Effective date: August 23, 2026 · Version: 1.0
This Data Processing Addendum (this "DPA") forms part of the Terms of Service (together with the documents they incorporate, the "Agreement") between Crescendo Labs AI, Inc. ("CrescendoLabs," "we," "us," "our") and the Customer ("you," "your"). It applies to the extent CrescendoLabs processes Customer Personal Data (defined below) on your behalf as your service provider / processor in providing the Services (Privacy Policy §1 — our processor role).
Incorporation; execution. This DPA is automatically incorporated into the Agreement and applies to every Customer — no signature is required for it to take effect. If your compliance, vendor-review, or regulatory process requires an executed copy, the parties may execute the signature blocks at the end of this DPA; execution does not change its terms.
Order of precedence. If there is a conflict between this DPA and the rest of the Agreement with respect to the processing of Customer Personal Data, this DPA controls; the Agreement otherwise controls (including the Limitation of Liability — see §12).
Roles. For Customer Personal Data, you are the "business"/controller and CrescendoLabs is your "service provider"/processor. You are responsible for the accuracy and lawfulness of the Customer Personal Data you provide or connect and for the rights and consents required for it (ToS §7).
Scope. The subject matter, duration, nature, and purpose of the processing, and the categories of data and data subjects, are described in Annex A.
Instructions. CrescendoLabs will process Customer Personal Data only on your documented instructions, which consist of: (a) the Agreement (including this DPA); (b) your and your Authorized Users' use and configuration of the Services (including the integrations you enable); and (c) other written instructions the parties agree to in writing. CrescendoLabs will notify you if, in its opinion, an instruction violates Applicable Data Protection Laws (and may suspend the affected processing until the instruction is resolved).
To the extent the CCPA or another Applicable Data Protection Law applies to Customer Personal Data, CrescendoLabs:
CrescendoLabs ensures that personnel authorized to process Customer Personal Data are bound by written or statutory confidentiality obligations and access Customer Personal Data only as needed to provide the Services (least-privilege — Annex B).
CrescendoLabs maintains reasonable technical and organizational measures designed to protect Customer Personal Data against a Security Incident, as described in Annex B. CrescendoLabs may update these measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data. You are responsible for your own account security obligations (ToS §4), including credential safeguarding and your configuration choices.
General authorization; list. You provide general authorization for CrescendoLabs to engage Sub-processors to provide the Services. The current Sub-processor list — including our AI Service Providers — is published at https://crescendolabs.ai/legal/subprocessors and is incorporated into this DPA.
Flow-down. CrescendoLabs will impose on each Sub-processor written data-protection obligations that are no less protective than those in this DPA with respect to Customer Personal Data, including confidentiality, security, and the no-re-identification commitment (§11), and CrescendoLabs remains responsible to you for each Sub-processor's performance. In particular, CrescendoLabs contractually requires its AI Service Providers not to use your Customer Data to train their own models (ToS §11(e)).
Changes. CrescendoLabs will update the published list before adding or replacing a Sub-processor and will provide notice of the change (e.g., by updating the list with a mechanism to receive notifications, by email, or in-product). If you have a reasonable, data-protection-based objection to a new Sub-processor, you may notify us within 30 days of the notice, and the parties will work in good faith to resolve the objection; if it cannot be resolved, you may terminate the affected Services and receive a refund of prepaid unused fees for them.
Connected third-party services are not Sub-processors. Third-party services that you or your Authorized Users connect to the Services (for example, your accounting, banking, or workspace providers — ToS §9) act under your own agreements with them and are not engaged by CrescendoLabs to process Customer Personal Data on its behalf. They are not Sub-processors under this DPA; their availability, terms, and any changes they make are governed by ToS §9, and CrescendoLabs' obligations under this DPA apply to Customer Personal Data only while it is within the Services.
If CrescendoLabs becomes aware of a Security Incident, CrescendoLabs will notify you without undue delay, and in any event within 48 hours after CrescendoLabs confirms the Security Incident affecting your Customer Personal Data. For a Security Incident originating on a Sub-processor's systems, CrescendoLabs is deemed to confirm it when it receives the Sub-processor's notice. The notice will describe, to the extent then known: the nature of the incident, the categories and approximate volume of Customer Personal Data affected, the measures taken or planned to address it, and a contact point. CrescendoLabs will take reasonable steps to contain and remediate the incident and will provide timely updates as material information becomes available.
