TorqBox Data Processing Addendum
Last Updated: September 22, 2026
TorqTech AI Inc.
This Data Processing Addendum (this “DPA”) forms part of and is incorporated by reference into the Software as a Service Agreement or other agreement governing Customer’s use of the applicable product that references this DPA or the URL at which it is published (the “Agreement”) between TorqTech AI Inc. (“Provider”) and the customer identified in the Agreement (“Customer”). This DPA applies automatically to the extent Provider Processes Customer Personal Data on behalf of Customer in connection with the Services. By entering into the Agreement, the Parties agree to this DPA; separate signature of this DPA is not required. The current DPA is published at https://torqtech.ai/dpa. Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Definitions
“Applicable Data Protection Laws” means all laws and binding regulations applicable to Provider’s Processing of Customer Personal Data under the Agreement, including, to the extent applicable, the GDPR, UK GDPR, the California Consumer Privacy Act of 2018 as amended (“CCPA”), and other U.S. state comprehensive privacy laws.
“Customer Personal Data” means Personal Data contained in Customer Data that Provider Processes on behalf of Customer to provide the Services. Customer Personal Data does not include information for which Provider determines the purposes and means of Processing independently, such as Provider’s own business contact, billing, security, fraud prevention, and service administration data, to the extent permitted by Applicable Data Protection Laws.
“De-identified or Aggregated Data” means information created from Customer Personal Data that has been processed so that it no longer constitutes Personal Data under Applicable Data Protection Laws, including information that qualifies as deidentified, anonymized, or aggregate information under applicable law. Information that is merely pseudonymized, tokenized, hashed, or otherwise capable of being linked to an individual remains Customer Personal Data to the extent Applicable Data Protection Laws continue to treat it as Personal Data.
“Data Subject,” “Personal Data,” “Process,” “Processing,” “Controller,” and “Processor” have the meanings given in Applicable Data Protection Laws.
“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, excluding unsuccessful attempts or events that do not compromise Customer Personal Data.
2. Roles and Scope
2.1 Roles. As between the Parties, Customer is the Controller or “business” of Customer Personal Data and Provider is the Processor, “service provider,” or “contractor,” as those terms are defined by Applicable Data Protection Laws, except where Customer acts as a Processor for another Controller, in which case Provider acts as Customer’s subprocessor.
2.2 Customer Instructions. Provider will Process Customer Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, Customer’s configuration and use of the Services, and other written instructions consistent with the Agreement, unless Processing is required by applicable law. Customer specifically instructs and authorizes Provider to Process Customer Personal Data as reasonably necessary to create De-identified or Aggregated Data in accordance with Section 3.4, the Agreement, and Applicable Data Protection Laws. If legally permitted, Provider will notify Customer before Processing required by law.
2.3 Customer Responsibilities. Customer is responsible for the lawfulness of its Processing, the accuracy and quality of Customer Personal Data, providing required notices, obtaining required consents or other lawful bases, and ensuring that its instructions comply with Applicable Data Protection Laws. Customer will not provide data types that the Services do not expressly support, including highly regulated or sensitive data identified in the Agreement, unless the Parties agree in writing to additional safeguards.
3. Processing Requirements
3.1 Purpose Limitation. Provider will Process Customer Personal Data only to provide, secure, maintain, support, and improve the Services for Customer; comply with Customer’s documented instructions, including the de-identification and aggregation instruction in Section 2.2; prevent fraud, abuse, or security threats; and comply with law. Provider will not Process Customer Personal Data for unrelated commercial purposes. Commercial use of information that has ceased to constitute Customer Personal Data is governed by Section 3.4 and the Agreement.
3.2 Confidentiality. Provider will ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as necessary for their duties.
3.3 AI and Model Training; Underlying Model Providers. Except as expressly authorized by Customer in writing, Provider will not use Customer Personal Data to train generalized artificial intelligence or machine learning models. Provider may use De-identified or Aggregated Data as permitted by Section 3.4 and the Agreement, including to develop, train, fine tune, test, evaluate, operate, and improve TorqTech models, the Services, analytics, datasets, data products, and other products or services, and for permitted third party licensing or commercialization. Provider will not disclose or make available Customer Personal Data, or De-identified or Aggregated Data derived from Customer Personal Data, to providers of third party foundation models underlying the Services for inference, training, fine tuning, evaluation, safety review, or otherwise, except to the extent Customer separately directs a disclosure through an external service outside TorqBox or a later written agreement expressly provides otherwise.
