Data Processing Addendum (DPA)

Effective Date: August 4, 2026 (Ver. 1.0) · Applicable Services: Xint (Web · Code), aprism

This Data Processing Addendum ("DPA") is entered into by and between Theori Korea and Theori, Inc. (collectively, "Processor," "Theori," "we," "us," or "our") and the customer using our services ("Controller" or "Customer").

This DPA applies automatically when a Customer agrees to our Terms of Service. This DPA applies alongside our Privacy Policy and GDPR Policy.

1. Definitions

1. Definitions
Term Definition
Customer Data Any Personal Data that the Customer uploads, transmits, or submits to the Services
Processing Any operation performed on Customer Data, including collection, recording, storage, analysis, transmission, and deletion
Sub-processor A third party engaged by Theori to Process Customer Data on Theori's behalf
Data Protection Laws The General Data Protection Regulation (EU) 2016/679 ("GDPR"), UK GDPR, the Personal Information Protection Act ("PIPA," 개인정보보호법), and any other applicable data protection legislation
Personal Data Any information relating to an identified or identifiable natural person, as defined under the applicable Data Protection Laws
Data Subject The identified or identifiable natural person to whom Personal Data relates
Services The services listed in Section 2.2
Security Incident Any unauthorized access to, or disclosure, alteration, destruction, or loss of, Customer Data

2. Scope and Roles

2.1. Roles

2.1. Roles
Party Role Description
Customer Controller Determines the purposes and means of Processing Customer Data
Theori Processor Processes Customer Data on the Customer's documented instructions

2.2. Applicable Services

This DPA applies to the following Services:

2.2. Applicable Services
Service URL Data Processed
Xint Web https://app.xint.io Scan target URLs, vulnerability scan results, web application metadata
Xint Code https://code.xint.io/login Source code, binaries, static analysis results, commit metadata
aprism https://app.aprism.io LLM request/response traffic, prompt logs, policy violation detection records

3. Purpose and Scope of Processing

3.1. Purpose of Processing

We Process Customer Data solely for the following purposes:

3.1. Purpose of Processing
Service Processing Purpose
Xint Web Web application security vulnerability scanning and delivery of scan results
Xint Code Static security analysis of source code and generation of vulnerability reports
aprism LLM traffic monitoring, prompt injection detection, and policy violation filtering

3.2. Processing Restrictions

We will not:

If we determine that a Customer's instruction would violate Data Protection Laws, we will suspend execution of that instruction and immediately notify the Customer.

Access requests from public authorities. Where a court, law enforcement body, or other public authority requests access to Customer Data, we follow the procedure set out in Clauses 14 and 15 of the EU Standard Contractual Clauses in Part 1 of Annex 2. Specifically, we will (i) notify the Customer of the request without undue delay unless legally prohibited from doing so, (ii) challenge the request where we consider it unlawful, (iii) disclose only the minimum information required, and (iv) keep records of such requests and make them available to the Customer on request. Where notification is prohibited, we will use reasonable efforts to obtain a waiver of that prohibition and will notify the Customer as soon as we are permitted to do so.

4. Customer Obligations

The Customer warrants that:

5. Confidentiality

6. Security Measures

6.1. Technical and Organizational Measures

We maintain the following technical and organizational measures to protect Customer Data:

For a complete list of security controls and real-time compliance status, visit our Trust Center.

6.2. Certifications

We maintain the following security certifications:

6.2. Certifications
Certification Scope Status
ISO/IEC 27001:2022 Information Security Management System Active
ISO/IEC 27017:2015 Cloud Service Information Security Active
SOC 2 Type II Xint and aprism Services Examination in progress (SOC 2 results in an attestation report, not a certification) — Request Engagement Letter

Certification copies and the SOC 2 report are available for download via the Trust Center or upon request under NDA.

7. Sub-processors

7.1. Current Sub-processor List

We engage Sub-processors to Process Customer Data. The current Sub-processor list is available on our Trust Center.

7.2. Sub-processor Change Notification

Urgent replacement. Where a Sub-processor must be replaced immediately to maintain the security or continuity of the Services (for example, a security incident at the Sub-processor, or the suspension, discontinuation, or termination of its service), the advance notice period above does not apply. In that case we will notify the Customer of the replacement and the reason for it without undue delay after the change, and the Customer's right to object and to terminate as set out above is unaffected. An urgently engaged Sub-processor is subject to the same obligations under Section 7.3.

