FileBackerz.com, LLC
Data Processing Addendum
Required before using the Service to process personal data under the EU or UK GDPR.
Effective 1 September 2026 · Version 1.0 · Last updated 9 August 2026
Contents
THIS ADDENDUM IS REQUIRED BEFORE YOU MAY USE THE SERVICE TO PROCESS PERSONAL DATA SUBJECT TO THE EU OR UK GENERAL DATA PROTECTION REGULATION. IT FORMS PART OF THE TERMS OF SERVICE AND, WHERE IT CONFLICTS WITH THEM ON DATA PROTECTION MATTERS, THIS ADDENDUM PREVAILS.
1. Scope and Parties
This Data Processing Addendum ("DPA") is entered into between FileBackerz.com, LLC, a Texas limited liability company at 3723 Greenville Avenue, Suite 19910, Dallas, Texas 75206 ("FileBackerz," "Processor"), and the customer identified in the applicable Order ("Customer," "Controller").
This DPA applies where and to the extent FileBackerz processes Customer Personal Data on Customer's behalf in providing the Service under the Terms of Service (the "Agreement"). It is incorporated into and forms part of the Agreement.
Where this DPA conflicts with the Agreement on the subject of the processing of Customer Personal Data, this DPA prevails. In all other respects the Agreement continues in full force.
2. Definitions
Terms not defined here have the meanings given in the Agreement or in Data Protection Law.
- "Customer Personal Data" means personal data contained within Customer Content or otherwise processed by FileBackerz on Customer's behalf under the Agreement.
- "Data Protection Law" means all laws applicable to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the UK GDPR and the UK Data Protection Act 2018 ("UK GDPR"), and the Swiss Federal Act on Data Protection ("FADP").
- "Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
- "Subprocessor" means any third party engaged by FileBackerz to process Customer Personal Data.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Supervisory Authority" have the meanings given in the EU GDPR.
3. Roles of the Parties
The parties agree that, in respect of Customer Personal Data, Customer is the Controller and FileBackerz is the Processor. Where Customer is itself a processor acting on behalf of a third-party controller, FileBackerz is a subprocessor, and Customer warrants that it has the authority of that controller to enter into this DPA on its behalf and to give the instructions it gives.
FileBackerz acts as an independent Controller in respect of account, billing, and usage data it processes for its own purposes, as described in its Privacy Policy. This DPA does not apply to that processing.
Details of the processing — subject matter, duration, nature and purpose, categories of data subjects, and types of personal data — are set out in Annex I.
4. Customer Instructions
FileBackerz will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law. Where FileBackerz is so required, it will inform Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
The Agreement, this DPA, and Customer's configuration and use of the Service constitute Customer's complete documented instructions. Additional instructions outside the scope of the Service require prior written agreement and may be subject to additional fees.
FileBackerz will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law. FileBackerz is not obliged to carry out a legal assessment of Customer's instructions and gives no assurance that an instruction complies with law.
FileBackerz will not sell Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service, and will not combine it with personal data received from other sources except as necessary to provide the Service. FileBackerz will not use Customer Personal Data to train machine learning or artificial intelligence models.
5. Customer Obligations
Customer is responsible for: the accuracy, quality, and legality of Customer Personal Data and the means by which it acquired it; establishing and documenting a valid legal basis for the processing; providing all required notices to and, where required, obtaining consents from data subjects; and configuring the Service — including Member permissions, folder permissions, sharing links, and retention settings — so that processing complies with Data Protection Law.
Customer will not upload special categories of personal data within the meaning of Article 9 GDPR, or personal data relating to criminal convictions and offences, unless it has notified FileBackerz in writing and the parties have agreed any additional measures required.
Customer acknowledges that the Service is not designed for the processing of protected health information under HIPAA (which requires a separate Business Associate Agreement) or cardholder data subject to PCI DSS, as set out in the Acceptable Use Policy.
6. Confidentiality of Personnel
FileBackerz will ensure that persons authorized to process Customer Personal Data are subject to a binding duty of confidentiality, whether contractual or statutory, that survives the end of their engagement.
FileBackerz limits access to Customer Personal Data to personnel who need it to provide the Service or to comply with law, applies least-privilege access, and logs administrative access.
