Data Processing Addendum
SKRIB, INC.
Data Processing Addendum
Effective Date: 26 May 2026
This Data Processing Addendum (this “DPA”) forms part of the agreement between Skrib, Inc. (“Processor” or “Skrib”) and the customer identified in the Order or applicable agreement (“Controller” or “Customer”) for Customer’s use of the Skrib platform and related services (the “Services”), as further described in the Skrib Terms of Service or in any separate written agreement between the parties governing the Services (together with this DPA, the “Agreement”). This DPA is incorporated into the Agreement by reference.
This DPA applies to Skrib’s processing of Personal Data on Customer’s behalf and where the processing is subject to applicable Data Protection Laws. Where Customer is a natural person using the Services solely as a consumer, this DPA does not apply; the Skrib Privacy Policy at https://skrib.com/legal/privacy governs.
1. Processing of Personal Data
1.1 Description.
Details about the processing — categories of Data Subjects and Personal Data, nature, purpose, and duration — are set out in Schedule 1.
1.2 Skrib’s role.
As a Processor, Skrib will process Personal Data contained in Customer Content only (i) in accordance with documented Customer Instructions, or (ii) where required by Applicable Law (in which case Skrib will inform Customer before processing, unless that law prohibits notice on important grounds of public interest).
1.3 Compliance with law.
Skrib and Customer will each comply with Data Protection Law. Customer is responsible for ensuring its Instructions comply with Data Protection Law. Skrib will notify Customer if it determines that an instruction infringes Data Protection Law.
1.4 Confidentiality.
Skrib will ensure that persons authorised to process Customer Content are subject to written confidentiality obligations or a statutory duty of confidentiality.
2. Security
2.1 Security measures.
Skrib has implemented and will maintain appropriate technical and organisational measures designed to protect the security, confidentiality, integrity, and availability of Customer Content, as set out in Annex II.
2.2 Security incidents.
Skrib will notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Content (a “Security Incident”). Skrib will use commercially reasonable efforts to investigate and identify the root cause and to mitigate and remediate the effects.
3. Sub-processors
3.1 General authorisation.
Customer generally authorises Skrib to engage third-party service providers (each, a “Sub-processor”) to process Customer Content. Customer further agrees that Skrib may engage its affiliates as Sub-processors.
3.2 Written agreements.
Skrib will enter into written agreements with each Sub-processor that impose data-protection obligations consistent with this DPA, and will remain liable to Customer where a Sub-processor fails to fulfil its data-protection obligations.
3.3 Sub-processor list.
Skrib maintains an up-to-date list of Sub-processors at https://skrib.com/legal/subprocessors which contains details about Sub-processor functions, the location of processing, and a mechanism for Customers to subscribe to notification of new Sub-processors or replacement of existing Sub-processors.
3.4 Notification of changes.
At least thirty (30) days before a new Sub-processor begins processing Customer Content, Skrib will add the Sub-processor to its list and (if Customer has subscribed) provide Customer with written notice.
3.5 Objections.
Customer may object during the notice period on reasonable data-protection grounds. The parties will discuss alternatives in good faith. If no resolution is reached, Skrib may proceed with the appointment and Customer, as its sole remedy, may terminate the affected Order with refund of pre-paid unused fees.
4. Assistance and cooperation
4.1 Data Subject rights.
Skrib will provide reasonable and timely assistance to enable Customer to respond to Data Subject requests, where Customer cannot reasonably fulfil such requests independently using the self-service functionality of the Platform.
4.2 Impact assessments and consultations.
Skrib will provide reasonable assistance in connection with any data-protection impact assessment or regulatory consultation that may be required under Data Protection Law.
4.3 Government and other third-party requests.
If Skrib receives a request from a third party (including a legally binding governmental request) for disclosure of Personal Data in Customer Content, Skrib will (i) promptly notify Customer unless legally prohibited; (ii) where permitted, refer the requesting party to Customer; (iii) use reasonable efforts to challenge any request that is unlawful, disproportionate, or overbroad; and (iv) not disclose Personal Data unless required to do so by law.
