Data Processing Addendum

CrossCode — Data Processing Addendum
Version 1.1 · Effective 2026-06-22

Capitalized terms not defined in this document have the meanings given in our Terms of Service.


CrossCode, Inc. — Data Processing Addendum Effective Date: 2026-06-22 (Version 1.1)

This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement between CrossCode, Inc. ("CrossCode," "Processor") and Customer ("Controller") (the "Agreement"). This DPA applies to the extent CrossCode processes Personal Data on behalf of Customer in connection with the Services.

1. Definitions

Terms used but not defined in this DPA have the meanings given in the Agreement or in applicable Data Protection Laws.

  • "Controller," "Processor," "Data Subject," "Personal Data," "Process" / "Processing," and "Supervisory Authority" have the meanings given in the GDPR.
  • "Business," "Service Provider," and "Personal Information" have the meanings given in the CCPA/CPRA.
  • "SCCs" means the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
  • "Data Protection Laws" has the meaning given in the Master Glossary.

2. Roles and Scope

2.1 Roles. With respect to Personal Data processed in connection with the Services, Customer is the Controller (or, where Customer is itself a processor, the processor acting on behalf of its own controllers), and CrossCode is the Processor. With respect to CCPA/CPRA, Customer is the Business and CrossCode is the Service Provider.

2.2 Scope and Instructions. CrossCode will Process Personal Data only on documented instructions from Customer, as set out in the Agreement, this DPA, the Order Form, and any subsequent written instructions agreed by the Parties. If CrossCode is required by law to Process Personal Data otherwise, CrossCode will notify Customer of that legal requirement before Processing, unless that law prohibits such notification on important public interest grounds.

2.3 CCPA/CPRA Service Provider Terms. CrossCode (a) will not "sell" or "share" Personal Information as defined under CCPA/CPRA; (b) will not retain, use, or disclose Personal Information for any purpose other than the specific purpose of performing the Services or as otherwise permitted by CCPA/CPRA; (c) will not retain, use, or disclose Personal Information outside the direct business relationship between CrossCode and Customer; (d) will not combine Personal Information received from Customer with Personal Information from other sources, except as permitted by 11 CCR § 7050(b); and (e) certifies that it understands and will comply with these restrictions.

3. Processing Details (Annex I)

3.1 Subject Matter. Provision of the Services described in the Agreement.

3.2 Duration. The Subscription Term, plus retention periods specified in Section 5 of the Privacy Policy and Section 7.4 of the Agreement.

3.3 Nature and Purpose. Hosting, processing, and analysis of commercial-trade documents and related information to provide AI-assisted HTS classification, duty calculation, and compliance support.

3.4 Categories of Data Subjects.

  • Customer's Authorized Users (employees, contractors of Customer).
  • Individuals named in commercial documents submitted to the Services (e.g., contact persons identified on commercial invoices, shipping documents, or import-export filings).

3.5 Categories of Personal Data.

  • Identification and contact data of Authorized Users (name, business email, business phone, employer, title, authentication credentials).
  • Limited identification data appearing on commercial documents (e.g., point-of-contact names at supplier or importer organizations).
  • Technical and usage data (IP address, device and browser identifiers, log data).

3.6 Special Categories. None intentionally processed. Customer agrees not to submit special category data, criminal conviction data, or other sensitive categories defined by Data Protection Laws to the Services.

3.7 Frequency of Transfers. Continuous.

3.8 Period of Retention. As set forth in Section 5 of the Privacy Policy and Section 7.4 of the Agreement.

4. Confidentiality

CrossCode ensures that personnel authorized to Process Personal Data are bound by written or statutory obligations of confidentiality, are trained in data protection, and access Personal Data only on a need-to-know basis under documented access controls.

5. Security (Annex II)

CrossCode implements and maintains the technical and organizational measures set forth in Annex II below. CrossCode may update Annex II from time to time, provided the overall level of protection is not materially reduced.

6. Sub-Processors

6.1 General Authorization. Customer provides general authorization for CrossCode to engage Sub-processors to Process Personal Data, subject to this Section.

6.2 Current Sub-Processors. The current list of Sub-processors is maintained at crosscode.pro/subprocessors and reproduced in Document 7 of the package.