3.4 De-identified or Aggregated Data. Customer instructs and authorizes Provider to create De-identified or Aggregated Data from Customer Personal Data as part of the Services and in accordance with the Agreement and Applicable Data Protection Laws. Provider may determine the technical methods and level of detail used to create such information, subject to Applicable Data Protection Laws and any controlling signed agreement. Until information satisfies the applicable legal requirements so that it no longer constitutes Personal Data, it remains Customer Personal Data and is subject to this DPA. Once information lawfully qualifies as De-identified or Aggregated Data and no longer constitutes Personal Data, it ceases to be Customer Personal Data under this DPA and Provider may retain, use, combine, analyze, disclose, license, commercialize, and otherwise use it as permitted by the Agreement. Provider will comply with any conditions Applicable Data Protection Laws impose on maintaining or using such information in deidentified, anonymized, or aggregate form, including applicable restrictions on reidentification and recipient obligations. This DPA does not impose a higher aggregation, anonymization, or de-identification standard than Applicable Data Protection Laws or the Agreement requires.
3.5 No Sale or Targeted Advertising. Provider will not sell or share Customer Personal Data for cross context behavioral advertising, as those terms are defined by the CCPA, and will not use Customer Personal Data for targeted advertising or profiling unrelated to providing the Services to Customer.
4. Security
4.1 Safeguards. Taking into account the state of the art, costs of implementation, the nature, scope, context, and purposes of Processing, and the risk to individuals, Provider will maintain commercially reasonable administrative, technical, and organizational measures appropriate to the risk. In assessing what is appropriate, the Parties acknowledge that Provider’s size and resources and the measures commonly used by similarly situated SaaS providers may be considered. Annex II describes the measures applicable to the Services.
4.2 Security Incident. Provider will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Provider will provide information reasonably available to Provider regarding the nature of the Security Incident, categories of affected data and individuals, likely consequences, and remediation measures, and will provide reasonable updates as material information becomes available. Provider’s notification is not an admission of fault or liability.
4.3 Customer Security. Customer is responsible for securely configuring its accounts, managing Authorized User credentials and permissions, using available security features, and promptly notifying Provider of suspected unauthorized access to Customer accounts.
5. Subprocessors
5.1 General Authorization. Customer gives Provider general written authorization to engage subprocessors to Process Customer Personal Data in connection with the Services. Provider will enter into a written agreement with each subprocessor that imposes data protection obligations materially consistent with those applicable to Provider under this DPA. Provider remains responsible for its subprocessors’ performance of those obligations to the extent required by Applicable Data Protection Laws.
5.2 Notice of Changes. Provider will make its then-current subprocessor list available at the location identified in Annex III or otherwise provide it to Customer on request. Provider will provide at least fifteen (15) days’ prior notice of a new subprocessor that will materially Process Customer Personal Data, which may be provided by email or by a subscription mechanism made available by Provider.
5.3 Objections. Customer may object to a new subprocessor during the notice period on reasonable, documented data protection grounds. The Parties will work in good faith to address the objection. If Provider cannot reasonably provide the affected Services without the new subprocessor, either Party may terminate only the affected portion of the Services, and Customer’s exclusive remedy will be a prorated refund of prepaid fees for the terminated portion after the effective termination date.
6. Assistance and Individual Rights
6.1 Data Subject Requests. Taking into account the nature of Processing, Provider will provide reasonable assistance through appropriate technical and organizational measures to enable Customer to respond to requests by Data Subjects to exercise rights under Applicable Data Protection Laws. If Provider receives a request relating to Customer Personal Data directly from a Data Subject, Provider will, where legally permitted, direct the requester to Customer and will not independently respond except on Customer’s documented instructions or as required by law.
6.2 Compliance Assistance. Taking into account the nature of Processing and information available to Provider, Provider will provide reasonable assistance with Customer’s obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, to the extent required by Applicable Data Protection Laws. Provider may charge reasonable fees for assistance that is materially beyond the standard functionality and support included in the Services, unless the assistance is required because of Provider’s breach of this DPA.
7. Return, Deletion, and Retention
Upon Customer’s written request or termination of the Services, Provider will delete or return Customer Personal Data within a commercially reasonable period, except to the extent retention is required by law or Customer Personal Data remains in routine backup systems. Any retained Customer Personal Data will remain protected by this DPA and will not be actively Processed except for security, backup restoration, or legal or compliance purposes. Unless a different period is stated in the Agreement or applicable service documentation, Provider will target deletion from active production systems within thirty (30) days after termination. These return and deletion obligations do not apply to De-identified or Aggregated Data that has lawfully ceased to constitute Customer Personal Data before the applicable deletion or return obligation; Provider may retain and use that information as permitted by Section 3.4 and the Agreement.
