Cover
| Effective Date | 3 September 2026 (or determined under Section 1 upon online acceptance) |
| Main Agreement | The Terms of Service together with any applicable Order Form |
| Eachlabs (Processor) | Eachlabs Inc., 8 The Green, Suite A, Dover, Delaware 19901, USA |
| Customer (Controller or Processor) | The Customer defined in the Terms of Service (identified under Section 1) |
This Data Processing Addendum (the "DPA") forms part of the Main Agreement between Eachlabs Inc. ("Eachlabs") and Customer governing Customer's use of the Services. Capitalized terms not defined here have the meanings given in the Main Agreement or Applicable Data Protection Laws. If Customer enters into this DPA on behalf of another Controller, Customer represents that it has full authority to bind that Controller.
1. Definitions and Entry into this DPA
| Term | Definition |
| Applicable Data Protection Laws | All privacy and data protection laws applicable to the Processing, including the GDPR, UK GDPR, Swiss FADP, Turkish KVKK, Saudi PDPL, UAE Data Protection Laws, and U.S. federal and state privacy laws (including the CCPA/CPRA). |
| Customer Content | Prompts, inputs, text, files, images, audio, video, documents, configurations, outputs and any other data submitted to, generated through, or stored in the Services by or for Customer. |
| Customer Personal Data | Personal Data contained in Customer Content Processed by Eachlabs as Processor on Customer's behalf, excluding independent-controller account and billing data governed by Section 2. |
| AI Service Provider | A third party that supplies, hosts, or routes an AI model or inference endpoint accessed through the Services. |
| Core Subprocessor | A Subprocessor providing foundational cloud hosting, networking, authentication, or database infrastructure listed in Schedule 3, Part A. |
| Customer-Connected Provider | A third-party endpoint, API, or webhook designated by Customer as a workflow destination that Eachlabs has not engaged as a Subprocessor. |
| Execution ID | The unique system identifier assigned by the Services to a specific workflow or API execution. |
| Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Eachlabs or an authorized Subprocessor. |
| Prohibited Data | Data identified in Section 3 that the Services are not designed or approved to process without Eachlabs' express written agreement. |
| Subprocessor | A third party engaged by Eachlabs to Process Customer Personal Data on Customer's behalf in connection with the Services. |
| Standard Contractual Clauses (SCCs) | The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, completed as set forth in Schedule 4. |
| UK Addendum | The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office. |
Statutory terms
"Controller", "Processor", "Data Subject", "Personal Data", and "Processing" have the meanings given in Applicable Data Protection Laws.
Entry into this DPA
This DPA is entered into either by mutual execution of an Order Form or this DPA (the signed path), or by Customer accepting Terms of Service that incorporate this DPA (the online path). On the online path, the Effective Date is the date Customer accepted the Terms of Service, or the effective date of those Terms of Service, whichever is later. On the online path, the legal entity associated with Customer's account registration and billing details completes the cover table and transfer annexes. Acceptance of the Terms of Service constitutes electronic signature of this DPA, the SCCs, and the UK Addendum. The KVKK standard contract in Schedule 4.D requires separate execution.
2. Scope and Roles
Roles of the parties
For Customer Personal Data, Customer acts as Controller and Eachlabs acts as Processor. Where Customer acts as a Processor on behalf of a third-party Controller, Eachlabs acts as Subprocessor, and Customer confirms it has full authority to instruct Eachlabs on that Controller's behalf.
Independent Controller data
Eachlabs acts as an independent Controller solely for account administration, billing, business contact management, tax compliance, and operational security telemetry. These activities never include Customer Content, which Eachlabs processes exclusively as Processor under this DPA. Eachlabs' Privacy Policy governs these independent activities.
3. Customer Responsibilities and Data Restrictions
Customer accountability
Customer controls the content and purposes of its Processing. Customer is solely responsible for the lawfulness, accuracy, quality, and minimization of Customer Personal Data, and for securing all necessary rights, notices, and consents. Customer is further responsible for the legality of its instructions and compliance with applicable international transfer requirements.
