This DPA takes effect on the date the customer accepts the Terms incorporating it.
1. Parties and scope
This DPA forms part of the Terms of Service between SF VENTURES ("Provider"), and the customer identified in the workspace and acceptance record ("Customer"). The person accepting for Customer confirms their authority to do so.
This DPA applies to personal data Provider processes on Customer's behalf through DearFax ("Customer Personal Data"). Customer acts as controller, or as a processor authorised by the relevant controller; Provider acts as processor or subprocessor respectively. It does not cover processing for which Provider independently determines purposes and means, such as its own billing and business-account administration, which is described in the Privacy Policy.
"Applicable Data Protection Law" means laws applying to the parties' processing under this DPA, including the GDPR and applicable French implementing legislation, and other applicable privacy laws. GDPR terms have their GDPR meanings. Contractually offering this DPA does not mean every law mentioned applies to every customer.
2. Customer responsibilities and instructions
Customer is responsible for the lawfulness of its purposes and instructions, required notices, relevant legal bases, and authority to disclose the data. Where Customer is a processor, it must obtain any required controller authorisation for Provider and its subprocessors.
Provider processes Customer Personal Data only on documented instructions, including this agreement, Customer's authorised use of service controls, and mutually agreed written instructions. Processing includes operations and transfers necessary to provide the agreed service, subject to section 8. Provider does not use Customer Personal Data for its own advertising, sale, or model training.
If EU or Member State law requires processing beyond those instructions, Provider will inform Customer beforehand unless that law prohibits notice. Provider will immediately inform Customer if it believes an instruction infringes Applicable Data Protection Law and may pause the affected processing while the parties resolve it.
3. Confidentiality and security
Provider limits access to authorised personnel who need it for their duties and are subject to confidentiality obligations. Provider implements appropriate technical and organisational measures under GDPR Article 32, including the completed measures in Schedule 2, taking account of risk, the nature of the data, and available technology. Provider regularly assesses those measures and does not materially reduce the agreed level of protection during the service.
4. Subprocessors
Customer grants general written authorisation to the subprocessors identified in Schedule 3. Provider imposes data protection obligations offering the protection required by this DPA and Article 28 on each subprocessor, and remains responsible for its subprocessor's performance of those obligations.
Provider will notify Customer at workspace administrators’ verified email addresses at least 30 days before a new or replacement subprocessor begins processing. Customer may object within that period on reasonable data protection grounds. The parties will seek a reasonable solution, such as using an alternative provider or disabling the affected feature. If unresolved, Customer may terminate the affected service before the change takes effect and receive a proportionate refund of unused prepaid fees. Provider will not allow the objected-to new subprocessor to process that Customer's data while the objection is unresolved.
5. Assistance
Taking account of the nature of processing and the information available, Provider will assist Customer with data subject requests, security obligations, breach reporting, data protection impact assessments, and prior consultations with supervisory authorities.
Provider will promptly forward requests concerning Customer Personal Data to Customer and will not independently respond on Customer's behalf unless instructed or legally required. Customer controls substantive decisions about its processing.
6. Personal data breaches
Provider will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notice will go to the security contact agreed with Customer, or otherwise to workspace administrators at their verified email addresses.
As information becomes available, Provider will describe the incident, affected data and people, likely consequences, mitigation measures, and a contact for follow-up. Provider will investigate, contain, and remediate the incident and cooperate with Customer. Information may be supplied in stages without undue further delay. Customer decides and performs its own legally required notices; Provider's independent legal obligations remain unaffected.
7. Information and audits
Provider will supply information reasonably needed to demonstrate compliance with this DPA and permit and contribute to audits, including inspections, by Customer or an appointed independent auditor. The parties will use reasonable confidentiality, scheduling, and security arrangements that do not prevent effective verification or regulatory access. Relevant reports may satisfy an audit request where sufficient, but do not replace necessary inspection rights.
8. International transfers
Provider will not make a restricted international transfer without a lawful mechanism and any necessary supplementary measures. Schedule 3 identifies processing locations and mechanisms for relevant subprocessors. Customer's selection of an overseas fax recipient is a documented delivery instruction, but is not by itself a substitute for any legally required transfer safeguard or derogation assessment.
An Article 28 DPA is not automatically an international-transfer mechanism. Where Standard Contractual Clauses are needed, the parties must implement the applicable official clauses with the correct module, parties, annexes, and options before the affected transfer. DearFax’s primary application hosting and storage are in the United States. Subprocessor processing locations and transfer arrangements are described in Schedule 3. Provider uses the applicable Standard Contractual Clauses in its subprocessor agreements for restricted transfers. Where a separate transfer agreement between Customer and Provider is required, the parties will complete the applicable official clauses and annexes before that transfer; this DPA does not replace them.
9. Return and deletion
Customer may request the return or deletion of Customer Personal Data by contacting privacy@dearfax.com. Provider verifies the requester’s identity and authority and agrees a secure means of returning the data.
At the end of processing services, Provider will, at Customer's choice, return or delete Customer Personal Data and delete existing copies unless EU or Member State law requires storage. Provider will carry out the agreed instructions without undue delay and assist Customer in meeting applicable legal deadlines. Return of data does not remove the obligation to delete remaining copies unless continued storage is legally required.