8. Data Retention and Deletion

8.1. Retention Periods

8.1. Retention Periods
Data Type Retention Period Notes
Scan target data (source code, URLs) Duration of the Services Retained for re-analysis after scan completion
Scan results and reports Duration of the Services Accessible via the Customer dashboard
Access logs and audit logs Per Customer contract terms Stored in immutable (WORM) storage

8.2. Post-Termination Processing

9. Security Incident Notification

9.1. Notification Procedure

Upon becoming aware of a Security Incident, we will notify the Customer (as Controller) according to the following procedure. "Security Incident" covers not only the loss, theft, or leakage of Customer Data but also its forgery, alteration, or damage, and includes cases where we identify the possibility of such an incident before it is confirmed.

9.1. Notification Procedure
Phase Deadline Content
① Initial Notification Within 48 hours of awareness Incident summary, estimated scope of impact, immediate remediation steps
①-1 Possible-Incident Notification Within 48 hours of identifying the possibility The basis for concluding an incident may have occurred, the potentially affected scope, and the steps the Customer can take
② Detailed Report Within a reasonable period Affected data categories, number of Data Subjects affected, root cause analysis, additional remediation plan
③ Final Report Within 30 business days of incident closure Root cause analysis, recurrence prevention measures, final impact assessment

Legal Benchmarks:

  • Processor → Controller notification (this DPA): GDPR Art. 33(2) requires notification "without undue delay," and PIPA §26(8) applies Section 34 (breach notification and reporting) to processors. This DPA gives that effect by setting a 48-hour deadline from becoming aware of the incident, so that the Customer can meet its own statutory deadlines (72 hours).
  • Controller → Data Subject notification: PIPA Enforcement Decree Section 39 — within 72 hours
  • Controller → Supervisory Authority (PIPC) report: PIPA Enforcement Decree Section 40 — within 72 hours (applies when 1,000+ individuals, sensitive data, or external intrusion is involved)
  • GDPR Art. 33(1): Controller → Supervisory Authority within 72 hours
  • Possible-breach notification (PIPA Article 34(2), as amended by Act No. 21445, effective September 11, 2026): applied to processors through PIPA Article 26(8). We apply phase ①-1 ahead of that date so the Customer can meet its statutory deadline.

9.2. Customer Obligations

10. Data Subject Rights

11. Data Protection Impact Assessment Support

12. International Data Transfers and Applicable Law

12.1. Applicable Laws

This DPA operates against the obligations that the following laws impose on processors. Which laws apply depends on the location of Customer Data and the residence of Data Subjects:

12.1. Applicable Laws
Law Jurisdiction Applicability
PIPA (개인정보보호법) Republic of Korea Data Subjects residing in Korea — home-base law
GDPR (EU 2016/679) EU/EEA Data Subjects residing in the EEA
UK GDPR United Kingdom Data Subjects residing in the UK (ICO jurisdiction)
CCPA/CPRA (Cal. Civ. Code §1798.100 et seq.) United States (California) Consumers residing in California
PDPA (Personal Data Protection Act 2012) Singapore Data Subjects residing in Singapore
APPI (個人情報保護法) Japan Data Subjects residing in Japan
  • We do not sell Customer Data. Under the CCPA, we act as a "Service Provider" and Process data solely for the Customer's business purposes.
  • If Data Protection Laws of jurisdictions not listed above apply, we will conduct additional reviews upon Customer request.

12.2. International Data Transfer Safeguards

12.2. International Data Transfer Safeguards
Transfer Route Safeguard
EEA → Republic of Korea EU adequacy decision (Commission Implementing Decision (EU) 2022/254)
UK → Republic of Korea UK adequacy regulations (Data Protection (Adequacy) (Republic of Korea) Regulations 2022; UK GDPR Art. 45A)
EEA/UK → Japan EU adequacy decision (Commission Implementing Decision (EU) 2019/419)
EEA/UK → United States Standard Contractual Clauses (SCCs, EU Commission Implementing Decision (EU) 2021/914) apply. We may additionally rely on any other transfer mechanism valid under Chapter V of the GDPR at the relevant time
Republic of Korea → United States PIPA §28-8(1)3(a) — processing entrustment or storage necessary for performance of a contract, disclosed in the privacy policy
Japan → Republic of Korea / United States Contractual safeguards under APPI Art. 28 (this DPA and Annex 2)
Singapore → Republic of Korea / United States PDPA Section 26 Transfer Limitation Obligation — contractual safeguards

Theori's engagement with the Global CBPR Forum is a matter of international interoperability only and is not a lawful basis for cross-border transfers under this DPA. Transfers rely on the grounds set out in the table above.

