Data Processing Agreement
Effective Date: 5/1/2026
Last Updated: 7/11/2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service or other agreement between FGPR, Inc. ("FGPR," "we," "us," or "our") and the customer identified in the applicable Order Form or account registration ("Customer," "you," or "your") governing your use of FGPR's digital signage software, media player management tools, and related services (the "Agreement" and the "Services").
This DPA applies to the extent FGPR Processes Personal Data on your behalf in connection with the Services and such Processing is subject to Data Protection Laws.
1. Definitions
"CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
"Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," and "Processing" (and its cognates) have the meanings given in the GDPR; where the CCPA applies, "Controller" includes "Business," "Processor" includes "Service Provider," "Data Subject" includes "Consumer," and "Personal Data" includes "Personal Information."
"Customer Personal Data" means Personal Data contained in Customer Content or otherwise Processed by FGPR on your behalf in connection with the Services, as further described in Annex I. Customer Personal Data does not include Account Data or Telemetry Data (defined in Section 3.3).
"Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including as applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into United Kingdom law ("UK GDPR") and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); the CCPA; and other applicable U.S. state privacy laws.
"EU SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
"Subprocessor" means a third party engaged by FGPR to Process Customer Personal Data on your behalf.
"UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office.
2. Roles of the Parties
2.1 Customer as Controller; FGPR as Processor. With respect to Customer Personal Data, you are the Controller (or, where you act on behalf of a third-party Controller, a Processor) and FGPR is your Processor (or Subprocessor). Each party will comply with its respective obligations under Data Protection Laws.
2.2 Customer Instructions. FGPR will Process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law to which FGPR is subject (in which case FGPR will inform you of that legal requirement before Processing, unless the law prohibits such disclosure on important grounds of public interest). Your instructions consist of: (a) the Agreement and this DPA; (b) your configuration and use of the Services (including content scheduling, display targeting, and account settings); and (c) other written instructions agreed by the parties. FGPR will promptly inform you if, in its opinion, an instruction infringes Data Protection Laws.
2.3 Customer Responsibilities. You are responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which you acquired it; (b) providing all notices and obtaining all consents and rights required under Data Protection Laws for FGPR to Process Customer Personal Data as contemplated by the Agreement; and (c) ensuring your instructions comply with Data Protection Laws. You will not upload or display Personal Data through the Services beyond what is described in Annex I without prior written agreement — in particular, no special categories of data (GDPR Article 9), biometric data, or data relating to children, unless the parties have agreed additional safeguards in writing.
3. Scope and Details of Processing
3.1 Details. The subject matter, duration, nature and purpose of Processing, categories of Data Subjects, and types of Personal Data are described in Annex I.
3.2 Purpose Limitation. FGPR will Process Customer Personal Data only as necessary to provide the Services under the Agreement and as permitted by this DPA, and not for any other purpose.
3.3 Account Data and Telemetry Data. For clarity, this DPA does not apply to: (a) "Account Data" — Personal Data relating to your personnel collected by FGPR for account management, billing, and support (e.g., names, business contact details, credentials); and (b) "Telemetry Data" — device and diagnostic data described in the Privacy Policy. FGPR Processes Account Data and Telemetry Data as an independent Controller in accordance with its Privacy Policy at https://www.fgr.cx/privacy.
4. Confidentiality
FGPR will ensure that persons authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and Process Customer Personal Data only as needed to perform their roles.
5. Security
5.1 Technical and Organizational Measures. Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects, FGPR will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, including at minimum the measures described in Annex II.
5.2 Updates. FGPR may update the Annex II measures from time to time, provided the updates do not materially reduce the overall level of protection.
6. Subprocessors
6.1 General Authorization. You provide general written authorization for FGPR to engage Subprocessors to Process Customer Personal Data. FGPR's current Subprocessors are listed in Annex III and at https://www.fgr.cx/subprocessors.
6.2 Notice of Changes; Objection. FGPR will provide notice (via the subprocessor page, email, or the administrative console) at least [30] days before authorizing a new Subprocessor. You may object on reasonable data protection grounds within [15] days of notice. The parties will work in good faith to resolve the objection (e.g., by configuration changes avoiding the Subprocessor). If no resolution is reached within [30] days, you may terminate the affected subscription upon written notice and receive a pro-rata refund of prepaid fees for the remainder of the term, as your sole remedy.
6.3 Flow-Down; Liability. FGPR will impose on each Subprocessor, by written contract, data protection obligations materially no less protective than those in this DPA, and FGPR remains liable for its Subprocessors' performance to the same extent it would be liable if performing the Processing itself.
