Last updated September 5, 2026
Data Processing Addendum
Version 2.4. Schedule A to the Cutova Software-as-a-Service Agreement, Version 2.4.
This Data Processing Addendum (“DPA”) supplements the Cutova Software-as-a-Service Agreement (the “Agreement”) between Lens Software LLC (“Company”) and the customer that accepts it (“Customer”). It applies to the Company’s processing of Personal Information contained in Customer Content on the Customer’s behalf.
This DPA forms Schedule A of Agreement Version 2.4. It applies automatically when the Company processes Personal Information in Customer Content on the Customer’s behalf. No separate signature is required. Existing separately signed agreements remain governed by their terms.
Capitalized terms not defined here have the meaning given in the Agreement.
1. Definitions
(a) “Data Protection Laws” means all privacy and data protection laws applicable to the Company’s processing of Personal Information under the Agreement, including the Florida Digital Bill of Rights, the California Consumer Privacy Act as amended, and comparable United States state privacy laws.
(b) “Personal Information” means information within Customer Content that identifies or is reasonably capable of being associated with an identified or identifiable natural person, as defined under Data Protection Laws.
(c) “Process” and “Processing” mean any operation performed on Personal Information.
(d) “Controller” (or “Business”) and “Processor” (or “Service Provider”) have the meanings given under the applicable Data Protection Laws.
(e) “Subprocessor” means a third party engaged by the Company to Process Personal Information in providing the Service.
2. Roles and instructions
The Customer is the Controller (or Business) of the Personal Information. The Company is a Processor (or Service Provider) acting on the Customer’s behalf. The Company will Process Personal Information only on the Customer’s documented instructions, which consist of the Agreement, the applicable Order, this DPA, and the configuration choices the Customer makes in the Service. The Company will inform the Customer if it believes an instruction violates Data Protection Laws. The Customer is responsible for the lawfulness of the Customer Content and for providing any notices and obtaining any consents required for the Company to Process it.
3. Service provider and business-purpose commitments
The Company will Process Personal Information only for the business purposes of providing, securing, supporting, metering, billing for, and improving the Service, and as otherwise permitted by Data Protection Laws. The Company:
(a) will not sell or share Personal Information, as those terms are defined under Data Protection Laws;
(b) will not retain, use, or disclose Personal Information for any purpose other than the business purposes specified above, or as otherwise permitted by Data Protection Laws, and will not retain, use or disclose it outside the direct business relationship between the parties;
(c) will not combine Personal Information received under the Agreement with personal information from another source, except as Data Protection Laws permit a service provider to do; and
(d) certifies that it understands the restrictions in this Section 3 and will comply with them.
No training on Customer Content. The Company will not use Personal Information, or any other Customer Content, to train, fine-tune, evaluate or otherwise develop any artificial-intelligence or machine-learning model, and will not sell, rent or license it to any third party. This commitment is permanent and survives termination, and mirrors Section 3.7 of the Agreement.
4. Confidentiality
The Company will ensure that personnel authorized to Process Personal Information are bound by appropriate confidentiality obligations.
5. Security
The Company will maintain the contractual security baseline in Section 8.3 of the Agreement. Changes to informational web pages do not reduce that baseline.
6. Subprocessors
The Customer authorizes subprocessors subject to Section 8.4 of the Agreement, including advance email notice, reasonable objections and the termination/refund remedy. The Company will impose written data protection obligations no less protective than this DPA and remains responsible for their performance. A customer-selected AI Client is independent; a provider engaged by the Company to process Customer Content is a subprocessor.
7. Assistance to the Customer
Taking into account the nature of the Processing, the Company will:
(a) assist the Customer, by appropriate technical and organizational measures and insofar as reasonably possible, to respond to requests from individuals to exercise their rights under Data Protection Laws. Because the Company does not hold Epicor records and Processes limited Personal Information, the Customer can fulfil most such requests by exporting its configured tool definitions through the administration console and by requesting deletion of other account and configuration data as described in Section 9;
(b) assist the Customer with security-incident notification as described in Section 8, and with data protection impact assessments and consultations with regulators, in each case at the Customer’s reasonable request and expense; and
(c) make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. On the Customer’s written request, not more than once per twelve (12) months and subject to reasonable confidentiality and security conditions, the Company will respond to a reasonable written security and privacy questionnaire; on-site audits are available only under a signed Enterprise Order.
8. Security incidents
A “Security Incident” means a confirmed unauthorized access to, or acquisition of, Personal Information in the Company’s possession, or of the Customer’s Epicor connection or service-account credentials. The Company will notify the Customer’s designated contact by email without undue delay, and in any event within seventy-two (72) hours, after the Company determines that a Security Incident has occurred. Where the Company is a third-party agent within the meaning of Fla. Stat. § 501.171, notice will be no later than ten (10) days after the Company determines that a Security Incident occurred or has reason to believe it occurred, as that statute requires. The Company will investigate, contain and mitigate the incident and provide the information the Customer reasonably needs to meet its own notification obligations. As the Controller, the Customer determines whether to notify individuals or regulators. Notification is not an admission of fault.
9. Retention, return and deletion
During the Subscription Term the Customer may export its configured tool definitions through the administration console. After termination or expiration of the Agreement, the Company will retain the Customer’s account and configuration data for thirty (30) days, after which the Company will delete it. The Company may retain Personal Information only (a) as usage data or aggregated or de-identified data, (b) in billing, tax and audit records for as long as the law requires, and (c) in routine backups until those backups expire in the ordinary course. The Customer may request deletion at any time by emailing support@cutova.ai; the Company will action the request within thirty (30) days, subject to the retention exceptions above. Deletion is irreversible.
10. Prohibited Data
The Customer will not transmit through the Service the categories of Prohibited Data described in Section 3.4 of the Agreement, subject to the inadvertent-transmission exception in Section 3.4, including protected health information subject to HIPAA, cardholder data subject to PCI DSS, government classified or controlled unclassified information, biometric identifiers, or personal information of children under 13, unless the parties agree otherwise in a signed writing.
11. International transfers
The Service is operated in the United States, and Personal Information is Processed in the United States. This DPA addresses United States state privacy laws. If the Customer requires the Company to Process personal data subject to the European Union or United Kingdom General Data Protection Regulation, the parties will agree an appropriate transfer mechanism, such as the applicable Standard Contractual Clauses, in a separate signed writing before that data is transmitted.
12. Liability and precedence
For conflicts about processing Personal Information, this DPA prevails as stated in Section 20.2 of the Agreement. The limits and exclusions in Sections 7.11 and 11 of the Agreement apply to this DPA. This DPA does not increase those caps or exclude liability that cannot lawfully be excluded.
13. Term
This DPA takes effect when Agreement Version 2.4 becomes applicable to the Customer and the Company processes Personal Information on its behalf and remains in effect for as long as the Company Processes Personal Information under the Agreement. Provisions that by their nature should survive, including Sections 3, 5, 8, 9 and 12, survive termination.
14. Questions and separately agreed terms
No separate signature is required for Schedule A. Contact legal@cutova.ai to request a separately signed form or discuss additional requirements. Changes to this standard DPA follow Section 17 of the Agreement; a later website version does not automatically replace this one.
Lens Software LLC, 12234 Meadowcrest Lane, Jacksonville, FL 32246.
Cutova is a product of Lens Software LLC, Jacksonville, Florida.