Data Processing Agreement

Version 2.0
Schemon, Inc.
Last Update: August 18, 2026

This Data Processing Agreement, including its Appendices (the "DPA"), forms part of the Schemon SaaS Agreement or another written or electronic agreement governing the Customer's use of the Schemon services (the "Agreement").

This DPA is entered into between Schemon Inc.*, a Delaware corporation with an address at Christiana Corporate Business Center, 200 Continental Dr, Suite 401, PMB 1578, Newark, Delaware 19713, United States ("Schemon"), and the person or entity identified as the customer in the Agreement ("Customer").

This DPA applies when Schemon Processes Customer Personal Data on behalf of Customer in connection with the Services. It is effective on the later of the date Customer accepts the Agreement, the date the parties execute this DPA, or the date Schemon first Processes Customer Personal Data subject to Applicable Data Protection Law.

If there is a conflict concerning the Processing of Customer Personal Data, the following order of precedence applies: (1) the applicable Standard Contractual Clauses or other mandatory transfer terms; (2) this DPA; and (3) the Agreement.

1. Definitions

1.1 Applicable Data Protection Law

"Applicable Data Protection Law" means any privacy, data protection, or data security law that applies to Schemon's Processing of Customer Personal Data under the Agreement, including, where applicable:

  • Regulation (EU) 2016/679 (the "EU GDPR");
  • the EU GDPR as incorporated into United Kingdom law, together with the UK Data Protection Act 2018 (the "UK GDPR");
  • the Swiss Federal Act on Data Protection (the "Swiss FADP");
  • applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA"); and
  • implementing regulations and binding requirements issued under those laws.

1.2 Other defined terms

  • -Account Data means Personal Data that Schemon Processes as an independent Controller for its own account administration, billing, security, legal compliance, service communications, and business operations, as described in the Schemon Privacy Policy.
  • -Business, Business Purpose, Consumer, Contractor, Personal Information, Sell, Service Provider, and Share have the meanings given under the CCPA where the CCPA applies.
  • -Controller, Processor, Data Subject, Personal Data, Processing, Supervisory Authority, and Personal Data Breach have the meanings given under Applicable Data Protection Law. "Process," "Processes," and "Processed" have corresponding meanings.
  • -Customer Data means data submitted to, stored in, retrieved from, transmitted through, or generated through the Services by or for Customer.
  • -Customer Personal Data means Personal Data contained in Customer Data that Schemon Processes on behalf of Customer under the Agreement.
  • -Customer-Selected Third-Party Service means a third-party product, account, application, model provider, MCP client, connector, or service that Customer or an authorized user elects to connect to the Services or directs Schemon to interact with, and that is not engaged by Schemon to Process Customer Personal Data on Schemon's behalf.
  • -EEA means the European Economic Area.
  • -MCP means the Model Context Protocol and related servers, clients, tools, resources, prompts, connectors, authentication, and actions.
  • -Restricted Transfer means a transfer of Personal Data that requires a valid transfer mechanism under Applicable Data Protection Law.
  • -Services means the Schemon services described in the Agreement, including applicable websites, portals, mobile applications, APIs, MCP servers, integrations, support, and related functionality.
  • -Standard Contractual Clauses or SCCs means the clauses adopted by European Commission Implementing Decision (EU) 2021/914, as amended, replaced, or superseded.
  • -Subprocessor means a third party appointed by or for Schemon to Process Customer Personal Data on behalf of Customer in connection with the Services.
  • -UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office, as amended, replaced, or superseded.

2. Scope and Roles

2.1 Customer as Controller

When Customer determines the purposes and means of Processing Customer Personal Data, Customer is the Controller and Schemon is the Processor.

2.2 Customer as Processor

When Customer Processes Customer Personal Data on behalf of another Controller, Customer is a Processor and Schemon is Customer's Subprocessor. Customer represents that it is authorized by the relevant Controller to appoint Schemon and to enter into this DPA. Customer will provide the identity and contact details of the relevant Controller when reasonably required for Schemon to comply with Applicable Data Protection Law.

2.3 Schemon as independent Controller

This DPA does not apply to Account Data or other Personal Data for which Schemon independently determines the purposes and means of Processing. Schemon Processes that data as described in the Schemon Privacy Policy. This distinction does not reduce any obligation Schemon has under Applicable Data Protection Law.

2.4 Details of Processing

The subject matter, duration, nature, purpose, categories of Data Subjects, categories of Customer Personal Data, and Processing operations are described in Appendix 1.

