AlphaCanvas AlphaCanvas
Features How It Works Pricing Enterprise Log In Get Started
← Back to AlphaCanvas

ALPHACANVAS DATA PROCESSING AGREEMENT

Effective Date: February 12, 2026 Last Updated: February 12, 2026


THIS DATA PROCESSING AGREEMENT ("DPA") SUPPLEMENTS THE ENTERPRISE LICENSE AGREEMENT ("AGREEMENT") BETWEEN 21CHAINS LLC (D/B/A "ALPHACANVAS") ("PROCESSOR") AND THE ENTITY IDENTIFIED IN THE APPLICABLE ORDER FORM ("CONTROLLER" OR "CLIENT").

This DPA applies where and to the extent AlphaCanvas processes Personal Data on behalf of Client in the course of providing the Platform under the Agreement. This DPA is incorporated into and forms part of the Agreement. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.

Capitalized terms not defined herein have the meanings given to them in the Agreement.


1. DEFINITIONS

"Applicable Data Protection Law" means all laws and regulations relating to the processing of Personal Data that apply to the processing described in this DPA, including but not limited to: (a) the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"); (b) the UK General Data Protection Regulation and UK Data Protection Act 2018 ("UK GDPR"); (c) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); and (d) any other applicable data protection or privacy legislation.

"Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA.

"EEA" means the European Economic Area.

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by AlphaCanvas on behalf of Client in connection with the Platform. For the avoidance of doubt, this includes "personal information" as defined under the CCPA/CPRA and equivalent terms under other Applicable Data Protection Laws.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

"Processing" (and its derivatives "process," "processed," "processes") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission for the transfer of personal data to processors established in third countries, as set forth in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, or any successor clauses adopted by the European Commission.

"Sub-processor" means any third party engaged by AlphaCanvas to process Personal Data on behalf of Client.

"Supervisory Authority" means an independent public authority responsible for monitoring the application of Applicable Data Protection Law, including EU/EEA data protection authorities, the UK Information Commissioner's Office, and equivalent bodies.


2. ROLES AND SCOPE

2.1 Roles

For the purposes of Applicable Data Protection Law:

(a) Client is the Controller -- Client determines the purposes and means of processing Personal Data; (b) AlphaCanvas is the Processor -- AlphaCanvas processes Personal Data on behalf of and in accordance with the documented instructions of Client.

2.2 Scope of Processing

The details of the processing are described in Annex 1 to this DPA, which specifies:

(a) The subject matter and duration of processing; (b) The nature and purpose of processing; (c) The types of Personal Data processed; (d) The categories of Data Subjects.

2.3 CCPA/CPRA Classification

For purposes of the CCPA/CPRA, AlphaCanvas is a "Service Provider" (as defined under the CCPA/CPRA) with respect to Personal Data it processes on behalf of Client. AlphaCanvas shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the services specified in the Agreement; (c) retain, use, or disclose Personal Data outside of the direct business relationship between AlphaCanvas and Client; or (d) combine Personal Data received from Client with Personal Data received from other sources, except as permitted by the CCPA/CPRA.


3. PROCESSING INSTRUCTIONS

3.1 Instructions

AlphaCanvas shall process Personal Data only on the documented instructions of Client, unless required to do so by applicable law, in which case AlphaCanvas shall (to the extent permitted by law) inform Client of such legal requirement before processing.

3.2 Documented Instructions

Client's instructions for processing Personal Data are set forth in:

(a) This DPA and its Annexes; (b) The Agreement and applicable Order Forms; (c) Client's use and configuration of the Platform; (d) Any additional written instructions provided by Client and acknowledged by AlphaCanvas.

3.3 Additional Instructions

If Client provides processing instructions that AlphaCanvas reasonably believes violate Applicable Data Protection Law, AlphaCanvas shall promptly notify Client. AlphaCanvas shall not be required to comply with instructions that it reasonably determines are unlawful.


