Effective Date: January 26, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written or electronic agreement between Falcon App Inc. ("Falcon" or "Processor") and the entity identified in the applicable agreement ("Customer" or "Controller") for the provision of the Services (the "Principal Agreement").
This DPA applies to the extent that Falcon processes Personal Data on behalf of Customer in connection with the Services. This DPA is incorporated into and forms part of the Principal Agreement.
For Customers in Colombia: This DPA complies with the requirements of Colombian Law 1581 of 2012 and Decree 1377 of 2013 regarding data processing by third parties. Section 12 (Colombian Data Protection Compliance) specifically addresses requirements under Colombian law.
"Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data, including, where applicable:
"Controller" means the entity that determines the purposes and means of the processing of Personal Data. In this DPA, Controller refers to Customer.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Falcon on behalf of Customer in connection with the Services.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
"Processor" means the entity that processes Personal Data on behalf of the Controller. In this DPA, Processor refers to Falcon.
"Services" means the cloud-based software services provided by Falcon to Customer under the Principal Agreement.
"Sub-processor" means any third party engaged by Falcon to process Personal Data on behalf of Customer.
For the purposes of this DPA:
This DPA applies to the processing of Personal Data by Falcon on behalf of Customer in connection with the provision of the Services.
The details of the data processing are described in Annex 1 to this DPA.
Customer shall:
(a) Comply with all Applicable Data Protection Laws in connection with its use of the Services and the processing of Personal Data;
(b) Ensure that the instructions provided to Falcon regarding the processing of Personal Data comply with Applicable Data Protection Laws;
(c) Obtain all necessary consents, authorizations, and legal bases required for the processing of Personal Data by Falcon;
(d) Provide Data Subjects with all required notices regarding the processing of their Personal Data;
(e) Ensure the accuracy, quality, and legality of Personal Data submitted to the Services.
Customer instructs Falcon to process Personal Data as necessary to:
(a) Provide the Services in accordance with the Principal Agreement and this DPA;
(b) Retain Personal Data for quality assurance purposes as described in Section 5.2;
(c) Use anonymized and aggregated data for model training as described in Section 5.3, unless Customer has exercised its opt-out right.
Customer may provide additional written instructions consistent with the terms of this DPA.
If Customer is subject to Colombian Law 1581 of 2012, Customer warrants that:
(a) Customer has obtained the prior, express, and informed authorization from Data Subjects for the collection and processing of their Personal Data;
(b) Customer has provided Data Subjects with the required privacy notice containing the information required by Article 12 of Law 1581 of 2012;
(c) Customer has informed Data Subjects that their Personal Data may be transferred to Falcon for processing;
(d) Customer maintains appropriate records of authorizations obtained from Data Subjects.
Falcon shall:
(a) Process Personal Data only on documented instructions from Customer, including with respect to transfers of Personal Data to a third country, unless required to do so by applicable law;
(b) Inform Customer if, in Falcon's opinion, an instruction infringes Applicable Data Protection Laws;
(c) Process Personal Data only for the purposes specified in this DPA and the Principal Agreement.
Falcon shall:
(a) Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(b) Treat all Personal Data as confidential and not disclose Personal Data to third parties except as permitted by this DPA or as instructed by Customer.
Falcon shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures shall include, at a minimum:
(a) Access Controls: Restricting access to Personal Data to authorized personnel only, using authentication mechanisms and role-based access controls;
(b) Encryption: Encrypting Personal Data in transit and at rest using industry-standard encryption protocols;
(c) Monitoring: Implementing logging and monitoring systems to detect unauthorized access or anomalies;
(d) Incident Response: Maintaining incident response procedures to address security incidents promptly;
(e) Personnel Security: Ensuring that personnel with access to Personal Data are appropriately trained and bound by confidentiality obligations;
(f) Physical Security: Utilizing data centers with appropriate physical security controls;
(g) Business Continuity: Maintaining backup and disaster recovery procedures.
(a) Customer authorizes Falcon to engage the Sub-processors listed in Annex 2 to this DPA.
(b) Falcon shall enter into written agreements with Sub-processors that impose data protection obligations no less protective than those set forth in this DPA.
(c) Falcon shall inform Customer of any intended changes to Sub-processors by updating Annex 2 and providing reasonable notice. Customer may object to such changes on reasonable grounds related to data protection within fifteen (15) business days.
The primary mode of processing Customer Content is transient. Personal Data is processed in real-time to provide the requested Services and is not permanently stored beyond the immediate processing session. This minimizes data retention and reduces privacy risks.
Falcon may retain Personal Data for up to thirty (30) days for quality assurance purposes, including:
Data retained for quality assurance is stored securely with access restricted to authorized personnel and is automatically deleted after the retention period.
Falcon may use Customer Content to develop, train, and improve its artificial intelligence and machine learning models, subject to the following safeguards:
(a) Anonymization: All personally identifiable information is removed before any data is used for training purposes;
(b) Aggregation: Data is aggregated with data from other sources to prevent identification of any individual or Customer;
(c) Non-Reversibility: The anonymized and aggregated data cannot be traced back to any specific Customer or individual.
Customer may opt out of model training by submitting a written request to legal@falconapp.ai. Falcon will implement the opt-out within fifteen (15) business days.
Falcon does not sell Personal Data to third parties. Falcon processes Personal Data only as instructed by Customer and as permitted under this DPA.
