Legal · Effective 2026-06-01 · v2026-06-01 · Not for public indexing
Data Processing Agreement
Effective Date: June 1, 2026
This Data Processing Agreement ("DPA") is incorporated by reference into the Factimonious Terms of Service. Customer's acceptance of the Terms of Service (including by clickwrap or online acceptance) constitutes Customer's execution of this DPA. No handwritten or electronic signatures are required. Enterprise customers requiring bespoke data processing terms must contact legal@factimonious.ai to negotiate a separate agreement.
PART I — CORE TEXT (UNIVERSAL PROVISIONS)
These Core provisions apply to every Customer regardless of geography. The Regulatory Annexes (Annex A, Annex B, and Annex C) are dormant and have no legal effect unless the conditions for their activation set out in Section 1.3 are met.
1. Definitions
"Applicable Data Protection Laws" means the data protection or privacy laws that specifically govern the Personal Data at issue, as identified in Section 1.3.
"Controller" means Customer, the entity that determines the purposes and means of Processing of Personal Data.
"Processor" means Level Up Labs, which Processes Personal Data on behalf of and under the instructions of the Controller.
"Personal Data" has the meaning given to it under Applicable Data Protection Laws, and refers to information that identifies or is capable of identifying a natural person.
"Processing" means any operation or set of operations performed on Personal Data, including collection, storage, use, disclosure, erasure, or destruction.
"Sub-Processor" means any third party engaged by Level Up Labs to assist in Processing Personal Data.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
"TOMs" means the Technical and Organizational Security Measures document published by Level Up Labs and made available at https://platform.factimonious.ai/legal/toms or upon written request, as updated from time to time.
"Session Result" means the output generated by the Service at the end of each analysis session, saved and linked to Customer's account as described in the Terms of Service.
1.3 Activation of Regulatory Annexes
The following Annexes are incorporated into and form part of this DPA only to the extent that the underlying Personal Data is legally subject to the corresponding jurisdiction:
Annex A (GDPR / UK GDPR Module) is activated solely where Personal Data of Data Subjects located in the European Economic Area or the United Kingdom is Processed.
Annex B (US State Privacy Laws Module) is activated solely where Personal Data of residents of a US state whose privacy law imposes processor-level obligations is Processed (including, without limitation, California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, and any other US state enacting substantially similar comprehensive consumer privacy legislation that imposes processor-level obligations).
Annex C (Canada / Brazil / Australia / Switzerland Module) is activated solely where Personal Data of individuals located in Canada, Brazil, Australia, or Switzerland is Processed.
Where neither condition is met, only the Core provisions of this DPA apply. Where more than one Annex's conditions are met with respect to different data subjects, each Annex applies independently to the data subjects it governs. The Annexes do not expand or modify each other.
2. Scope and Nature of Processing
Level Up Labs processes limited Personal Data (such as account registration data, contact information, billing data, and usage logs) as a data Processor on behalf of Customer, solely in connection with providing the Factimonious Service as described in the Terms of Service and Schedule 1 below.
Customer's code repository contents are accessed transiently for analysis and are not retained by Level Up Labs. Session Results, which are the output of that analysis, are saved and linked to Customer's account; Session Results are Personal Data, are not anonymized, and are subject to this DPA, as further described in Schedule 1. Separately, before any data is used for AI/ML training, testing, or cross-Customer analysis, it is subjected to a one-way anonymization process described in the Technical and Organizational Security Measures (“TOMs”) document. The data is anonymized such that it is no longer reasonably capable of identifying an individual under applicable law, and as a result the anonymized data set is not Personal Data and is not subject to this DPA. Level Up Labs periodically reviews its anonymization methodology against evolving regulatory guidance.
Level Up Labs shall not Process Personal Data for any purpose other than those specified in this DPA and the Terms of Service, except as required by applicable law.