12.3. Data Locations

12.3. Data Locations
Service Primary Data Location Region Notes
Xint Web AWS Seoul ap-northeast-2 Web scan results and Customer Data
Xint Code AWS Virginia us-east-1 Source code analysis
aprism AWS Seoul ap-northeast-2 LLM traffic monitoring

The locations above are where Customer Data is stored. When Xint Web, Xint Code, or aprism runs an AI analysis, the input is sent to the providers below for processing and is deleted immediately after processing under Zero Data Retention (ZDR) terms — it is not stored there. These are therefore transient processing locations, not data residency locations.

Where AI inference takes place

Where AI inference takes place
AI provider Processing location Retention
Anthropic PBC (Claude API) United States ZDR — deleted immediately after processing; not used for model training
OpenAI, Inc. (GPT API) United States ZDR — deleted immediately after processing; not used for model training
Google LLC (Gemini API) United States ZDR — deleted immediately after processing; not used for model training
Amazon Web Services, Inc. (Bedrock) United States (us-east-1) ZDR — deleted immediately after processing; not used for model training
Amazon Web Services Korea LLC (Bedrock) Republic of Korea (ap-northeast-2) ZDR — deleted immediately after processing; not used for model training

Which provider is used may vary by service and feature, always within the list above. See Annex III for their status as Sub-processors and the applicable contractual terms.

13. Audit Rights

13.1. Report-Based Audits (From First Provision of the SOC 2 Type II Report)

Following our SOC 2 Type II report, we will provide the following certification documents as the primary means of audit:

13.1. Report-Based Audits (From First Provision of the SOC 2 Type II Report)
Certification Availability
SOC 2 Type II Report Available upon request via the Trust Center (NDA required)
ISO/IEC 27001:2022 Certificate Available for download on the Trust Center
ISO/IEC 27017:2015 Certificate Available for download on the Trust Center

The Customer agrees that the above certification documents satisfy its audit obligations. However, the Customer may request an additional audit under Section 13.2 for specific matters that the certification documents do not address.

13.2. Direct Audits

13.3. Compliance Information

We will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and GDPR Art. 28, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The frequency, notice period, and manner of such audits are governed by Sections 13.1 and 13.2. These limits do not apply to audits ordered by a supervisory authority or otherwise required by Data Protection Laws.

14. Limitation of Liability and Indemnification

14.1. General Limitation

14.2. Carve-outs

The limitation of liability in Section 14.1 does not apply to:

14.3. Mutual Indemnification

14.4. Regulatory Fine Allocation

In the event a supervisory authority imposes a fine or penalty related to the Processing of Customer Data under this DPA, this Section 14.4 prevails over Section 14.3.

14.5. Breach Notification Costs

If a Security Incident (Section 9) requires notification to Data Subjects or supervisory authorities:

15. Term and Termination

15.1. Order of Precedence

If this DPA conflicts with other contractual documents, the following order of precedence applies:

  1. EU Standard Contractual Clauses (SCCs) or other statutory transfer mechanisms
  2. This DPA
  3. Terms of Service
  4. Privacy Policy

Where provisions within this DPA conflict, the interpretation that does not fall below the minimum standard required by Data Protection Laws prevails; to that extent, Section 13.3 (compliance information and audit cooperation) prevails over Section 13.1, and Section 14.4 (allocation of regulatory fines) prevails over Section 14.3.

15.2. Language

This DPA is executed in Korean and English. As between the Customer and Theori, the version in the language in which this DPA was presented to and accepted by the Customer prevails. Accordingly, the English version prevails for Customers contracting with Theori, Inc., and the Korean version prevails for Customers contracting with Theori Korea in Korean; in each case the prevailing version is construed consistently with the governing law in Section 16. Where the prevailing version cannot be determined, the interpretation more favorable to the Customer applies.

