Customer Personal Data in the countries where they operate, subject to Applicable Data Protection Law. If a restricted transfer requires an approved transfer mechanism, the parties will cooperate in good faith to implement the applicable standard contractual clauses, UK addendum, or another legally recognized safeguard. The relevant module and party roles will follow the roles described in this DPA.
11. California personal information
For Customer Personal Data subject to the CCPA, Rhycon acts as Customer's service provider or contractor. Rhycon will not sell or share that information; retain, use, or disclose it outside the direct business relationship with Customer or for a commercial purpose other than the specific purposes in the agreement; or combine it with personal information received from another source except as permitted by the CCPA. Rhycon will notify Customer if it can no longer meet these obligations. Customer may take reasonable and appropriate steps to help ensure compliant use and, after notice, to stop and remediate unauthorized use.
12. Processing details
Research, fit ranking, segmentation, and reply classification may constitute profiling under applicable law. The Service is not designed to make decisions producing legal or similarly significant effects about a person, and Customer must not use it for employment, credit, housing, insurance, healthcare, or other high-impact eligibility decisions.
- Subject and purpose: providing, securing, supporting, and maintaining the customer-configured Service.
- Duration: the agreement term plus the limited retention and deletion periods described above.
- Nature of processing: collection, recording, organization, enrichment, structuring, storage, retrieval, consultation, generation, classification, transmission, synchronization, restriction, suppression, deletion, and other operations initiated through the Service.
- Data Subjects: Customer users, employees and contractors; prospects, leads, customers, professional contacts, connected-account participants, meeting attendees, and message recipients.
- Data types: identifiers and professional contact details; employer, role, profile, and company information; account and connected-service identifiers; campaign, CRM, communication, reply, scheduling, consent, suppression, usage, and support data; customer-provided documents and images; and inferences generated from those data.
- Sensitive data: not intentionally required for ordinary use and prohibited unless expressly agreed and lawfully provided.
13. Conflict, liability, and contact
If this DPA conflicts with the agreement on the processing of Customer Personal Data, this DPA controls. All other agreement terms, including liability limits and governing law, apply to this DPA. Questions and notices may be sent to sales@rhycon.ai or:
Rhycon, Corp.1111B Governors Ave #87247
Dover, DE 19904, United States