Prohibited Data
Unless an Order Form expressly authorizes an approved use case, Customer will not submit, and will ensure its users do not submit: (a) special-category or sensitive Personal Data; (b) criminal-offence data; (c) biometric templates or biometric data used for unique identification; (d) payment-card or financial credentials; (e) protected health information; (f) government identification numbers; (g) children's data; (h) classified or export-controlled data; or (i) data subject to sector-specific localization or residency laws that the Services are not configured to meet (including Saudi NDMO/SAMA standards or UAE Health ICT Law).
Use restrictions
Customer will not deploy the Services for automated decision-making producing legal or similarly significant effects on individuals without human oversight and required statutory safeguards.
4. Documented Instructions and Processing
Documented instructions
Customer instructs Eachlabs to Process Customer Personal Data solely to execute, route, deliver, store, and support Customer's requests under the Main Agreement, this DPA, applicable Order Forms, and Customer's authenticated configuration of the Services. Eachlabs Processes Customer Personal Data outside these instructions only where required by applicable law, in which case Eachlabs will notify Customer in advance unless prohibited by law.
Unlawful instructions and suspension
If Eachlabs reasonably believes an instruction violates Applicable Data Protection Laws or creates a security risk, it will notify Customer without undue delay via API error response, console notification, or email, and may suspend the affected Processing until resolved.
Additional instructions
Instructions outside the standard documented functionality of the Services require Eachlabs' prior written agreement. Eachlabs has no obligation to develop custom features or disclose confidential source code.
6. Confidentiality and Security
Personnel confidentiality
Eachlabs ensures that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations that survive termination of their engagement. Access is strictly limited on a need-to-know basis.
Security measures and shared responsibility
Eachlabs maintains the technical and organizational security measures set forth in Schedule 2 to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure. Eachlabs may update these measures, provided updates do not materially degrade overall service security. Customer is solely responsible for protecting its API keys, managing user credentials, and configuring its workflow security. Eachlabs does not warrant absolute security or invulnerability.
7. Subprocessors
Authorized Subprocessors
Customer authorizes Eachlabs to engage the Subprocessors listed in Schedule 3 on the Effective Date. Eachlabs imposes data protection obligations on Subprocessors substantially consistent with this DPA.
Core Subprocessor changes and objections
Eachlabs provides at least 15 days' advance notice of any new Core Subprocessor by updating the published Subprocessor list, console notification, or email. Customer may object on reasonable, documented data-protection grounds within 15 days of notice. If the parties cannot resolve the objection within 30 days, Customer may terminate the affected Service on written notice without penalty as its sole remedy.
AI Service Providers
Customer manages AI Service Providers directly through model selection. Invoking a model constitutes specific authorization of that provider under Section 5. Core Subprocessor objection rights do not apply to third-party AI models.
8. Data Subject Rights and Compliance Assistance
Data Subject requests
If Eachlabs receives a Data Subject request concerning Customer Personal Data, Eachlabs will redirect the requester to Customer. Where the request identifies Customer or includes an associated Execution ID, Eachlabs will promptly notify Customer. Customer is solely responsible for responding to Data Subject requests.
Assistance and operational limits
Taking into account the nature of Processing and available information, Eachlabs provides commercially reasonable assistance with Customer's statutory data protection obligations through standard self-service tools and available documentation. Eachlabs has no obligation to execute custom code, alter immutable execution records, or modify operational logs.
9. Personal Data Breaches
Breach notification
Eachlabs will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data Processed by Eachlabs or an authorized Subprocessor, sent to Customer's designated security contact or account owner. Notice does not constitute an admission of fault. An incident occurring solely within an AI Service Provider's systems is not a breach by Eachlabs; Eachlabs will notify Customer without undue delay after learning of a confirmed breach formally disclosed by that provider.
Notice and containment
Notice will describe, to the extent reasonably available, the nature of the breach, affected data categories, likely consequences, and remediation measures taken or planned. Information may be delivered in phases as facts are verified. Eachlabs will take commercially reasonable steps to contain and mitigate confirmed breaches on its systems. Customer is solely responsible for notifying regulators and Data Subjects.
Unsuccessful security attempts
Unsuccessful security attempts—including routine pings, port scans, blocked DDoS attacks, firewall drops, or failed login attempts—do not constitute a Personal Data Breach and require no notification.
10. International Transfers and Government Requests
Transfer mechanisms
Where Customer Personal Data is transferred to a country without an adequacy decision, the transfer terms in Schedule 4 apply. Customer is solely responsible for verifying that its selected routes, models, and endpoints comply with Applicable Data Protection Laws and for conducting any required Transfer Impact Assessments.