3. Controller Obligations
Customer represents and warrants that:
It has a lawful basis for Processing Personal Data and for engaging Level Up Labs to Process it;
It will provide Data Subjects with appropriate privacy notices describing the Processing activities;
Personal Data provided to Level Up Labs is accurate, relevant, and not excessive for the stated purposes;
It will promptly notify Level Up Labs of any changes to applicable law that may affect Level Up Labs's obligations under this DPA;
It will cooperate with Level Up Labs in conducting data protection impact assessments where required by Applicable Data Protection Laws.
4. Processor Core Obligations
Level Up Labs shall:
Process Personal Data only on documented instructions from Customer, unless required by applicable law (in which case Level Up Labs shall, to the extent permitted by law, notify Customer before such Processing);
Ensure that all personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations;
Implement and maintain appropriate technical and organizational security measures as described in its TOMs;
Engage Sub-Processors only in accordance with Section 6;
Provide reasonable technical assistance to Customer to enable it to fulfil Data Subject rights obligations under Applicable Data Protection Laws;
Notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA;
Upon termination or expiry of the Terms of Service, delete or return all Personal Data as directed by Customer, subject to Section 9;
Provide information reasonably necessary to demonstrate compliance with this DPA, subject to the audit limitations in Section 5 and any applicable Annex.
5. Security Measures and Compliance Demonstration
5.1 Security Measures
Level Up Labs implements and maintains appropriate technical and organizational security measures designed to protect Personal Data, proportionate to the nature, scope, context, and purposes of the Processing and the risks presented to Data Subjects, as further described in its TOMs. Level Up Labs reviews and updates the TOMs from time to time as its security program matures and as risks evolve. Such measures are designed to address, as appropriate to the relevant risk profile: encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent); role-based access controls and least-privilege principles; Level Up Labs requires unique credentials for all personnel accessing systems that Process personal data. Multi-factor authentication (MFA) is required for personnel and contractor access to production environments and cloud infrastructure used to process or store Personal Data; incident response procedures; and periodic data protection and security awareness training for personnel with access to Personal Data; Level Up Labs is developing secure software development practices, including separation between production and non-production environments and pre-deployment review processes, appropriate to the current stage of the Service. Level Up Labs' key Sub-Processors, including its cloud infrastructure provider and payment processor, each maintain multi-factor authentication and other access controls on their respective platforms, as further described in the TOMs.
The Service is hosted on Amazon Web Services (AWS), which maintains independent third-party certifications including SOC 1, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, and PCI DSS. AWS compliance reports are available at aws.amazon.com/compliance/programs/. Level Up Labs may, in its discretion, obtain its own third-party certifications and will make any such reports available to Customer upon written request. Level Up Labs is under no obligation to obtain or maintain any third-party security certification as a condition of this DPA.
5.2 TOMs Sufficiency
Customer acknowledges and agrees that the Security Measures detailed in the TOMs document are designed to provide appropriate guarantees under applicable law and represent Level Up Labs's good-faith initial demonstration of compliance with its security obligations. This acknowledgment does not limit Customer's audit and inspection rights under Section 5.3 and Section 5.4, or under Annex A or Annex B where activated. Customer further acknowledges that the AWS certifications referenced in Section 5.1 serve as evidence of the technical infrastructure controls underpinning those measures.
The Technical and Organizational Measures described in Section 5.1 and the TOMs document represent appropriate technical and organizational measures within the meaning of GDPR Art. 32, having regard to the state of the art, costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks to the rights and freedoms of natural persons. Customer acknowledges that the measures set out in Section 5.1 constitute the minimum-security baseline; Level Up Labs shall not materially reduce those baseline measures without providing Customer with at least thirty (30) days’ prior written notice to the email address on Customer’s account.
5.3 Standard Compliance Demonstration (All Customers)
For all Customers under the Core provisions, compliance with this DPA and with Applicable Data Protection Laws shall be demonstrated exclusively through the following means, upon at least thirty (30) days' prior written notice to legal@factimonious.ai:
Completion of a written security questionnaire provided by Level Up Labs; and/or
Review of Level Up Labs's current TOMs document and any available third-party audit reports or certifications.