Provider will coordinate deletion with relevant subprocessors. Provider tracks supplier deletion requests and explains any legally required retention. Copies already delivered to Customer-selected fax or email recipients are outside Provider’s account controls and cannot be recalled by deleting the source document. Legally retained data remains protected and is used only for the required purpose. Provider will confirm completion on request and explain any specific legal retention exception. The retention criteria in section 6 of the Privacy Policy apply subject to this DPA and Customer’s agreed instructions.
10. Liability, priority, and duration
The Terms govern liability between the parties to the extent legally permitted. Nothing limits data subject rights, supervisory authority powers, or mandatory liabilities. This DPA controls conflicting provisions about Customer Personal Data, and mandatory transfer clauses take priority where applicable. The DPA remains in effect while Provider or its subprocessors hold Customer Personal Data on Customer's behalf.
Schedule 1 — Processing details
Subject matter
Personal data handled to prepare, send, receive, store, and manage faxes for Customer.
Duration
Subscription or other service period, plus the agreed return/deletion period.
Nature and purpose
Collection, upload, storage, document conversion, retrieval, display, transmission, receipt, delivery-status handling, instructed forwarding, and deletion; support access only as authorised and necessary.
Data subjects
Customer personnel, clients, patients where expressly permitted, suppliers, fax senders and recipients, and other people identified in Customer's documents.
Data categories
Names, contact details, fax numbers, document content, cover pages, transmission metadata, and identifiers necessary to operate the service; workspace membership and document-processing identifiers.
Sensitive data
May appear in customer-selected documents; Customer must not submit special-category data or criminal-offence data unless Customer has established the required legal basis and the parties have agreed appropriate additional safeguards in writing. No HIPAA-regulated use requiring a BAA before that BAA and the approved service are in place.
Frequency
As initiated by Customer, authorised users, or incoming senders, with continuous storage where enabled.
Customer rights and duties
Those in this DPA and Applicable Data Protection Law.
Customer contact
Workspace customer identity and privacy/security contact captured in the acceptance record.
Provider contact
Schedule 2 — Technical and organisational measures
Transport and storage
The web application and its configured provider API connections use HTTPS. Fax files are held in private storage; access is restricted as described below. These controls do not provide end-to-end encryption through telephone networks or recipient equipment. Provider does not operate a customer-managed encryption-key service.
Access controls
Production administrative access is currently limited to the service operator, who uses two-factor authentication on provider accounts. The operator reviews administrative access when responsibilities change and removes access when it is no longer needed. Credentials must not be shared; any future personnel access is limited to the duties assigned.
Workspace isolation
Workspace records are scoped to the relevant workspace. Server-side access checks verify the signed-in user’s workspace membership and required permissions. Before sign-in, temporary drafts are protected by a private browser cookie; a draft identifier alone does not authorise access. After sign-in and workspace selection, the draft is assigned to that workspace and follows its access controls and retention rules. Unclaimed drafts expire after 24 hours without an edit or upload and are deleted with their files by daily cleanup. Documents are held in private storage and accessed through authorised server routes or time-limited signed links.
Logging and monitoring
Application error reporting records operational status and error codes. The analytics error pipeline filters payloads and removes document contents, credentials, query strings and private document URLs. This does not imply that every provider log is controlled by DearFax.
Product analytics
Analytics uses an allowlist of event fields and filters out document contents, filenames, fax numbers, email addresses, payment methods, access tokens and private document URLs. URLs are stripped of query strings and fragments. Optional product analytics and campaign attribution require consent, as described in the Privacy Policy.
Resilience
Provider does not operate a separate backup or recovery system. The current Supabase Free project does not include project backups. Provider relies on the infrastructure supplied by its hosting and storage providers and does not promise restoration of deleted documents. Customer should retain its own copies of important documents. No recovery-time or recovery-point guarantee applies.
Software security
The service operator is responsible for dependency updates and security maintenance. The operator reviews security reports, prioritises fixes according to risk, tests changes and deploys corrections. No fixed patch deadline or independent penetration-testing certification is represented.
Incident response
The service operator is responsible for incident response and customer notification under section 6. The operator records reported incidents, assesses affected systems and data, contains unauthorised access, coordinates with suppliers and informs affected Customers without undue delay. Investigation and remediation are documented; information is updated as it becomes available.
Deletion and export
Customer requests return or deletion through privacy@dearfax.com. The service operator verifies identity and workspace authority, arranges a secure return, and coordinates deletion of relevant application and supplier copies under section 9. The service does not promise automatic deletion when a plan’s file-access window expires.
Organisational controls
The service operator handles support and data requests under the confidentiality obligations in this DPA. Hosting providers manage physical data-centre security. Before giving another person access, Provider establishes appropriate confidentiality obligations and explains the applicable access and incident-handling procedures.
Sensitive documents
Customer is responsible for determining that the service and agreed measures are appropriate for the documents it submits. HIPAA-regulated use requiring a BAA is not available unless Provider expressly enables the relevant service and signs a BAA. Customer must not submit such information before those arrangements are in place.
