Data Processing Addendum
DATA PROCESSING ADDENDUM
Last Updated: July 31, 2026
This DATA PROCESSING ADDENDUM (this “DPA”) is incorporated into and forms part of the terms and conditions of the online terms (found at fal.ai/terms) between Company and Client (the “Agreement”). This DPA amends and forms part of the Agreement. This DPA applies where Company Processes Client Personal Data as a Processor on behalf of Client, the Controller, in connection with providing the Services. This DPA will terminate automatically upon termination of the Agreement or as earlier terminated pursuant to the terms of this DPA. If there is any conflict between the Agreement and this DPA, the terms of this DPA will prevail as it relates to the conflict.
1. DATA PROCESSING AND PROTECTION
1.1. Limitations on Use. Company will Process Client Personal Data only: (a) pursuant to Client’s documented instructions as specified under Section 1.2 (Instructions), including with regard to transfers of Client Personal Data to a third country; and (b) as otherwise required by applicable laws, provided that Company will inform Client (unless prohibited by law) of the applicable legal requirement before such Processing.
1.2. Instructions. Client instructs Company to Process Client Personal Data as necessary to provide the Services and as otherwise authorized or permitted under this DPA and the Agreement, including as specified in Attachment 2 (Scope of Processing). This DPA, the Agreement, and any instructions provided by Client through configuration tools made available by Company are Client’s documented instructions regarding Company’s Processing of Client Personal Data. Additional instructions provided by Client (if any) require prior written agreement by Client and Company. Client will not instruct Company to Process Client Personal Data in violation of any Data Protection Law. Company may suspend Processing based upon any Client instructions that Company reasonably suspects violate Data Protection Law, provided Company will promptly inform Client if Company believes an instruction infringes Data Protection Law.
1.3. Compliance. Each party will comply with its obligations under Data Protection Law.
1.4. Confidentiality. Company will ensure that persons authorized by Company to Process any Client Personal Data are subject to appropriate confidentiality obligations.
1.5. Security. Company will implement and maintain appropriate technical and organizational measures designed to protect Client Personal Data against Security Incidents and provide the level of protection required by Data Protection Law in accordance with Attachment 3 (Data Security Exhibit). Company may amend the technical and organizational measures, provided the new measures do not reduce the level of security provided by Attachment 3 (Data Security Exhibit).
1.6. Disposal. At the choice of Client, Company will (or will enable Client via the Services to) delete (and will delete existing copies of) all Client Personal Data after termination of the Agreement (unless Data Protection Law requires the storage of such Client Personal Data by Company, in which case Company will only further retain and Process such Client Personal Data for the limited duration and purposes required by such Data Protection Law). The certification of deletion contemplated by Clause 8.5 of the SCCs shall be provided on Clients’ written request.
1.7. CCPA. With respect to any Processing of Client Personal Data subject to the CCPA, the following additional obligations apply:
Company will act as a “service provider” and will Process Client Personal Data only for the limited and specified business purposes set forth in this DPA and the Agreement. Without limiting the foregoing, Company will not: (a) retain, use, or disclose the Client Personal Data (i) outside of the direct business relationship between the parties or (ii) for any purpose other than for the specific purpose of performing the Services; (b) sell or share (as defined by the CCPA) the Client Personal Data; or (c) combine Client Personal Data with Personal Data Company receives from individuals or other sources, except as permitted by the CCPA.
1.7.1. Company shall promptly notify Client if it determines that it cannot meet its obligations under the CCPA. Upon receiving written notice from Client that Company has Processed Client Personal Data without authorization, Company will take reasonable and appropriate steps to stop and remediate such Processing.
1.7.2. Deidentified Data. Company may Process Deidentified Data to improve the Services. Company will (a) take reasonable measures to ensure the Deidentified Data cannot be associated with an individual and (b) publicly commit to maintain and use Deidentified Data in deidentified form and not attempt to reidentify Deidentified Data except as permitted by Data Protection Law.
1.8. U.S. Bulk Data Export Rules. Client is responsible for ensuring that its use of the Services comply with applicable law, including the Department of Justice Data Security Program (“DSP”) rules codified at 28 C.F.R. Part 202. If Client processes “government-related data” or “U.S. sensitive personal data” (as these terms are defined in the DSP), Client is responsible for determining whether its use of the Services (e.g., the Client’s selection of the underlying model) is consistent with the DSP.
