Data processing agreement.
How Facet, LLC processes personal data on behalf of Customer, incorporating GDPR Art. 28(3), the EU Standard Contractual Clauses, the UK IDTA, and the Swiss FADP addendum.
Parties, scope, and incorporation.
1.1 The parties
This Data Processing Agreement (the "DPA") is entered into between Facet, LLC, a Delaware limited liability company ("Facet", acting as Processor), notice address 1 Market St, Suite 100, San Francisco, CA 94105, and the organization or person that accepts the Terms of Service v2.1 at facet.llc/legal/terms.html ("Customer", acting as Controller). Where Customer is itself a Processor acting for a downstream Controller, Facet acts as Sub-Processor and this DPA is construed accordingly.
1.2 Incorporation by title and version
This DPA supplements the Terms of Service v2.1 and applies to Facet's Processing of Personal Data on behalf of Customer. It is referenced by title and version from Privacy Policy v2.1, Security page v2.0, AUP v2.0, DMCA/Copyright policy v2.0, and Cookie Policy v2.0. In the event of a conflict over data-protection matters, this DPA governs, consistent with Terms of Service v2.1 § 1.5 (Order of precedence).
1.3 Applicability
This DPA applies where Facet Processes Personal Data as Processor for Customer, including Personal Data subject to: (a) the EU General Data Protection Regulation, Regulation (EU) 2016/679 ("GDPR"); (b) the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"); (c) the Swiss Federal Act on Data Protection of 25 September 2020, in force 1 September 2023 ("Swiss FADP"); and (d) equivalent non-European privacy laws including the CCPA/CPRA and the U.S. state comprehensive privacy laws identified in Privacy Policy v2.1 § 14 where those laws impose Processor obligations.
1.4 Execution
By accepting the Terms of Service v2.1, Customer executes this DPA. No separate countersignature is required for the DPA to bind both parties; an electronically-signed DPA on Customer's letterhead may be substituted on request to [email protected] where Customer's procurement procedure requires it.
Definitions.
Capitalized terms used but not defined in this DPA have the meanings given in the Terms of Service v2.1, the Privacy Policy v2.1, or the GDPR, as context requires. The following additional definitions apply:
- “Adequacy Decision” means a decision by the European Commission under GDPR Art. 45, the UK Secretary of State, or the Swiss Federal Council determining that a third country provides an adequate level of protection for Personal Data.
- “Customer Personal Data” means Personal Data that Facet Processes on behalf of Customer under this DPA, as described in Annex I.
- “Aggregated and De-identified Data” means data derived from Customer Personal Data that has been aggregated or de-identified as described in Section 5.6 of the Terms of Service, such that it no longer identifies and cannot reasonably be linked to any Data Subject or Customer. Aggregated and De-identified Data is not Personal Data or Customer Personal Data for purposes of this DPA. Facet Processes Aggregated and De-identified Data as an independent Controller and business for its own purposes, subject to the re-identification safeguards in Section 5.6 of the Terms of Service.
- “Data Subject”, “Personal Data”, “Processing”, “Controller”, “Processor”, “Sub-Processor”, “Special Categories of Personal Data”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in GDPR Art. 4.
- “EU-US Data Privacy Framework” or “DPF” means the framework operated under Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 and its UK Extension and Swiss-US extension.
- “Restricted Transfer” means a transfer of Personal Data from the EEA, the UK, or Switzerland to a country that is not the subject of an Adequacy Decision and that requires a transfer mechanism under GDPR Chapter V, UK GDPR Chapter V, or the Swiss FADP.
- “SCCs” means the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended.
- “UK IDTA” means the UK Information Commissioner's Office International Data Transfer Agreement (version B1.0 or later issued version) and/or the International Data Transfer Addendum to the EU SCCs, as applicable.
- “Swiss Addendum” means the Swiss Federal Data Protection and Information Commissioner's recognized adaptation of the SCCs for transfers subject to Swiss FADP.
- “TIA” means a Transfer Impact Assessment conducted under the methodology in European Data Protection Board Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of Personal Data (as updated).
Processor obligations under GDPR Art. 28(3).
