Effective October 7, 2026
This Data Processing Agreement (the "DPA") is between Foxx Cyber LLC, which operates RailCompliant ("we," "us"), and each organization that subscribes to the Service ("Customer," "you"). It forms part of our Terms of Service (the "Terms") and applies to the personal information in Customer Data. Accepting the Terms for an organization account accepts this DPA; there is nothing separate to sign.
Individual accounts are not covered. For a free individual account, and for what a person keeps in it, we decide what is collected and why, so we are the controller and our Privacy Policy applies instead.
When you are the controller of the Customer Personal Data, we are your processor. When you process it on behalf of someone else, we are your subprocessor.
| Subject matter and purpose | Providing the Service: recording locomotive inspections, tests, maintenance, and related operational data, and generating reports from those records |
| People the data is about | Your users, and the crew members, volunteers, and contract inspectors you record |
| Kinds of personal data | Names, work email addresses, and roles of your users; the names, roles, qualifications, and hours you choose to record for your crew and volunteers; names on the records they sign; and anything else you choose to enter or upload |
| Special category data | None is needed to use the Service. Don't enter it unless you must |
| How often | Continuously, while you use the Service |
| How long | For the term of the Terms, and then as Section 9 below describes |
If we add features that change any of these, we will tell you what changed.
You instruct us to process Customer Personal Data (a) to provide and maintain the Service; (b) as you direct through your use of the Service; (c) as the Terms describe; and (d) as you otherwise instruct us in writing and we acknowledge. We follow these instructions unless the law prohibits it, and we will tell you promptly if we can't follow one. Your instructions must comply with the law.
You are responsible for having given any notices and obtained any consents the law requires for the personal information you put into the Service. If you are yourself a processor, you will comply with the law and with your agreement with your controller.
You approve the subprocessors listed in "Who we share it with" in our Privacy Policy. We will tell you at least 10 business days before we add or replace one, by email or in the Service. You may object within 30 days of that notice; otherwise the change is accepted. If you object, we will work with you in good faith to resolve it.
We will have a written agreement with each subprocessor that lets it use Customer Personal Data only as needed to do the work we give it, and consistently with the Terms. On request, we will tell you where to read the terms of that agreement, or give you a copy where the agreement allows. We remain responsible for our subprocessors' processing of Customer Personal Data, and we will tell you if one fails to meet a material obligation about it.
The Service is hosted in the United States, and Customer Data is stored there (Privacy Policy, "Where data is stored"). If you need to send us Customer Personal Data protected by the GDPR, the UK GDPR, or Swiss law, tell us before you do: standard contractual clauses or the UK addendum apply only when we sign them with you.
If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data, we will (a) notify you without undue delay, and no later than 72 hours after we become aware of it; (b) give you timely information about it as we learn it or as you reasonably ask; and (c) promptly take reasonable steps to contain and investigate it. Notifying you or responding to an incident is not an admission of fault or liability.
We will give you the information reasonably necessary to show that we comply with this DPA. We will answer reasonable written security and due-diligence questions, including questionnaires, sent to [email protected], up to once a year. You agree to use this process to exercise any audit rights you have under this DPA or data protection law. We may hold back information whose disclosure would harm our intellectual property or break a confidentiality or legal obligation. We keep records of our compliance with this DPA for 3 years after it ends.
If anyone else asks us about our processing of Customer Personal Data, such as a person the data is about, a court, or a regulator, we will tell you where the law allows, and we will not respond without your consent unless the law requires us to. We will follow your reasonable instructions about the request and help you answer it, including a valid request from a person to delete their data. Help with a legal or procedural response to a third party is at your expense.
Where the law requires it, we will reasonably help you with data protection impact assessments, transfer impact assessments, and consultations with a data protection authority.
You can delete Customer Personal Data in the ways the Service offers. Some records are deliberately immutable: the audit trail keeps a tamper-evident history, so a correction is a new entry rather than an edit (Privacy Policy, "How long we keep it"). After the Terms end, you may request an export within 30 days, after which we delete Customer Data from active systems, and copies in routine backups age out on our normal backup cycle (Terms, Section 6). Where the law requires us to keep some of it, we will protect what we keep and not process it further.
Each party's liability under this DPA is subject to the limits in the Terms, to the extent data protection law allows. Only the Customer that accepted the Terms may bring a claim under this DPA. This DPA does not limit any liability to a person for their rights under data protection law.
For Customer Personal Data, if this DPA and the Terms conflict, this DPA controls, and any standard contractual clauses we sign with you control over both. This DPA lasts as long as the Terms do for your organization account, and both of us remain bound by it until we stop processing Customer Personal Data.
"Customer Personal Data" means personal information in the Customer Data you put into the Service under an organization account. "Controller," "processor," "subprocessor," "personal information," and "processing" have the meanings given in the data protection law that applies. Other capitalized words have the meanings given in the Terms.
See also our Terms of Service and Privacy Policy.
This DPA is adapted from the Common Paper Data Processing Agreement Standard Terms, Version 1.1 (© Common Paper, Inc.), used under CC BY 4.0. We changed it: we put it in plain language for a public page, filled in our details, removed the cover page and the third-party audit reports, and replaced the automatic standard contractual clauses with clauses signed on request. Common Paper does not endorse this version, and the original is provided without warranties.