Last updated: 10 July 2026

Data Processing Agreement

How Factory1 processes customer business data for organizations that use the platform.

Roles

For customer business data, the customer is the Data Controller and Factory1 acts as the Data Processor.

The customer decides what data is entered into Factory1 and who inside the organization may access it.

Processing Instructions

Factory1 processes data only to provide, secure, maintain, support and improve the Factory1 service.

Factory1 may process data for AI assistance, reporting, import/export, notifications, support, backups and security monitoring.

GDPR Readiness

Factory1 is being designed with GDPR-friendly practices such as access control, data export, deletion workflows and processor accountability.

If an EU customer requires a signed DPA, Factory1 can provide a commercial DPA during onboarding.

Subprocessors And Transfers

Factory1 may use cloud hosting, email delivery, analytics, monitoring and AI providers as subprocessors.

Where cross-border transfers occur, Factory1 will use reasonable safeguards appropriate to the provider and customer agreement.

Security Controls

Factory1 uses authentication, role-based access, organization-level isolation, password hashing, production TLS and operational security practices.

Customers should configure roles carefully and promptly remove users who no longer need access.

These pages are written for transparency and onboarding. Commercial agreements, signed DPAs or enterprise contracts may override public policy text where expressly agreed in writing.