Data Processing Addendum
Version September 8, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in an Order or account (“Customer”) and Ad-Apt Holdings LLC, doing business as Carcin (“Carcin”). It applies where Carcin processes Personal Data for Customer as a processor or service provider. Capitalized terms not defined here have the meanings in the agreement or applicable Data Protection Law.
This posted DPA becomes binding when an Order incorporates it, the parties sign it, or Carcin confirms Customer’s written request to add it to an existing agreement. Request an execution copy at [email protected].
1. Roles and instructions
Customer is the controller or business and Carcin is the processor, service provider, or contractor for Customer Personal Data. Carcin will process that data only to provide, secure, support, and improve the contracted Service; follow documented instructions in the agreement and Customer’s use of the Service; comply with law; or protect the Service and users. Carcin will notify Customer if an instruction appears to violate Data Protection Law, unless prohibited.
Customer determines whether the Service is appropriate, provides lawful instructions, supplies required notices, obtains required permissions, and limits Personal Data to what is necessary. Customer will not submit regulated sensitive data unless the parties expressly agree in writing.
2. Processing details
| Subject | Hosting and operating Carcin workspaces, AI-assisted business operations, customer-authorized integrations, support, security, and related services. |
|---|---|
| Duration | The agreement term plus the limited return, deletion, backup, security, and legal-retention periods described below. |
| People | Customer users, personnel, prospects, customers, vendors, website visitors, and other people whose data Customer submits or makes available. |
| Data | Identifiers, contact and account data, communications, content, business records, integration data, usage/security metadata, and other data selected by Customer. |
| Operations | Collecting, organizing, storing, retrieving, transmitting, analyzing, generating, modifying, securing, deleting, and otherwise processing to provide the Service. |
3. Confidentiality and personnel
Carcin will limit access to personnel who need it, bind them to confidentiality, provide appropriate privacy and security training, and remain responsible for their compliance with this DPA.
4. Security
Carcin will maintain measures appropriate to the risk, including access controls, least privilege, encrypted transport, protected secrets, logging, vulnerability management, backup protections, incident response, and vendor oversight. Customer remains responsible for its endpoints, permissions, instructions, integrations, and account security.
5. Subprocessors
Customer authorizes the subprocessors listed at carcin.ai/subprocessors. Carcin will impose materially equivalent data-protection obligations, remain responsible for their processing as required by law, and provide a mechanism to request notice of additions. A reasonable objection based on documented data-protection grounds must be submitted promptly; the parties will seek a commercially reasonable alternative, and if none exists either party may terminate the affected feature.
6. Assistance
Taking into account the nature of processing and information available, Carcin will reasonably assist Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments, regulator consultations, and demonstrations of compliance. Customer is responsible for its responses and may be charged reasonable costs for exceptional assistance not caused by Carcin’s breach.
7. Security incidents
Carcin will notify Customer without undue delay after confirming unauthorized access to, acquisition of, or disclosure of Customer Personal Data for which notice is required (“Security Incident”). Notice will provide available information about nature, likely consequences, affected data and people, mitigation, and a contact. Notice is not an admission of fault. Unsuccessful attempts and events that do not compromise Customer Personal Data are not Security Incidents.
8. Return, deletion, and retention
At Customer’s request during the term, Carcin will provide available export functionality. After termination or a valid instruction, Carcin will delete or return Customer Personal Data within a commercially reasonable period unless law permits or requires retention. Residual backup copies remain protected, unavailable for ordinary use, and expire under normal rotation. Consent, billing, security, and legal records may be retained as permitted or required. Customer acknowledges that data sent to a connected third party may require a separate deletion request to that party.
9. Audits
On reasonable written request, no more than annually unless required after a Security Incident or by a regulator, Carcin will provide available policies, summaries, certifications, or questionnaires needed to demonstrate compliance. If those are insufficient, the parties may arrange a narrowly scoped audit during business hours, subject to confidentiality, security, non-interference, and Customer bearing reasonable costs. Audits may not expose another customer’s data or Carcin trade secrets.
10. Government requests
Carcin will review demands for Customer Personal Data, challenge unlawful or overbroad demands where reasonably appropriate, disclose only what is legally required, and notify Customer before disclosure unless prohibited.
11. International transfers
Where the EEA restricted-transfer rules apply and no adequacy mechanism covers the transfer, the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference: Module Two for controller-to-processor transfers and Module Three for processor-to-processor transfers. The optional docking clause applies; optional Clause 9(a) general authorization applies; Clause 11 optional redress language does not apply; the supervisory authority and governing law are determined by the exporter’s establishment or otherwise Ireland; and Irish courts have jurisdiction. Annexes I–III consist of this DPA, the processing table, the subprocessor list, and the security measures described here and in Carcin’s security materials. The UK Addendum and Swiss adaptations apply when their respective laws govern. Carcin will provide reasonable transfer-assessment information on request.
12. US state terms
Carcin will not sell or share Customer Personal Data, retain/use/disclose it outside the direct business relationship or permitted purposes, combine it with data from other sources except as legally permitted, or use it for targeted advertising. Carcin will comply with applicable processor/service-provider duties, provide the same level of privacy protection required of Customer, notify Customer if it can no longer comply, and allow Customer to take reasonable steps to stop and remediate unauthorized use.
13. Priority and liability
This DPA controls over conflicting terms concerning processing of Customer Personal Data. The agreement’s liability limits apply to this DPA to the maximum extent lawful. If the agreement ends, provisions that must survive to protect retained data remain effective.
14. Contact
Ad-Apt Holdings LLC d/b/a Carcin
252 A Avenue, Suite 200, Lake Oswego, Oregon 97034
[email protected]