Last updated: July 1, 2026
This is a template outline. Enterprise customers who need a signed DPA should request one at legal@scoringfactory.ai — we'll send the current version for execution.
Where ScoringFactory processes personal data on Customer's behalf to provide the Service, Customer is the "Controller" (or "Business") and ScoringFactory is the "Processor" (or "Service Provider"), as those terms are defined under applicable data protection law (e.g. GDPR, CCPA).
ScoringFactory processes personal data for the duration of the underlying subscription agreement, solely to provide the scoring service described there.
Collection, enrichment, and analysis of publicly available and Customer-provided information about founders and candidates, for the purpose of generating evidence-backed scores for Customer's diligence or hiring decisions.
Customer authorizes ScoringFactory to engage the subprocessors listed on our Trust & security page. We'll give notice before adding a new subprocessor so Customer can object on reasonable grounds.
Where personal data is transferred outside the EEA or UK, the parties incorporate the Standard Contractual Clauses (or another lawful transfer mechanism) by reference.
Customer may request evidence of ScoringFactory's compliance, including any available SOC 2 report or completed security questionnaire, once per year. On-site audits are available for cause, with reasonable advance notice and confidentiality protections.
Liability under this DPA is governed by the limitation of liability provisions in the underlying Terms of Service.
Data protection questions or a signed copy of this DPA: legal@scoringfactory.ai.