5. Deletion and return of Customer Personal Data
At the end of the Services, Skrib will, as directed by Customer (exercised within thirty (30) days of termination), delete or return all Customer Content within thirty (30) days. Skrib may retain Customer Content only to the extent required by Data Protection Law, subject to the confidentiality and processing restrictions in this DPA. Backup and disaster-recovery copies are deleted in the ordinary course in accordance with Skrib’s backup retention schedule (typically within ninety (90) days).
6. Audit
6.1 Audit reports.
Skrib uses independent third-party auditors to verify the adequacy of its technical and organisational measures. Audits are performed at least once per calendar year at Skrib’s expense. On Customer’s written request at reasonable intervals and subject to confidentiality, Skrib will make available the executive summary of its then-current third-party certifications and audit reports (such as SOC 2 Type II / ISO 27001) so Customer can verify Skrib’s compliance.
6.2 Audit right.
Only to the extent Customer’s audit requirements under Data Protection Law cannot reasonably be satisfied through Section 6.1, Customer (or its appointed representative) may, at Customer’s expense, conduct an audit. Any audit must be subject to confidentiality, conducted during business hours, with at least forty-five (45) days’ advance written notice, limited to once per year (unless required by a regulator), and carried out in a manner that prevents unnecessary disruption to Skrib’s operations or compromise of other customers’ data.
7. Region-specific terms
Where Customer instructs Skrib to process Customer Content originating in a region listed in Schedule 2, the applicable regional terms apply, including those governing international transfers.
8. Order of precedence
In the event of conflict among the following documents, the order of precedence (highest to lowest) is: (1) the applicable terms in Schedule 2 (Region-Specific Terms), including any transfer provisions; (2) the main body of this DPA; and (3) the Agreement.
9. Definitions
“Controller” (also referred to as “Business” under applicable law) means the entity which determines the purposes and means of the processing of Personal Data.
“Customer Content” means materials that are developed by Customer or its Authorized Users on the Skrib platform or uploaded to the Skrib platform by Customer or its Authorized Users.
“Customer Instructions” mean (i) processing to provide the Services and perform Skrib’s obligations under the Agreement (including this DPA); (ii) investigating Security Incidents; and (iii) other reasonable documented instructions consistent with the Agreement. The parties agree that the Agreement and Customer’s use of the features and functionality within the Skrib platform are Customer’s complete and final instructions to Skrib in relation to the processing of Personal Data contained in Customer Content.
“Data Protection Law” means laws and regulations applicable to a party’s respective processing of Personal Data under this DPA, including (as applicable) the GDPR, the UK GDPR, the Georgian DPP Law, the CCPA / CPRA, and other comparable laws.
“Personal Data” means information about an identified or identifiable natural person, or which otherwise constitutes “personal information,” “personally identifiable information,” or similar terms defined under applicable Data Protection Law.
“Processor” (also referred to as “Service Provider”) means the entity which processes Personal Data on behalf of the Controller.
“Security Incident” has the meaning set out in Section 2.2.
Schedule 1 — Description of Processing
Subject matter — Description: Provision of the Skrib platform — an AI-integrated writing studio offering document drafting, editing, collaboration, file storage, and optional AI-assisted features — to Customer and its Authorized Users..
Duration — Description: The term of the Agreement, plus any additional period during which Skrib is required to retain Customer Personal Data under Applicable Law (including up to ninety (90) days for backup and disaster-recovery copies)..
Nature — Description: Hosting, storage, retrieval, organisation, display, transmission, sharing, collaboration, AI processing (where activated), backup, security monitoring, support, and deletion of Customer Personal Data..
Purpose — Description: Providing, operating, securing, and supporting the Services and enabling Customer’s use of features Customer chooses to activate..
