data processing addendum
Effective date: October 1, 2026
Last updated: October 1, 2026
1. About this DPA
1.1 Parties. This Data Processing Addendum ("DPA") is between HELPERG LLC, a Wyoming limited liability company, 30 N Gould St Ste N, Sheridan, WY 82801, USA ("HELPERG", "we", "us" or "our"), and the Customer. It forms part of the faxB2B Terms of Use at https://faxb2b.com/legal/terms (the "Terms"). It applies automatically whenever we process Customer Personal Data, including during a Trial. No separate signature is needed.
1.2 What it does not cover. Our Privacy Policy at https://faxb2b.com/legal/privacy, not this DPA, covers the personal information we process for our own purposes, such as account and billing information.
2. Definitions
Other capitalized terms, such as Customer Content, have the meanings in the Terms.
- "Customer Personal Data" means personal information in Customer Content that we process on the Customer's behalf.
- "Data Protection Law" means every privacy and data protection law that applies to that processing, including the EU General Data Protection Regulation (the "GDPR") where it applies to our processing, the California Consumer Privacy Act and its regulations (the "CCPA") and other US state privacy laws, the Swiss Federal Act on Data Protection (the "FADP") and Canadian privacy laws, among them Quebec's Act respecting the protection of personal information in the private sector (the "Quebec Act").
- "Controller" includes a "business" under the CCPA. "Processor" includes a "service provider" or "contractor" under the CCPA. "Data subject" includes a "consumer".
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorized acquisition or disclosure of or access to, Customer Personal Data that we or our Sub-processors process.
- "Swiss Clauses" has the meaning given in Section 13.4.
- "Sub-processor" means a third party we engage to process Customer Personal Data. Our employees, and individual contractors who work for us under our direct supervision and are bound by written terms at least as protective as this DPA, including confidentiality, are not Sub-processors; we remain responsible for them as for ourselves. Neither are the telephone carriers that carry a fax beyond our carrier, which we do not choose or control.
3. Roles and scope
3.1 Roles. The Customer is the controller of Customer Personal Data, and HELPERG is its processor. If the Customer acts as a processor for another controller, we are its sub-processor. The Customer then confirms that its controller has authorized this processing and our Sub-processors, and it relays that controller's instructions. We take instructions only from the Customer. Annex 1 describes the processing.
3.2 Fax details. The Customer instructs us to use fax details, such as fax numbers, page counts, times and delivery status, to bill Pages, keep the Service secure, prevent fraud and junk faxes, meet legal duties that apply to us, and produce aggregated statistics about how the Service is used and performs that identify no one, which we use to understand and improve the Service (Terms, Section 19.7; Privacy Policy, section 2). These uses are part of the Service, are listed in Annex 1, and this DPA applies to them. We do not try to re-identify anyone from aggregated or de-identified information, and we require any recipient not to try. We make no other use of Customer Personal Data: we do not sell it, use it for advertising, build profiles of individuals from it, or use it to train artificial intelligence models.
4. Instructions
4.1 Documented instructions. We process Customer Personal Data only on the Customer's documented instructions: (a) the Terms, including this DPA; (b) the Customer's use of the Service, including what its Users upload, send, receive, keep, export and delete; and (c) other instructions we agree to in writing.
4.2 Exceptions. If the law requires other processing, we tell the Customer first, unless the law forbids it. If we believe an instruction breaks Data Protection Law, we tell the Customer and may suspend the affected processing until the instruction is confirmed or changed.
4.3 The Customer's responsibilities. The Customer is responsible for having a lawful basis and for the notices and consents Data Protection Law requires, including for fax recipients, fax senders and people named in documents; for lawful instructions and correct fax numbers; and for deciding whether the Service suits any sensitive information it chooses to fax (Terms, Section 10).
5. Confidentiality and access
5.1 Personnel. Everyone we authorize to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality and has only the access their role needs.
5.2 Staff access. Our staff open documents, fax images and cover-sheet text only for the reasons in Section 19.5 of the Terms, using the break-glass procedure in Annex 2. A fax that arrives during quarantine on a Fax Number the Customer released is handled for the Customer as Section 7.5 of the Terms describes.
5.3 Disclosures. We disclose Customer Personal Data to others only: (a) when the law or valid legal process requires it; (b) with the Customer's consent; (c) where the law allows, to a government authority in an emergency involving danger of death or serious physical injury (Terms, Section 12.6); or (d) where the law allows, fax details under Section 3.2, never the content of a fax or document, to the person who complained about a fax, our carriers, our payment processor or authorities, where needed to investigate or stop misuse of the Service (Terms, Section 12.2). Unless the law forbids it or there is an emergency, we tell the Customer before a disclosure under (a). We disclose only what is required, and we keep a record of each request under (a). For transfers covered by the Swiss Clauses, Clause 15 of the Swiss Clauses also applies, including notice to data subjects where it requires it.
