FoundIn.ai

Legal

Data Processing Agreement (DPA)

The Article 28 GDPR terms governing personal data we process on your behalf. Auto-applies to every paid plan; no signature required.

Last updated: 26 June 2026

1. Parties and scope

This DPA is entered into between Nexari B.V. ("Processor", "we") and the Customer ("Controller", "you"). It applies whenever we process personal data on your behalf as part of the FoundIn.ai service and forms part of our Terms of Service. Capitalised terms not defined here have the meaning in the GDPR.

2. Subject matter, duration, nature, and purpose

  • Subject matter: personal data submitted to or generated by the service.
  • Duration: for the term of your subscription, plus retention periods in the Privacy Policy.
  • Nature and purpose: providing the FoundIn.ai SaaS — AI-visibility monitoring, reporting, and related features.
  • Categories of data subjects: Customer's authorised users, contacts entered into the product, and individuals named in monitored AI outputs.
  • Categories of personal data: identifiers (name, email), authentication data, content submitted by the Customer, usage metadata.

3. Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure personnel with access are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Annex A).
  • Assist the Controller in responding to data-subject requests.
  • Notify the Controller without undue delay of any personal data breach.
  • On termination, delete or return personal data within 30 days, save where retention is required by law.

4. Sub-processors

The Controller provides general authorisation for the engagement of sub-processors. A current list is maintained at /legal/subprocessors. We will notify Customers at least 14 days before adding a new sub-processor, by email and an in-app banner. You may object on reasonable grounds.

5. International transfers

Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) and any supplementary measures required by Schrems II case law.

6. Audit rights

We make available all information necessary to demonstrate compliance and contribute to audits, including inspections conducted by the Controller or an auditor mandated by the Controller, on 30 days' written notice and subject to confidentiality. Where the Controller can rely on our existing third-party reports (e.g. ISO 27001, SOC 2) we may provide those in lieu of an on-site audit.

Annex A — Technical and Organisational Measures (TOMs)

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access control with mandatory 2FA for production systems.
  • Centralised logging, anomaly detection, and 90-day retention of security logs.
  • Vendor security review prior to onboarding any sub-processor.
  • Quarterly access reviews and least-privilege enforcement.
  • Documented incident response plan with 72-hour breach-notification target.
  • Encrypted, geographically-redundant backups with periodic restore tests.

A quick word on cookies

FoundIn.ai uses essential cookies to keep you signed in. With your permission, we'd also use a few more to improve the product and see which features actually help.

Cookie Policy · Privacy