7. Security
FileBackerz will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as required by Article 32 GDPR. Those measures are described in Annex II.
FileBackerz may update the measures in Annex II from time to time, provided that no update materially reduces the overall level of security.
Customer is responsible for security within its control, including the strength of credentials, enablement of available authentication controls, correct configuration of permissions and sharing, prompt deprovisioning of departed Members, and the configuration and security of any Connected Storage.
8. Subprocessors
Customer grants FileBackerz general written authorization to engage Subprocessors. A current list of authorized Subprocessors is set out in Annex III and maintained at filebackerz.com/subprocessors.
FileBackerz will impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor's obligations.
FileBackerz will give Customer at least thirty (30) days' notice before adding or replacing a Subprocessor, by email to the address designated by Customer. To designate or change that address, write to [email protected].
Customer may object to a proposed Subprocessor on reasonable data protection grounds by written notice within thirty (30) days of FileBackerz's notice. The parties will discuss the objection in good faith. If FileBackerz is unable to make the Service available without the objected-to Subprocessor, and the objection is not resolved within thirty (30) days, Customer may terminate the affected subscription on written notice and receive a pro-rata refund of prepaid unused fees. This is Customer's sole remedy.
Where a Subprocessor is engaged on an emergency basis to maintain the security or continuity of the Service, FileBackerz will notify Customer as soon as reasonably practicable.
9. Assistance with Data Subject Rights
The Service provides Customer with the ability to access, correct, export, restrict, and delete Customer Personal Data directly. Customer will use those functions to respond to data subject requests in the first instance.
Taking into account the nature of the processing, FileBackerz will provide reasonable assistance by appropriate technical and organizational measures, insofar as possible, to enable Customer to respond to requests to exercise rights under Chapter III of the GDPR.
If FileBackerz receives a request directly from a data subject relating to Customer Personal Data, it will not respond to the substance of the request except to acknowledge it and direct the data subject to Customer, and will promptly notify Customer, unless prohibited by law.
FileBackerz may charge a reasonable fee for assistance that goes materially beyond the functionality of the Service, on prior notice to Customer.
10. Personal Data Breach
FileBackerz will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information.
FileBackerz will take reasonable steps to contain, investigate, and mitigate the breach, will preserve relevant evidence, and will cooperate with Customer and provide the information Customer reasonably requires to meet its own obligations under Articles 33 and 34 GDPR.
FileBackerz's notification is not and will not be construed as an acknowledgement of fault or liability.
Customer is solely responsible for determining whether to notify a Supervisory Authority or data subjects, and for making any such notification. FileBackerz will not notify a Supervisory Authority or data subjects on Customer's behalf without Customer's prior written agreement, except where required to do so in its own right.
11. Data Protection Impact Assessments
Taking into account the nature of the processing and the information available to it, FileBackerz will provide reasonable assistance to Customer with data protection impact assessments under Article 35 GDPR and prior consultations with Supervisory Authorities under Article 36 GDPR, where these relate to the processing of Customer Personal Data by FileBackerz.
FileBackerz may satisfy this obligation by providing Annex II, its security documentation, and any available third-party assessment reports.
12. Deletion and Return of Data
On termination or expiry of the Agreement, FileBackerz will, at Customer's election, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage.
Customer may export Customer Personal Data using the Service's export functionality at any time during the subscription term and during the thirty (30) day retention period following termination described in the Agreement. After that period, FileBackerz will delete Customer Personal Data from live systems.
Backup copies are overwritten on a rolling cycle and are fully purged within thirty-five (35) days of deletion from live systems. Until purged, backups remain subject to the security measures in Annex II and are not restored except as part of a full-system recovery.
Where FileBackerz terminates for cause under the Agreement in circumstances involving apparent unlawful content, no export period applies and FileBackerz may delete or, where legally required, preserve the affected data.
FileBackerz will certify deletion in writing on Customer's written request.
13. International Transfers
Customer authorizes FileBackerz to transfer Customer Personal Data to the United States and to the locations of authorized Subprocessors listed in Annex III.
13.1. EU transfers
Where Customer Personal Data protected by the EU GDPR is transferred from the European Economic Area to a country not subject to an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where Customer is a controller. Module Three (processor to processor) applies where Customer is itself a processor.
