Last updated: August 18, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Fenix.ai LLC ("Fenix," the processor) and the Customer (the controller) governing the Fenix Services, and applies to Fenix's processing of personal data contained in Customer Data.
Fenix processes Customer Data solely to provide the Services and only on the Customer's documented instructions, which consist of the agreement, this DPA, and the Customer's and its users' use of the Services' features. Fenix does not use Customer Data for its own purposes and does not use it to train machine-learning models.
Customer Data consists of patent matter content and related records, which may include personal data such as inventor and practitioner names, contact details, and user activity records. Data subjects are the Customer's personnel, clients, and inventors. The Customer is responsible for having a lawful basis for the personal data it stores in the Services.
Each Customer's data is held in a dedicated database. Access through the Services — including through the Fenix MCP connector — is authenticated to an individual person, scoped by that person's role, and confined to the Customer's own tenant; access tokens are cryptographically bound to the single tenant's endpoint. Every connector action is recorded in an audit log with the acting user's identity.
Fenix maintains appropriate technical and organizational measures, including: encryption of data in transit and at rest; per-user authentication via the Customer's identity provider with no password storage; short-lived, audience-bound access tokens; role-based authorization enforced server-side; per-credential rate limiting; audit logging of connector activity; and least-privilege operational access.
The Customer authorizes the following subprocessors, engaged under written data protection terms and reviewed annually against their current certifications: Amazon Web Services (document storage, email, queues, and OCR), MongoDB Atlas (database hosting), Vercel (application hosting), and OpenAI (document AI processing, transient). Fenix will give the Customer prior notice of new subprocessors and an opportunity to object. An AI assistant the Customer connects through the Fenix MCP connector is not a Fenix subprocessor: it receives data under the Customer's own agreement with that provider.
Fenix personnel with access to Customer Data are bound by confidentiality obligations and access Customer Data only as needed to operate and support the Services.
Fenix will promptly forward to the Customer any data subject request it receives concerning Customer Data and will provide reasonable assistance, including through the Services' export and deletion capabilities, so the Customer can fulfil such requests.
Fenix will give the Customer preliminary notice within 48 hours of becoming aware of a personal data breach affecting Customer Data (within 24 hours where the Customer's agreement requires it), followed by detailed findings — scope, impact, and remediation — within 72 hours, and will provide the information reasonably required for the Customer's own notification obligations.
On termination of the agreement, Fenix will make Customer Data available for export and, at the Customer's choice, delete it, subject to legal retention requirements. Backup copies are deleted on the backup rotation schedule.
On reasonable notice and no more than annually, Fenix will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party assessments where available.
Fenix.ai LLC — contact@fenix.ai
Transform your patent workflow in under 5 minutes. Yes, really.