Legal

Data Processing Addendum

Effective Date: April 4, 2026

This Data Processing Addendum ("DPA") forms part of the ForecastWorx Software Terms of Service, Enterprise Software Subscription Agreement, Master Services Agreement, Order Form, or other services agreement (the "Agreement") between InventoryWorx Software LLC d/b/a ForecastWorx ("ForecastWorx," "Processor," "Service Provider," "Contractor," "we," "us," or "our") and the customer entity that is a party to the Agreement ("Customer," "Controller," "Business," or "you"). This DPA applies to the extent ForecastWorx Processes Personal Data on behalf of Customer in connection with the Services.
General questions: hello@forecastworx.ai
Legal notices: legal@forecastworx.ai
Mailing Address: PO Box 1093, Fort Collins, CO 80522

1. Purpose and Order of Precedence

1.1This DPA sets out the parties' obligations with respect to the Processing of Personal Data by ForecastWorx on behalf of Customer under the Agreement.
1.2If there is a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA will control to the extent of that conflict.
1.3Except as expressly modified by this DPA, the Agreement remains in full force and effect.

2. Definitions

For purposes of this DPA:
2.1 "Applicable Data Protection Law"
means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss data protection law, and U.S. state privacy laws such as the CCPA/CPRA and the Colorado Privacy Act.
2.2 "CCPA/CPRA"
means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.
2.3 "Customer Personal Data"
means Personal Data contained within Customer Data that ForecastWorx Processes on behalf of Customer in connection with the Services.
2.4 "Data Subject, Personal Data, Personal Data Breach, Processing, Processor, Controller"
have the meanings given to them under Applicable Data Protection Law, as applicable.
2.5 "EU GDPR"
means Regulation (EU) 2016/679.
2.6 "SCCs"
means the Standard Contractual Clauses approved by the European Commission for the transfer of personal data to third countries pursuant to the EU GDPR, as updated, replaced, or superseded from time to time.
2.7 "Subprocessor"
means any third party engaged by ForecastWorx to Process Customer Personal Data on ForecastWorx's behalf in connection with the Services.
2.8 "UK Addendum"
means the United Kingdom International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner's Office and as updated, replaced, or superseded from time to time.
2.9 "UK GDPR"
means the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland.
2.10 "Business, Service Provider, Contractor, Sell, Share, Sensitive Personal Information"
have the meanings given in the CCPA/CPRA where applicable.

3. Roles of the Parties

3.1The parties acknowledge that, with respect to Customer Personal Data, Customer is the Controller or Business, and ForecastWorx is the Processor, Service Provider, or Contractor, as applicable, unless otherwise expressly agreed in writing for a specific Processing activity.
3.2Customer is responsible for complying with its obligations as Controller or Business under Applicable Data Protection Law, including providing notices and obtaining consents or other lawful bases for Processing where required.

4. Nature and Scope of Processing

4.1 Subject Matter

The subject matter of the Processing is the provision of the Services under the Agreement.

4.2 Duration

The duration of the Processing is the Subscription Term under the Agreement, plus any limited period after termination during which ForecastWorx retains Customer Personal Data in accordance with the Agreement, this DPA, or applicable law.

4.3 Nature and Purpose

ForecastWorx may Process Customer Personal Data as necessary to host, store, organize, retrieve, analyze, display, transmit, secure, support, maintain, improve, and provide the Services, and to perform related obligations under the Agreement.

4.4 Categories of Data Subjects

Depending on Customer's use of the Services, Data Subjects may include Customer employees, users, contractors, agents, suppliers, business partners, customers, and other individuals whose Personal Data Customer submits to the Services.

4.5 Categories of Personal Data

Depending on Customer's use of the Services, Customer Personal Data may include business contact data, user account data, transactional and operational records, supplier information, and other Personal Data submitted by Customer.

4.6 Special Categories / Sensitive Data

Unless expressly agreed in writing, Customer will not submit special categories of personal data, protected health information, or other regulated sensitive data requiring heightened contractual or regulatory treatment beyond the scope of the Agreement and this DPA.

