Data Processing Addendum

Data Processing Addendum (DPA) — Figmentic|Words

Effective Date: September 6, 2025
Legal Entity: Xruseon, Inc., doing business as Figmentic, Inc. ("Figmentic," "we," "us," or "our")
Product: Figmentic|Words (the "Service")

This Data Processing Addendum ("DPA") forms part of the agreement between Figmentic and a business or enterprise customer ("Customer," "you," or "your") for the provision of the Service (the "Agreement"). It governs the processing of personal data that Customer makes available to Figmentic, or that Figmentic processes on Customer's behalf, in connection with Customer's use of the Service.

Who This DPA Applies To

This DPA applies only to business and enterprise Customers who, through their use of the Service, process personal data about their own end users, employees, or other individuals, and who have entered into an Agreement with Figmentic. If you are an individual consumer using Figmentic|Words for your own personal, non-commercial purposes, this DPA does not apply to you, and your use is governed instead by our Privacy Policy. Where there is a conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA controls.

1) Definitions

Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. The following terms apply:

  • Applicable Data Protection Law: all data protection and privacy laws applicable to the processing of personal data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
  • Controller: the entity that determines the purposes and means of the processing of personal data. For the purposes of the CCPA, "controller" includes a "business."
  • Processor: the entity that processes personal data on behalf of the Controller. For the purposes of the CCPA, "processor" includes a "service provider."
  • Sub-processor: any third party engaged by the Processor to process personal data on behalf of, and under the instructions of, the Controller.
  • Personal Data: any information relating to an identified or identifiable natural person ("data subject") that is processed by Figmentic on Customer's behalf under the Agreement.
  • Data Subject: the identified or identifiable natural person to whom the Personal Data relates.
  • Processing: any operation performed on Personal Data, whether automated or not, including collection, recording, storage, use, disclosure, and erasure.
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • Standard Contractual Clauses (SCCs): the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission and/or the UK International Data Transfer Agreement or Addendum, as applicable.

2) Roles and Scope of Processing

The parties acknowledge and agree that, with respect to Personal Data processed in connection with Customer's use of the Service, Customer acts as the Controller and Figmentic acts as the Processor. Where Customer itself acts as a processor on behalf of a third-party controller, Figmentic acts as a sub-processor.

Figmentic processes Personal Data only for the limited and specified purposes set out in this DPA and the Agreement. The details of the processing are as follows:

Subject Matter: the provision of the Service, including AI-assisted generation of summaries, themes, and reflections based on Bible passages associated with a date, account management, and related support.

Duration: for the term of the Agreement and any period thereafter required for return or deletion of Personal Data as described in Section 11.

Nature and Purpose: hosting, storage, AI processing of Customer-submitted inputs and settings, authentication, analytics, communications, security, and abuse prevention.

Categories of Data Subjects: Customer's authorized users and end users, and any individuals whose Personal Data is included in inputs Customer submits to the Service.

Types of Personal Data: account and contact details (such as name and email), authentication identifiers, usage and device data, and any free-text inputs, prompts, or notes that Customer or its users choose to submit. Customer is responsible for ensuring inputs do not include unnecessary or unlawful Personal Data.

3) Customer Instructions

Figmentic will process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Figmentic will, where legally permitted, inform Customer of that legal requirement before processing).

Customer's instructions are set out in the Agreement and this DPA, as supplemented by Customer's lawful use of the configuration options and features of the Service. Customer is responsible for the lawfulness of its instructions and represents that it has all necessary rights, consents, and legal bases to provide the Personal Data to Figmentic for processing.

Figmentic will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, although Figmentic has no obligation to provide legal advice and Customer remains solely responsible for compliance assessments relating to its own data.

4) Confidentiality of Personnel

Figmentic ensures that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory), are made aware of the confidential nature of the Personal Data, and receive guidance appropriate to their role on the secure handling of Personal Data. Access to Personal Data is limited to personnel who need it to provide, support, or secure the Service.

5) Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Figmentic implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk. Consistent with the security commitments described in our Privacy Policy, these measures include:

  • Encryption in Transit: Personal Data is encrypted in transit using industry-standard transport encryption (e.g., TLS).
  • Access Controls: role-based access controls and authentication safeguards to restrict access to Personal Data.
  • Least-Privilege: access to Personal Data is granted on a need-to-know, least-privilege basis and is reviewed periodically.
  • Resilience and Logging: measures designed to maintain the confidentiality, integrity, and availability of processing systems, including diagnostic logging and monitoring for abuse and security events.
  • Vendor Controls: reliance on reputable infrastructure providers (such as Google Cloud and Firebase) that maintain recognized security and compliance programs.

No system is completely secure. Customer is responsible for its own security configuration, credentials, and the security of any systems Customer uses to access the Service.

6) Sub-processors

Customer provides a general authorization for Figmentic to engage Sub-processors to support the provision of the Service. Figmentic enters into written agreements with each Sub-processor imposing data protection obligations no less protective than those in this DPA, and remains responsible for the performance of its Sub-processors' obligations.

