Legal

CrescendoLabs Data Processing Addendum

Effective date: August 23, 2026 · Version: 1.0


1. Introduction; Incorporation; Order of Precedence

This Data Processing Addendum (this "DPA") forms part of the Terms of Service (together with the documents they incorporate, the "Agreement") between Crescendo Labs AI, Inc. ("CrescendoLabs," "we," "us," "our") and the Customer ("you," "your"). It applies to the extent CrescendoLabs processes Customer Personal Data (defined below) on your behalf as your service provider / processor in providing the Services (Privacy Policy §1 — our processor role).

Incorporation; execution. This DPA is automatically incorporated into the Agreement and applies to every Customer — no signature is required for it to take effect. If your compliance, vendor-review, or regulatory process requires an executed copy, the parties may execute the signature blocks at the end of this DPA; execution does not change its terms.

Order of precedence. If there is a conflict between this DPA and the rest of the Agreement with respect to the processing of Customer Personal Data, this DPA controls; the Agreement otherwise controls (including the Limitation of Liability — see §12).

2. Definitions

  • "Applicable Data Protection Laws" — the US federal and state privacy and data-protection laws that apply to a party's processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the CPRA ("CCPA") and other comprehensive US state privacy laws, and, to the extent applicable to Customer Data from financial-account connections, the Gramm-Leach-Bliley Act ("GLBA").
  • "Customer Personal Data" — Personal Information contained in Customer Data that CrescendoLabs processes on your behalf in providing the Services. It does not include the account, billing, and usage information for which CrescendoLabs is the "business"/controller (Privacy Policy §1 — that data is governed by the Privacy Policy directly).
  • "Security Incident" — a confirmed breach of CrescendoLabs' security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It does not include unsuccessful attempts (e.g., blocked attacks, port scans, or failed log-ins).
  • "Sub-processor" — a third party engaged by CrescendoLabs that processes Customer Personal Data to help provide the Services.
  • "process" / "processing," "business," "service provider," "controller," "processor," "sell," "share" — as defined in Applicable Data Protection Laws.

3. Roles; Scope of Processing; Instructions

Roles. For Customer Personal Data, you are the "business"/controller and CrescendoLabs is your "service provider"/processor. You are responsible for the accuracy and lawfulness of the Customer Personal Data you provide or connect and for the rights and consents required for it (ToS §7).

Scope. The subject matter, duration, nature, and purpose of the processing, and the categories of data and data subjects, are described in Annex A.

Instructions. CrescendoLabs will process Customer Personal Data only on your documented instructions, which consist of: (a) the Agreement (including this DPA); (b) your and your Authorized Users' use and configuration of the Services (including the integrations you enable); and (c) other written instructions the parties agree to in writing. CrescendoLabs will notify you if, in its opinion, an instruction violates Applicable Data Protection Laws (and may suspend the affected processing until the instruction is resolved).

4. CCPA Service-Provider Commitments

To the extent the CCPA or another Applicable Data Protection Law applies to Customer Personal Data, CrescendoLabs:

  • (a) will not sell or share Customer Personal Data;
  • (b) will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and Annex A (including the specific business purposes of providing, securing, and improving the Services, and creating De-Identified Data used to provide the Services' benchmarking and analytical features), or as otherwise permitted for service providers under Applicable Data Protection Laws;
  • (c) will not retain, use, or disclose Customer Personal Data outside of the direct business relationship between the parties;
  • (d) will not combine Customer Personal Data with personal information it receives from other sources, except as permitted for service providers under Applicable Data Protection Laws (including to detect security incidents and protect against fraudulent or illegal activity, and to create De-Identified Data as permitted by the Agreement — ToS §8, §11(c));
  • (e) certifies that it understands and will comply with the restrictions in this Section 4;
  • (f) will notify you if it determines it can no longer meet its obligations under Applicable Data Protection Laws, in which case you may take the reasonable and appropriate steps provided by those laws to stop and remediate any unauthorized use of Customer Personal Data; and
  • (g) will grant you the rights, and provide the assistance, that Applicable Data Protection Laws require a service-provider contract to provide.

5. Confidentiality

CrescendoLabs ensures that personnel authorized to process Customer Personal Data are bound by written or statutory confidentiality obligations and access Customer Personal Data only as needed to provide the Services (least-privilege — Annex B).