This Section does not apply to the EU Standard Contractual Clauses in Part 1 of Annex 2, for which each official EU language version published under Commission Implementing Decision (EU) 2021/914 is equally authentic, and does not affect Clause 5 (Conflict) thereof. The English version of the UK Addendum in Part 2 of Annex 2 is authoritative.

16. Governing Law and Dispute Resolution

The governing law and jurisdiction for this DPA are determined by the Theori entity with which the Customer has contracted:

16. Governing Law and Dispute Resolution
Contracting Entity Governing Law Jurisdiction
Theori Korea Laws of the Republic of Korea Seoul Central District Court
Theori, Inc. Laws of the State of Delaware, USA Federal or state courts located in Delaware
  • For EU/EEA Customers, the authority of the competent GDPR supervisory authority is not affected regardless of the contracting entity.
  • Customers in other jurisdictions are subject to the governing law specified in the Terms of Service.

17. Contact Information

For inquiries related to this DPA:

17. Contact Information
Item Details
DPO Kenny Kwansoon Park (박관순)
Email privacy@theori.io
Phone +82-70-8864-1337
Address (KR) 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea
Address (US) Theori, Inc., PO Box 40033, Austin, TX 78704, USA

Annex 1: Processing Details

(i) Categories of Data Subjects

(i) Categories of Data Subjects
Service Categories of Data Subjects
Xint Web End users of the Customer's web applications (whose data may appear in metadata collected during scans)
Xint Code Customer's developers (where included in commit metadata); Data Subjects whose Personal Data is hardcoded in source code
aprism End users of the Customer's LLM-powered services (where Personal Data is included in prompts or responses)

(ii) Categories of Personal Data Processed

(ii) Categories of Personal Data Processed
Service Categories of Personal Data
Xint Web URLs, domain information, HTTP request/response headers, cookie names, web application metadata
Xint Code Personal Data embedded in source code (if hardcoded), Git commit author information (name, email), binary metadata
aprism Personal Data contained in LLM prompts/responses (where entered by users), policy violation detection records

(iii) Sensitive Data and Safeguards

(iii) Sensitive Data and Safeguards
Service Sensitive Data Processing Safeguards
Xint Web Not intentionally Processed (the Customer is responsible for sensitive data that may be present in the scanned web application) RBAC, encryption in transit and at rest, audit logging
Xint Code Not intentionally Processed (the Customer is responsible for Personal Data hardcoded in source code) RBAC, encryption in transit and at rest, audit logging
aprism Not intentionally Processed (the Customer is responsible for Personal Data included in prompts) RBAC, encryption in transit and at rest, audit logging

(iv) Frequency of Processing

(iv) Frequency of Processing
Service Frequency
Xint Web On-demand (each time the Customer initiates a scan)
Xint Code On-demand (upon code upload and analysis execution)
aprism Continuous real-time processing (LLM traffic monitoring)

(v) Nature and Purpose of Processing

Nature of Processing: Automated processing operations necessary for service delivery, including collection, recording, storage, analysis, transmission, and deletion.

(vi) Retention Period

(vi) Retention Period
Data Type Retention Period
Scan target data Duration of the Services
Scan results and reports Duration of the Services
Post-termination Deleted using irreversible methods within 30 days

This Annex 1 forms an integral part of DPA v1.0 and takes effect on the same date as the main body.

Annex 2: International Data Transfer Safeguards

Annex 2 to the Data Processing Addendum (DPA) v1.0

Applicable Services: Xint (Web · Code), aprism (same as the main body)

Incorporation by Reference: The parties to this Annex incorporate by reference the full text of the Standard Contractual Clauses ("SCCs") set out in the EU Commission Implementing Decision (EU) 2021/914. The official text of the SCCs is available at EUR-Lex. Annexes I, II, and III of this Annex serve as the annexes to the SCCs.

Part 1: EU Standard Contractual Clauses (SCCs)

This Part 1 constitutes the Annexes to the Standard Contractual Clauses ("SCCs") pursuant to EU Commission Implementing Decision (EU) 2021/914.

The SCCs apply under Module 2 (Controller-to-Processor) by default. Module 3 (Processor-to-Processor) applies where the Customer, acting as a Processor on behalf of its own Controller, transfers Personal Data to Theori.

