Data Processing Addendum

Effective date: July 25, 2026


1. Scope and Incorporation

This Data Processing Addendum ("DPA") supplements the Terms of Service (the "Agreement") between PainRadar LLC ("PainRadar", "we", "us") and the customer entity that has agreed to the Agreement ("Customer"). It applies to the extent PainRadar processes Personal Data on Customer's behalf as a processor in the course of providing the Service. Terms not defined here have the meaning given in the Agreement or in Applicable Data Protection Law.

This DPA does not cover PainRadar's processing of Third-Party Content (publicly posted content PainRadar independently collects and analyzes from third-party platforms). For that processing, PainRadar acts as an independent controller, not as Customer's processor — see our Privacy Policy, Section 4.

2. Definitions

  • "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR, applied correspondingly under other Applicable Data Protection Law.
  • "Customer Personal Data" means Personal Data contained within Your Content (as defined in the Terms of Service) that PainRadar processes on Customer's behalf and on Customer's documented instructions.
  • "Sub-processor" means any third party PainRadar engages to process Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission (Commission Implementing Decision (EU) 2021/914), as amended or replaced.

3. Roles of the Parties

Customer is the Controller of Customer Personal Data. PainRadar is the Processor and will process Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's ordinary use of the Service — unless required to do otherwise by law, in which case PainRadar will inform Customer before processing, unless legally prohibited from doing so.

4. Details of Processing

The subject matter, duration, nature and purpose, categories of Data Subjects, and types of Personal Data processed under this DPA are described in Annex I.

5. Processor Obligations

PainRadar will:

  • Process Customer Personal Data only on Customer's documented instructions, including regarding international transfers, unless required otherwise by law;
  • Ensure persons authorized to process Customer Personal Data are subject to confidentiality obligations;
  • Implement appropriate technical and organizational security measures as described in Annex III;
  • Not engage a Sub-processor without authorization as set out in Section 6;
  • Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, with Customer's obligations to respond to Data Subject requests under Applicable Data Protection Law;
  • Assist Customer, taking into account the nature of processing and information available to PainRadar, with Customer's obligations relating to security of processing, breach notification, and data protection impact assessments;
  • At Customer's election, delete or return all Customer Personal Data after the end of the provision of Service, except to the extent PainRadar is required by law to retain it, consistent with Section 6 (Termination) of the Terms of Service;
  • Make available information reasonably necessary to demonstrate compliance with this Section 5, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable notice, confidentiality, and no more than once per twelve-month period absent a Personal Data Breach or regulatory requirement.

6. Sub-processors

Customer authorizes PainRadar to engage the Sub-processors listed in Annex II as of the effective date of this DPA. PainRadar will impose data protection terms on each Sub-processor that are no less protective than those in this DPA.

PainRadar will give Customer notice (by updating Annex II and, for material additions, by email or in-Service notice) before engaging a new Sub-processor. Customer may object on reasonable data-protection grounds within thirty (30) days of notice; if the parties cannot resolve the objection, Customer's sole remedy is to terminate the affected Service in accordance with the Agreement.

7. International Transfers

Where PainRadar processes Customer Personal Data originating in the EEA, UK, or Switzerland in a country that has not received an adequacy decision, the parties incorporate the Standard Contractual Clauses (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable) by reference, with Customer as data exporter and PainRadar as data importer, completed using the details in Annexes I through III of this DPA.

8. Personal Data Breach Notification

PainRadar will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to PainRadar to assist Customer in meeting its own breach-notification obligations under Applicable Data Protection Law.

9. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in Section 15 (Limitation of Liability) of the Terms of Service.

10. Term and Termination

This DPA takes effect upon Customer's acceptance of the Agreement and remains in effect until, and automatically terminates upon, deletion of all Customer Personal Data by PainRadar as described in Section 5.

11. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Customer Personal Data, this DPA controls. In all other respects, the Terms of Service control.

12. Governing Law

This DPA is governed by the laws of the State of New Mexico, USA, consistent with Section 18 (Governing Law and Venue) of the Terms of Service, except that the Standard Contractual Clauses incorporated under Section 7 are governed by the law specified therein.

13. Contact

PainRadar LLC 8206 Louisiana Blvd NE, Ste A #7683 Albuquerque, NM 87113, USA contact@painradar.ai


Annex I — Details of Processing

Subject matter: PainRadar's provision of the Service to Customer under the Agreement.

Duration: For the term of the Agreement, plus any period during which PainRadar retains Customer Personal Data as described in Section 5.

Nature and purpose of processing: Hosting, storage, and automated analysis (including AI-based analysis) of Customer Personal Data submitted to the Service, in order to provide the Service's scanning, classification, and gap-analysis features.

Categories of Data Subjects: Customer's authorized users (Account holders) and any individuals whose information Customer includes in Your Content (e.g. names or identifiers within topic notes).

Categories of Personal Data: Account contact details (name, email); any Personal Data Customer chooses to include within Your Content (topic names, keywords, notes). PainRadar does not require Customer to submit special categories of Personal Data (as defined in GDPR Article 9), and Customer should not do so.

Annex II — Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageUnited States
AnthropicAI-based analysis of submitted contentUnited States
ApifyCollection of publicly available third-party platform contentEuropean Union
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
UpstashCaching and rate-limiting infrastructureUnited States

Annex III — Security Measures

PainRadar maintains the following technical and organizational measures:

  • Encryption of Customer Personal Data in transit (TLS) and at rest;
  • Access controls limiting access to Customer Personal Data to personnel who need it to perform their duties;
  • Authentication controls on Customer accounts and on PainRadar's administrative systems;
  • Logical separation of Customer data by workspace within the database layer;
  • Regular review of Sub-processor security practices.