Facet will Process Customer Personal Data only on the documented instructions of Customer, as set out in this DPA, the Terms of Service v2.1, the Privacy Policy v2.1, and any Order Form. Use of the Services, selection of subscription tier, and configuration of the admin dashboard constitute Customer instructions. Additional instructions must be in writing and may be delivered by email to [email protected]. Facet will notify Customer in writing if Facet believes that a specific instruction infringes applicable data-protection law (GDPR Art. 28(3) second paragraph).
3.1 Article 28(3)(a) · Documented instructions
Facet will Process Customer Personal Data only on Customer's documented instructions, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by Union or Member State law to which Facet is subject, in which case Facet will inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
3.2 Article 28(3)(b) · Confidentiality of personnel
Facet ensures that persons authorized to Process Customer Personal Data have committed themselves to confidentiality under written contract or are under an appropriate statutory obligation of confidentiality, and that such commitments survive termination of the engagement.
3.3 Article 28(3)(c) · Article 32 security measures
Facet takes all measures required under GDPR Art. 32 (security of Processing), including the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing.
3.4 Article 28(3)(d) · Sub-Processor conditions
Facet respects the conditions for engaging Sub-Processors set out in Section 6 (prior written authorization, flow-down obligations, Facet's continuing liability).
3.5 Article 28(3)(e) · Data-subject rights assistance
Taking into account the nature of the Processing, Facet assists Customer by appropriate technical and organizational measures, insofar as this is possible, to fulfill Customer's obligation to respond to requests for exercising Data Subject rights under GDPR Chapter III. Operational mechanics are in Section 9.
3.6 Article 28(3)(f) · Arts. 32 to 36 assistance
Facet assists Customer in ensuring compliance with the obligations under GDPR Arts. 32 (security), 33 (Controller breach notification), 34 (data-subject breach notification), 35 (data-protection impact assessment), and 36 (prior consultation with the supervisory authority), taking into account the nature of the Processing and the information available to Facet.
3.7 Article 28(3)(g) · Return or deletion on termination
At the choice of Customer, Facet deletes or returns all Customer Personal Data to Customer after the end of the provision of Services relating to Processing, and deletes existing copies unless Union or Member State law requires storage. Operational mechanics are in Section 11.
3.8 Article 28(3)(h) · Audit rights
Facet makes available to Customer all information necessary to demonstrate compliance with the obligations in Art. 28, and allows for and contributes to audits, including inspections, conducted by Customer or another auditor mandated by Customer. Operational mechanics (frequency, scope, and cost allocation) are in Section 10.
3.9 UK GDPR and Swiss FADP equivalents
Sections 3.1 through 3.8 apply equally to Facet's Processing of Customer Personal Data subject to UK GDPR and Swiss FADP, construed as obligations under the equivalent UK and Swiss provisions (UK GDPR Art. 28(3); Swiss FADP Arts. 9 and 26).
Customer’s Controller responsibilities.
4.1 Lawful basis and notices
Customer represents that Customer has established a lawful basis under GDPR Art. 6 (and, where applicable, Art. 9) for each Processing operation it instructs Facet to perform, has provided all required notices to Data Subjects under GDPR Arts. 13 and 14, and has obtained all required consents.
4.2 Instructions
Customer will issue instructions to Facet only through the Services, the admin dashboard, an executed Order Form, or written notice to [email protected]. Customer will not instruct Facet to Process Customer Personal Data in a manner that violates applicable law.
4.3 Accuracy and data-minimization
Customer is responsible for the accuracy, quality, and legality of Customer Personal Data submitted to the Services and for the means by which Customer acquired Customer Personal Data.
4.4 Data-subject requests directed to Facet
Where a Data Subject addresses a request to Facet directly in respect of Customer Personal Data, Facet will forward the request to Customer without undue delay and, subject to Customer's instructions, will not respond substantively unless legally required to do so.
Security of processing.
5.1 Technical and organizational measures
Facet implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by GDPR Art. 32. The specific measures in force as of the Effective Date are described in Annex II and are summarized in the Security page v2.0 at facet.llc/legal/security.html. Facet may update the measures from time to time, provided that the overall level of protection does not materially decrease.