6. Security
6.1 Measures. We maintain the technical and organizational measures in Annex 2, which are designed to give a level of security appropriate to the risk. We may update them, but not in a way that reduces the overall protection.
6.2 Limits. Faxes cross the public telephone network, and neither that network nor email is encrypted end to end. We hold no third-party security certification such as SOC 2 or ISO 27001.
7. Sub-processors
7.1 Authorization. The Customer gives us general authorization to engage the Sub-processors listed at https://faxb2b.com/legal/subprocessors when it accepts the Terms, and others added under this Section 7. The list shows each one's purpose, the personal information involved and where it processes it.
7.2 Contracts and responsibility. We bind each Sub-processor by a written contract to data protection obligations at least as protective as this DPA for the processing it carries out on our behalf, as far as they apply to its service (Section 7.6 covers our carrier's own records). We remain responsible to the Customer for each Sub-processor's performance as for our own, subject to Section 15.
7.3 Notice. At least 30 days before a new Sub-processor starts processing Customer Personal Data, we update the list and email the owner of each Organization. Anyone can ask for these notices at info@faxb2b.com.
7.4 Objection. The Customer may object to a new Sub-processor on reasonable data protection grounds by writing to info@faxb2b.com within the notice period. We will discuss alternatives in good faith. If we cannot resolve the objection before the Sub-processor starts processing the Customer's data, the Customer may end the affected Subscription or Trial by written notice, and we will refund prepaid fees for the unused period.
7.5 Urgent replacement. If we must replace a Sub-processor urgently, for example for security reasons or because it stops its service, we give notice as soon as practicable and, where we can, before the replacement starts processing. The Customer may object under Section 7.4 within 30 days after the notice. For Customers covered by the Swiss Clauses or a law that requires an opportunity to object before engagement, we use this Section only as far as those clauses or that law allow, and otherwise follow Section 7.3.
7.6 Carrier records. To transmit faxes and provide Fax Numbers, our carrier, Telnyx, receives fax numbers, times and routing data, and keeps and uses some of these records as an independent controller, under its own privacy policy, to bill, prevent fraud and abuse, and meet telecommunications law. The Customer instructs us to make these disclosures as part of sending and receiving faxes. Section 7.2 applies to Telnyx's other processing on our behalf.
8. Assistance
8.1 Data subject requests. If a data subject asks us about Customer Personal Data, we pass the request to the Customer without undue delay, or tell the person how to reach the Customer, and we do not answer it ourselves unless the law requires. Beyond the Service's own export and deletion features, we give the Customer reasonable help, taking into account the nature of the processing, to respond as Data Protection Law requires.
8.2 Security, assessments and consultations. Taking into account the information available to us, we help the Customer meet its obligations on security, breach notification, impact assessments (including under section 17 of the Quebec Act) and consultations with authorities, usually by providing this DPA, the Sub-processor list, our security page at https://faxb2b.com/security (if that page differs from Annex 2, Annex 2 controls) and answers under Section 11.
8.3 If we can no longer comply. We tell the Customer within five business days if we determine that we can no longer meet our obligations under this DPA or Data Protection Law. The Customer may then, on notice, take reasonable and appropriate steps to stop and remediate unauthorized processing, including instructing us to stop it or to delete the data concerned, and it may end the affected Subscription or Trial by written notice, and we will refund prepaid fees for the unused period.
9. Personal Data Breaches
9.1 Notice. We tell the Customer about a Personal Data Breach without undue delay after we become aware of it, and within any shorter time the law requires, by email to the owner of the Organization and to any privacy contact the Customer has given us in writing.
9.2 Content. The notice gives the information reasonably available to us, including, where known, what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and whom to contact. We add information as we learn more.
9.3 Response. We take reasonable steps to investigate, contain and reduce the effects of the breach, and we cooperate with the Customer's reasonable requests. The Customer decides whether to notify data subjects and authorities, and gives those notices. We give them only if the Customer asks and we agree, or if the law requires. Our notice is not an admission of fault.
10. Deletion and return
10.1 During the Subscription. Users can download the faxes, receipts and lists their role allows, owners and admins can delete received faxes, and the owner can ask for a full export of the Organization (Terms, Section 19.6). Some Customer Content is also deleted automatically on the schedule in section 10 of the Privacy Policy, which Sections 6.4 and 19.6 of the Terms adopt, including any period an owner or admin sets for keeping received faxes. By using the Service, the Customer instructs us to follow that schedule.