8. Audits and Compliance Information
8.1 Information. Upon reasonable written request not more than once in any twelve (12)-month period, Provider will make available information reasonably necessary to demonstrate compliance with this DPA, which may include then-current security documentation, summaries of third party assessments, or relevant certifications, if any. Provider may redact confidential information unrelated to Customer and may require reasonable confidentiality protections.
8.2 Audit. If the information provided under Section 8.1 is not reasonably sufficient to demonstrate compliance with obligations that Applicable Data Protection Laws expressly require to be auditable, Customer may conduct an audit through an independent auditor that is not a competitor of Provider, subject to at least thirty (30) days’ prior written notice, reasonable scope and timing, and confidentiality obligations. Audits will occur during normal business hours, will not unreasonably interfere with Provider’s operations, and will avoid access to other customers’ data. Customer bears its audit costs unless the audit identifies a material breach of this DPA by Provider.
9. U.S. State Privacy Laws; CCPA Terms
To the extent the CCPA applies to Customer Personal Data, Provider acts as a “service provider” or “contractor” as applicable. Provider certifies that it understands and will comply with the restrictions in this Section. Provider will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA or as otherwise permitted by the CCPA; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Provider and Customer, except as permitted by the CCPA; or (d) combine Customer Personal Data with personal information received from or on behalf of another person, or collected from Provider’s own interaction with a consumer, except as permitted by the CCPA. Provider will provide the same level of privacy protection for Customer Personal Data as required of Customer to the extent applicable, will notify Customer if Provider determines it can no longer meet its applicable CCPA obligations, and will allow Customer to take reasonable and appropriate steps to help ensure that Provider uses Customer Personal Data consistently with Customer’s obligations under the CCPA. Provider will contractually require subprocessors Processing CCPA-covered Customer Personal Data to comply with applicable downstream restrictions. For clarity, information that lawfully qualifies as deidentified or aggregate consumer information under the CCPA and therefore is no longer Personal Information is governed by Section 3.4 and the Agreement, subject to all conditions that the CCPA imposes on maintaining and using such information in deidentified or aggregate form.
10. International Transfers
10.1 Transfer Mechanisms. Provider will not transfer Customer Personal Data from the European Economic Area, United Kingdom, or Switzerland to a country that does not provide an adequate level of data protection unless an applicable lawful transfer mechanism is in place.
10.2 EU Standard Contractual Clauses. Where required for a restricted transfer from the EEA or otherwise subject to the GDPR, the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated by reference. Module Two (Controller to Processor) applies where Customer is a Controller and Provider is a Processor; Module Three (Processor to Processor) applies where Customer is a Processor and Provider is a subprocessor. Clause 7 (Docking Clause) applies. For Clause 9, Option 2 (general written authorization) applies with the notice period in Section 5.2 of this DPA. The optional language in Clause 11 does not apply. For Clause 17, the law of the EU Member State in which the data exporter is established applies; if the exporter is not established in an EU Member State, the laws of Ireland apply. For Clause 18, the corresponding courts have jurisdiction. Annex I and Annex II of this DPA complete the corresponding annexes of the EU SCCs.
10.3 United Kingdom. For restricted transfers subject to the UK GDPR, the then-current International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner is incorporated by reference to the extent required, with the information in this DPA used to complete the applicable tables and annexes. The Parties agree that the EU SCCs, as modified by the UK Addendum, apply to the transfer.
10.4 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with adaptations necessary to cover Swiss law, including references to the competent Swiss supervisory authority and Swiss data subjects, to the extent required by law.
10.5 Conflict. If there is a conflict between this DPA and an applicable mandatory transfer mechanism, the mandatory transfer mechanism controls with respect to the restricted transfer.
11. Liability and Order of Precedence
The limitations, exclusions, and allocation of liability in the Agreement apply to this DPA and to claims arising from the Processing of Customer Personal Data, to the maximum extent permitted by applicable law. This DPA does not increase either Party’s aggregate liability beyond the liability cap in the Agreement. If there is a conflict between this DPA and the Agreement regarding Processing or protection of Customer Personal Data, this DPA controls. If there is a conflict between this DPA and an applicable transfer mechanism described in Section 10, the transfer mechanism controls for that transfer.
12. Term; Online Publication and Updates
12.1 Term. This DPA takes effect when it becomes part of the Agreement and remains in effect for so long as Provider Processes Customer Personal Data on Customer’s behalf. Sections that by their nature should survive, including confidentiality, return/deletion, transfer protections, and liability provisions, survive termination for as long as Provider retains Customer Personal Data.
