Data Protection Agreement
07/28/2026
This Data Processing Addendum, including Schedule A and Annexes I-III (“DPA”), forms an integral part of the Agreement (“Main Agreement”) entered between Crowded Technologies, Inc. (“Company“) and between the counterparty agreeing to these terms (“Customer“; each “Party” and together “Parties”) and applies to the extent that Company processes Personal Data on behalf of the Customer, in the course of its performance of its obligations under the Main Agreement.
If you are accepting this DPA on behalf of Customer, you warrant that: (a) you have full legal authority to bind Customer to this DPA; (b) you have read and understand this DPA; and (c) you agree, on behalf of Customer, to this DPA. If you do not have the legal authority to bind Customer, please do not accept this DPA.
All capitalized terms not defined herein shall have the meaning set forth in the Main Agreement.
1. Definitions
1.1 “Approved Jurisdiction” means a jurisdiction approved as having adequate legal protections for data by the European Commission (or by the UK Information Commissioner’s Office, where applicable), currently found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en and here: https://ico.org.uk/for-organisations/dp-at-the-end-of-the-transition-period/data-protection-and-the-eu-in-detail/the-uk-gdpr/international-data-transfers/.
1.2 “Data Protection Laws” means, any and all applicable domestic and foreign laws, rules, directives and regulations, on any local, provincial, state, federal or national level, pertaining to data privacy, data security or the protection of Personal Data, including the Privacy and Electronic Communications Directive 2002/58/EC (as amended, and respective local implementing laws) concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), the Data Protection Act 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR“), US Data Protection Laws, and any amendments or replacements to the foregoing.
1.3 “Data Subject” means a natural person to whom Personal Data relates. Where applicable, a Data Subject shall include “Consumer“, as this term is defined under the US Data Protection Laws.
1.4 “EEA“ means those countries that are members of the European Economic Area.
1.5 “Security Incident“ shall mean any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. For the avoidance of doubt, any Personal Data Breach (as defined under the GDPR) will comprise a Security Incident.
1.6 “Special Categories of Data“ means personal data as defined under Article 9 of the GDPR or sensitive personal information, as defined under US Data Protection Laws.
1.7 “Standard Contractual Clauses” the applicable module of the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council from June 4th 2021, as available here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX:32021D0914&locale=en.
1.8 ”UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, which was entered into force on 21 March, 2022.
1.9 “US Data Protection Laws” means, any and all applicable laws, rules, acts, decrees, directives, regulations and binding regulatory guidance, on any state or federal level, pertaining to data privacy, data security and the protection of Personal Data, including, without limitation, the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020, and the regulations enacted thereunder, Colorado Privacy Act, 2021 Colo. ALS 483; 2021 Colo. Ch. 483; 2021 Colo. SB. 190, Connecticut Data Privacy and Online Monitoring Act, Conn. Gen. Stat. §42-515 et. Seq., Utah Consumer Privacy Act, Utah Code Ann. Title 13, Ch. 61, Virginia Consumer Data Protection Act, Va. Civ. Code § 59.1, the Texas Data Privacy and Security Act, Tex. Bus. & Com. Code Ann. § 541.001 et seq, the Oregon Consumer Privacy Act, ORS 646A.570-646A.589, Florida Digital Bill of Rights, Fla. Stat. §501.701, as well as any future laws, amendments, or regulations that may be enacted or promulgated governing data protection within the United States.
1.10 The terms “controller”, “Personal Data” “process(ing)” and “processor” as used in this DPA have the meanings given to them in Data Protection Laws. Where applicable, a controller shall be deemed a “Business“, a processor shall be deemed a “Service Provider“ or “Contractor”, and Personal Data shall be deemed “Personal Information” as these terms are defined under US Data Protection Laws.
1.11 Any reference to a legal framework, statute or other legislative enactment is a reference to it as amended or re-enacted from time to time.
2. Application of this DPA
2.1 This DPA will only apply to the extent all of the following conditions are met:
2.1.1 Company processes Personal Data that is made available by the Customer in connection with the Main Agreement (whether directly by the Customer or indirectly by a third party retained by and operating for the benefit of the Customer);
2.1.2 Data Protection Laws apply to the processing of Personal Data.
2.2 This DPA will only apply to the services for which the Parties agreed to in the Main Agreement (“Services“), which incorporates the DPA by reference.