Transfer Relationships

Transfer Relationships
Item Module 2 (C2P) Module 3 (P2P)
Data Exporter Customer (Controller) Customer (Processor, acting on behalf of its Controller)
Data Importer Theori (Processor) Theori (Sub-processor)
When Applicable Customer is the Controller of the Personal Data Customer is a Processor transferring data on behalf of a third-party Controller

Optional Clauses

Optional Clauses
Clause Applicability Description
Clause 7 — Docking Clause Applicable Third parties may accede to the SCCs after execution
Clause 9(a) — Option 2 (General Written Authorisation) Applicable General written authorisation for Sub-processors adopted. Advance notice period: 10 days; the manner of notice is set out in DPA Section 7.2
Clause 11(a) — Optional Redress Mechanism Not applicable No independent dispute resolution body designated
Clause 17 — Governing Law Option 1 applicable EU Member State law (see Annex I.C below)
Clause 18(b) — Forum for Disputes See Annex I.C below

Annex I — Parties and Transfer Details

Annex I.A — List of Parties

Data Exporter
Data Exporter
Item Details
Name Customer (the entity or natural person that has entered into the DPA)
Address As specified in the Services agreement
Contact Person As specified in the Services agreement
Role Module 2: Controller / Module 3: Processor
Signature and Date Date of Customer's acceptance of the DPA
Data Importer
Data Importer
Item Details
Name The Theori entity identified in the Services agreement (Theori Korea or Theori, Inc.); where not specified, Theori Korea
Address (KR) 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea / (US) Theori, Inc., PO Box 40033, Austin, TX 78704, USA
Contact Person Kenny Kwansoon Park (박관순), DPO, privacy@theori.io
Role Module 2: Processor / Module 3: Sub-processor
Signature and Date DPA Effective Date
Data Protection Activities Processing of Customer Data — security vulnerability scanning, source code analysis, and LLM traffic monitoring services

Annex I.B — Description of Transfer

The details of the transfer (including categories of data subjects, categories of personal data, sensitive data, frequency, nature and purpose of processing, and retention periods) are identical to the details set forth in Annex 1 (Processing Details) of this DPA and are incorporated herein by reference.

Annex I.C — Competent Supervisory Authority

Annex I.C — Competent Supervisory Authority
Item Details
Module 2 The supervisory authority of the EU/EEA Member State in which the Data Exporter (Customer) is established
Module 3 The supervisory authority of the EU/EEA Member State in which the Data Exporter's (Customer's) Controller is established
Governing Law (Clause 17) The law of the EU/EEA Member State in which the Data Exporter is established. If not established in the EU/EEA, Irish law applies
Forum for Disputes (Clause 18) The courts of the EU/EEA Member State whose law governs

Annex II — Technical and Organisational Measures

The technical and organisational measures implemented by the Data Importer are described in DPA Section 6 (Security Measures) and Section 6.2 (Certifications). For a complete list of security controls and real-time compliance status, visit the Trust Center.

Annex III — List of Sub-processors

1. General Written Authorisation

The Data Exporter (Customer) grants the Data Importer (Theori) General Written Authorisation to engage Sub-processors in accordance with SCCs Clause 9(a), Option 2.

2. Current Sub-processor List

The current Sub-processor list is maintained on the Trust Center and is updated in real time.

3. Sub-processor Change Procedure

Per DPA Section 7.2:

  1. We publish the addition or change on the Trust Center at least 10 days before processing begins; Customers who have subscribed to change notifications also receive it by email
  2. The Customer may submit a written objection to privacy@theori.io within 10 days of the notice. Where an objection is raised, processing through that Sub-processor is held until the objection is resolved
  3. If the Customer does not object within the objection period, approval is deemed granted
  4. If the objection is not resolved, the Customer may terminate the affected portion of the Services without penalty, with prepaid fees refunded pro rata
  5. The advance notice period does not apply to an urgent replacement needed to maintain security or continuity; in that case we notify without undue delay after the change

Part 2: UK Addendum to the EU SCCs

This Part 2 is drafted in accordance with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (ICO) (Version B1.0, in force March 21, 2022). It takes effect when the Customer accepts this DPA, and only to the extent a Chapter V transfer under the UK GDPR actually occurs.