4. CONFIDENTIALITY

4.1 Personnel

AlphaCanvas shall ensure that all personnel authorized to process Personal Data:

(a) Have committed to confidentiality obligations or are under an appropriate statutory obligation of confidentiality; (b) Process Personal Data only as necessary to perform AlphaCanvas's obligations under the Agreement and this DPA; (c) Have received appropriate training on data protection requirements.


5. SECURITY MEASURES

5.1 Technical and Organizational Measures

AlphaCanvas shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex 2 to this DPA. These measures shall include, at minimum:

(a) Encryption: Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent); (b) Access Controls: Role-based access controls, multi-factor authentication for administrative access, and principle of least privilege; (c) Network Security: Firewalls, intrusion detection/prevention systems, and network segmentation; (d) Monitoring: Logging of access to Personal Data, security event monitoring, and regular log review; (e) Vulnerability Management: Regular vulnerability assessments, penetration testing (at least annually), and timely patching; (f) Business Continuity: Regular data backups, disaster recovery procedures, and tested recovery plans; (g) Physical Security: Data center security controls (for cloud infrastructure providers); (h) Employee Training: Regular security awareness training for all personnel with access to Personal Data.

5.2 Assessment and Updates

AlphaCanvas shall regularly assess and update its security measures to address evolving threats and changes in the processing activities. Security measures may be updated from time to time, provided that such updates do not materially reduce the overall level of protection.


6. SUB-PROCESSORS

6.1 General Authorization

Client provides general written authorization for AlphaCanvas to engage Sub-processors to process Personal Data, subject to the conditions in this Section 6.

6.2 Current Sub-processors

The current list of Sub-processors is set forth in Annex 3 to this DPA. AlphaCanvas shall maintain an up-to-date list of Sub-processors and make it available to Client upon request.

6.3 New Sub-processors

Before engaging a new Sub-processor or replacing an existing Sub-processor, AlphaCanvas shall:

(a) Notify Client in writing at least thirty (30) days in advance, specifying the name, location, and processing activities of the proposed Sub-processor; (b) Provide Client with the opportunity to object to the engagement of the proposed Sub-processor.

6.4 Objection Right

If Client objects to a proposed Sub-processor on reasonable data protection grounds, the parties shall discuss the objection in good faith and AlphaCanvas shall use commercially reasonable efforts to make available an alternative solution that avoids the use of the objected-to Sub-processor. If no alternative is available and AlphaCanvas proceeds with the engagement, Client may terminate the affected Order Form and receive a pro-rata refund of prepaid Fees for the unused portion of the Term.

6.5 Sub-processor Obligations

AlphaCanvas shall:

(a) Enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those in this DPA; (b) Remain fully liable to Client for the acts and omissions of its Sub-processors with respect to Personal Data processing; (c) Conduct appropriate due diligence on Sub-processors before engagement and periodically thereafter.


7. DATA SUBJECT RIGHTS

7.1 Assistance

AlphaCanvas shall, taking into account the nature of the processing, assist Client by appropriate technical and organizational measures (insofar as this is possible) in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law, including rights of:

(a) Access; (b) Rectification; (c) Erasure ("right to be forgotten"); (d) Restriction of processing; (e) Data portability; (f) Objection; (g) Rights related to automated decision-making and profiling.

7.2 Direct Requests

If AlphaCanvas receives a request directly from a Data Subject regarding Personal Data processed on behalf of Client, AlphaCanvas shall promptly redirect the Data Subject to Client and notify Client of the request, unless otherwise required by applicable law.

7.3 Response Timeline

AlphaCanvas shall respond to Client's requests for assistance under this Section within ten (10) business days, or such shorter period as may be required by Applicable Data Protection Law.


8. PERSONAL DATA BREACH

8.1 Notification

AlphaCanvas shall notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach.

8.2 Notification Content

The notification shall include, to the extent reasonably available:

(a) A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned; (b) The name and contact details of AlphaCanvas's point of contact for further information; (c) A description of the likely consequences of the Personal Data Breach; (d) A description of the measures taken or proposed to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

8.3 Ongoing Communication

If it is not possible to provide all required information at the time of initial notification, AlphaCanvas shall provide the information in phases without further undue delay as it becomes available.