No regional data localization
Eachlabs provides no local data hosting, residency, or localization within Saudi Arabia, the UAE, any other MENA jurisdiction, or any specific territory, unless expressly agreed in a signed, paid Order Form. All Processing occurs in the United States and the infrastructure locations identified in Schedules 1 and 3.
Government demands
If Eachlabs receives a binding legal demand for Customer Personal Data, it will notify Customer before disclosure unless legally prohibited, review the demand's legality, disclose only the minimum required, and challenge unlawful demands where reasonable grounds exist.
11. Return, Deletion and Retention
During the term
Customer manages stored files via the Storage API and may delete workflows and API keys via the console. Customer may export execution metadata, workflow configurations, and stored files using the standard self-service export tools in the Services. Execution records are retained as set forth in Schedule 1 to maintain workflow history and are not deletable during the term.
Termination and deletion
Upon termination, Customer may export Customer Personal Data using standard self-service export tools prior to access termination. Upon Customer's written request submitted to support@eachlabs.ai within 30 days following termination of the Main Agreement, Eachlabs will provide temporary read-only export re-enablement to permit Customer to retrieve stored Customer Content prior to permanent deletion under this Section 11. Self-service export satisfies Customer's statutory return rights and excludes offline bulk extraction of execution payloads. Following termination and expiry of a 30-day grace period, Customer instructs Eachlabs to delete Customer Personal Data from Eachlabs-controlled systems in accordance with Schedule 1, unless applicable law requires retention. On written request, Eachlabs will confirm completion of account deletion by email. Provider-side copies are governed solely by each provider's published retention terms.
Backups and legal exceptions
Customer Personal Data in backups is isolated, put beyond ordinary use, and overwritten in the standard backup cycle set forth in Schedule 1. Eachlabs may retain limited records where required to comply with legal obligations or defend legal claims, deleting them when the obligation ends.
12. Compliance Information and Audits
Evidence first
Eachlabs demonstrates compliance by providing standard compliance documentation, security summaries, and available independent certifications. Customer will review existing documentation before requesting an audit.
Audit terms and costs
If standard documentation is reasonably insufficient or a competent authority requires an audit, Customer may audit Eachlabs' compliance with this DPA once in any 12-month period upon at least 30 days' advance written notice. Audits must occur during normal business hours, remotely where feasible, and are strictly limited to systems and personnel relevant to the Processing. Audits exclude penetration testing, vulnerability scanning, source-code review, or access to other customers' data. Audits under Clause 8.9 of the SCCs follow this Section. Customer bears its own costs of any such audit, unless the audit establishes a material breach of this DPA by Eachlabs.
13. Liability
Main Agreement limits
Eachlabs' aggregate liability arising out of or related to this DPA, Applicable Data Protection Laws, or transfer instruments is subject to the limitation of liability and cap in Section 18 of the Main Agreement. Such liability forms part of that aggregate cap and does not create an additional cap. Pursuant to and to the extent permitted under Clause 12(a) of the SCCs and applicable law, all inter-party liability under the SCCs or a KVKK standard contract is subject to that cap. Nothing in this Section limits non-waivable statutory liability owed directly to Data Subjects. Eachlabs is not liable for Customer-Connected Providers.
Provider responsibility
Eachlabs is responsible for Subprocessors, including AI Service Providers, solely to the extent required by mandatory Applicable Data Protection Laws. Otherwise, each AI Service Provider is responsible for its own Processing under its published terms. Eachlabs gives no warranty and assumes no liability for the availability, continuity, latency, throughput, or output quality of third-party AI models.
14. AI Laws and Regulated Uses
Regulatory allocation
The parties allocate regulatory roles under applicable artificial intelligence laws (including Regulation (EU) 2024/1689) in accordance with their technical activities. Eachlabs provides API routing, model orchestration, and workflow tooling; Customer acts as deployer of any AI system configured by Customer and is responsible for its own compliance, intended purpose, and end-user transparency notices. Customer will not deploy the Services for any prohibited AI practice under applicable law.
