Data Processing Addendum
1. Scope, Roles, and Definitions
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Foreman and the customer ("Customer") and applies to Foreman's processing of personal information that Customer submits to the Service. Because the Service is offered only in the United States, this DPA is written for U.S. privacy law, including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and comparable state statutes.
For personal information subject to the CCPA/CPRA, Customer is the "business" and Foreman is a "service provider" that processes personal information solely on Customer's behalf. "Personal information," "sell," "share," "consumer," and "service provider" have the meanings given in the CCPA/CPRA. This DPA does not incorporate EU/UK Standard Contractual Clauses, the UK Addendum, or Data Privacy Framework certification, because the Service is not offered to EU or UK users.
2. Details of Processing
- Subject matter: Foreman's provision of the AI agent orchestration Service.
- Duration: For the term of the Terms of Service and until deletion or return of personal information under Section 10.
- Nature and purpose: Hosting, processing, and transmitting personal information to operate the Service, generate deliverables, execute Customer-authorized integration actions, provide support, and secure the platform.
- Categories of personal information: As described in the Privacy Policy (Notice at Collection), including identifiers, account and business content, commercial/billing data, usage data, integration and audit data, and approximate location.
- Categories of individuals: Customer's authorized users and administrators, and individuals whose information Customer includes in workspace content or connected integrations.
3. Service-Provider Restrictions
Foreman certifies that it understands and will comply with the following restrictions. Foreman shall not:
- Sell or share Customer personal information (as "sell" and "share" are defined by the CCPA/CPRA);
- Retain, use, or disclose Customer personal information for any purpose other than the specific business purpose of performing the Service, or as otherwise permitted by the CCPA/CPRA;
- Retain, use, or disclose Customer personal information outside the direct business relationship with Customer; or
- Combine Customer personal information with personal information from other sources, except as permitted by the CCPA/CPRA to perform the Service.
Consistent with the Privacy Policy, Foreman does not use Customer content to train or fine-tune AI models. Any model-quality improvement uses only de-identified operational data with Customer identifiers and content removed.
4. Customer Instructions
Foreman processes Customer personal information only to provide and secure the Service, to comply with Customer's documented instructions (including through the Service's configuration and features), to meet legal obligations, and to support verified consumer-rights requests. Foreman will inform Customer if, in its reasonable opinion, an instruction violates applicable privacy law.
Customer is responsible for the lawfulness of its instructions and for providing any required notices and obtaining any required permissions or consent for personal information it supplies or makes available through connected mailboxes, calendars, social platforms, CRMs, prospecting sources, or enrichment providers.
5. Subprocessors and Change Notification
Customer authorizes Foreman to engage the subprocessors listed on the Subprocessor List. Foreman imposes data-protection obligations on each subprocessor that are at least as protective as those in this DPA, including the service-provider restrictions in Section 3, and remains responsible for its subprocessors' performance.
Before adding or replacing a subprocessor that will process Customer personal information, Foreman will update the Subprocessor List and give at least 30 days' advance notice to account administrators. Customer may object to a new subprocessor in good faith during that period; if Foreman cannot reasonably accommodate the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees as its exclusive remedy.
A service that Customer independently selects, contracts with, supplies credentials or an API key for, or directs Foreman to connect to is a "Customer-Directed Service," not a Foreman subprocessor merely because Foreman transmits data to it at Customer's direction. Customer-Directed Services include the provider of a connected mailbox, calendar, social account, CRM, prospecting or enrichment account, and a BYOK model account. Foreman remains responsible for securely implementing the connection and following Customer's documented instructions, but Customer's direct agreement with the Customer-Directed Service governs that service's independent processing.
6. Security Measures
Foreman maintains administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, tenant isolation enforced at the application and database layers, role-based access control, input validation, and rate limiting. These are described in the Security Overview. Foreman reviews and updates these measures as the Service matures and will not materially degrade them during the term.
7. Assistance with Consumer-Rights Requests
Taking into account the nature of the processing, Foreman will provide reasonable assistance to enable Customer to respond to verified consumer requests to know, access, delete, correct, or opt out. If Foreman receives a request directly from a consumer relating to Customer's data, Foreman will, where permitted, forward it to Customer rather than respond directly, and will support Customer's fulfillment through Service features and the Privacy tab in Settings.
8. Security-Incident Notification
Foreman will notify Customer without undue delay, and in any event within 72 hours, after confirming a security incident affecting Customer personal information processed by Foreman. The notice will describe, to the extent known, the nature of the incident, the categories of information and individuals affected, the likely consequences, and the measures taken or proposed to address it. Foreman will provide reasonable cooperation to help Customer meet any legal notification obligations. A notification is not an acknowledgment of fault or liability.
9. Audits and Verification
Upon reasonable written request, no more than once per year (unless required by law or following a confirmed incident), Foreman will make available information reasonably necessary to demonstrate compliance with this DPA — such as a completed security questionnaire, a summary of controls, or, when available, third-party assessment or penetration-test summaries. On-site or hands-on audits, where reasonably required, will be conducted under mutually agreed scope, timing, and confidentiality terms.
10. Return and Deletion of Data
On termination of the Service or a verified deletion request, Foreman will delete or, where the Service supports it, return Customer personal information in accordance with the single retention schedule in the Privacy Policy (Data Retention & Deletion): active workspace and account data are deleted within 45 days, and backup copies are purged within 30 days thereafter, except where longer retention is required by law (for example, billing/tax and sanctions-screening records).
11. Sensitive Personal Information
Foreman does not seek to collect "sensitive personal information" and processes it only where necessary to provide the Service or to meet a legal obligation (such as sanctions screening), limited to the purposes permitted under CCPA/CPRA § 7027(m). Foreman does not use sensitive personal information to infer characteristics about individuals.
12. Order of Precedence and Contact
This DPA supplements the Terms of Service; where they conflict on the subject of personal-information processing, this DPA controls. Enterprise customers who require a countersigned DPA or additional terms may contact legal@foreman.company. This document is implementation-aligned and remains subject to counsel review before enterprise execution.