Type of Personal Data — Description: Account and profile information; Customer Content (documents, files, prompts, AI inputs and outputs, comments, workspace metadata); usage and technical telemetry; support communications. Special Categories: Skrib does not solicit Special Categories..
Data Subjects — Description: Customer’s Authorized Users; third parties identified in Customer Content..
Frequency of transfer — Description: Continuous, for the duration of the Services..
Schedule 2 — Region-Specific Terms
Capitalised terms used in this Schedule 2 have the meanings given to them in applicable Data Protection Law.
1. Brazil
Where Customer Content originates in Brazil, the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, “LGPD”) applies. The Brazilian Standard Contractual Clauses apply to Personal Data in Customer Content that is transferred from Brazil to any country or recipient outside Brazil that is not recognised by the Autoridade Nacional de Proteção de Dados (ANPD) as providing an adequate level of protection. The clauses are incorporated into this DPA by reference; the description of the international data transfer is set out in Schedule 1; the security measures are set out in Annex II; the list of Sub-processors is at https://skrib.com/legal/subprocessors.
2. European Economic Area
The EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the EU e-Privacy Directive apply. The European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914 of 4 June 2021, the “EU SCCs”) apply to Personal Data in Customer Content that is transferred from the EEA (including Iceland, Liechtenstein, and Norway) to a country or recipient that is not recognised by the relevant competent authority as providing an adequate level of protection. The EU SCCs are incorporated into this DPA by reference and completed as follows:
Module 2 (Controller to Processor) applies where Customer is a Controller and Skrib is a Processor.
Module 3 (Processor to Processor) applies where Customer is a Processor and Skrib is a Sub-processor.
Clause 7 (Docking clause): does not apply.
Clause 9: Option 2 applies; the time period for prior notice of Sub-processor changes is set out in Section 3.
Clause 11: optional language does not apply.
Clause 17: Option 1 applies; governing law is the law of Ireland.
Clause 18(b): the courts of Ireland have jurisdiction.
Annex I.A (List of parties): set out in Annex I to this Schedule 2.
Annex I.B (Description of transfer): set out in Schedule 1.
Annex I.C (Competent supervisory authority): the Irish Data Protection Commission, except where Customer is established in another EEA member state and the local supervisory authority of Customer’s establishment is competent.
Annex II (Technical and organisational measures): set out in Annex II to this Schedule 2.
Annex III (List of Sub-processors): https://skrib.com/legal/subprocessors.
3. Switzerland
The revised Swiss Federal Act on Data Protection (FADP) applies. The EU SCCs apply to Personal Data in Customer Content that is transferred from Switzerland to a country that is not recognised as providing an adequate level of protection, with the following modifications: references to Regulation (EU) 2016/679 are interpreted as references to Swiss Data Protection Law (and references to specific Articles of the GDPR are replaced with the equivalent sections of Swiss Data Protection Law); references to “EU,” “Union,” “Member State,” or similar terms are interpreted to include Switzerland; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); the laws of Switzerland are the governing law; and the courts of Switzerland have jurisdiction. Data Subjects in Switzerland are not excluded from enforcing their rights in their place of habitual residence in accordance with Clause 18(c).
4. United Kingdom
The UK Data Protection Act 2018 and the UK GDPR apply. The UK International Data Transfer Addendum to the EU SCCs (the “UK Addendum”) applies to Personal Data transferred from the United Kingdom. The UK Addendum is incorporated into this DPA by reference and completed as follows: Table 1 (Parties) is set out in Annex I; Table 2 (Selected SCCs) corresponds to the EEA section above; Table 3 (Appendix Information) is completed using Annexes I and II to this Schedule 2 and Schedule 1; Table 4 (Ending the IDTA) — either party may end the IDTA in the circumstances set out in Section 19 of the UK Addendum.