8.4 Cooperation

AlphaCanvas shall cooperate with Client and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

8.5 No Assessment by AlphaCanvas

AlphaCanvas's notification of a Personal Data Breach shall not be construed as an acknowledgment of fault or liability. The assessment of whether a Personal Data Breach triggers notification obligations to Supervisory Authorities or Data Subjects is the responsibility of Client as Controller.


9. DATA PROTECTION IMPACT ASSESSMENTS

Where required by Applicable Data Protection Law, AlphaCanvas shall provide reasonable assistance to Client in conducting data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the processing and the information available to AlphaCanvas.


10. INTERNATIONAL DATA TRANSFERS

10.1 Processing Locations

AlphaCanvas processes Personal Data primarily in the United States. Personal Data may also be transferred to or accessed from locations where Sub-processors operate, as identified in Annex 3.

10.2 Transfer Mechanisms

Where Personal Data originating from the EEA, UK, or Switzerland is transferred to a country that has not been deemed to provide an adequate level of data protection, AlphaCanvas shall ensure that appropriate safeguards are in place, which may include:

(a) Standard Contractual Clauses: The parties agree to the SCCs (Module Two: Controller to Processor), which are incorporated into this DPA by reference. The SCCs shall be deemed completed as follows: - Clause 7 (Docking clause): Included; - Clause 9 (Use of sub-processors): Option 2 (general written authorization) with 30-day notice period; - Clause 11 (Redress): Optional language not included; - Clause 13 (Supervision): The Supervisory Authority of the EEA member state in which the Controller is established, or if not established in the EEA, the Supervisory Authority of the member state where Data Subjects are most likely located; - Clause 17 (Governing law): The law of the EEA member state applicable under Clause 13; - Clause 18 (Choice of forum): The courts of the EEA member state applicable under Clause 13; - Annex I, II, and III of the SCCs: As set forth in Annexes 1, 2, and 3 of this DPA respectively.

(b) UK International Data Transfer Addendum: For transfers subject to UK GDPR, the UK International Data Transfer Addendum to the EU SCCs (as issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018) is incorporated by reference, and shall supplement the SCCs as applicable.

(c) Swiss Addendum: For transfers subject to Swiss data protection law, the SCCs shall apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner.

10.3 Alternative Transfer Mechanisms

If any transfer mechanism described above is invalidated or deemed insufficient by a court or regulatory authority, the parties shall cooperate in good faith to implement an alternative legally valid transfer mechanism.


11. AUDITS

11.1 Audit Rights

Client may, at its own expense and upon reasonable prior written notice (not less than thirty (30) days), audit AlphaCanvas's compliance with this DPA, subject to the following conditions:

(a) Audits shall be conducted during normal business hours and shall not unreasonably interfere with AlphaCanvas's operations; (b) Audits shall be limited to once per twelve (12) month period, unless a Personal Data Breach has occurred or a Supervisory Authority requires an audit; (c) Client may use a qualified, independent third-party auditor, subject to AlphaCanvas's reasonable approval and the auditor's execution of a confidentiality agreement; (d) The scope of the audit shall be limited to AlphaCanvas's processing of Personal Data on behalf of Client.

11.2 Audit Reports

AlphaCanvas may satisfy Client's audit request by providing:

(a) Copies of relevant third-party audit reports, certifications, or attestations (such as SOC 2 Type II reports); (b) Written responses to Client's reasonable audit questionnaires; (c) Evidence of compliance with the security measures described in Annex 2.

If such materials are insufficient to address Client's reasonable concerns, Client may conduct an on-site audit subject to the conditions in Section 11.1.

11.3 Costs

Client shall bear all costs of audits it initiates, unless an audit reveals a material breach of this DPA by AlphaCanvas, in which case AlphaCanvas shall bear the reasonable costs of the audit.


