# Neon Deer Platform Data Processing Addendum **Version:** 1.0 **Document date:** September 30, 2026 This Data Processing Addendum ("DPA") forms part of the [Platform Terms](/platform-terms/) accepted by Customer, or another agreement that incorporates it, between Neon Deer Data Labs Inc. ("Provider") and Customer. It applies to personal data Provider processes on Customer's behalf through the platform and its associated apps (the "Service"). It does not cover consulting or other professional services unless the parties' separate services agreement expressly incorporates it. This Cover Page and its annexes incorporate the [Common Paper DPA Standard Terms, Version 1.1](https://commonpaper.com/standards/data-processing-agreement/1.1/) ("Standard Terms"). The changes below control conflicting Standard Terms. Mandatory international-transfer clauses control conflicting provisions of this DPA or the Agreement. Other capitalized terms have the meanings given in the Standard Terms or Agreement. ## Key Terms | Term | Value | | --- | --- | | Provider | Neon Deer Data Labs Inc., 100 N Howard St Ste R, Spokane, WA 99201, United States. | | Customer / Agreement | The organization or sole proprietor identified in the accepted Agreement and the customer details described below. | | Service | The Neon Deer platform at app.neondeerdata.com and associated apps, providing CRM duplicate review, authorized record changes, workflow lookup storage, and related functionality selected by Customer. | | Approved Subprocessors | The providers listed in Annex III, as changed through the notice process below. | | Provider Security Contact | support@neondeerdata.com for urgent security reports; legal@neondeerdata.com for DPA matters and formal notices. Formal notices may also be sent to Provider's postal address. | | Security Policy | Annex II and Change 2 below. | | Governing Member State | Ireland for the EEA Standard Contractual Clauses. The UK Addendum applies its mandatory governing-law and court provisions. | | Liability | No additional indemnity or separate cap is added. Standard Terms Section 8 and the Agreement apply, including the exceptions for individuals' rights and violations of the EEA Standard Contractual Clauses or UK Addendum. | Acceptance of the Platform Terms or another Agreement incorporating this DPA includes acceptance of this Cover Page and its annexes; no separate signature is required. The parties must record any required customer and transfer details before the affected processing begins. ## Changes to the Standard Terms ### 1. Scope, roles, and permitted use Section 11.5 is replaced: "Customer Personal Data" means personal data Provider processes on Customer's behalf to provide the Service, including connected CRM data, workflow lookup values, customer submissions, results derived from them, and related support processing. Annex I describes the processing. Provider acts as Processor where Customer is Controller, and as Subprocessor where Customer acts for another Controller. Customer is responsible for its lawful instructions and any necessary authorization from that Controller. The Privacy Policy separately describes information Provider controls for its own account administration, billing, and business operations. Where the same information is also processed on Customer's behalf, that processing remains covered by this DPA. The Agreement does not authorize independent use of Customer Personal Data contrary to this DPA. Where US state privacy laws apply, Provider acts as a processor or service provider as applicable. For California personal information, the specified business purposes are the services in Annex I. Provider will not sell or share that information, retain, use, or disclose it outside those purposes or the direct business relationship, or combine it with information from other sources except as permitted by applicable law. Provider will comply with applicable California privacy law and provide the same level of privacy protection it requires of businesses, notify Customer if it can no longer meet its obligations, and allow reasonable steps to verify compliance and stop and remedy unauthorized use. Provider certifies that it understands and will comply with these restrictions. Audit and assistance provisions below support these rights. A platform Customer selects and contracts with, such as Attio, does not become Provider's Subprocessor solely because Customer instructs Provider to exchange information with it. Provider remains responsible for its own processing and its appointed Subprocessors. ### 2. Instructions, confidentiality, and security Sections 2.2–2.3 are supplemented as follows. Connections, settings, approvals, schedules, and other authorized actions are Customer's documented instructions. Provider will process Customer Personal Data only on those instructions. Product changes do not authorize new purposes or processing beyond them merely because Provider gives notice. If law requires different processing, Provider will inform Customer beforehand unless the law prohibits notice. Where GDPR Article 28 applies, that exception is limited to Union or Member State law applicable to Provider. Other government requests remain subject to mandatory transfer protections. Provider will immediately inform Customer if it considers an instruction unlawful and may pause the affected processing while the parties resolve it. Provider will limit access to personnel who need it for their work and who are bound by confidentiality obligations or an appropriate statutory duty. Provider will maintain measures appropriate