Data Processing Addendum (DPA)
Last updated: 13 January 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the customer identified in the Order Form or other written agreement ("Customer" or "Controller") and the applicable TechFarben Group contracting entity identified in the Order Form ("Farben.ai", "Processor", "we").
TechFarben Group contracting entities (each may act as Processor depending on the Order Form):
- TECHFARBEN LIMITED (UK) — 71–75 Shelton Street, Covent Garden, London, England, WC2H 9JQ.
- TECHFARBEN PTE. LTD. (Singapore) — 122 McNair Road, #02-49, Singapore 320122.
- TechFarben India Pvt Ltd (India) — Cyber City, DLF Phase 2, Sector 25, Gurugram, Haryana 122001, India.
This DPA applies to the extent Farben.ai processes Personal Data on behalf of Customer in the course of providing the Farben.ai platform and related services (the "Services").
If there is a conflict between this DPA and the main agreement, this DPA governs regarding Personal Data processing.
1. Definitions
Terms not defined here have the meaning given in the Agreement. In addition:
- "Applicable Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including (as applicable) the EU GDPR, UK GDPR, and Data Protection Act 2018.
- "EU GDPR" means Regulation (EU) 2016/679.
- "UK GDPR" means the EU GDPR as transposed into UK law.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" has the meaning given in the EU GDPR.
- "Subprocessor" means any processor engaged by Processor to process Personal Data on behalf of Controller.
- "Standard Contractual Clauses" or "SCCs" means the European Commission's standard contractual clauses for international transfers.
- "UK Addendum/IDTA" means the UK International Data Transfer Addendum to the SCCs and/or the UK International Data Transfer Agreement, as applicable.
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
2. Roles and Scope
2.1 Controller and Processor. Customer is the Controller of Personal Data processed in the Services. Farben.ai is the Processor.
2.2 Customer instructions. Farben.ai will process Personal Data only on documented instructions from Customer, including as necessary to provide the Services and as set out in the Agreement, this DPA, and Customer's configuration/use of the Services.
2.3 Customer responsibilities. Customer is responsible for:
- establishing a lawful basis for processing Personal Data;
- providing required notices to data subjects;
- ensuring the Personal Data provided to the Services is relevant, accurate, and limited to what is necessary;
- managing access and user permissions; and
- evaluating whether the Services are suitable for Customer's compliance obligations.
3. Details of Processing
3.1 Subject matter. Provision of the Services, including document ingestion, extraction, workflow automation, controls, reconciliation, analytics, and audit logging.
3.2 Duration. Processing for the term of the Agreement and any applicable post-termination period for data export, deletion, or legal retention.
3.3 Nature and purpose. To host, process, and secure Customer data and Personal Data as necessary to provide the Services.
3.4 Categories of data subjects. Customer's authorised users; Customer's employees, contractors, vendors, customers, and other individuals whose Personal Data is included in Customer data.
3.5 Types of Personal Data. May include identifiers (name, email), professional details, invoice/contract metadata, payment-related references, and workflow/audit trail information as configured by Customer.
3.6 Special categories. Customer will not provide special category data (e.g., health, biometrics, religion) unless explicitly agreed in writing and with additional safeguards.
4. Processor Obligations
4.1 Confidentiality. Processor will ensure persons authorised to process Personal Data are bound by confidentiality.
4.2 Assistance. Processor will reasonably assist Customer with:
- responding to data subject requests;
- completing DPIAs and consultations (where required);
- demonstrating compliance with Processor obligations.
4.3 Legal requests. Processor will notify Customer of legally binding requests for disclosure of Personal Data (unless prohibited by law).
4.4 Return or deletion. At termination, Processor will (at Customer's option and subject to the Agreement) return and/or delete Personal Data, except to the extent required by law.
5. Security Measures
5.1 Security program. Processor will implement and maintain appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, loss, or alteration.
5.2 Controls (summary). Measures may include:
- encryption in transit and at rest (where supported)
- role-based access control (RBAC) and least privilege
- audit logging and monitoring
- secure development and change management
- vulnerability management
- incident response procedures
5.3 Customer security. Customer is responsible for maintaining secure credentials, controlling access, and configuring security features.
6. Subprocessors
6.1 General authorisation. Customer authorises Processor to engage Subprocessors to support delivery of the Services.
6.2 Subprocessor list. Processor will maintain an up-to-date list of Subprocessors and make it available upon request (or via a posted list) at: support@techfarben.com.
