Fromenance

Legal

Data Processing Addendum

This Data Processing Addendum forms part of the agreement between Many Software Enterprises LLC and each institution that uses Fromenance, the communication provenance service. It sets out how we process personal data on the institution's behalf. It is offered to every tenant from day one and is incorporated by reference in every order form and pilot agreement.

Effective date:
Provider:
Many Software Enterprises LLC, a Delaware limited liability company (manyent.com)

Article 1. Definitions

"Agreement" means the Terms of Service, the applicable order form or pilot agreement, and this DPA. "Customer" means the institution that is party to the Agreement, acting as controller (or as a business under United States state privacy law). "Provider" means Many Software Enterprises LLC, a Delaware limited liability company, acting as processor (or service provider). "Personal Data" means information relating to an identified or identifiable natural person that Provider processes on Customer's behalf under the Agreement. "End User" means a customer of Customer who submits a communication for verification. "Subprocessor" means a third party engaged by Provider to process Personal Data. "Data Protection Law" means all laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the Gramm-Leach-Bliley Act and its implementing rules, United States state privacy laws such as the California Consumer Privacy Act, and, if Customer is subject to it, the EU or UK General Data Protection Regulation. "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

Article 2. Roles and scope

2.1 Customer is the controller of Personal Data processed in the Service and Provider is the processor. Provider processes Personal Data only on Customer's documented instructions, which consist of the Agreement, Customer's configuration of the Service (domains, retention window, reply templates, fraud list, users and roles, webhooks), and any further written instructions Customer gives. Provider will inform Customer if an instruction in Provider's opinion infringes Data Protection Law.

2.2 Annex I describes the subject matter, duration, nature and purpose of processing, the categories of data subjects, and the categories of Personal Data. Annex II lists Subprocessors. Annex III describes the technical and organisational measures.

2.3 Provider does not sell Personal Data, does not share it for cross context behavioral advertising, does not retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than the Agreement, and does not combine it with Personal Data received from other sources except as permitted in Article 7.3. Provider certifies that it understands these restrictions.

Article 3. Confidentiality and personnel

Provider ensures that persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate training. Access to Personal Data is limited to personnel who need it to provide the Service, is protected by passkey or hardware key authentication, and, for Provider's internal backoffice, is read only and recorded in an audit log for every session.

Article 4. Security

Provider implements and maintains the technical and organisational measures in Annex III, which are designed to protect Personal Data against Security Incidents and to ensure a level of security appropriate to the risk. Provider may update the measures from time to time provided that the updates do not materially reduce the overall level of protection.

Article 5. Subprocessors

5.1 Customer authorizes Provider to engage the Subprocessors in Annex II. Provider imposes data protection obligations on each Subprocessor that are no less protective than this DPA and remains liable to Customer for each Subprocessor's performance.

5.2 Provider will notify tenant administrators by email at least 30 days before adding or replacing a Subprocessor. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Service and receive a refund of prepaid fees for the remaining term.

Article 6. Data subject requests and assistance

6.1 Provider will promptly forward to Customer any request from an End User or other data subject concerning Personal Data processed for Customer, and will not respond except to direct the person to Customer, unless required by law. Provider will assist Customer, through the Service's export, search, override, and deletion functions and on request, in responding to requests to access, correct, delete, restrict, or export Personal Data.

6.2 Provider will assist Customer, taking into account the nature of processing and the information available to Provider, with data protection impact assessments and prior consultations with authorities, and with Customer's security and regulatory obligations relating to the Service.

Article 7. Data minimization, retention, and derived intelligence

7.1 The Service is designed so that Provider holds the minimum Personal Data needed. On a registered communication, Provider stores only a one way HMAC of the recipient address computed with a Customer specific secret, a one way content fingerprint, a verify code, and metadata; the database contains no column for a recipient address and Provider never receives one on the registration API. On an End User submission, Provider stores the forwarded message or screenshot encrypted with a Customer specific key for Customer's configured retention window (90 days unless Customer sets otherwise), the submitter address as a one way hash, and an encrypted copy of the submitter address solely to send the reply, which is purged 30 days after the reply.

7.2 Verdict replies sent on Customer's behalf never quote the submitted message, never include its links, and never name its sender. Mail that fails the trust check is held for 24 hours and deleted without processing.

