Data Processing Addendum
Cadlyx as data processor on behalf of customers subject to GDPR, UK GDPR, or comparable laws.
Effective:
This Data Processing Addendum (the "DPA") supplements and forms part of the Terms of Service (the "Agreement") between Cadlyx, LLC ("Provider", "Cadlyx", "we", "us") and the Customer ("Customer", "you", "your"). It governs Cadlyx's Processing of Customer Personal Data when Customer is acting as data Controller (or Processor on behalf of a third party) and Cadlyx is acting as data Processor (or Subprocessor).
1. Definitions
Capitalized terms used in this DPA but not defined here have the meanings given in the Agreement. The following definitions apply:
"Applicable Data Protection Laws" means the Applicable Laws that govern how the Service may process or use an individual's personal information, personal data, personally identifiable information, or other similar term.
"Controller" has the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.
"Customer Personal Data" means Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.
"EEA SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679.
"European Economic Area" or "EEA" means the member states of the European Union, Norway, Iceland, and Liechtenstein.
"GDPR" means European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation.
"Personal Data" has the meaning(s) given in the Applicable Data Protection Laws.
"Processing" or "Process" has the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.
"Processor" has the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.
"Restricted Transfer" means (a) where the GDPR applies, a transfer of Personal Data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of Personal Data from the United Kingdom to any other country which is not subject to adequacy regulations.
"Security Incident" means a Personal Data Breach as defined in Article 4 of the GDPR.
"Special Category Data" has the meaning given in Article 9 of the GDPR.
"Subprocessor" has the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.
"UK Addendum" means the international data transfer addendum to the EEA SCCs issued by the UK Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.
"UK GDPR" means European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom's European Union (Withdrawal) Act of 2018.
2. Roles and scope of processing
2.1 Provider as Processor
In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.
2.2 Provider as Subprocessor
In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.
2.3 Processing details
Appendix A (Description of processing) describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.
3. Customer instructions
Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer's use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Provider about Processing Customer Personal Data under this DPA. Provider will abide by these instructions unless prohibited from doing so by Applicable Laws and will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.
If Provider updates the Service to add new products, features, or functionality, Provider may change the Categories of Data Subjects, Categories of Personal Data, Special Category Data treatment, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect those updates by notifying Customer.
Where Customer is itself a Processor (and Provider is a Subprocessor), Customer will comply with all Applicable Laws that apply to Customer's Processing of Customer Personal Data and with the Subprocessor requirements in Customer's agreement with its Controller. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider, including making all disclosures, obtaining all consents, and providing adequate choice.
4. Confidentiality of personnel
Provider will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and have received security awareness training appropriate to their role. All Provider personnel with production access undergo background checks and sign confidentiality agreements as a condition of employment.
5. Security measures
Provider will implement and maintain the technical and organizational measures described in Appendix B (Technical and organizational measures) and in the Security Policy referenced on the Cover Page. The Security Policy is the security regime defined in Section 7 of the Privacy Policy and the practices described in this DPA.
Provider's Security Contact for inquiries related to security or Customer Personal Data is [email protected].
6. Subprocessors
Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors, including their identities, country of location, and anticipated Processing tasks, is published at https://cadlyx.com/legal/subprocessors.
Provider will inform Customer at least 10 business days in advance and in writing of any intended changes to the Approved Subprocessors (whether by addition or replacement). Customer has 30 days after notice of a change to object, otherwise Customer will be deemed to accept the change. If Customer objects within 30 days, Customer and Provider will cooperate in good faith to resolve the objection.
When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it and (ii) consistent with the terms of the Agreement. Where the GDPR applies, the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR) are also imposed on the Subprocessor. Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data.
7. Data subject rights
If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and will not respond to the request without Customer's prior consent. Examples include a judicial, administrative, or regulatory order about Customer Personal Data (where notifying Customer is not prohibited by Applicable Law) or a request from a data subject.
If allowed by Applicable Law, Provider will follow Customer's reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer's giving of Customer Personal Data to Provider, Provider will assist Customer in fulfilling the request.
Provider will cooperate with and provide reasonable assistance to Customer, at Customer's expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Provider's Processing of Customer Personal Data under this DPA.