6.3 New Sub-Processors. CrossCode will provide at least thirty (30) days' prior notice of any new Sub-processor (by update to the public list and, where Customer has subscribed, by email). Customer may object on reasonable data-protection grounds within thirty (30) days; the Parties will work together in good faith to address the objection, and if not resolved, Customer's sole remedy is to terminate the affected Order Form for convenience and receive a refund of pre-paid, unused fees attributable to the period after termination.

6.4 Sub-Processor Obligations. CrossCode will impose written obligations on each Sub-processor that are no less protective than this DPA and will remain liable to Customer for each Sub-processor's acts and omissions to the extent set forth in the Agreement.

7. International Transfers

7.1 Mechanism. Where Customer transfers Personal Data subject to the GDPR or UK GDPR to CrossCode, the SCCs are hereby incorporated by reference as follows:

  • Module 2 (Controller to Processor) applies where Customer is a Controller and CrossCode is a Processor.
  • Module 3 (Processor to Processor) applies where Customer is a Processor and CrossCode is a Sub-processor to Customer.

7.2 SCC Details. For purposes of the SCCs: Clause 7 (the docking clause) applies, permitting additional entities to accede as a data exporter or data importer by executing the accession addendum to the SCCs; in Clause 9, Option 2 (general authorization) applies with the notice period in Section 6.3; in Clause 11, the optional independent dispute resolution body redress mechanism does not apply; in Clause 17, the governing law is the law of the Republic of Ireland; in Clause 18, the forum is the courts of the Republic of Ireland. Annex I to the SCCs is populated by reference to Section 3 above and the Sub-Processor List. Annex II to the SCCs is populated by reference to Annex II below.

7.3 UK. Where transfers are subject to the UK GDPR, the UK International Data Transfer Addendum (Version B1.0) issued by the UK Information Commissioner's Office and laid before Parliament on 2 February 2022 is incorporated by reference and amends the SCCs accordingly. The Importer's and Exporter's signatures to this DPA are deemed signatures to the UK Addendum.

7.4 Swiss. Where transfers are subject to the Swiss Federal Act on Data Protection (FADP), the SCCs apply with the following modifications: references to the GDPR are interpreted as references to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; and Data Subjects in Switzerland have the right to enforce the SCCs.

8. Assistance to Customer

8.1 Data Subject Requests. Taking into account the nature of the Processing, CrossCode will, by appropriate technical and organizational measures, assist Customer in fulfilling its obligation to respond to requests by Data Subjects exercising rights under Data Protection Laws. CrossCode will promptly notify Customer if it receives a Data Subject request directed to Customer Data and will not respond directly except to confirm that the request has been forwarded to Customer.

8.2 DPIAs and Prior Consultation. CrossCode will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities, at Customer's expense for non-trivial requests.

9. Personal Data Breach Notification

CrossCode will notify Customer without undue delay and in any event within seventy-two (72) hours after becoming aware of a confirmed Personal Data Breach affecting Customer's Personal Data. The notification will include the information required by Article 33(3) GDPR to the extent then known and will be updated as additional information becomes available. CrossCode will cooperate with Customer in investigating and remediating the breach.

10. Audit Rights

10.1 Information. CrossCode will make available to Customer the information necessary to demonstrate compliance with this DPA, including responses to reasonable security questionnaires.

10.2 Third-Party Reports. Once CrossCode obtains a SOC 2 Type II report or equivalent independent attestation (target: within 24 months of the Effective Date), CrossCode will provide such report under NDA in lieu of on-site audit.

10.3 On-Site Audit. Until such third-party report is available, Customer may, no more than once per twelve-month period and on at least thirty (30) days' prior written notice, conduct an audit of CrossCode's compliance with this DPA. The audit will be conducted during business hours, will not unreasonably interfere with CrossCode's operations, will be subject to confidentiality, and will exclude any information of other customers, source code, and security measures whose disclosure would create vulnerability. Customer bears its own costs and, if it engages a third-party auditor, the auditor's costs and must execute confidentiality terms reasonably acceptable to CrossCode.

11. Return or Deletion

Upon termination of the Agreement, CrossCode will, at Customer's choice, return or delete Personal Data within the periods set forth in Section 7.4 of the Agreement, except to the extent retention is required by law or by the recordkeeping support provision in Section 7.4(c) of the Agreement. CrossCode will certify deletion upon request.

