Data Processing Agreement

Last updated on October 2nd, 2026

Effective October 2nd, 2026

Introduction

This Data Processing Agreement ("DPA") binds only when it has been executed (signed) by both VividEngine, LLC (doing business as Fast Technologies) ("Fast"), 4747 Research Forest Dr., Ste 180-265, The Woodlands, TX 77381-4902, and an eligible customer ("Customer"). Once executed, it governs the processing of personal data by Fast on behalf of the Customer. "We", "us", and "our" refer to Fast; "you" and "your" refer to the Customer. This DPA supplements the Fast.io Terms of Service and any separately signed agreement between Fast and the Customer, such as a master services agreement or order form (together, the "Agreement"). This DPA applies to the extent that Fast processes personal data subject to applicable data protection laws, including the European Union General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), the Texas Data Privacy and Security Act ("TDPSA"), other U.S. state consumer privacy laws, and other applicable privacy regulations.

Execution & Eligibility:

This DPA is published for review. It is not incorporated into the Fast.io Terms of Service, and it becomes binding only when it has been executed (signed) by both Fast and the Customer. Execution is available to customers on Fast's Enterprise Plus plan and to customers that have a separately signed agreement with Fast, such as a master services agreement or order form. To request an executed copy, contact privacy@fast.io.

Which means:

This agreement explains how we handle your data when we process it on your behalf, especially for GDPR and CCPA compliance. It applies once we have both signed it, which we do for Enterprise Plus customers and customers with a signed contract. Email privacy@fast.io to request one.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Fast on behalf of the Customer through the Services.
  • "Data Controller" means the Customer, which determines the purposes and means of processing Personal Data. Where the Customer processes Personal Data on behalf of its own customers, the Customer acts as a processor, and references in this DPA to the Customer as Data Controller apply to the Customer in that processor role, acting on its controllers' instructions.
  • "Data Processor" means Fast, which processes Personal Data on behalf of the Customer, as a processor where the Customer is a controller, or as a sub-processor where the Customer is itself a processor.
  • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
  • "Sub-processor" means any third party engaged by Fast to process Personal Data on behalf of the Customer.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • "Content" has the meaning given in the Fast.io Terms of Service.
  • "Services" means the Fast platform, APIs, MCP servers, desktop applications, and any other products or services provided by Fast.

2. Scope and Purpose of Processing

Fast processes Personal Data solely for the purpose of providing the Services as described in the Agreement, including:

  • File storage, synchronization, and sharing services
  • Desktop application synchronization (macOS and Windows)
  • Programmatic access via APIs and MCP servers
  • Agent Account operations and automated actions taken through the API or MCP
  • Comments, notes, AI features, and e-signature workflows used by the Customer and its users
  • Access control for the Customer's users, as the Customer configures it
  • Customer support relating to the Services
  • Security and abuse prevention

Fast processes account, billing, and service-usage data, including the authentication of the Customer's users and their 2FA phone numbers, as an independent controller under its Privacy Policy; this DPA does not govern that processing.

The types of Personal Data processed may include: names, email addresses, IP addresses, device identifiers, file metadata, comments, notes, AI chat prompts and responses, e-signature data (signer name, email, phone number, signature, IP address and browser), audit and activity logs visible to the Customer, and any Personal Data contained within Content uploaded by the Customer or its users. Data Subjects may include: Customer employees, contractors, customers, recipients of shares, guest uploaders, e-signature signers who do not hold a Fast account, and any other individuals whose data is stored or processed through the Services. Fast does not require sensitive data; any special-category data in Content is determined solely by the Customer.

Which means:

We only use personal data to provide our services to you: storing files, syncing across devices, handling API requests, and keeping things running smoothly. Your account and billing details are covered by our Privacy Policy instead.

3. Obligations of Fast as Data Processor

Fast agrees to:

  • Process Personal Data only on documented instructions from the Customer, unless required by applicable law
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures as described in Section 5
  • Assist the Customer in responding to Data Subject requests to exercise their rights under applicable law
  • Assist the Customer in ensuring compliance with security, breach notification, and data protection impact assessment obligations
  • Delete or return Personal Data within 180 days after termination of the Agreement, subject only to the retention exceptions in Section 12. Data kept under these exceptions remains protected by these terms until it is deleted.
  • Make available information necessary to demonstrate compliance with this DPA
  • Notify the Customer promptly if Fast believes an instruction violates applicable data protection law
  • Maintain records of processing activities as required by Article 30 of the GDPR

Which means:

We follow your instructions, keep data confidential, maintain security, help you respond to user requests, and delete data when you're done with our services, except the data Section 12 lists as kept longer, which stays protected until it is deleted.

