Effective date: May 18, 2026 · Antifragile GRC LLC, a Texas limited liability company
Who this is for: This Data Processing Agreement ("DPA") applies to all customers who use the Antifragile GRC platform and supplements the Terms of Service. It governs how we process personal data on your behalf as your service provider.
"Controller" means the Customer — the financial institution that determines the purposes and means of processing personal data.
"Processor" means Antifragile GRC LLC, acting on the Controller's instructions.
"Personal Data" means any information relating to an identified or identifiable natural person that is processed through the Platform. In the context of a bank compliance program, this may include employee names and contact details, customer complaint records, conflict of interest declarations, and audit finding assignments.
"Processing" means any operation performed on Personal Data, including storage, retrieval, use, and deletion.
"Sub-processor" means any third party engaged by Antifragile GRC to process Personal Data on behalf of the Customer.
Antifragile GRC processes Personal Data only to provide the compliance management platform described in the Terms of Service and only on documented instructions from the Customer.
| Category | Types of Personal Data | Purpose |
|---|---|---|
| Platform users | Name, email address, job title, login records | Account management, authentication, audit logging |
| Complaint records | Customer names, complaint details, contact information | Complaint tracking and resolution management |
| Conflict of interest | Employee names, declared relationships | Governance and conflict management |
| Audit findings | Assignee names, examiner references | Finding tracking and remediation management |
| Vendor contacts | Vendor representative names and contact details | Third-party risk management |
Antifragile GRC will:
You warrant that:
Antifragile GRC implements the following technical and organizational measures:
In the event of a security incident involving your Personal Data, Antifragile GRC will:
By accepting these Terms, you provide general written consent to our use of the following sub-processors. We will notify you of any changes to this list with at least 30 days' notice.
| Sub-processor | Location | Purpose |
|---|---|---|
| Railway (Railway Corp) | United States | Cloud hosting and database infrastructure |
| Google Workspace | United States | Email communications |
| Formspree | United States | Website inquiry form processing |
Each sub-processor is required to maintain data protection standards consistent with this DPA.
Where individuals exercise data subject rights (access, correction, deletion, portability) that relate to Personal Data processed through the Platform, we will assist you in fulfilling those requests. You are responsible for determining whether and how to respond to such requests.
To the extent Personal Data is accessible within the Platform, you can access, correct, or delete it directly. For requests requiring our assistance, contact support@antifragilegrc.com.
Personal Data is processed and stored in the United States. If you are subject to regulations governing international data transfers (such as GDPR for European operations), please contact us to discuss appropriate transfer mechanisms.
You may request, no more than once per year and with 30 days' written notice, a summary of our data protection practices or documentation demonstrating compliance with this DPA. We will respond to reasonable information requests within 30 days.
This DPA remains in effect for the duration of the subscription. Upon termination, Section 3's data deletion obligations apply: Personal Data is retained for 90 days for export, then permanently deleted.
In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA takes precedence.
Data protection inquiries:
support@antifragilegrc.com
Antifragile GRC LLC, Texas, United States