Legal
Data Processing Addendum
This Data Processing Addendum, including its Annexes (the "DPA"), supplements and forms part of the AccessFuel Terms of Service available at https://www.accessfuel.com/terms-of-service, or any other written or electronic agreement between AccessFuel, Inc. ("AccessFuel") and the customer identified in that agreement ("Customer") governing Customer's access to and use of the AccessFuel Console and related services (the "Services"). That agreement, together with this DPA, is the "Agreement."
Version 1.3 — Effective August 26, 2026
Preamble
This DPA applies to the extent AccessFuel Processes Personal Data on Customer's behalf in connection with the Services and is subject to Data Protection Laws.
This DPA becomes binding on both parties upon Customer entering into the Agreement. No separate signature is required. By entering into the Agreement, Customer accepts this DPA on its own behalf and, to the extent required under Data Protection Laws, on behalf of its Authorized Affiliates.
Where Customer's procurement or compliance process requires a separately executed instrument, Customer may execute the signature block at the end of this DPA and submit it to privacy@accessfuel.com. A separately executed copy does not alter the terms of this DPA and does not take effect until countersigned by AccessFuel.
In the event of a conflict, this DPA prevails over the remainder of the Agreement with respect to the Processing of Personal Data.
1. Definitions
1.1 "Agreement" has the meaning given in the Preamble.
1.2 "Authorized Affiliate" means any entity that controls, is controlled by, or is under common control with Customer and that is permitted to use the Services under the Agreement.
1.3 "Customer Data" means all data, including files and text, that Customer or its authorized users submit to the Services or that AccessFuel ingests on Customer's behalf from the third-party sources Customer connects.
1.4 "Customer Personal Data" means Personal Data contained in Customer Data that AccessFuel Processes on Customer's behalf under the Agreement.
1.5 "Data Protection Laws" means all United States federal and state laws applicable to the Processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act ("CCPA") and the comprehensive state privacy laws of other states as they apply.
1.6 "Personal Data", "Processing" (and "Process"), "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in applicable Data Protection Laws; where those laws use different terms for the same concept, the equivalent term applies. "Business", "Service Provider", "Sell", "Share", "Consumer" and "Sensitive Personal Information" have the meanings given in the CCPA.
1.7 "Subprocessor" means any Processor engaged by AccessFuel (or by an AccessFuel affiliate) to Process Customer Personal Data.
Capitalized terms not defined in this DPA have the meaning given in the Agreement.
2. Roles of the Parties
2.1 Roles. For Customer Personal Data, Customer is the Controller (and, under the CCPA, the Business) and AccessFuel is the Processor (and, under the CCPA, the Service Provider). Where Customer is itself a Processor acting on behalf of a third-party Controller, AccessFuel is a Subprocessor and Customer warrants that it has the third-party Controller's authority to enter into this DPA.
2.2 Customer responsibilities. Customer is responsible for: (a) the lawfulness of its instructions and of the Customer Personal Data it submits to the Services, including having a valid legal basis and providing required notices to Data Subjects; (b) the accuracy and quality of Customer Data; (c) configuring the Services, including workspace membership and access roles, appropriately for its use case; and (d) securing its own credentials and the credentials of the third-party data sources it connects.
2.3 AccessFuel responsibilities. AccessFuel Processes Customer Personal Data only as set out in this DPA and the Agreement.
2.4 AccessFuel as Controller. AccessFuel is an independent Controller with respect to account registration data, billing data, authentication metadata, security logs, and product telemetry that AccessFuel Processes to operate, secure, bill for and improve the Services. That Processing is governed by the AccessFuel Privacy Policy and not by this DPA.
3. Details of Processing
3.1 Subject matter. AccessFuel's provision of the Services to Customer under the Agreement.
3.2 Duration. The term of the Agreement, plus the period until Customer Personal Data is deleted or returned in accordance with Section 7.
3.3 Nature and purpose. AccessFuel ingests Customer Data from the commerce, ticketing, CRM and marketing platforms connected by Customer (for example Shopify, HubSpot, Klaviyo, ticketing systems, web and advertising analytics platforms) and from files uploaded by Customer (for example CSV), stores it in AccessFuel's operational and analytics infrastructure, and Processes it to provide the Services, which include: data ingestion and pipeline transformation; storage and hosting; dashboards and reporting; audience segmentation and customer persona generation; document indexing and retrieval; and AI-assisted analysis through the AIRA assistant, which submits relevant Customer Personal Data to third-party AI model providers engaged as Subprocessors. AccessFuel also Processes Customer Personal Data to provide support and to maintain the security, availability and integrity of the Services.