8. Personal data breaches
Upon becoming aware of any Security Incident, Provider will:
- Notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident;
- Provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and
- Promptly take reasonable steps to contain and investigate the Security Incident.
Provider's notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Provider of any fault or liability for the Security Incident.
9. Data protection impact assessments
If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments (DPIAs) or data transfer impact assessments (DTIAs) and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.
10. Deletion and return of personal data
10.1 Deletion by Customer
Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Service. Provider will comply with this instruction as soon as reasonably practicable except where further storage of Customer Personal Data is required by Applicable Law.
10.2 Deletion at DPA expiration
After the DPA expires, Provider will return or delete Customer Personal Data at Customer's instruction unless further storage is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Laws, Provider will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession.
If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will give Customer the certification of deletion described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs upon request.
11. Audit rights
11.1 Audit rights
Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and will allow for and contribute to audits, including inspections by Customer, to assess Provider's compliance with this DPA. Provider may restrict access to data or information if Customer's access would negatively impact Provider's intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws.
Customer acknowledges and agrees that it will exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Provider to comply with the reporting and due diligence requirements below. Provider will maintain records of its compliance with this DPA for 3 years after the DPA ends.
11.2 Security reports
Customer acknowledges that Provider may be regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will give Customer, on a confidential basis, a summary copy of its then-current Report so that Customer can verify Provider's compliance with the standards defined in the Security Policy.
11.3 Security due diligence
In addition to any Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider's compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing and made to [email protected] and may be made up to once per year.
12. International transfers
12.1 Authorization
Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Provider will implement appropriate safeguards consistent with Applicable Data Protection Laws.
12.2 Ex-EEA transfers (EEA SCCs)
If the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer within the EEA to Provider outside the EEA, and the transfer is not governed by an adequacy decision, then by entering into this DPA, Customer and Provider are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. The EEA SCCs are completed as follows:
- Module Two (Controller to Processor) of the EEA SCCs applies when Customer is a Controller and Provider is Processing Customer Personal Data for Customer as a Processor.
- Module Three (Processor to Sub-Processor) of the EEA SCCs applies when Customer is a Processor and Provider is Processing Customer Personal Data on behalf of Customer as a Subprocessor.
- The optional docking clause in Clause 7 does not apply.
- In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of Subprocessor changes is 10 business days.
- In Clause 11, the optional language does not apply.
- All square brackets in Clause 13 are removed.
- In Clause 17 (Option 1), the EEA SCCs will be governed by the laws of the Netherlands (the Governing Member State).
- In Clause 18(b), disputes will be resolved in the courts of the Netherlands.
- The Cover Page values reflected in this DPA (Annex I, Annex II, and Annex III) constitute the information required by the EEA SCCs.
12.3 Ex-UK transfers (UK Addendum)
If the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer within the United Kingdom to Provider outside the United Kingdom, and the transfer is not governed by an adequacy decision, then by entering into this DPA, Customer and Provider are deemed to have signed the UK Addendum and its Annexes, which are incorporated by reference. The UK Addendum is completed as follows:
- Section 12.2 of this DPA contains the information required in Table 2 of the UK Addendum.
- Table 4 of the UK Addendum is modified: neither party may end the UK Addendum as set out in Section 19. To the extent the ICO issues a revised Approved Addendum under Section 18 of the UK Addendum, the parties will work in good faith to revise this DPA accordingly.
- The Cover Page values reflected in this DPA constitute the information required by Annex 1A, Annex 1B, Annex II, and Annex III of the UK Addendum. The Governing Member State for UK transfers is England and Wales.
12.4 Other international transfers
For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.
13. CCPA addendum
To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed in Appendix A, which constitutes a limited and specified business purpose.
Provider will not sell or share any Personal Data provided by Customer under the Agreement. Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
14. Order of precedence
This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum; (2) this DPA; and then (3) the Agreement.
15. Limitation of liability
To the maximum extent permitted under Applicable Data Protection Laws, each party's total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement. This DPA does not limit any liability to an individual about the individual's data protection rights under Applicable Data Protection Laws, nor any liability between the parties for violations of the EEA SCCs or UK Addendum.
16. Term
This DPA starts when Provider and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement and continues until the Agreement expires or is terminated. However, Provider and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing Customer Personal Data.
