Data Processing Addendum (DPA)
Last updated January 1, 2026
1. Introduction and Scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Bit Flip LLC ("Known Agents," "we," "us," or "Processor") and the customer ("Customer" or "Controller") and governs the processing of personal data by Known Agents on behalf of the Customer.
This DPA applies when Known Agents processes personal data contained in website logs and analytics data submitted by the Customer through the Known Agents platform.
2. Definitions
- Personal Data: Has the meaning given in applicable Data Protection Laws.
- Data Protection Laws: The EU General Data Protection Regulation (GDPR), UK GDPR, Swiss Federal Act on Data Protection, and other applicable laws and regulations relating to privacy and data protection.
- Controller: The entity that determines the purposes and means of processing Personal Data.
- Processor: The entity that processes Personal Data on behalf of the Controller.
- Subprocessor: Any third party engaged by the Processor to process Personal Data.
- Data Subject: An identified or identifiable natural person whose Personal Data is processed.
California Consumer Privacy Act (CCPA): To the extent the CCPA applies to the processing of Personal Data under this DPA, Known Agents acts as a service provider or contractor (as defined by the CCPA) and will process Personal Data only for the business purposes specified in this DPA and the Terms of Service.
3. Roles and Responsibilities
The parties acknowledge and agree that:
- Customer is the Controller of Personal Data contained in website logs and analytics data submitted to the Known Agents platform.
- Known Agents is the Processor acting on behalf of Customer with respect to such Personal Data.
- Customer shall comply with all applicable Data Protection Laws in its use of the services and its processing of Personal Data.
- Known Agents shall process Personal Data only in accordance with Customer's documented instructions and applicable Data Protection Laws.
4. Data Processing Details
4.1 Nature and Purpose of Processing
Known Agents processes Personal Data for the purpose of providing artificial agent (bot) detection, visitor analytics, and traffic classification services to Customer.
4.2 Duration of Processing
Personal Data will be processed for the duration of the service agreement, unless otherwise agreed in writing, and subject to Section 12 (Data Deletion and Return).
4.3 Types of Personal Data
Known Agents processes the following categories of Personal Data on behalf of Customer:
- IP addresses
- User agent strings
- HTTP referrer information
- Requested URLs and paths
- Timestamps and session data
- HTTP request methods and response codes
- Other metadata or identifiers submitted by Customer or generated by the Services in connection with providing the Services
4.4 Categories of Data Subjects
Data Subjects whose Personal Data may be processed include visitors and end users of Customer's websites or applications. Known Agents also processes automated traffic signals and artificial agent (bot) activity data, though such automated systems are not natural persons and therefore not Data Subjects under GDPR.
5. Customer Instructions
Known Agents shall process Personal Data only on documented instructions from Customer, including:
- Processing necessary to provide the services described in the Terms of Service
- Processing initiated by Customer through the use of the platform and its features
- Other written instructions agreed upon by the parties
Known Agents will inform Customer if, in its opinion, an instruction violates applicable Data Protection Laws.
6. Security Measures
Known Agents implements appropriate technical and organizational measures to protect Personal Data, including:
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest using AES-256
- Multi-factor authentication and role-based access controls
- Security logging and monitoring where applicable
- Cloud infrastructure security controls provided by Google Cloud Platform
- Regular software updates and security patches
- Automated backups with encryption
Known Agents may pursue independent security assessments (such as SOC 2) and will provide updates if and when such reports become available.
7. Subprocessors
7.1 Authorized Subprocessors
Customer authorizes Known Agents to engage the following Subprocessors for processing Customer Data:
- Google Cloud Platform / Firebase: Cloud infrastructure and hosting (Google Cloud region: us-central1)
- Stripe: Payment processing
7.2 Subprocessor Obligations
Known Agents shall:
- Ensure each Subprocessor is bound by written agreement imposing data protection obligations substantially similar to those in this DPA
- Remain liable to Customer for the acts and omissions of Subprocessors
- Provide at least 30 days' notice of any intended changes concerning the addition or replacement of Subprocessors
Customer may object to the use of a new Subprocessor on reasonable data protection grounds by notifying Known Agents within 30 days of notice. If Customer objects, Known Agents will use reasonable efforts to provide alternative processing or, if not possible, Customer may terminate the affected services.