10.2 At the end. When a Trial ends without a paid Subscription, or a Subscription ends, Users can still sign in and download Customer Content, and the owner can ask for a full export, until we carry out a deletion of the Organization (Terms, Sections 14.2 and 24.5). That access and export are how we return Customer Personal Data. If they do not cover all Customer Personal Data, or if we do not allow sign-in because of the law, sanctions or a serious breach, we return the data on the owner's written request by another secure means, unless the law or sanctions forbid it. The Customer may instead ask us to delete the data. We carry out a deletion of the Organization only at the owner's request or, after telling the owner by email at least 30 days in advance, when we decide to; the deletion is completed 30 days later (Terms, Section 19.6).
10.3 Backups and what we keep. When we make backups, they are encrypted, we keep each one for no more than 30 days, and we use them only to restore the Service. After deletion, we keep billing and tax records, the history of which Organization held each Fax Number, and the Organization's audit log, which records Users' actions with short details, without a fixed deletion date (Privacy Policy, section 10). Where the Swiss Clauses or the Quebec Act apply, we keep Customer Personal Data only as they allow. We keep protecting what we keep under this DPA and use it only for that purpose. On written request, we certify deletion in writing.
11. Information and audits
11.1 Information. We make available the information reasonably necessary to demonstrate our compliance with this DPA. Once in any 12-month period, and also after a Personal Data Breach affecting the Customer or at a data protection authority's request, we answer in writing, within a reasonable time, a reasonable written questionnaire about our processing of Customer Personal Data.
11.2 Audits. Where Section 11.1 does not reasonably satisfy the Customer's need to verify our compliance, including where the Swiss Clauses, section 42-521 of the Connecticut General Statutes or section 18.3 of the Quebec Act give it a right to audit, assess or verify, we allow and cooperate with a reasonable audit by the Customer or an independent auditor bound by confidentiality who is not our competitor. The audit needs at least 30 days' written notice, with scope and timing agreed in advance, each party acting reasonably. It is remote where that suffices, and on site only where it does not. It happens at most once in any 12-month period, unless an authority requires more, a Personal Data Breach has affected the Customer, or there are reasonable indications that we are not complying with this DPA. It must not give access to other customers' data or weaken the Service's security, and the Customer bears its costs, including our reasonable costs, estimated in advance. Audits of a Sub-processor's facilities follow its own audit terms. Audit results are our confidential information, but the Customer may share them with its advisers, its own controller and any competent authority.
12. US state privacy laws
12.1 Scope. This Section 12 applies where the CCPA, section 42-521 of the Connecticut General Statutes or a similar US state law applies to Customer Personal Data. Under those laws, we are the Customer's service provider, contractor or processor.
12.2 Commitments. For Customer Personal Data:
- (a) the Customer discloses it to us only for the limited and specified business purposes in Annex 1, and we process it only for those purposes or as those laws otherwise permit, such as to detect security incidents, protect against fraud or illegal activity, or comply with the law;
- (b) we do not sell or share it, as the CCPA defines those terms;
- (c) we do not keep, use or disclose it for any other purpose, including another commercial purpose, or outside our direct business relationship with the Customer;
- (d) we do not combine it with personal information from other sources, except as those laws permit;
- (e) we comply with the obligations those laws place on us and provide the level of privacy protection they require;
- (f) the Customer may take reasonable and appropriate steps, including under Section 11, to ensure that we use it consistently with the Customer's obligations under those laws;
- (g) we notify the Customer as Section 8.3 describes if we can no longer meet those obligations, and the Customer may then stop and remediate unauthorized use as that Section allows; and
- (h) the Customer tells us about any data subject request we must comply with and gives us the information we need.
Sections 5, 7, 10 and 11 contain the other terms those laws require.
12.3 Certification. We certify that we understand the restrictions in this Section 12 and will comply with them.
13. International processing and transfers
13.1 Locations. Our servers, database and stored files are hosted in Germany by Hetzner Online GmbH. HELPERG LLC is a US company, and our personnel access Customer Personal Data only from countries of the European Union. Several Sub-processors, including Telnyx, process it in the United States, and the Sub-processor list names each country. A fax sent abroad reaches its destination country through telephone carriers. The Customer authorizes these transfers as needed to provide the Service.