3.4 Categories of Personal Data. Customer determines what Customer Data it submits. Customer Personal Data typically includes:
Identifiers: customer, order, ticket, account, member, subscriber and profile identifiers assigned by Customer or by a connected source system; pseudonymous IDs.
Contact details: name, email address, telephone number, postal and billing/shipping address.
Transaction, order and ticketing data: order, booking and line-item history, transaction value, currency, discounts, refunds, product, SKU, ticket, seat, membership and event data, purchase and attendance dates and frequency, lifetime value and derived metrics.
Marketing engagement data: email and campaign sends, opens, clicks, unsubscribes, list and flow membership, subscription status, campaign and ad attribution data.
Device and usage data: IP address, user-agent, device and browser attributes, session and web or app analytics event data, referral and traffic source, approximate location derived from IP.
Derived data: segment membership, RFM and similar scores, persona attributes and other analytical outputs generated by the Services.
Free-text data: any Personal Data Customer includes in CSV uploads, uploaded documents, or prompts submitted to AIRA.
3.5 Categories of Data Subjects. Customer's end customers, audience and prospects, including purchasers, ticket buyers, subscribers, members, fans and event attendees, donors, marketing contacts and email or SMS recipients, website and mobile app visitors, and holders of accounts with Customer; and Customer's own personnel who are authorized users of the Services.
3.6 Special category data. The Services are not designed or intended to Process Sensitive Personal Information, data revealing racial or ethnic origin, religious or philosophical beliefs, or trade union membership, genetic or biometric data, data concerning health or sex life, data relating to criminal convictions and offences, government-issued identifiers, financial account or payment card numbers, health data, or the Personal Data of children. Customer must not submit such data to the Services. If Customer nonetheless submits such data, Customer does so at its own risk and remains solely responsible for the consequences, and AccessFuel's obligations under this DPA are unchanged.
3.7 Frequency. Continuous, for the duration described in Section 3.2.
4. AccessFuel Obligations
4.1 Documented instructions. AccessFuel shall Process Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA, and Customer's configuration and use of the Services (including the data sources Customer connects, the segments and reports Customer runs, and the prompts Customer submits to AIRA) constitute Customer's complete and final documented instructions. Additional instructions require written agreement and may be subject to additional fees where they exceed the scope of the Services.
4.2 Unlawful instructions. AccessFuel shall inform Customer if, in its opinion, an instruction infringes Data Protection Laws, unless prohibited from doing so by law. AccessFuel may suspend the affected Processing until the instruction is withdrawn, amended or confirmed.
4.3 Legally required Processing. If AccessFuel is required by applicable law to Process Customer Personal Data other than on Customer's instructions, AccessFuel shall inform Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest. AccessFuel shall notify Customer of any legally binding request for disclosure of Customer Personal Data by a public authority unless prohibited, shall challenge requests it considers unlawful, and shall disclose only the minimum amount of data legally required.
4.4 Confidentiality. AccessFuel shall ensure that personnel authorized to Process Customer Personal Data are bound by an appropriate statutory or contractual obligation of confidentiality that survives termination of their engagement.
4.5 Personnel. AccessFuel shall limit access to Customer Personal Data to personnel who require access to perform the Agreement, shall apply the principle of least privilege, and shall provide those personnel with appropriate training on their data protection and security obligations.
4.6 Security. AccessFuel shall implement and maintain the technical and organizational measures described in Annex II to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. AccessFuel may update those measures from time to time provided the overall level of security is not materially reduced.
4.7 Assistance with data-subject requests. Taking into account the nature of the Processing, AccessFuel shall assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights under Data Protection Laws. The Services provide functionality allowing Customer to access and export Customer Personal Data, and to delete records that Customer created directly. For records ingested from a connected source, and for deletion requests AccessFuel must carry out on Customer's behalf, Customer may contact privacy@accessfuel.com. If AccessFuel receives a request directly from a Data Subject relating to Customer Personal Data, AccessFuel shall not respond to it other than to acknowledge receipt and direct the Data Subject to Customer, and shall promptly forward the request to Customer where it can identify the relevant Customer.