2. DATA PROCESSING ASSISTANCE
2.1. Data Subject Rights Assistance. Client shall be responsible for responding to requests from individuals to exercise rights under Data Protection Law relating to Client Personal Data (each a “Data Subject Request”). Client will inform Company of any Data Subject Request to which Company must comply and provide the information necessary for Company to comply with the request. Company will, to the extent permitted by Data Protection Law, notify Client if Company receives a Data Subject Request. To the extent Client, in its use of the Services, does not have the ability to address the Data Subject Request, Company will, on Client’s request, provide commercially reasonable assistance to Client in responding to such Data Subject Request, to the extent the response to such Data Subject Request is required under Data Protection Law.
2.2. Security Assistance. Taking into account the nature of Processing and the information available to Company, Company will provide commercially reasonable efforts to assist Client in Client’s efforts to comply with Client’s obligations to secure Client Personal Data by providing the information and assistance described in Section 3 (Audits).
2.3. Security Incident Notice and Assistance. Company will notify Client without undue delay after becoming aware of a Security Incident. Company will further take commercially reasonable steps to mitigate the effects and minimize any impact from the Security Incident and assist Client in complying with any related notification obligations under Data Protection Law.
2.4. Data Protection Impact Assessment (“DPIA”) and Prior Consultation Assistance. Taking into account the nature of Processing and the information available to Company, Company will provide commercially reasonable assistance to Client in ensuring compliance with the obligations related to DPIAs and consulting with regulatory authorities.
2.5. Government Access Requests. If Company receives a legally binding request from a public authority for access to Client Personal Data, Company will, to the extent permitted by applicable law: (a) promptly notify Client of the request and provide reasonable detail about the requesting authority, the Personal Data requested, and the legal basis for the request (so as to provide Client the opportunity to comply with its notice and consent obligations with respect to affected Data Subjects or oppose the disclosure and obtain a protective order or seek other relief); and (b) where applicable, also comply with the notice obligations set forth in Clause 15.1 of the EU SCCs.
3. AUDITS
3.1. Company Audits. Company may procure audits by third parties to assess Company’s adherence to the following standards or requirements: (a) SOC 2 Type II; (b) ISO 27001; and/or (c) certifications or other documentation evidencing compliance with alternative standards that are substantially equivalent to the foregoing (collectively, “Audits”). Subject to the confidentiality obligations set forth in the Agreement, Company will provide Client with summaries of Company’s then-current Audit reports (“Reports”) on Client’s request.
3.2. Client Audits. Client agrees to exercise its audit rights by first requesting the Reports as described in Section 3.1 (Company Audits). Client will only request additional information to the extent the Reports provided by Company are not reasonably sufficient to enable Client to evaluate Company’s compliance with this DPA and/or Data Protection Law. Except in the event of a Security Incident or regulatory investigation, Client will provide no less than 30 days’ advance notice of its request for an on-site audit and will cooperate in good faith with Company to schedule any such audit on a mutually agreeable date and time. Any such on-site audit must occur during Company’s normal business hours and be conducted by Client or a nationally recognized independent auditor that has agreed to confidentiality provisions reasonably acceptable to Company. Client is responsible for ensuring that the audit will comply with Company’s applicable on-site policies and procedures and will not unreasonably interfere with Company’s business activities. Client will provide a written summary of any audit findings to Company, and the results of the audit will be the confidential information of Company.
4. SUBPROCESSORS
4.1. Appointment of Subprocessors. Client authorizes Company to use subcontractors to Process Client Personal Data in connection with providing the Services (each, a “Subprocessor”). Client specifically consents to Company’s appointment of the Subprocessors identified on Attachment 4 (the “Subprocessor List”).
4.2. Objection Right for New Subprocessors.
4.2.1. Company will notify Client of its intent to update the Subprocessor List at least 15 days prior to engaging a new Subprocessor. Client may object to Company’s use of a new Subprocessor within 10 days of receiving such notice by sending an e-mail to support@fal.ai clearly indicating its desire to object to any such change.