5.2 Personnel
Personnel with access to Customer Personal Data are subject to background checks proportionate to their role, mandatory training on data protection, and confidentiality obligations that survive termination of employment.
5.3 Third-party assurance
Facet maintains, and refreshes on the cadence described in the Security page v2.0, third-party assurance including SOC 2 Type II (current-year report available under NDA) and is on the ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certification roadmap. Current assurance artifacts are available to Customer under NDA on request to [email protected].
Sub-Processors.
6.1 General written authorization
Customer grants Facet general written authorization, pursuant to GDPR Art. 28(2), to engage the Sub-Processors listed in Annex III and to replace or add Sub-Processors on the terms of this Section 6.
6.2 Thirty-day prior written notice
Facet will provide Customer with at least thirty (30) days prior written notice of any addition or replacement of a Sub-Processor, by (a) updating the canonical Sub-Processor list in Annex III and the mirror of that list in the Privacy Policy v2.1 § 6.1 and the Security page v2.0 § 11, with the new version number and effective date, and (b) emailing the administrative contact on each active Customer account.
6.3 Objection right
Customer may object to the addition or replacement of a Sub-Processor in writing within the notice period on reasonable grounds related to data-protection compliance (for example, the proposed Sub-Processor's data-protection posture, restricted-transfer mechanisms, regulatory standing, or public-sector clients). Facet will make commercially reasonable efforts to address the objection, which may include proposing a comparable alternative Sub-Processor or additional supplementary measures. If the parties cannot resolve the objection within thirty (30) days after Customer's written objection, Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid unused fees covering periods after the effective date of termination, as the sole remedy for Customer's objection.
6.4 Sub-Processor obligations flow-down
Facet imposes on each Sub-Processor, by written contract, data-protection obligations no less protective than those Facet owes Customer under this DPA (Art. 28(4) GDPR), including Art. 28(3) obligations where applicable. Facet remains fully liable to Customer for each Sub-Processor's performance of its data-protection obligations, as required by Art. 28(4).
6.5 Restricted transfers to Sub-Processors
Where a Sub-Processor Processes Customer Personal Data in a country that is the subject of a Restricted Transfer, Facet will execute the SCCs in the applicable Module (typically Module 3, Processor-to-Processor), the UK IDTA, and the Swiss Addendum, or will rely on a Sub-Processor's active DPF certification where the destination is the United States and the certification covers the transferred data. The specific mechanism for each Sub-Processor is recorded in Annex III.
International data transfers.
7.1 Incorporated clauses
To the extent a Processing operation under this DPA involves a Restricted Transfer, the following instruments are incorporated into and form part of this DPA on the Effective Date:
- The EU SCCs (Implementing Decision (EU) 2021/914 of 4 June 2021), executed in the Module applicable to the specific flow:
- Module 2 (Controller-to-Processor), where Customer is Controller and Facet is Processor for Personal Data transferred from the EEA to the United States or another third country without an Adequacy Decision.
- Module 3 (Processor-to-Processor), where Customer is itself a Processor, Facet is Sub-Processor, or where Facet further transfers Personal Data to a Sub-Processor outside the EEA. Module selection per Sub-Processor is recorded in Annex III.
- The UK IDTA (or the UK Addendum to the EU SCCs) for transfers subject to the UK GDPR, in the version in force at the time of transfer.
- The Swiss Addendum for transfers subject to the Swiss FADP.
- The EU-US DPF (and its UK Extension and Swiss-US extension) where the recipient Sub-Processor is self-certified to the DPF at dataprivacyframework.gov; Facet verifies certification status before relying on the DPF for any specific transfer and retains SCCs + IDTA + Swiss Addendum as a fallback without gap.
7.2 Docking clause and optional clauses
Where the SCCs offer optional clauses, the parties' elections are: Option 2 for Clause 7 (docking clause, included); Option 2 for Clause 9(a) (general authorization for Sub-Processors, consistent with Section 6.1); Option 2 for Clause 17 (EU Member State law governing the SCCs, the law of Ireland); Clause 18 (forum and jurisdiction), the courts of Ireland. For the UK IDTA, the parties elect the ICO's mandatory clauses and, where applicable, the UK courts of competent jurisdiction. For the Swiss Addendum, the parties elect the courts of the Canton of Zurich.