4.8 Assistance with DPIAs and consultations. AccessFuel shall provide reasonable assistance to Customer with data protection impact assessments, risk assessments and consultations with regulators required of Customer under Data Protection Laws, taking into account the nature of the Processing and the information available to AccessFuel. Assistance beyond the provision of AccessFuel's standard documentation may be subject to reasonable fees.
5. Subprocessors
5.1 General authorization. Customer grants AccessFuel general written authorization to engage Subprocessors to Process Customer Personal Data in connection with the Services, subject to this Section 5. AccessFuel's affiliates may be engaged as Subprocessors on the same terms.
5.2 Current list. The current list of Subprocessors, including their purpose and location, is available to Customer on request from privacy@accessfuel.com and is incorporated into this DPA as Annex III.
5.3 Notice and objection. Customer may subscribe to notifications of changes to the Subprocessor list by written request to privacy@accessfuel.com. AccessFuel shall give at least thirty (30) days' notice before a new Subprocessor begins Processing Customer Personal Data. Customer may object on reasonable data-protection grounds by written notice to privacy@accessfuel.com within that 30-day period. The parties shall discuss the objection in good faith; if AccessFuel is unable to make available a commercially reasonable alternative within a reasonable period, Customer may, as its sole and exclusive remedy, terminate the affected Services or Subscription by written notice, with a pro-rata refund of prepaid fees for the terminated portion of the then-current term. Absent objection within the notice period, the new Subprocessor is deemed authorized.
5.4 Flow-down and liability. AccessFuel shall enter into a written agreement with each Subprocessor imposing data protection obligations that are no less protective than those in this DPA, to the extent applicable to the nature of the Subprocessor's services. AccessFuel remains fully liable to Customer for the performance of each Subprocessor's obligations.
5.5 AI model providers. Certain features of the Services, including AIRA, transmit Customer Personal Data to third-party providers of large language models and other AI models. Those providers are Subprocessors and are identified as such in the Subprocessor list. With respect to those providers, AccessFuel shall:
(a) use enterprise or commercial API terms, and not consumer-facing offerings;
(b) configure the shortest data-retention option each provider makes available under those terms, and enable zero-data-retention where AccessFuel has contracted for it;
(c) not permit any AI model provider to use Customer Personal Data to train, fine-tune or otherwise improve its models, and require contractual terms to that effect; and
(d) not itself use Customer Personal Data to train models for the benefit of any other customer.
Outputs generated by AI features are probabilistic and may be inaccurate. Customer remains responsible for reviewing outputs before relying on them, including where those outputs inform decisions about Data Subjects. The Services are not intended to be used for solely automated decision-making producing legal or similarly significant effects on Data Subjects.
6. Personal Data Breach
6.1 Notification. AccessFuel shall notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it.
6.2 Content. The notification shall include, to the extent known at the time and supplemented as further information becomes available: the nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.
6.3 Assistance. AccessFuel shall provide reasonable assistance to Customer in meeting Customer's own notification obligations to regulators and to affected individuals.
6.4 No admission. AccessFuel's notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability.
6.5 Customer notice contact. AccessFuel will send notices to the owner of Customer's workspace and to any additional contact Customer has provided to AccessFuel in writing for this purpose. Customer is responsible for keeping that contact current by notifying privacy@accessfuel.com of any change.
7. Deletion and Return
7.1 During the term. Customer may export Customer Personal Data at any time using the functionality of the Services, and may delete records it created directly. For any other deletion, Customer may contact privacy@accessfuel.com.
7.2 On termination. Upon termination or expiry of the Agreement, AccessFuel shall, at Customer's election, delete or return Customer Personal Data and delete existing copies. Customer must make its election, and complete any export, within thirty (30) days of termination. Absent a timely election, AccessFuel shall delete Customer Personal Data.
7.3 Timing and backups. AccessFuel will complete deletion across its operational database, its analytics databases, object storage and its search index within thirty (30) days of the end of the period in Section 7.2. Customer Personal Data residing in encrypted routine backups is deleted on the ordinary backup expiry cycle rather than on demand. Until deleted, such data remains protected by the measures in Annex II and is not actively Processed.
