Data Processing Addendum
Published: September 20, 2026
Data Processing Addendum
This Data Processing Addendum (“DPA”) supplements and forms part of the agreement governing a Customer’s use of the Services, including Scend’s Terms of Service or any applicable Order Form or Services Agreement (collectively, the “Agreement”), between Scend, Inc. (“Scend”) and the Customer identified in the Agreement (“Customer”).
This DPA applies to the extent Scend Processes Customer Personal Data on behalf of Customer in connection with the Services.
Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
Definitions
Applicable Data Protection Law means privacy, data protection, and data security laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the California Consumer Privacy Act, as amended (“CCPA”), the EU General Data Protection Regulation (“GDPR”), the UK General Data Protection Regulation (“UK GDPR”), and other applicable U.S. state privacy laws.
Controller, Processor, Business, Service Provider, Contractor, Consumer, Data Subject, Personal Data, Personal Information, Process, Processing, Sell, and Share have the meanings given to them under Applicable Data Protection Law.
Customer Content has the meaning provided in the Agreement and generally includes data, text, prompts, files, and other materials submitted to the Services by Customer or its Authorized Users.
Customer Personal Data means Personal Data contained in Customer Content that Scend Processes on behalf of Customer in connection with the Services, and other Personal Data that Scend Processes solely on Customer’s behalf pursuant to Customer’s documented instructions.
Customer Personal Data does not include Scend Data.
Scend Data means data, information, records, datasets, professional or business information, company information, contact information, metadata, classifications, embeddings, indexes, and other information that Scend or its providers obtain or develop independently of Customer Content, including information obtained from public sources, websites, licensed or commercial data providers, APIs, data partners, Scend’s own research or collection activities, or other lawful sources.
Scend Data may include Personal Data, including professional and business contact information. Scend Data remains Scend Data when it is identified, retrieved, returned, enriched, or otherwise made available in response to a Customer search, query, prompt, workflow, list, enrichment request, or other use of the Services.
Security Incident means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Scend. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, pings, port scans, denial-of-service attacks, or similar activity.
Subprocessor means a third party engaged by Scend to Process Customer Personal Data on behalf of Customer.
Roles of the Parties
With respect to Customer Personal Data, Customer is the Controller or Business, as applicable, and Scend is the Processor, Service Provider, or Contractor, as applicable.
Customer instructs Scend to Process Customer Personal Data as reasonably necessary to:
- Provide, operate, maintain, support, secure, and improve the Services
- Perform searches, research, enrichment, analysis, workflows, integrations, and other functionality requested or configured by Customer
- Generate and deliver Output
- Provide onboarding, implementation, support, integration assistance, technical advisory, workflow enablement, and forward deployed engineering
- Personalize Customer’s workspace and configured workflows
- Prevent fraud, abuse, and Security Incidents
- Comply with the Agreement and applicable law
- Otherwise Process Customer Personal Data in accordance with Customer’s documented instructions
The Agreement, Customer’s use and configuration of the Services, and written instructions provided by Customer constitute Customer’s documented instructions to Scend.
If Scend is required by applicable law to Process Customer Personal Data other than pursuant to Customer’s documented instructions, Scend will notify Customer of that requirement before Processing unless applicable law prohibits such notice.
Scend Data and Independent Processing
Scend operates and develops data products, datasets, indexes, and information resources independently of any particular Customer.
This DPA does not restrict Scend’s collection, licensing, acquisition, storage, caching, indexing, vectorization, embedding, analysis, enrichment, classification, combination, updating, or other Processing of Scend Data obtained from public sources, third-party data providers, APIs, websites, data partners, and other lawful sources.
Scend may maintain Scend Data in persistent databases, search indexes, vector databases, knowledge bases, caches, or other systems and may use such Scend Data in providing, operating, maintaining, and improving the Services, including making Scend Data available through the Services to Customer and other customers.
To the extent Scend determines the purposes and means of Processing Personal Data contained in Scend Data, Scend acts as an independent Controller or Business with respect to that Processing and not as Customer’s Processor, Service Provider, or Contractor.
For clarity:
- Scend Data does not become Customer Content or Customer Personal Data solely because Customer searches for, identifies, requests, receives, or uses the data through the Services
- Scend Data may have existed in Scend’s systems before Customer requested it
- Scend may independently obtain, maintain, update, or reacquire the same or similar information from sources independent of Customer Content
- Termination of Customer’s account or deletion of Customer Personal Data does not require Scend to delete Scend Data that Scend independently maintains
- Customer does not obtain ownership or exclusive rights in Scend Data merely because the data is returned through the Services
Scend will not treat Personal Data contained solely in Customer Content as Scend Data merely because Customer submitted that information to the Services.
