Data Processing Addendum
Last updated June 11, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Terms") between you ("Customer") and Fast and Forward Software, S.A. de C.V. ("Unifix"), and applies whenever Unifix processes personal data on Customer's behalf through the Service. It takes effect when you accept the Terms. Where this DPA conflicts with the Terms on the subject of data protection, this DPA prevails.
For the personal data covered by this DPA, the Customer is the controller and Unifix is the processor. Personal data that Unifix collects about the Customer's own account (name, email, billing) is governed by our Privacy Policy, where Unifix is the controller, and is outside the scope of this DPA.
1. Definitions
"Personal data", "processing", "controller", "processor", and "data subject" have the meanings given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means the personal data within the Content that Unifix processes on Customer's behalf. "Applicable Data Protection Law" means the data protection laws that apply to that processing, including the GDPR and UK GDPR where relevant.
2. Scope and instructions
Unifix processes Customer Personal Data only on the Customer's documented instructions, including those given through normal use of the Service, except where law requires otherwise (in which case we'll tell you, unless the law forbids it). Customer is responsible for the accuracy and legality of the Content and for having the right to provide it to us for processing. The details of the processing are set out in Annex I.
3. Confidentiality
We ensure that anyone authorized to process Customer Personal Data is bound by an appropriate duty of confidentiality, and we limit access to those who need it to provide, secure, or support the Service.
4. Security
We implement appropriate technical and organizational measures to protect Customer Personal Data, described in Annex II. We may update those measures over time provided the level of protection isn't reduced.
5. Subprocessors
Customer authorizes Unifix to engage the subprocessors listed in Annex III. We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance. If we add or replace a subprocessor, we'll update that list and, on request, notify you so you have a chance to object on reasonable data-protection grounds.
6. International transfers
Customer Personal Data is processed in the United States and the European Union, depending on the vendor. Where Applicable Data Protection Law requires a transfer mechanism for personal data from the European Economic Area, United Kingdom, or Switzerland, the European Commission's Standard Contractual Clauses are incorporated into this DPA by reference and apply to that transfer, with Unifix as "data importer" and Customer as "data exporter".
7. Assistance with data subject requests
Taking into account the nature of the processing, we'll assist you with appropriate technical and organizational measures, so far as possible, to respond to requests from data subjects exercising their rights. If a data subject contacts us directly about Customer Personal Data, we'll direct them to you rather than respond on your behalf.
8. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we'll notify you without undue delay and provide the information you reasonably need to meet your own notification obligations.
9. Deletion and return
You can export your Content at any time while your account is active. On termination, we delete Customer Personal Data on the timeline described in our Privacy Policy — inaccessible immediately, removed from active systems within 30 days and from backups within 60 days — except where law requires us to retain it.
10. Audits
We'll make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits conducted by you or an auditor you mandate, on reasonable prior notice, no more than once a year unless required by a supervisory authority, and subject to confidentiality.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms.
Annex I — Description of processing
- Subject matter and duration. Processing of Customer Personal Data to provide the Service, for the duration of the Customer's subscription.
- Nature and purpose. Hosting, storage, and processing of Content so the Customer can manage service requests, clients, contacts, and related records — including AI-assisted drafting and titling.
- Categories of data subjects. The Customer's clients and contacts, and the people who submit or are named in service requests (for example, a person who reports an issue).
- Types of personal data. Names, email addresses, phone numbers, physical addresses, and the free-text content of tickets and service records that the Customer chooses to enter.
- Special categories. Not intended. The Service is not designed for special-category data, and the Customer should not submit it.
Annex II — Security measures
- Encryption of data in transit (TLS) and encryption of sensitive fields and personal data at rest.
- Encrypted database backups.
- Access controls limiting data access to authorized personnel on a need-to-know basis.
- Logical separation of each customer account's data.
- Monitoring and error tracking to detect and respond to issues.
- Regular review of these measures as the Service evolves.
Annex III — Subprocessors
The current list of subprocessors, with their purpose and location, is maintained in our Privacy Policy.
Contact
Questions about this DPA, or want a countersigned copy for your records? Email support@unifix.io.