Fieldwork AI Inc.
Data Processing Addendum
Data protection terms for Fieldwork customers.
Last updated: 14 July 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Fieldwork AI Inc. ("Fieldwork") and the customer identified in that agreement ("Customer") governing Customer's use of Fieldwork's services (the "Agreement"). It applies where Fieldwork processes Customer Personal Data as a processor on Customer's behalf. Capitalized terms not defined here have the meanings in the Agreement.
1. Definitions
- "Customer Personal Data" means personal data contained in Customer Data that Fieldwork processes on Customer's behalf under the Agreement.
- "Data Protection Laws" means all laws applying to the processing of Customer Personal Data, including the EU GDPR, the UK GDPR and Data Protection Act 2018, and applicable US state privacy laws.
- "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" means the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0).
- "controller", "processor", "personal data", "personal data breach", and "processing" have the meanings given in the GDPR.
2. Roles and instructions
2.1 Roles. Customer is the controller of Customer Personal Data (or a processor acting for its own controllers, in which case Customer warrants its instructions to Fieldwork are consistent with its controllers' instructions). Fieldwork is Customer's processor. Fieldwork's independent processing of Account Data, Usage Data, security data, and De-identified Data is described in the Agreement and Fieldwork's Privacy Policy and is outside the scope of this DPA.
2.2 Instructions. Fieldwork will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required otherwise by law to which Fieldwork is subject (in which case Fieldwork will inform Customer of that legal requirement before processing, unless the law prohibits it). The Agreement, this DPA, and Customer's use and configuration of the Service (including autonomy settings, Connected System scopes, and Network Feature settings) constitute Customer's complete documented instructions, and include the instruction to process Customer Personal Data as necessary to: (a) provide, secure, and support the Service; (b) create De-identified Data; and (c) improve the Service.
2.3 Unlawful instructions. Fieldwork will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Fieldwork may suspend the affected processing until instructions are revised.
3. Details of processing
The subject matter, duration, nature and purpose of processing, categories of data subjects, and categories of personal data are set out in Annex I.
4. Confidentiality
Fieldwork ensures that persons authorized to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality and access it on a least-privilege, need-to-know basis.
5. Security and personal data breach
5.1 Measures. Fieldwork implements and maintains the technical and organizational measures set out in Annex II, and will not materially reduce the overall security of the Service during the term of the Agreement.
5.2 Breach notification. Fieldwork will notify Customer without undue delay, and in any event within 72 hours, after confirming a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known: the nature of the breach, categories and approximate volumes of data subjects and records affected, likely consequences, measures taken or proposed, and a contact point. Fieldwork will provide timely updates as information develops and will reasonably cooperate with Customer's own notification obligations. Fieldwork's notification is not an acknowledgment of fault or liability.
6. Sub-processing
6.1 General authorisation. Customer grants Fieldwork general written authorisation to engage sub-processors. Fieldwork's current sub-processors, and the locations and inference-routing behaviour applicable to them, are listed at https://www.getfieldwork.ai/subprocessors (Annex III).
6.2 Changes and objection. Fieldwork will give notice of any intended addition or replacement of a sub-processor at least 14 days before it processes Customer Personal Data, via the sub-processor page's notification mechanism. Customer may object on reasonable data-protection grounds within 14 days of notice. The parties will work in good faith to resolve an objection (including by making the change inapplicable to Customer's Organization, such as geography pinning or provider exclusion, where the Service supports it); if it cannot be resolved within 30 days, Customer may terminate the affected Order Form (or, if the change affects the whole Service, the Agreement) on notice, with a pro-rata refund of prepaid, unused fees, as its sole remedy.
6.3 Emergency replacement. Where a sub-processor must be replaced or added immediately to address a security incident, the sub-processor's insolvency or service failure, or another circumstance outside Fieldwork's reasonable control, Fieldwork may make the change without advance notice and will notify Customer promptly thereafter; Customer's objection right under Section 6.2 runs from that notice.
6.4 Flow-down and liability. Fieldwork will impose data protection obligations on each sub-processor materially equivalent to those in this DPA, and remains liable to Customer for its sub-processors' performance.
7. Data subject requests
Fieldwork will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to requests to exercise data subject rights. If a data subject contacts Fieldwork directly regarding Customer Personal Data, Fieldwork will redirect them to Customer without responding substantively, except as required by law.
8. Assistance
Taking into account the nature of the processing and the information available to it, Fieldwork will reasonably assist Customer in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), including by providing the information described in Section 10. Fieldwork may charge reasonable fees for assistance materially exceeding what the Service ordinarily provides.
9. International transfers
9.1 Transfer mechanism. Where Customer Personal Data protected by the EU GDPR is transferred to Fieldwork in a country without an adequacy decision, the EU SCCs are incorporated into this DPA - Module Two (controller to processor) where Customer is a controller, or Module Three (processor to processor) where Customer is a processor acting on behalf of its own controller(s) - completed as follows: Clause 7 (docking) included; Clause 9(a): general authorisation with 14 days' notice; Clause 11: the optional independent-complaints provision does not apply; Clause 17: the law of Ireland; Clause 18: the courts of Ireland; Annexes I–III of the EU SCCs are populated by Annexes I–III of this DPA. Where the UK GDPR applies, the UK Addendum supplements the EU SCCs, with the ICO as competent authority and the tables completed by reference to this DPA's Annexes.