13.2 Government access. As a US company, HELPERG may be required by US law to disclose information it controls, wherever it is stored. Section 5.3 describes how we handle such requests. On request, we give the Customer the information reasonably available to us for its transfer impact assessment.
13.3 The EEA and the United Kingdom. faxB2B is not offered to organizations or Users in the European Economic Area or the United Kingdom (Terms, Section 3.5). This DPA therefore includes no standard contractual clauses for transfers from the European Economic Area and no UK International Data Transfer Addendum. We will add the transfer terms the law requires before we offer the Service there.
13.4 Switzerland. Where the FADP applies to the Customer's disclosure of Customer Personal Data to us, the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914, adapted as follows (the "Swiss Clauses"), are incorporated into this DPA by reference. Module 2 applies where the Customer is a controller, and Module 3 where it is a processor. The Customer is the data exporter, and HELPERG is the data importer.
- (a) References to Regulation (EU) 2016/679 mean the FADP, and the competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
- (b) "Member State" in Clause 18(c) does not prevent data subjects in Switzerland from suing where they habitually reside.
- (c) Clause 7 and the optional wording in Clause 11(a) do not apply.
- (d) Option 2 of Clause 9(a) applies, with the notice period in Section 7.3.
- (e) Swiss law governs (Clause 17), and the courts of Switzerland have jurisdiction (Clause 18(b)).
- (f) Annex 1 of this DPA is Annex I, Annex 2 is Annex II, and the Sub-processor list is Annex III.
Accepting the Terms counts as signing the Swiss Clauses.
13.5 Canada and Quebec. For Customers subject to Canadian privacy law, this DPA is the contract through which we provide a comparable level of protection. Under the Quebec Act, it is also the written agreement for communicating personal information outside Quebec and to a service provider (sections 17 and 18.3). We protect the information with the measures in Annex 2, use it only to perform the Terms, and keep it afterwards only as Section 10 allows. We tell the Customer's person in charge of the protection of personal information without delay of any violation or attempted violation of a confidentiality obligation we become aware of, and let that person verify confidentiality requirements under Section 11. If the Customer's privacy impact assessment identifies risks, the Customer may send us the measures it needs. Measures we agree to in writing become part of this DPA. If we cannot agree them within 30 days, the Customer may end the affected Subscription by written notice, and we will refund prepaid fees for the unused period.
13.6 Other countries. If the Customer's law requires standard clauses or other transfer terms that this DPA does not include, the Customer may ask for them at info@faxb2b.com, and we will work with it in good faith to agree them in writing.
14. Health information
This DPA is not a business associate agreement under the US Health Insurance Portability and Accountability Act (HIPAA). The Customer must not use the Service for protected health information unless both parties have signed such an agreement, which we do not currently offer (Terms, Section 10.1).
15. Liability
Each party's liability arising out of or relating to this DPA is subject to the exclusions and limits in Section 26 of the Terms ("Limitation of liability") and counts toward the same cap, except that nothing in this DPA or the Terms limits or excludes (a) either party's liability under Clause 12 of the Swiss Clauses, or (b) liability to data subjects.
16. General
16.1 Order of precedence. For Customer Personal Data, this DPA prevails over the rest of the Terms, subject to Section 15. The Swiss Clauses prevail over both for the transfers they cover. A business associate agreement signed by both parties prevails for protected health information.
16.2 Duration and changes. This DPA applies for as long as we process Customer Personal Data, including after the Terms end. We change it as Section 30.1 of the Terms allows changes to the Terms, with at least 30 days' notice of material changes. We will not change it to reduce the protection of Customer Personal Data unless the law, a regulator or a court requires it.
16.3 Law and disputes. Section 29 of the Terms (governing law and disputes) applies to this DPA, except where the Swiss Clauses require otherwise.
16.4 Contact. Write to our Privacy Officer at info@faxb2b.com, or by mail to the address in Section 1.1.
16.5 Language. This DPA and the Sub-processor list are written in English. A French version of this DPA is available at https://faxb2b.com/legal/fr/dpa. If a translation differs from the English version, the English version controls, to the extent the law allows.