to the risk, including Annex II, and will not materially reduce the overall protection of Customer Personal Data. ### 3. Subprocessors and changes Section 2.6.1 is replaced. Customer generally authorizes the Subprocessors and tasks in Annex III. A listed provider receives Customer Personal Data only when used to provide the Service. Provider will email Customer's designated operational notice contact at least 10 business days before a new or replacement Subprocessor begins processing Customer Personal Data. The notice will identify the provider, task, and processing locations. "Business days" means Monday through Friday, excluding US federal holidays. The initial operational notice contact is the email address of the person who accepts the Agreement for the workspace. A workspace administrator may change that address in Settings; the contact need not be a workspace member. Customer must keep it current. Changing the contact does not restart the notice period for a notice already validly delivered. Customer may object on reasonable data-protection grounds by emailing legal@neondeerdata.com during that period. If Customer does not object, Provider may proceed after the period ends. The parties will try in good faith to resolve an objection before processing starts. Provider need not maintain separate infrastructure or retain an existing provider. If the objection remains unresolved, Provider will not begin the disputed processing, and either party may terminate the affected Service. Provider will refund unused prepaid fees for that Service; Change 7 below governs return and deletion. A shorter period requires Customer's specific written authorization. An urgent replacement does not override that requirement or applicable transfer clauses; Provider may suspend the affected Service while obtaining authorization. The same 10-business-day period replaces the period in Standard Terms Section 3.2.3.2 for EEA SCC Clause 9. Sections 2.6.2–2.6.4 continue to apply. Provider will bind each Subprocessor to applicable data-protection obligations no less protective than this DPA and remains responsible for its subcontracted processing. A provider's own terms do not reduce Provider's obligations to Customer. ### 4. Security incidents Section 4.1(a) is replaced. Provider will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data and sooner where law requires. This includes immediate notice where Washington RCW 19.255.010(2) applies. Initial notice will not be delayed because an investigation is incomplete. Provider will supply known information about the incident, affected data and individuals, likely consequences, response measures, and a follow-up contact, and provide updates as material information becomes available. The remaining containment, investigation, and assistance obligations in Section 4.1 continue to apply. ### 5. Information and audits Sections 5.1–5.3 are replaced. Provider will provide information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by Customer or its appointed auditor. Available documentation and written answers may be used first where they reasonably satisfy the request. No independent certification or recurring third-party audit is promised. Requests must concern processing under this DPA and be sent to the Provider Security Contact. Audits must be reasonably scoped, protect confidential information and other customers' data, and minimize unnecessary disruption. Routine inspections will normally take place during business hours on at least 30 days' notice. Substantially identical routine reviews should not normally be repeated within 12 months where existing information remains sufficient. These scheduling expectations do not restrict reviews needed following a Security Incident, credible indications of noncompliance, a regulator's request, or applicable law or mandatory transfer clauses. Shorter notice or additional reviews will be accommodated where required. Customer may conduct the review itself or appoint an auditor. ### 6. Assistance Section 6 is supplemented. Taking account of the processing and available information, Provider will assist with data-subject requests and Customer's obligations concerning security, breach notifications, impact assessments, and prior regulatory consultation, including GDPR Articles 32–36 where applicable. Provider will also provide assistance required by applicable California law with Customer's assessments, audits, and consumer requests. Provider may respond directly where law requires, subject to applicable notice and transfer protections; Section 6.1 does not require Customer's prior consent for that response. For information, audits, and assistance under Changes 5 and 6, existing documentation and ordinary compliance responses are included without additional charge. Where legally permitted, substantial additional work may be subject to reasonable charges agreed in writing before that work begins. Provider will not charge Customer to remedy Provider's own breach. A fee dispute will not delay or prevent action required by applicable law or mandatory transfer clauses. This paragraph controls any conflicting cost provision in Standard Terms Section 6.1. ### 7. Return and deletion Sections 7.1–7.2 are replaced. Customer may request return or deletion at privacy@neondeerdata.com. At the end of processing, Provider will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies unless applicable law requires retention. Where GDPR Article 28(3)(g) applies, that exception is limited to Union or Member State law. Retained information remains protected and may be