7.4 Retention required by law. AccessFuel may retain Customer Personal Data to the extent required by applicable law, and only for the period and purpose required, subject to continued confidentiality and the measures in Annex II.
8. Processing Location
8.1 Location. AccessFuel Processes Customer Personal Data in the United States. AccessFuel's Subprocessors Process Customer Personal Data in the United States except where the Subprocessor list identifies another location.
8.2 Scope of this DPA. The Services are offered to customers established in the United States. This DPA does not provide a transfer mechanism for Personal Data protected by the European Union General Data Protection Regulation, the United Kingdom General Data Protection Regulation, or the Swiss Federal Act on Data Protection, and AccessFuel makes no representation that the Services meet the requirements of those laws. If Customer requires such a mechanism, the parties must agree it in writing before Customer submits Personal Data subject to those laws.
9. CCPA and US State Privacy Laws
9.1 Roles and specified purposes. With respect to Customer Personal Data subject to the CCPA, Customer is the Business and AccessFuel is a Service Provider. Customer discloses Customer Personal Data to AccessFuel only for the limited and specified purposes of providing the Services described in Section 3.3 of this DPA — data ingestion and pipeline transformation; storage and hosting; dashboards and reporting; audience segmentation and customer persona generation; document indexing and retrieval; AI-assisted analysis; and support, security and maintenance of the Services (the "Business Purpose"). AccessFuel Processes Customer Personal Data solely for those purposes and is prohibited from Processing it for any other purpose, except as permitted by the CCPA.
9.2 Restrictions. AccessFuel shall not:
(a) Sell or Share Customer Personal Data;
(b) retain, use or disclose Customer Personal Data for any purpose other than the Business Purpose, including for any commercial purpose other than performing the Services, or outside the direct business relationship with Customer, except as permitted by the CCPA;
(c) combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from its own interactions with Consumers, except as permitted by the CCPA for a Service Provider; or
(d) use Customer Personal Data to build or improve profiles of Consumers for use outside the Services provided to Customer.
9.3 Certification. AccessFuel understands the restrictions in Section 9.2 and certifies that it will comply with them.
9.4 Assistance and oversight. AccessFuel shall provide the same level of privacy protection as required of a Business under the CCPA in respect of the Customer Personal Data it Processes, shall notify Customer if it determines it can no longer meet its obligations under the CCPA, and shall assist Customer in responding to verifiable Consumer requests. Customer may, on reasonable notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, including by exercising the rights in Section 10.
9.5 Other US state laws. Where other US state privacy laws apply, AccessFuel acts as a "processor," "service provider" or equivalent, Processes Customer Personal Data only on Customer's instructions for the purposes set out in Section 3, and shall comply with the corresponding obligations of such laws, including duties of confidentiality, subprocessor engagement, deletion or return, and cooperation with assessments.
10. Audits and Documentation
10.1 Documentation. AccessFuel shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including a current description of the technical and organizational measures in Annex II, AccessFuel's ISO/IEC 27001 certificate and SOC 2 Type 2 report, and the policies and control descriptions published at AccessFuel's trust center: https://trust.inc/org_69aafd0a3fdca3ccbcd8e957.
10.2 Questionnaires. AccessFuel shall respond within a reasonable period to Customer's reasonable written security and privacy questionnaires relating to AccessFuel's Processing of Customer Personal Data, no more than once in any twelve (12) month period unless a Personal Data Breach has occurred or a regulator requires otherwise.
10.3 Audits. Where the information made available under Sections 10.1 and 10.2 is not sufficient to demonstrate compliance, and to the extent required by Data Protection Laws, AccessFuel shall allow for and contribute to an audit conducted by Customer or an independent auditor mandated by Customer and not reasonably objected to by AccessFuel. Any such audit shall: be requested at least thirty (30) days in advance; take place during business hours; occur no more than once in any twelve (12) month period (except where required by a regulator or following a Personal Data Breach); be subject to confidentiality obligations; not unreasonably disrupt AccessFuel's business; and not extend to the data, systems or information of other AccessFuel customers or to information whose disclosure would compromise AccessFuel's security. Customer bears its own and AccessFuel's reasonable costs of any on-site audit.
10.4 Subprocessor audits. AccessFuel shall use commercially reasonable efforts to obtain, and to make available to Customer on request, the audit reports or equivalent documentation of its Subprocessors, subject to confidentiality.
