Data Processing Agreement

Last updated: February 2026

Enterprise or regulated customers who require a countersigned copy may email dynesdalila@proton.me to request one.

This Data Processing Agreement ("DPA") is incorporated into and forms part of the Terms of Service (the "Agreement") between Anchor Point Consultancy LLC ("Processor") and the customer accepting these terms ("Controller"). Capitalized terms not defined herein have the meanings given in the Agreement or in Regulation (EU) 2016/679 ("GDPR").

1. Subject Matter

Processor provides the Point Forward Service as described in the Agreement and processes personal data on Controller's behalf strictly to deliver, secure, and improve that Service.

2. Duration

This DPA remains in effect for as long as Processor processes personal data on behalf of Controller and survives termination of the Agreement to the extent required for return or deletion of data.

3. Nature and Purpose of Processing

Processor processes personal data to provide the Service, including tracking commitments, generating AI-assisted reports and insights, facilitating collaboration among Controller's authorized users, and maintaining audit and security records.

4. Types of Personal Data

CategoryExamples
Account InformationName, email address, organization name, job title, role
ContentCommitments, goals, projects, tasks, notes, reports, bright ideas
AI InteractionsQueries submitted to the LLM and generated responses
Usage DataFeature usage, login timestamps, audit events

5. Categories of Data Subjects

  • Employees and contractors of Controller's organization
  • Other users authorized by Controller to access the Service

6. Processor's Obligations

Processor will:

  • Process data only for the purposes described in this DPA or on Controller's documented instructions.
  • Follow Controller's reasonable instructions regarding data processing, and promptly inform Controller if an instruction, in Processor's opinion, infringes applicable data-protection law.
  • Implement the technical and organizational security measures described in Section 8.
  • Ensure personnel with production access to Controller's data are bound by written non-disclosure obligations before access is granted.
  • Not transfer personal data to any third country except as described in Section 13.

7. Subprocessors

Controller authorizes Processor to engage the following subprocessors to deliver the Service:

ProviderPurposeLocation
Emergent LabsApp hosting, deployment, LLM proxyUnited States
MongoDB (via hosting provider)Database hostingUnited States
Stripe, Inc.Payment processingUnited States
ResendTransactional email deliveryUnited States
OpenAI (via Emergent LLM proxy)AI report and insight generationUnited States
PostHogProduct analytics (only if user consents)United States

Processor will notify Controller at least fifteen (15) days in advance of engaging any new subprocessor, via email to Controller's registered admin contact. Controller may object to a new subprocessor in writing within thirty (30) days of notification; if the objection is not resolved, Controller may terminate the Agreement for the affected portion of the Service and receive a pro-rata refund of prepaid fees.

8. Security Measures

Processor implements at least the following measures, and may enhance them without notice provided the level of protection is not reduced:

  • Encryption in transit: TLS 1.2+ for all client-to-server and server-to-subprocessor traffic, with HSTS enforced on the production domain (1-year max-age).
  • Encryption at rest: disk-level encryption provided by our hosting vendor(s) for the databases and file storage that hold Controller data. Application-level encryption is applied to selected sensitive fields.
  • Password protection: user passwords and two-factor recovery codes are bcrypt-hashed at rest.
  • Access controls: role-based permissions enforced at the API layer with per-organization data isolation.
  • Two-factor authentication: available to all users; mandatory for platform-owner and organization-admin accounts.
  • Rate limiting: automated brute-force protection on authentication endpoints.
  • Audit logging: immutable-intent audit trail (`action_logs`) for user actions, admin actions, data exports, LLM queries, and security events.
  • Regular security review: at minimum annual static-code analysis by the engineering team; third-party penetration testing available on request for enterprise customers at Controller's cost.
  • Cyber insurance: Cyber-liability insurance policy is pending.

9. Data Subject Rights

Processor will, taking into account the nature of processing, assist Controller by appropriate technical and organizational measures in fulfilling Controller's obligation to respond to data-subject requests for access, rectification, erasure, restriction, portability, and objection. Requests routed to Processor will be forwarded to Controller within five (5) business days.

10. Breach Notification

Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach that may affect Controller's data. Notification will include (i) the nature and scope of the breach, (ii) the categories and approximate number of data subjects and records affected, (iii) likely consequences, and (iv) measures taken or proposed. Processor's full Breach Response Plan is available under NDA on request.

11. Data Return or Deletion

Upon termination of the Service, and at Controller's written election, Processor will (a) return Controller's personal data in a structured, commonly used, machine-readable format (JSON or CSV) via a secure download link, or (b) delete Controller's personal data. Return or deletion will be completed within thirty (30) days, except where retention is required by law (in which case Processor will inform Controller of the retained categories and grounds). Backup copies will be purged within ninety (90) days of return/deletion.

12. Audit Rights

Controller may audit Processor's compliance with this DPA once per calendar year on thirty (30) days' written notice, and at additional times promptly following any confirmed breach affecting Controller's data. Audits are limited to review of security documentation, subprocessor certifications, and written responses to Controller's questionnaire; they do not extend to physical inspection of Processor's or its subprocessors' facilities. Any on-site audit requires mutual written agreement, an NDA, and Controller's payment of Processor's reasonable costs.

13. International Data Transfers & Data Localization

Personal data is stored and processed in the United States. Where Controller or a data subject is located in the European Economic Area, the United Kingdom, or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (Module 2, controller-to-processor, dated 4 June 2021, C(2021) 3972 final), the UK IDTA, and/or the Swiss Addendum, as applicable. These clauses are incorporated by reference.

Data localization: Processor does not currently offer EU- or UK-only data residency. Controllers with strict localization requirements should contact dynesdalila@proton.me before signing to discuss options; if none can be agreed, Controller may decline to sign the Agreement.

14. Liability

Each party's aggregate liability arising from or relating to this DPA is subject to the limitations set forth in the Agreement. To the extent applicable law imposes higher limits (for example, direct liability to data subjects under GDPR Article 82), those limits apply notwithstanding the Agreement.

15. Order of Precedence

In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of personal data. In the event of a conflict between this DPA and the SCCs, the SCCs control.

16. Contact

Data-protection matters, subject rights requests, and DPA questions:
Anchor Point Consultancy LLC
1500 North Grant Street, Suite N
Denver, CO 80203
dynesdalila@proton.me

© 2026 Anchor Point Consultancy LLC. All rights reserved.