Nothing in this DPA prevents Scend from independently obtaining the same or similar information from public sources, third-party data providers, APIs, websites, data partners, or other sources independent of Customer Content and maintaining that independently obtained information as Scend Data.
Scend may also use aggregated or de-identified information derived from the Services for analytics, benchmarking, evaluation, security, reliability, and product improvement, provided such information does not identify Customer or an individual as originating from Customer.
Scend’s Processing Obligations
With respect to Customer Personal Data, Scend will:
- Process Customer Personal Data in accordance with Customer’s documented instructions, the Agreement, and this DPA
- Ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations
- Implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data
- Provide reasonable assistance to Customer with Customer’s obligations under Applicable Data Protection Law, taking into account the nature of the Processing and information available to Scend
- Notify Customer if Scend reasonably believes a documented instruction violates Applicable Data Protection Law, unless prohibited by law
Customer Responsibilities
Customer is responsible for:
- Complying with Applicable Data Protection Law in its collection, use, and disclosure of Customer Personal Data
- Providing any notices and obtaining any rights, permissions, authorizations, or consents required for Scend to Process Customer Personal Data as contemplated by the Agreement
- Ensuring Customer’s instructions to Scend comply with applicable law
- Determining whether the Services are appropriate for Customer’s intended Processing activities
- Responding to Data Subject and Consumer requests where required by applicable law
- Using Scend Data, Output, and contact information obtained through the Services in compliance with applicable law
Customer represents that it has the rights necessary to provide Customer Personal Data to Scend and instruct Scend to Process it as contemplated by the Agreement.
Data Subject and Consumer Requests
Taking into account the nature of the Processing, Scend will provide reasonable assistance to Customer with requests by Data Subjects or Consumers to exercise rights applicable to Customer Personal Data, including rights of access, correction, deletion, restriction, objection, or portability where required by Applicable Data Protection Law.
If Scend receives a request directly from a Data Subject relating specifically to Customer Personal Data and can reasonably identify Customer as the relevant Controller or Business, Scend may direct the Data Subject to Customer or notify Customer of the request unless prohibited by applicable law.
Customer remains responsible for responding to requests for which Customer is the Controller or Business.
Requests concerning Personal Data for which Scend acts as an independent Controller or Business, including applicable Scend Data, may be handled separately by Scend in accordance with Scend’s Privacy Policy and applicable law.
Subprocessors
Customer provides Scend with general authorization to engage Subprocessors in connection with the Services.
Scend may use Subprocessors including:
- Cloud infrastructure and hosting providers
- AI and model providers
- Analytics and monitoring providers
- Communications and support providers
- Security providers
- Integration and infrastructure providers
- Other service providers necessary to operate and provide the Services
Where a Subprocessor Processes Customer Personal Data on Scend’s behalf, Scend will impose contractual data protection obligations appropriate to the nature of the services provided and the Customer Personal Data Processed.
Scend remains responsible for the performance of its obligations under this DPA notwithstanding its use of Subprocessors.
Scend may add or replace Subprocessors from time to time. Where required by Applicable Data Protection Law, Scend will provide reasonable notice of material additions or replacements of Subprocessors that Process Customer Personal Data.
Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice to Scend within fifteen days after receiving notice of the change.
The parties will work in good faith to address a reasonable objection. If the parties cannot resolve the objection, Scend may provide a commercially reasonable modification to the affected Services or Customer may discontinue the affected portion of the Services.
For clarity, a third-party data source or data vendor is not a Subprocessor solely because Scend obtains Scend Data from that provider. A provider is a Subprocessor under this DPA only to the extent it Processes Customer Personal Data on Scend’s behalf.
AI and Model Providers
Certain features of the Services may use third-party artificial intelligence or model providers.
To the extent an AI or model provider Processes Customer Personal Data on Scend’s behalf, that provider will be treated as a Subprocessor under this DPA.
Scend will use such providers in accordance with its contractual commitments, Usage Policy, and Applicable Data Protection Law.
Scend does not use Customer Content to train a general-purpose foundation model for broad external use unless Customer explicitly opts in in writing or through an applicable product setting.
Security
Scend will maintain an information security program containing administrative, technical, and organizational safeguards appropriate to the nature of the Customer Personal Data and the risks associated with the Processing.
Scend’s security measures may include, as appropriate:
- Access controls and least-privilege principles
- Authentication controls
- Encryption in transit and at rest
- Logging and monitoring
- Vulnerability management
- Incident response procedures
- Personnel confidentiality and security requirements
- Vendor and Subprocessor risk management
- Backup and recovery measures
- Business continuity measures
- Periodic testing and assessment of relevant security controls
Scend may make additional information regarding its security and compliance practices available through its trust center, security documentation, audit reports, penetration testing summaries, or other materials.
Security Incidents
Scend will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.