No physical, on-site, or remote technical inspection rights are granted under the Core provisions. Enhanced audit rights, where applicable, are governed exclusively by Annex A or Annex B.
5.4 No Code or Database Access
No audit, inspection, or compliance review conducted under this DPA or any Annex hereto shall include or permit: (a) access to Level Up Labs’s source code, software algorithms, or proprietary systems; (b) access to, or review of, databases or storage systems containing Personal Data of other customers; (c) execution of code, scripts, or queries on Level Up Labs’s production systems; or (d) any action that would compromise the security, integrity, or confidentiality of data belonging to Level Up Labs or any other customer. Any auditor or reviewer shall execute a confidentiality agreement acceptable to Level Up Labs before commencing any permitted review, as specified in Gate 3 of Section A.3 of Annex A.
6. Sub-Processors
Customer grants Level Up Labs general authorization to engage Sub-Processors, subject to the following conditions:
Level Up Labs maintains a current list of Sub-Processors available upon written request to factimoniousprivacy@factimonious.ai;
Level Up Labs shall provide at least thirty (30) days' advance written notice of any new or replacement Sub-Processor via email to the account administrator or by updating an online subscription mechanism where Customer has registered for updates;
Customer may object to a new Sub-Processor within fourteen (14) days of notice on reasonable data protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected Service upon written notice;
Level Up Labs imposes data protection obligations on all Sub-Processors no less protective than those in this DPA;
Level Up Labs remains liable to Customer for the performance of Sub-Processors.
Current Sub-Processors include cloud infrastructure (AWS) and Stripe, Inc. (payment processing).
7. International Data Transfers
Where Level Up Labs transfers Personal Data outside the jurisdiction in which it was collected, it shall ensure such transfers are subject to appropriate safeguards under Applicable Data Protection Laws. For transfers of EEA or UK Personal Data, the applicable transfer mechanisms are set out in Annex A.
8. Personal Data Breach Notification
In the event of a Personal Data Breach affecting Personal Data Processed under this DPA, Level Up Labs shall:
Notify Customer without undue delay after becoming aware of the Breach, to the email address on Customer's account;
Provide, to the extent available: a description of the nature of the Breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; and measures taken or proposed;
Cooperate with Customer in any required regulatory notifications and remediation efforts. Such cooperation shall include, without limitation: providing Level Up Labs’s written confirmation of the Breach details to support Customer’s notification to any applicable supervisory authority (including within the 72-hour window under GDPR Art. 33 where Annex A is activated); and providing reasonable assistance in drafting notifications to affected Data Subjects where required by Applicable Data Protection Laws.
Breach notification obligations do not imply any admission of fault or liability by Level Up Labs. What constitutes notification “without undue delay” will depend on the nature and severity of the Breach, the information available to Level Up Labs at the time, and the time reasonably necessary to investigate and confirm the relevant facts.
9. Term, Termination, and Data Return
This DPA is effective from the date Customer accepts the Terms of Service and continues for the duration of the Terms of Service. Upon termination or expiry, Level Up Labs shall, at Customer's election and within thirty (30) days: (a) return all Personal Data to Customer in a commonly used, machine-readable format; or (b) securely delete all Personal Data and provide written certification of deletion. Level Up Labs may retain Personal Data where required by applicable law. Anonymized data is not subject to return or deletion obligations. Any Personal Data retained pursuant to a legal obligation shall be: (i) limited to the minimum scope and duration required by the applicable law; (ii) subject to the same technical and organizational security measures set out in Section 5.1; and (iii) deleted promptly upon expiry of the mandatory retention period.
10. Governing Law
This DPA is governed by the laws of the State of California and the federal laws of the United States. Any disputes arising under this DPA shall be subject to the dispute resolution provisions of the Terms of Service. Where any provision conflicts with mandatory provisions of Applicable Data Protection Laws, the mandatory law prevails to the minimum extent necessary.