15. Term, Precedence and General Terms
Term and precedence
This DPA continues while Eachlabs Processes Customer Personal Data. In case of conflict, the order of precedence is: (1) mandatory transfer clauses and mandatory law; (2) this DPA, for data protection and Customer Content matters; and (3) the Main Agreement otherwise, including its commercial and liability framework.
Amendments
Eachlabs may update this DPA by publishing a revised version. For existing Customers, Eachlabs provides at least 30 days' advance notice of material updates via the Services or email. Updates required by law take effect as stated in the notice. Non-material or protective updates take effect upon publication. Continued use after the effective date constitutes acceptance. A Customer objecting to a material update may terminate the affected Service before the effective date as its sole remedy. Updates apply prospectively and do not modify the SCCs, UK Addendum, or signed Order Forms.
Governing law
The provisions of the Main Agreement on disputes, governing law (Delaware), venue (Delaware), limitation periods, and third-party beneficiaries apply to this DPA, except where mandatory transfer terms or Schedule 4 provide otherwise. References to statutory transfer instruments include their valid successors.
SCHEDULE 1 - PROCESSING DETAILS
| Item | Details |
| Subject matter | Provision of Eachlabs' AI gateway, APIs, workflows, media storage, delivery, and related support under the Main Agreement. |
| Duration | The Services term plus applicable return, deletion, backup, legal, and security retention periods. |
| Nature and operations | Receiving, authenticating, routing, and delivering Customer requests; workflow orchestration; media storage; logging; troubleshooting; export and deletion. |
| Specific purposes | Routing inputs and outputs to Customer-selected models; maintaining workflow execution history; metering usage; security and abuse prevention; return and deletion under this DPA. |
| Frequency | Continuous and on-demand as configured by Customer. |
| Data Subjects | Customer personnel; Customer users and end users; individuals depicted, recorded, or described in Customer Content. |
| Categories of Personal Data | Prompts, text, images, audio, video, documents, generated outputs, file and job metadata, identifiers, and relevant operational and security logs. |
| Special or sensitive data | Not intended or approved by default. Customer is solely responsible for establishing a lawful basis for any faces, voices, or identifiable content submitted. |
| Processing locations | United States (AWS us-east-1), Cloudflare edge network, and locations of Subprocessors and Customer-selected AI Service Providers disclosed in Schedule 3 and the catalog. |
| Authorized recipients | Authorized Eachlabs personnel, Subprocessors in Schedule 3, Customer-Connected Providers at Customer's direction, and competent authorities where required by law. |
Retention and deletion
| Data or record | Retention / handling |
| Execution records and payloads | Retained in primary databases and private object storage in AWS us-east-1 for the life of Customer's account to maintain workflow history; deleted under Section 11. |
| In-flight state and webhooks | In-flight execution state is held for 14 days; webhook delivery payloads are retained for 30 days. |
| Uploaded files and generated media | Retained per upload deadline (default 180 days, configurable between 60 seconds and 365 days, or non-expiring until deleted via the Storage API). |
| Backups and archives | Automated database backups retained for 14 days; versioned object storage for 30 days. Backups are isolated and not used for ordinary processing. |
| Operational and security logs | System telemetry retained in accordance with operational log lifecycles; incident and legal hold records preserved as required by law. |
| Training and secondary use | Eachlabs never uses Customer Content to train, retrain, or fine-tune AI models for itself, other customers, or third parties. This commitment is unconditional. |
SCHEDULE 2 - TECHNICAL AND ORGANIZATIONAL MEASURES
Eachlabs maintains administrative, technical, and physical safeguards designed to protect Customer Personal Data, as detailed below. These measures are maintained in accordance with prevailing cloud standards and may be updated provided overall security is not materially degraded.
- ·Information Security Program: Defined security responsibilities, confidentiality commitments, least-privilege access controls, and role-appropriate security training.
- ·Identity & Access Management: Role-based access control, administrative least-privilege principles, and prompt access revocation upon personnel role change or departure.
- ·Encryption: Customer Personal Data is encrypted in transit using modern TLS protocols and encrypted at rest in primary database clusters and object storage where supported by the underlying cloud infrastructure or as specified in an Order Form.
- ·Secure Engineering: Automated testing, code review, static analysis workflows, and risk-based vulnerability management.
- ·Network & Tenant Separation: Multi-layered boundary defenses, logical tenant isolation in the application layer, and network segmentation.