Figmentic currently engages Sub-processors in the following categories:

  • Cloud Hosting and Infrastructure: Google Cloud and Firebase (including Firebase Authentication, Cloud Firestore, and Firebase App Check via reCAPTCHA Enterprise).
  • AI Processing: Google Vertex AI (Gemini) for generating summaries, themes, and reflections from submitted inputs.
  • Analytics: Google Tag Manager and associated analytics tooling for aggregated usage measurement and performance.
  • Email and Marketing: Mailchimp for transactional and marketing communications where applicable.
  • Forms: Formspree for contact, feedback, and account-deletion request forms.
  • Payments (future): Stripe, if and when paid tiers are introduced. Mobile in-app purchases, if offered, would be billed by the Apple App Store or Google Play.

A current list of Sub-processors is available on request by emailing privacy@figmentic.com. Figmentic will provide a mechanism to notify Customer of intended changes to its Sub-processors. Customer may object in writing to a new Sub-processor on reasonable, documented data protection grounds within the notice period; the parties will work in good faith to address the objection, and if it cannot be resolved, Customer may terminate the affected portion of the Service in accordance with the Agreement.

7) Assistance with Data-Subject Requests

Taking into account the nature of the processing, Figmentic will provide reasonable assistance to Customer, through appropriate technical and organizational measures and insofar as practicable, to enable Customer to respond to requests from data subjects exercising their rights under Applicable Data Protection Law (such as access, rectification, erasure, restriction, portability, and objection). If Figmentic receives a request directly from a data subject relating to Personal Data processed on Customer's behalf, Figmentic will, where legally permitted, advise the data subject to submit the request to Customer and will not respond to the request except on Customer's documented instructions or as required by law.

8) Personal Data Breach Notification

Figmentic will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on Customer's behalf. Such notification will, to the extent then known and reasonably available, describe:

  • the nature of the breach, including the categories and approximate number of data subjects and records affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its possible adverse effects; and
  • a point of contact for further information.

Figmentic will provide reasonable cooperation and assistance to support Customer's obligations to notify supervisory authorities and affected data subjects where required. Figmentic's notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.

9) International Transfers

Figmentic is U.S.-based, and Personal Data may be processed in the United States or other countries where Figmentic or its Sub-processors operate. Where Customer's transfer of Personal Data to Figmentic, or an onward transfer by Figmentic, requires a lawful transfer mechanism under Applicable Data Protection Law, the parties agree that the applicable Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Agreement or Addendum) are incorporated into this DPA by reference and apply to such transfers. Where the SCCs apply, Customer acts as the data exporter and Figmentic as the data importer, and the appropriate modules and selections are deemed completed consistent with the roles and processing described in this DPA.

10) Audits and Information

Figmentic will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, subject to the following conditions:

  • Customer provides reasonable prior written notice, and audits occur no more than once per year except where required by a supervisory authority or following a Personal Data Breach;
  • audits are conducted during normal business hours, in a manner that does not disrupt Figmentic's operations, and subject to confidentiality obligations;
  • Figmentic may satisfy audit requests, where appropriate, by providing relevant policies, certifications, or third-party audit reports of its infrastructure providers; and
  • each party bears its own costs associated with an audit.

11) Return and Deletion of Data

Upon termination or expiry of the Agreement, Figmentic will, at Customer's choice, delete or return all Personal Data processed on Customer's behalf and delete existing copies, unless retention is required by applicable law. Customer may also use the in-app account-deletion functionality (available in Settings), the Formspree-backed deletion request form, or email privacy@figmentic.com to request deletion. Figmentic may retain limited Personal Data to the extent required by law or for the establishment, exercise, or defense of legal claims, in which case Figmentic continues to protect it in accordance with this DPA. Personal Data held in routine backups is deleted in accordance with Figmentic's standard backup retention cycles.

12) Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. Any reference in the Agreement to the liability of a party means the aggregate liability of that party under and in connection with the Agreement and this DPA together. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under Applicable Data Protection Law.

13) How to Execute This DPA

Business and enterprise Customers who require a countersigned copy of this DPA, or who need to incorporate the Standard Contractual Clauses with completed annexes, should contact legal@figmentic.com with the following information:

  • the full legal name and address of the Customer entity entering into the DPA;
  • the name, title, and email address of the authorized signatory;
  • the account or order associated with your use of the Service; and
  • any specific transfer-mechanism or regulatory requirements applicable to your organization.

Once executed, this DPA is incorporated into and forms part of the Agreement. If no separate Agreement exists, this DPA applies to the extent Figmentic processes Personal Data on Customer's behalf in connection with the Service.

14) Contact

Xruseon, Inc. d/b/a Figmentic, Inc.

Email: legal@figmentic.com (legal/DMCA) • privacy@figmentic.com (privacy/data)

Mailing: 1621 CENTRAL AVE #6094, Cheyenne, WY 82001