Skip to main content
Legal & Policy center

Data Processing Addendum

Effective September 1, 2026 · Version 2026-09-01

1. Application

This Data Processing Addendum ("DPA") forms part of the agreement between ProInstincts Enterprises, Inc., as operator of Phasoric, and a customer when Phasoric processes personal data on the customer's behalf through hosted services. Terms such as controller, processor, data subject, personal data, and processing have the meanings given by applicable data-protection law. If those terms do not apply, comparable legal roles are intended.

2. Roles, scope, and instructions

The customer is the controller or responsible business and Phasoric is its processor or service provider for customer personal data. The subject matter is delivery of the hosted features selected by the customer; processing lasts for the agreement and applicable deletion period; data and people are those submitted to, connected with, or generated through the selected features. The agreement, product configuration, authorized user actions, support requests, and documented API calls are the customer's instructions.

Phasoric will process customer personal data only on documented instructions, including for transfers, unless law requires otherwise. If legally permitted, we will tell the customer before processing under a legal requirement. We will promptly inform the customer if an instruction appears to violate applicable data-protection law, but the customer remains responsible for the lawfulness, notices, legal bases, accuracy, and scope of its instructions.

3. Confidentiality and personnel

People authorized to process customer personal data are bound by confidentiality and receive access only as needed for their duties. Human access to workspace content is prohibited except for customer-authorized support, security response, legal compliance, or appropriately aggregated and de-identified operations.

4. Security

Phasoric maintains measures appropriate to the service and risk, including encrypted transport, encrypted secret storage, authentication and authorization, tenant scoping, least privilege, logging and audit controls, secure development and dependency practices, backups, incident response, and durable deletion workflows. The Security Policy and confidential security materials describe the current measures. The customer is responsible for its devices, identity configuration, membership, permissions, connections, exports, and lawful use.

5. Service providers and subprocessors

The customer gives general authorization for Phasoric to engage subprocessors needed to provide the service. The public register identifies categories; the exact current schedule is available confidentially when legally or contractually required. Phasoric will impose data-protection obligations materially protective of customer personal data and remains responsible for its subprocessors to the extent required by law and the agreement. Required change notices and reasoned objections will follow the customer's confidential schedule or signed order.

6. Assistance

Taking account of the nature of processing, Phasoric will provide reasonable assistance for verified data-subject requests, impact assessments, regulator consultations, security obligations, and information needed to demonstrate compliance. The customer should first use available export, correction, connection, membership, retention, and deletion controls. Additional assistance may be subject to reasonable fees when permitted and agreed in advance.

7. Security incidents

Phasoric will notify the customer without undue delay after confirming a personal-data breach affecting customer personal data, provide available information needed for the customer's obligations, take reasonable containment and remediation steps, and provide updates as material facts develop. Notification is not an admission of fault. The customer is responsible for notices and decisions required of the controller unless law assigns them to Phasoric.

8. Return and deletion

During the service, the customer may use available exports. At termination or on instruction, Phasoric will delete or return customer personal data unless law requires retention. Deletion follows the durable workflow and backup window described in the Privacy Policy. The customer must separately delete data stored on local devices, in connected provider accounts, or in another party's authorized copy.

9. International transfers

If a restricted international transfer requires a recognized mechanism, the parties will execute or incorporate the applicable standard clauses, addendum, or other lawful mechanism and complete the required annexes. This public DPA does not by itself claim that an incomplete transfer annex has been executed. Confidential processing locations and transfer details are available through the DPA process.

10. Audit and precedence

Phasoric will make available information reasonably necessary to demonstrate compliance, normally through current policies, independent reports if any, security materials, and written responses. If those materials are insufficient, the parties will arrange a proportionate audit subject to confidentiality, security, scope, timing, and cost controls. This DPA controls over conflicting agreement terms for its subject matter. A signed customer DPA or order controls over this public version where it expressly differs.

Requests for a signed DPA, confidential provider schedule, transfer annex, or security review may be sent to privacy@phasoric.com.