12. DATA RETENTION AND DELETION

12.1 Duration

AlphaCanvas shall process Personal Data only for the duration of the Agreement, except as required by applicable law or as otherwise specified in this DPA.

12.2 Return or Deletion

Upon termination or expiration of the Agreement, or upon Client's written request, AlphaCanvas shall:

(a) Return all Personal Data to Client in a commonly used, machine-readable format within thirty (30) days; and/or (b) Securely delete or destroy all Personal Data (including all copies) within sixty (60) days, unless applicable law requires retention.

12.3 Certification

Upon Client's request, AlphaCanvas shall provide written certification of the deletion or destruction of Personal Data.

12.4 Retained Copies

If AlphaCanvas is required by applicable law to retain any Personal Data after termination, AlphaCanvas shall:

(a) Notify Client of such retention requirement; (b) Continue to protect such Personal Data in accordance with this DPA; (c) Process such Personal Data only as required by the applicable law; (d) Delete such Personal Data when the retention requirement expires.


13. LLM-SPECIFIC PROVISIONS

13.1 Third-Party LLM Processing

Client acknowledges that the Platform transmits data (which may include Personal Data embedded in user prompts or contextual data) to third-party LLM providers for AI processing. AlphaCanvas:

(a) Processes such transmissions solely on Client's instructions (i.e., Client's and Authorized Users' use of AI features); (b) Does not control or determine the purposes of processing by LLM providers beyond what is specified in their API terms; (c) Requires that LLM providers accessed through the Platform operate under API terms that restrict training on customer data.

13.2 LLM Provider Terms

Client acknowledges that each LLM provider has its own data processing terms. Under the BYOK model, Client maintains a direct contractual relationship with its chosen LLM providers. Client is responsible for:

(a) Reviewing and accepting the terms and privacy policies of each LLM provider; (b) Ensuring that its use of LLM providers through the Platform complies with Applicable Data Protection Law; (c) Conducting appropriate due diligence on LLM providers with respect to data protection; (d) Determining whether a Data Protection Impact Assessment is required for its use of LLM-powered features.

13.3 Minimization

AlphaCanvas implements data minimization measures in AI features, including structured prompt templates that limit unnecessary data transmission. However, Client and its Authorized Users control the content of prompts and inputs, and are responsible for ensuring that Personal Data included in prompts is necessary and lawful.


14. GENERAL

14.1 Precedence

In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters. In the event of a conflict between this DPA and the SCCs, the SCCs shall prevail.

14.2 Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, except that such limitations shall not apply to the extent prohibited by Applicable Data Protection Law.

14.3 Severability

If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

14.4 Governing Law

This DPA shall be governed by the same governing law as the Agreement, except where Applicable Data Protection Law requires otherwise (including as specified in the SCCs).


ANNEX 1 -- DETAILS OF PROCESSING

A. List of Parties

Controller (Client): - Name: As specified in the applicable Order Form - Address: As specified in the applicable Order Form - Contact: As specified in the applicable Order Form - Role: Controller

Processor (AlphaCanvas): - Name: 21Chains LLC (d/b/a "AlphaCanvas") - Address: Commonwealth of Puerto Rico - Contact: dpo@alphacanvas.ai - Role: Processor

B. Description of Processing

Element Description
Subject matter Provision of the AlphaCanvas Enterprise Platform as described in the Agreement
Duration For the Term of the Agreement plus the data return/deletion period
Nature of processing Collection, storage, organization, retrieval, use, transmission (to LLM providers and market data providers), analysis, deletion
Purpose of processing To provide the Platform services, including: market data aggregation and delivery, AI-powered research and analysis, trade execution and monitoring, portfolio management tools, and user account management
Categories of Data Subjects Client's Authorized Users (employees, contractors, agents)
Types of Personal Data Account information (name, email, role); authentication data (hashed passwords, OAuth tokens); usage data (Platform interactions, feature usage, timestamps); research inputs (prompts, queries, configurations); API keys (LLM provider keys, stored encrypted); IP addresses and device identifiers; any Personal Data that Authorized Users include in prompts or research inputs
Sensitive data Not intentionally processed. Client is responsible for instructing Authorized Users not to input sensitive personal data (e.g., health data, biometric data, racial/ethnic origin) into the Platform unless necessary and lawful