4. Obligations of the Customer as Data Controller

The Customer agrees to:

  • Ensure that the processing of Personal Data through the Services has a valid legal basis
  • Provide clear and documented instructions to Fast regarding the processing of Personal Data
  • Ensure that Data Subjects have been informed of and have consented to the processing of their data where required
  • Comply with all applicable data protection laws in the collection and use of Personal Data
  • Maintain appropriate security measures for any devices, Agent Accounts, or programmatic access used to interact with the Services
  • Notify Fast promptly of any changes to processing instructions or any Data Subject requests received directly
  • Where the Customer acts as a processor for its own customers, ensure that its instructions to Fast, and its engagement of Fast as a sub-processor, are authorized by the relevant controller

Which means:

You're responsible for making sure you have the right to upload the data you share with us and that you've gotten proper consent from your users.

5. Security Measures

Fast owns and operates its own servers and network, in leased space at a third-party data center in the United States whose provider maintains its own SOC 2 Type II, ISO/IEC 27001, and PCI DSS certifications. Those certifications belong to the data center provider, not to Fast. Fast implements and maintains appropriate technical and organizational measures to protect Personal Data, including:

  • Hosting on Fast-operated servers in a third-party data center in the United States
  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256
  • Access controls and authentication mechanisms, including support for two-factor authentication
  • Enterprise single sign-on (OIDC, SAML) with SCIM provisioning
  • Role-based access controls
  • Audit logging of account and content activity
  • Independent assessment under Google CASA (Assurance Level 1); automated security analysis before code is committed and static analysis in CI
  • Employee security training and confidentiality agreements
  • Security monitoring and alerting
  • Secure software development practices
  • Physical security measures for data center facilities
  • Business continuity and disaster recovery procedures
  • API rate limiting and automated abuse detection for programmatic access and Agent Accounts

Which means:

We use industry-standard encryption, access controls, monitoring, and security practices to keep data safe.

6. Sub-processors

The Customer authorizes Fast to engage Sub-processors to assist in providing the Services. Fast maintains a current list of Sub-processors at fast.io/legal/subprocessors, which is incorporated into and forms part of this DPA. Fast ensures that Sub-processors are bound by data protection obligations no less protective than those in this DPA, and Fast remains liable to the Customer for the performance of each Sub-processor's data protection obligations as required by Article 28(4) of the GDPR.

Important: Customer Content is stored on Fast-operated infrastructure. Customer Content, or portions of it, may be processed by the following Sub-processors only as described: (a) Cloudflare, which carries Content in transit over its edge network, hosts real-time collaboration content (such as collaborative notes), and temporarily stages files uploaded through the Fast MCP server; a staged file is deleted when it is used, and an unused one becomes unreadable after five minutes and is removed the next time that session stages or uses a file; (b) Google Cloud, which performs AI processing with Gemini and Anthropic Claude models on Vertex AI and temporarily stores files while AI features process them, for up to approximately seven days; (c) Voyage AI, which generates search embeddings from Content; (d) LangChain, Inc. (LangSmith), which records AI requests and responses, which may include prompts, AI answers, and excerpts of files; (e) Brave Search, which receives web search queries that the AI generates from a user's request; (f) Lunaweb GmbH (CloudConvert), which converts files and generates previews for formats Fast cannot render itself; (g) Twilio (SendGrid), which delivers notification emails that can include comment excerpts, file names, and thumbnails; and (h) PostHog, which may receive limited Content in page titles, page addresses, and error reports. PostHog session replay in the web application masks on-screen text and text-bearing attributes and blocks images and media, and autocaptured clicks omit element text and attributes. PostHog may still receive limited customer content in page titles and page addresses (for example a file, folder, or share name) and in error reports. Other Sub-processors (such as payment, authentication, error monitoring, and support services) receive only operational data necessary for their specific function and are not provided access to Customer files; limited file metadata may, however, incidentally appear in operational logs, error reports, or support communications.