7. Data Subject Requests: Taking into account the nature of the Processing, FGPR will assist you, through appropriate technical and organizational measures (including the export, editing, and deletion functions of the Services), in fulfilling your obligations to respond to Data Subject requests to exercise their rights under Data Protection Laws. If FGPR receives a request from a Data Subject relating to Customer Personal Data, it will promptly forward the request to you (to the extent legally permitted) and will not respond except to acknowledge receipt and direct the Data Subject to you, unless legally required.
8. Personal Data Breach: FGPR will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent known: the nature of the breach; the categories and approximate number of affected Data Subjects and records; likely consequences; and measures taken or proposed to address the breach and mitigate its effects. FGPR will provide timely updates as information becomes available and will reasonably cooperate with your investigation and any legally required notifications. FGPR's notification of a breach is not an acknowledgment of fault or liability.
9. Assistance: Taking into account the nature of the Processing and information available to FGPR, FGPR will provide reasonable assistance with your obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities), at your expense where the assistance exceeds the standard features of the Services.
10. Audits and Compliance Information
10.1 Information. FGPR will make available to you information reasonably necessary to demonstrate compliance with this DPA, including, upon written request, copies of FGPR's then-current third-party audit reports or certifications [e.g., SOC 2 Type II], subject to confidentiality obligations.
10.2 Audits. To the extent the reports and information under Section 10.1 are insufficient to demonstrate compliance as required by Data Protection Laws, you (or an independent auditor on your behalf that is not a competitor of FGPR) may audit FGPR's compliance with this DPA, no more than once per 12-month period (except following a Personal Data Breach or where required by a supervisory authority), upon at least [30] days' written notice, during business hours, in a manner that minimizes disruption, and subject to reasonable confidentiality and security requirements. Each party bears its own audit costs.
10.3 SCC Audits. Nothing in this Section limits audit rights mandated by the EU SCCs, which apply as set out therein.
11. International Data Transfers
11.1 Hosting. The Services are hosted in [the United States]. You acknowledge that Customer Personal Data will be transferred to and Processed in the United States and other locations where FGPR or its Subprocessors operate, as identified in Annex III.
11.2 Transfer Mechanisms. Where Customer Personal Data protected by the GDPR, UK GDPR, or FADP is transferred to a country not recognized as providing an adequate level of protection, the parties agree that the transfer is governed by the following, which are incorporated by reference:
-
EU transfers: the EU SCCs, Module Two (Controller to Processor) — or Module Three (Processor to Processor) where you act as a Processor — completed as follows: Clause 7 (docking) is included; Clause 9(a) Option 2 (general authorization) applies with the notice period in Section 6.2; Clause 11(a) optional language is not included; Clause 17: the law of [Ireland]; Clause 18: the courts of [Ireland]; Annexes I, II, and III of the EU SCCs are completed with the contents of Annexes I, II, and III of this DPA.
-
UK transfers: the UK Addendum, with Tables 1–3 completed by the corresponding details in this DPA and the EU SCCs as completed above, and Table 4 permitting either party to end the Addendum as set out in Section 19 of the Addendum.
-
Swiss transfers: the EU SCCs as completed above, adapted as required by the FADP (references to the GDPR are to the FADP; the competent supervisory authority is the Swiss FDPIC; "Member State" includes Switzerland for the purpose of Data Subjects' rights).
11.3 Government Requests. If FGPR receives a legally binding request from a public authority for access to Customer Personal Data, it will (unless legally prohibited) promptly notify you, direct the authority to you where possible, and disclose only the minimum data required.
12. CCPA / U.S. State Privacy Law Terms
To the extent Customer Personal Data includes Personal Information subject to the CCPA or similar U.S. state privacy laws, FGPR acts as your Service Provider (or processor) and:
(a) will not sell or share Customer Personal Data (as "sell" and "share" are defined in the CCPA); (b) will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted by the CCPA, including not retaining, using, or disclosing it outside the direct business relationship between the parties; (c) will not combine Customer Personal Data with Personal Information received from other sources, except as permitted by the CCPA; (d) certifies that it understands and will comply with the restrictions in this Section 12; (e) will notify you if it determines it can no longer meet its obligations under applicable U.S. state privacy laws, in which case you may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data; and (f) grants you the right to take reasonable steps to ensure FGPR uses Customer Personal Data consistently with your obligations, as provided in Section 10.
13. Return and Deletion
Upon termination or expiration of the Agreement, FGPR will, at your choice (exercised through the export functions of the Services during the 30-day export window described in the Agreement, or by written request), return and/or delete Customer Personal Data, and thereafter delete remaining copies in accordance with its retention schedules, unless retention is required by applicable law. Deletion from backups occurs in the ordinary course of FGPR's backup cycles, and backup copies remain protected by this DPA until deleted. Upon request, FGPR will confirm deletion in writing.