Annex 1: Details of the processing
| Item | Details |
|---|---|
| Parties | Data exporter: the Customer (controller, or processor for another controller), with the details in its account. Data importer: HELPERG LLC (processor, or sub-processor), at the address in Section 1.1; contact: Privacy Officer, info@faxb2b.com |
| Subject matter and duration | Our provision of the Service under the Terms, for their term and afterwards until deletion under Section 10 |
| Frequency of transfer | Continuous, for as long as the Customer uses the Service |
| Nature of the processing | Storage, encryption, malware scanning, conversion, display and editing of files; sending and receiving faxes through our carrier; export; deletion; staff access under Section 5.2 |
| Business purposes | Providing the Service described in the Terms: sending and receiving faxes, Fax Numbers, storage of documents, faxes, cover sheets, contacts, notes and receipts, the team inbox and document tools; support the Customer or its Users ask for; the uses in Section 3.2: billing Pages, security, fraud and junk-fax prevention, legal duties that apply to us, and aggregated statistics that identify no one |
| Data subjects | Users; recipients and senders of faxes, and their staff; people named or shown in documents, faxes and cover sheets; people in the Customer's contacts |
| Personal information | Whatever the Customer includes in documents and faxes, such as names, contact details, signatures and identification numbers; fax numbers of recipients and senders and the receiving Fax Number; dates, times, page counts, status and delivery timeline; receipts; cover-sheet text; contacts; inbox notes, assignments and statuses; names or email addresses of Users who acted on an item |
| Special categories and sensitive information | The Service is not designed for them, but they may occur because the Customer chooses what to fax, for example health, government identification, financial account or criminal-matter information. Safeguards: the measures in Annex 2; the Terms' limits on protected health information and Restricted Data (Terms, Section 10) |
| Retention | Section 10 of this DPA and section 10 of the Privacy Policy |
| Sub-processors | As listed at https://faxb2b.com/legal/subprocessors |
| Supervisory authority (Swiss Clauses only) | FDPIC |
| Signature and date | The Customer's acceptance of the Terms, which include this DPA, on the date it accepts them (Terms, Section 1.3) |
Annex 2: Security measures
These measures describe how the Service is built. No third party has certified them.
- Sign-in. Passwordless sign-in with one-time email codes, stored only in hashed form, valid for 10 minutes, with limited attempts and rate limits by IP address. Two-factor authentication with an authenticator app (TOTP) is mandatory for every User before a workspace opens; secrets are stored encrypted and codes cannot be reused. Sensitive actions, such as changing roles, asking to delete an account and downloading an export, need a fresh two-factor check.
- Sessions and roles. Only a hash of each session identifier is stored. Sessions end after 120 minutes without activity and at most 12 hours after sign-in, and Users can sign out of any one or all of their devices. Owner, admin and member roles limit what each User can do.
- Encryption. TLS (HTTPS) with HSTS. Stored documents and fax files are encrypted at rest with AES-256-GCM, under a separate key derived for each Organization. Authenticator secrets are also stored encrypted, and when we make backups, they are encrypted. Other database content is protected by the access controls in this Annex.
- Isolation. Row-level security is enforced on every table holding an Organization's data, and the application's database role cannot bypass it. Database permissions follow least privilege, and audit logs and the Pages ledger are append-only.
- Files. Uploads are quarantined, checked for their real file type and scanned for malware on our own servers, and received faxes are scanned too. Scanning fails closed: if the scanner is unavailable, no file is converted, shown or sent unscanned; an upload is held until the User tries again, and a received fax is kept encrypted and scanned when the scanner is back. Conversion runs in an isolated sandbox with no network access and no access to secrets or stored files; if the sandbox is not available, files are not converted. Received fax files are downloaded only over HTTPS from our carrier's approved hosts.
- Providers and the application. Our carrier fetches outgoing fax files through signed, temporary links, and we verify the signatures on messages from our carrier and payment processor. The application uses cross-site request forgery protection, a strict Content Security Policy and rate limits, including an hourly limit on faxes per Organization. Production servers refuse to start with a configuration that turns off HTTPS, the malware scanner or the sandbox.
- Staff access. Staff use a separate staff console with mandatory two-factor authentication and a 30-minute inactivity timeout. Every staff action is recorded in a staff audit log kept for 730 days. Support staff see metadata only. Staff can open documents, fax images and cover-sheet text only through temporary break-glass access, which only operations staff and a few senior staff can open, after a fresh two-factor check and with a recorded reason. It lasts 30 minutes, works only for the staff member who opened it, and every document opened is logged. Each opening is shown in the Organization's audit log, and the owner is notified by email and in the Service unless the owner has turned these notices off. Staff prepare exports the Customer asks for, and deliver faxes that arrive during a number's quarantine, without opening their content.
- Logging and incidents. Each Organization's audit log records sign-ins, role changes and other sensitive actions for its owners and admins. Application logs are designed to leave out sign-in codes, tokens, phone and fax numbers, email addresses and links to documents. Automated alerts tell our operations staff about problems such as a high share of failed faxes or a stopped scanner, and a possible duplicate send is held for manual review.
