100x / POLICIES
Data Processing Addendum
This Data Processing Addendum ('DPA') supplements the Terms of Service or any agreement between the customer ('Client') and One Hundred X Inc. ('Processor').
Last updated January 5, 2026
1. Roles
Client = Data Controller
100x = Data Processor
2. Scope
This DPA applies to all Personal Information processed by 100x on behalf of Client for workflow automation, AI operation, or service execution.
3. Processor Obligations
100x will:
- Process Personal Information only as instructed by Client
- Maintain reasonable administrative, physical, and technical safeguards
- Restrict access to authorized personnel only
- Notify Client of data breaches without undue delay
- Assist with audits, security assessments, and compliance reviews
- Not use Client data for model training or unrelated purposes
- Delete or return Client data upon written request
4. Subprocessors
100x may use vetted subprocessors (e.g., AWS, GCP, Stripe). We maintain a list available upon request. Client may object to new subprocessors on reasonable grounds.
5. International Transfers
Client data is hosted and processed in the United States unless otherwise agreed in writing.
6. Data Subjects
100x will assist Client with responding to privacy rights requests, including access, deletion, correction, and restrictions.
7. Security Measures
100x implements SOC2-aligned safeguards including:
- AES-256 encryption
- TLS 1.3
- Zero-trust access
- Key rotation
- Immutable audit logs
- Role-based access
- Multi-region redundancy
8. Data Breach Notification
In the event of unauthorized access or disclosure, 100x will notify Client promptly and provide:
- Nature of breach
- Affected data
- Remediation steps
- Measures to prevent recurrence
9. Duration
This DPA lasts as long as 100x processes Client data.