6.3 Changes and objection. Processor will provide notice of material changes to Subprocessors. Customer may object on reasonable grounds related to data protection by notifying Processor within 15 days of the notice. If the objection is not resolved, Customer may terminate the affected Services without penalty (pro rata where applicable), to the extent the Subprocessor is necessary to provide those Services.
6.4 Flow-down. Processor will impose data protection obligations on Subprocessors that are no less protective than those in this DPA.
7. International Data Transfers
7.1 Transfers. Personal Data may be processed in the UK, EU/EEA, Singapore, India, or other jurisdictions where Processor or its Subprocessors operate.
7.2 Transfer safeguards. Where transfers are subject to EU GDPR or UK GDPR cross-border transfer restrictions, the parties will rely on:
- the SCCs (as applicable), and
- the UK Addendum/IDTA (as applicable),
- plus any required supplementary measures.
7.3 Incorporation. The SCCs and (where relevant) the UK Addendum/IDTA are incorporated by reference. If Customer requires execution of SCCs in a specific format, Processor will reasonably cooperate.
8. Security Incident Notification
8.1 Notification. Processor will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Personal Data.
8.2 Information. Processor will provide information reasonably required for Customer to meet its notification obligations, including (to the extent available):
- nature of the incident
- categories and approximate number of data subjects/records affected
- likely consequences
- remediation steps taken
8.3 No admission. Notification is not an admission of fault or liability.
9. Data Subject Requests
9.1 Processor support. Processor will implement appropriate measures to assist Customer in responding to requests to exercise data subject rights.
9.2 Direct requests. If Processor receives a request directly, it will (where legally permitted) redirect the requester to Customer and notify Customer.
10. Audit and Compliance
10.1 Information rights. Processor will make available information necessary to demonstrate compliance with this DPA.
10.2 Audit. Customer may audit Processor's compliance no more than once per year, on 30 days' written notice, during normal business hours, and subject to reasonable confidentiality and security restrictions. Audits may be satisfied via:
- independent third-party audit reports or certifications (if available), and/or
- questionnaires and security documentation,
prior to any on-site audit.
10.3 Costs. If an on-site audit is required, Customer bears its costs and Processor may charge reasonable fees for time and resources, unless the audit identifies a material breach.
11. Data Deletion and Export
11.1 Export. During the term and for a reasonable period after termination (as defined in the Agreement), Customer may export Customer data and Personal Data.
11.2 Deletion. Processor will delete Customer data within a reasonable period after termination, subject to legal retention and backup cycles.
11.3 Backups. Personal Data may persist in backups for a limited period, protected by security controls, and will be deleted according to Processor's backup retention schedules.
12. No Training on Customer Data (Default)
By default, Processor will not use Customer data or Personal Data processed under this DPA to train public or third-party AI models.
If Customer requests an optional program to use limited Customer data to improve Processor's models or prompts, this will require a separate written agreement specifying scope, safeguards, retention, and opt-out.
13. Limitation of Liability
Liability under this DPA is subject to the limitation of liability provisions in the Agreement, unless prohibited by Applicable Data Protection Laws.
14. Order of Precedence
In the event of conflict, the following order applies:
- SCCs / UK Addendum/IDTA (for transfer-related matters)
- this DPA
- the Agreement
Annex 1 — Processing Details
A. List of Parties
Controller: Customer identified in the Order Form/Agreement.
Processor: The applicable TechFarben Group entity identified in the Order Form/Agreement (one of: TECHFARBEN LIMITED (UK); TECHFARBEN PTE. LTD. (Singapore); TechFarben India Pvt Ltd (India)).
B. Description of Transfer (if applicable)
As described in Section 3 of this DPA.
C. Competent Supervisory Authority
Determined under Applicable Data Protection Laws (typically based on Controller's establishment).
Annex 2 — Technical and Organisational Measures (TOMs)
Processor maintains a security program designed to protect Personal Data. Measures may include:
- Access controls: RBAC, least privilege, MFA support
- Encryption: TLS in transit; encryption at rest (where supported)
- Logging/monitoring: audit logs, anomaly detection, alerting
- SDLC: secure development practices and change management
- Vulnerability management: scanning and patching
- Incident response: documented procedures and escalation
- Business continuity: backups and recovery processes
Processor will provide additional detail upon reasonable request as part of procurement/security review.
Annex 3 — Subprocessors
Processor will provide the current list of Subprocessors upon request and/or maintain it at a published location. Requests: support@techfarben.com.