12.2 Online Publication and Updates. Provider may update the DPA posted at https://torqtech.ai/legal/dpa from time to time. The version in effect on the Agreement’s Effective Date applies during the then-current Term. A revised DPA will apply beginning with the next Renewal Term, except that Provider may make an earlier change to the extent reasonably necessary to comply with applicable law or where the change does not materially diminish the protection of Customer Personal Data. Provider will not materially diminish the protection of Customer Personal Data during a then-current Term without Customer’s written agreement.
ANNEX I DETAILS OF PROCESSING
| Item | Description |
|---|---|
| Subject Matter | Processing necessary to provide, host, secure, maintain, support, and improve the Services for Customer in accordance with the Agreement and Customer’s documented instructions. |
| Duration | For the Term of the Agreement and any limited post-termination retention period described in this DPA, subject to legal retention and backup exceptions. |
| Nature and Purpose | Hosting, storage, organization, retrieval, search, AI assisted analysis and generation, transmission, support, security monitoring, troubleshooting, logging, backup, creation of De-identified or Aggregated Data as instructed in this DPA, and other Processing necessary to provide the Services. |
| Categories of Data Subjects | Authorized Users; Customer personnel and contractors; Customer’s customers or end users, if Customer submits their Personal Data; and other individuals whose Personal Data Customer elects to submit through the Services. |
| Types of Personal Data | Business contact and account information; identifiers and authentication data; user IDs; IP addresses and device/network information; usage, log, and telemetry data; support communications; queries, prompts, files, notes, images, and other content submitted to the Services; vehicle, VIN, asset, diagnostic, maintenance, repair, estimate, invoice, workflow, insurance, claim, policy, correspondence, and related information to the extent associated with an identifiable person. |
| Sensitive / Special Category Data | None intentionally required. Customer will not submit payment card data, Social Security numbers, government identification numbers, protected health information, medical or bodily injury claim records, biometric identifiers used for unique identification, or other sensitive/special category data unless expressly supported by the Services and agreed by the Parties in writing. |
| Frequency | Continuous or as initiated by Customer and Authorized Users during use of the Services. |
| Controller Instructions | The Agreement, this DPA, Customer’s configuration and use of the Services, the instruction and authorization to create De-identified or Aggregated Data under Sections 2.2 and 3.4, and additional written instructions accepted by Provider. |
EU SCC Annex I.A - List of Parties
| Data Exporter | Data Importer |
|---|---|
| Customer, as identified in the Agreement. Role: Controller or Processor, as applicable. | TorqTech AI Inc., Delaware, United States. Role: Processor or subprocessor, as applicable. Contact: support@torqtech.ai. |
EU SCC Annex I.C - Competent Supervisory Authority
The supervisory authority determined in accordance with Clause 13 of the EU SCCs. Where the exporter is not established in the EEA but is subject to the GDPR and has appointed an EU representative, the authority of the Member State in which the representative is established will apply; otherwise the authority determined by the EU SCCs applies.
ANNEX II TECHNICAL AND ORGANIZATIONAL MEASURES
Provider maintains the measures below based on the Services, applicable risks, costs of implementation, and Provider’s size and resources. Measures may be implemented directly or through subprocessors and may evolve so long as the overall level of protection remains appropriate to the risk. No certification, audit standard, or unlisted security control is represented.
| Control Area | Baseline Measure |
|---|---|
| Access and Authentication | Access to Customer Personal Data is limited to authorized personnel with a business need using authenticated accounts and permissions appropriate to their responsibilities. |
| Encryption | Customer Personal Data is protected in transit using generally accepted transport encryption. Provider uses encryption at rest where provided by, or reasonably available through, its production hosting environment. |
| System Maintenance | For systems under its control, Provider uses commercially reasonable processes to apply security updates and address material known vulnerabilities, taking into account risk, available fixes, and operational feasibility. |
| Security Events | Provider maintains or uses logs reasonably available in its production environment for security investigation and maintains reasonable procedures to investigate and respond to confirmed Security Incidents. |
| Availability and Recovery | Provider uses commercially reasonable backup or recovery measures appropriate to the Services and the risks presented. No specific recovery time, recovery point, uptime, or availability commitment is made under this DPA. |
| Personnel | Personnel authorized to access Customer Personal Data are subject to confidentiality obligations, and access is removed or adjusted when no longer reasonably required. |
| Subprocessors | Provider requires subprocessors that Process Customer Personal Data to be bound by written data protection obligations as described in Section 5. |
ANNEX III SUBPROCESSORS
Provider’s current subprocessor list will be maintained at https://torqtech.ai/subprocessors or, until that page is published, provided to Customer upon written request. Provider may use the posted list to provide notice of subprocessor changes as described in Section 5.2.