6. Security

CrescendoLabs maintains reasonable technical and organizational measures designed to protect Customer Personal Data against a Security Incident, as described in Annex B. CrescendoLabs may update these measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data. You are responsible for your own account security obligations (ToS §4), including credential safeguarding and your configuration choices.

7. Sub-processors

General authorization; list. You provide general authorization for CrescendoLabs to engage Sub-processors to provide the Services. The current Sub-processor list — including our AI Service Providers — is published at https://crescendolabs.ai/legal/subprocessors and is incorporated into this DPA.

Flow-down. CrescendoLabs will impose on each Sub-processor written data-protection obligations that are no less protective than those in this DPA with respect to Customer Personal Data, including confidentiality, security, and the no-re-identification commitment (§11), and CrescendoLabs remains responsible to you for each Sub-processor's performance. In particular, CrescendoLabs contractually requires its AI Service Providers not to use your Customer Data to train their own models (ToS §11(e)).

Changes. CrescendoLabs will update the published list before adding or replacing a Sub-processor and will provide notice of the change (e.g., by updating the list with a mechanism to receive notifications, by email, or in-product). If you have a reasonable, data-protection-based objection to a new Sub-processor, you may notify us within 30 days of the notice, and the parties will work in good faith to resolve the objection; if it cannot be resolved, you may terminate the affected Services and receive a refund of prepaid unused fees for them.

Connected third-party services are not Sub-processors. Third-party services that you or your Authorized Users connect to the Services (for example, your accounting, banking, or workspace providers — ToS §9) act under your own agreements with them and are not engaged by CrescendoLabs to process Customer Personal Data on its behalf. They are not Sub-processors under this DPA; their availability, terms, and any changes they make are governed by ToS §9, and CrescendoLabs' obligations under this DPA apply to Customer Personal Data only while it is within the Services.

8. Security Incident Notification

If CrescendoLabs becomes aware of a Security Incident, CrescendoLabs will notify you without undue delay, and in any event within 48 hours after CrescendoLabs confirms the Security Incident affecting your Customer Personal Data. For a Security Incident originating on a Sub-processor's systems, CrescendoLabs is deemed to confirm it when it receives the Sub-processor's notice. The notice will describe, to the extent then known: the nature of the incident, the categories and approximate volume of Customer Personal Data affected, the measures taken or planned to address it, and a contact point. CrescendoLabs will take reasonable steps to contain and remediate the incident and will provide timely updates as material information becomes available.

Notification is not an acknowledgment of fault or liability. You are responsible for your own notification obligations to individuals, regulators, carriers, broker-dealers, or other parties arising from your use of the Services — the 48-hour notice is designed to give you time to meet them.

9. Consumer Requests; Assistance

If CrescendoLabs receives a request from an individual (e.g., your customer or employee) to exercise privacy rights regarding Customer Personal Data, CrescendoLabs will direct the individual to you and will not respond substantively except to confirm that the request should be made to you, or as required by law (Privacy Policy §11). Taking into account the nature of the processing, CrescendoLabs will provide reasonable assistance — including through the Services' export, correction, and deletion capabilities — to help you respond to consumer requests and meet your security, breach-notification, and risk-assessment obligations under Applicable Data Protection Laws.

10. Audits & Information

On your written request (no more than once per 12-month period, absent a Security Incident affecting your data or a regulator's requirement — in which case any additional review remains in the form described in this Section), CrescendoLabs will make available information reasonably necessary to demonstrate compliance with this DPA — such as its then-current security documentation, third-party attestations and audit summaries as they become available, and responses to reasonable written security questionnaires. This Section is the agreed mechanism for audits under Applicable Data Protection Laws; on-site audits are not offered for the self-serve Services.

11. Return, Export & Deletion; De-Identified Data; No Re-identification

During the term. The Services provide export capabilities for your Customer Data.

After termination. CrescendoLabs will make your Customer Data available for export for 30 days after termination (ToS §15), after which CrescendoLabs will delete or de-identify Customer Personal Data — except records CrescendoLabs is required or permitted to archive under the Agreement (e.g., to comply with law, tax and recordkeeping obligations, dispute resolution, and fraud prevention, and the append-only audit records described in the Privacy Policy §8), which remain protected under this DPA for as long as they are retained.

