Data Processing Addendum
Last updated: 2026-07-23
This Data Processing Addendum (the "DPA") supplements and forms part of the Terms of Service between you (the "Customer") and Metiix, LLC ("Metiix") and applies wherever Metiix processes personal information contained in Customer Data on the Customer's behalf. In this DPA, "personal information", "controller", "processor", "service provider", "business", and "personal data" have the meanings given in the applicable privacy law, including the California Consumer Privacy Act (CCPA), other US state privacy laws, PIPEDA, and Québec's Law 25. Where this DPA conflicts with the Terms of Service on the processing of personal information, this DPA governs.
1. Roles and scope
For personal information contained in Customer Data, the Customer is the controller (or an intermediary processor for its own customers) and Metiix is a processor and service provider acting on the Customer's documented instructions. Those instructions consist of the Terms of Service, this DPA, and the Customer's configuration and use of the Service. Metiix is a controller only for its own account, billing, and security records, as described in the Privacy Policy.
2. Purpose limitation and instructions
Metiix processes personal information in Customer Data only to provide, secure, and support the Service and as the Customer instructs. Metiix does not sell personal information; does not share it for cross-context behavioral advertising; and does not retain, use, or disclose it for any purpose other than the business purposes specified in the Terms or as permitted by applicable law. Metiix does not combine that personal information with data from other sources except as a service provider is permitted to do, and does not use it outside the direct business relationship with the Customer. Metiix will tell the Customer if it determines it can no longer meet its obligations under applicable privacy law, and the Customer may take reasonable steps to stop and remediate unauthorized processing.
3. Confidentiality
Metiix limits access to personal information to personnel who need it to provide the Service and who are bound by confidentiality obligations.
4. Sub-processors
The Customer authorizes Metiix to engage the sub-processors listed in the Privacy Policy — cloud hosting and database infrastructure, Stripe, Twilio, Amazon SES, OpenRouteService, Google Places, and Honeybadger. Metiix binds each sub-processor to data-protection obligations materially equivalent to those in this DPA and remains responsible for their processing. Metiix will give notice (through the Privacy Policy or by email) before adding or replacing a sub-processor; if the Customer reasonably objects on data-protection grounds, its sole remedy is to terminate the affected part of the Service.
5. Security measures
Metiix maintains administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit, access controls, session-token hashing, tenant isolation between organizations, logging, and monitoring.
6. Confidentiality incidents
Metiix will notify the Customer without undue delay after becoming aware of a confirmed breach of security affecting personal information in the Customer's Customer Data, and will provide the information reasonably available to help the Customer meet its own notification obligations to individuals and regulators (including the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, and US state authorities). Metiix does not notify the Customer's own end users unless the Customer instructs it or the law requires.
7. Assistance with individual requests and assessments
Taking into account the nature of the processing, Metiix will provide reasonable assistance (at the Customer's expense where the effort is material) so the Customer can respond to individuals exercising access, correction, deletion, portability, and similar rights, and can carry out privacy assessments. Requests Metiix receives directly from the Customer's data subjects about Customer Data are forwarded to the Customer within a reasonable time; the Customer is responsible for the substantive response.
8. International transfers
Personal information is processed in the United States and by sub-processors as described in the Privacy Policy. Where personal information is transferred across borders, including from Canada or Québec to the United States, the transfer is subject to the contractual and technical safeguards described in the Privacy Policy, and Metiix supports the Customer's own transfer assessments.
9. Retention, return, and deletion
Metiix retains personal information in Customer Data as described in the Privacy Policy — including automatic deletion of high-frequency GPS pings approximately 72 hours after they are recorded. On termination, Metiix makes Customer Data available for export for thirty (30) days, after which it deletes or de-identifies it in the ordinary course, except where retention is required by law. Metiix will confirm deletion on request.
10. Audit
Metiix will demonstrate compliance with this DPA by making available relevant documentation and written summaries of its security practices, and by responding to a reasonable security questionnaire no more than once per year. This satisfies the Customer's audit rights to the maximum extent permitted by applicable law.
11. US state law and Canadian terms
US state privacy laws. Metiix acts as the Customer's "service provider" (CCPA) or "processor" and certifies that it understands and will comply with the restrictions in Section 2. The Customer will make available to individuals the notices required of a business or controller.
Canada. For personal information governed by PIPEDA or Québec's Law 25, this DPA is the written mandate under which Metiix processes personal information for the Customer; Metiix processes it only for the agreed purposes, applies the security measures above, assists with confidentiality-incident handling and individual rights, and returns or destroys it at the end of the mandate, all as described in this DPA and the Privacy Policy.
12. Term, liability, and precedence
This DPA is effective for as long as Metiix processes personal information in Customer Data and is coterminous with the Terms of Service. Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. This DPA is incorporated into the Terms of Service; on any conflict about the processing of personal information, this DPA controls, and in all other respects the Terms of Service continue to apply.
This DPA is provided for general information. Larger customers may request a countersigned copy or negotiated terms by writing to privacy@snowmass.io.