3. Parties’ Roles
3.1 In respect of the Parties’ rights and obligations under this DPA regarding the Personal Data, the Parties hereby acknowledge and agree that the Customer is the Controller or Processor (as well as, as applicable, the Business or Service Provider, as these terms are defined under US Data Protection Laws) and Company is a Processor or Sub-Processor (as well as, as applicable, the Service Provider, as this term is defined under the US Data Protection Laws), and accordingly:
3.1.1 Company agrees that it shall process all Personal Data in accordance with its obligations pursuant to this DPA;
3.1.2 The Parties acknowledge that the Customer discloses Personal Data to Company only for the performance of the Services and that this constitutes a valid business purpose for the processing of such data.
3.2 If Customer is a Processor, Customer warrants to Company that Customer’s instructions and actions with respect to the Personal Data, including its appointment of Company as another Processor and concluding the Standard Contractual Clauses, have been authorized by the relevant Controller.
3.3 Notwithstanding anything to the contrary in the DPA, Customer acknowledges that Company shall have the right to collect, use and disclose Personal Data:
3.3.1 Collected in the context of providing the Services to Customer for its legitimate internal business purposes including but not limited to the purposes of billing, record-keeping, account management, support, protection against fraudulent or illegal activity and the prevention of misuse of the Services, compliance with legal obligations, the establishment, exercise and defense of legal claims, analytics, research, as well as product improvement and development.
3.3.2 The Company may use aggregated or anonymized information for any purpose, subject to the confidentiality obligations in the Main Agreement, to the extent applicable.
3.3.3 To the extent any data referred to under section 3.3 above is considered Personal Data, then the Company shall be deemed to be an independent Controller of such data under Data Protection Laws, and its Processing shall be outside the scope of this DPA.
3.4 Customer-Directed Disclosures to Customer’s Own Tools. Where Customer or its authorized users direct the Company, whether through an application programming interface, the Model Context Protocol, or any comparable connector or interface, to make Personal Data available to tools, applications, or services that are selected and controlled by Customer (including third-party artificial intelligence tools and the providers operating them), the Company makes such Personal Data available at Customer’s instruction and in Customer’s capacity as Controller (or Business, as applicable). Such tools, applications, services, and their providers are not the Company’s Sub-Processors, the Company is not responsible for their receipt, processing, retention, use, or disclosure of Personal Data, and such processing is outside the scope of this DPA. Customer is solely responsible for ensuring that any such disclosure and processing complies with Data Protection Laws, including providing all notices and obtaining all consents and authorizations required.
4. Compliance with Laws
4.1 Each Party shall comply with its respective obligations under Data Protection Laws.
4.2 Company shall provide reasonable cooperation and assistance to Customer in relation to Company’s processing of Personal Data in order to allow Customer to comply with its obligations under Data Protection Laws.
4.3 Company agrees to notify Customer promptly if it becomes unable to comply with the terms of this DPA and take reasonable and appropriate measures to remedy such non-compliance.
4.4 Throughout the duration of the DPA, Customer represents and warrants that:
4.4.1 Personal Data has been and will continue to be collected, processed and transferred by Customer to Company in accordance with the relevant provisions of Data Protection Laws;
4.4.2 Customer is solely responsible for determining the lawfulness of the data processing instructions it provides to Company and shall provide Company only instructions that are lawful under Data Protection Laws;
4.4.3 The processing of Personal Data by Company for the Permitted Purposes, as well as any instructions to Company in connection with the processing of the Personal Data (“Processing Instructions”), has been and will continue to be carried out in accordance with the relevant provisions of the Data Protection Law; and that
4.4.4 The Customer has informed Data Subjects of the processing and transfer of Personal Data pursuant to the DPA and obtained any relevant consents or established other lawful grounds thereto (including without limitation any consent required in order to comply with the Processing Instructions and the Permitted Purposes).
5. Processing Purpose and Instructions
5.1 The subject matter of the processing, the nature and purpose of the processing, the type of Personal Data and categories of Data Subjects, shall be as set out in the Main Agreement, or in the attached Annex I.