used only for the required retention purpose. Workspace administrators may also request deletion in the platform. Once accepted, the request ends workspace access and starts deletion without waiting for the paid subscription period to end. This action cannot be cancelled or postponed by a subsequent email request. Return and deletion requests are handled as soon as reasonably practicable within applicable legal deadlines. Customer should request a return before erasure; available product downloads may not include all Customer Personal Data. Provider will certify completion of deletion in writing where required by applicable standard contractual clauses. Backup and recovery copies remain protected and unavailable for ordinary use pending deletion under documented expiry schedules and applicable legal deadlines. Deleted information must not return to ordinary use following restoration. Provider remains responsible for required deletion of copies within its control and those held by its appointed Subprocessors. These arrangements do not override applicable law or mandatory transfer clauses. Deleting a workspace does not itself delete Customer's records in Attio or other customer-selected services. Requests concerning a sign-in account used across workspaces are handled separately; Customer Personal Data remains subject to this DPA regardless of how it is labelled. These obligations continue while Provider holds Customer Personal Data. ### 8. International transfers Standard Terms Section 3 applies with the following additions and clarifications. A transfer subject to the EU GDPR uses the EEA SCCs where required and legally applicable, including where the exporter outside the EEA is subject to the GDPR for that processing. Module Two applies to a Controller-to-Processor transfer; Module Three applies where Customer is a Processor. The selections in Section 3.2.3 remain in effect, with Ireland as Governing Member State and the notice period above. Annexes I–III and the customer details described below supply the transfer particulars. For UK transfers, the UK Addendum's mandatory clauses, Version B1.0 in force March 21, 2022, as revised under their terms, apply. Table 1 is completed by the parties and contacts in this Cover Page and customer details; its start date is the DPA's effective date. Table 2 uses the SCC modules and selections above. Table 3 uses Annexes I–III. For Table 4, both the importer and exporter are selected to exercise the right to end the Addendum under Section 19, subject to its conditions. This replaces the contrary selection in Standard Terms Section 3.3.2 and does not permit transfers to continue without required safeguards. For transfers subject to the Swiss Federal Act on Data Protection that require contractual safeguards, the SCCs apply with the corresponding module. References to the GDPR include the Swiss Act for Swiss-protected data; the competent authority is the Swiss Federal Data Protection and Information Commissioner. Where only Swiss law applies, references to the GDPR mean the Swiss Act. Individuals in Switzerland may bring proceedings in Switzerland under Clause 18(c). These adaptations do not reduce protections for data also subject to EU or UK law. The parties will complete required transfer assessments and supplementary safeguards before relying on a transfer mechanism. Provider will notify Customer if it cannot comply with applicable transfer protections; affected transfers will be suspended or otherwise addressed as the mandatory clauses require. For other countries, Provider will provide the contractual protection and assistance required by Applicable Data Protection Laws. ## Annex I — parties and processing ### A. Parties Customer is the exporter, as Controller or Processor for the applicable data. Provider is the importer, as Processor or Subprocessor. Provider's address and contact are above; Customer's information and the parties' contacts are recorded as described below. ### B. Processing description | Field | Description | | --- | --- | | Subject matter and purpose | Provide Customer's selected CRM and workflow functions: read and compare authorized records, identify possible duplicates, check domain redirects, supply AI assessments, store and return workflow lookup information, carry out authorized changes, maintain results and history, provide downloads, and support, secure, and delete the data. | | Individuals | Customer's users and teammates; contacts, prospects, customers, and other people whose information Customer submits or connects. Where Customer is a Processor, the relevant individuals of its Controller. | | Personal data | Contact and company details; sales and relationship information; selected record fields and notes; workflow information; connection credentials; assessment results and change history; and user, access, and notification information processed on Customer's behalf. | | Sensitive data | The Agreement prohibits health information and specified sensitive data. Personal data about individuals under 18 is also prohibited. Incidental prohibited data remains protected; Customer must stop the affected use and request removal. The Service does not screen all records for prohibited content. | | Frequency | On demand, on customer-configured schedules, and as connected apps or accounts send events. | | Duration | While providing the instructed Service, subject to the applicable periods in the [September 30, 2026 Privacy Policy](/privacy/2026-09/) and return or deletion under Change 7 above. The Privacy Policy does not authorize indefinite retention contrary