Schedule 3 — Authorised subprocessors
The providers below support the service. The register identifies the entities named in the providers’ published terms and the available processing-location and transfer information. A provider is covered by this Schedule only to the extent it processes Customer Personal Data on Provider's behalf; processing for which it acts as an independent controller remains outside this DPA and is described in the Privacy Policy and the provider's own notice.
Telnyx
Function: Fax transport, numbers, and porting
Data handled: Fax content, sender and recipient numbers, transmission metadata, and porting records
Provider identified in public terms: Telnyx LLC (or the Telnyx affiliate identified in the service agreement)
Data protection terms: Provider DPA
Processing locations and transfer arrangements: United States. The applicable Telnyx data processing agreement incorporates Standard Contractual Clauses for restricted transfers, using the module appropriate to the parties’ roles.
Supabase
Function: Private database and document storage
Data handled: Workspace data, fax content, transmission metadata and porting documents
Provider identified in public terms: Supabase Pte. Ltd.
Data protection terms: Provider DPA
Processing locations and transfer arrangements: Primary database/storage: United States (AWS us-east-1). The published DPA incorporates the European Commission’s Standard Contractual Clauses where applicable. All processing, including support and onward processing for DearFax, takes place in the United States under the applicable provider data processing agreement.
Vercel
Function: Application hosting and related logs
Data handled: Application requests, operational logs and data processed by server functions
Provider identified in public terms: Vercel Inc.
Data protection terms: Provider DPA
Processing locations and transfer arrangements: Application function region: United States (iad1). The published DPA includes international-transfer terms and applies to Pro and Enterprise plans. Vercel’s Trust Center lists onward providers and locations. All processing, including support and onward processing for DearFax, takes place in the United States under the applicable provider data processing agreement.
Clerk
Function: Authentication and workspace membership
Data handled: User identity, authentication and workspace membership information; workspace authentication and membership processing under this DPA; Clerk also acts independently for processing described in its own privacy notice
Provider identified in public terms: Clerk, Inc.
Data protection terms: Provider DPA
Processing locations and transfer arrangements: United States. The applicable Clerk data processing agreement includes Standard Contractual Clauses for restricted transfers. All processing for DearFax, including support and onward processing, takes place in the United States.
Resend
Function: Transactional email delivery, including incoming-fax notifications
Data handled: Recipient email addresses, notification content, and incoming fax PDF attachments
Provider identified in public terms: Plus Five Five, Inc. (Resend)
Data protection terms: Provider DPA
Processing locations and transfer arrangements: United States. Sending is configured in us-east-1; Resend states that message content and logs are stored in the United States independently of sending region. Its account DPA incorporates Standard Contractual Clauses, including processor-to-processor terms where applicable. Resend’s subprocessor list identifies its onward providers.
Hookdeck (Outpost)
Use: Webhook delivery for workspaces that enable an endpoint.
Function: Outgoing webhook delivery, signing, retries, and delivery diagnostics
Data handled: Workspace, fax, submission and number-allocation identifiers; event types, fax statuses, timestamps, page counts and receipt links; endpoint URLs, event subscriptions, signing secrets and delivery diagnostics. Webhook payloads exclude fax documents and document download URLs. Receipt links provide access to transmission metadata.
Provider identified in public terms: Hookdeck Technologies Inc.
Data protection terms: Provider DPA
Processing locations and transfer arrangements: Default hosting region: United States, confirmed by Hookdeck. Hookdeck’s subprocessor list identifies its onward providers. Support-access countries and the transfer terms applicable when DearFax acts as a processor remain under review; this entry does not provide an assurance that all onward processing occurs only in the United States.
Stripe
Function: Payment processing and subscription administration
Data handled: Billing contact details, billing address, tax information, purchased plan, invoice and payment status, payment references, and payment details entered through Stripe's payment interface; no fax content
Provider identified in public terms: Stripe Payments Europe, Limited for accounts outside North and South America, or the Stripe entity identified in the service agreement
Data protection terms: Provider DPA
Processing locations and transfer arrangements: Stripe processes data globally, including transfers to Stripe, LLC in the United States and to affiliates and subprocessors in other jurisdictions. Its DPA incorporates a Data Transfers Addendum that provides the applicable Data Privacy Framework, Standard Contractual Clauses, and UK transfer mechanism. Stripe also acts as an independent controller for activities identified in its DPA and privacy notice.
PostHog
Function: Consent-based product analytics, performance monitoring, and error reporting
Data handled: Opaque user and workspace identifiers, page paths without query strings or fragments, allowlisted product events, performance measurements, and filtered error diagnostics; no fax content, filenames, fax numbers, email addresses, payment methods, access tokens, or private document URLs
Provider identified in public terms: PostHog, Inc.
Data protection terms: Provider DPA
Processing locations and transfer arrangements: PostHog stores data in the data-centre location selected for the configured project and processes data in the United States and other locations used by its subprocessors. Its DPA incorporates the EU Standard Contractual Clauses and UK transfer addendum where applicable. The selected project location should be confirmed in the PostHog account before relying on a specific regional storage claim.