5.2 Company shall process Personal Data only for the Permitted Purposes and in accordance with Customer’s written Processing Instructions (unless waived in a written requirement), the Main Agreement and Data Protection Laws, unless Company is otherwise required to do so by law to which it is subject (and in such a case, Company shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest). Company shall promptly inform Customer if, in Company’s opinion, an instruction is in violation of Data Protection Laws.
5.3 To the extent that the Processing Instructions may result in the Processing of any Personal Data outside the scope of the Main Agreement or the Permitted Purposes, then such Processing will require prior written agreement between Company and Customer, which may include any additional fees that may be payable by Customer to Company for carrying out such Processing Instructions.
5.4 Company shall not process Personal Data for any purpose other than for the purpose of performing the Services or for a lawful commercial or business purpose (as defined under US Data Protection Laws), or as otherwise permitted under Data Protection Laws. Company’s performance of the Services may include disclosing Personal Data to Sub-Processors where such disclosure is necessary for the provision of the Services and Company’s activities.
6. Reasonable Security and Safeguards
6.1 Company shall use security measures (i) to protect the availability, confidentiality, and integrity of Personal Data processed by Company in connection with this DPA, and (ii) to protect such data from Security Incidents. Such security measures include the security measures set out in Annex II.
6.2 The security measures are subject to technical progress and development and Company may update or modify the security measures from time to time provided that such updates and modifications shall not, in the Company’s discretion, result in the degradation of the overall security of the services procured by Customer.
6.3 Company shall take reasonable steps to ensure the reliability of its staff and any other person acting under its supervision who has access to and processes Personal Data. Company shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7. Security Incidents
Upon becoming aware of a Security Incident, Company will notify Customer without undue delay and will provide information relating to the Security Incident as reasonably requested by Customer. Company will make reasonable endeavors, at Customer’s expense, to assist Customer in mitigating, where possible, the adverse effects of any Security Incident.
8. Security Assessments and Audits
8.1 Company audits its compliance with data protection and information security standards on a regular basis. Such audits are conducted by Company’s internal audit team or by third party auditors engaged by Company, and will result in the generation of an audit report (“Report”), which will be Company’s confidential information.
8.2 Company shall, upon prior written notice and subject to obligations of confidentiality, no more than once a year and in normal business hours, allow its data processing procedures and documentation to be inspected by Customer (or its designee), at Customer’s expense, in order to ascertain compliance with this DPA; Company shall cooperate in good faith with such audit requests by providing access to relevant knowledgeable personnel and documentation.
8.3 Subject to obligations of confidentiality, Company may satisfy the requirements set out in this section by providing Customer with a copy of the Report so that Customer can reasonably verify Company’s compliance with its obligations under this DPA.
9. Cooperation and Assistance
9.1 If Company receives any requests from individuals or applicable data protection authorities relating to the processing of Personal Data under the Main Agreement, including requests from individuals seeking to exercise their rights under applicable Data Protection Law, Company will promptly redirect the request to Customer. Company will not respond to such communication directly without Customer’s prior authorization, unless legally compelled to do so. If Company is required to respond to such a request, Company will promptly notify Customer and provide Customer with a copy of the request, unless legally prohibited from doing so. The Customer is responsible for verifying that the requestor is the data subject whose information is being sought or its duly authorized representative. Company bears no responsibility for information provided in good faith to Customer in reliance on this subsection.
9.2 If Company receives a legally binding request for the disclosure of Personal Data which is subject to this DPA, Company shall (to the extent legally permitted) notify Customer upon receipt of such order, demand, or request. It is hereby clarified however that if no response is received from Customer within three (3) business days (or otherwise any shorter period as dictated by the relevant law or authority), Company shall be entitled to provide such information.
9.3 Notwithstanding the foregoing, Company will cooperate with Customer with respect to any action taken by it pursuant to such order, demand or request, including ensuring that confidential treatment will be accorded to such disclosed Personal Data. Customer shall cover all costs incurred by the Company in connection with its provision of such assistance.