9.2 Processing locations. Customer Personal Data is stored at rest in the United States. AI inference requests are routed globally by default and may be processed transiently in other regions, as described on the sub-processor page; Customer may enable geography-pinned inference (US or EU) as a per-Organization configuration. Onward transfers by sub-processors are covered by the sub-processors' own compliant transfer mechanisms.
9.3 Government requests. If Fieldwork receives a legally binding request from a public authority for Customer Personal Data, it will (unless legally prohibited) notify Customer, direct the authority to Customer, and disclose only the minimum required.
10. Audits
Fieldwork will make available information reasonably necessary to demonstrate compliance with this DPA, in the following order of preference: (a) its security documentation and summaries; (b) third-party certifications and audit reports when obtained (Fieldwork is pursuing ISO 27001 and SOC 2 Type II); and (c) where (a)–(b) are insufficient to demonstrate compliance, an audit by Customer or its independent auditor, no more than once in any 12-month period, on at least 30 days' notice, during business hours, at Customer's cost, under confidentiality, without access to other customers' data, and without material disruption to the Service. Regulator-mandated audits are not subject to the frequency limit.
11. Return and deletion
Upon termination or expiry of the Agreement, Fieldwork will make Customer Personal Data available for export for 30 days and delete it within 30 days thereafter, except as retained in routine backups (which expire on rotation and remain protected by this DPA until deleted) or as required by law. Fieldwork will confirm deletion in writing on request. De-identified Data is not personal data and is outside this Section.
12. US state privacy laws
Where a US state privacy law applies to Customer Personal Data, Fieldwork acts as Customer's "service provider" or "processor": it will not sell or share Customer Personal Data, will not retain, use, or disclose it other than to provide the Service and as permitted by such laws (including as instructed under Section 2.2), will not combine it with other data except as permitted, and certifies that it understands these restrictions. Fieldwork will notify Customer if it can no longer meet them, and Customer may take reasonable steps to stop and remediate unauthorized use.
13. Liability and precedence
Each party's liability under or in connection with this DPA (including the EU SCCs and UK Addendum, to the extent permitted by them) is subject to the limitations and exclusions in the Agreement, including the enhanced cap applying to DPA breaches. For data protection matters, this DPA controls over the Agreement; the EU SCCs and UK Addendum control over this DPA in case of conflict.
14. Term
This DPA applies for as long as Fieldwork processes Customer Personal Data.
Annex I - Details of processing
A. Parties. Data exporter: Customer (contact as stated on the Order Form) - controller. Data importer: Fieldwork AI Inc., 169 Madison Ave, Ste 79708, New York, NY 10016, USA, privacy@getfieldwork.ai - processor.
B. Description of processing.
- Subject matter and nature: hosting and operation of Fieldwork's agentic AI platform, including ingestion of data from Connected Systems, storage, analysis, AI inference over Customer Data as model context, generation of Outputs and Prompted Artifacts, and actions taken in Connected Systems as authorized by Customer.
- Purpose: provision, security, and support of the Service; creation of De-identified Data; improvement of the Service - each on Customer's documented instructions.
- Duration: the term of the Agreement plus the export and deletion periods in Section 11.
- Frequency: continuous.
- Categories of data subjects: Customer's personnel and Users; Customer's end customers; Customer's suppliers' and business partners' personnel.
- Categories of personal data: names, business contact details, and roles; transaction and order data (names, addresses, contact details, order histories); identifiers appearing in Customer's business systems; and the contents and metadata of business records and communications within the data sources Customer connects to or enters into the Service. The specific data sources are determined by Customer's configuration of the Service.
- Special categories: none intended; the Agreement instructs Customer not to submit them, and no special-category processing is authorized.
- Retention: per Section 11 (export window plus deletion within 30 days; backups on rotation).
C. Competent supervisory authority. For EU SCC purposes: the supervisory authority determined in accordance with Clause 13 (generally the authority of the EU/EEA member state in which the data exporter (Customer) is established, or otherwise as Clause 13 provides). For the UK Addendum: the Information Commissioner's Office (ICO).
Annex II - Technical and organizational measures
Per Fieldwork's information security policy (FW-SEC-001), including: encryption in transit (TLS 1.2+) and at rest (AES-256 via managed KMS); least-privilege, named-account access with MFA on all systems and SSO; logical multi-tenant isolation with scoped, short-lived data-access credentials; personal data minimised or pseudonymised at ingestion where practicable; secrets management with no credentials in code and automated secret scanning; production/development network isolation and infrastructure-as-code with peer review; endpoint full-disk encryption and EDR; audited administrative access; application-level data-access logging (excluding data values) and 12-month audit-log retention; vulnerability management with defined remediation windows; backup and disaster recovery with tested restore (24-hour RTO target); a documented six-step incident response procedure with 72-hour customer breach notification; access revocation within 24 hours of personnel change; security review at least every 6 months. Fieldwork maintains cyber liability and technology E&O insurance and is pursuing ISO 27001 and SOC 2 Type II certification.
Annex III - Sub-processors
The current list of sub-processors, including processing locations, inference-routing behaviour, and the change-notification mechanism, is maintained at https://www.getfieldwork.ai/subprocessors and is incorporated into this DPA.