Eightx Talk to a CFO

Data Processing Addendum

Last updated: June 16, 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service and any separate written engagement letter (together, the "Agreement") between Eightx ("Eightx," "we," "us") and the client that uses the Eightx client platform at hub.eightx.co (the "Platform") (the "Client," "you"). This DPA applies to the extent Eightx processes Personal Data on the Client's behalf in providing the Platform and related services (the "Services"). If there is a conflict between this DPA and the rest of the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.

  • "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and substantially similar provincial laws; the EU General Data Protection Regulation (Regulation 2016/679) and the UK GDPR ("GDPR"); and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
  • "Personal Data" means information relating to an identified or identifiable individual that is contained within Client Data and processed by Eightx on the Client's behalf under the Agreement.
  • "Client Data" has the meaning given in the Terms of Service.
  • "Processing" (and "process") means any operation performed on Personal Data, whether automated or not.
  • "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given under applicable Data Protection Laws. Where the CCPA applies, "Business" and "Service Provider" carry the meanings given in the CCPA.
  • "Subprocessor" means a third party engaged by Eightx to process Personal Data in connection with the Services.

2. Roles of the Parties

As between the parties, the Client is the Controller (or Business) of Personal Data contained in Client Data, and Eightx is the Processor (or Service Provider) that processes such Personal Data on the Client's behalf. Where the Client is itself a processor acting for another controller (for example, in relation to the Client's own customers), Eightx acts as a sub-processor. Each party shall comply with its obligations under applicable Data Protection Laws.

3. Scope and Instructions

Eightx shall process Personal Data only: (a) to provide, secure, maintain, and improve the Services; (b) in accordance with the Client's documented instructions, including those set out in the Agreement and as given through the Platform (such as connecting or disconnecting data sources and configuring the Services); and (c) as required by applicable law, in which case Eightx shall, where legally permitted, inform the Client of that requirement before processing. The Client's instructions shall not require Eightx to process Personal Data in a manner that violates Data Protection Laws. The details of processing are set out in Annex A.

4. Client Obligations

The Client is responsible for the accuracy, quality, and legality of Client Data and for the means by which it acquired Personal Data. The Client represents and warrants that it has provided all notices and obtained all consents, permissions, and rights necessary under Data Protection Laws for Eightx to process Personal Data as contemplated by the Agreement, including in respect of any data relating to the Client's own customers or employees.

5. Eightx Obligations

Eightx shall:

  • process Personal Data only as set out in Section 3;
  • ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality;
  • implement and maintain the technical and organizational security measures described in Annex B;
  • taking into account the nature of the processing, provide reasonable assistance to the Client, by appropriate measures, in responding to requests from Data Subjects to exercise their rights under Data Protection Laws (for example access, correction, deletion, or portability);
  • provide reasonable assistance to the Client with data protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and relating to Eightx's processing; and
  • make available information reasonably necessary to demonstrate compliance with this DPA.

6. Subprocessors

The Client provides a general authorization for Eightx to engage Subprocessors to process Personal Data. The Subprocessors engaged as of the date above are listed in Annex C. Eightx shall: (a) impose data-protection and security obligations on each Subprocessor that are no less protective than those in this DPA; and (b) remain responsible for each Subprocessor's performance of its obligations. Eightx shall give the Client notice of any intended addition or replacement of a Subprocessor (for example by updating Annex C or the Privacy Policy), and the Client may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection.

7. Personal Data Breach

Eightx shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under the Agreement, and shall provide information reasonably available to it to assist the Client in meeting any obligations to notify supervisory authorities or affected Data Subjects. Eightx's notification is not an acknowledgment of fault or liability.

8. International Transfers

The Client acknowledges that Eightx and its Subprocessors may process Personal Data in Canada, the United States, and other countries. Where Data Protection Laws require a transfer mechanism for the export of Personal Data (for example from the EEA, the UK, or Switzerland), the parties agree to rely on an appropriate safeguard recognized under those laws, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference and deemed completed with Eightx as data importer, the Client as data exporter, and the details in the Annexes, to the extent applicable.

