Applies where we process personal data on your behalf.
Last updated: September 1, 2026
This Addendum forms part of the Terms of Service between you and IT-Harvest, LLC and applies where we process personal data on your behalf in providing the Service. Where it conflicts with the Terms on the subject of personal data, this Addendum wins.
Where we are your processor. For the personal data in your account — the people you invite, the content they create, and their use of the Service — you are the controller and we are the processor. We process that data only on your documented instructions, which are these documents and your use of the Service, unless the law requires otherwise; if it does, we will tell you before processing unless the law forbids us to.
Where we are a controller. We are a controller in our own right for the business-intelligence content of the Service — information about companies, their products, and the people who work at them — and for our own account, billing and security records. That processing is described in the Privacy Policy and is not covered by this Addendum.
You are responsible for the lawfulness of the personal data you put into the Service and of the instructions you give us, including having a basis to provide the data to us and to let the people in your organization use the Service.
We keep personal data processed under this Addendum confidential, and we limit access to people who need it to perform their role and who are bound by confidentiality obligations.
We maintain technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature and scope of the processing. In general terms, those measures cover: encryption of data in transit; access control and authentication, with access limited to what a role requires; separation of customer data; secure handling of credentials; logging of system activity; resilience and backup of data; and review of the measures over time.
We describe them at this level deliberately. A published inventory of individual controls is a map as much as an assurance. Our security overview covers our approach; we do not hold a security certification and do not claim one.
You authorise us to engage subprocessors to help provide the Service. Each is engaged under a written contract imposing data-protection obligations no less protective than these, and we remain responsible for their performance.
The current list is published at Subprocessors and is updated before a new subprocessor begins processing customer personal data. If you ask us in writing to notify you of changes, we will email you at the address you give us. If you object to a new subprocessor on reasonable data-protection grounds, tell us; if we cannot resolve it, you may terminate the affected part of the Service.
You can see and change most of the personal data in your account through the Service itself. Where a person exercises a right under applicable data protection law in relation to data we process for you, and you need something we hold, we will provide reasonable assistance so that you can respond within the time the law allows. If a request reaches us directly, we will not respond to it ourselves except to acknowledge it and direct the person to you, unless the law requires otherwise.
We will also give you reasonable assistance with data protection impact assessments and prior consultations, to the extent they concern our processing and you cannot reasonably do it yourself.
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification will describe what we know at the time, and we will provide further information as it becomes available so that you can meet your own obligations.
Notifying you is not an acknowledgement of fault.
On reasonable written request, and no more than once a year unless a regulator requires otherwise or there has been a breach affecting your data, we will make available the information reasonably necessary to demonstrate compliance with this Addendum. Where you need more than that, we will discuss a proportionate way to satisfy it, at your cost, and subject to confidentiality.
We process personal data in the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties will put in place the transfer mechanism required by applicable law, and the European Commission Standard Contractual Clauses (with the UK Addendum or the Swiss equivalent where relevant) apply where they are the appropriate mechanism. If you need them executed, write to us.
While your subscription is running you can ask us to export or delete the personal data in your account; those requests are handled by hand, as the Privacy Policy describes. On termination, and on your written request made within a reasonable period afterwards, we will return or delete the personal data we process on your behalf. Otherwise we delete it in the ordinary course. We may retain data where the law requires us to, and anything retained stays subject to this Addendum for as long as we hold it.
This Addendum applies for as long as we process personal data on your behalf.
The subject matter is the provision of the Service. Processing lasts for the term of your subscription and for as long afterwards as is needed to return or delete the data.
Hosting, storing, transmitting and displaying customer content; authenticating users and managing accounts, organizations, agencies and seats; providing search, comparison, stack management, framework mapping and AI-assisted answers; billing and support; and securing the Service and preventing abuse.
Identification and contact data (name, business email address, profile image); account and authentication data; subscription, seat and billing metadata; content created in the Service and the identity of who created it; support and communication content; queries submitted to AI features and the answers returned; and usage and technical data, including network and device metadata.
Your personnel and other people you authorise to use the Service, including account owners, organization and agency members, invitees, and anyone who contacts us on your behalf.
The Service is not designed for special categories of personal data, and you should not put them into it.
Requests under this Addendum, including requests for signed Standard Contractual Clauses, go to team@cyberexchange.ai.
For any question about these documents — including a privacy request, a security report, a copyright or accuracy complaint, or a billing dispute — write to us. One address reaches us for all of it.
IT-Harvest, LLC
Email: team@cyberexchange.ai
Website: it-harvest.com
Notices: 850 New Burton Rd., Suite 201, Dover, Delaware 19904, Kent County