Legal

Data Processing Addendum

Last updated July 11, 2026Effective when incorporated into an applicable customer agreement
On this page Scope & roles Processing details Customer instructions Confidentiality Security measures Subprocessors Data subject rights Breach notification International transfers Deletion & return Audits Contact

This Data Processing Addendum ("DPA") governs Fibric Inc.'s ("Fibric," "we") processing of personal data on a customer's ("Customer," "you") behalf only when a written customer agreement expressly incorporates it. It applies to BearScope or a managed deployment identified in that agreement. Posting this DPA does not by itself create a processor relationship or make the generalized reference kernel, public documentation, CLI, API, or SDK part of the contracted Service. Capitalized terms not defined here have the meaning given in the applicable agreement.

Scope & roles

This DPA applies to the processing activities and Service scope identified in the applicable customer agreement. For that Customer Data, the Customer is the controller (or a processor acting for its own customers) and Fibric is the processor (or subprocessor), to the extent those roles apply under applicable law. For personal data about website visitors, authorized users, and prospects that Fibric handles for its own purposes, Fibric generally acts as an independent controller under our Privacy Policy, and this DPA does not apply.

Processing details

The required particulars of processing are as follows:

ElementDetail
Subject matterProvision of BearScope or the specific managed deployment identified in the applicable customer agreement.
DurationFor the term and any contractually specified deletion, return, backup-cycle, or transition period in the applicable customer agreement.
NatureCollection, storage, structuring, retrieval, transmission, and other operations reasonably necessary to provide, secure, and support the contracted Service. Supported paths may include governed action-record logging or connector-specific recovery processes where the agreement identifies them; those features do not guarantee reversal of downstream actions.
PurposeTo deliver the contracted Service in accordance with the Customer's documented instructions and the applicable customer agreement.
Categories of dataThe categories identified in the applicable agreement, which may include identifiers and contact details, account and configuration data, operational records from connected systems, and usage or telemetry data. Customer must not route data categories that the agreement excludes.
Categories of data subjectsThe categories identified in the applicable agreement, which may include authorized users, end customers, employees, and contacts whose data appears in supported connected systems.

Customer instructions

Fibric processes personal data on the Customer's documented instructions as set out in the applicable customer agreement, this incorporated DPA, and supported configuration available in the contracted Service. We will inform the Customer if, in our opinion, an instruction infringes applicable data-protection law, unless the law prohibits that notice, and we will not be required to follow an unlawful or out-of-scope instruction. The Customer is responsible for the lawfulness of the data it provides and the instructions it gives.

Confidentiality

Fibric ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and are granted access on a least-privilege, need-to-know basis. These obligations survive the end of their engagement.

Security measures

Fibric implements technical and organizational measures designed to protect personal data, taking into account the contracted processing scope and associated risks. For supported BearScope production paths, current measures include encryption in transit and at rest, role-based or least-privilege access controls, authentication, logging and monitoring, and tenant-scoped controls. Current BearScope production customer-data tables use reseller and tenant identifiers and row-level access controls where implemented. These measures do not represent that every reference-kernel component is deployed, that every event or row uses identical controls, or that security incidents or cross-tenant exposure are impossible. Measures for a managed deployment, including any additional network controls, action records, duplicate suppression, or connector-specific compensating recovery, are those stated in the applicable customer agreement or security schedule.

Subprocessors

The Customer authorizes Fibric to engage subprocessors for the contracted Service. Fibric will impose data-protection obligations appropriate to the processing and as required by applicable law, and remains responsible for each subprocessor to the extent required by this DPA and applicable law. The Subprocessors page is a public category summary; the named schedule, change notices, and objection rights that apply are governed by the customer agreement.

Data subject rights assistance

Taking into account the nature of the processing, Fibric provides reasonable assistance, through appropriate technical and organizational measures and the controls available in the Service, to help the Customer respond to requests from data subjects exercising their rights of access, correction, deletion, restriction, portability, or objection. If a request reaches Fibric directly, we will, unless legally prohibited, refer it to the Customer.

Personal data breach notification

Fibric notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and provides information reasonably available to help the Customer meet its own notification obligations. We take reasonable steps to contain and remediate the breach. Our notification is not an acknowledgment of fault or liability.

International transfers

Where a restricted transfer requires a transfer mechanism under applicable law, the parties will use the mechanism identified in the applicable customer agreement or transfer addendum. If Standard Contractual Clauses or a UK Addendum are required, the parties will execute or validly incorporate the applicable modules and complete the required annex information. This public page alone is not a completed set of Standard Contractual Clauses. We make reasonably available information about transfers that is relevant to the contracted Service.

Deletion & return on termination

On termination or expiry of the contracted Service, Fibric will delete or return Customer personal data as required by the applicable customer agreement, this DPA, and applicable law. Timing, export availability, backup-cycle deletion, and retention of supported action records are contract-specific. Fibric may retain data where required by law or where it remains in protected backups pending ordinary deletion cycles, provided it remains subject to this DPA and is not used for another purpose.

Audits

Fibric will make available information reasonably necessary to demonstrate compliance with this incorporated DPA and, where required by applicable law, allow for and contribute to audits by the Customer or an independent auditor it mandates. Audit procedure, cost, notice, confidentiality, frequency, and scope are governed by the applicable customer agreement and reasonable security requirements. Where appropriate, an audit may be satisfied through Fibric's then-current documentation or reports if they reasonably address the Customer's questions.

Contact

Data-protection questions or requests under this DPA? Contact Fibric's privacy team at privacy@fibric.io, or use the notice contact identified in your customer agreement.