To the extent reasonably available, Scend will provide Customer with information concerning:
- The nature of the Security Incident
- The categories of Customer Personal Data affected
- Measures Scend has taken or plans to take to investigate, mitigate, or remediate the Security Incident
- Information reasonably necessary for Customer to satisfy applicable notification obligations
Scend may provide information in phases as additional information becomes available.
Notification of a Security Incident does not constitute an acknowledgment of fault or liability by Scend.
Customer is responsible for determining whether notification to regulators, Data Subjects, Consumers, or other parties is required, except where applicable law imposes such an obligation directly on Scend.
Retention and Deletion
Scend retains Customer Personal Data as necessary to provide the Services and for legitimate purposes including security, fraud prevention, dispute resolution, and compliance, subject to Applicable Data Protection Law.
Following termination or expiration of the Services, or upon Customer’s reasonable request where required by Applicable Data Protection Law, Scend will delete or return Customer Personal Data in accordance with the Agreement, Scend’s retention practices, and applicable law.
Scend may retain Customer Personal Data:
- Where required by applicable law
- In backups maintained pursuant to ordinary backup and disaster recovery procedures until overwritten or deleted in the ordinary course
- As reasonably necessary for security, fraud prevention, dispute resolution, or enforcement of the Agreement
- In aggregated or de-identified form that no longer identifies Customer or an individual as originating from Customer
Customer Personal Data retained under this section will remain subject to the protections of this DPA for so long as Scend retains it.
For clarity, deletion of Customer Personal Data does not require Scend to delete Scend Data independently obtained or maintained by Scend, even where Scend Data concerns the same individual, company, or entity appearing in Customer Personal Data.
Audits and Compliance Information
Upon Customer’s reasonable request, Scend will make available information reasonably necessary to demonstrate its compliance with this DPA.
Scend may satisfy such requests, where reasonably sufficient, by providing relevant:
- Independent audit reports or certifications
- Security and compliance documentation
- Penetration testing summaries
- Trust center materials
- Security questionnaires
- Other relevant compliance information
Customer will use existing reports and documentation where reasonably sufficient before requesting additional audit activity.
Any additional audit must:
- Be reasonably necessary to demonstrate compliance with Applicable Data Protection Law
- Occur no more than once in any twelve-month period unless otherwise required by a regulator or reasonably necessary following a Security Incident materially affecting Customer Personal Data
- Be conducted during normal business hours with reasonable advance notice
- Not unreasonably interfere with Scend’s operations
- Be subject to appropriate confidentiality and security requirements
- Not provide Customer or its auditor access to information belonging to other Scend customers or information that would compromise the security of Scend’s systems
Customer will bear its costs associated with an audit unless Applicable Data Protection Law requires otherwise.
U.S. State Privacy Laws
To the extent Scend Processes Customer Personal Data as a Service Provider or Contractor under the CCPA or similar role under another applicable U.S. state privacy law, Scend will:
- Process Customer Personal Data for the limited and specified purposes described in the Agreement and this DPA
- Not Sell or Share Customer Personal Data as those terms are defined by the CCPA
- Not retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and Scend except as permitted by Applicable Data Protection Law
- Not combine Customer Personal Data received from or on behalf of Customer with Personal Information received from another person or collected through Scend’s independent interactions with a Consumer except as permitted by Applicable Data Protection Law
- Comply with applicable obligations imposed on Service Providers and Contractors
- Provide reasonable assistance necessary to enable Customer to comply with applicable Consumer requests
- Notify Customer if Scend determines that it can no longer meet its applicable obligations with respect to Customer Personal Data
Customer may take reasonable and appropriate steps permitted by Applicable Data Protection Law to help ensure Scend uses Customer Personal Data consistently with Customer’s obligations.
This section applies only to Customer Personal Data that Scend Processes in its capacity as Customer’s Service Provider or Contractor. It does not apply to Scend Data that Scend independently collects, obtains, licenses, or maintains in its capacity as a Business, Controller, or other independent party.
European Data Protection Laws
To the extent Customer Personal Data is subject to the GDPR or UK GDPR and Scend acts as a Processor, Scend will:
- Process Customer Personal Data only on documented instructions from Customer unless otherwise required by applicable law
- Ensure persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations
- Implement appropriate technical and organizational security measures
- Engage Subprocessors in accordance with this DPA
- Taking into account the nature of the Processing, provide reasonable assistance to Customer with Data Subject requests
- Provide reasonable assistance with Customer’s obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of the Processing and information available to Scend
- Delete or return Customer Personal Data following termination as described in this DPA
- Make available information reasonably necessary to demonstrate compliance with applicable Processor obligations, subject to the audit provisions of this DPA
International Data Transfers
Where Applicable Data Protection Law requires an appropriate safeguard for the transfer of Customer Personal Data from the European Economic Area to Scend in the United States or another jurisdiction, the parties will rely on an applicable lawful transfer mechanism.