9.4 Upon reasonable notice, Company shall:
9.4.1 Taking into account the nature of the processing, provide reasonable assistance to the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer’s obligation to respond to requests for exercising Data Subject’s rights, at Customer’s expense;
9.4.2 Provide reasonable assistance to the Customer in ensuring Customer’s compliance with its obligation to carry out data protection impact assessments or prior consultations with data protection authorities with respect to the processing of Personal Data, provided, however, that if such assistance entails material costs or expenses to Company, the Parties shall first come to agreement on Customer reimbursing Company for such costs and expenses.
10. Use of Sub-Processors
10.1 Customer provides a general authorization to Company to appoint (and permit each Sub-Processor appointed in accordance with this Clause to appoint) Processors and/or Sub Processors in accordance with this section.
10.2 Company may continue to use those Sub-Processors already engaged by Company as at the date of this DPA, as specified in Annex III, subject to Company, in each case as soon as practicable, meeting the obligations set out in this Clause.
10.3 Company can at any time appoint a new Sub-Processor provided that Customer is given ten (10) days’ prior notice (such notice may be given through Company’s Services) and the Customer does not legitimately object to such changes within that time frame. Legitimate objections must contain reasonable and documented grounds relating to a Sub-Processor’s non-compliance with Data Protection Laws. If, in Company’s reasonable opinion, such objections are legitimate, Company shall either refrain from using such Sub-Processor in the context of the processing of Personal Data or shall notify Customer of its intention to continue to use the Sub-Processor. Where Company notifies Customer of its intention to continue to use the Sub-Processor in these circumstances, Customer may, by providing written notice to Company, terminate the affected portion of the Main Agreement.
10.4 With respect to each Sub-Processor, Company shall ensure that the arrangement between Company and the Sub-Processor is governed by a written contract including terms which offer at least the same level of protection as those set out in this DPA and meets the requirements of Data Protection Laws.
10.5 Company will be responsible for any acts or omissions by its Sub-Processors, which may cause Company to breach any of its obligations under this DPA.
10.6 Company will only disclose Personal Data to Sub-Processors for the specific purposes of carrying out the Services on Company’s behalf.
11. Data Retention and Destruction
11.1 Company will only retain Personal Data for the duration of the Main Agreement or as required to perform its obligations under the Main Agreement, or as otherwise required to do so under applicable laws or regulations. Following expiration or termination of the Main Agreement, Company will delete or return to Customer all Personal Data in its possession as provided in the Main Agreement, except to the extent Company is required under applicable laws to retain the Personal Data. The terms of this DPA will continue to apply to such Personal Data. This section shall not apply to the activities that are the subject matter of section 3.3 herein.
12. General
12.1 Any claims brought under this DPA will be subject to the terms and conditions of the Main Agreement, including any exclusions and limitations set forth therein.
12.2 In the event of a conflict between the Main Agreement (or any document referred to therein) and this DPA, the provisions of this DPA shall prevail.
12.3 Company may change this DPA if the change is required to comply with Data Protection Laws, a court order or guidance issued by a governmental regulator or agency, provided that such change does not: (i) seek to alter the categorization of the Parties; (ii) expand the scope of, or remove any restrictions on, either Party’s rights to use or otherwise process Personal Data; or (iii) have a material adverse impact on Customer, as reasonably determined by Company. Company will use commercially reasonable efforts to inform Customer at least 30 days (or such shorter period as may be required to comply with applicable law, applicable regulation, a court order or guidance issued by a governmental regulator or agency) before the change will take effect.
Annex I – Description of Processing Activities
Categories of data subjects: |
|
Categories of Personal Data |
|
Special Categories of Data/Sensitive Personal Information |
|
Nature of Processing |
|
Frequency of Transfer |
|
Purpose of the processing |
|
Retention period |
|
Annex II – Technical and Organizational Measures to Ensure the Security of the Data
This Annex forms part of the DPA and describes the technical and organisational measures implemented by the Company to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
The Company’s information security program is designed and implemented in accordance with applicable laws and industry best practices, including the Gramm-Leach-Bliley Act (GLBA), Dodd-Frank Act, and GDPR principles of security, integrity, and confidentiality.