7.3 Transfer Impact Assessment
Facet has conducted a TIA under the methodology in EDPB Recommendations 01/2020 for each Restricted Transfer, taking into account: (a) the legal regime at the destination, including U.S. government-access laws (FISA 702, EO 12333), and the Schrems II jurisprudence; (b) the likelihood of a government-access request; (c) the nature, sensitivity, and volume of the data; (d) technical supplementary measures (encryption in transit via TLS 1.3; encryption at rest via AES-256; pseudonymization where feasible; per-tenant isolation; key management); and (e) contractual and procedural supplementary measures (transparency reporting, challenge commitments, customer-notice commitments). TIAs are reviewed annually, and whenever a destination's legal regime materially changes. Customer may request a redacted copy of the TIA applicable to any Restricted Transfer by writing to [email protected].
7.4 Government-access requests
If Facet receives a legally binding request from a public authority to disclose Customer Personal Data, Facet will: (a) review the request for legal validity and challenge overbroad, facially invalid, or legally impermissible requests; (b) narrow the scope of disclosure to what is legally required; (c) where not legally prohibited, give prompt written notice to Customer so Customer may seek a protective order or other remedy; and (d) maintain aggregate statistics about government-access requests and publish them in a periodic transparency report consistent with U.S. legal constraints. These commitments apply to U.S. national-security process (FISA 702, EO 12333) to the maximum extent permitted by U.S. law.
Personal Data Breach notification.
8.1 Notification to Customer
Facet will notify Customer of a confirmed Personal Data Breach affecting Customer Personal Data without undue delay and in any event within forty-eight (48) hours after Facet becomes aware of the Breach, by email to Customer's administrative contact and by notification in the admin dashboard. The notification will be made in writing and treated as confidential.
8.2 Content of notification
The notification will, to the extent known at the time of notification (with updates to follow as further information becomes available), include: (a) the nature of the Breach, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (b) the name and contact details of Facet's security contact ([email protected]) from whom further information can be obtained; (c) the likely consequences of the Breach; and (d) the measures taken or proposed to be taken to address the Breach, including, where appropriate, measures to mitigate its possible adverse effects.
8.3 Assistance with GDPR Arts. 33 and 34
Facet assists Customer, to the extent reasonably required and taking into account the nature of the Processing and the information available to Facet, in complying with Customer's obligations under GDPR Arts. 33 (notification to the competent Supervisory Authority, within 72 hours where feasible) and 34 (communication to Data Subjects, without undue delay where the Breach is likely to result in a high risk to the rights and freedoms of natural persons). Equivalent assistance applies for UK GDPR and Swiss FADP notifications.
8.4 Remediation
Facet will investigate the Breach, take appropriate remedial action, and provide Customer with a written post-incident report within thirty (30) days of the initial notification, or earlier where practicable.
Data-subject request assistance.
9.1 Routing
Where a Data Subject directs a request in respect of Customer Personal Data to Facet, Facet will (a) forward the request to Customer through the admin dashboard's Data-Subject Request queue (or by email where the dashboard is unavailable) within five (5) business days; (b) not respond substantively unless legally required to do so or directed by Customer in writing; and (c) confirm to the Data Subject that the request has been routed to the Controller.
9.2 Technical tooling
Facet provides Customer with technical tools through the admin dashboard to (a) locate Customer Personal Data responsive to an access, portability, or erasure request; (b) export responsive Customer Personal Data in a structured, commonly used, and machine-readable format; (c) correct or restrict Customer Personal Data; and (d) log rights-request activity for audit evidence.
9.3 Timelines
Facet will complete assistance steps within timelines that allow Customer to meet the statutory response window applicable to the Data Subject's request (GDPR Art. 12(3) default one (1) month extendable by two (2) further months; state-law analogues per Privacy Policy v2.1 § 14).
9.4 Fees
Reasonable assistance is provided without additional charge. Where Customer requests bespoke tooling or substantial investigative effort beyond the default response flow, Facet may charge a reasonable fee and will estimate the fee in advance.
Audit rights.