Appendix A — Description of processing
A.1 List of parties
Data Exporter: The Customer signing this DPA (the entity entering into the Agreement). Role: Controller (or Processor where Customer is itself acting on behalf of a Controller).
Data Importer: Cadlyx, LLC. Address: 3714 Valley Forge Dr, Stow, Ohio 44224, USA. Contact person: Bentley Johnson, Founder. Role: Processor (or Subprocessor where Customer is a Processor).
A.2 Description of transfer and processing
Service: Cadlyx is a cloud-based platform for CAD analysis, quote generation, and supplier collaboration for manufacturing buyers and suppliers. The Service includes automated CAD file analysis (STEP, IGES, and other formats), AI-assisted quote generation via the Bid Advisor agent (running on AWS Bedrock in us-east-2), buyer-supplier collaboration via ShareView and RFQ workflows, and document generation (build documents, technical documents, quotes).
Categories of Data Subjects: Customer's end users or customers; Customer's employees.
Categories of Personal Data: Name; contact information such as email, phone number, or address; transactional information such as account information or purchases; user activity and analysis such as device information or IP address.
Special Category Data: No special category data (as defined in Article 9 of the GDPR) is intended to be processed. Customer must not upload special category data to the Service. See the Acceptable Use Policy.
Frequency of Transfer: Continuous.
Nature and Purpose of Processing: Provider will Process Customer Personal Data for the following activities: receiving data (collection, accessing, retrieval, recording, data entry); holding data (storage, organization, structuring); using data (analysis, consultation, testing, automated decision making, profiling); updating data (correcting, adapting, alteration, alignment, combination); protecting data (restricting, encrypting, security testing); sharing data (disclosure, dissemination, allowing access); returning data to the data exporter or data subject; and erasing data (destruction and deletion).
Duration of Processing: Provider will Process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 3 of this DPA, or (ii) by Applicable Laws.
A.3 Competent supervisory authority
The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
Appendix B — Technical and organizational measures
Cadlyx implements the following technical and organizational measures to protect Customer Personal Data:
- Encryption in transit: TLS 1.2+ for all connections, with HSTS enforced and HSTS preload in progress.
- Encryption at rest: AES-256 for all Customer Personal Data stored in S3 and RDS.
- Access controls: role-based access, multi-factor authentication required for production access, principle of least privilege.
- Logging and monitoring: structured application logs and CloudWatch monitoring, retention 90 days hot and 1 year cold.
- Incident response: 72-hour notification for confirmed personal data breaches; documented response runbook and on-call rotation.
- Vendor management: subprocessor list maintained at /legal/subprocessors; minimum 10 business days advance notice for additions or material changes.
- Personnel: background checks, confidentiality agreements, security awareness training for all personnel with production access.
- Physical security: inherited from AWS data center controls and certifications applicable to the Standard services Cadlyx actually uses.
- AI / ML processing: all foundation model inference runs in AWS Bedrock under AWS Service Terms §50, which contractually prohibits training on or sharing of Customer prompts and outputs with foundation model providers. Customer Content is not used to train any AI/ML model. Current Standard-service Bedrock processing remains pinned to us-east-2. Any separately contracted controlled-data deployment, its subprocessors, and its residency terms will be documented before Customer use. See Terms of Service Section 1.6 and Privacy Policy Section 3 for the full AI processing commitments.
- Data residency: current Standard-service data resides in AWS us-east-2 (Ohio). Standard is not authorized for CUI or export-controlled technical data.
- Backup and recovery: automated daily backups with cross-AZ redundancy; documented restore procedures tested on a recurring schedule.
Appendix C — Subprocessors
See /legal/subprocessors for the current list of Approved Subprocessors. The list at the time of DPA execution is also captured for reference in your organization's onboarding records.
Contact
Data protection inquiries: [email protected]. Security inquiries: [email protected]. To request a counter-signed DPA on Cadlyx letterhead, contact [email protected].
This DPA is adapted from the Common Paper Data Processing Agreement Standard Terms Version 1.1, used under the Creative Commons CC BY 4.0 license. Cadlyx-specific Cover Page values (subprocessor URL, security contact, governing member states for SCCs, data importer details, AI/ML processing language) are incorporated inline.