- ·Logging & Incident Response: Centralized operational and security logging, automated anomaly alerting, and documented incident response and notification procedures.
- ·Business Continuity & Backups: Automated regular database and storage backups with multi-zone cloud infrastructure redundancy.
- ·Subprocessor Governance: Risk-based vendor diligence, binding contractual data protection terms, and ongoing security reviews.
SCHEDULE 3 - SUBPROCESSORS AND AI SERVICE PROVIDERS
Customer grants general written authorization for the Subprocessors listed below, current as of 3 September 2026. The current list is published at https://eachlabs.ai/subprocessors.
Part A - Core Subprocessors
| Subprocessor | Purpose | Location & Contact |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting: compute, object storage, databases, and workflow orchestration | 410 Terry Ave N, Seattle, WA 98109, USA (us-east-1); contact: aws-privacy@amazon.com |
| Cloudflare, Inc. | Network edge, CDN, DDoS mitigation, and reverse proxy | 101 Townsend St, San Francisco, CA 94107, USA; contact: privacyquestions@cloudflare.com |
| Google LLC (Google Cloud & Firebase) | User authentication and identity management | 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA; contact: enterprise-dpo@google.com |
| Vercel Inc. | Web application hosting for console and account management | 440 N Barranca Ave #4133, Covina, CA 91723, USA; contact: privacy@vercel.com |
| Zilliz, Inc. | Managed vector database (Milvus) for catalog search embeddings | 440 N Wolfe Rd, Sunnyvale, CA 94085, USA; contact: privacy@zilliz.com |
Part B - Third-Party AI Model Providers (Customer-Directed Endpoints)
Third-party AI model providers (such as OpenAI, Anthropic, Google, and OpenRouter) accessible through the Services are independent Customer-Directed Endpoints, not Eachlabs subprocessors. Customer's selection and invocation of a model affirmatively instructs Eachlabs to route requests to that independent provider under Section 5 and constitutes specific prior written authorization under Clause 9(a) of the SCCs where applicable. Selections made through assisted model selection, routing, or fallback features Customer uses are Customer's instruction under Section 5. (See Part C below for Eachlabs' separate platform operations accounts).
Part C - Platform Tooling for Service Operation
The entities listed in this Part C act as Eachlabs subprocessors strictly when providing platform operations, internal tooling, diagnostics, or automated workflow orchestration under Eachlabs' own business accounts. Where Customer directly selects or directs requests to these providers for Customer Content inference (directly or through assisted model selection, routing, or fallback features), such processing is governed exclusively by Part B above as Customer-Directed Endpoints.
| Subprocessor | Purpose | Location & Contact |
|---|---|---|
| Anthropic, PBC | Platform operations, automated orchestration, and service diagnostics | United States; contact: privacy@anthropic.com |
| OpenAI OpCo, LLC | Platform operations, automated orchestration, and service diagnostics | United States; contact: privacy@openai.com |
| OpenRouter, Inc. | Platform operations, workflow routing, and service diagnostics | United States; contact: privacy@openrouter.ai |
Part D - Support and Operational Tools
| Tool | Purpose | Location & Contact |
|---|---|---|
| Intercom, Inc. | In-app support messaging | 55 2nd St, 4th Fl, San Francisco, CA 94105, USA; contact: privacy@intercom.io |
| Linear Orbit, Inc. | Engineering and support tracking | 548 Market St #62411, San Francisco, CA 94104, USA; contact: privacy@linear.app |
| PagerDuty, Inc. | On-call operational alerting | 600 Townsend St, Suite 200, San Francisco, CA 94103, USA; contact: privacy@pagerduty.com |
| Pylon Labs, Inc. | Customer support ticketing | 548 Market St, San Francisco, CA 94104, USA; contact: privacy@usepylon.com |
| Slack Technologies, LLC | Internal operational alerts | 500 Howard St, San Francisco, CA 94105, USA; contact: privacy@slack.com |
| Stripe, Inc. | Payments and billing | 354 Oyster Point Blvd, South San Francisco, CA 94080, USA; contact: privacy@stripe.com |
SCHEDULE 4 - INTERNATIONAL TRANSFER TERMS
A. EEA Restricted Transfers (EU SCCs)
Where Customer exports Customer Personal Data subject to the GDPR to Eachlabs in a third country without an adequacy decision, the EU Standard Contractual Clauses (Decision (EU) 2021/914) are incorporated by reference and completed as follows:
- ·Modules: Module 2 (Controller-to-Processor) applies where Customer is a Controller; Module 3 (Processor-to-Processor) applies where Customer is a Processor.