10.1 Routine audits
Customer may audit Facet's compliance with this DPA once per twelve (12)-month period, on at least thirty (30) days prior written notice, at mutually acceptable times during Facet's business hours, and in a manner that does not unreasonably interfere with Facet's business operations. Customer's then-current SOC 2 Type II report (available under NDA from [email protected]), ISO/IEC 27001 certification once obtained, and Facet's written responses to a security questionnaire of Customer's reasonable scope are deemed to satisfy the routine audit right for the period covered.
10.2 Breach-triggered audits
The once-per-year limitation does not apply to an audit reasonably requested (a) following a confirmed Personal Data Breach affecting Customer Personal Data, or (b) at the documented request of a competent Supervisory Authority. Such audits are conducted on a scope and timeline agreed in writing by the parties.
10.3 Confidentiality
Audits and resulting audit reports are Facet's Confidential Information under Terms of Service v2.1 § 5.5 and may be disclosed only in accordance with that section. Third-party auditors must sign an NDA with Facet before gaining access to Facet systems or Confidential Information.
10.4 Cost allocation
Customer bears its own costs of audit and the reasonable costs Facet incurs in providing the assistance, unless the audit uncovers a material non-compliance by Facet, in which case Facet bears its own costs.
Return or deletion on termination.
11.1 Customer’s election
On termination or expiration of the Services (or the affected portion), Customer may elect in writing, within thirty (30) days after termination, to have Facet (a) return Customer Personal Data to Customer in a structured, commonly used, machine-readable format, or (b) delete Customer Personal Data from Facet's production systems. If Customer does not elect within thirty (30) days, Facet will delete.
11.2 Deletion timeline
Facet will complete deletion from production systems within thirty (30) days after the applicable election date, and from backups through the ordinary backup-overwrite cycle not later than ninety (90) days after deletion from production.
11.3 Certification of deletion
On Customer's written request, Facet will provide a certification of deletion signed by an authorized officer, listing the data categories deleted, the deletion method, and the completion date.
11.4 Legal-hold carve-out
Facet may retain Customer Personal Data beyond the default deletion period to the extent required by Union, Member State, or other applicable law, or under legal hold (including for litigation, regulatory investigation, or tax recordkeeping). Facet will describe any retained categories to Customer on request and will continue to protect retained data in accordance with this DPA and the Security page v2.0 until deletion becomes permissible.
Liability allocation.
12.1 Cap subject to carve-outs
Each party's liability arising out of or relating to this DPA, whether in contract, tort (including negligence), strict liability, or otherwise, is subject to the liability cap and exclusions in Terms of Service v2.1 § 6.4 (cap on direct damages) and § 6.5 (exclusion of consequential damages), except that the carve-outs in Terms of Service v2.1 § 6.6 apply equally to DPA-specific obligations. In particular:
- Facet's obligations under this DPA to the extent arising from a data-breach caused by Facet's security failure confirmed by independent forensic investigation are uncapped (Terms of Service v2.1 § 6.6(c)).
- Each party's gross negligence, willful misconduct, or fraud is uncapped (Terms of Service v2.1 § 6.6(a)).
- Confidentiality breaches are uncapped (Terms of Service v2.1 § 6.6(d)).
- Any liability that cannot be limited or excluded under applicable law is uncapped (Terms of Service v2.1 § 6.6(g)).
12.2 SCC liability
Where a Restricted Transfer is governed by the SCCs, liability under the SCCs (Clause 12) applies between the parties to the transfer. Between Customer and Facet, the allocations in Section 12.1 apply notwithstanding the SCC liability regime, except that the SCC provisions take precedence where a conflict with mandatory EU law would otherwise arise.
12.3 Insurance
Facet maintains commercial general liability, technology errors and omissions, and cyber liability insurance in amounts appropriate for an enterprise SaaS at Facet's scale. Certificates of insurance are available on request to [email protected] under NDA.
Term, survival, and conflicts.
13.1 Term
This DPA takes effect on the Effective Date and continues in force for as long as Facet Processes Customer Personal Data. Provisions that by their nature survive termination (including Sections 8 (Breach), 10 (Audit for the audit-records retention period), 11 (Return / deletion), and 12 (Liability)) survive.
