Last updated June 2026
About this agreement
This is the customer-facing DPA Focor offers where it processes personal data on behalf of a customer (the controller). Focor's agreements with its own vendors and sub-processors are signed separately.
This Data Processing Agreement (“DPA”) forms part of the agreement between you or your organization (“Customer”, the “Controller”) and Focor Inc. (“Focor”, the “Processor”) for use of the Focor service (the “Agreement”). It applies where Focor processes personal data on the Customer's behalf, and governs that processing under the GDPR, the UK GDPR, and other applicable data protection law.
Where Focor acts as a controller (for example, for its website and for individuals using Focor directly), the Privacy Policy governs instead. If this DPA conflicts with the Agreement on data protection, this DPA prevails.
Definitions
- Applicable Data Protection Law: all laws governing the processing of personal data that apply to the Customer's use of the service, including the GDPR, the UK GDPR, and the CCPA.
- Controller, Processor, Sub-processor, Data Subject, Processing, Personal Data: as defined in Applicable Data Protection Law.
- Customer Personal Data: personal data that Focor processes on behalf of the Customer under the Agreement.
- SCCs: the Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
Roles and scope
The Customer is the controller (or a processor acting for its own controllers) of Customer Personal Data, and Focor is the processor. Each party will comply with its obligations under Applicable Data Protection Law. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I.
Focor's processing obligations
Focor will:
- Process Customer Personal Data only on the Customer's documented instructions, including the Agreement and use of the service, unless required by law (in which case Focor will inform the Customer where permitted).
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement and maintain the technical and organizational security measures in Annex II (Art 32).
- Not sell Customer Personal Data, and not use it for any purpose other than providing and securing the service.
- Promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
Sub-processors
The Customer provides general authorization for Focor to engage sub-processors. Focor:
- Maintains a current list of sub-processors in Annex III and in our Privacy Policy.
- Imposes data protection obligations on each sub-processor that are no less protective than those in this DPA.
- Gives the Customer prior notice of any new sub-processor and a reasonable opportunity to object on legitimate data protection grounds.
- Remains responsible to the Customer for its sub-processors' performance.
International transfers
Where Focor transfers Customer Personal Data outside the EEA or the UK to a country without an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference (Module Two for controller-to-processor, and Module Three for processor-to-processor transfers), together with the UK Addendum. The details in Annexes I to III populate the corresponding annexes of the SCCs.
Assistance to the Customer
Taking into account the nature of the processing, Focor will assist the Customer:
- To respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection).
- To meet its obligations on security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
If Focor receives a request directly from a data subject regarding Customer Personal Data, it will not respond except on the Customer's instructions, and will forward the request to the Customer.
Security incidents
Focor will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its breach notification obligations. Focor will take reasonable steps to mitigate and remediate the incident.
Audits and records
Focor will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To minimize disruption, audits may rely on Focor's available certifications and reports (such as SOC 2 and ISO 27001 once obtained), on reasonable notice, and no more than once per year except where required by a supervisory authority or following a Security Incident.
Return and deletion
On termination of the Agreement, or earlier at the Customer's request, Focor will delete or return Customer Personal Data in accordance with the Agreement and the retention practices described in the Privacy Policy, and delete existing copies unless retention is required by law.
CCPA terms
For personal information subject to the CCPA, Focor acts as a “service provider”. Focor will not sell or share such information, will not retain, use, or disclose it for any purpose other than performing the service or as permitted by the CCPA, and will not combine it with information from other sources except as the CCPA allows. Focor certifies that it understands and will comply with these restrictions.
Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA takes effect when the Customer accepts the Agreement and continues until Focor has stopped processing Customer Personal Data.
Annex I: details of processing
Parties. Data exporter: the Customer (controller). Data importer: Focor Inc. (processor), 1111b S Governors Ave, Suite 97911, Dover, DE 19904 US.
Subject matter and duration. Provision of the Focor service for the duration of the Agreement and any permitted retention period.
Nature and purpose. To read authorized data from the Customer's connected tools, build a private model of how the user works, and surface what deserves their attention, including inference performed through the model providers in Annex III.
Categories of data subjects
- The Customer's authorized users.
- Individuals referenced in the connected sources (for example, colleagues, contacts, and senders).
Categories of personal data
- Identifiers and contact details (name, email, account identifiers).
- Communications and content metadata from connected sources (messages, events, files, and the people, topics, and decisions referenced in them).
- The derived model and usage and telemetry data.
Special categories. The service is not intended to process special categories of data. Any such data incidentally present is processed only as part of the connected-source content and is subject to the safeguards in Annex II.
Annex II: security measures
Focor maintains technical and organizational measures including:
- Encryption of personal data in transit (TLS) and at rest.
- Pseudonymization of personal data where feasible, separating identifiers from the working data.
- Zero-trust architecture: read-only by default, scoped least-privilege access, and no standing access to Customer data.
- Authentication, access controls, logging, and regular security review.
- Data minimization, and secure development with data protection by design and by default (Art 25).
- Measures to restore availability and access to personal data after an incident, and a process for testing and evaluating effectiveness.
Focor is pursuing SOC 2 Type II and ISO 27001 certification.
Annex III: sub-processors
Focor engages the following sub-processors, each under a signed DPA:
- Supabase: database, authentication, and storage.
- Vercel: application hosting and website analytics.
- PostHog: product and website analytics.
- xAI (Grok) and Anthropic: large language model inference.
- Resend: transactional and account email.
To request the current list, including processing locations and transfer safeguards, contact privacy@focor.com.
Contact
Questions about this DPA, or to sign a countersigned copy, contact privacy@focor.com.