1. Information Security Management
The Company maintains a documented Information Security Policy approved by management and reviewed annually by the CTO and Head of Compliance.
The CTO serves as Information Security Officer (ISO), responsible for overseeing implementation, monitoring, and compliance.
The Company maintains ISO-aligned procedures covering user access, authentication, logging, incident response, patching, and vendor management.
Security awareness training and periodic phishing simulations are conducted at least annually for all employees.
2. Access Control and Authentication
Role-based access control (RBAC) is enforced on a least-privilege basis.
Access to production systems and customer data is granted only to authorized DevOps and IT personnel as approved by the ISO.
Multi-Factor Authentication (MFA) and secure Single Sign-On (SSO) are mandatory for all systems containing personal or financial data.
User access is reviewed quarterly, and access rights are revoked immediately upon role change or termination.
3. Network and System Security
The Company maintains secure network boundaries using firewalls, intrusion detection/prevention systems (IDS/IPS), and network segmentation across Production, Corporate, and Sandbox environments.
Remote access is restricted and only permitted via VPN and encrypted tunnels.
External access is pre-approved by the ISO.
Patching and vulnerability management follow defined procedures for timely remediation.
Annual third-party penetration testing and ongoing vulnerability scans are conducted to identify and address risks.
4. Encryption and Data Protection
All data in transit is encrypted using TLS 1.2 or higher.
All data at rest is encrypted using AES-256 or equivalent encryption.
Encryption keys are securely stored and managed with restricted access.
Sensitive data is pseudonymized or masked when displayed or processed where possible.
Data minimization principles ensure only the minimum required data is collected and retained.
5. Data Loss Prevention (DLP)
The Company enforces a formal Data Loss Prevention Policy that governs the prevention of unauthorized access, transfer, or disclosure of sensitive or personal data.
Automated DLP tools and third-party services continuously monitor network traffic, email, endpoints, and cloud environments to detect and block unauthorized data transmissions.
Endpoint Detection and Response (EDR) and Endpoint Security solutions provide real-time behavioral monitoring, anti-malware, phishing, and ransomware protection.
Outgoing communications are automatically scanned for sensitive or regulated data (e.g., PII, NPI, PCI).
Alerts are logged and investigated by the security team under the supervision of the ISO.
6. Logging, Monitoring, and Incident Response
All user and system activity within production environments is logged according to the Company’s Logging and Monitoring Policy.
Logs are securely stored and protected from alteration.
Security events are reviewed and correlated through automated tools for anomaly detection.
A documented Incident Response Procedure ensures immediate investigation, containment, and notification in accordance with legal and contractual obligations.
7. Business Continuity and Disaster Recovery
The Company maintains a Business Continuity and Disaster Recovery (BCDR) Policy consistent with FDIC and FFIEC guidance.
A Business Impact Analysis (BIA) identifies and prioritizes critical systems, dependencies, and data assets.
Automated encrypted backups are performed regularly, and stored securely offsite.
8. Physical Security
The Company’s offices and partner data centers (e.g., Google Cloud) implement multi-layered physical access controls, 24/7 surveillance, and environmental safeguards.
Office access is badge-controlled; visitors require authorization and escort.
Server infrastructure is hosted in Google Cloud data centers certified under ISO 27001, SOC 1/2/3, and PCI DSS.
9. Development and Change Management
Security is integrated into the Software Development Lifecycle (SDLC), including secure coding practices, peer review, and QA testing.
Production and test environments are logically segregated; real customer data is never used in testing.
Changes to production systems follow the Change Management Policy and require ISO approval for material updates.
10. Supplier and Sub-Processor Management
The Company’s Third-Party Risk Management Policy ensures all vendors and sub-processors undergo security due diligence and maintain equivalent safeguards.
Vendor performance and certifications are reviewed periodically.
11. Human Resources and Training
Background and reference checks are conducted for all employees and/or subcontractors with access to personal data.
All staff sign confidentiality agreements and are bound by the Acceptable Use Policy.
Upon termination, system access is immediately revoked, and company equipment is recovered.
Regular security awareness sessions, phishing simulations, and role-based training reinforce compliance.
12. Data Retention and Deletion
Data retention follows the principle of data minimization. Personal data is retained only as long as required by law or contractual obligation.