13.2 Order of precedence
In the event of a conflict between this DPA and any other document governing the parties' relationship, the order of precedence in Terms of Service v2.1 § 1.5 applies, with this DPA controlling data-protection matters. If the SCCs, UK IDTA, or Swiss Addendum incorporated in Section 7 conflict with another provision of this DPA on a data-protection matter, the incorporated instrument governs.
13.3 Severability
If any provision of this DPA is held invalid or unenforceable, that provision will be enforced to the maximum extent permitted, and the remaining provisions remain in full force.
Annex I · Description of processing.
A. Data exporter (Customer)
Customer is the organization or person that accepted the Terms of Service v2.1. Customer acts as Controller (or, where Customer is itself a Processor, as Processor for a downstream Controller). The data-exporter's contact details are those on Customer's account of record.
B. Data importer (Facet)
Facet, LLC, a Delaware limited liability company, with notice address 1 Market St, Suite 100, San Francisco, CA 94105. Activities relevant to the transfer: operating the Services described in the Terms of Service v2.1 (Terminal, Identity Gateway, Atomic Commerce Primitives, signed-response provenance, Agent Reputation Registry, admin dashboards, SDKs and tooling). Contact: [email protected]; security matters: [email protected].
C. Categories of Data Subjects
- Customer's authorized admin users (account owners, technical operators).
- Agent Operators authenticating to a Customer Terminal (organizations and, where identified, natural-person operators).
- Natural persons identifiable through Agent Identity Data under Privacy Policy v2.1 § 13.
- Visitors to Customer's properties whose interactions are captured at the classifier aggregate level (not individually).
D. Categories of Personal Data
- Identifiers (email, name, OIDC subject).
- Admin-session metadata (IP at sign-in, user-agent, sign-in timestamp).
- Agent Identity Data as defined in Privacy Policy v2.1 § 13.
- Request / response metadata for Terminal calls.
- Commerce settlement metadata (reservation / settlement identifiers, signed-receipt hashes, amounts).
- Support, sales, and billing communications.
E. Special Categories of Personal Data
Not processed by default. Customer will not submit Special Categories of Personal Data through the Services without a prior written supplemental agreement establishing the additional safeguards required by GDPR Art. 9.
F. Frequency of transfer
Continuous, for the duration of the Services.
G. Nature of processing
Hosting, storage, routing, authentication, metering, signing, audit-log generation, settlement-metadata recording, classification, backup, deletion, and return at Customer's instruction.
H. Purpose(s) of processing
Providing the Services to Customer as specified in the Terms of Service v2.1 and any Order Form.
I. Duration of processing
For the duration of the Services; subsequent retention as described in Privacy Policy v2.1 § 8 and Section 11 of this DPA.
J. Competent Supervisory Authority
As a B2B platform without a single EU establishment, Facet does not rely on a lead Supervisory Authority. Complaints may be lodged with the Supervisory Authority of the Member State of the Data Subject's habitual residence, place of work, or place of the alleged infringement; the UK ICO for UK-related complaints; and the Swiss FDPIC for Swiss-related complaints.
Annex II · Technical and organizational measures.
II.1 Pseudonymization and encryption
- TLS 1.3 (or higher when broadly available) in transit; HSTS enforced; modern cipher suites only.
- AES-256 encryption at rest for database, object storage, and backups.
- Ed25519 signing of provenance artifacts with key rotation at least quarterly; prior keys retained for signature verification.
- Pseudonymization of identifiers in telemetry data where feasible.
II.2 Confidentiality, integrity, availability, resilience
- Row-level security with zero anon grants on public schemas on all Supabase projects.
- Per-tenant database isolation; per-supplier credential isolation; least-privilege role design.
- MFA-enforced admin sign-in via OIDC (Microsoft Entra ID or Google Workspace).
- Append-only audit logs for admin sign-ins, configuration changes, key rotations, signature operations, billing events, and policy acknowledgments.
- Automated backups with point-in-time recovery; documented BC/DR RTO and RPO in Security v2.0.
- WAF and DDoS protection at the edge via Cloudflare and Netlify.