11. Regulated and Sector-Specific Data
This DPA does not cover Personal Data that is regulated under US sector-specific federal laws, including without limitation the Health Insurance Portability and Accountability Act (HIPAA), the Children’s Online Privacy Protection Act (COPPA), the Gramm-Leach-Bliley Act (GLBA), or the Family Educational Rights and Privacy Act (FERPA). Customer represents and warrants that it will not submit Protected Health Information, data relating to children under the age of 13, or other data governed exclusively by such sector-specific laws to the Service without first executing a separate written addendum or agreement with Level Up Labs specifically addressing those obligations.
ANNEX A — GDPR / UK GDPR MODULE
ACTIVATION: This Annex applies only where Personal Data of Data Subjects located in the European Economic Area (EEA) or the United Kingdom is Processed under this DPA. It is dormant and has no legal effect with respect to any other Personal Data.
A.1 Additional Definitions
"GDPR" means EU Regulation 2016/679 (General Data Protection Regulation).
"UK GDPR" means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018.
"SCCs" means the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914/EU, Controller-to-Processor, Module 2), incorporated into this Annex by reference.
"IDTA" means the International Data Transfer Agreement issued by the UK Information Commissioner's Office for transfers of UK Personal Data.
A.2 GDPR-Specific Processor Obligations
To the extent Annex A is activated, Level Up Labs shall additionally:
Assist Customer in responding to Data Subject requests under GDPR Arts. 15–22 (access, rectification, erasure, restriction, portability, and objection) within reasonable timescales;
Assist Customer in meeting its obligations under GDPR Arts. 32–36 (security, breach notification, DPIAs, prior consultation), having regard to the nature of the Processing and information available to Level Up Labs;
Assist Customer in meeting its obligations under GDPR Art. 30 (maintaining records), by providing information reasonably requested by Customer to assist Customer in maintaining records of processing activities;
Make available all information necessary to demonstrate compliance with GDPR Art. 28, subject to the audit provisions in Section A.3;
Notify Customer without undue delay if, in Level Up Labs's opinion, an instruction infringes the GDPR or other applicable EU or Member State data protection law.
A.3 Audit Rights (GDPR) — Reasonable Assurance Process
The parties agree that the audit mechanism below represents the practical, proportionate, and legally sufficient means to fulfil the audit obligation under GDPR Art. 28(3)(h).
Gate 1 — Documentation Audit (Standard)
Upon at least thirty (30) days' prior written notice to legal@factimonious.ai, Customer may request any or all of the following, which Level Up Labs shall provide within a reasonable time: a completed written security questionnaire; the current TOMs document; any available third-party audit reports or certifications held by Level Up Labs; and relevant AWS compliance reports. Customer acknowledges that the foregoing documentation constitutes presumptive evidence of compliance absent a documented reason for further review.
Gate 2 — Evaluation Trigger (Prerequisite for Physical/Virtual Inspection)
A physical or virtual inspection of Level Up Labs's systems or facilities is permitted only where: (a) a European data protection supervisory authority has issued a formal requirement; (b) a confirmed Personal Data Breach has occurred directly affecting Customer's data; or (c) Customer provides a written statement signed by its Data Protection Officer or counsel identifying a specific, material, and documented non-compliance that cannot be adequately assessed through Gate 1 documentation, and Level Up Labs has not resolved that concern within thirty (30) days.
Gate 3 — Operational Framework (Conditions for Permitted Inspection)
Where a Gate 2 trigger is satisfied, any inspection shall be conducted by a qualified independent third-party auditor mutually agreed upon, during normal business hours, limited to systems processing Customer's data, subject to the No Code / No Database restriction in Section 5.4, and following execution of a standard confidentiality agreement. Customer shall bear its own internal and auditor costs; if an inspection requires extraordinary or disproportionate engineering support from Level Up Labs, the parties will mutually agree in advance on reasonable, capped cost-reimbursement terms.