3. Customer Instructions

3.1 Documented instructions

Schemon will Process Customer Personal Data only on Customer's documented instructions, unless Applicable Data Protection Law requires otherwise. Customer's documented instructions consist of:

  • the Agreement and this DPA;
  • Customer's use, configuration, and administration of the Services;
  • instructions submitted through the Services, APIs, support channels, or MCP tools by authorized users;
  • Customer's selection and configuration of integrations, permissions, scopes, retention settings, and exports; and
  • other written instructions that are consistent with the Agreement and accepted by Schemon.

3.2 Required Processing

If law requires Schemon to Process Customer Personal Data contrary to or beyond Customer's instructions, Schemon will inform Customer before the Processing unless the law prohibits notice on important grounds of public interest.

3.3 Unlawful instructions

Schemon will promptly inform Customer if, in Schemon's reasonable opinion, an instruction infringes Applicable Data Protection Law. Schemon may suspend the affected Processing until Customer confirms, modifies, or withdraws the instruction.

3.4 No independent use of Customer Personal Data

Schemon will not:

  • Sell or Share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than providing the Services and performing the Agreement;
  • combine Customer Personal Data with Personal Data received from another person or collected from Schemon's own interaction with a Data Subject, except as permitted by Applicable Data Protection Law and necessary to provide or secure the Services; or
  • use Customer Personal Data to train a general-purpose artificial intelligence model, or authorize a Schemon-managed AI Subprocessor to do so, except on Customer's express documented instruction or under a separate written agreement.

Schemon may use aggregated or de-identified information that cannot reasonably be linked to Customer or a Data Subject, provided Schemon maintains it in de-identified form and does not attempt to re-identify it except to test de-identification as permitted by law.

3.5 CCPA certification

To the extent the CCPA applies, Schemon certifies that it understands and will comply with the restrictions and obligations applicable to a Service Provider or Contractor. Schemon will notify Customer if it determines it can no longer meet those obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.

4. Customer Obligations

Customer will:

  1. comply with Applicable Data Protection Law in its collection, use, disclosure, and instructions concerning Customer Personal Data;
  2. ensure that it and its authorized users have a lawful basis to Process and disclose Customer Personal Data through the Services;
  3. provide required privacy notices and obtain required consents or authorizations;
  4. ensure that its instructions are lawful, accurate, complete, and consistent with the rights of Data Subjects;
  5. respond to Data Subject requests and communications from Supervisory Authorities, except to the extent Schemon is legally responsible;
  6. configure permissions, roles, integrations, and retention settings appropriately;
  7. protect Account credentials, API keys, OAuth tokens, MCP credentials, and administrator access;
  8. notify Schemon promptly of suspected unauthorized access, unlawful instructions, or a complaint relating to Schemon's Processing;
  9. avoid submitting Personal Data not reasonably needed for the Services; and
  10. ensure that Customer Personal Data does not violate the Agreement, law, or the rights of another person.

4.1 Special-category and sensitive data

Customer will not submit special-category, sensitive, biometric, genetic, precise geolocation, criminal-offense, or similar highly regulated Personal Data unless:

  • the relevant Service feature is intended for that data;
  • Customer has a valid legal basis and has completed any required impact assessment;
  • required notices, consents, and safeguards are in place; and
  • Customer has implemented appropriate access restrictions and security settings.

4.2 Recordings and communications

If Customer enables recording, transcription, monitoring, messaging, or communications features, Customer is responsible for providing all notices and obtaining all consents required from participants, personnel, clients, or other Data Subjects.

4.3 HIPAA and Protected Health Information

Unless Schemon expressly agrees otherwise in writing and the parties execute a Business Associate Agreement, Customer must not submit Protected Health Information regulated by the U.S. Health Insurance Portability and Accountability Act (HIPAA) to the Services. This DPA is not a Business Associate Agreement.

5. Schemon Personnel and Confidentiality

Schemon will:

  • ensure that persons authorized to Process Customer Personal Data are subject to contractual, statutory, or professional confidentiality obligations;
  • limit access to personnel who need it to provide, secure, support, or maintain the Services;
  • provide appropriate privacy and security training; and
  • ensure that authorized personnel Process Customer Personal Data only in accordance with Customer's instructions, unless law requires otherwise.

The confidentiality obligations in this Section survive termination of the DPA.

6. Security

6.1 Security program

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects, Schemon will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.

The measures in effect as of the Last Updated date are described in Appendix 3.

6.2 Updates to safeguards

Schemon may update its safeguards to reflect technological development, operational changes, and evolving threats, provided that the overall level of protection is not materially reduced during the term of the Agreement.

6.3 Customer security responsibilities

Customer is responsible for securely configuring and using the Services, managing authorized users, reviewing logs and integrations made available to Customer, and protecting credentials and Customer-controlled systems.

7. Personal Data Breaches

7.1 Notice

Schemon will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 Content of notice

To the extent known and reasonably available, the notice will include:

  • the nature of the Personal Data Breach;
  • the categories of Customer Personal Data and Data Subjects affected;
  • the approximate number of affected records and Data Subjects;
  • the likely consequences;
  • measures taken or proposed to contain, investigate, and remediate the breach; and
  • a contact for follow-up questions.

Schemon may provide information in phases as the investigation progresses. A notice is not an admission of fault or liability.

7.3 Cooperation

Schemon will take reasonable steps to contain and remediate the Personal Data Breach and will provide information reasonably needed for Customer to meet its notification obligations. Customer is responsible for notifying Supervisory Authorities, Data Subjects, and other third parties unless Applicable Data Protection Law requires Schemon to do so directly.

7.4 Unsuccessful security incidents

Unsuccessful attempts that do not compromise the confidentiality, integrity, or availability of Customer Personal Data, such as blocked scans, failed login attempts, pings, or denial-of-service attempts, are not Personal Data Breaches and do not require notice under this Section.

8. Data Subject Requests

8.1 Forwarding requests

If Schemon receives a request from a Data Subject concerning Customer Personal Data and can identify the relevant Customer, Schemon will forward the request to Customer without undue delay and will not respond substantively except on Customer's documented instruction or where law requires.

8.2 Assistance

Taking into account the nature of the Processing, Schemon will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to requests to access, correct, delete, restrict, object, port, or otherwise exercise Data Subject rights.

8.3 Customer controls

Where available, Customer will use Service functionality to search, access, export, correct, or delete Customer Personal Data before requesting manual assistance. Schemon may charge reasonable fees for unusually burdensome assistance that is not required by Applicable Data Protection Law, provided Schemon gives Customer advance notice.

9. Regulatory and Compliance Assistance

Taking into account the nature of Processing and the information available to Schemon, Schemon will provide reasonable assistance with Customer's obligations concerning:

  • security of Processing;
  • Personal Data Breach assessments and notifications;
  • data protection impact assessments;
  • prior consultation with a Supervisory Authority;
  • records of Processing; and
  • inquiries from a Supervisory Authority relating to Schemon's Processing.

If a Supervisory Authority contacts Schemon about Customer Personal Data, Schemon will notify Customer unless prohibited by law. Schemon is not authorized to represent Customer before a Supervisory Authority without written authorization.

10. Government and Third-Party Requests

If Schemon receives a legally binding request for Customer Personal Data from a public authority or third party, Schemon will, to the extent legally permitted:

  • notify Customer promptly;
  • review the request for legal validity;
  • challenge an unlawful or overbroad request where there are reasonable grounds to do so;
  • disclose only the minimum data legally required; and
  • seek confidential treatment or appropriate protective measures.

Schemon will not voluntarily provide a public authority with direct, indiscriminate, or unfettered access to Customer Personal Data.

11. Records, Information, and Audits

11.1 Compliance information

Schemon will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the EU GDPR or UK GDPR, where applicable. Information may include security documentation, policies, summaries of independent assessments, questionnaires, or other relevant materials, subject to confidentiality and security restrictions.

11.2 Audit process

Customer may conduct an audit no more than once in any 12-month period, unless a Personal Data Breach, material compliance concern, or Supervisory Authority requires an additional audit. Customer will:

  • first review information Schemon makes available remotely;
  • provide at least 30 days' prior written notice, unless urgent circumstances require less;
  • use an independent, qualified auditor that is not a competitor of Schemon and is bound by confidentiality;
  • conduct the audit during normal business hours without unreasonably disrupting Schemon's operations;
  • avoid access to another customer's data, trade secrets, or systems that would create a security risk; and
  • bear its own audit costs, unless Applicable Data Protection Law requires otherwise.

The parties will agree on a reasonable audit scope and method. Schemon may charge reasonable costs for extensive on-site or bespoke audit support after providing an estimate.

11.3 Remediation

Schemon will address material findings relating to its obligations under this DPA within a reasonable period, taking into account the risk and complexity of remediation.

12. Subprocessors

12.1 General authorization

Customer grants Schemon general written authorization to appoint Subprocessors in accordance with this Section. The Subprocessors authorized as of the Last Updated date are listed in Appendix 2.

12.2 Subprocessor contracts

Schemon will enter into a written agreement with each Subprocessor that imposes data-protection obligations that are no less protective in substance than those imposed on Schemon under this DPA, to the extent applicable to the Subprocessor's services.

12.3 Responsibility

Schemon remains responsible to Customer for a Subprocessor's performance of its data-protection obligations to the same extent Schemon would be responsible if it performed the Processing directly, subject to the Agreement's liability terms and Applicable Data Protection Law.

12.4 Notice of changes

Schemon will provide at least 30 days' prior notice of a new or replacement Subprocessor that will Process Customer Personal Data, normally by email, in-product notice, or an updated subprocessor notice. If advance notice is not reasonably possible because of an urgent security, legal, or continuity need, Schemon will provide notice as soon as reasonably practical.

12.5 Objections

Customer may object to a new Subprocessor on reasonable, documented data-protection grounds by notifying Schemon within 30 days after notice. The parties will work in good faith to address the objection. Schemon may, at its discretion:

  • provide additional information or safeguards;
  • avoid using the Subprocessor for Customer Personal Data;
  • offer a commercially reasonable alternative; or
  • suspend or terminate the affected feature or Services in accordance with the Agreement if no reasonable alternative is available.

An objection does not relieve Customer of payment obligations except as expressly stated in the Agreement.

13. MCP and Customer-Selected Third-Party Services

13.1 MCP Processing by Schemon

When an authorized user connects an MCP client to a Schemon MCP server, Customer instructs Schemon to receive the MCP request, authenticate and authorize it, Process the Customer Personal Data needed for the requested tool or resource, perform the supported action, and return the result to the MCP client.

MCP Processing may include reading, searching, retrieving, creating, updating, transmitting, or deleting records, depending on the selected tool, granted scope, and user approval.

13.2 Customer authorization

Customer represents and warrants that it has authority to:

  • connect the selected MCP client or integration;
  • disclose the relevant Customer Personal Data to that service;
  • permit the requested actions;
  • authorize its users to grant scopes and approve tool calls; and
  • instruct Schemon to transmit results to the selected service.

Customer will apply data minimization, least privilege, appropriate approval controls, and any required human review before sensitive or consequential actions.

13.3 Customer-Selected Third-Party Services are not automatically Subprocessors

A third-party AI provider, MCP client, or connected service is not a Schemon Subprocessor solely because Customer or an authorized user directs Schemon to exchange Customer Personal Data with it using Customer's own account, workspace, credentials, or contractual relationship.

For a Customer-Selected Third-Party Service:

  • Customer is responsible for selecting the provider and reviewing its privacy, retention, data residency, security, model-improvement, and deletion terms;
  • the third party Processes data under its agreement with Customer or the authorized user;
  • Schemon is not responsible for the third party's Processing after the data is transmitted, except to the extent required by law or expressly stated in the Agreement; and
  • disconnecting the service prevents future access but does not automatically delete data already retained by the third party.

OpenAI and Anthropic products may be Customer-Selected Third-Party Services when a Customer uses its own OpenAI or Anthropic account or client to access a Schemon MCP server.

13.4 Schemon-managed AI providers

If Schemon separately engages an AI provider under Schemon's own contract to Process Customer Personal Data as part of a Schemon-managed feature, that provider is a Subprocessor and is subject to Section 12 and Appendix 2.

13.5 Authentication, authorization, and logs

Schemon may Process connection identifiers, OAuth or access tokens, granted scopes, tool names, parameters, results, approval records, security events, and diagnostic logs to provide and secure MCP functionality. Schemon will apply the retention periods in Appendix 1 and the safeguards in Appendix 3.

Customer is responsible for protecting credentials under its control, reviewing granted permissions, revoking unused connections, and promptly reporting suspected compromise.

13.6 No transfer of Customer obligations

MCP functionality does not transfer Customer's Controller obligations to Schemon. Customer remains responsible for determining whether a tool call, data disclosure, or automated action is lawful and appropriate for the relevant Data Subjects and use case.

14. International Transfers

14.1 Transfer mechanisms

Schemon and its Subprocessors may Process Customer Personal Data in the United States, the EEA, the United Kingdom, and other countries. Schemon will ensure that Restricted Transfers are supported by a valid transfer mechanism and any supplementary measures required by Applicable Data Protection Law.

14.2 EU Standard Contractual Clauses

For a Restricted Transfer of Customer Personal Data from the EEA to Schemon in a country not recognized as providing adequate protection, the SCCs are incorporated into this DPA by reference and completed as follows:

  1. Module Two (Controller to Processor) applies when Customer is a Controller.
  2. Module Three (Processor to Processor) applies when Customer is a Processor on behalf of another Controller.
  3. Clause 7 (Docking Clause) applies.
  4. For Clause 9, Option 2 applies and the notice period is the period stated in Section 12.4 of this DPA.
  5. The optional language in Clause 11 does not apply.
  6. For Clause 17, Option 1 applies and the governing law is the law of Ireland.
  7. For Clause 18, the courts of Ireland have jurisdiction.
  8. The competent Supervisory Authority is determined in accordance with Clause 13 of the SCCs.
  9. Appendix 4, Part A provides the parties' details for Annex I.A.
  10. Appendix 1 provides the information required by Annex I.B.
  11. The competent Supervisory Authority under item 8 provides Annex I.C.
  12. Appendix 3 provides the technical and organizational measures required by Annex II.
  13. Appendix 2 provides the list of Subprocessors for Annex III.

If the SCCs conflict with this DPA, the SCCs control for the Restricted Transfer.

14.3 United Kingdom transfers

For a Restricted Transfer subject to the UK GDPR, the UK Addendum is incorporated into this DPA. The information in the Agreement and Appendices 1 through 4 completes the applicable tables of the UK Addendum. The parties select neither party as the party permitted to terminate the UK Addendum solely because the UK Information Commissioner's Office issues a revised approved addendum, unless the revised mandatory clauses require otherwise.

14.4 Swiss transfers

For a Restricted Transfer subject to the Swiss FADP, the SCCs apply with the following adaptations:

  • references to the EU GDPR include the Swiss FADP as applicable;
  • references to the European Union, EEA, or Member State include Switzerland;
  • references to a Supervisory Authority include the Swiss Federal Data Protection and Information Commissioner;
  • references to courts of a Member State include competent Swiss courts where required; and
  • the SCCs also protect Personal Data relating to legal entities to the extent protected by the Swiss FADP.

14.5 Other transfer mechanisms

If the SCCs, UK Addendum, or another transfer mechanism is invalidated or no longer available, the parties will cooperate in good faith to implement another valid mechanism. Schemon may rely on an adequacy decision, approved certification, binding corporate rules, or another lawful mechanism where available.

15. Return and Deletion

15.1 During the term

Customer may use available Service functionality to access, export, correct, or delete Customer Data during the Agreement term. Customer is responsible for exporting Customer Data it wishes to retain before the Account or Services are terminated.

15.2 After termination

At Customer's choice and on documented instruction, Schemon will return or delete Customer Personal Data after termination of the affected Services. Unless the Agreement or a written instruction states otherwise, Schemon may retain Customer Personal Data for up to 60 days after termination to support export, account recovery, and protection against accidental deletion, after which Schemon will delete or render it inaccessible from active systems.

15.3 Backups and legal retention

Customer Personal Data may remain in backups until overwritten or deleted through Schemon's normal backup rotation, provided the data remains protected and is not restored except for disaster recovery, continuity, security, or legal purposes. If law requires retention, Schemon will isolate and protect the retained data and Process it only for the required purpose.

15.4 Customer-Selected Third-Party Services

Schemon cannot delete Customer Personal Data retained by a Customer-Selected Third-Party Service. Customer must use that provider's deletion controls or contact the provider directly.

16. Term and Termination

This DPA remains in effect for as long as Schemon Processes Customer Personal Data. Sections that by their nature should survive, including confidentiality, international transfers, deletion, audit records, liability, and general terms, survive termination.

17. Liability

Each party is responsible for its own compliance with Applicable Data Protection Law. Liability arising from this DPA is subject to the exclusions, limitations, procedures, and aggregate caps in the Agreement, except to the extent Applicable Data Protection Law prohibits such limitation.

Nothing in this DPA limits a Data Subject's rights or remedies under the SCCs or other mandatory law.

18. Amendments

Schemon may update this DPA where reasonably necessary to:

  • comply with a change in Applicable Data Protection Law;
  • implement a new or replacement transfer mechanism;
  • reflect changes to the Services, subprocessors, or security measures; or
  • improve clarity or protection.

Schemon will provide notice of a material change as required by the Agreement or Applicable Data Protection Law. An update will not materially reduce Customer's data-protection rights during the current subscription term unless required by law or agreed by Customer.

19. General Terms

  1. This DPA supersedes prior data processing agreements between the parties concerning the same Processing, unless the parties expressly agree otherwise in writing.
  2. Customer may assign this DPA only together with the Agreement. Schemon may assign it as permitted by the Agreement.
  3. If a provision is invalid or unenforceable, it will be interpreted or replaced to best achieve its lawful purpose, and the remaining provisions continue in effect.
  4. Failure to enforce a provision is not a waiver.
  5. Notices under this DPA will be given using the notice method in the Agreement. Privacy and data-protection notices to Schemon may be sent to legal@schemon.com.
  6. Electronic acceptance of the Agreement or this DPA has the same effect as a signature.

Appendix 1 - Details of Processing

A. Subject Matter

Schemon Processes Customer Personal Data to provide, host, secure, maintain, support, and improve the Services selected by Customer, including web and mobile access, scheduling, communications, files, payments-related functionality, APIs, MCP servers, integrations, and customer support.

B. Duration

Processing continues for the term of the Agreement and the deletion period described in Section 15 and this Appendix, unless law requires a longer period.

C. Nature and Purpose of Processing

Schemon may perform the following operations on Customer Personal Data:

  • collection and receipt;
  • organization, structuring, and indexing;
  • storage, hosting, backup, and retrieval;
  • consultation, search, display, and export;
  • transmission and synchronization;
  • authentication, authorization, logging, and security monitoring;
  • scheduling, communications, collaboration, and workflow execution;
  • billing and payment-related processing;
  • support, troubleshooting, and incident response;
  • MCP tool and resource processing, including reading, creating, updating, transmitting, or deleting records as instructed;
  • restriction, deletion, anonymization, or return; and
  • other Processing initiated by Customer through the Services and consistent with the Agreement.

The purposes are to provide the Services, perform the Agreement, follow Customer instructions, maintain security and availability, provide support, and comply with applicable legal obligations.

D. Categories of Data Subjects

Depending on Customer's use, Data Subjects may include:

  • Customer's owners, directors, employees, contractors, administrators, and authorized users;
  • Customer's clients, customers, patients where permitted, service recipients, prospects, and contacts;
  • invitees, attendees, appointment participants, meeting participants, and event participants;
  • payers, payees, purchasers, and invoice recipients;
  • people appearing in messages, notes, files, recordings, transcripts, or other User Content;
  • support contacts and people whose information is included in a support request; and
  • other individuals whose Personal Data Customer lawfully submits to the Services.

E. Categories of Customer Personal Data

Depending on the Services and Customer configuration, Customer Personal Data may include:

Identity and contact data

  • name, surname, username, and profile information;
  • email address, telephone number, and mailing address;
  • organization, job title, role, and account permissions;
  • language, time zone, and communication preferences; and
  • identifiers assigned by Schemon, Customer, or a connected service.

Account and authentication data

  • login and authentication events;
  • hashed or otherwise protected authentication credentials;
  • multi-factor authentication status;
  • API keys, OAuth tokens, access tokens, scopes, and connection identifiers; and
  • administrator and permission records.

Scheduling and service data

  • appointments, availability, calendars, booking history, invitees, and attendance;
  • service descriptions, forms, intake responses, and workflow status;
  • customer relationship and service delivery records; and
  • notes and information submitted in connection with a scheduled or delivered service.

Communications and content

  • messages, chats, email content, comments, and notifications;
  • documents, files, images, audio, video, recordings, transcripts, and summaries;
  • support communications and attachments; and
  • any other User Content submitted by or for Customer.

Payment and business data

  • invoice and payment request information;
  • transaction identifiers, amount, currency, status, refunds, disputes, and payout status;
  • billing contact, tax, VAT, and company information; and
  • limited payment method information made available by a payment provider.

Technical and Usage Data

  • IP address, Device, browser, operating system, and app version;
  • identifiers, timestamps, session data, feature interactions, and diagnostic logs;
  • security, access, audit, crash, and performance data; and
  • push-notification tokens and app settings where applicable.

MCP and integration data

  • MCP client, server, tool, resource, prompt, and connection identifiers;
  • tool calls, arguments, parameters, scopes, approvals, and invocation metadata;
  • Customer records selected for retrieval or action;
  • tool results, errors, and diagnostic information; and
  • data exchanged with a Customer-Selected Third-Party Service or Schemon-managed Subprocessor at Customer's instruction.

F. Sensitive or Special Categories

Customer may submit sensitive or special-category Personal Data only as permitted by Section 4.1. Depending on Customer's lawful use, this could include health-related information, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, sex life or sexual orientation, biometric or genetic data, precise geolocation, financial information, or other data treated as sensitive by law.

Schemon does not intentionally require those categories for ordinary Account administration. Protected Health Information regulated by HIPAA is prohibited unless the parties execute a Business Associate Agreement.

G. Frequency

Processing may be continuous, recurring, or occasional, depending on Customer's use of the Services and integrations.

H. Retention Schedule

Unless a different period is agreed in writing or required by law:

  • Customer Personal Data in active Services: For the subscription term and up to 60 days after termination or applicable deletion instruction
  • IP, access, security, and Usage Data: Generally up to 12 months; longer where reasonably required for security, fraud, incident response, or law
  • Support case data and attachments: Generally 6 months after closure; longer for an ongoing matter, security, training, contract administration, or law
  • MCP connection, authorization, audit, and diagnostic data: Generally up to 12 months; underlying Customer records follow the retention period for that record
  • Payment, invoice, tax, and accounting data Processed as Customer Personal Data: For the service term or as instructed; Account Data retained by Schemon as Controller follows legal and financial retention requirements
  • Backups: Until overwritten or deleted under the applicable backup rotation, subject to Section 15.3

A Customer-Selected Third-Party Service applies its own retention period to data it receives.

Appendix 2 - Authorized Subprocessors and Provider Roles

The entities below are authorized to Process Customer Personal Data only to the extent the applicable service is used and the entity acts on Schemon's behalf.

A. Core Subprocessors

  1. Amazon Web Services, Inc. and applicable affiliates: United States, EEA, and Customer-configured or service-configured regions | Cloud infrastructure, compute, databases, file and object storage, backups, network services | Subprocessor for Customer Personal Data hosted in Schemon's AWS environment
  2. Cloudflare, Inc. and applicable affiliates: Global edge network, including the United States and EEA | DNS, content delivery, web application firewall, network performance, bot and abuse protection, security logging | Subprocessor for network identifiers, requests, and content processed to deliver and secure the Services
  3. Intercom R&D Unlimited Company, Intercom, Inc., and applicable affiliates: United States and/or available regional hosting locations | Customer support messaging, ticketing, support history, attachments, and support communications | Subprocessor for Customer Personal Data submitted to or synchronized with support services
  4. Stripe, LLC, Stripe Payments Europe, Limited, and applicable Stripe affiliates: United States, EEA, and other locations used by Stripe | Payment processing, billing, invoicing, fraud prevention, refunds, disputes, and related support | Subprocessor only for activities Stripe performs on Schemon's behalf; Stripe may act as an independent Controller for regulated payment, identity, fraud, or legal-compliance activities

B. Conditional Schemon-Managed AI Subprocessors

These providers are Subprocessors only when Schemon uses the provider under Schemon's own contract to deliver a Schemon-managed feature that Processes Customer Personal Data. They are not Subprocessors merely because Customer uses its own account or client to connect to a Schemon MCP server.

  1. OpenAI OpCo, LLC, OpenAI Ireland Ltd, and applicable affiliates: United States, EEA, and other locations described in OpenAI's applicable service and subprocessor documentation | AI inference, content processing, tool orchestration, or related AI functionality | Applies only to a Schemon-managed OpenAI API, business, or enterprise service used to provide the Services. Customer-connected OpenAI accounts or clients are Customer-Selected Third-Party Services.
  2. Anthropic, PBC and applicable affiliates: United States and other locations described in Anthropic's applicable service and subprocessor documentation | AI inference, content processing, tool orchestration, or related AI functionality | Applies only to a Schemon-managed Anthropic API or commercial service used to provide the Services. Customer-connected Anthropic accounts or clients are Customer-Selected Third-Party Services.

C. Customer-Selected Third-Party Services

A provider selected and contracted directly by Customer or an authorized user is not included in the authorized Subprocessor list solely because Schemon exchanges data with it at Customer's instruction. Examples may include an OpenAI or Anthropic product used as the MCP client, a customer-owned calendar or communications account, or another connected application.

Customer is responsible for the provider's terms, legal basis, configuration, retention, deletion, international transfers, and any required data processing agreement with that provider.

Appendix 3 - Technical and Organizational Measures

Schemon maintains a security program designed to protect Customer Personal Data. The specific controls may evolve, but Schemon will maintain an overall level of protection appropriate to the risks of the Processing.

1. Governance and Risk Management

  • Documented security and privacy policies appropriate to Schemon's size, services, and risk profile.
  • Assigned security and incident-response responsibilities.
  • Periodic risk assessments and review of material changes.
  • Vendor and Subprocessor due diligence appropriate to the data and service involved.
  • Confidentiality obligations and acceptable-use requirements for personnel.

2. Identity and Access Management

  • Unique user accounts for personnel with system access.
  • Strong, unique credentials managed using an encrypted password-management system.
  • Multi-factor authentication for critical and high-risk systems.
  • Role-based access and the principle of least privilege.
  • Documented access requests, approval, changes, and revocation.
  • Prompt offboarding and removal of access when personnel leave or change roles.
  • Periodic access reviews, including at least semi-annual review of critical systems.
  • Logging of administrative and security-relevant access where appropriate.

3. Encryption and Transmission Security

  • Encryption of data in transit over public networks using TLS 1.2 or higher, or an equivalent current protocol.
  • Encryption at rest for production Customer Personal Data where appropriate to the system and risk.
  • Secure management of encryption keys and secrets using access controls and dedicated secret-management methods where appropriate.
  • Protection of API keys, OAuth tokens, access tokens, and other integration credentials.

4. Network, Infrastructure, and Cloud Security

  • Use of reputable cloud infrastructure providers with documented security and compliance programs.
  • Network filtering, firewalling, content delivery, and web application security controls appropriate to Internet-facing services.
  • Segmentation and environment separation appropriate to development, testing, and production.
  • Monitoring for suspicious activity, abuse, and availability incidents.
  • Protection against common web application and infrastructure threats.

5. Secure Software Development

  • Documented development and change-management practices.
  • Code review before production deployment for material changes.
  • Automated testing and manual testing appropriate to the change.
  • Dependency, source code, and vulnerability scanning.
  • Security review of material architectural changes and high-risk features.
  • Remediation processes that prioritize findings based on severity and exploitability.
  • Restricted production access and controlled deployment mechanisms.

6. Vulnerability Management

  • Regular vulnerability scanning of relevant systems and software.
  • Monitoring of security advisories and dependencies.
  • Risk-based remediation timelines.
  • Coordinated vulnerability disclosure process.
  • Penetration testing or equivalent independent testing where appropriate to risk and maturity.

7. Logging, Monitoring, and Incident Response

  • Centralized or otherwise controlled collection of relevant application, infrastructure, and security logs.
  • Monitoring and escalation processes for availability and security incidents.
  • Documented incident-response procedures covering identification, containment, investigation, remediation, recovery, and communication.
  • On-call or escalation coverage appropriate to the Service.
  • Preservation of relevant evidence and post-incident review.
  • Customer and public communications where required, including use of Schemon's status or security channels where appropriate.

8. Availability, Backup, and Recovery

  • Backups appropriate to the nature of the Service and Customer Personal Data.
  • Restricted access to backups and protection against unauthorized alteration.
  • Recovery procedures and periodic testing appropriate to service criticality.
  • Capacity, availability, and incident-management processes.
  • Business continuity and disaster-recovery planning appropriate to Schemon's risk profile.

9. Data Minimization, Segregation, and Deletion

  • Processing limited to data reasonably needed for the Services and Customer instructions.
  • Logical separation of Customer environments or records using account, tenant, authorization, or equivalent controls.
  • Retention controls and deletion processes for active systems.
  • Backup expiration and secure media disposal processes.
  • Restrictions on using production Customer Personal Data in development or testing, except where necessary and protected.

10. Personnel Security and Training

  • Screening where lawful and appropriate to role.
  • Security and privacy awareness during onboarding.
  • Periodic training and policy reminders.
  • Confidentiality obligations that continue after employment or engagement ends.
  • Disciplinary and access-removal processes for policy violations.

11. Support Security

  • Access to support data limited to authorized personnel with a business need.
  • Customer verification and case-management controls appropriate to the request.
  • Secure handling of files, screenshots, recordings, HAR files, and diagnostic information.
  • Instructions to Customers to remove unnecessary sensitive information before submitting support materials.

12. MCP and Integration Security

  • Authentication and authorization checks for MCP requests and integration calls.
  • Scope and permission controls designed to limit access to authorized tools and data.
  • Revocation and disconnection mechanisms for supported integrations.
  • Logging of security-relevant connection and tool activity where appropriate.
  • Protection of OAuth tokens, access tokens, API keys, and connection secrets.
  • Input validation, rate limiting, and abuse-prevention controls appropriate to exposed tools.
  • Approval or confirmation controls for sensitive actions where supported by the selected MCP client and Schemon feature.
  • Data minimization in tool results and error messages where reasonably practicable.
  • Review of Schemon-managed AI providers and contractual restrictions on use of Customer Personal Data.

Appendix 4 - Transfer Parties and SCC Information

Part A - Parties

Data exporter

  • Name: The Customer identified in the Agreement.  
  • Address: The Customer address in the Agreement or Account.
  • Contact: The Customer privacy or legal contact stated in the Agreement, Account, or written notice to Schemon.
  • Activities relevant to the transfer: Use and administration of the Services and submission of Customer Personal Data.  
  • Role: Controller or Processor, as described in Section 2.

Data importer

  • Name: Schemon Inc.  
  • Address: Christiana Corporate Business Center, 200 Continental Dr, Suite 401, PMB 1578, Newark, Delaware 19713, United States.  
  • Contact: legal@schemon.com
  • Activities relevant to the transfer: Provision, hosting, security, support, and maintenance of the Services.
  • Role: Processor or Subprocessor, as described in Section 2.

Electronic acceptance of the Agreement and DPA constitutes signature of the SCCs to the extent a signature is required.

Part B - Description of Transfer

The categories of Data Subjects, categories of Personal Data, sensitive data, frequency, nature, purpose, duration, retention, and Processing operations are described in Appendix 1.

Transfers may occur continuously or intermittently through Customer's use of the Services, including web and mobile access, API calls, MCP tool calls, integrations, support, storage, and synchronization.

Part C - Competent Supervisory Authority

The competent Supervisory Authority is determined under Clause 13 of the SCCs. Where that determination permits more than one authority, the parties will select the authority with the closest connection to the affected Data Subjects and Processing.