This Data Processing Addendum ("DPA") is part of our Terms of Service. It applies only when you use FYProof for a business and the Service handles personal information for you or your clients, for example when an agency uses a team or client workspace (if offered) to check its clients' videos. In this DPA, "you" means that business (the "Customer"), and "we" means FYProof, which is operated by an individual based in Ohio. You don't need to sign anything: it applies automatically. If you need a signed copy, email legal@fyproof.com.
1. Words used here
- Customer Personal Data: personal information in the content you or your team upload to a team or client workspace (videos, captions, hashtags, transcripts and reports), in the connected accounts and analytics numbers of those workspaces, and the names and email addresses of the people you invite.
- Privacy Laws: the US federal and state privacy laws that apply to Customer Personal Data, such as the California Consumer Privacy Act and the consumer privacy laws of Virginia, Colorado, Connecticut, Texas and other states.
- Other words (such as "controller", "processor", "service provider", "contractor" and "sell" or "share") mean what they mean in the Privacy Laws.
2. Who does what
- You decide why and how Customer Personal Data is used. You are the controller or business (or, if you act for a client, a processor or service provider for that client).
- We process it for you, as your processor, service provider or contractor (or as a subprocessor, if you act for a client).
- What this DPA doesn't cover: information we handle for our own purposes, such as account and sign-in details, security and audit logs, anti-abuse and child-safety measures, legal records and (if anything is sold) billing. For that information we decide how it is used, as our Privacy Policy explains.
3. What we do with Customer Personal Data
- We process it only to provide the Service to you, as the Terms and your use of the Service's features describe (those are your instructions), and as you otherwise tell us in writing, unless the law requires something else. If the law requires something else, we tell you first unless the law forbids it.
- We tell you if we believe an instruction breaks a Privacy Law, or if we can no longer meet our duties under the Privacy Laws.
- We don't sell or share Customer Personal Data (as the Privacy Laws use those words); we don't keep, use or disclose it for any purpose other than providing the Service to you, or outside our direct business relationship with you; and we don't combine it with personal information from other sources, except as the Privacy Laws allow. We follow the Privacy Laws that apply to us as your service provider, and you may take reasonable steps to stop and fix any use of Customer Personal Data that this DPA doesn't allow.
- Everyone who can access Customer Personal Data for us is bound to keep it confidential. Today that is only the operator of FYProof. Each time we open a user's video or report, it is recorded in an audit log.
4. Subprocessors
- You allow us to use the subprocessors on our Subprocessors page. We use them under written terms that require them to protect the data and to use it only to provide their service to us. About the AI and speech-to-text companies: They process it only to produce your report, under their API terms for business customers, which don't let them use your content to train their AI models or to improve their products. Some keep data for a short time to monitor for abuse or meet legal duties, as their own terms describe.
- We stay responsible to you for how our subprocessors handle Customer Personal Data, as the Privacy Laws require.
- New subprocessors. We update the Subprocessors page before a new company receives Customer Personal Data. If you email legal@fyproof.com asking for notices, we also email you at least 15 days before. You may object on reasonable data-protection grounds within those 15 days. If we can't address your objection, you may stop using the affected part of the Service or close your team, and we will refund any prepaid fees for the unused part of a paid period.
5. Security
We protect Customer Personal Data with encryption in transit (HTTPS) and at rest, access controls, audit logging of administrator access, encrypted storage of connected-account access, deletion of uploaded videos 72 hours after the check, and encrypted backups kept for up to 30 days.
6. Security incidents
If we learn of a breach of security that leads to accidental or unlawful loss, change, disclosure of or access to Customer Personal Data, we tell the team's owner by email without undue delay, and within 72 hours after we confirm it. We tell you what we know, what we are doing about it, and what you may need to do, and we keep you updated. We help you meet your own duties to notify people or regulators, as far as is reasonable.
7. Helping you with requests and duties
- People's requests. The Service lets you download, correct and delete Customer Personal Data yourself (for example by deleting videos, reports and stored numbers, disconnecting accounts or deleting the team). If we receive a request about Customer Personal Data from someone else, we pass it to you and don't answer it ourselves, unless the law requires us to.
- Assessments. We give you the information you reasonably need, and that we have, to carry out data protection assessments that the Privacy Laws require.
8. When the processing ends
When you delete Customer Personal Data, or delete the team, we delete it from the Service, except for copies in backups (deleted within 30 days) and anything we must keep by law (for example material reported to the National Center for Missing & Exploited Children, or data under a legal hold). Before deleting a team, you can download its reports.
9. Showing that we comply
Once a year, on request, we will answer a reasonable written security and privacy questionnaire. If a Privacy Law requires more (such as an audit), we will allow it at your cost, with at least 30 days' notice, during business hours, in a way that protects other customers' data and our confidential information, or we may instead give you a report from an independent assessor.
10. Your duties
You are responsible for having a lawful reason to use Customer Personal Data with the Service, and for giving the notices and getting the permissions the law requires, including from your clients, from people who appear in their videos, and from the parents of any minors who appear in them. Don't use the Service for personal information that is subject to the laws of other countries (such as the EU or UK GDPR): we don't offer the terms those laws require.
11. Everything else
- Customer Personal Data is stored and processed only in the United States.
- If this DPA and the Terms conflict about Customer Personal Data, this DPA wins. Otherwise the Terms apply, including the limits on liability, the disclaimers and the dispute section.
- This DPA lasts as long as we process Customer Personal Data for you.