Secure deletion and disposal methods (digital) are employed for all storage media.
13. Audit and Continuous Improvement
The Company conducts annual reviews of security controls and policies.
The Company performs regular internal audits and management reviews to verify compliance with its security framework.
Improvements and corrective actions are documented and tracked.
14. Regulatory Alignment
The Company’s information security and DLP frameworks are aligned with and designed to satisfy:
GLBA (Safeguards Rule)
Dodd-Frank Act and CCPA (where applicable)
GDPR principles for processors, including Article 28 and Article 32, and the use of EU Standard Contractual Clauses for lawful data transfers to the United States.
15. Certifications and Data Hosting
All production systems and personal data are hosted in Google Cloud data centers located in the United States. The Company ensures that such hosting complies with applicable data protection laws, including by implementing appropriate safeguards under the GDPR (e.g., Standard Contractual Clauses) and maintaining contractual commitments with Google Cloud to ensure data security, integrity, and confidentiality.
Annex III to the Standard Contractual Clauses
List of Sub-Processors
Below is the list of the Data Importer’s Sub-processors:
# | Name | Details | |
1 | Unit Finance Inc. | Address: | 228 Park Ave S PMB 72777, New York, NY 10003, United States |
Contact details: | |||
Description of processing: | Provides Banking-as-a-Service and financial API infrastructure enabling customer onboarding, account opening, transaction processing, and KYC/KYB verification. Processes customer identification data for compliance, onboarding, and account management purposes. | ||
2 | i3 Banks | Address: | 12212 N 156th Street, Bennington, NE 68007, United States |
Contact details: | |||
Description of processing: | Acts as the partner bank for regulated financial operations including account issuance, payments processing, and funds custody. Processes customer identity and transaction data for banking, compliance, and audit purposes. | ||
3 | Checkout Inc. | Address: | 40 Tenth Avenue 4th Floor, New York, 10014, United States |
Contact details: | |||
Description of processing: | Provides global payment processing services for online transactions and settlements, including fraud detection and payment authorization. | ||
4 | Google Cloud | Address: | 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States |
Contact details: | |||
Description of processing: | Provides secure cloud hosting, data storage, infrastructure, and analytics services for company platforms and databases. | ||
5 | Salesforce Inc. | Address: | 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States |
Contact details: | 1-800-667-6389 | ||
Description of processing: | Customer relationship management (CRM) platform used to manage client records, deal tracking, account data, and customer communications. | ||
6 | Hubspot Inc. | Address: | 2 Canal Park, Cambridge, MA 02141, United States |
Contact details: | 888-482-7768 | ||
Description of processing: | Marketing automation, CRM, and communication platform used for lead management, marketing campaigns, website analytics, and client engagement. | ||
7 | Plaid Inc. | Address: | 1098 Harrison St, San Francisco, CA 94103, United States |
Contact details: | |||
Description of processing: | Financial data aggregator used to connect user bank accounts and verify financial information to enable payments, funding, and account linking. | ||
8 | Intercom, Inc. | Address: | 55 2nd St, 4th Fl, San Francisco, California 94105, United States |
Contact details: | |||
Description of processing: | Provides customer support chat and user communication tools integrated into web and mobile platforms. | ||
9 | Twilio Inc. (Segment) | Address: | 101 Spear Street, Suite 500, San Francisco, CA 94105, United States |
Contact details: | |||
Description of processing: | Provides communication APIs and data analytics services, including message delivery, customer tracking, and analytics integration across systems. | ||
10 | Zendesk, Inc. | Address: | 181 Fremont St, 17th Floor, San Francisco, CA 94105, United States |
Contact details: | |||
Description of processing: | Provides helpdesk and ticket management platform used to manage customer service inquiries and support interactions. | ||
11 | Mixpanel Inc. | Address: | 1 Front St Ste 2800, San Francisco, CA 94111, United States |
Contact details: | |||
Description of processing: | Provides product analytics and event-tracking services used to measure, analyze, and optimize user behavior across web and mobile applications. Processes event data, usage metrics, and user identifiers to help understand product engagement and improve customer experience. | ||