- Rate-limiting and anomaly detection at the Terminal and Identity Gateway layers.
II.3 Regular testing, assessing, and evaluating
- SOC 2 Type II annually; ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certification on the roadmap documented in Security v2.0.
- Third-party penetration testing at least annually for the Terminal, admin dashboard, and identity surfaces; remediation to closure.
- Coordinated vulnerability-disclosure program with safe-harbor for good-faith researchers (see Security v2.0).
- Periodic tabletop and live incident-response exercises.
II.4 Personnel measures
- Background checks proportionate to role, subject to applicable law.
- Mandatory data-protection and security training on hire and annually.
- Written confidentiality obligations surviving termination.
- Role-based access aligned to the principle of least privilege.
II.5 Sub-Processor oversight
- Written data-processing agreements with each Sub-Processor imposing obligations no less protective than this DPA.
- Periodic review of Sub-Processor compliance posture (SOC 2, ISO 27001, DPF certification).
- Canonical Sub-Processor list maintained in Annex III, mirrored byte-for-byte in Privacy v2.0 § 6.1 and Security v2.0 § 11.
Annex III · Approved Sub-Processors.
The following Sub-Processors are authorized by Customer under Section 6.1 as of the Effective Date. Facet will provide thirty (30) days prior written notice before adding or replacing a Sub-Processor, and Customer may object as set out in Section 6.3.
| Sub-Processor | Service | Location | SCC Module (EU → Sub-Processor) | UK / Swiss mechanism | DPF status (verify current) |
|---|---|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL, Edge Functions, object storage | USA (us-east-2) | Module 3 (P2P) | UK IDTA; Swiss Addendum | DPF certification verified at dataprivacyframework.gov before reliance; SCC + IDTA + Swiss Addendum fallback without gap |
| Netlify, Inc. | Edge routing, static hosting, host-router | USA (primary); global edge | Module 3 (P2P) | UK IDTA; Swiss Addendum | DPF-certified as of current verification |
| Cloudflare, Inc. | DNS, WAF, DDoS protection, rate-limiting at the edge | USA (primary); global edge | Module 3 (P2P) | UK IDTA; Swiss Addendum | DPF-certified as of current verification |
| Stripe, Inc. | Subscription billing and tax calculation for Customer invoicing; agent-originated card-rail (Visa, Mastercard) settlement | USA | Module 3 (P2P); Module 2 (C2P) where Stripe acts as Controller for its own fraud-prevention purposes | UK IDTA; Swiss Addendum | DPF-certified as of current verification |
| Skyfire Systems, Inc. (KYAPay) | KYAPay issuer services; agent identity attestation | USA | Module 3 (P2P) | UK IDTA; Swiss Addendum | Not presently DPF-certified; SCC + IDTA + Swiss Addendum is primary mechanism |
| Microsoft Corporation (Entra ID) | OIDC identity-provider for admin sign-in (multitenant) | USA (primary); EU regions for EU-tenanted identities | Module 3 (P2P) | UK IDTA; Swiss Addendum | DPF-certified as of current verification |
| Google LLC (Workspace OIDC) | OIDC identity-provider for admin sign-in (Workspace tenants) | USA (primary); regional replicas | Module 3 (P2P) | UK IDTA; Swiss Addendum | DPF-certified as of current verification |
| GitHub, Inc. (Microsoft) | Source-control, CI/CD, deployment pipeline (does not Process end-user Personal Data) | USA (primary); global edge | Module 3 (P2P) where applicable | UK IDTA; Swiss Addendum | DPF-certified as of current verification |
Agent-originated USDC settlement occurs non-custodially on-chain via the x402 protocol and Boson escrow. Funds move directly between the Agent Operator's and Supplier's own addresses; Facet does not hold, custody, or process those funds, and no Sub-Processor is engaged for that transfer.
Changelog
- v2.0 (2026-04-23). Initial v2.0 list published with Terms / Privacy / DPA bundle rewrite. Added per-Sub-Processor SCC Module column and DPF-verification discipline. Added Cloudflare, Microsoft Entra ID, and Google Workspace OIDC as distinct entries.
- v1.0 (2026-04-18). Initial Sub-Processor list published at repository bootstrap.