Table 1: Parties

Table 1: Parties
Item Details
Start Date Effective Date of this DPA
Exporter Customer (the entity or natural person that has entered into the DPA)
Importer The Theori entity identified in the Services agreement (Theori Korea or Theori, Inc.). Where the Services agreement does not specify, the Data Importer is Theori Korea.
Key Contact (Exporter) As specified in the Services agreement
Key Contact (Importer) Kenny Kwansoon Park (박관순), DPO, privacy@theori.io

Table 2: Selected SCCs, Modules, and Clauses

Table 2: Selected SCCs, Modules, and Clauses
Item Details
Addendum EU SCCs The EU SCCs attached in Part 1 of this Annex
Applicable Module Module 2 (C2P) by default / Module 3 (P2P) where applicable
Selected Clauses As specified in Part 1

Table 3: Appendix Information

Table 3: Appendix Information
UK Addendum Appendix Corresponding EU SCCs Annex
Appendix 1: List of Parties Annex I.A
Appendix 2: Description of Transfer Annex I.B
Appendix 3: Technical and Organisational Measures Annex II
Appendix 4: List of Sub-processors Annex III

Table 4: Ending this Addendum

If the ICO issues a revised Approved Addendum, either party may terminate this Addendum. The Importer will provide reasonable notice and propose alternative safeguards upon termination.

UK Addendum — Additional Terms

  1. Competent Supervisory Authority: UK Information Commissioner's Office (ICO)
  2. Governing Law: The laws of England and Wales
  3. Forum for Disputes: The courts of England and Wales
  4. In the event of any conflict between the EU SCCs and this UK Addendum, this UK Addendum prevails for UK-related transfers

Part 3: Swiss Addendum (Federal Act on Data Protection)

Where the Swiss Federal Act on Data Protection ("FADP") applies, the EU SCCs in Part 1 apply subject to the following modifications:

Part 3: Swiss Addendum (Federal Act on Data Protection)
EU SCCs Clause Swiss Addendum Modification
References to GDPR Interpreted as references to the Swiss FADP
References to "EU," "Union," "Member State" Interpreted as references to "Switzerland"
Clause 13(a) / Annex I.C — Competent Supervisory Authority The Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Clause 17 — Governing Law Swiss law
Clause 18(b) — Forum for Disputes Swiss courts
Scope of Data Subjects Includes both natural persons and legal entities (within the scope of the FADP)

Note: The Republic of Korea is not currently listed on Switzerland's adequacy list. Accordingly, the SCCs (including this Swiss Addendum) apply to transfers from Switzerland to Korea.

Part 4: Summary of Transfer Safeguards by Route

Part 4: Summary of Transfer Safeguards by Route
Transfer Route Applicable Safeguard Notes
EEA → Republic of Korea EU adequacy decision (EU) 2022/254 The adequacy decision suffices; no additional safeguards are required
EEA → United States SCCs (Module 2) under this Annex Theori, Inc. is not currently DPF-certified. This entry will be updated upon certification
UK → Republic of Korea UK adequacy regulations (UK GDPR Art. 45A) The adequacy regulations suffice. The UK Addendum applies only to transfers to countries without adequacy regulations
UK → United States UK Addendum under this Annex Not DPF-certified — UK Addendum applies
Switzerland → Republic of Korea SCCs + Swiss Addendum under this Annex Not on Switzerland's adequacy list
Switzerland → United States SCCs + Swiss Addendum under this Annex Not DPF-certified — SCCs apply

Data Locations

See DPA Section 12.3 for data location details.


This Annex 2 forms an integral part of DPA v1.0 and takes effect on the same date as the main body.

Annex 3: US State Privacy Laws Addendum

Annex 3 to the Data Processing Addendum (DPA)

1. Purpose and Scope

1.1. Purpose

This Addendum ("US Addendum") supplements DPA Section 12 and sets forth additional obligations and conditions governing the Processing of Personal Information subject to US state privacy laws.

1.2. Applicable Laws

This US Addendum applies to Personal Information subject to US state privacy laws, including the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA") and other applicable state data privacy legislation. This US Addendum also applies, to the extent reasonably practicable, to any US state privacy laws enacted or effective after the date of this DPA.

For a comprehensive list of enacted US state privacy laws, refer to the IAPP US State Privacy Legislation Tracker.

1.3. Applicable Services

This US Addendum applies to the Services listed in DPA Section 2.2.