Notification is not an acknowledgment of fault or liability. You are responsible for your own notification obligations to individuals, regulators, carriers, broker-dealers, or other parties arising from your use of the Services — the 48-hour notice is designed to give you time to meet them.
If CrescendoLabs receives a request from an individual (e.g., your customer or employee) to exercise privacy rights regarding Customer Personal Data, CrescendoLabs will direct the individual to you and will not respond substantively except to confirm that the request should be made to you, or as required by law (Privacy Policy §11). Taking into account the nature of the processing, CrescendoLabs will provide reasonable assistance — including through the Services' export, correction, and deletion capabilities — to help you respond to consumer requests and meet your security, breach-notification, and risk-assessment obligations under Applicable Data Protection Laws.
On your written request (no more than once per 12-month period, absent a Security Incident affecting your data or a regulator's requirement — in which case any additional review remains in the form described in this Section), CrescendoLabs will make available information reasonably necessary to demonstrate compliance with this DPA — such as its then-current security documentation, third-party attestations and audit summaries as they become available, and responses to reasonable written security questionnaires. This Section is the agreed mechanism for audits under Applicable Data Protection Laws; on-site audits are not offered for the self-serve Services.
During the term. The Services provide export capabilities for your Customer Data.
After termination. CrescendoLabs will make your Customer Data available for export for 30 days after termination (ToS §15), after which CrescendoLabs will delete or de-identify Customer Personal Data — except records CrescendoLabs is required or permitted to archive under the Agreement (e.g., to comply with law, tax and recordkeeping obligations, dispute resolution, and fraud prevention, and the append-only audit records described in the Privacy Policy §8), which remain protected under this DPA for as long as they are retained.
De-Identified Data. CrescendoLabs may create and retain De-Identified Data as permitted by the Agreement (ToS §8, §11(c); Privacy Policy §8). CrescendoLabs will not attempt to re-identify De-Identified Data and will contractually require its Sub-processors not to do so. Once de-identified, that data is no longer Customer Personal Data.
This DPA is effective while the Agreement is in effect and for as long as CrescendoLabs processes Customer Personal Data. Each party's liability arising out of or relating to this DPA is subject to the Limitation of Liability in ToS §17, and this DPA does not create a separate or additional liability cap — all claims under the Agreement and this DPA count toward the same aggregate cap.
The Services are offered in, and operated from, the United States for US businesses (ToS §4), and this DPA is scoped to US law accordingly. If your use of the Services becomes subject to the data-protection laws of another jurisdiction (for example, the EU or UK GDPR), the parties will cooperate in good faith to execute the additional terms required (e.g., standard contractual clauses or a GDPR processor module) before any processing subject to those laws begins.
Subject matter & nature. Hosting, storage, capture into structured Business Records, automated analysis, display, export, and transmission of Customer Data as needed to provide the Services described in the Agreement (ToS §6, §11).
Purpose. Providing, securing, supporting, and improving the Services for you, as permitted by the Agreement — including generating Insights and Recommendations from your own Business Records and creating De-Identified Data (ToS §8, §11).
Duration. The Subscription term, plus the 30-day post-termination export window, plus any archival retention permitted by the Agreement (§11 above).
Categories of data subjects. Your customers, prospects, and end clients; your vendors and suppliers; your personnel (employees and contractors), including Authorized Users to the extent their information appears in Customer Data.
Categories of Customer Personal Data. Identifiers and contact details (names, emails, phone numbers, postal addresses); commercial and financial records (customers, vendors, invoices, bills, payments, and — from financial-account connections — balances, transactions, account type, and at most masked account numbers); professional and employment information; and, where you choose to record it, work-authorization status and voluntary EEO / demographic information (sensitive — kept segregated and access-logged, per Privacy Policy §2).
Data not permitted in the Services (AUP §3(g); Privacy Policy §2): full payment-card data outside the designated payment processor; protected health information subject to HIPAA absent a signed BAA; personal information of children under 13; Social Security or other government ID numbers; full financial-account or routing numbers; and online-banking login credentials.
CrescendoLabs maintains, at a minimum, the following measures for the production Services.
This DPA is effective by incorporation into the Agreement without signature. Executed at a party's request:
Crescendo Labs AI, Inc. — Signature: ______________ Name: ______________ Title: ______________ Date: ______
Customer (legal name): ______________ — Signature: ______________ Name: ______________ Title: ______________ Date: ______