A.4 International Data Transfers and EU SCC Elections
Where Level Up Labs transfers EEA Personal Data outside the EEA, it shall do so only on the basis of: (a) an adequacy decision, including (where Level Up Labs is self-certified) the EU-U.S. Data Privacy Framework with respect to transfers to the United States; (b) EU Standard Contractual Clauses (Module 2: Controller-to-Processor), which are incorporated by reference and modified by the following specific processor-friendly elections; or (c) other appropriate safeguards under GDPR Chapter V. For UK Personal Data, Level Up Labs shall rely on the UK IDTA, the UK extension to the EU-U.S. Data Privacy Framework (where applicable), or the EU SCCs together with the UK Addendum. Level Up Labs's does not represent that it is currently certified unless listed in the Data Privacy Framework registry. Level Up Lab’s current Data Privacy Framework certification status, if any, is available at https://www.dataprivacyframework.gov.
For the purposes of the incorporated EU Standard Contractual Clauses (Module 2), the parties explicitly select and agree to the following elections:
Clause 7 (Docking Clause): Excluded.
Clause 9 (Use of Sub-processors): Option 2 (General written authorization) is selected. The notice period for changes to sub-processors shall be thirty (30) days as set forth in Section 6 of this DPA.
Clause 11 (Redress): The optional provision allowing data subject dispute resolution before independent bodies is excluded.
Clause 13 (Supervision): The competent supervisory authority shall be the Irish Data Protection Commission (DPC), provided that where the operation of this Clause 13 and the criteria set out in Annex I.C (or the corresponding Module provisions under which these Clauses are entered into) require that a different supervisory authority act as the competent supervisory authority, that other supervisory authority shall instead be the competent supervisory authority for purposes of these Clauses.
Clause 17 (Governing Law): The Clauses shall be governed by the laws of Ireland, provided that where Clause 13 determines that the competent supervisory authority is that of a different EU Member State, the Clauses shall instead be governed by the laws of that Member State.
Clause 18 (Choice of Forum and Jurisdiction): The courts of Dublin, Ireland shall have exclusive jurisdiction over any disputes arising under the Clauses, provided that where Clause 13 determines that the competent supervisory authority is that of a different EU Member State, the courts of that Member State shall instead have exclusive jurisdiction.
A.5 Governing Law (GDPR Supplement)
To the extent required by mandatory EU or UK data protection law, the provisions of this Annex A shall be interpreted in accordance with GDPR and UK GDPR respectively.
ANNEX B — US STATE PRIVACY LAWS MODULE
ACTIVATION: This Annex applies only where Personal Data of residents of a US state whose privacy law imposes processor / service-provider-level obligations on Level Up Labs is Processed under this DPA.
B.1 Applicable Laws and Relationship of Parties
This Annex addresses Level Up Labs's obligations as a 'Service Provider' or 'Processor' (as applicable under each state law) with respect to Personal Data of residents of states including California (CCPA/CPRA), Texas (TDPSA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and including any subsequently enacted comprehensive state consumer privacy law imposing processor obligations.
For purposes of the CCPA/CPRA, Level Up Labs is a 'Service Provider' and processes Personal Data solely to provide the Service and as otherwise permitted under the CCPA/CPRA. Level Up Labs certifies that it understands and will comply with all restrictions and obligations applicable to Service Providers under the CCPA/CPRA. Level Up Labs shall promptly notify Customer if it determines that it can no longer meet its obligations under applicable US State Privacy Laws. Upon receiving such notice, Customer reserves the right to take reasonable and appropriate steps to stop and remediate any unauthorized processing of Personal Data.
