Freakout AIFreakout AI

Data Processing Addendum

How enterprise customers access Freakout's standard Data Processing Addendum.

Availability#

Freakout provides a standard Data Processing Addendum (DPA) for enterprise customers during contracting. To request the current DPA package, email privacy@freakout.ai or contact your Freakout commercial contact.

The signed DPA and order form are the source of truth for legal commitments. This page summarizes the standard enterprise DPA process and does not replace the signed agreement.

Standard coverage#

The standard enterprise DPA covers:

  • Roles — customer as controller, Freakout as processor for enterprise service data.
  • Processing scope — hosted room experiences, iframe embeds, product asset workflows, optional AI features, support, security, monitoring, and service operations.
  • Data categories — account identifiers, email addresses, request metadata, product assets, prompts, visitor messages when AI is enabled, and audit events.
  • Security measures — encryption in transit, encrypted managed storage, private asset storage, signed URL delivery, role-based access, audit logging, managed secrets, backup and recovery, and incident response.
  • Subprocessors — provider list, data categories, transfer mechanisms, notice process, and flow-down obligations.
  • International transfers — approved transfer mechanisms such as EU Standard Contractual Clauses, UK transfer addendum or IDTA, adequacy decisions, or another valid mechanism agreed by the parties.
  • Retention and deletion — default asset purge windows, backup rotation, audit-log retention, storage access-log retention, and legal or security exceptions.
  • Data subject requests — assistance with access, correction, export, deletion, restriction, and objection requests.
  • Incident notification — notification without undue delay and no later than 72 hours after confirmation of a notifiable incident affecting customer personal data.
  • Audit and evidence — reasonable security evidence under NDA, including architecture, retention, backup, access-control, audit-log, and incident-response summaries.

Review flow#

  1. Customer confirms the contracting entity, enterprise scope, region, and enabled features.
  2. Freakout provides the current DPA package and subprocessor list.
  3. Both teams review data residency, transfer mechanisms, retention, deletion, support, and AI provider terms.
  4. Sensitive evidence such as audit exports, detailed controls, penetration-test reports, and future third-party audit reports is shared under NDA or through a controlled trust workflow.
  5. The executed DPA and order form become the binding record.

Public materials#

Public enterprise documentation includes:

  • High-level security and data-protection controls.
  • Current public subprocessor list.
  • Retention and deletion targets.
  • Breach-notification position.
  • Procurement and security checklist.

Materials that are not public:

  • Executable DPA templates before contracting.
  • SOC 2, ISO 27001, or auditor materials when available.
  • Penetration-test reports.
  • Detailed cloud policies, access-review evidence, and incident runbooks.
  • Customer-specific architecture, SLA, support, and residency terms.