Legal

Data Processing Agreement

Effective date: May 18, 2026 · Antifragile GRC LLC, a Texas limited liability company

Who this is for: This Data Processing Agreement ("DPA") applies to all customers who use the Antifragile GRC platform and supplements the Terms of Service. It governs how we process personal data on your behalf as your service provider.

1. Definitions

"Controller" means the Customer — the financial institution that determines the purposes and means of processing personal data.

"Processor" means Antifragile GRC LLC, acting on the Controller's instructions.

"Personal Data" means any information relating to an identified or identifiable natural person that is processed through the Platform. In the context of a bank compliance program, this may include employee names and contact details, customer complaint records, conflict of interest declarations, and audit finding assignments.

"Processing" means any operation performed on Personal Data, including storage, retrieval, use, and deletion.

"Sub-processor" means any third party engaged by Antifragile GRC to process Personal Data on behalf of the Customer.

2. Scope and purpose of processing

Antifragile GRC processes Personal Data only to provide the compliance management platform described in the Terms of Service and only on documented instructions from the Customer.

CategoryTypes of Personal DataPurpose
Platform usersName, email address, job title, login recordsAccount management, authentication, audit logging
Complaint recordsCustomer names, complaint details, contact informationComplaint tracking and resolution management
Conflict of interestEmployee names, declared relationshipsGovernance and conflict management
Audit findingsAssignee names, examiner referencesFinding tracking and remediation management
Vendor contactsVendor representative names and contact detailsThird-party risk management

3. Our obligations as processor

Antifragile GRC will:

4. Your obligations as controller

You warrant that:

5. Security measures

Antifragile GRC implements the following technical and organizational measures:

6. Data breach notification

In the event of a security incident involving your Personal Data, Antifragile GRC will:

7. Sub-processors

By accepting these Terms, you provide general written consent to our use of the following sub-processors. We will notify you of any changes to this list with at least 30 days' notice.

Sub-processorLocationPurpose
Railway (Railway Corp)United StatesCloud hosting and database infrastructure
Google WorkspaceUnited StatesEmail communications
FormspreeUnited StatesWebsite inquiry form processing

Each sub-processor is required to maintain data protection standards consistent with this DPA.

8. Data subject rights

Where individuals exercise data subject rights (access, correction, deletion, portability) that relate to Personal Data processed through the Platform, we will assist you in fulfilling those requests. You are responsible for determining whether and how to respond to such requests.

To the extent Personal Data is accessible within the Platform, you can access, correct, or delete it directly. For requests requiring our assistance, contact support@antifragilegrc.com.

9. International transfers

Personal Data is processed and stored in the United States. If you are subject to regulations governing international data transfers (such as GDPR for European operations), please contact us to discuss appropriate transfer mechanisms.

10. Audit rights

You may request, no more than once per year and with 30 days' written notice, a summary of our data protection practices or documentation demonstrating compliance with this DPA. We will respond to reasonable information requests within 30 days.

11. Term and termination

This DPA remains in effect for the duration of the subscription. Upon termination, Section 3's data deletion obligations apply: Personal Data is retained for 90 days for export, then permanently deleted.

12. Order of precedence

In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA takes precedence.

13. Contact

Data protection inquiries:
support@antifragilegrc.com
Antifragile GRC LLC, Texas, United States