12. Liability

The liability provisions of the Agreement (including the limitations of liability in Section 13) apply to this DPA. Where the SCCs apply and impose liability that exceeds the cap in the Agreement, the cap in the SCCs governs as to Data Subject claims under the SCCs.

13. Order of Precedence

In the event of conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Personal Data. In the event of conflict between this DPA and the SCCs, the SCCs control.

14. Term

This DPA is effective for the duration of the Agreement and survives termination to the extent CrossCode continues to Process Personal Data.


Annex II — Technical and Organizational Measures

CrossCode implements the following measures, calibrated to the nature of the Personal Data Processed and the risks presented by the Processing. CrossCode may update these measures from time to time provided that the overall level of protection is not materially reduced.

1. Encryption. (a) In transit: TLS 1.2 or higher for all external traffic, including to and from Sub-processors that support TLS. (b) At rest: AES-256 for production databases and object storage.

2. Access Controls. (a) Role-based access control on principle of least privilege; documented joiner/mover/leaver process. (b) Multi-factor authentication required for all employee access to production systems and Customer Data. (c) Quarterly access reviews of production systems. (d) Centralized identity provider for human access.

3. Network and Host Security. (a) Production environment segregated from development; no Customer Data in development or test environments without de-identification. (b) Vulnerability scanning of production systems at least monthly. (c) Annual third-party penetration test once SOC 2 process is underway (target within 12 months of Effective Date). (d) Patch management with documented SLAs (critical: 7 days; high: 30 days).

4. Application Security. (a) Secure development lifecycle aligned with OWASP ASVS Level 2. (b) Mandatory code review prior to merge to main. (c) Dependency scanning with documented remediation SLAs. (d) Prompt-injection and adversarial-input testing as part of the AI model release process.

5. Logging and Monitoring. (a) Centralized logging of access to Customer Data and production systems, retained for 24 months. (b) Alerting on anomalous access and authentication events. (c) Documented incident response runbook.

6. Backup and Resilience. (a) Daily backups of production data, encrypted and stored in a separate cloud region. (b) Documented recovery time and point objectives reviewed annually.

7. Personnel. (a) Background checks (US right-to-work plus criminal background where lawful) on all employees with production access. (b) Confidentiality and IP assignment obligations under written employment or contractor agreements. (c) Annual security and privacy awareness training; targeted AI safety training for engineers working on the classification pipeline.

8. Sub-Processor Management. (a) Written contracts imposing materially equivalent security and privacy obligations. (b) Pre-engagement security questionnaire and SOC 2 / ISO 27001 review (where available). (c) Annual review of critical Sub-processors.

9. AI-Specific Controls. (a) CrossCode does not use Customer Data (including any Submission, Customer-identifiable Output, or Customer-identifiable record) to train, retrain, fine-tune, evaluate, benchmark, or otherwise improve any artificial intelligence or machine-learning model, including any foundation model, classifier, retrieval index, or evaluation suite, except with Customer's prior written opt-in consent. (b) CrossCode will, prior to processing any Customer Data through LLM Sub-processors, configure provider API settings to minimize data retention and prohibit training use to the extent available under each provider's current API tier, and will preserve contemporaneous evidence of that configuration (account-level setting, API endpoint, and the contractual basis). The specific retention and training terms applicable to each LLM Sub-processor are as stated in the Sub-Processor List at crosscode.pro/subprocessors. (c) Versioned model release process. CrossCode records for each Output the model identifier and configuration, prompt template hash, and retrieval index hash, so that the inputs and configuration behind a classification remain auditable for the full retention period. Where a foundation-model provider retires a model version, CrossCode preserves the recorded identifier and contemporaneous evaluation results; provider-side runtime reproducibility of retired models is not warranted.

10. Compliance Roadmap. (a) Target: SOC 2 Type I within 12 months of Effective Date; SOC 2 Type II within 24 months. (b) Security program aligned with NIST AI Risk Management Framework (NIST AI 100-1) and ISO/IEC 27001 controls; formal certification pursued post-Series A.



CrossCode, Inc. (a Delaware corporation in formation) — operating as CrossCode.

Terms of Service · Privacy Policy · Data Processing Addendum · Acceptable Use Policy · SLA · Sub-processors · Trust