- Clause 7 (docking clause) does not apply.
- In Clause 9(a), Option 2 (general written authorisation) applies, with the notice period specified in Section 8 of this DPA.
- In Clause 11(a), the optional independent dispute resolution language does not apply.
- In Clause 17, the SCCs are governed by the law of Ireland.
- In Clause 18(b), disputes will be resolved before the courts of Ireland.
- Annexes I, II, and III to this DPA serve as Annexes I, II, and III to the SCCs.
13.2. UK transfers
Where Customer Personal Data protected by the UK GDPR is transferred, the UK Addendum is incorporated by reference and applies to the SCCs as set out above. For the purposes of Table 4 of the UK Addendum, neither party may end the Addendum as set out in Section 19 of it. The start date is the effective date of this DPA, and Tables 1 to 3 are completed by reference to the corresponding details in this DPA and its Annexes.
13.3. Swiss transfers
Where Customer Personal Data protected by the Swiss FADP is transferred, the SCCs apply with the following modifications: references to the GDPR are to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; the term "member state" does not limit data subjects in Switzerland from bringing proceedings in their place of habitual residence; and, until the revised FADP is fully in force, the SCCs also protect the data of legal entities.
13.4. Government access requests
If FileBackerz receives a legally binding request from a public authority for disclosure of Customer Personal Data, it will, unless legally prohibited: notify Customer promptly; review the legality of the request; challenge requests that are overbroad or unlawful; and disclose only the minimum amount of data lawfully required. FileBackerz will document such requests and provide summary information to Customer on request, to the extent permitted by law.
FileBackerz confirms that, as at the effective date, it has not received any order to provide backdoor access to Customer Personal Data or to its systems, and has not deliberately created any such access.
14. Audits and Information Rights
FileBackerz will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.
FileBackerz will satisfy this obligation in the first instance by providing Annex II, its security documentation, responses to a reasonable security questionnaire not more than once in any twelve (12) month period, and any third-party audit or certification report it holds.
Where the above is not sufficient to demonstrate compliance, Customer may, not more than once in any twelve (12) month period and on at least thirty (30) days' written notice, conduct or mandate an independent auditor to conduct an audit of FileBackerz's processing. The auditor must not be a competitor of FileBackerz and must be bound by confidentiality obligations.
Audits will take place during normal business hours, must not unreasonably disrupt FileBackerz's operations, and must not grant access to data or systems of other customers. Customer bears its own and FileBackerz's reasonable costs of the audit, unless the audit identifies a material breach of this DPA, in which case FileBackerz bears its own costs.
Customer may conduct an additional audit following a Personal Data Breach affecting Customer Personal Data, or where required by a Supervisory Authority.
15. Liability
Each party's liability arising out of or in connection with this DPA, including the SCCs, is subject to the exclusions and limitations of liability set out in the Agreement, and any liability under this DPA counts toward and does not increase the aggregate cap in the Agreement.
Nothing in this DPA limits the rights of data subjects under Data Protection Law or under the SCCs, or either party's liability to a Supervisory Authority.
16. Term, Order of Precedence, and General
This DPA takes effect on the effective date of the Agreement, or on the date it is executed if later, and continues until FileBackerz ceases to process Customer Personal Data.
In the event of conflict, the following order of precedence applies: (1) the SCCs and UK Addendum; (2) this DPA; (3) the Agreement.
This DPA is governed by the law and subject to the venue stated in the Agreement, except that the SCCs are governed as stated in Section 13.
If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect and the parties will replace the affected provision with a valid one achieving as nearly as possible the same commercial and legal effect.
This DPA may be executed electronically. Where Customer accepts the Agreement online, this DPA takes effect on Customer's written request to [email protected] identifying the account, without the need for a countersignature.