De-Identified Data. CrescendoLabs may create and retain De-Identified Data as permitted by the Agreement (ToS §8, §11(c); Privacy Policy §8). CrescendoLabs will not attempt to re-identify De-Identified Data and will contractually require its Sub-processors not to do so. Once de-identified, that data is no longer Customer Personal Data.

12. Term; Liability

This DPA is effective while the Agreement is in effect and for as long as CrescendoLabs processes Customer Personal Data. Each party's liability arising out of or relating to this DPA is subject to the Limitation of Liability in ToS §17, and this DPA does not create a separate or additional liability cap — all claims under the Agreement and this DPA count toward the same aggregate cap.

13. Non-US Data Protection Laws

The Services are offered in, and operated from, the United States for US businesses (ToS §4), and this DPA is scoped to US law accordingly. If your use of the Services becomes subject to the data-protection laws of another jurisdiction (for example, the EU or UK GDPR), the parties will cooperate in good faith to execute the additional terms required (e.g., standard contractual clauses or a GDPR processor module) before any processing subject to those laws begins.


Annex A — Details of Processing

Subject matter & nature. Hosting, storage, capture into structured Business Records, automated analysis, display, export, and transmission of Customer Data as needed to provide the Services described in the Agreement (ToS §6, §11).

Purpose. Providing, securing, supporting, and improving the Services for you, as permitted by the Agreement — including generating Insights and Recommendations from your own Business Records and creating De-Identified Data (ToS §8, §11).

Duration. The Subscription term, plus the 30-day post-termination export window, plus any archival retention permitted by the Agreement (§11 above).

Categories of data subjects. Your customers, prospects, and end clients; your vendors and suppliers; your personnel (employees and contractors), including Authorized Users to the extent their information appears in Customer Data.

Categories of Customer Personal Data. Identifiers and contact details (names, emails, phone numbers, postal addresses); commercial and financial records (customers, vendors, invoices, bills, payments, and — from financial-account connections — balances, transactions, account type, and at most masked account numbers); professional and employment information; and, where you choose to record it, work-authorization status and voluntary EEO / demographic information (sensitive — kept segregated and access-logged, per Privacy Policy §2).

Data not permitted in the Services (AUP §3(g); Privacy Policy §2): full payment-card data outside the designated payment processor; protected health information subject to HIPAA absent a signed BAA; personal information of children under 13; Social Security or other government ID numbers; full financial-account or routing numbers; and online-banking login credentials.

Annex B — Technical & Organizational Security Measures

CrescendoLabs maintains, at a minimum, the following measures for the production Services.

  • Tenant isolation. Every customer's data is segregated per-tenant, with isolation enforced at the database layer on every query — configured fail-closed, so a request without a valid tenant context returns nothing rather than another tenant's data.
  • Encryption. Customer Data is encrypted in transit (TLS) and at rest; database connections are restricted to encrypted channels. Sensitive client documents are additionally protected with field-level AES-256-GCM encryption.
  • Access control & authentication. Multi-factor authentication is enforced platform-wide for every user — it cannot be disabled by tenants. Access within a customer account follows least-privilege, role- and scope-based controls; internal administrative access is restricted, logged, and follows least-privilege service accounts.
  • Auditability. Security- and data-relevant actions are recorded in an append-only, tamper-evident audit log enforced at the database level (records cannot be modified or deleted, including by CrescendoLabs).
  • Secrets management. Credentials and keys are stored in a managed secrets service, never in code or configuration files.
  • Sub-processor minimization. Each Sub-processor receives only the data needed to perform its function; AI Service Providers are contractually barred from training their models on Customer Data.
  • Personnel. Access limited to personnel who need it, under confidentiality obligations (§5).
  • Resilience & data protection. Managed cloud infrastructure with automated backups and point-in-time recovery for the primary database.

Execution (optional — see §1)

This DPA is effective by incorporation into the Agreement without signature. Executed at a party's request:

Crescendo Labs AI, Inc. — Signature: ______________ Name: ______________ Title: ______________ Date: ______

Customer (legal name): ______________ — Signature: ______________ Name: ______________ Title: ______________ Date: ______