7.3 Provider may extract from submissions that do not verify the technical indicators of the suspicious message (URLs, domains, IP addresses, phone numbers, sender addresses, QR payloads), which describe the impersonation infrastructure rather than the End User, and may compare such indicators and aggregate counts across tenants to detect campaigns and improve the Service. Provider will not disclose submissions, message content, End User identifiers, or Customer's identity to any other tenant.

Article 8. Security Incident notification

Provider will notify Customer without undue delay, and in any event no later than 72 hours after confirming a Security Incident affecting Customer's Personal Data, by email to Customer's tenant owner and administrators. The notification will describe the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point, and will be supplemented as information becomes available. Provider will cooperate with Customer's investigation and with Customer's own notification obligations. Notification is not an admission of fault.

Article 9. Audits and information

Provider will make available the information reasonably necessary to demonstrate compliance with this DPA, including the Security page, this DPA, completed security questionnaires, and, when available, third party audit reports (a SOC 2 Type 1 report is targeted within 12 months of Provider's first paying tenant). Where such information is insufficient to meet Customer's regulatory obligations, Customer or an independent auditor bound by confidentiality may audit Provider's relevant controls once per year on 30 days' notice, during business hours, without disrupting the Service, at Customer's expense. Provider may require that audits of Subprocessor facilities proceed through the Subprocessor's own audit program.

Article 10. International transfers and residency

Provider stores and processes Personal Data in the United States. Provider will not transfer Personal Data outside the United States without Customer's prior written consent. If Customer is subject to the EU or UK GDPR and transfers Personal Data to Provider, the parties will execute the applicable Standard Contractual Clauses (module two, controller to processor) or the UK Addendum, which will be incorporated into this DPA.

Article 11. Return and deletion

During the term Customer may export Customer Data at any time through the Service. Within 30 days after the Agreement ends, Provider will delete all Personal Data processed for Customer, including encrypted message copies, registrations, submissions, verdicts, indicators, and audit records, except to the extent retention is required by law, in which case Provider will isolate and protect the data and delete it when the requirement lapses. Backups containing Personal Data are overwritten in the ordinary course within 35 days. Provider will confirm deletion in writing on request.

Article 12. Liability, term, and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA takes effect on the effective date above or on the date Customer accepts the Agreement, whichever is later, and remains in effect until Provider has deleted all Personal Data. If this DPA conflicts with the Terms of Service, this DPA controls with respect to Personal Data. This DPA is governed by the law of the State of Delaware, except where Data Protection Law requires otherwise.


Annex I. Description of processing

A. Parties

Controller (data exporter): the Customer identified on the order form or pilot agreement, represented by its tenant owner. Processor (data importer): Many Software Enterprises LLC, Delaware, United States, contactprivacy@fromenance.com.

B. Subject matter and duration

Provision of the Fromenance communication provenance Service: registration of Customer's outbound communications, verification of communications submitted by End Users, reply to End Users on Customer's behalf, and production of fraud intelligence for Customer. Duration: the term of the Agreement plus the deletion period in Article 11.

C. Nature and purpose

Collection, storage, hashing, fingerprinting, encryption, matching, retrieval, transmission of replies, extraction of indicators, export, and deletion, for the purpose of answering whether Customer issued a specific communication and of identifying impersonation of Customer.

D. Categories of data subjects

  • End Users: customers, members, policyholders, or account holders of Customer who receive registered communications or submit communications for verification.
  • Customer personnel: users of the admin application.
  • Third parties whose identifiers appear in suspicious messages (senders of impersonation attempts).

E. Categories of Personal Data

CategoryForm heldRetention
Recipient email address (registered communication)One way HMAC-SHA256 only; never the addressCustomer retention window, default 90 days
Content of registered communicationOne way SimHash and SHA-256 fingerprint only; never the bodyCustomer retention window
Registration metadataMessage id, From address, sent time, link domains, template and campaign ids, verify codeCustomer retention window
Submitted message or screenshotEncrypted at rest with a Customer specific key, Customer scoped storage prefixCustomer retention window, default 90 days, deleted with audit record
Submitter email addressOne way hash for matching; encrypted copy for reply onlyEncrypted copy purged 30 days after reply
Extracted signals and verdictsVerify code found, fingerprint, authentication results, outcome, rule, override trailLife of the account
Indicators of suspicious messagesURLs, domains, IPs, phone numbers, sender addresses, QR payloadsLife of the account
Customer personnelName, email, role, authentication credentials, audit log entriesLife of the account

No special categories of data are intentionally processed. Submitted messages may incidentally contain any content an End User forwards; Customer instructs End Users accordingly.