Fast reserves the right to add or change Sub-processors as the Services evolve. We update fast.io/legal/subprocessors at least 15 days before a new Sub-processor begins processing personal data, and at the same time we email customers who have an executed DPA. Business customers may object on reasonable data protection grounds by emailing privacy@fast.io within that period. If we cannot resolve the objection, the customer may stop using the affected Services. Fast will work with the Customer in good faith to address an objection. If the Customer stops using the affected Services for this reason, it may also terminate them and receive a pro-rata refund of any prepaid fees for the terminated portion of the then-current subscription term. This does not limit any non-waivable statutory right or remedy available to the Customer or a Data Subject under applicable data protection law, including under the Standard Contractual Clauses (as defined in Section 10). For Clause 9(a) of the Standard Contractual Clauses, Option 2 (general written authorisation) applies and the time period is fifteen (15) days.

Customer-Connected Services: The Services allow the Customer to connect, or to direct Fast to connect to, third-party services and tools chosen by the Customer, including MCP (Model Context Protocol) servers, integrations, connectors, and other external tools. When the Customer enables such a connection, the Customer instructs and authorizes Fast to transmit the relevant Content and Personal Data to that third-party service so that it can perform the function the Customer requested. These customer-connected services are not Fast Sub-processors; they operate under the Customer's own relationship with, and the terms of, the relevant third party. The Customer is solely responsible for these connections, including the data protection practices of the connected service and having a lawful basis for the transfer, and the Customer controls and may disable them at any time.

Which means:

We use trusted partners to help run our service, and we keep the full, current list on a dedicated page. We'll update it and email you at least 15 days before adding a new one. If you're not comfortable with a new vendor, your option is to stop using the affected Services. Anything you choose to connect yourself (like an MCP server or integration) is your call: if you connect it, we'll send data to it because you asked us to.

7. Data Subject Rights

Fast will assist the Customer in responding to requests from Data Subjects exercising their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, data portability, and objection. If Fast receives a request directly from a Data Subject, Fast will promptly notify the Customer unless prohibited by law. The Customer is responsible for responding to such requests, and Fast will provide reasonable assistance as needed.

Which means:

If someone wants to access, correct, or delete their data, we'll help you handle that request.

8. Data Breach Notification

Fast will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer data. The notification will include, to the extent known: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach. Fast will cooperate with the Customer and provide reasonable assistance in investigating and remediating the breach.

Which means:

If there's ever a data breach affecting your data, we'll tell you within 72 hours and work with you to fix it.

9. Audit Rights

Upon reasonable written request and subject to confidentiality obligations, Fast will make available to the Customer information necessary to demonstrate compliance with this DPA. The Customer may conduct an audit, or engage a third-party auditor, no more than once per year, with at least 30 days' advance notice. Fast may instead provide a report of an independent assessment. The annual limit does not apply after a Personal Data breach, where there are indications of non-compliance, or where a supervisory authority requires an audit. Audits shall be conducted during normal business hours and in a manner that minimizes disruption to Fast's operations. The Customer shall bear the costs of any audit unless the audit reveals material non-compliance by Fast.

Which means:

You can audit our data protection practices once a year with advance notice, or more often after a breach, if there are signs of non-compliance, or if a regulator requires it. We may offer an independent assessment report instead, and we'll provide the information you need.

10. International Data Transfers

Fast stores Customer Content in the United States. Some processing takes place outside the United States: AI processing through the Google Cloud Vertex AI global endpoint, and Content in transit over Cloudflare's global edge network. For transfers of Personal Data from the European Economic Area (EEA) to the United States or other countries not recognized as providing adequate data protection, Fast relies on the standard contractual clauses adopted by the European Commission in Commission Implementing Decision (EU) 2021/914 (the "Standard Contractual Clauses" or "SCCs"): Module Two (controller to processor) where the Customer acts as controller, and Module Three (processor to processor) where the Customer acts as processor.

(a) SCC elections. Clause 7 (docking clause) applies. For Clause 9(a), Option 2 (general written authorisation) applies, with a time period of 15 days, as set out in Section 6. The optional language in Clause 11 does not apply. Clause 13 and Annex I.C apply as set out in Appendix A. For Clause 17, Option 1 applies, and the governing law is the law of Ireland. For Clause 18(b), disputes are resolved by the courts of Ireland.

(b) Transfers from the United Kingdom. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) (the "UK Addendum") applies. Its Tables 1 to 3 are completed by this DPA and its Appendix A. For Table 4, either party may end the UK Addendum as permitted by its Section 19. The governing law and courts are those of England and Wales, and the Information Commissioner's Office (ICO) is the competent supervisory authority.

(c) Transfers from Switzerland. The Standard Contractual Clauses apply with these changes: the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority; references to the GDPR include the Swiss Federal Act on Data Protection (FADP); and the term "Member State" in Clause 18(c) does not exclude data subjects in Switzerland from bringing proceedings in their place of habitual residence.