5. Customer Instructions

5.1ForecastWorx will Process Customer Personal Data only on Customer's documented instructions, unless required to do otherwise by applicable law.
5.2The Agreement, this DPA, applicable Order Forms, and Customer's use and configuration of the Services constitute Customer's complete and documented instructions as of the effective date of this DPA.
5.3If Customer issues additional instructions that materially expand the scope of Processing or ForecastWorx's obligations, ForecastWorx may charge reasonable additional fees or decline such instructions if they are not technically feasible, would violate law, or would materially degrade the security or performance of the Services.
5.4ForecastWorx will promptly inform Customer if, in ForecastWorx's opinion, a Customer instruction infringes Applicable Data Protection Law, unless prohibited by law from doing so.

6. Confidentiality

ForecastWorx will ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory.

7. Security of Processing

7.1

ForecastWorx will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, taking into account:
  • the state of the art;
  • implementation costs;
  • the nature, scope, context, and purposes of Processing; and
  • the risks to the rights and freedoms of natural persons.

7.2

Such measures will include, as appropriate to the Services, measures such as:
  • access control procedures;
  • authentication controls;
  • least-privilege practices where appropriate;
  • encryption in transit using industry-standard protocols;
  • encryption at rest where supported by the service architecture;
  • vulnerability management and patching practices;
  • logging and monitoring;
  • backup and recovery controls; and
  • incident response procedures.

7.3

ForecastWorx may update its security measures from time to time, provided such updates do not materially diminish the overall security posture of the Services during the applicable Subscription Term.

8. Assistance with Data Subject Requests

8.1

Taking into account the nature of the Processing, ForecastWorx will provide reasonable assistance to Customer to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

8.2

To the extent legally permitted, if ForecastWorx receives a request directly from a Data Subject relating to Customer Personal Data, ForecastWorx will:
  • not respond directly except as instructed by Customer or required by law; and
  • promptly direct the requester to Customer or notify Customer, as appropriate.

8.3

Customer is responsible for responding to Data Subject requests unless otherwise expressly agreed.

9. Assistance with Compliance Obligations

Taking into account the nature of the Processing and the information available to ForecastWorx, ForecastWorx will provide reasonable assistance to Customer with Customer's compliance obligations relating to:
  • security of Processing;
  • Personal Data Breach notifications;
  • data protection impact assessments; and
  • consultations with supervisory authorities,
provided that Customer will reimburse ForecastWorx for reasonable documented costs incurred for assistance beyond ForecastWorx's standard obligations under the Agreement and this DPA.

10. Personal Data Breach Notification

10.1

ForecastWorx will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

10.2

Such notice will include, to the extent reasonably available:
  • the nature of the Personal Data Breach;
  • the categories of Customer Personal Data affected;
  • the categories of affected Data Subjects, where known;
  • the likely consequences of the Personal Data Breach, where reasonably assessable; and
  • the measures taken or proposed to address the Personal Data Breach.

10.3

ForecastWorx may provide information in phases as it becomes available.

10.4

ForecastWorx's notification of a Personal Data Breach is not an admission of fault or liability.

11. Subprocessors

11.1 General Authorization

Customer authorizes ForecastWorx to engage Subprocessors in connection with the Services.

11.2 Subprocessor Obligations

ForecastWorx will enter into a written agreement with each Subprocessor imposing data protection obligations that are no less protective, in substance, than those set out in this DPA, as appropriate to the nature of the services provided by the Subprocessor.

11.3 Responsibility

ForecastWorx remains responsible for the acts and omissions of its Subprocessors to the extent required by Applicable Data Protection Law.

11.4 Subprocessor List

ForecastWorx will make available to Customer a current list of material Subprocessors, whether by trust center, online legal page, or written request to legal@forecastworx.ai.

11.5 Notice of New Subprocessors

ForecastWorx will provide notice of the addition or replacement of a material Subprocessor at least ten (10) days before the Subprocessor begins Processing Customer Personal Data, unless a shorter period is required due to urgent operational or security reasons.

11.6 Objection Right

Customer may object in writing to a new material Subprocessor within ten (10) days after receiving notice if Customer reasonably believes the Subprocessor presents a material data protection risk.

11.7 Objection Process

If Customer raises a reasonable objection:
  • the parties will discuss the objection in good faith;
  • ForecastWorx may use commercially reasonable efforts to provide an alternative; and
  • if no reasonable resolution is available, ForecastWorx may continue with the Subprocessor and Customer may terminate the affected Services upon written notice, without penalty for the terminated portion, before the Subprocessor begins Processing the affected Customer Personal Data.

