Combra
TermsPrivacyDPASub-processors

Combra — Data Processing Addendum (DPA)

Last updated: 28 June 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Fabrique-Futur LLC, a Wyoming limited liability company ("Fabrique-Futur," "we," "Processor"), and the customer agreeing to the Agreement ("Customer," "Controller," "you"), and governs the processing of Personal Data through Combra (the "Service").

If you require a signed copy, contact [email protected]. By using the Service to process Personal Data subject to Data Protection Laws, you and we agree to this DPA. Where this DPA conflicts with the rest of the Agreement on data-protection matters, this DPA controls.


1. Definitions

  • Data Protection Laws — all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025 ("UK GDPR"), and the California Consumer Privacy Act as amended by the CPRA ("CCPA"), each as applicable.
  • Controller, Processor, Data Subject, Personal Data, Processing, Special Categories of Personal Data, and Supervisory Authority have the meanings in the EU GDPR. For the CCPA, Business, Service Provider, Personal Information, and Sell/Share apply and map to Controller, Processor, Personal Data, and the corresponding activities.
  • Customer Personal Data — Personal Data that we process on your behalf to provide the Service, contained in: Customer Data you submit or connect; queries you make; and Output generated for you. "Output" is excluded from "Customer Data" in the Terms for ownership purposes, but Personal Data within Output is Customer Personal Data for data-protection purposes under this DPA.
  • Authorized Affiliate — any entity that controls, is controlled by, or is under common control with Customer, that is permitted to use the Service under the Agreement, where "control" means ownership of more than 50% of voting interests. Customer enters this DPA for itself and on behalf of its Authorized Affiliates that use the Service, and is responsible for their compliance; an Authorized Affiliate may exercise data-exporter rights under the SCCs through Customer, or accede directly using the docking option in SCC Clause 7.
  • Sub-processor — a third party engaged by us to process Customer Personal Data, as described in our Sub-processor List.
  • SCCs — the Standard Contractual Clauses approved by the European Commission on 4 June 2021 (Commission Implementing Decision (EU) 2021/914).
  • UK Addendum — the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (or the UK IDTA, as applicable).

2. Roles and scope

  • For Customer Personal Data, you are the Controller (or Business) and we are the Processor (or Service Provider). Where you act as a processor for another controller, you appoint us as a sub-processor, and you confirm you have authority to do so.
  • For Personal Data we process as a controller in our own right (for example, account-administrator contact details, billing data, and Service security and operations data), our Privacy Policy applies rather than this DPA.
  • This DPA applies to processing of Customer Personal Data within the scope of Data Protection Laws.

3. Processing instructions

  • We will process Customer Personal Data only on your documented instructions, including as set out in the Agreement and this DPA, and as needed to provide, secure, support, and debug the Service for you (the "Permitted Purposes"), unless required to act by law (in which case we will inform you where legally permitted).
  • De-identification. You instruct and authorize us to create aggregated or de-identified data from Customer Personal Data. Once de-identified, such data is no longer Customer Personal Data; we will not attempt to re-identify it, will maintain controls preventing re-identification, and will not disclose it in a form that identifies you or any individual. This authorization survives termination.
  • Your use and configuration of the Service (including which connectors you enable and what content you submit) constitute your instructions.
  • We will inform you if, in our opinion, an instruction infringes Data Protection Laws.
  • CCPA service-provider terms. With respect to Personal Information governed by the CCPA, we act as a Service Provider and:
    • will not sell or share Customer Personal Data;
    • will not retain, use, or disclose it for any purpose other than the business purposes specified in this DPA and the Agreement, or as otherwise permitted by the CCPA, and not outside the direct business relationship with you;
    • will not combine it with personal information from other sources, except as permitted by the CCPA to perform the Service;
    • will provide the same level of privacy protection as required of businesses under the CCPA;
    • will notify you if we determine we can no longer meet our CCPA obligations, and you may take reasonable steps to stop and remediate unauthorized use;
    • grant you the right to take reasonable and appropriate steps to ensure we use Customer Personal Data consistent with your CCPA obligations;
    • will impose these same restrictions on any sub-processor (sub-contractor) we engage. We certify that we understand and will comply with these restrictions. We do not use Customer Personal Data to train our own generative-AI or machine-learning models.

4. Confidentiality and personnel

We ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only on a need-to-know basis under appropriate access controls.