(d) Incorporation and precedence. When this DPA is executed, the Standard Contractual Clauses, with the elections in Section 10(a) and as supplemented by Sections 10(b) and 10(c) where relevant, are incorporated into this DPA by reference, and their Annexes are completed as set out in Appendix A and any company-specific details agreed at execution. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

Which means:

We store your files in the US. Some processing happens elsewhere: AI features run on Google's global endpoint, and data in transit crosses Cloudflare's global network. If you're in Europe, the UK, or Switzerland, we use the EU's approved contract terms (with the UK and Swiss additions) to transfer data lawfully.

11. Desktop Applications and Programmatic Access

This DPA applies to all methods of accessing the Services, including through our desktop applications for macOS and Windows, as well as programmatic access via APIs, MCP (Model Context Protocol) servers, SDKs, and Agent Accounts. The Customer acknowledges that:

  • Desktop applications store authentication credentials and cache data locally on user devices; the Customer is responsible for the security of those devices
  • Programmatic access and Agent Accounts may process Personal Data automatically; the Customer remains the Data Controller (or, where it acts for its own customers, the processor) for all such processing
  • Fast monitors programmatic access for security and abuse prevention, which may involve automated analysis of access patterns
  • Agent Account activity is attributable to the Customer, and the Customer is responsible for ensuring agents comply with applicable data protection law

Which means:

Whether you use our desktop app, API, or connect through agents, this agreement covers all of it. You're responsible for securing your devices and making sure your bots follow the rules.

12. Term and Termination

This DPA remains in effect for the duration of Fast's processing of Personal Data on behalf of the Customer. Upon termination of the Agreement, Fast will, at the Customer's choice, delete or return all Personal Data within 180 days. Some data is kept longer: data under a legal hold, until the hold is released; e-signature envelopes and their records, for up to seven years; billing and tax records, as the law requires; usage records, for up to 120 days; activity history and audit records, as needed for security, audit, and legal purposes; backups, which contain account and file metadata but not file contents, for no longer than one year and restored only for disaster recovery; and copies held by Sub-processors, which are deleted on their own schedules. Data kept under these exceptions remains protected by these terms until it is deleted. Fast may retain anonymized or aggregated data that does not identify individuals. Provisions of this DPA that by their nature should survive termination (including confidentiality and the deletion and return obligations) will survive.

Which means:

This agreement lasts as long as we process your data. When you leave, we'll delete or return your data within 180 days. Some data is kept longer: data under a legal hold, until the hold is released; e-signature envelopes and their records, for up to seven years; billing and tax records, as the law requires; usage records, for up to 120 days; activity history and audit records, as needed for security, audit, and legal purposes; backups, which contain account and file metadata but not file contents, for no longer than one year and restored only for disaster recovery; and copies held by Sub-processors, which are deleted on their own schedules. Data kept under these exceptions remains protected by these terms until it is deleted.

13. Modifications

Fast may update the standard form of this DPA published on this page from time to time to reflect changes in data protection law or our practices. Changes to an executed DPA take effect only as agreed in writing by the parties, except that changes to Sub-processors follow Section 6, and changes required by applicable law take effect when Fast gives the Customer notice of them.

14. Governing Law and Disputes

Except for the Standard Contractual Clauses and the UK Addendum, this DPA is governed by, and disputes arising out of or relating to it are resolved under, the governing-law and dispute-resolution provisions of the Fast.io Terms of Service, currently the substantive law of the State of Texas and final, binding arbitration seated in Houston, Harris County, Texas. The Standard Contractual Clauses (including as applied to transfers from Switzerland) are governed by the law of Ireland, and disputes under them are resolved by the courts of Ireland, as elected in Section 10(a). The UK Addendum is governed by the law of England and Wales, and disputes under it are resolved by the courts of England and Wales, as set out in Section 10(b). Nothing in this DPA or the Terms of Service limits or waives any non-waivable statutory right or remedy a Data Subject has under applicable data protection law, including the right to lodge a complaint with a supervisory authority or to bring proceedings in the Data Subject's country of habitual residence.

Which means:

Commercial disputes follow our Terms of Service (Texas law, arbitration in Houston). The EU transfer clauses follow Irish law and Irish courts, and the UK addendum follows the law and courts of England and Wales. Your local data protection rights, such as complaining to your regulator, still apply. We don't take those rights away.