Where the European Commission’s Standard Contractual Clauses are required, the Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference.
Where Customer is a Controller and Scend is a Processor, Module Two will apply.
Where Customer is a Processor acting on behalf of another Controller and Scend is Customer’s Subprocessor, Module Three will apply.
For purposes of the Standard Contractual Clauses:
- The optional docking clause will apply
- General written authorization for the appointment of subprocessors will apply
- The notice period for new subprocessors will be the period specified in the Subprocessors section of this DPA
- The parties identified in the Agreement will be the relevant data exporter and data importer
- The description of Processing contained in this DPA will constitute the applicable description of the transfer and Processing activities
- The security measures described in this DPA and Scend’s applicable security documentation will constitute the applicable technical and organizational measures
- The competent supervisory authority will be determined in accordance with the Standard Contractual Clauses
- Where a Member State governing law must be selected, the laws of Ireland will apply
- The courts of Ireland will have jurisdiction where the Standard Contractual Clauses require jurisdiction in an EU Member State
Where Customer Personal Data is subject to the UK GDPR and an international transfer mechanism is required, the applicable UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses will be incorporated into this DPA and deemed completed using the information contained in the Agreement and this DPA.
The parties will cooperate in good faith to implement another lawful transfer mechanism if required by Applicable Data Protection Law.
Details of Processing
Subject Matter
The provision of Scend’s websites, applications, APIs, hosted software, data products, search and research functionality, workflows, integrations, enrichment, AI functionality, support, onboarding, implementation, configuration, technical advisory, workflow enablement, and forward deployed engineering.
Duration
For the duration of the Agreement and any additional period during which Scend Processes Customer Personal Data in accordance with the Agreement, this DPA, or applicable law.
Nature and Purpose of Processing
Processing necessary to provide, operate, maintain, secure, support, configure, integrate, personalize, and improve the Services and to perform functionality initiated or requested by Customer.
Processing activities may include:
- Collection and receipt
- Organization and structuring
- Storage and hosting
- Retrieval and consultation
- Search and analysis
- Enrichment and comparison
- Transmission
- Generation of Output
- Integration with third-party systems
- Deletion
- Other Processing necessary to provide the Services
Categories of Data Subjects
Depending on Customer’s use of the Services, Customer Personal Data may relate to:
- Customer’s employees, contractors, representatives, and Authorized Users
- Customer’s customers and prospective customers
- Business contacts and counterparties
- Investors
- Acquisition targets
- Buyers and sellers
- Advisers and service providers
- Employees, owners, executives, directors, and representatives of companies or organizations
- Candidates or prospective employees
- Other individuals whose Personal Data Customer submits to the Services
Types of Customer Personal Data
Depending on Customer’s use of the Services, Customer Personal Data may include:
- Names
- Business email addresses
- Business telephone numbers
- Job titles
- Employer and company affiliations
- Professional profiles and employment history
- Business relationship information
- Customer-provided notes, tags, classifications, and CRM information
- Account identifiers and account information
- Communications and support information
- Search queries and prompts
- Files and other Customer Content containing Personal Data
- Other Personal Data Customer elects to submit through the Services
The Services are not intended for Customer to submit sensitive Personal Data, special-category Personal Data, protected health information, payment card information, government identification numbers, passwords, biometric information, or other highly sensitive Personal Data unless expressly agreed by Scend in writing.
Frequency of Processing
Processing occurs continuously or as initiated by Customer through its use of the Services.
Relationship to Other Scend Policies
This DPA supplements the Agreement and should be read together with Scend’s Terms of Service, Privacy Policy, and Usage Policy.
Scend’s Privacy Policy describes Processing for which Scend acts as an independent Controller or Business.
Scend’s Usage Policy provides additional information regarding Customer Content, Usage Data, Output, Scend Data, AI and model usage, third-party providers, retention, and security.
In the event of a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls solely with respect to such Processing.
Except as expressly modified by this DPA, the Agreement remains unchanged and in full force and effect.
Nothing in this DPA expands Scend’s liability beyond the limitations, exclusions, disclaimers, and liability caps contained in the Agreement unless Applicable Data Protection Law expressly prohibits the application of those limitations.
Term
This DPA becomes effective when it is incorporated into or otherwise made part of the Agreement and remains effective for as long as Scend Processes Customer Personal Data subject to this DPA.
Provisions that by their nature should survive termination will remain effective for as long as necessary to give them effect.
Governing Law
Unless Applicable Data Protection Law or the Standard Contractual Clauses require otherwise, this DPA is governed by the governing law and dispute resolution provisions contained in the Agreement.