Data Processing Addendum
Effective date: July 24, 2026
Last updated: July 24, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Foldout Terms of Service (the "Agreement") between Foldout LLC, a Georgia limited liability company ("Foldout," "Processor"), and the customer agreeing to the Agreement ("Customer," "you"). It governs Foldout's processing of Personal Data on your behalf when you use the Service. If there is a conflict between this DPA and the Agreement on data-processing matters, this DPA controls.
1. Definitions
"Personal Data" means information relating to an identified or identifiable natural person that Customer submits to or creates in the Service. "Customer Personal Data" means Personal Data that Foldout processes on Customer's behalf — including the names and contact details of Customer's investors (LPs) and personnel, and deal, financial, and commentary data Customer submits that identifies individuals. "Processing," "Controller," "Processor," "Sub-processor," "Data Subject," and "Security Incident" have the meanings given under applicable data protection law (including, as applicable, the GDPR/UK GDPR and the CCPA/CPRA and comparable U.S. state laws) ("Applicable Data Protection Law").
2. Roles and scope
As between the parties, Customer is the Controller (or the processor acting for its own investors) and Foldout is the Processor. Foldout processes Customer Personal Data only to provide the Service and only on Customer's documented instructions (the Agreement, this DPA, and Customer's configuration and use of the Service). Subject matter, duration, nature, purpose, data types, and categories of Data Subjects are described in Annex A.
3. Foldout's processing obligations
Foldout will:
- Process Customer Personal Data only on Customer's documented instructions, and inform Customer if, in Foldout's opinion, an instruction infringes Applicable Data Protection Law;
- Ensure personnel authorized to process Customer Personal Data are bound by confidentiality;
- Implement and maintain the technical and organizational security measures described in Annex B;
- Not use Customer Personal Data to train or fine-tune any AI model, not pool or combine it with any other customer's data, and not use it to generate content for or serve any other customer;
- Not sell or "share" Customer Personal Data, and not retain, use, or disclose it for any purpose other than providing the Service (Foldout acts as a "service provider"/"processor" under U.S. state law).
4. Sub-processors
Customer authorizes Foldout to engage the sub-processors listed in Annex C to process Customer Personal Data. Foldout will impose data-protection obligations on each sub-processor no less protective than those in this DPA, and remains responsible for their performance. Foldout will maintain the current sub-processor list in its Privacy Policy and give Customer notice of any new or replacement sub-processor, with a reasonable opportunity to object on legitimate data-protection grounds.
5. Assistance to Customer
Taking into account the nature of the processing, Foldout will assist Customer, by appropriate technical and organizational measures and insofar as possible, in fulfilling Customer's obligations to (a) respond to Data Subject requests (access, correction, deletion, portability, objection), and (b) ensure security, breach notification, and data protection impact assessments. The Service provides Customer self-serve tools to review, edit, export, and delete Customer Personal Data and the voice profile within its workspace.
6. Security incidents
Foldout will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and will provide information reasonably available to Foldout to help Customer meet its own notification obligations.
7. Return and deletion
On termination or expiry of the Agreement, Foldout will delete or return Customer Personal Data as described in the Agreement, and delete existing copies except to the extent retention is required by law. Customer may delete its content and workspace within the Service.
8. Audits
Foldout will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits, subject to confidentiality and reasonable limits on frequency, scope, and disruption.
9. International transfers
Foldout processes Customer Personal Data in the United States. To the extent Customer Personal Data originating in the EEA, UK, or Switzerland is transferred, the parties will rely on an appropriate transfer mechanism (e.g., Standard Contractual Clauses), incorporated by reference where applicable.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
11. Term
This DPA takes effect when Customer accepts the Agreement and continues until Foldout has deleted or returned all Customer Personal Data.
Annex A — Details of processing
- Subject matter: Foldout's provision of the Service (drafting and delivering branded investor updates).
- Duration: the term of the Agreement, plus any legally required retention.
- Nature and purpose: hosting, storage, and processing of Customer inputs to generate, format, export, and deliver investor updates; product operation, security, and support.
- Categories of Data Subjects: Customer's investors/limited partners; Customer's personnel and collaborators.
- Types of Personal Data: names and contact details; deal/property information; financial figures and commentary submitted by Customer that may identify individuals. Customer is asked not to submit special-category/sensitive data.
Annex B — Security measures
Encryption in transit; tenant isolation via row-level security and access controls; private storage buckets scoped per customer; hashed passwords via the authentication provider; least-privilege internal access; regular backups; monitoring and logging. Foldout works to protect data using industry-standard measures and updates these measures as the Service evolves.
Annex C — Authorized sub-processors
| Provider | What it does for us |
|---|---|
| Supabase | Database, authentication, and file storage |
| Anthropic | AI model that drafts updates from Customer inputs |
| Resend | Transactional and notification email |
| Stripe, Inc. | Payment processing and subscription billing. Located in the United States. Stripe's data processing agreement is automatically incorporated through the Stripe Services Agreement and is available at stripe.com/legal/dpa. |
| PostHog | Product and usage analytics |
| Lovable | Application hosting |
| Optional sign-in (OAuth) |
Foldout will keep this list current in its Privacy Policy.