Data Processing Agreement

Last Updated

This Data Processing Agreement ("DPA") applies where Bold and Code, Inc., a Delaware corporation operating the Patentia service ("Patentia", "Processor", "we"), processes personal data on behalf of a customer ("Controller", "you") in the course of providing the Services.

This DPA forms part of our Terms of Service and applies automatically where you are a controller of personal data that we process on your behalf. If you have signed a separate written agreement with us covering data protection, that agreement controls.

It reflects the parties' obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR and the Swiss FADP. Terms such as "personal data", "processing", "controller", "processor" and "personal data breach" have the meanings given in Article 4 GDPR.

1. Roles and scope

1.1 Controller determines the purposes and means of processing. Processor processes personal data solely on Controller's documented instructions to provide the services described in the Terms of Service.

1.2 Details of processing are set out in Annex 1: subject matter, duration, nature and purpose, categories of data subjects and categories of personal data.

1.3 Controller warrants that it has a lawful basis for the processing it instructs, that it has provided the information required by Articles 13 and 14 GDPR to the data subjects concerned, including any inventor whose details it submits, and that its instructions comply with applicable data protection law. Controller may issue further instructions in writing to legal@patentia.online.

2. Processor obligations

Processor shall:

(a) process personal data only on documented instructions from Controller, including with regard to international transfers, unless required by law, in which case Processor informs Controller unless legally prohibited from doing so;

(b) ensure that persons authorised to process the data are bound by confidentiality;

(c) implement the technical and organisational measures described in Annex 2;

(d) respect the sub-processing conditions in section 4;

(e) taking into account the nature of the processing, assist Controller with data subject requests covering access, rectification, erasure, restriction, portability and objection. Where Processor receives such a request directly from a data subject, it shall forward it to Controller within three business days and shall not respond except on Controller's documented instruction or where legally required;

(f) assist Controller with security, breach notification, data protection impact assessments and prior consultation obligations under Articles 32 to 36 GDPR;

(g) at Controller's choice, delete or return all personal data at the end of the services, subject to legal retention requirements, in accordance with section 7;

(h) make available the information necessary to demonstrate compliance and allow audits in accordance with section 6;

(i) immediately inform Controller if, in Processor's opinion, an instruction infringes the GDPR or other applicable data protection law.

3. Security

Processor maintains a security programme aligned with its SOC 2 Type 2 attestation, the report for which is available under NDA through the access request flow at trust.patentia.online. The programme includes encryption in transit and at rest, access control on a least-privilege basis, logging and monitoring, and tested backups. Details are in Annex 2.

4. Sub-processors

4.1 Controller grants general authorisation to the sub-processors listed in Annex 3. That list is also published in our Privacy Policy.

4.2 Processor will give at least thirty (30) days' notice of any intended addition or replacement, by email to Controller's designated contact and by updating the list in the Privacy Policy. Controller may object on reasonable data protection grounds. If the objection cannot be resolved, Controller may terminate the affected services.

4.3 Processor imposes data protection obligations on sub-processors no less protective than those in this DPA, and remains fully liable for their performance.

5. International transfers

5.1 Processor is established in the United States and processing occurs in the United States.

5.2 For personal data subject to the GDPR:

(a) transfers from Controller to Processor rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, controller to processor, incorporated by reference and completed with the details in the Annexes. Processor is not itself certified under the EU-U.S. Data Privacy Framework.

(b) onward transfers from Processor to the sub-processors in Annex 3 rely on each sub-processor's EU-U.S. Data Privacy Framework certification where it holds one, and otherwise on the Standard Contractual Clauses, Module Three, processor to processor, as incorporated in that sub-processor's data processing agreement identified in Annex 3.

For United Kingdom transfers the UK International Data Transfer Addendum applies. For Swiss transfers the Swiss-adapted Clauses apply.

5.3 For the purposes of the Standard Contractual Clauses: under Clause 9(a), Option 2 applies, being general written authorisation with thirty (30) days' prior notice; the optional Clause 7 docking clause and the optional wording in Clause 11(a) are not used; under Clause 17, Option 1 applies and the Clauses are governed by the law of Ireland; under Clause 18, disputes arising from the Clauses shall be resolved before the courts of Ireland; the competent supervisory authority under Clause 13 is the supervisory authority of the Member State in which Controller is established. Annex I of the Clauses corresponds to the parties and to Annex 1 of this DPA, and Annex II of the Clauses corresponds to Annex 2 of this DPA. For Annex I.A, the data exporter is Controller as identified in its Patentia account record, acting as controller, and the data importer is Bold and Code, Inc., 1111B S Governors Ave, STE 23343, Dover, DE 19904, contact legal@patentia.online, acting as processor; acceptance of the Terms of Service constitutes signature by both parties. For Annex I.B the frequency of transfer is continuous for the duration of the Services. Annex III is not used, Clause 9(a) Option 2 having been selected. A copy of the Clauses is available on request from legal@patentia.online.