11. Liability
11.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, to the fullest extent permitted by applicable law.
11.2 Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws.
12. Term, Changes and Miscellaneous
12.1 Term. This DPA takes effect on the effective date of the Agreement and continues until AccessFuel ceases to Process Customer Personal Data. Provisions that by their nature should survive termination do so.
12.2 Changes. AccessFuel may update this DPA where required to reflect changes in Data Protection Laws, the Services, or AccessFuel's Subprocessors, provided that no update materially reduces the protections afforded to Customer Personal Data. AccessFuel shall publish the updated DPA with a new version number and effective date and, where the change is material, give Customer at least thirty (30) days' notice before it takes effect.
12.3 Authorized Affiliates. An Authorized Affiliate that is a Controller of Customer Personal Data is a party to this DPA. Customer remains responsible for coordinating all communications with AccessFuel under this DPA on behalf of its Authorized Affiliates, and only Customer may exercise the rights in Sections 5.3 and 10.
12.4 Notices. Notices under this DPA shall be given to privacy@accessfuel.com (for AccessFuel) and to the administrative contact designated in Customer's account (for Customer).
12.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect.
12.6 Governing law. This DPA is governed by the governing law and subject to the jurisdiction and venue set out in the Agreement.
Annex I — Description of the Processing: A. List of Parties
| Name | The Customer identified in the Agreement, and its Authorized Affiliates using the Services. |
|---|---|
| Address | The address specified in Customer's account or in the Agreement. |
| Contact | The administrative and privacy contacts designated in Customer's account. |
| Activities relevant to the Processing | Use of the Services as described in the Agreement, including connecting data sources and submitting Customer Data for analysis. |
| Role | Controller, or Processor where Customer Processes on behalf of a third party. |
| Name | AccessFuel, Inc. |
|---|---|
| Address | 520 Broadway, Santa Monica, CA 90401, USA |
| Contact | privacy@accessfuel.com |
| Activities relevant to the Processing | Provision of the AccessFuel Console business-intelligence Services, including ingestion of data from the commerce, ticketing, CRM and marketing platforms connected by Customer and from files uploaded by Customer, and storage, analytics, segmentation and AI-assisted analysis, as described in Section 3.3 of the DPA. |
| Role | Processor. |
Annex I — Description of the Processing: B. Details
| Item | Detail |
|---|---|
| Categories of data subjects | As set out in Section 3.5 of the DPA: Customer's end customers, audience and prospects (purchasers, ticket buyers, subscribers, members, fans and event attendees, donors, marketing contacts, website and mobile app visitors, account holders) and Customer's authorized users. |
| Categories of personal data | As set out in Section 3.4 of the DPA: identifiers; contact details; transaction, order and ticketing data; marketing engagement data; device and usage data; derived analytical data; free-text data submitted by Customer. |
| Sensitive data | None. Customer is prohibited from submitting special category or other sensitive data under Section 3.6 of the DPA. |
| Frequency | Continuous, for the duration of the Agreement. |
| Nature of the processing | Collection, ingestion, structuring, storage, transformation, analysis, indexing, retrieval, generation of derived analytics and AI-assisted outputs, transmission to Subprocessors, erasure. |
| Purpose of the processing | Provision, support, security and maintenance of the Services as described in Section 3.3 of the DPA. |
| Retention period | For the term of the Agreement plus the deletion periods set out in Section 7 of the DPA. |
| Subprocessor disclosures | Subject matter, nature and duration as set out in the Subprocessor list and Annex III. |
Annex II — Technical and Organizational Measures
AccessFuel maintains an information security management system certified to ISO/IEC 27001 and undergoes SOC 2 Type 2 examination. Current certificates, the SOC 2 report and the underlying policies and controls are available at AccessFuel's trust center: https://trust.inc/org_69aafd0a3fdca3ccbcd8e957. In addition to the controls covered by those frameworks, AccessFuel implements and maintains the following measures.
Annex II — Technical and Organizational Measures: Encryption
- Customer Personal Data is encrypted in transit over public networks using TLS 1.2 or higher.
- Customer Personal Data is encrypted at rest in AccessFuel's databases, object storage and backups using industry-standard algorithms (AES-256 or equivalent), as provided by the underlying infrastructure Subprocessors.