to this DPA. | | Processing locations | Primary platform storage in the United States; personnel access from the United States, Brazil, and Mexico; provider processing as listed in Annex III. Any independent service provider requiring subprocessor authorization must be authorized before access. | | Subprocessor duration | For the relevant assigned task, subject to this DPA's retention and deletion obligations. | ### C. Supervisory authority For EU transfers, the authority is determined under SCC Clause 13 by Customer's establishment, representative, or relevant individuals, and identified in the customer details. Choosing Irish law does not automatically make Ireland's authority competent. The UK Information Commissioner and Swiss Federal Data Protection and Information Commissioner apply to their respective protected transfers. ## Annex II — security measures | Area | Measures | | --- | --- | | Access | Authenticated user access, workspace permissions, and organization-scoped authorization. Administrative access is restricted. Personnel access is limited by role and confidentiality obligations. | | Connection credentials | CRM access tokens are encrypted in storage using an organization-specific key. Disconnecting removes the platform's usable credentials. | | Data in transit | HTTPS for access to the Service and certificate-verified encrypted database connections. | | Monitoring | Error reporting with filtering of common identifiers and secrets, and activity records for relevant account and data changes. Filtering reduces exposure but does not guarantee every report is free of personal data. | | Retention | Scheduled deletion for data with configured expiry periods, plus a request-based workspace-erasure process. Other copies and provider-held data remain subject to Change 7. | | Recovery | Primary database backups support recovery. Backup retention and handling are governed by Change 7. Access to recovery copies is restricted. | These measures do not promise uninterrupted service, a complete backup of Customer's connected systems, or the ability to reverse CRM changes. ## Annex III — approved subprocessor schedule Schedule edition: September 30, 2026. Appointments concern only personal data processed on Customer's behalf for the specified tasks. Locations describe the configured primary region or the provider's broader processing footprint, not exclusive residency. Provider personnel locations are disclosed in Annex I. | Provider | Location | Task | | --- | --- | --- | | Neon / Databricks, Inc. | United States, Northern Virginia | Primary platform database. | | Hetzner / Hetzner Online GmbH | United States, Ashburn, Virginia; EU support | Application hosting, request processing, and server logs. | | Cloudflare / Cloudflare, Inc. | Global network | Traffic delivery, service protection, and sign-in checks. | | Clerk / Clerk, Inc. | United States | Sign-in, accounts, and workspace memberships. | | Anthropic / Anthropic, PBC | United States storage; processing in the United States, Europe, Asia and Australia, with support, safety review and incident response in countries where Anthropic or its affiliates operate; no exclusive residency commitment. See [Anthropic’s location disclosure](https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers). | AI assessment inputs and outputs. | | OpenAI / OpenAI OpCo, LLC | United States and other countries listed in [OpenAI’s subprocessor schedule](https://openai.com/policies/sub-processor-list/); no exclusive residency commitment. | AI assessment inputs and outputs. | | Google LLC (Gemini API Paid Services) | Countries where Google or its agents maintain facilities, as described in the [Gemini API terms](https://ai.google.dev/gemini-api/terms); no exclusive residency commitment. | AI assessment inputs and outputs. | | Sentry / Functional Software, Inc. | United States storage; Austria, Canada, and Netherlands service/support | Error reports and diagnostic information. | | Postmark / AC PM, LLC | United States | Notification email recipients, content, and delivery information. | Checkredirects.io is a service operated by Neon Deer Data Labs Inc. When used for platform domain checks, its processing is covered by this DPA. External providers handling Customer Personal Data for those checks are subject to this DPA’s subprocessor requirements. Website vendors and payment processing for Provider's own billing purposes are described separately on the public providers page. ## Customer details The accepted Agreement and customer records maintained with it identify Customer's legal name, country and general business location, covered workspaces, authorized contact, and acceptance date. These details may be supplied during account setup, in an Order Form, or directly to legal@neondeerdata.com; they need not be published or separately signed. Where international-transfer clauses apply, the parties also record required postal addresses, contact and representative details, Customer's role as Controller or Processor, the applicable transfer clauses, and the competent supervisory authority. Required details not collected during setup may be supplied privately by form or email and must be completed before the affected transfer begins. Customer must keep its details current. --- Adapted from the [Common Paper DPA v1.1](https://commonpaper.com/standards/data-processing-agreement/1.1/), licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). The Cover Page and changes above are by Neon Deer Data Labs Inc. Common Paper does not endorse this adaptation and provides its forms without warranties.