Annex I - Details of the Processing
A. List of Parties
| Data Exporter | Data Importer | |
|---|---|---|
| Name | Customer, as identified in the Order | FileBackerz.com, LLC |
| Address | As stated in the Order or the Customer's account record | 3723 Greenville Avenue, Suite 19910, Dallas, Texas 75206 |
| Contact | The account administrator or privacy contact designated by Customer | [email protected] |
| Activities | Use of the Service for business file storage, backup, and sharing | Provision of the Service |
| Role | Controller (or processor, where acting for a third-party controller) | Processor (or subprocessor) |
B. Description of the Processing
| Item | Description |
|---|---|
| Subject matter | Provision of cloud file storage, backup, sharing, versioning, and collaboration services, and related support. |
| Duration | The term of the Agreement, plus the retention and deletion periods described in Section 12. |
| Nature and purpose | Hosting, storage, encryption, transmission, backup, restoration, indexing, preview generation, access control, audit logging, and deletion of Customer Content, in each case as necessary to provide the Service and as instructed by Customer. |
| Categories of data subjects | Determined by Customer. Typically: Customer's employees, contractors, and Members; Customer's clients and their personnel; Customer's vendors, auditors, and other counterparties; and any individuals whose personal data appears within files Customer uploads. |
| Categories of personal data | Determined by Customer. For Members: name, email address, IP address, authentication data, and activity logs. Within Customer Content: any personal data Customer chooses to upload, the categories of which are known only to Customer. |
| Special categories | Not permitted without prior written notice to, and agreement from, FileBackerz (Section 5). Protected health information is prohibited absent a Business Associate Agreement. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Retention | As set out in Section 12 of this DPA and Section 9 of the Privacy Policy. |
| Subprocessor processing | As set out in Annex III, for the duration of the Agreement. |
| Competent Supervisory Authority | Determined in accordance with Clause 13 of the SCCs, by reference to Customer's place of establishment in the EEA or, where Customer is not established in the EEA, the authority of the member state in which its Article 27 representative is established. |
Annex II - Technical and Organizational Measures
The measures below describe the safeguards FileBackerz applies.
| Area | Measures |
|---|---|
| Encryption | Customer Content encrypted at rest using AES-256. All data in transit encrypted using TLS 1.2 or higher, with TLS 1.3 preferred. Encryption keys managed through a dedicated key management service with restricted access and periodic rotation. |
| Access control — personnel | Role-based access control with least privilege. Unique named accounts; shared administrative credentials prohibited. Multi-factor authentication required for all administrative and production access. Access reviewed periodically and revoked promptly on role change or departure. |
| Access control — customer | Seven-level granular folder and file permissions, group-based permission management, configurable session timeouts, optional two-factor authentication, password complexity enforcement, and optional IP allow-listing. |
| Logging and monitoring | Audit logging of uploads, downloads, deletions, permission changes, share-link creation, and authentication events, each with actor, timestamp, and IP address. Administrative access to production is logged. Logs retained for twelve months. |
| Pseudonymization and minimization | Passwords stored only as salted hashes. Internal analytics performed on aggregated or de-identified data where practicable. Personal data collected at signup limited to what is necessary, with optional fields marked as such. |
| Resilience and availability | Redundant storage with automated integrity checking. Regular automated backups with defined recovery point and recovery time objectives. Documented restoration procedures, tested periodically. |
| Business continuity | Documented incident response and business continuity procedures, with defined roles, escalation paths, and communication templates. Reviewed at least annually. |
| Vulnerability management | Dependency and infrastructure vulnerability scanning, timely patching of security updates according to documented severity-based timelines, and a published channel for external vulnerability reports at [email protected]. |
| Secure development | Version-controlled source code, peer code review, separation of development, staging, and production environments, and secrets held in a managed secrets store rather than in source code. |
| Subprocessor management | Written data protection terms with each Subprocessor, security review before engagement, and periodic reassessment. |
| Personnel | Confidentiality obligations in all personnel agreements; security and data protection awareness training; documented access provisioning and deprovisioning. |
| Physical security | Production infrastructure hosted in third-party data centers operated by our infrastructure Subprocessors, which maintain physical access controls, environmental controls, and independent security certifications. FileBackerz does not operate its own data centers. |
| Deletion | Documented deletion procedures for live systems, with backup purge within thirty-five days as described in Section 12. |
| Governance | Named individual accountable for information security. Written information security policy reviewed at least annually. FileBackerz does not hold a SOC 2 Type II attestation and does not represent that it does. |