- ·Docking & Subprocessors: Clause 7 applies. Under Clause 9, Option 2 applies with at least 15 days' advance notice.
- ·Governing Law & Jurisdiction: Under Clauses 17 and 18, Irish law and the courts of Ireland govern.
- ·Liability: Pursuant to and to the extent permitted under Clause 12(a), inter-party liability between data exporter and data importer is subject to the limitation of liability and cap in Section 18 of the Main Agreement.
- ·Annexes: Annex I.A reflects the parties in this DPA; Annex I.B is Schedule 1; Annex I.C is the competent supervisory authority under Clause 13; Annex II is Schedule 2; Annex III is Schedule 3.
B. United Kingdom Transfers
Where UK data protection laws apply, the ICO International Data Transfer Addendum (Version B.1.0) is incorporated by reference:
- ·Table 1 uses party details from this DPA; Table 2 selects the Approved EU SCCs above; Table 3 incorporates Schedules 1–3; Table 4 selects "Importer".
- ·Customer is responsible for conducting any required UK transfer risk assessments prior to transfer.
C. Switzerland Transfers
For transfers subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs apply with the following modifications:
- ·References to the GDPR refer to the FADP; the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent authority under Annex I.C; and Swiss data subjects may enforce claims in Switzerland under Clause 18(c).
D. Türkiye / KVKK Transfers
For transfers subject to the Turkish Personal Data Protection Law No. 6698 (KVKK):
- ·The parties will execute the mandatory Turkish text of Standard Contract 2 (Controller-to-Processor) or Standard Contract 3 (Processor-to-Processor) prior to the first transfer.
- ·Customer as data exporter is solely responsible for filing the executed Standard Contract with the Turkish Personal Data Protection Authority within 5 business days of execution and providing filing proof to Eachlabs.
E. Middle East & North Africa (MENA) Transfers
For transfers subject to the Saudi Arabia Personal Data Protection Law (Saudi PDPL) or UAE Data Protection Laws (Federal Decree-Law No. 45/2021, DIFC, ADGM):
- ·This DPA and Schedule 4 constitute binding controller-to-processor transfer terms.
- ·Customer is solely responsible for conducting required Transfer Impact Assessments, obtaining any necessary regulatory permits from SDAIA or the UAE Data Office, and securing all required explicit consents prior to initiating transfers.
SCHEDULE 5 - U.S. STATE PRIVACY TERMS
Roles and Status
To the extent Customer Personal Data is subject to applicable U.S. state privacy laws (including the CCPA/CPRA, VCDPA, and CPA), Customer is the Business or Controller, and Eachlabs is a Service Provider or Processor.
Prohibitions and Certification
Eachlabs will not:
- ·(a) Sell or Share Customer Personal Data;
- ·(b) Process Customer Personal Data for targeted advertising or cross-context behavioral advertising;
- ·(c) retain, use, or disclose Customer Personal Data outside the direct business relationship or for any purpose other than providing the Services under the Main Agreement;
- ·(d) combine Customer Personal Data with personal data received from other sources, except as permitted by applicable law; or
- ·(e) use Customer Content or Customer Personal Data to train, retrain, or fine-tune any AI or machine-learning model, as Section 5 provides.
Eachlabs certifies that it understands and will comply with these restrictions.
Consumer Requests and Remediation
Eachlabs will provide reasonable assistance to Customer in responding to consumer rights requests under applicable U.S. state privacy laws, redirecting direct consumer requests to Customer. Eachlabs will notify Customer without undue delay if it determines it can no longer meet its obligations under applicable U.S. state privacy laws. Customer has the right, upon written notice, to take reasonable steps to stop and remediate any unauthorized use of Customer Personal Data.
SIGNATURES
This block is completed solely on the signed path (an Order Form or signed copy of this DPA); on the online path, Section 1 applies and no separate signature is required.
On the online path, Customer enters into this DPA by accepting the Terms of Service or using the Services. Enterprise customers requiring a countersigned copy or custom Order Form may request one at support@eachlabs.ai.