5. United States
Where Personal Data in Customer Content is subject to applicable U.S. state privacy laws (CCPA / CPRA, Virginia CDPA, Colorado CPA, Connecticut DPA, Utah UCPA, Texas DPDSA, Oregon CPA, Montana CDPA, Iowa, Indiana, Tennessee, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, and similar successor laws) (“U.S. State Privacy Laws”) and Skrib acts as a Service Provider or Processor on behalf of Customer, Skrib will process such Personal Data in compliance with applicable U.S. State Privacy Laws and only on Customer Instructions for the limited and specified purposes set out in this DPA. Skrib will not (a) retain, use, disclose, or process such Personal Data for any commercial purpose other than the limited purposes contemplated by this DPA or as otherwise permitted under U.S. State Privacy Laws; (b) “sell” or “share” such Personal Data; (c) retain, use, disclose, or process such Personal Data outside of the direct business relationship with Customer; or (d) combine such Personal Data with Personal Data obtained from other sources except as permitted by U.S. State Privacy Laws.
Skrib will notify Customer if it determines that it can no longer meet its obligations under U.S. State Privacy Laws. Customer may take reasonable and appropriate steps to stop and remediate any unauthorised processing.
6. Georgia
Where Customer Content originates in Georgia, the Law of Georgia on Personal Data Protection No. 3144/2023 (the “Georgian DPP Law”) applies. For Restricted Transfers from Georgia, Skrib relies on the lawful transfer grounds permitted under Articles 36–39 of the Georgian DPP Law, including (as applicable) appropriate contractual safeguards or, where required, prior authorisation from the Personal Data Protection Service of Georgia.
Annex I — List of Parties
Data exporter (Controller).
Customer, as identified in the Agreement. Address: as set out in the Agreement. Contact details: as set out in the Agreement. Activities relevant to the data transferred: processing of Customer Content for the purpose of the Agreement. Role: Controller (or, where applicable, Processor for an underlying controller). Signature and date: see signature (or electronic acceptance) and date of execution of the Agreement.
Data importer (Processor).
Skrib, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Operational address: 37m I. Chavchavadze Avenue, Axis Business Centre, 0179 Tbilisi, Georgia. Contact: contact@skrib.com. Activities relevant to the data transferred: processing of Customer Personal Data for the purpose of the Agreement. Role: Processor.
Annex II — Technical and Organisational Measures
Skrib implements and maintains the following technical and organisational measures (the “TOMs”) for the security of Customer Personal Data, as required by Article 32 of the GDPR and analogous Data Protection Laws. The TOMs are reviewed and updated periodically; Skrib may make changes that maintain or improve the level of security. The longer-form security programme — used by Skrib’s enterprise customers — is set out in Exhibit B to the Software Services Agreement.
Encryption and pseudonymisation — Description: TLS 1.2+ in transit. AES-256 (or equivalent) at rest for primary storage and backups. Cryptographic keys managed in dedicated KMS with role-based access..
Confidentiality, integrity, availability and resilience — Description: Network segmentation, web-application firewalls, DDoS mitigation. Multi-AZ deployment. Annual third-party security assessments..
Restoration — Description: Daily encrypted backups retained ≥30 days. Documented disaster-recovery plan, tested at least annually..
Testing and validation — Description: Continuous vulnerability scanning. Annual penetration test by qualified independent third party. Vulnerability disclosure programme..
Identification and authorisation — Description: Customer-managed authentication via Skrib’s authentication provider. SSO/SAML for enterprise. MFA required for administrative access..
Access controls — Description: Role-based access with least-privilege defaults. Just-in-time access workflow with audit logging for production access..
Data minimisation, retention — Description: Customer-controlled retention. Documented retention schedule at https://skrib.com/trust/retention..
Incident management — Description: Documented incident response. Personal Data Breach notification within 72 hours of confirmation..
Sub-processor governance — Description: Vendor risk-management process. Public list at https://skrib.com/legal/subprocessors with subscription form for change notifications.