4.2.2. If Client objects to the change in Subprocessors, Company and Client will cooperate in good faith to resolve Client’s objection. If the parties are unable to resolve Client’s objection within 10 days, then either party may terminate the Agreement only with respect to those Services that Company indicates cannot be provided without the objected-to Subprocessor.
4.3. Liability. Company will impose data protection obligations upon any Subprocessor that are no less protective of Client Personal Data than those included in this DPA. Company will be liable to Client for any breach of such obligations by its Subprocessors as it would for its own acts and omissions.
5. DATA TRANSFERS
5.1. Overview. The parties will conduct any transfers of European Economic Area, the United Kingdom, and Swiss residents’ Client Personal Data to a country not subject to an adequacy decision (a “Data Transfer”) pursuant to the SCCs, which are incorporated and deemed executed by this reference. If Company notifies Client that Data Transfers can be conducted in compliance with Data Protection Law pursuant to an alternative transfer mechanism such as the Data Privacy Framework, the parties will rely on the alternative mechanism to legitimize Data Transfers instead of the provisions that follow.
5.2. SCCs. The parties agree to comply with the general clauses and with Module 2 (Controller to Processor) of the SCCs with Client as the “data exporter” and Company as the “data importer.”
5.3. Transfers Subject to Swiss Data Protection Law. If any Client Personal Data subject to the Swiss Federal Act on Data Protection of 19 June 1992, as amended or revised, (the “FADP”) is subject to a Data Transfer, the parties will conduct such transfer pursuant to the SCCs with the following modifications: the competent supervisory authority in Annex I.C under Clause 13 shall be the Federal Data Protection and Information Commissioner; references to a “Member State” and “EU Member State” will not be read to prevent individuals in Switzerland from suing for their rights in Switzerland; and references to “GDPR” in the SCCs will be understood as references to the FADP.
5.4. Transfers Subject to the UK GDPR. Any Client Personal Data that is subject to the UK GDPR and a Data Transfer will be subject to the UK IDTA, which is incorporated and deemed executed by this reference.
6. LIMITATION OF LIABILITY
Each party’s and all of its affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitation of liability in the Agreement. Nothing in this Section 6 is intended to restrict the rights of individuals under Data Protection Law.
7. MISCELLANEOUS
To the extent there is any conflict between the terms of this DPA, on the one hand, and the applicable SCCs or the UK IDTA, on the other hand, the SCCs or the UK IDTA, as appropriate, will control. Except as specifically amended and modified by this DPA, the terms and provisions of the Agreement remain unchanged and in full force and effect. Except as expressly stated in the SCCs and the UK IDTA, the governing law and forum selection provisions of the Agreement will apply to any disputes arising out of this DPA. No supplement, modification, or amendment of this DPA will be binding unless executed in writing by each party to this DPA.
Attachment 1
DEFINITIONS
For purposes of this DPA, the following terms will have the meaning ascribed below. Capitalized terms not defined herein shall have the meaning ascribed to them in the Agreement:
“Controller” means “controller” and “business” (and analogous variations of such terms) under Data Protection Law.
“Client Personal Data” means Personal Data that Company Processes on behalf of Client in connection with providing the Services as described in Attachment 2.
“Data Protection Law” means the GDPR, the UK GDPR, the FADP, the California Consumer Privacy Act (“CCPA”), and any other state, federal, or international data protection or privacy laws that apply to Company’s Processing of Client Personal Data.
“Deidentified Data” means information that cannot reasonably be linked to or associated with Client or any Data Subject.
“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
“Process” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, extending further to such operation or operations under Data Protection Law.
“Processor” means “processor” and “service provider” (and analogous variations of such terms) under Data Protection Law.
“SCCs” means Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on SCCs for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (Text with EEA relevance), available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX:32021D0914, as may be replaced or superseded by the European Commission. The parties make the following choices for implementing the SCCs:
· In Clause 7, the optional docking clause will apply.
· The audits contemplated by Clause 8.9 shall be conducted according to the audit provisions of this DPA.
· In Clause 9, Option 2 will apply and the time period for notice of Subprocessor changes will be as set forth in this DPA.
· In Clause 11 the optional language will not apply to the SCCs or the UK IDTA.
· In Clause 17, the SCCs shall be governed by the laws of Ireland.