11.8

Objections must be based on reasonable, documented concerns related to data protection, confidentiality, or information security, and not on general commercial preference alone.

12. Deletion and Return of Customer Personal Data

12.1

Upon expiration or termination of the Services, ForecastWorx will return or make available Customer Personal Data for export and thereafter delete Customer Personal Data in accordance with the Agreement, unless retention is required by applicable law.

12.2

Nothing in this Section requires ForecastWorx to delete Customer Personal Data from archival or backup systems immediately, provided such data remains protected and is deleted in accordance with ForecastWorx's standard retention lifecycle.

13. Audit Rights and Audit Evidence

13.1

ForecastWorx will make available to Customer information reasonably necessary to demonstrate ForecastWorx's compliance with this DPA.

13.2

Such information may include, where available and appropriate:
  • summaries of independent third-party audit reports;
  • SOC 2 Type II reports or equivalent independent assessments;
  • ISO 27001 certificates or similar certifications, if obtained;
  • responses to reasonable security questionnaires;
  • penetration test executive summaries or remediation attestations, where disclosure is appropriate and does not compromise security;
  • security whitepapers, trust materials, or control descriptions; and
  • written confirmations regarding Subprocessors, security practices, and incident response measures.

13.3

ForecastWorx may satisfy audit and inspection obligations by providing the materials described above, to the extent such materials provide Customer with reasonable information to verify compliance.

13.4

If the information made available under Section 13.2 is insufficient for Customer to satisfy a specific legal obligation under Applicable Data Protection Law, Customer may request an additional audit, subject to the following conditions:
  • no more than once per twelve (12) month period, unless required by law or following a confirmed Personal Data Breach materially affecting Customer Personal Data;
  • upon at least thirty (30) days' prior written notice;
  • during normal business hours;
  • in a manner designed to minimize disruption to ForecastWorx's business operations;
  • using an independent third-party auditor reasonably acceptable to ForecastWorx and not a competitor of ForecastWorx;
  • subject to appropriate confidentiality obligations; and
  • limited to systems, records, and facilities relevant to the Processing of Customer Personal Data under the Agreement.

13.5

Customer will bear the costs of any such audit unless the audit reveals a material noncompliance by ForecastWorx with this DPA.

13.6

ForecastWorx may object to an auditor or audit scope that would:
  • compromise the security of ForecastWorx or its other customers;
  • disclose confidential information unrelated to Customer;
  • violate legal obligations owed to third parties; or
  • create unreasonable operational burden,
in which case the parties will work in good faith to agree on a reasonable alternative verification method.

14. International Transfers

14.1

To the extent ForecastWorx Processes Customer Personal Data subject to the EU GDPR, UK GDPR, or Swiss data protection law in a country not recognized as providing an adequate level of protection, the parties agree that the applicable transfer mechanism in this Section will apply.

14.2 EU Transfers

Where Customer Personal Data subject to the EU GDPR is transferred from the European Economic Area to ForecastWorx or onward to a Subprocessor in a third country without an adequacy decision, the SCCs are incorporated by reference and apply as follows:
  • Module Two (Controller to Processor) applies where Customer is a Controller and ForecastWorx is a Processor;
  • Module Three (Processor to Processor) applies where Customer is a Processor and ForecastWorx is a subprocessor;
  • the optional docking clause applies;
  • Clause 7 applies if available in the SCC version in use;
  • in Clause 9, Option 2 applies, and the time period for prior notice of new Subprocessors will be as set out in Section 11 of this DPA;
  • in Clause 11, the optional language does not apply unless required by law;
  • in Clause 17, the governing law will be Ireland, unless another EU Member State is required by Customer's lead supervisory authority or applicable law; and
  • in Clause 18, the parties submit to the courts of Ireland, unless another EU Member State is required by applicable law.
Annex I, II, and III to the SCCs will be deemed completed with the information set out in this DPA, the Agreement, the applicable Order Form, and ForecastWorx's then-current Subprocessor List and security materials made available to Customer.

