Data Processing Addendum
Effective: September 15, 2026|Last updated: August 16, 2026|Version: 1.0|8 min read
Standard addendum for business customers using REPTOR OS services
This Customer Data Processing Addendum (“Customer DPA”) is between REPTOR LLC (“REPTOR”) and the business or organizational customer that accepts or executes an agreement for REPTOR services (“Customer”). It applies only when REPTOR processes Personal Data on Customer’s behalf. It does not govern ordinary direct-to-consumer use for which REPTOR acts as an independent Controller.
This Addendum is incorporated into the agreement governing the relevant services (the “Agreement”). If there is a conflict concerning processing of Personal Data, this Addendum controls. Capitalized terms not defined here have the meanings in the Agreement or Applicable Data Protection Law.
1. Definitions
- “Applicable Data Protection Law” means privacy, data protection, breach notification, consumer health data, and security laws applicable to the Processing, including as applicable the GDPR, UK GDPR, CCPA/CPRA, and U.S. state privacy laws.
- “Controller,” “Processor,” “Business,” “Service Provider,” “Contractor,” “Consumer,” “Data Subject,” “Personal Data,” “Personal Information,” “Processing,” “Sell,” and “Share” have the meanings given by Applicable Data Protection Law.
- “Customer Personal Data” means Personal Data processed by REPTOR on behalf of Customer under the Agreement.
- “Security Incident” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to protected Personal Data. It excludes unsuccessful attempts that do not compromise Personal Data.
- “Subprocessor” means a third party engaged by the Processor to process protected Personal Data on behalf of the Controller.
2. Roles and Scope
For processing governed by this Addendum, Customer acts as Controller or Business and REPTOR acts as Processor, Service Provider, or Contractor, unless Applicable Data Protection Law requires a different characterization for a specific activity. Each party remains independently responsible for processing it performs as a Controller.
The subject matter, duration, nature, purpose, categories of Data Subjects, and types of Personal Data are described in Schedule 1. Processing is limited to documented instructions in the Agreement, this Addendum, and Schedule 1, including transfers permitted by those documents.
3. Processing Instructions and Legal Compliance
- REPTOR will process protected Personal Data only on documented instructions from Customer, unless required by applicable law; where legally permitted, it will notify the Controller before processing under that requirement.
- REPTOR will promptly inform Customer if it believes an instruction violates Applicable Data Protection Law and may suspend the affected processing while the parties address the issue.
- Customer is responsible for the lawfulness, fairness, transparency, accuracy, and proportionality of its instructions and for providing required notices and obtaining required consents.
- Neither party is required to perform an instruction that violates applicable law.
4. Confidentiality and Access Controls
REPTOR will ensure that persons authorized to process protected Personal Data are bound by confidentiality obligations and access the data only as necessary for assigned duties. Access will be reviewed and removed when no longer required.
5. Security Measures
REPTOR will implement and maintain appropriate technical and organizational measures designed to protect protected Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage, alteration, or disclosure. Schedule 2 describes baseline measures. The parties acknowledge that security is risk-based and evolves over time.
6. Subprocessors
Customer grants general written authorization for REPTOR to engage Subprocessors subject to this section. REPTOR will impose written data-protection obligations materially protective of the data and remains responsible for Subprocessor performance to the extent required by applicable law.
REPTOR will provide reasonable advance notice of a new Subprocessor that materially affects processing. Customer may object on reasonable data-protection grounds within the notice period. The parties will work in good faith toward a commercially reasonable solution; if none is available, the affected service may be discontinued in accordance with the Agreement.
7. Data Subject and Consumer Requests
Taking into account the nature of processing, REPTOR will provide reasonable assistance enabling Customer to respond to verified requests to access, correct, delete, restrict, object, port, opt out, withdraw consent, or exercise other rights. If REPTOR receives a request relating to protected Personal Data, it will direct the requester to Customer or forward the request unless prohibited by law.
8. Security Incidents
REPTOR will notify Customer without undue delay after confirming a Security Incident involving protected Personal Data and will provide information reasonably available concerning its nature, affected data and persons, likely consequences, mitigation, and contact point. Notice is not an admission of fault. REPTOR will take reasonable steps to contain, investigate, remediate, and prevent recurrence and will reasonably cooperate with legally required notifications.
9. Assessments, Consultations, and Compliance Information
Taking into account the nature of processing and information available, REPTOR will provide reasonable assistance with data protection impact assessments, risk assessments, prior consultations, regulatory inquiries, and compliance obligations applicable to the processing. On reasonable written request, it will make available information necessary to demonstrate compliance, subject to confidentiality, security, privilege, and proportionality safeguards.
10. Audits
No more than once annually, unless a Security Incident, regulator request, or reasonable evidence of material noncompliance justifies additional review, Customer may request relevant audit reports, certifications, questionnaires, or other documentation. If those materials are insufficient, the parties may arrange a scoped audit during normal business hours with reasonable notice, confidentiality protections, minimal disruption, and allocation of costs under the Agreement.