2. Definitions and Mapping

2. Definitions and Mapping
US State Privacy Law Term Corresponding DPA Term Definition
Business Controller / Customer An entity that determines the purposes and means of Processing consumers' Personal Information
Service Provider Processor / Theori An entity that Processes Personal Information on behalf of a Business for business purposes
Consumer Data Subject A natural person residing in the applicable state
Personal Information Personal Data Information that identifies, relates to, or could reasonably be linked to a particular Consumer
Sale Providing Personal Information to a third party for monetary consideration
Share Providing Personal Information to a third party for cross-context behavioral advertising purposes

Our Role: Under all applicable US state privacy laws, we act exclusively as a Service Provider or Processor on behalf of the Customer. We do not assume the role of an independent Controller or Business.

3. Service Provider Obligations

3.1. No Sale or Sharing

We do not Sell or Share Personal Information received from the Customer. (Cal. Civ. Code §1798.140(ad), Section 1798.140(ah))

3.2. No Data Combination

We do not combine Personal Information received from the Customer with Personal Information from other sources, except as necessary to (a) perform the business purposes specified in the DPA and Terms of Service, (b) follow the Customer's documented instructions, or (c) comply with applicable law. (Cal. Civ. Code §1798.140(ag)(1)(A)(iv))

3.3. No Processing Beyond Instructions

We Process Personal Information only in accordance with the Customer's documented instructions. (Cal. Civ. Code §1798.140(ag)(1)(A)(i))

3.4. Compliance Certification

Upon the Customer's reasonable request, we will certify that we understand and will comply with the obligations set forth in this US Addendum. (Cal. Civ. Code §1798.100(d)(1))

3.5. Inability-to-Comply Notification

If we can no longer meet our obligations under this US Addendum, we will promptly notify the Customer. (Cal. Civ. Code §1798.100(d)(3))

When the Customer forwards a Consumer's opt-out request to us, we will cease Processing that Consumer's Personal Information within a reasonable period.

3.7. Global Privacy Control (GPC) Signal

We technically recognize GPC signals and treat them as equivalent to opt-out requests. (Cal. Civ. Code §1798.135(e), 11 CCR §7025)

3.8. Audit Cooperation

The scope, schedule, and cost allocation for audits are governed by DPA Section 13 (Audit Rights).

3.9. Sub-processor Management

We require all Sub-processors to enter into written agreements that include obligations equivalent to those set forth in this US Addendum.

4. Consumer Rights Support

4.1. Right to Know / Right to Access

Upon the Customer's request, we will provide the Customer with the categories of Personal Information held, the Processing purposes, and the specific data items pertaining to a given Consumer within 15 business days.

4.2. Right to Delete

After receiving the Customer's deletion instruction, we will delete the relevant Personal Information using irreversible methods within 30 days and instruct all Sub-processors to do the same.

4.3. Right to Correct

After receiving the Customer's correction instruction, we will correct the relevant Personal Information within a reasonable period, to the extent technically feasible.

4.4. Response Deadlines

We will support the Customer in meeting the applicable response deadline under each state law (typically 45 days, with one 45-day extension upon notice to the Consumer).

5. Sensitive Personal Information

We do not intentionally collect or Process Sensitive Personal Information as defined in Cal. Civ. Code §1798.140(ae). The Customer is responsible for ensuring that data uploaded to the Services does not contain Sensitive Personal Information.

6. De-identified and Aggregate Data

If we generate de-identified data, we will not attempt to re-identify it and will maintain safeguards to preserve its de-identified status, in accordance with CCPA §1798.140(m).

7. Non-discrimination

We will not discriminate against any Consumer for exercising rights under applicable US state privacy laws. (CCPA §1798.125)

8. Conflict of Laws — Order of Precedence

If this US Addendum conflicts with the DPA, this US Addendum prevails with respect to the Processing of Personal Information subject to US state privacy laws. Where multiple US state privacy laws apply simultaneously, we will follow the law that provides the highest level of Consumer protection.


This Annex 3 forms an integral part of DPA v1.0 and takes effect on the same date as the main body.

Change Log

Change Log
Version Effective Date Changes
v1.0 August 4, 2026 Initial publication (applying to the main text and Annex 1, 2, 3)

Supplementary Provisions

This DPA v1.0 and its Annexes take effect on the date shown at the top of this document.

All previous privacy policies and addendums can be found on our consolidated Previous Versions page: