Data Processing Addendum
Last updated: 25 July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between TITAN PRIME CORP, doing business as "Irradiation AI" ("Irradiation," "we," or "us"), and the customer or merchant agreeing to the Terms ("you" or "Customer"). It applies where and to the extent we Process Customer Personal Data on your behalf in providing the Services (for example, the personal data of your end customers held in the apps, sites, and stores you operate through the Services).
It does not apply to personal data for which we are the controller (such as your own account data), which is governed by our Privacy Policy.
1. Definitions
- "Data Protection Laws" — all laws applicable to the Processing of Customer Personal Data, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss FADP, and U.S. state privacy laws such as the CCPA/CPRA.
- "Customer Personal Data" — personal data we Process on your behalf through the Services.
- "Controller," "Processor," "Subprocessor," "Data Subject," "Personal Data Breach," and "Process/Processing" — have the meanings given in the Data Protection Laws.
- Other capitalized terms have the meaning given in the Terms.
2. Roles of the parties
You are the Controller of the Customer Personal Data (or a Processor acting on behalf of a third-party controller), and we are your Processor (or, where you are a Processor, your Subprocessor). For the CCPA/CPRA, you are the Business and we act as your Service Provider. You are responsible for the accuracy, quality, and lawfulness of the Customer Personal Data and the means by which you acquired it.
Independent controller for the Activity Record. By way of exception, we act as an independent Controller, not as your Processor, in respect of the Activity Record described in section 11 of the Merchant & Payments Terms — the sealed record of significant events on the Services. We determine its purposes and means, and we Process it for our own purposes: establishing, exercising, or defending legal claims, answering enquiries from payment processors and financial institutions, and preventing fraud and abuse. That Processing is therefore outside your instructions under section 3 and outside the deletion obligation in section 11. The Activity Record identifies end customers only by an irreversible reference and contains no name, email address, postal address, IP address, order contents, or message text belonging to them.
3. Scope and your instructions
We will Process Customer Personal Data only: (a) to provide, secure, support, and maintain the Services under the Terms; (b) in accordance with your documented instructions — the Terms and your configuration and use of the Services constitute your complete and final instructions; and (c) as required by applicable law (in which case we will inform you unless legally prohibited). We will inform you if, in our opinion, an instruction infringes Data Protection Laws; we have no obligation to monitor or assess the legality of your data or instructions.
Aggregated and de-identified data. Notwithstanding the foregoing, we may create and use aggregated, anonymized, and de-identified data derived from the Processing — data that does not identify, and cannot reasonably be used to identify, any individual, Customer, or end customer — for any lawful business purpose, including to operate, secure, analyze, benchmark, improve, and develop the Services and to understand trends across the platform. We maintain such data in de-identified form and do not attempt to re-identify it.
4. Your obligations
You represent and warrant that: (a) you have a valid legal basis and have provided all required notices and obtained all required consents for the Customer Personal Data and its Processing; (b) your instructions comply with Data Protection Laws; and (c) you are solely responsible for your own privacy notices, your relationship with Data Subjects, and the lawfulness of the Customer Personal Data.
5. Confidentiality
We ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations.
6. Security
We implement appropriate technical and organizational measures designed to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of Processing — including, as appropriate, encryption in transit, access controls, and logical isolation between accounts. You are responsible for your own use and configuration of the Services, including access management, and for assessing whether the Services' security is appropriate for your data.
7. Subprocessors
You provide a general authorization for us to engage Subprocessors to Process Customer Personal Data in order to provide the Services (for example, cloud hosting, database, storage, and infrastructure providers). We impose data-protection obligations on each Subprocessor that are substantially similar to those in this DPA, and we remain responsible for their performance. A current list of Subprocessors is available on request or online. We will give notice of new Subprocessors, and you may object on reasonable, documented data-protection grounds; if we cannot reasonably address your objection, your sole remedy is to stop using the affected feature.
8. Data Subject requests
Taking into account the nature of the Processing, we will provide reasonable assistance — including, where appropriate, through the self-service features of the Services — to help you respond to requests from Data Subjects to exercise their rights. If we receive such a request directly, we will, where permitted, refer the Data Subject to you. Assistance beyond the Services' standard features may be subject to reasonable charges.
9. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to us and reasonable assistance. As the Controller, you are responsible for notifying supervisory authorities and Data Subjects where required. Our notice is not an acknowledgment of fault or liability.
10. Impact assessments
Taking into account the nature of Processing and the information available to us, we will provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities.
11. Return or deletion
On termination or expiry of the Services, at your choice, we will delete or return Customer Personal Data within a reasonable period, except to the extent retention is required by law. Residual copies in routine backups are deleted in the ordinary course. This section does not apply to the Activity Record, which we hold as an independent Controller under section 2 and retain for the period stated in section 11 of the Merchant & Payments Terms.
12. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA, primarily through our documentation, security information, certifications, and responses to reasonable written questionnaires. On-site audits will be permitted only where required by Data Protection Laws, on reasonable prior written notice, no more than once per twelve (12) months (unless required by a supervisory authority), during business hours, subject to confidentiality, without disrupting our operations, and at your expense.
13. International transfers
Where Customer Personal Data is transferred from the EEA, the UK, or Switzerland to a country without an adequacy decision, the applicable Standard Contractual Clauses approved by the European Commission (together with the UK International Data Transfer Addendum and any Swiss amendments) are incorporated into this DPA by reference and apply, with you as data exporter and us as data importer. Details are available on request.
14. CCPA / U.S. state laws
To the extent we Process personal information subject to the CCPA/CPRA as your Service Provider, we: (a) will not sell or share it; (b) will retain, use, and disclose it only as necessary to provide the Services or as otherwise permitted by the CCPA; and (c) will not retain, use, disclose, or combine it outside the direct business relationship except as permitted by law. We certify that we understand and will comply with these restrictions. Equivalent commitments apply under comparable U.S. state laws.
15. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms (including the aggregate liability cap). This DPA does not increase either party's liability beyond what is provided in the Terms.
16. Conflict and term
If there is a conflict between this DPA and the rest of the Terms regarding the Processing of Customer Personal Data, this DPA controls for that subject matter; otherwise the Terms control. This DPA remains in effect for as long as we Process Customer Personal Data.
17. Contact
TITAN PRIME CORP (d/b/a Irradiation AI) — 525 Randall Ave, Ste 100, Cheyenne, WY 82001, United States — privacy@irradiation.ai.