15. U.S. State Privacy Law Terms

To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies to Fast's processing of Personal Information (as defined in the CCPA) on behalf of the Customer, Fast acts as a "service provider" and not as a "third party," and Fast:

  • will not sell or share Personal Information, as those terms are defined under the CCPA;
  • will not retain, use, or disclose Personal Information for any purpose other than the business purpose of providing the Services specified in the Agreement, or as otherwise permitted by the CCPA;
  • will not retain, use, or disclose Personal Information outside the direct business relationship between Fast and the Customer;
  • will not combine Personal Information received from the Customer with personal information from other sources, except as permitted by the CCPA;
  • will comply with its applicable obligations under the CCPA and provide the same level of privacy protection the CCPA requires;
  • will notify the Customer if Fast determines it can no longer meet its obligations under the CCPA; and
  • grants the Customer the right to take reasonable and appropriate steps to ensure that Fast uses Personal Information in a manner consistent with the Customer's obligations under the CCPA, and to stop and remediate unauthorized use of Personal Information.

Fast certifies that it understands and will comply with these restrictions. Sub-processors that Fast engages to process Personal Information are bound by equivalent service-provider or contractor obligations.

To the extent Fast acts as a "processor" under the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541) or a similar U.S. state consumer privacy law, Fast: (a) processes Personal Data only on the Customer's documented instructions, which are set out in this DPA, including the nature and purpose of processing, the type of data, the duration of processing, and the rights and obligations of both parties; (b) ensures that each person processing Personal Data is subject to a duty of confidentiality; (c) at the Customer's direction, deletes or returns Personal Data within 180 days after the end of the Services, as described in Section 12, except the data Section 12 lists as kept longer, which remains protected by these terms until it is deleted; (d) makes available to the Customer the information necessary to demonstrate compliance; (e) allows and cooperates with reasonable assessments by the Customer or its designated assessor, or provides a report of an independent assessment, as described in Section 9; and (f) engages subcontractors only under a written contract imposing the same obligations, after giving the Customer the opportunity to object, as described in Section 6.

Which means:

Under California, Texas, and similar U.S. state privacy laws, we act as your service provider or processor: we only use your data to run the Services on your instructions, don't sell or share it, keep it confidential, delete or return it within 180 days when you leave (except the data Section 12 lists as kept longer, which stays protected until it is deleted), let you check our compliance, and hold our vendors to the same rules.

16. Privacy Contact

Fast has not appointed a Data Protection Officer as we do not meet the mandatory appointment thresholds under GDPR Article 37. However, for all data protection inquiries or questions about this DPA, please contact our privacy team at privacy@fast.io. Executed copies of this DPA, including the Standard Contractual Clauses, are available to Enterprise Plus customers and customers with a separately signed agreement with Fast.

Appendix A: Standard Contractual Clauses (Annexes)

Where the Standard Contractual Clauses (as defined in Section 10) apply to transfers of Personal Data under this DPA, the following completes their Annexes by reference. The UK Addendum and transfers from Switzerland use the same information, with the UK provisions set out in Section 10(b) and the Swiss changes set out in Section 10(c).

  • Annex I.A: List of Parties. Data exporter: the Customer (and its authorized affiliates and users), acting as controller or, where it processes Personal Data on behalf of its own customers, as processor. Data importer: VividEngine, LLC (doing business as Fast Technologies) ("Fast"), 4747 Research Forest Dr., Ste 180-265, The Woodlands, TX 77381-4902, contact privacy@fast.io, acting as processor or, where the Customer acts as processor, as sub-processor. Signature and date: the parties' execution of this DPA. The Customer's contact details are those set out in the executed DPA or, if none are given, those associated with the Customer's account.
  • Annex I.B: Description of Transfer. The categories of Data Subjects and Personal Data, and the nature, purpose, and duration of processing, are as described in Section 2 (Scope and Purpose of Processing) and Section 12 (Term and Termination). Transfers are continuous for the duration of the Services. Sub-processors are listed at fast.io/legal/subprocessors.
  • Annex I.C: Competent Supervisory Authority. The supervisory authority of the EU/EEA member state in which the data exporter (or its EU representative) is established, or as otherwise determined under Clause 13 of the SCCs.
  • Annex II: Technical and Organizational Measures. The measures described in Section 5 (Security Measures) apply as the technical and organizational measures under the SCCs.
  • Annex III: List of Sub-processors. The Customer authorizes the Sub-processors listed at fast.io/legal/subprocessors, as updated in accordance with Section 6.

For questions about this DPA, contact us at privacy@fast.io. Executed copies are available to Enterprise Plus customers and customers with a signed agreement.