14. Liability; Order of Precedence; General
14.1 Liability. Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the limitations and exclusions of liability in the Agreement, including ToS Section 10.3(b). Nothing in this Section limits a Data Subject's rights under the SCCs or Data Protection Laws.
14.2 Precedence. In the event of conflict: (1) the EU SCCs / UK Addendum prevail over this DPA with respect to the matters they govern; (2) this DPA prevails over the Agreement with respect to the Processing of Customer Personal Data; and (3) the Agreement governs all other matters.
14.3 Term. This DPA remains in effect for as long as FGPR Processes Customer Personal Data.
14.4 Governing Law. Except where the SCCs require otherwise, this DPA is governed by the law governing the Agreement (Delaware).
14.5 Updates. FGPR may update this DPA as required to reflect changes in Data Protection Laws or approved transfer mechanisms, provided updates do not materially reduce protections for Customer Personal Data; material updates follow the modification process in the Agreement.
Annex I — Details of Processing
A. List of Parties
-
Data exporter: Customer (contact details as in the Order Form or account registration). Role: Controller (or Processor on behalf of a third-party Controller).
-
Data importer: FGPR, Inc., 333 Sylvan Ave, Ste 305, Englewood Cliffs, NJ 07632, USA; privacy@fgr.cx. Role: Processor.
B. Description of Processing
-
Subject matter: Provision of FGPR's digital signage SaaS platform, including hosting, encoding, rendering, scheduling, and delivery of Customer Content to Customer-designated displays, and related support.
-
Duration: The term of the Agreement, plus the export and deletion periods in Section 13.
-
Nature and purpose: Hosting, storage, transmission, encoding/rendering, display delivery, backup, and technical support of Customer Content as configured by Customer; no independent use.
-
Frequency: Continuous, as determined by Customer's use of the Services.
C. Categories of Data Subjects (as determined by Customer's use)
Customer's employees, contractors, and authorized platform users; and individuals appearing in or identified by Customer Content, which may include Customer's personnel, customers, visitors, or other individuals Customer chooses to feature in displayed media.
D. Categories of Personal Data (as determined by Customer's use)
Identification and contact data of Customer's platform users (names, business email addresses); and Personal Data contained in Customer Content, such as names, images, photographs, video, job titles, schedules, or announcements that Customer uploads for display.
E. Special Categories of Data
None intended. Customer agrees not to submit special categories of data (GDPR Art. 9), biometric identifiers, or children's data through the Services absent separate written agreement (see Section 2.3).
F. Competent Supervisory Authority (for EU SCCs)
Determined in accordance with Clause 13 of the EU SCCs: [the supervisory authority of the Member State of the data exporter's establishment or EU representative].
Annex II — Technical and Organizational Measures
-
Encryption: TLS/HTTPS for all data in transit between clients, cloud controllers, and media players; encryption at rest [AES-256] for stored Customer Content and sensitive account data.
-
Access control: Role-based access controls; unique accounts; multi-factor authentication for administrative access; least-privilege provisioning; access reviews at least [quarterly]; prompt revocation upon role change or departure.
-
Device authentication: Token-based authentication between cloud controllers and media player devices; remote management commands are authenticated, encrypted, and logged.
-
Logging and monitoring: Centralized logging of administrative actions, remote device commands, and security events; alerting on anomalous activity; log retention of [90 days].
-
Vulnerability management: Regular vulnerability scanning; risk-based patching (critical patches within 7 days); periodic penetration testing by internal team, at least annually.
-
Secure development: Code review, dependency scanning, and separation of production and non-production environments; no Customer Personal Data in non-production environments except as anonymized.
-
Resilience: Redundant infrastructure via [AWS/GCP]; routine backups with defined restoration procedures tested at least [annually]; documented business continuity and disaster recovery plans.
-
Incident response: Documented incident response plan with defined roles, severity classification, and escalation; tested at least [annually]; breach notification per Section 8.
-
Personnel: Confidentiality obligations for all personnel (Section 4); security and privacy training at hire and at least [annually]; background checks where permitted by law.
-
Physical security: Production infrastructure hosted in [AWS/GCP] data centers with certified physical security controls (e.g., SOC 2, ISO 27001); FGPR offices protected by access controls.
-
Data minimization and segregation: Logical separation of Customer data by account; Processing limited to purposes in Annex I.
Annex III — Authorized Subprocessors
| Subprocessor | Service | Location of Processing |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, content delivery | United States |
| Google Cloud Platform (Google LLC) | Cloud hosting, storage | United States |
Execution. Where this DPA is incorporated by reference into click-through Terms, acceptance of the Terms constitutes execution of this DPA, including the SCCs, by both parties. Where the Agreement is executed via Order Form, the parties' signatures on the Order Form constitute execution of this DPA and the SCCs.