F. Frequency

Continuous, as communications are sent and verified.

Annex II. Subprocessors

SubprocessorPurposeLocation
Cloudflare, Inc.Hosting and edge compute (Workers), edge database (D1), object storage (R2), queues, screenshot OCR (Workers AI), bot protection (Turnstile), access controlUnited States
Neon, Inc.Postgres database, system of recordUnited States
Resend, Inc.Inbound email receipt and outbound email deliveryUnited States
Stripe, Inc.Billing and invoicing (Customer billing contact data only)United States
Functional Software, Inc. (Sentry)Error monitoring (technical event data; message content is scrubbed)United States

Annex III. Technical and organisational measures

1. Pseudonymisation and minimisation

  • Recipient addresses are hashed with HMAC-SHA256 under a Customer specific secret before transmission; the registration schema has no address column.
  • Message content is reduced to one way fingerprints at registration; normalized text is not persisted.
  • Submitter addresses are hashed for matching and held in encrypted form only for the reply, then purged after 30 days.
  • Verdict replies never include the submitted message, its links, or its sender.

2. Encryption

  • TLS 1.2 or higher for all data in transit, including between Provider and Subprocessors.
  • Encrypted fields use AES-256-GCM with a per Customer data key wrapped by a master key held only in the runtime secret store; message copies in object storage are encrypted with Customer scoped keys.
  • Customer scoped keys are rotated yearly; database and storage credentials are rotated quarterly.

3. Access control and tenant isolation

  • Every Customer owned record carries a tenant identifier; every query passes through a repository that requires it; storage prefixes are per Customer; API keys and site keys are Customer bound.
  • An automated test suite asserts that no endpoint reads across tenants and runs on every change.
  • Admin users authenticate with passkeys or email magic links and are assigned least privilege roles (owner, admin, analyst, integrator, viewer). Provider's backoffice sits behind Cloudflare Access with hardware key authentication; backoffice access to Customer views is read only and audited.
  • API keys are hashed at rest, displayed once, scoped, revocable, and tracked by last use.

4. Integrity and abuse resistance

  • Inbound mail is processed only after DKIM or ARC verification for a Customer owned domain and a matching DNS trust record; failures are quarantined for 24 hours and deleted.
  • Provider webhooks are signature verified with a 5 minute replay window; outbound webhooks are HMAC-SHA256 signed.
  • The public verify endpoint is rate limited per IP and per site key, origin checked, and escalates to bot challenge on abnormal rates.
  • No machine learning model participates in verdicts; extraction and matching are deterministic. OCR output is treated as untrusted input.
  • Fraud list entries originate only from authenticated analyst actions.

5. Availability and resilience

  • Stateless compute on a global edge network; queue based processing with dead letter handling and operator alerts.
  • Managed database with point in time recovery; object storage with durability guarantees from the Subprocessor.
  • Edge mirror of lookup data with fallback to the system of record.

6. Logging, monitoring, and incident response

  • Audit log of every administrative and analyst write with actor, action, target, and before and after values.
  • Application and error monitoring with per Customer latency and error dashboards; operator alerts for suspended domains, silent sources, dead letters, reply latency, replay spikes, and rejected inbound spikes.
  • Documented incident response with Customer notification within 72 hours of confirmation (Article 8).

7. Secure development and operations

  • Secrets held only in the runtime secret store, never in configuration or source control.
  • Dependency scanning; deployment only from continuous integration on the main branch after typecheck and test gates.
  • Responsible disclosure program with a monitored security mailbox.

8. Retention and deletion

  • Customer configurable retention window (default 90 days) enforced by scheduled sweeps with deletion records in the audit log.
  • Deletion of all Customer data within 30 days of termination; backups overwritten within 35 days.

9. Organisational measures

  • Confidentiality obligations and training for all personnel with access.
  • Subprocessor due diligence and contractual flow down of these measures.
  • Annual review of this Annex and of the Security page; SOC 2 Type 1 targeted within 12 months of the first paying tenant.