B.2 Specific Prohibited Uses
Level Up Labs shall not, with respect to Personal Data subject to this Annex:
Sell or share the Personal Data;
Retain, use, or disclose the Personal Data for any commercial purpose other than providing the Service;
Retain, use, or disclose the Personal Data outside the direct business relationship between Level Up Labs and Customer;
Combine the Personal Data with Personal Data received from or on behalf of another person or entity, except as permitted by applicable state law;
Process Sensitive Data or Sensitive Personal Information as defined under applicable state privacy law, including Social Security numbers, financial account credentials, precise geolocation data, health or medical data, and biometric data) for any purpose other than providing the Service, or retain Sensitive Personal Information beyond the period necessary to provide the Service.
B.3 Audit Rights (US State Laws)
The parties agree that the documentation-based compliance process set out below constitutes “reasonable audit and inspection” for purposes of all applicable US state privacy laws. No on-site, on-premise, source-code, database, or virtual technical inspection rights are granted to Customer under this Annex. Compliance shall be demonstrated exclusively through completion of a written security questionnaire provided by Level Up Labs and/or review of the current TOMs document, upon at least thirty (30) days' prior written notice to legal@factimonious.ai.
B.4 Data Subject / Consumer Rights Assistance
Level Up Labs shall provide reasonable technical assistance to Customer to enable Customer to fulfil its obligations to respond to Consumer rights requests. If Level Up Labs receives a Consumer rights request directly, it shall forward the request to Customer within three (3) business days.
ANNEX C — CANADA / BRAZIL / AUSTRALIA / SWITZERLAND MODULE
ACTIVATION: This Annex applies only where Personal Data of individuals located in Canada, Brazil, Australia, or Switzerland is Processed under this DPA, and then only to the extent the data protection law of the applicable jurisdiction below applies to that Processing. It is dormant and has no legal effect with respect to any other Personal Data.
C.1 Canada (PIPEDA / Québec Law 25)
With respect to Personal Information of individuals located in Canada, Level Up Labs acts as a processor (a “third party” under PIPEDA) and shall: Process Personal Information solely to provide the Service and in accordance with Customer’s instructions; implement physical, organizational, and technological safeguards consistent with Section 5.1 of this DPA; not use or disclose Personal Information for any purpose other than providing the Service; assist Customer in responding to access and correction requests received from individuals; and notify Customer without undue delay upon becoming aware of a breach of security safeguards involving Personal Information that creates a real risk of significant harm to an affected individual, consistent with Section 8 of this DPA.
To the extent Customer is subject to Québec’s Law 25, Level Up Labs shall provide reasonable assistance and information (subject to confidentiality) necessary fulfill the Customer’s obligations to evaluate any cross-border transfer of Personal Information as required under Québec Law 25, upon Customer request.
C.2 Brazil (LGPD)
With respect to Personal Data of individuals located in Brazil, Level Up Labs acts as “Operator” (Operator) and Customer acts as “Controller” (Controller) for purposes of the LGPD. Level Up Labs shall: Process Personal Data only in accordance with Customer’s documented instructions and the purposes of this DPA; implement technical and administrative security measures consistent with Section 5.1 of this DPA; provide reasonable assistance to Customer in responding to Data Subject requests under LGPD Articles 17 through 22; and notify Customer without undue delay upon becoming aware of a security incident that may result in risk or relevant damage to Data Subjects, consistent with Section 8 of this DPA.
C.3 Australia (Privacy Act 1988)
With respect to Personal Information of individuals located in Australia, Level Up Labs shall: handle Personal Information consistent with Australian Privacy Principle (APP) 11 (security of personal information) and Section 5.1 of this DPA; not use or disclose Personal Information for any secondary purpose other than providing the Service, except as otherwise permitted under the Privacy Act 1988; assist Customer in responding to access and correction requests under APPs 12 and 13; and notify Customer without undue delay upon becoming aware of an eligible data breach (within the meaning of the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988) likely to result in serious harm, consistent with Section 8 of this DPA, so that Customer may fulfil any notification obligations it may have to the Office of the Australian Information Commissioner and to affected individuals.