11. Return and Deletion
At the end of the Services, REPTOR will, at Customer’s choice and subject to applicable law, return or delete protected Personal Data and delete copies within its control. Data retained under law, legal hold, security requirements, or technically isolated backup cycles will remain protected and will not be used for other purposes.
12. International Transfers
The parties will use a valid transfer mechanism where required. For restricted transfers from the EEA, the applicable modules of the European Commission’s 2021 Standard Contractual Clauses are incorporated by reference when necessary and completed using Schedule 3. For restricted UK transfers, the UK International Data Transfer Addendum or another valid mechanism applies. The parties will reasonably cooperate on transfer risk assessments and supplementary measures.
13. U.S. State Privacy Terms
- REPTOR will not sell or share protected Personal Data, retain, use, or disclose it outside the direct business relationship or permitted purposes, or combine it with data from other sources except as allowed by Applicable Data Protection Law.
- REPTOR will provide the same level of privacy protection required of the applicable Business or Controller, permit reasonable monitoring, and notify Customer if it can no longer meet its obligations.
- Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
- Consumer health data will be processed only under binding instructions consistent with applicable health-data privacy notices and applicable consent requirements.
14. Liability, Term, and Order of Precedence
This Addendum remains effective while protected Personal Data is processed. Liability is governed by the Agreement unless prohibited by Applicable Data Protection Law. The mandatory terms of incorporated transfer clauses control over conflicting terms, followed by this Addendum, then the Agreement.
15. Notices and Execution
REPTOR privacy notices under this Addendum may be sent to support@reptoros.com. Customer notices must be sent to the contact identified in the Agreement. This Customer DPA may be accepted electronically, incorporated through an order form, or executed in counterparts.
Schedule 1 — Processing Details
| Field | Description |
|---|---|
| Subject matter | Provision, support, security, and administration of contracted REPTOR OS services for Customer. |
| Duration | For the Agreement term and any limited retention period permitted by the Agreement, documented instructions, or applicable law. |
| Nature and purpose | Account administration, authentication, customer support, configuration, fitness and wellness functionality selected by Customer, analytics directed by Customer, security, and service delivery. |
| Data Subjects | Customer-authorized users, employees, contractors, administrators, support contacts, and other individuals whose data Customer submits lawfully. |
| Personal Data | Names, contact details, account identifiers, authentication data, role and organization data, usage data, support communications, device and log data, and Customer-submitted content. |
| Potential sensitive data | Fitness, wellness, body measurement, activity, nutrition, progress, or consumer health data only when enabled and lawfully submitted by Customer; REPTOR does not request medical records unless expressly agreed. |
| Frequency | Continuous or intermittent, depending on Customer use. |
| Deletion | Through product controls where available and otherwise under the Agreement and Section 11. |
| Controller contact | Customer contact identified in the Agreement or order form. |
| Processor contact | REPTOR LLC, support@reptoros.com, 18117 Biscayne Blvd #1400, Miami, FL 33160, United States. |
Schedule 2 — Baseline Technical and Organizational Measures
- Governance: documented privacy and security responsibilities, risk-based policies, workforce confidentiality, and periodic review.
- Access control: least privilege, unique accounts, authentication controls, prompt access removal, and privileged-access restriction.
- Data protection: encryption in transit using current industry-standard protocols and encryption at rest where appropriate to risk and supported by the service.
- Secure operations: vulnerability management, patching, environment separation where appropriate, logging, monitoring, and change controls.
- Resilience: backups or recovery mechanisms appropriate to the service, incident response procedures, and continuity planning.
- Vendor management: risk-based due diligence, written obligations, and oversight for subprocessors handling protected Personal Data.
- Data minimization: collection, access, retention, and disclosure limited to documented purposes and operational need.
- Incident response: detection, containment, investigation, remediation, evidence preservation, and legally required cooperation.
Schedule 3 — International Transfer Details
| Field | Description |
|---|---|
| EU SCC modules | Module Two (Controller to Processor) or Module Three (Processor to Processor), as applicable to the parties’ roles. |
| Docking clause | Applies where permitted by the incorporated SCCs. |
| Supervisory authority | Determined under Clause 13 of the SCCs based on the exporter and affected Data Subjects. |
| Governing EU law | The law of an EU Member State permitting third-party beneficiary rights; selected in the applicable order form or agreement. |
| Forum | Courts corresponding to the selected governing EU law. |
| UK transfers | The then-current ICO International Data Transfer Addendum to the EU SCCs, completed using this Addendum and the Agreement. |
| Additional safeguards | Encryption, access controls, data minimization, government-request review, and supplementary measures appropriate to the transfer risk. |
Schedule 4 — Authorized Subprocessors
The current Subprocessor list will be made available through REPTOR’s legal or trust materials when business processing begins. The list must identify each Subprocessor’s name, purpose, and processing location. REPTOR must not describe a provider as active until it is actually used for the relevant Customer service.