9. CCPA Terms

To the extent the CCPA applies, Eightx is a Service Provider receiving Personal Data from the Client (a Business) to perform the Services. Eightx shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Services or as otherwise permitted by the CCPA; (c) retain, use, or disclose Personal Data outside the direct business relationship between the parties; or (d) combine Personal Data with information received from other sources except as permitted by the CCPA. Eightx certifies that it understands and will comply with these restrictions. The creation and use of de-identified and aggregated data as permitted by the Agreement is performed in compliance with the CCPA's requirements for de-identified information.

10. Audit

Eightx shall, on reasonable prior written request and no more than once in any 12-month period (unless required more frequently by a supervisory authority), make available information reasonably necessary to demonstrate compliance with this DPA. Any audit shall be conducted during business hours, subject to reasonable confidentiality obligations, and in a manner that does not disrupt Eightx's operations or compromise the confidentiality of other clients' data.

11. Deletion and Return

On termination or expiry of the Agreement, Eightx shall, at the Client's choice and request, delete or return Personal Data processed on the Client's behalf, and delete existing copies, except to the extent retention is required by applicable law or for the limited purposes of backup, audit, and dispute resolution, during which time the data remains subject to this DPA. De-identified and aggregated data created as permitted by the Agreement is not subject to this Section.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, including the Terms of Service. This DPA does not expand either party's liability beyond what is provided in the Agreement, except to the extent required by Data Protection Laws.

13. Term, Order of Precedence, and Changes

This DPA takes effect when the Client begins using the Platform and continues for as long as Eightx processes Personal Data on the Client's behalf. Except as expressly modified here, the Agreement remains in full force and effect. We may update this DPA to reflect changes in the Services, Subprocessors, or Data Protection Laws; the "Last updated" date reflects the most recent revision, and material changes will be noted on the Platform or communicated to the Client.

Annex A — Details of Processing

Subject matterProvision of the Eightx client Platform and related fractional-CFO and financial-analysis services.
DurationFor the term of the Agreement and any period of permitted post-termination retention.
Nature and purposeCollecting, aggregating, computing, storing, analyzing, and displaying Client Data to produce dashboards, reports, forecasts, board packs, benchmarks, and AI-assisted answers.
Types of Personal DataAuthorized-user account data (name, email, role); identifiers and limited data relating to the Client's own customers that may be contained in connected sources (for example Shopify order and customer identifiers); and any personal data the Client chooses to include in financial or operational records it connects or enters.
Categories of Data SubjectsThe Client's authorized users; and, to the extent present in Client Data, the Client's customers and personnel.

Annex B — Security Measures

Eightx maintains technical and organizational measures appropriate to the risk, including:

  • encryption of connected-account credentials (OAuth/API tokens) at rest, and encryption of data in transit using TLS;
  • authentication of all Platform users and role-based access controls, with logical isolation of each client's data so that users may access only the client organizations to which they have been granted access;
  • use of reputable infrastructure providers (see Annex C) that maintain industry-standard physical and network security;
  • restriction of personnel access to Personal Data on a need-to-know basis, subject to confidentiality obligations;
  • access controls and secrets management for production systems; and
  • logging of synchronization and access activity to support security monitoring and auditability.

Annex C — Approved Subprocessors

SubprocessorPurposeLocation
Vercel Inc.Application hosting and content deliveryUnited States
Supabase, Inc.Database hosting and user authenticationUnited States / EU
Anthropic, PBCAI processing for assistant and brief-generation featuresUnited States

The third-party services that the Client chooses to connect (for example QuickBooks Online, Xero, Shopify, Meta Ads, and Google Ads) act as sources of Client Data at the Client's direction and under their own terms; they are not Eightx Subprocessors.

Contact

For questions about this DPA or to exercise data-related requests, contact us at contact@eightx.co. For legal notices: legal@eightx.co.