8. Data Subject Rights
Known Agents shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise their rights under Data Protection Laws. Known Agents shall:
- Assist Customer in responding to Data Subject requests, including access, rectification, erasure, restriction, objection, and portability requests
- Provide reasonable assistance to Customer in fulfilling its obligations under Data Protection Laws
- Not respond directly to Data Subject requests without Customer's prior written authorization
Known Agents shall provide reasonable assistance to Customer in conducting data protection impact assessments (DPIAs), prior consultations with supervisory authorities, and meeting other security and compliance obligations under Data Protection Laws, taking into account the nature of processing and information available to Known Agents.
9. International Data Transfers
Personal Data processed by Known Agents is stored and processed in the United States (Google Cloud region: us-central1). For transfers of Personal Data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, the parties agree to rely on:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- Any applicable adequacy decisions
- Other lawful transfer mechanisms as may be approved by relevant supervisory authorities
The parties incorporate by reference the Standard Contractual Clauses for the transfer of personal data to processors established in third countries (Module Two: Controller to Processor) as approved by the European Commission. Upon request, Known Agents will provide a copy of the applicable Standard Contractual Clauses.
10. Data Breach Notification
Known Agents shall notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Customer Data. Such notification shall include:
- A description of the nature of the breach, including categories and approximate number of Data Subjects and records affected
- The likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate potential adverse effects
- Contact information for further inquiries
Known Agents shall cooperate with Customer and provide reasonable assistance in investigating and remediating any breach.
11. Audits and Compliance
Known Agents shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA. Customer may conduct audits (which shall be document reviews or remote assessments unless physical inspection is legally required), subject to:
- Providing at least 30 days' prior written notice
- Conducting audits no more than once per year unless required by a supervisory authority or in response to a suspected breach
- Executing a confidentiality agreement
- Conducting audits during normal business hours and in a manner that minimizes disruption
- Reimbursing Known Agents' reasonable costs for facilitating the audit
Known Agents may provide third-party compliance reports (such as SOC 2 Type II reports when available) in lieu of an audit, and Customer agrees to accept such reports as satisfying audit rights to the extent such reports address Customer's reasonable compliance concerns.
12. Data Deletion and Return
Upon termination or expiration of the services, or upon Customer's written request, Known Agents shall (at Customer's election):
- Delete all Personal Data in its possession or control, except as required by law; or
- Return all Personal Data to Customer in a standard, machine-readable format
Known Agents shall confirm in writing upon request that it has complied with this requirement. Personal Data in backup systems may be retained for up to 90 days following deletion from production systems, after which it will be permanently deleted or anonymized.
13. Liability and Indemnification
Each party's liability under this DPA shall be subject to the limitations of liability set forth in the Terms of Service. Known Agents shall indemnify and hold Customer harmless from any claims, damages, or costs arising from Known Agents' breach of this DPA, except to the extent caused by Customer's instructions or actions.
14. Term and Termination
This DPA shall remain in effect for as long as Known Agents processes Personal Data on behalf of Customer. Upon termination of the Terms of Service, this DPA shall automatically terminate, subject to the obligations in Section 12 (Data Deletion and Return).
15. Governing Law and Jurisdiction
This DPA shall be governed by the same laws as the Terms of Service. Any disputes shall be resolved in accordance with the dispute resolution provisions in the Terms of Service.
16. Order of Precedence
In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail to the extent of the conflict with respect to the processing of Personal Data.
17. Changes to this DPA
Known Agents may update this DPA to reflect changes in Data Protection Laws, regulatory guidance, or our processing practices. Material changes will be communicated to Customer with at least 30 days' notice. Continued use of the services after such notice constitutes acceptance of the updated DPA.
Contact
For questions about this DPA or to exercise any rights under Data Protection Laws, contact contact@knownagents.com.
Bit Flip LLC
418 Broadway STE R
Albany, NY 12207
United States