Last updated: 10 July 2026
Data Processing Agreement
How Factory1 processes customer business data for organizations that use the platform.
Roles
For customer business data, the customer is the Data Controller and Factory1 acts as the Data Processor.
The customer decides what data is entered into Factory1 and who inside the organization may access it.
Processing Instructions
Factory1 processes data only to provide, secure, maintain, support and improve the Factory1 service.
Factory1 may process data for AI assistance, reporting, import/export, notifications, support, backups and security monitoring.
GDPR Readiness
Factory1 is being designed with GDPR-friendly practices such as access control, data export, deletion workflows and processor accountability.
If an EU customer requires a signed DPA, Factory1 can provide a commercial DPA during onboarding.
Subprocessors And Transfers
Factory1 may use cloud hosting, email delivery, analytics, monitoring and AI providers as subprocessors.
Where cross-border transfers occur, Factory1 will use reasonable safeguards appropriate to the provider and customer agreement.
Security Controls
Factory1 uses authentication, role-based access, organization-level isolation, password hashing, production TLS and operational security practices.
Customers should configure roles carefully and promptly remove users who no longer need access.