5. Security

We implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II. We regularly review these measures and may update them provided protection is not materially reduced.


6. Sub-processors

  • You provide general authorization for us to engage Sub-processors to process Customer Personal Data. Our current Sub-processors are listed in the Sub-processor List.
  • We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
  • We will give notice of any intended addition or replacement of a Sub-processor that processes Customer Personal Data at least 15 days before it begins processing, by updating the Sub-processor List and by direct notice (email and/or in-product) to your account's administrator or designated contact. It is your responsibility to keep that contact current.
  • Objection. You may object on reasonable data-protection grounds by emailing [email protected] within 15 days of the notice, explaining your grounds. We will work with you in good faith to address the concern (for example, by offering an alternative or additional safeguards). If we cannot reasonably resolve it, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid, unused fees for that part. While an objection is pending, we will not begin the new Sub-processor's processing of your Customer Personal Data unless doing so is necessary to continue the Service.
  • Emergency replacement. If a Sub-processor must be replaced urgently (for example, due to a Sub-processor outage or security or legal issue), we may engage a replacement before the notice period ends and will notify you as soon as practicable; your objection rights still apply afterward.

7. Data-subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). If we receive such a request directly from a Data Subject relating to Customer Personal Data, we will, where legally permitted, direct them to you. The Service provides self-service tools (for example, search, edit, archive, and deletion) that you can use to action many such requests yourself.


8. Personal-data breaches

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known: the nature of the breach and categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for more information. Where we cannot provide all information at once, we will provide it in phases without further undue delay, and will give reasonable updates as the investigation progresses. Notice will be sent to your account's administrator or designated security contact. Our notice is not an acknowledgment of fault.


9. Data-protection impact assessments

Taking into account the nature of processing and information available to us, we will provide reasonable assistance with your data-protection impact assessments and prior consultations with Supervisory Authorities, where required by Data Protection Laws and relating to the Service.


10. International transfers

  • Where processing of Customer Personal Data involves a transfer from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the SCCs apply and are incorporated by reference, completed as set out in Annex III.
    • Module Two (Controller-to-Processor) applies where you are a controller; Module Three (Processor-to-Processor) applies where you are a processor.
    • For UK transfers, the UK Addendum applies to the SCCs; for Swiss transfers, the SCCs apply with the adjustments required by Swiss law (FADP).
  • Where a Sub-processor is certified under the EU-US Data Privacy Framework (and, where relevant, the UK Extension), that mechanism may additionally apply to transfers to that Sub-processor. The SCCs are the primary safeguard between you and us.
  • If a transfer mechanism is invalidated or must be replaced, the parties will work in good faith to implement an alternative lawful mechanism.

11. Deletion and return

On termination or expiry of the Agreement, we will, at your choice, delete or return Customer Personal Data, and delete existing copies, unless retention is required by law. For 30 days after termination (unless legally prohibited), the Service allows you to export Customer Data. We delete or de-identify Customer Personal Data from active systems within 60 days of termination; residual copies in routine backups are deleted on the ordinary backup cycle no later than 90 days after termination and remain protected by this DPA until deleted. This Section controls over any conflicting deletion or retention statement in the Agreement or Privacy Policy for Personal Data.


12. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party certifications or reports where available. Where Data Protection Laws give you an audit right that such information does not satisfy, you may, on reasonable prior notice, no more than once per year (unless required by a Supervisory Authority), and subject to confidentiality, conduct an audit limited to information relevant to your Customer Personal Data, at your expense, without disrupting our operations or compromising other customers' data.


13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. However, nothing in the Agreement or this DPA limits or excludes any liability, remedy, or right that cannot be limited or excluded under the SCCs or mandatory Data Protection Laws, and the SCCs prevail over any conflicting term to the extent of the conflict. Data Subjects' rights under the SCCs and Data Protection Laws are not affected by any liability cap.


