Legal

Data Processing Agreement

Last updated October 6, 2026

This Data Processing Agreement (“DPA”) sets out the terms on which [Legal entity name] (“4xlabs”, the “Service Provider” or “Processor”) processes personal information on behalf of a partner, customer, or vendor (“Controller” or “Business”). It is incorporated by reference into each applicable agreement between the parties.

1. Purpose & scope

This DPA applies where 4xlabs processes personal information on behalf of a Controller in connection with services 4xlabs provides, or where a Controller shares personal information with 4xlabs for joint or collaborative purposes. It is intended to satisfy the processor and service-provider requirements of applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended (CCPA/CPRA), and comparable statutes.

2. Definitions

  • “Personal Information” means any information relating to an identified or identifiable individual that is processed under the applicable agreement.
  • “Processing” means any operation performed on Personal Information, including collection, storage, use, disclosure, and deletion.
  • “Security Incident” means any unauthorized access to, or acquisition, use, or disclosure of, Personal Information in 4xlabs' possession.
  • “Sub-processor” means a third party engaged by 4xlabs to assist in Processing Personal Information.

3. Roles & compliance

Each party is responsible for its own compliance with applicable privacy laws. 4xlabs acts as a Processor/Service Provider and processes Personal Information only:

  • on the documented instructions of the Controller, including with regard to transfers and retention, unless required to act otherwise by law;
  • for the limited and specified purposes described in Annex I;
  • in compliance with the obligations applicable to service providers under U.S. state privacy laws.

4. Confidentiality & personnel

4xlabs ensures that personnel authorized to process Personal Information are bound by confidentiality obligations and receive appropriate training. Access is limited to personnel whose duties require it.

5. Security

4xlabs maintains administrative, technical, and physical safeguards appropriate to the nature of the Personal Information, consistent with Annex II, including hosting with a SOC 2 Type 2 attested infrastructure provider. The Controller is responsible for the security of Personal Information it retains on its own systems.

6. Sub-processors

The Controller generally authorizes the sub-processors listed in Annex III. 4xlabs will give the Controller prior written notice of any new sub-processor and a reasonable opportunity to object. 4xlabs remains fully liable for the performance of its sub-processors' obligations under this DPA. Sub-processors are bound by written agreements imposing obligations no less protective than this DPA.

7. Assistance with requests

4xlabs will provide reasonable assistance to the Controller in responding to verifiable consumer requests under applicable privacy laws (such as requests to know, access, correct, delete, or port Personal Information). If 4xlabs receives a request directly from an individual, it will direct the individual to the Controller or, where the Controller cannot be identified, respond in accordance with applicable law.

8. Security incidents

4xlabs will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Personal Information processed under this DPA. Notification does not constitute an admission of fault. 4xlabs will take commercially reasonable steps to identify and remediate the cause, and will cooperate with the Controller's reasonable investigation needs.

9. Government & legal requests

If a law enforcement or regulatory authority demands Personal Information processed under this DPA, 4xlabs will notify the Controller promptly unless legally prohibited, and will direct the authority to request the data from the Controller where feasible. 4xlabs will challenge or seek to narrow overbroad or unlawful requests where reasonably permitted.

10. Audits

Upon the Controller's reasonable request, and no more than once per 12-month period except following a Security Incident, 4xlabs will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of security assessments or attestations (including its infrastructure provider's SOC 2 Type 2 report, subject to confidentiality restrictions).

11. No sale, sharing, or retention

4xlabs certifies that it does not sell or share Personal Information as those terms are defined under applicable state privacy laws, does not retain, use, or disclose Personal Information for any purpose other than performing the services or as permitted by this DPA, and does not combine Personal Information received from the Controller with Personal Information received from other sources except as permitted by law.

12. U.S. data handling

4xlabs operates exclusively in the United States and processes Personal Information in U.S.-based systems. Personal Information is not transferred to, stored in, or processed by persons or systems located outside the United States.

13. Return & deletion

Upon termination or expiry of the applicable agreement, or upon the Controller's reasonable instruction, 4xlabs will delete Personal Information or return it at the Controller's election, except where retention is required by law. Where deletion is technically infeasible (for example, in backups), 4xlabs will extend the protections of this DPA to the retained data and delete it when feasible.

14. Liability & general terms

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the applicable agreement, except that such limitations do not limit a party's liability to data subjects where such limitation is prohibited by law. If any provision of this DPA conflicts with the applicable agreement, this DPA controls with respect to the Processing of Personal Information. If any provision is held unenforceable, it will be modified to the minimum extent necessary, and the remainder will remain in effect.

Annex O

  • Subject matter: provision of website, communications, collaboration, and contracted services by 4xlabs.
  • Duration: the term of the applicable agreement plus retention periods required by law.
  • Nature and purpose: hosting, storage, transmission, analysis, and communication related to the contracted services.
  • Categories of data subjects: the Controller's personnel, customers, prospective partners, and applicants, as applicable.
  • Categories of Personal Information: identification and contact data (name, email, organization), application and inquiry content, and technical/log data.
  • Sensitive data: none, unless separately agreed in writing.

Annex P

  • Hosting on U.S.-based infrastructure with SOC 2 Type 2 attestation.
  • Encryption of data in transit (TLS).
  • Role-based access control, least-privilege access, and MFA for administrative access.
  • Logging, monitoring, and vulnerability management practices.
  • Personnel confidentiality agreements and security training.
  • Documented incident response process.

Annex Q

  • Railway — hosting and infrastructure (SOC 2 Type 2).
  • [Analytics provider, if enabled] — aggregate site usage analytics.
  • [Email/communications provider] — transactional and announcement email delivery.