Data Processing Addendum
Formsort Inc. · Effective date: 09/04/2026 · Applies to the Rooks services
This Data Processing Addendum (“DPA”) forms part of the terms of service or other written agreement between Formsort Inc. (“Formsort,” “we,” “us”) and the customer identified in that agreement (“Customer,” “you”) governing your use of the Formsort or Rooks services, as applicable (the “Agreement”). This DPA is incorporated into the Agreement by reference and requires no signature. It applies where and only to the extent we process Customer Personal Data on your behalf in providing the services described in the Agreement (the “Services”). If you have executed a separate data processing agreement with us, that agreement governs to the extent it conflicts with this DPA.
1. Definitions
“Customer Personal Data” means personal information that we process on your behalf in providing the Services, including the forms you create, the data submitted through them by respondents, and the materials you submit to AI-powered features (however these are styled in the Agreement, e.g., “Form Data” and “Customer Materials”), in each case to the extent they contain personal information. Customer Personal Data does not include information we process as an independent business, such as your account, billing, usage, and builder-activity information, which is described in our Privacy Policy.
“US Privacy Laws” means U.S. state consumer privacy laws applicable to the Customer Personal Data in question, including the California Consumer Privacy Act as amended (“CCPA”), and comparable comprehensive state privacy laws. Terms such as “personal information,” “business,” “controller,” “service provider,” “processor,” “sell,” “share,” and “consumer” have the meanings given in the applicable US Privacy Laws.
“Sub-processor” means a third party we engage to process Customer Personal Data on our behalf in providing the Services.
“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data on systems we manage. Security Incidents do not include unsuccessful attempts such as blocked intrusions or port scans.
2. Roles and Scope
As between the parties, you are the business or controller of Customer Personal Data and we are your service provider or processor. You are responsible for the accuracy and lawfulness of Customer Personal Data, for providing all required notices to and obtaining any required consents from individuals (including form respondents), and for your instructions to us. Individuals who submit information through your forms should direct privacy requests to you; we will refer any such requests we receive to you as described in Section 5.
3. Our Processing Obligations
Instructions. We will process Customer Personal Data only for the purposes described in this Section (the “Permitted Purposes”) and in accordance with the Agreement and your documented instructions, unless required otherwise by law (in which case we will notify you unless legally prohibited).
Permitted Purposes. The Permitted Purposes are: (a) providing, maintaining, securing, and supporting the Services as described in the Agreement; (b) complying with law; and (c) the internal uses described in the Agreement, including any provisions addressing the use of data to improve the Services or AI features, in each case only as permitted for service providers and processors under US Privacy Laws. We do not provide data submitted by form respondents to AI model providers, as further described in the Agreement and the applicable Privacy Policy.
CCPA Certifications. We will not: (a) sell or share Customer Personal Data, or process it for targeted advertising or cross-context behavioral advertising; (b) retain, use, or disclose it for any purpose other than the Permitted Purposes, or outside the direct business relationship between us; or (c) combine it with personal information we receive from or on behalf of other customers, except as permitted for service providers under US Privacy Laws. We certify that we understand and will comply with these restrictions, and we will notify you if we determine we can no longer meet our obligations under US Privacy Laws, in which case you may take reasonable steps to stop and remediate any unauthorized processing.
Confidentiality. We limit access to Customer Personal Data to personnel who need it to perform the Services and who are bound by confidentiality obligations.
4. Sub-processors
You authorize us to engage Sub-processors to provide the Services. Our current Sub-processors for each of the Services are identified on our Subprocessor List at https://rooks.ai/subprocessors. We will update the list before adding or replacing a Sub-processor, and you may subscribe at that page to receive notice of changes. If you have a reasonable, good-faith objection to a new Sub-processor on data protection grounds, you may notify us within fifteen (15) days of the update; if we cannot offer a reasonable alternative, you may terminate the affected Services and receive a pro-rata refund of prepaid fees. We impose data protection obligations on Sub-processors that are no less protective than those in this DPA, and we remain responsible for their performance.