· In Clause 18(b), the parties agree to resolve disputes arising from the SCCs in the courts of Ireland.
· The information needed to complete Annex I of the SCCs is included in Attachment 2 to this DPA.
· The information needed to complete Annex II of the SCCs is included in Attachment 3 to this DPA.
· The information needed to complete Annex III of the SCCs is included in Attachment 4 to this DPA.
“Security Incident” means “personal data breach” and “security incident” (and analogous variations of such terms) under Data Protection Law.
“UK GDPR” means the GDPR as incorporated into the United Kingdom law by the Data Protection Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments, etc.) (EU Exit) Regulations 2019 (each as amended, superseded, or replaced).
“UK IDTA” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf. Neither party can terminate the UK IDTA pursuant to Table 4 and Section 19 thereof without the written consent of the other.
Attachment 2
SCOPE OF PROCESSING
Data exporter: Client
Data importer: Company
Subject-Matter and Duration of Processing
Company Processes Client Personal Data if and when provided by Client in the course of providing the Services in accordance with the Agreement and until the Agreement terminates or expires.
Nature and Purpose of Processing
Processing of Client Personal Data in connection with and for the purpose of Company providing the Services to Client pursuant to the Agreement. Specifically, the Client Personal Data will, if and to the extent Client provides it, be subject to storage and analysis, among other Processing activities.
Types of Client Personal Data
Client may submit Client Personal Data to the Services, the extent of which is determined and controlled by Client in its sole discretion. This may include, but is not limited to, the following categories of data:
· Direct identifying information (e.g., name, email address, physical address)
· Indirect identifying information (e.g., date of birth)
· Device identification data and traffic data (e.g., IP addresses, MAC addresses, web logs)
· Any other Personal Data supplied by users (e.g., images or videos uploaded by users)
Categories of Data Subjects
The data subjects will include Client’s employees and end-users.
Special Categories of Data (as applicable)
The Services are not designed for special categories of Personal Data. Company does not anticipate that Client will submit special categories to the Services. To the extent that such data is submitted to the Services, it is determined and controlled by Client in its sole discretion.
Frequency of Transfers
Company will import Client Personal Data on a continuous basis.
Period of Data Retention
Company will retain the Client Personal Data until the termination of the Agreement, unless otherwise agreed to by the parties.
Attachment 3
DATA SECURITY EXHIBIT
1. Program. Company will implement and maintain a written information security program containing administrative, technical, and organizational safeguards appropriate to the risks posed that comply with this Attachment 2 and that: (a) are designed to protect against any Security Incident; and (b) meet or exceed prevailing industry standards and requirements under Data Protection Law.
2. Access Controls. Company will: (a) abide by the “principle of least privilege,” pursuant to which Company will permit access to Client Personal Data by its personnel solely on a need-to-know basis; and (b) promptly terminate its personnel’s access to Client Personal Data when such access is no longer required for performance under the Agreement.
3. Account Management. Company will effectively manage the creation, use, and deletion of all account credentials used to access the Company systems, including by implementing: (a) a segregated account with unique credentials for each User; and (b) strict management of administrative accounts.
4. Vulnerability Management. Company will: (a) use automated vulnerability scanning tools to scan its systems; (b) log vulnerability scan reports; (c) use patch management and software update tools for the Company systems; and (d) prioritize and remediate vulnerabilities by severity.
5. Security Segmentation. Company will monitor, detect and restrict the flow of information on a multilayered basis within its systems using tools such as firewalls, proxies, and network-based intrusion detection systems.
6. Data Loss Prevention. Company will use data loss prevention measures designed to identify, monitor and protect Client Personal Data in use, in transit, and at rest. Such data loss prevention processes and tools will include: (a) automated tools to identify attempts of data exfiltration; and (b) the secure and managed use of portable devices.
7. Encryption. Company will encrypt, using industry standard encryption tools, all Client Personal Data that Company: (a) transmits or sends wirelessly across public networks or within the Company systems; and (b) stores on laptops, portable devices or otherwise within the Company systems. Company will safeguard the security and confidentiality of all encryption keys associated with encrypted Client Personal Data.
8. Physical Safeguards. Company will maintain physical access controls designed to secure its systems.
Attachment 4