ANNEX 2 -- TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

AlphaCanvas implements the following technical and organizational measures:

Access Controls

  • Role-based access control (RBAC) with principle of least privilege
  • Multi-factor authentication for administrative and production system access
  • Unique user accounts; shared accounts prohibited
  • Access reviews conducted quarterly
  • Automated account deprovisioning upon personnel offboarding

Encryption

  • TLS 1.2+ for all data in transit
  • AES-256 encryption for data at rest (database-level and storage-level)
  • API keys and credentials encrypted at rest
  • Encryption key management using industry-standard practices

Network Security

  • Firewalls and network segmentation between production, staging, and development environments
  • Intrusion detection and prevention systems
  • DDoS mitigation
  • VPN required for administrative access to production infrastructure

Application Security

  • Secure software development lifecycle (SDLC) practices
  • Code review requirements for all production changes
  • Dependency vulnerability scanning
  • Input validation and output encoding
  • Protection against OWASP Top 10 vulnerabilities

Monitoring and Logging

  • Centralized logging of security events and access to Personal Data
  • Security information and event management (SIEM)
  • Automated alerting for suspicious activities
  • Log retention in accordance with security best practices

Business Continuity and Disaster Recovery

  • Regular automated backups (at minimum daily)
  • Geographically separated backup storage
  • Documented disaster recovery plan
  • Recovery time objectives (RTO) and recovery point objectives (RPO) as specified in the SLA

Personnel Security

  • Background checks for personnel with access to production systems (where permitted by law)
  • Confidentiality agreements for all personnel
  • Regular security awareness training
  • Disciplinary procedures for security policy violations

Vendor Management

  • Due diligence assessments for Sub-processors
  • Contractual data protection obligations for all Sub-processors
  • Periodic review of Sub-processor compliance

ANNEX 3 -- LIST OF SUB-PROCESSORS

Current as of the Effective Date. AlphaCanvas will notify Client of changes in accordance with Section 6.3.

Sub-processor Location Processing Activity Personal Data Processed
Cloud Infrastructure Provider (to be specified) United States Platform hosting, data storage, compute All Personal Data processed through the Platform
Anthropic United States LLM processing (when selected by Authorized Users via BYOK) Prompt inputs, contextual data included in AI requests
OpenAI United States LLM processing (when selected by Authorized Users via BYOK) Prompt inputs, contextual data included in AI requests
xAI United States LLM processing (when selected by Authorized Users via BYOK) Prompt inputs, contextual data included in AI requests
Market Data Providers (to be specified) United States Market data sourcing and delivery Minimal -- query metadata only (no Personal Data in standard operation)

Note: LLM providers are accessed under the BYOK model. Client maintains a direct contractual relationship with each provider. AlphaCanvas facilitates the API connection but Client controls which providers are used and what data is transmitted.


21Chains LLC (d/b/a "AlphaCanvas") Organized under the laws of the Commonwealth of Puerto Rico

AlphaCanvas AlphaCanvas

AI-powered market intelligence for the modern analyst.

Product

Features Pricing How It Works Enterprise

Company

Contact Enterprise Sales

Legal

Privacy Policy Terms of Service Risk Disclosure AI Disclaimer Subscription Agreement

© 2026 21Chains LLC (d/b/a "AlphaCanvas"). All rights reserved.

21Chains LLC (d/b/a "AlphaCanvas") is not a broker-dealer, registered investment adviser, or fiduciary. The Platform is a market intelligence and research tool — not a trading platform. All content is for informational and educational purposes only and does not constitute investment advice, a recommendation, or a solicitation to buy or sell any security. Past performance does not guarantee future results. You are solely responsible for your own investment decisions. Terms | Privacy | Risk Disclosure | AI Disclaimer