Falcon shall assist Customer in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.
If Falcon receives a request directly from a Data Subject, Falcon shall promptly notify Customer and shall not respond to the request directly unless authorized by Customer or required by law.
For Data Subjects located in Colombia, Falcon shall assist Customer in complying with the rights established under Law 1581 of 2012, including:
Falcon shall notify Customer without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification shall include:
(a) A description of the nature of the breach, including the categories and approximate number of Data Subjects and records affected;
(b) The name and contact details of Falcon's data protection contact;
(c) A description of the likely consequences of the breach;
(d) A description of the measures taken or proposed to address the breach and mitigate its effects.
Falcon shall cooperate with Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the Personal Data Breach.
Falcon shall document all Personal Data Breaches, including the facts, effects, and remedial actions taken, and shall make such documentation available to Customer upon request.
Falcon shall make available to Customer all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or a third-party auditor mandated by Customer.
Customer shall provide reasonable advance notice (at least 30 days) of any audit request. Audits shall be conducted during normal business hours, shall not unreasonably disrupt Falcon's operations, and shall be subject to reasonable confidentiality obligations. Customer shall bear the costs of any audit.
Upon request, Falcon shall provide Customer with copies of relevant certifications, audit reports, or other evidence of compliance with security and data protection requirements.
Falcon shall ensure that any transfer of Personal Data to a country outside the jurisdiction of the Controller is made in compliance with Applicable Data Protection Laws, using appropriate transfer mechanisms such as:
(a) Standard Contractual Clauses approved by relevant authorities;
(b) Binding Corporate Rules;
(c) Adequacy decisions by competent authorities;
(d) The Data Subject's explicit consent to the transfer.
For transfers of Personal Data from Colombia, Falcon shall comply with the requirements of Law 1581 of 2012 and Decree 1377 of 2013, which require that international transfers be made only to countries with adequate levels of data protection or with the express authorization of the Data Subject.
By default, Personal Data is processed in Falcon's infrastructure located in the United States (AWS Ohio region). Customer acknowledges and agrees to this transfer. Alternative hosting locations may be available upon request, subject to additional terms and fees.
This DPA shall remain in effect for the duration of the Principal Agreement and for as long as Falcon processes Personal Data on behalf of Customer.
Upon termination of the Principal Agreement or upon Customer's written request, Falcon shall:
(a) Return all Personal Data to Customer in a commonly used, machine-readable format; or
(b) Delete all Personal Data within thirty (30) days, except as required for legal compliance.
Falcon shall provide written certification of deletion upon Customer's request.
The obligations under this DPA relating to confidentiality, data security, and cooperation with audits shall survive termination of this DPA.
Each party shall be liable for damages caused by its breach of this DPA or Applicable Data Protection Laws. The liability limitations set forth in the Principal Agreement shall apply to this DPA, except to the extent prohibited by Applicable Data Protection Laws.
Each party shall indemnify the other party for any damages, losses, or expenses arising from the indemnifying party's breach of this DPA, including fines or penalties imposed by regulatory authorities.
This section applies to the processing of Personal Data of individuals located in Colombia or Personal Data otherwise subject to Colombian Law 1581 of 2012.
Customer warrants that it has obtained the prior, express, and informed authorization (autorizacion previa, expresa e informada) from Data Subjects for the collection and processing of their Personal Data, in accordance with Article 9 of Law 1581 of 2012.
This DPA constitutes a processing contract (contrato de transmision) between Customer (as Controller/Responsable) and Falcon (as Processor/Encargado) in accordance with Article 25 of Decree 1377 of 2013. Falcon shall process Personal Data only in accordance with Customer's instructions and the purposes specified in this DPA.
Customer acknowledges that the processing of sensitive data (datos sensibles), including health data, is subject to enhanced protections under Colombian law. Customer warrants that it has obtained explicit authorization for the processing of any sensitive data and has informed Data Subjects of the voluntary nature of providing such data.
Falcon shall cooperate with Customer in responding to any inquiries, investigations, or requests from the Superintendencia de Industria y Comercio (SIC) or other competent authorities regarding the processing of Personal Data under this DPA.
This DPA shall be governed by the same governing law as the Principal Agreement, except that any provisions required by Applicable Data Protection Laws shall be interpreted in accordance with those laws.
In the event of any conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the processing of Personal Data.
Falcon may update this DPA from time to time to reflect changes in Applicable Data Protection Laws or our processing practices. Material changes will be communicated to Customer at least thirty (30) days before taking effect.
If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall continue in full force and effect.
For questions about this DPA or to exercise data protection rights, please contact:
Falcon App Inc., 2483 Coney Island Ave CO ODIS, Brooklyn, NY 11223, United States
Email: legal@falconapp.ai
For Colombian data protection inquiries, please include "DPA - Colombia" in the subject line.
The Services may process sensitive data including:
Customer is responsible for ensuring appropriate authorization has been obtained for the processing of sensitive data.
Personal Data is processed for the duration of the Principal Agreement. Transient processing occurs in real-time. Quality assurance retention is limited to thirty (30) days.
The following Sub-processors are authorized to process Personal Data on behalf of Customer:
Falcon will notify Customer of any changes to this list at least fifteen (15) business days before engaging a new Sub-processor.
Last Updated: January 26, 2026
Next steps