- Credentials and access tokens for Customer-connected data sources are encrypted by the application (AES-256-GCM) before being stored, using a key held outside the data store.
Annex II — Technical and Organizational Measures: Access control and tenant isolation
- The Services are multi-tenant. Analytics data is held in a separate per-workspace database with its own database credentials. Application data is held in a shared database in which records are scoped to a workspace and access is filtered by the application layer.
- Role-based access control within each workspace (owner, admin, member, viewer) allows Customer to control what its own users can see and do.
- Authentication uses per-session credentials with server-side session management; support for multi-factor authentication where offered by the identity mechanism in use.
Annex II — Technical and Organizational Measures: Personnel and administrative access
- Access to production systems and Customer Personal Data is restricted to personnel with an operational need, on a least-privilege basis, and is reviewed periodically.
- Administrative access requires individual named accounts and multi-factor authentication.
- Personnel are bound by written confidentiality obligations and receive security and data protection training.
- Access is revoked promptly on role change or termination.
Annex II — Technical and Organizational Measures: Secrets management
- Application secrets and infrastructure credentials are stored in managed secret stores, not in source code, and are rotated on a defined basis and on suspected compromise.
Annex II — Technical and Organizational Measures: Logging and monitoring
- Application, infrastructure and authentication events are logged.
- Error and availability monitoring, alerting and on-call escalation are in place.
- Logs are retained for a defined period and access to them is restricted.
Annex II — Technical and Organizational Measures: Secure development and change management
- Source code is version-controlled; changes are peer-reviewed before deployment to production.
- Automated static analysis runs against the codebase on a scheduled basis and its findings are reviewed.
- Environments are separated (development, preview, production) and production Customer Personal Data is not used in development environments.
Annex II — Technical and Organizational Measures: Availability, resilience and backups
- Managed database services with automated backups and point-in-time recovery, where offered by the underlying provider.
- Backups are encrypted and retained for a defined period.
- Infrastructure is deployed on managed, redundant cloud platforms.
Annex II — Technical and Organizational Measures: Network and application security
- Bot protection, rate limiting and DDoS mitigation at the network edge.
- Input validation and output sanitization in the application layer.
- Restricted network access to data stores.
Annex II — Technical and Organizational Measures: Vendor and Subprocessor management
- Subprocessors are reviewed for security and data protection posture before engagement and are bound by written data protection terms.
- The Subprocessor list is maintained by AccessFuel and made available to Customer on request.
Annex II — Technical and Organizational Measures: Incident response
- A documented incident response process covering detection, triage, containment, remediation, customer notification and post-incident review.
Annex II — Technical and Organizational Measures: Deletion
- Customer-initiated deletion via the Services, and deletion or return on termination in accordance with Section 7 of the DPA.
Annex II — Technical and Organizational Measures: Measures for disclosures to Subprocessors
- Written data protection terms with each Subprocessor, encryption in transit, and scoping of data disclosed to the minimum necessary for the Subprocessor's function.
Annex III — List of Subprocessors
Customer has granted general written authorization for the engagement of Subprocessors under Section 5 of this DPA.
The current list of Subprocessors, including each Subprocessor's name, the Processing it performs, and the country or region in which it Processes Customer Personal Data, is maintained by AccessFuel and is available to Customer on request from:
privacy@accessfuel.com
That list is incorporated into this DPA by reference and forms Annex III. Customer may subscribe to notifications of changes to that list by written request to the same address. Changes are subject to the notice and objection rights in Section 5.3.
Signature Block
For reference purposes only — this DPA is executed by acceptance of the Agreement. No signature is required for this DPA to be binding. A signature page is provided solely for customers whose internal procurement or compliance processes require a countersigned copy; a signed copy does not modify the terms above and takes effect only when countersigned by AccessFuel.
How to obtain a countersigned copy. The downloadable PDF version of this DPA contains the signature page for both parties. Download it, complete and sign the Customer block, and email it to privacy@accessfuel.com — or ask AccessFuel to send it for electronic signature. AccessFuel will return a countersigned copy; the DPA takes effect for a separately executed instrument only once AccessFuel has countersigned it.
Where the parties execute this DPA separately, their signatures on that page confirm their agreement to this DPA.
Document version
AccessFuel Data Processing Addendum, Version 1.3. Effective August 26, 2026.