6. Audit

Processor makes available, on request and under NDA, its current SOC 2 Type 2 report, penetration test summaries and completed security questionnaires. Where those are insufficient to demonstrate compliance, Controller may conduct an audit, by itself or by an independent auditor it mandates who is not a competitor of Processor and who signs a confidentiality undertaking, at most annually, on thirty (30) days' notice and at its own cost, limited in scope and conducted so as not to disrupt the services. Where a supervisory authority requires an audit on a different basis, that requirement prevails over this section.

7. Deletion and return

On termination, Controller has thirty (30) days to export its data, either itself or by asking Processor for it in a structured, commonly used, machine-readable format. After that period Processor deletes it from active systems within a further thirty (30) days and confirms in writing. A certificate of destruction is available on request.

Copies held in backup archives are removed as those archives expire under their normal retention cycle, the longest of which does not exceed 400 days. Throughout that period those copies remain isolated from further processing and remain subject to the confidentiality obligations in section 4 of the Terms of Service.

Security audit logs recording access to the Services are retained for 400 days under a retention lock that prevents earlier alteration or deletion. Those logs contain no invention disclosure or report content, remain isolated from further processing, and remain subject to the same confidentiality obligations.

Data that Processor is required by law to retain is retained, isolated from further processing, and remains subject to those same obligations.

Deletion requests during the term are processed via privacy@patentia.online.

8. Breach notification

Processor notifies Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Controller personal data, providing the information reasonably required for Controller's own notification obligations. Shorter notification periods are available under a negotiated agreement.

9. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service on data protection matters.

10. Governing law, survival, and US state privacy laws

10.1 This DPA is governed by the law governing the Terms of Service, save that the Standard Contractual Clauses are governed as stated in section 5.3.

10.2 This DPA survives termination or expiry of the Terms of Service until all Controller personal data has been deleted or returned in accordance with section 7.

10.3 Where Controller personal data is subject to the California Consumer Privacy Act or other United States state privacy law, Processor acts as a "service provider" or equivalent, and shall not sell or share such personal data, nor retain, use or disclose it for any purpose other than providing the services.

Annex 1, Details of processing

Subject matter, nature and purpose. Hosting and operating the Patentia patent intelligence service; generating patent-related analyses and documents from Controller-submitted invention disclosures using Google's enterprise AI service; payment processing; transactional email.

Duration. The term of the Terms of Service plus the deletion period in section 7.

Categories of data subjects. Controller's authorised users, including employees, researchers and inventors; inventors named in submitted disclosures.

Categories of personal data. Name, business email, job title and organisation; account credentials, stored only as a salted hash; inventor names and contact details, whether entered as structured fields or appearing in disclosures and in generated documents; billing records, where payment card data is handled solely by Stripe; usage logs and correlation identifiers.

Special categories. Controller shall not deliberately submit special category data under Article 9 GDPR or data relating to criminal convictions under Article 10, and shall not rely on the Services to process such data as a primary purpose. The parties acknowledge that an invention disclosure may incidentally contain such data. Where it does, Processor processes it solely to deliver the Services, on Controller's instruction and under Controller's Article 9 condition, and applies the same technical and organisational measures as to all other Customer Content.

Annex 2, Technical and organisational measures

  • Encryption in transit using TLS 1.2 or above, and encryption at rest on all data stores.

  • Named individual accounts with role-based, least-privilege access. Multi-factor authentication is enforced on administrative accounts, and access is reviewed quarterly.

  • Centralised logging, alerting on error rates and availability, and audit logging of privileged administrative actions.

  • Automated daily backups with point-in-time recovery, and periodic tested restores.

  • Change management: protected release branches, mandatory review by someone other than the author, automated deployment, and static and dependency security scanning.

  • Vendor management with sub-processor data processing agreements, annual policy review, and SOC 2 Type 2 examinations conducted by Securance Pro Assurance PLLC on a recurring cycle.

Annex 3, Authorised sub-processors

Sub-processor

Purpose

Location

Transfer mechanism

Google LLC

Cloud infrastructure and AI inference

United States

Data Privacy Framework certified; Google Cloud Data Processing Addendum

Cloudflare, Inc.

Edge network and DNS

United States

Data Privacy Framework certified; Cloudflare DPA

Stripe, Inc.

Payment processing

United States

Data Privacy Framework certified; Stripe DPA

ActiveCampaign LLC (Postmark)

Transactional email

United States

Standard Contractual Clauses; Postmark DPA

Tooling that Processor runs on its own infrastructure is not a separate sub-processor.

Contact

Purpose

Address

Data protection and this DPA

legal@patentia.online

Privacy and data subject requests

privacy@patentia.online

Security and vulnerability reports

security@patentia.online

Bold and Code, Inc., 1111B S Governors Ave, STE 23343, Dover, DE 19904, United States.

© 2026 Bold and Code, Inc. All rights reserved.