C.4 Switzerland (nFADP)
With respect to Personal Data of data subjects located in Switzerland, Level Up Labs acts as a processor and shall: Process Personal Data solely on Customer’s documented instructions and for the purposes of this DPA; implement technical and organizational measures consistent with Section 5.1 of this DPA; provide reasonable assistance to Customer in fulfilling Customer’s own obligations to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and to data subjects under the nFADP; and notify Customer without undue delay upon becoming aware of a data security breach likely to result in a high risk to a data subject’s personality rights or fundamental rights, consistent with Section 8 of this DPA.
C.5 Audit Rights (Canada / Brazil / Australia / Switzerland)
None of PIPEDA, Québec’s Law 25, the LGPD, the Australian Privacy Act 1988, or the Swiss nFADP requires on-site, on-premise, or technical system-level inspection of a processor’s facilities or infrastructure as a condition of compliance. The parties agree that the documentation-based compliance process described in Section B.3 of Annex B (completion of a written security questionnaire and/or review of the current TOMs document, upon at least thirty (30) days’ prior written notice to legal@factimonious.ai) constitutes reasonable assurance of Level Up Labs’s compliance with this Annex. No on-site, on-premise, source-code, database, or virtual technical inspection rights are granted to Customer under this Annex.
C.6 Sub-Processors
Level Up Labs shall ensure that any Sub-Processor engaged to Process Personal Data subject to this Annex is bound by contractual obligations that provide a level of protection consistent with this Annex and the applicable law identified above.
C.7 International Transfers (Canada / Brazil / Australia)
Personal Data of individuals located in Brazil that is transferred by Level Up Labs outside Brazil (including to the United States) is transferred on the basis of standard contractual clauses, or another transfer mechanism recognized under LGPD Articles 33 through 36, including any ANPD-approved standard contractual clauses or transfer mechanisms in force at the time of transfer. Level Up Labs will provide Customer with documentation of the applicable transfer mechanism upon written request.
Personal Information of individuals located in Australia that is disclosed by Level Up Labs to an overseas recipient (including in the United States) is disclosed consistent with Australian Privacy Principle (APP) 8, including by taking reasonable steps to ensure the overseas recipient does not breach the APPs in relation to that information.
PIPEDA does not impose a transfer-mechanism requirement equivalent to the EU SCC or LGPD regimes; transfers of Canadian Personal Information are addressed through the contractual safeguards and accountability obligations set out elsewhere in this Annex and this DPA.
Schedule 1 — Details of Processing
| Processing Element | Details |
|---|---|
| Subject Matter | Processing of personal data in connection with Customer's use of the Factimonious SaaS platform. |
| Duration | For the duration of the Terms of Service, plus any applicable post-termination retention period required by law. |
| Nature of Processing | Collection, storage, use, analysis, and deletion of personal data to provide and operate the Service. |
| Purpose | Account management, authentication, communications, payment processing, and Service delivery. |
| Types of Personal Data | Contact information (name, email address); GitHub OAuth identity data (GitHub user ID, username, and email); billing contact information; usage and log data (IP address, feature interactions, timestamps); Session Results (account-linked individual engineering activity data, including code-analysis outputs and recommendations tied to Customer's account, as described in Section 2). Session Results are Personal Data and are not anonymized; they are distinct from the aggregated, cross-Customer anonymized data described in Section 2 and the TOMs document, which is not Personal Data. |
| Categories of Data Subjects | Customer's authorized users, including employees, contractors, and administrators who access the Service. |
| Special Categories | None anticipated. Customer must notify Level Up Labs if special category data (as defined under GDPR Art. 9) is to be processed. |
| Retention Period | Account data: duration of account plus three (3) years. Billing records: seven (7) years. Session Results: duration of account plus three (3) years. |
Factimonious is a product of Level Up Technology LLC d/b/a Level Up Labs | legal@factimonious.ai | factimoniousprivacy@factimonious.ai
Contact: factimoniousprivacy@factimonious.ai