5. Assistance with Privacy Rights Requests
Taking into account the nature of the Services, we will assist you in responding to verifiable consumer and data subject requests (such as access, deletion, correction, and opt-out requests) concerning Customer Personal Data, primarily through the export, correction, and deletion capabilities of the Services. If an individual submits a request directly to us that identifies you, we will refer the individual to you and will not respond substantively except as required by law. We will provide reasonable additional assistance for requests you cannot fulfill through the Services, and we will reasonably assist you with data protection assessments to the extent required by US Privacy Laws and relevant to the Services.
6. Security and Security Incidents
We maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data, as summarized in Annex B. We may update these measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data. We will notify you without undue delay after confirming a Security Incident, and will provide information reasonably available to us about its nature and scope, the categories of data affected, and the measures taken, supplementing the notice as information becomes available. Our notice is not an admission of fault. You are responsible for any notifications required of you as the business or controller.
7. Audit Reports
Upon your reasonable written request (no more than once per year), we will make available information reasonably necessary to demonstrate our compliance with this DPA, which may include summaries of third-party audit reports or security certifications [e.g., SOC 2] and responses to written security questionnaires. This information is our Proprietary Information under the Agreement.
8. Deletion and Return of Data
You can export Customer Personal Data through the Services at any time during the term. Following termination of the Agreement, export and deletion are handled as described in the Agreement, including the post-termination export period stated there, after which we will delete Customer Personal Data, except where retention is required by law or expressly provided in the Agreement (including audit and compliance records we retain under HIPAA). Data retained under these exceptions remains subject to this DPA and is deleted when the retention purpose ends. Deletion from backup systems occurs in the ordinary course of our backup cycles.
9. De-identified Data
Where we process de-identified or aggregated data derived from Customer Personal Data (such as Form Analytics described in the Agreement), we will maintain and use it only in de-identified form and will not attempt to re-identify it, except as permitted by US Privacy Laws to test the effectiveness of de-identification.
10. Protected Health Information
Where we process protected health information subject to HIPAA on your behalf, the Business Associate Agreement between us governs that information and controls over this DPA to the extent of any conflict. For customers with a Business Associate Agreement, the Business Associate Agreement continues to apply in accordance with its terms, and this DPA governs Customer Personal Data and processing activities outside its scope.
11. Processing Location; European Data
We process Customer Personal Data in the United States. The Services are not directed to individuals in the European Economic Area, the United Kingdom, or Switzerland. If your use of the Services becomes subject to European data protection law, the parties will in good faith execute such additional terms (including Article 28 terms and applicable standard contractual clauses) as that law requires before any such processing.
12. General
This DPA is subject to the limitations of liability in the Agreement, and each party’s liability arising out of this DPA is subject to those limitations in the aggregate together with liability under the Agreement. If this DPA conflicts with the Agreement with respect to the processing of Customer Personal Data, this DPA controls. We may update this DPA in accordance with the change provisions of the Agreement; updates will not materially reduce the protections for Customer Personal Data during your then-current subscription term. This DPA terminates automatically when we cease to process Customer Personal Data on your behalf.
Annex A — Details of Processing
Subject matter and duration: Processing of Customer Personal Data to provide the Services for the term of the Agreement, plus the export and retention periods described in the Agreement.
Nature and purposes: Hosting and storage of forms and submitted form data; form building, deployment, and management, including AI-assisted form creation as described in the Agreement; support; security; and the other Permitted Purposes in Section 3.
Categories of individuals: Your form respondents (such as patients, applicants, or other end users) and your personnel who appear in the forms, submitted form data, or materials you provide.
Categories of data: Personal information contained in forms, submitted form data, and materials you provide, as determined and submitted by you. Sensitive information is permitted only as provided in the Agreement (including any Business Associate Agreement).
Annex B — Summary of Security Measures
Encryption of Customer Personal Data in transit and at rest
Access controls: role-based access, least-privilege provisioning, and authentication requirements for personnel; form responses are not accessible to Formsort personnel in the ordinary course of operations
Logical separation of customer data; audit logging of access to production systems
Vulnerability management, including patching and periodic security testing
Personnel security: confidentiality obligations and security training
Incident response procedures, including detection, escalation, and notification
Vendor management: security and data protection review of Sub-processors
Business continuity: backups and recovery procedures