14.3 UK Transfers

Where Customer Personal Data subject to the UK GDPR is transferred from the United Kingdom to a country that is not recognized as adequate under UK law, the SCCs as supplemented by the UK Addendum are incorporated by reference and apply. For purposes of the UK Addendum:
  • the SCCs selected under Section 14.2 form the Approved EU SCCs;
  • the parties agree that the tables in the UK Addendum will be deemed completed with the relevant information from this DPA, the Agreement, and the applicable Order Form; and
  • any conflict between the SCCs and the UK Addendum will be resolved in favor of the UK Addendum for UK-restricted transfers.

14.4 Swiss Transfers

Where Customer Personal Data subject to Swiss data protection law is transferred from Switzerland to a country not recognized as adequate, the SCCs will apply with such modifications as are necessary for Swiss law, including interpreting references to:
  • "Member State" as including Switzerland where required;
  • "GDPR" as including the Swiss Federal Act on Data Protection where appropriate; and
  • the competent supervisory authority and courts as those applicable under Swiss law.

14.5 Alternative Transfer Mechanisms

If the SCCs, UK Addendum, or other transfer mechanisms referenced in this Section are replaced, invalidated, amended, or no longer legally sufficient, the parties will cooperate in good faith to implement a lawful alternative transfer mechanism.

14.6 Transfer Risk Measures

ForecastWorx will implement reasonable supplementary measures, where appropriate, taking into account the nature of the Customer Personal Data transferred, the Processing involved, and the technical and organizational safeguards available.

15. California and Other U.S. State Privacy Terms

15.1

To the extent the CCPA/CPRA applies, ForecastWorx is a Service Provider or Contractor with respect to Personal Data Processed on behalf of Customer.

15.2

ForecastWorx will not:
  • Sell or Share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, except as otherwise permitted by the CCPA/CPRA;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship between ForecastWorx and Customer, except as permitted by law; or
  • combine Customer Personal Data received from Customer with Personal Data received from another source, except as permitted by Applicable Data Protection Law.

15.3

ForecastWorx certifies that it understands and will comply with the restrictions applicable to Service Providers and Contractors under the CCPA/CPRA.

15.4

To the extent required by Applicable Data Protection Law, ForecastWorx will support Customer in responding to consumer requests and will permit reasonable steps by Customer to verify ForecastWorx's compliance with these obligations using the audit and information rights in Section 13.

16. Limitation

This DPA does not apply to data for which ForecastWorx is an independent Controller, such as business contact information relating to Customer representatives used for account management, billing, contract administration, compliance, or direct communications regarding the Services.

17. Termination

This DPA will remain in effect for so long as ForecastWorx Processes Customer Personal Data under the Agreement.

18. Annex 1 — Description of Processing

Parties

Data exporter: Customer Data importer: ForecastWorx

Subject matter of the Processing

Provision of ForecastWorx SaaS services, support, hosting, maintenance, and related services under the Agreement.

Duration of the Processing

For the term of the Agreement and any limited retention period permitted under the Agreement and this DPA.

Nature and purpose of the Processing

Hosting, storage, organization, retrieval, analysis, display, transmission, support, maintenance, security, and other Processing activities necessary to provide the Services.

Categories of Data Subjects

May include Customer personnel, contractors, suppliers, customers, and other individuals whose data is submitted to the Services by or for Customer.

Categories of Personal Data

May include names, business contact details, account information, supplier and transaction data, user metadata, operational records, and other Personal Data submitted by Customer.

Sensitive Data

None unless expressly agreed in writing.

Frequency of Processing

Continuous and as initiated by Customer through use of the Services.

Retention

As set forth in the Agreement, this DPA, and ForecastWorx's retention and deletion practices.

19. Annex 2 — Technical and Organizational Measures

ForecastWorx maintains technical and organizational measures designed to protect Customer Personal Data, including measures relating to:
  • access management;
  • authentication;
  • encryption in transit;
  • encryption at rest where supported;
  • logging and monitoring;
  • vulnerability management;
  • incident response;
  • backup and recovery;
  • personnel confidentiality; and
  • vendor and subprocessor oversight.
Further detail may be provided through ForecastWorx's trust materials, questionnaires, or audit evidence made available under Section 13.

20. Annex 3 — Subprocessors

ForecastWorx will maintain and make available a current list of material Subprocessors in accordance with Section 11.