Annex I — Description of processing

  • Subject matter: provision of the Combra company-knowledge / retrieval and AI-assistant Service.
  • Duration: the term of the Agreement, plus any limited post-termination export and deletion period.
  • Nature and purpose: hosting, storing, indexing, embedding, retrieving, searching, summarizing, extracting facts and decisions from, and generating answers from Customer Data, and securing, supporting, and debugging the Service (the Permitted Purposes). Account administration and billing involve Personal Data we process as a controller and are governed by the Privacy Policy, not this DPA.
  • Types of Personal Data: as determined by Customer. Typically: business contact details and identifiers of Authorized Users (name, email); content of documents, messages, and files Customer submits or connects, which may incidentally contain Personal Data about Customer's personnel, customers, or third parties; queries and generated Output; usage and audit logs. Customer should not submit Special Categories of Personal Data unless agreed in writing.
  • Categories of Data Subjects: Customer's Authorized Users; and any individuals referenced within Customer Data (for example, employees, contractors, customers, or contacts of the Customer).
  • Frequency: continuous, for the duration of the Agreement.

Annex II — Technical and organizational security measures

We maintain measures including:

  • Tenant isolation: PostgreSQL Row-Level Security (RLS) enforced at the database layer with per-request and per-worker tenant scoping; the application connects as a non-superuser role so RLS applies; fail-closed behavior when tenant context is absent.
  • Access controls: role-based and team-based access controls within each customer workspace; retrieval and reads are filtered to the requesting user's authorized collections.
  • Authentication: JWT-based sessions stored in httpOnly cookies; short token lifetimes with server-side revocation (logout denylist and credentials-change invalidation); rate limiting and login lockout on authentication endpoints.
  • Encryption: TLS in transit; encryption at rest for stored third-party OAuth credentials (authenticated symmetric encryption); reliance on managed-database and object-storage encryption at rest provided by our infrastructure provider.
  • Secrets management: production secrets supplied via environment configuration, not source control; boot-time validation rejects placeholder secrets in production.
  • Webhook integrity: signature verification and replay protection on inbound integration webhooks (e.g., Slack, inbound email).
  • Logging and monitoring: application logging with request correlation IDs; optional error tracking configured to exclude request bodies, cookies, and stack-frame locals (PII-minimizing); operational metrics behind authentication.
  • Data minimization in operations: error and analytics tooling configured to avoid collecting Customer Personal Data where feasible.
  • Resilience: managed, access-controlled database, cache, and object storage with provider-side backups.

Annex III — Sub-processors and SCC completion

  • Sub-processors: as listed in the Sub-processor List, which is incorporated into this DPA.
  • SCC completion (where the SCCs apply):
    • Data exporter: the Customer (and its authorized affiliates), acting as controller or processor of Customer Personal Data.
    • Data importer: Fabrique-Futur LLC, providing the Service.
    • Module: Two (Controller-to-Processor) or Three (Processor-to-Processor), as applicable.
    • Clause 7 (docking): applies.
    • Clause 9 (sub-processors): Option 2 (general written authorization), with the notice period in Section 6 of this DPA.
    • Clause 11 (redress): the optional independent-dispute-resolution language does not apply.
    • Clause 13 / Annex I.C (competent supervisory authority): the supervisory authority of the EEA Member State in which the data exporter (Customer) is established; where the Customer is not established in the EEA but has appointed an EU representative, the authority of that Member State; otherwise, where legally competent, the Irish Data Protection Commission, and failing that, the authority determined in accordance with SCC Clause 13.
    • Clause 17 (governing law): the law of Ireland (for EU SCCs), unless another EU Member State law is required.
    • Clause 18 (forum): the courts of Ireland (for EU SCCs), without prejudice to Data Subjects' rights.
    • Annex I/II of the SCCs: completed by Annex I and Annex II of this DPA.
    • Special categories of data: the parties do not anticipate transferring special categories of Personal Data. Customer will not submit such data without prior written agreement and any additional safeguards required; where any is transferred, the access limitations and security measures in Annex II apply, and access is restricted to personnel under confidentiality on a strict need-to-know basis.
    • UK transfers: the UK Addendum applies to the EU SCCs. Table 1 (parties) and the Appendix Information (Tables 2 and 3) are populated by this DPA's Annexes; Table 2 selects the Approved EU SCCs above with the modules and options stated here; Table 4 ("Ending this Addendum"): the Importer may end the Addendum as set out in Section 19 of the Addendum. The parties agree the Addendum and IDTA update automatically to any new ICO-published version that comes into force.

Contact

Data-protection contact: [email protected] Fabrique-Futur LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States EU/UK Article 27 representative: where required, details available on request (see Privacy Policy).

© 2026 Fabrique-Futur LLC[email protected] · combra.ai