LegalData & Security

Data Processing Addendum (Summary)

Version 1.0 · Effective 21 July 2026 · Last updated 21 July 2026

Contact legal

This page summarizes our Data Processing Addendum (DPA), the contract under which Fulcrum processes personal data on behalf of its customers as a processor under GDPR Article 28 and equivalent laws. The full executed DPA is available to customers on request at [email protected].

1. Roles and scope (link to this section)

The customer is the controller of the personal data in its Customer Content. Fulcrum is the processor and processes that data only to provide the Service.

2. Processing instructions (link to this section)

We process personal data only on the customer's documented instructions, which include the Terms of Service, the customer's configuration of the Service, and the DPA itself.

3. Confidentiality (link to this section)

Personnel with access to personal data are bound by confidentiality obligations and receive access on a least-privilege basis.

4. Security measures (link to this section)

Encryption in transit and at rest, role-based access control, per-tenant data isolation, logging and monitoring, and regular review of controls. The Security Overview describes these measures.

5. Subprocessors (link to this section)

We use vetted subprocessors for hosting, telephony, payments, AI models, email, and monitoring. Each is bound by data protection terms consistent with the DPA. A current list is available on request, and customers are notified of material changes with a right to object.

6. Assisting with data subject rights (link to this section)

We provide the tools and assistance customers reasonably need to respond to access, correction, deletion, and portability requests from their own customers.

7. Breach notification (link to this section)

We notify affected customers without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting their data, with the information needed for their own notifications.

8. Return and deletion (link to this section)

On termination, customers can export their data. We then delete personal data within the period stated in the DPA, except where law requires retention.

9. Audits and transfers (link to this section)

The DPA grants customers audit rights, exercised through documentation and, where justified, independent review. International transfers rely on Standard Contractual Clauses and equivalent safeguards.

10. Getting an executed DPA (link to this section)

Enterprise customers receive an executed DPA at onboarding. Customers on any plan can request one at [email protected].

This policy is issued by Altnativ Pty Ltd (ABN 52 681 839 029), trading as Fulcrum, registered in Victoria, Australia.

Websites: tryfulcrum.ai · www.altnativ.co

Legal contact: Legal and Privacy, Altnativ Pty Ltd, Victoria, Australia. Email [email protected].

© 2026 Altnativ Pty Ltd. All rights reserved.