Patentia is an IP intelligence software and advisory service. Patentia is not a law firm and does not provide legal advice. Outputs generated by Patentia, including search results, novelty assessments, claim drafts, landscape analyses, and freedom-to-operate reports, are informational and intended to support, not replace, the judgment of licensed patent counsel. Filing decisions, prosecution strategy, and any reliance on Patentia outputs in litigation or licensing should be validated by a qualified IP attorney admitted to practice in the relevant jurisdiction.

Access to Patentia is subject to the Terms of Service and Privacy Policy. Customer data is processed in accordance with applicable data protection laws and stored under enterprise-grade security controls.
Patentia makes no representation that outputs are exhaustive, error-free, or that the use of Patentia will result in patent grant, freedom to operate, or any particular legal or commercial outcome.

All third-party integrations and connected services are provided "as is." Patentia assumes no responsibility for the accuracy, availability, or continued support of connected services, including patent office data feeds, scientific literature sources, and language model providers. AI-generated outputs reflect the state of available data at the time of generation and may be incomplete or out of date. Customers are responsible for verifying outputs against authoritative sources before filing, contracting, or making strategic decisions based on Patentia.

Patentia is intended for use by professional IP teams, R&D organizations, and tech transfer offices. Feature availability may vary by plan level and jurisdiction. Forward-looking analyses, including patent landscape projections, white-space recommendations, and prior-art coverage estimates, are provided for informational purposes only and should not be the sole basis for filing, licensing, or investment decisions.

Patentia is a product of Bold and Code, Inc., a Delaware corporation. For questions regarding software usage, licensing, or data security, contact legal@patentia.online.

© 2026 Bold and Code, Inc. All rights reserved.

Patentia is an IP intelligence software and advisory service. Patentia is not a law firm and does not provide legal advice. Outputs generated by Patentia, including search results, novelty assessments, claim drafts, landscape analyses, and freedom-to-operate reports, are informational and intended to support, not replace, the judgment of licensed patent counsel. Filing decisions, prosecution strategy, and any reliance on Patentia outputs in litigation or licensing should be validated by a qualified IP attorney admitted to practice in the relevant jurisdiction.

Access to Patentia is subject to the Terms of Service and Privacy Policy. Customer data is processed in accordance with applicable data protection laws and stored under enterprise-grade security controls.
Patentia makes no representation that outputs are exhaustive, error-free, or that the use of Patentia will result in patent grant, freedom to operate, or any particular legal or commercial outcome.

All third-party integrations and connected services are provided "as is." Patentia assumes no responsibility for the accuracy, availability, or continued support of connected services, including patent office data feeds, scientific literature sources, and language model providers. AI-generated outputs reflect the state of available data at the time of generation and may be incomplete or out of date. Customers are responsible for verifying outputs against authoritative sources before filing, contracting, or making strategic decisions based on Patentia.

Patentia is intended for use by professional IP teams, R&D organizations, and tech transfer offices. Feature availability may vary by plan level and jurisdiction. Forward-looking analyses, including patent landscape projections, white-space recommendations, and prior-art coverage estimates, are provided for informational purposes only and should not be the sole basis for filing, licensing, or investment decisions.

Patentia is a product of Bold and Code, Inc., a Delaware corporation. For questions regarding software usage, licensing, or data security, contact legal@patentia.online.

© 2026 Bold and Code, Inc. All rights reserved.

Patentia is an IP intelligence software and advisory service. Patentia is not a law firm and does not provide legal advice. Outputs generated by Patentia, including search results, novelty assessments, claim drafts, landscape analyses, and freedom-to-operate reports, are informational and intended to support, not replace, the judgment of licensed patent counsel. Filing decisions, prosecution strategy, and any reliance on Patentia outputs in litigation or licensing should be validated by a qualified IP attorney admitted to practice in the relevant jurisdiction.

Access to Patentia is subject to the Terms of Service and Privacy Policy. Customer data is processed in accordance with applicable data protection laws and stored under enterprise-grade security controls.
Patentia makes no representation that outputs are exhaustive, error-free, or that the use of Patentia will result in patent grant, freedom to operate, or any particular legal or commercial outcome.

All third-party integrations and connected services are provided "as is." Patentia assumes no responsibility for the accuracy, availability, or continued support of connected services, including patent office data feeds, scientific literature sources, and language model providers. AI-generated outputs reflect the state of available data at the time of generation and may be incomplete or out of date. Customers are responsible for verifying outputs against authoritative sources before filing, contracting, or making strategic decisions based on Patentia.

Patentia is intended for use by professional IP teams, R&D organizations, and tech transfer offices. Feature availability may vary by plan level and jurisdiction. Forward-looking analyses, including patent landscape projections, white-space recommendations, and prior-art coverage estimates, are provided for informational purposes only and should not be the sole basis for filing, licensing, or investment decisions.

Patentia is a product of Bold and Code, Inc., a Delaware corporation. For questions regarding software usage, licensing, or data security, contact legal@patentia.online.