US State Privacy / Service-Provider Addendum (to the DPA)
Last updated: 2026-06-26
> About this Addendum. This US State Privacy / Service-Provider Addendum (this "Addendum") is a schedule to, and incorporated by reference into, the Recovea Data Processing Addendum (the "DPA"), which is in turn incorporated into the agreement between the Customer and Recovea, Inc. governing the Customer's use of the Services (the "Agreement"). Where Recovea Processes Customer Personal Data on the Customer's behalf, the DPA — including this Addendum and the CCPA/CPRA service-provider terms — is automatically incorporated into and forms part of the Agreement. This Addendum governs Recovea's handling of Personal Information (as defined below) that is subject to one or more US State Privacy Laws and that Recovea Processes on the Customer's behalf in connection with the Services. It exists to establish, in writing and with the specificity those laws require, that Recovea acts as a service provider / processor — not a "third party," "seller," or "sharer" — for such Personal Information, and to flow down the consumer-rights, purpose-limitation, de-identification, and deletion covenants that the US State Privacy Laws require a business to impose on its service providers and processors. > > Recovea is a bootstrap-funded US company; nothing in this Addendum concerns investment or securities. Recovea's operations and hosting are United States–only (AWS US East (N. Virginia), us-east-1). This Addendum addresses US state privacy law only. The cross-border transfer mechanics for the EEA, UK, and Switzerland (EU Standard Contractual Clauses Module Two, the UK International Data Transfer Addendum, and the Swiss amendments) live exclusively in the DPA's international-transfer annexes and remain dormant given Recovea's US-only posture; nothing in this Addendum is a representation about, or a mechanism for, international data transfers, and this Addendum is not the EU SCC module.
1. Definitions
1.1 Capitalized terms. Capitalized terms used but not defined in this Addendum have the meanings given to them in the DPA or, if not defined there, in the Agreement. The following terms have the meanings set out below.
1.2 "US State Privacy Laws" means, collectively and each as amended and supplemented by their implementing regulations, the comprehensive consumer-privacy statutes of US states as in effect and applicable to a given act of Processing, including, without limitation:
- the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its regulations (collectively, the "CCPA");
- the Virginia Consumer Data Protection Act ("VCDPA");
- the Colorado Privacy Act ("CPA");
- the Connecticut Data Privacy Act ("CTDPA");
- the Utah Consumer Privacy Act ("UCPA");
- the Texas Data Privacy and Security Act ("TDPSA");
and the analogous comprehensive consumer-privacy laws of Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Maryland, Indiana, Tennessee, Kentucky, Rhode Island, and any other US state, as and when each becomes effective and applicable. References in this Addendum to a category of statutory role or right apply under each US State Privacy Law in which an equivalent concept exists, whether or not that law uses the identical term.
1.3 Statutory terms. The terms "Personal Information," "Personal Data," "sell," "sale," "share," "sharing," "business," "business purpose," "commercial purpose," "service provider," "contractor," "processor," "controller," "third party," "consumer," "deidentified" / "de-identified," "aggregate consumer information," "process" / "processing," and "sensitive personal information" / "sensitive data" have the meanings given to them under the applicable US State Privacy Law. Where a term is defined differently across states, it has the meaning given under the US State Privacy Law that applies to the relevant Processing. In this Addendum, "Personal Information" is used as the umbrella term and includes "Personal Data" as defined under the non-California US State Privacy Laws.
1.4 "Customer Personal Data" means Personal Information that Recovea Processes on the Customer's behalf as a service provider / processor in the course of providing the Services. "Covered Personal Information" means Customer Personal Data that is subject to one or more US State Privacy Laws. Covered Personal Information consists of all Customer Personal Data subject to a US State Privacy Law, including without limitation Personal Information contained within Inference Content (the prompts, requests, responses, and associated payloads that the Customer or its Authorized Users transmit through the in-path gateway), within the Usage Data metadata derived from that traffic (including any Customer-supplied tenant or member identifiers), within data ingested through Customer-authorized connectors, and within observation signals generated by Customer-configured features, in each case to the extent it relates to an identified or identifiable consumer. Covered Personal Information does not include (i) Personal Information that Recovea Processes as a business or controller for its own purposes (for example, the Customer's account-administrator and billing contacts, prospect and marketing data, and personnel data), which is governed by the Recovea Privacy Notice and not by this Addendum, or (ii) Aggregated/De-identified Data as described in Section 8.
1.5 "Services" means the Recovea in-path AI-spend observability, control, and cost-optimization gateway and all related products, applications, features, tooling, APIs, and capabilities that Recovea makes available, together with any optimization, additional features and capabilities Recovea may offer that Recovea may include from time to time. Any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this Addendum unless Recovea expressly states otherwise.
1.6 "Customer" is the business or controller with respect to Covered Personal Information. Where the Agreement uses "Client," "Subscriber," or a similar term for the contracting customer, that term has the same meaning as "Customer" here.
1.7 "Recovea," "we," "us," and "our" mean Recovea, Inc., a Delaware corporation, with its registered notice address at 2810 N Church St STE 89986, Wilmington, DE 19802. Recovea is the service provider / processor with respect to Covered Personal Information.
1.8 "Provider" means a third-party artificial-intelligence model or inference provider (for example, OpenAI, Anthropic, or OpenRouter) with which the Customer maintains its own account and to which the Customer's traffic is routed using the Customer's own Provider Keys. "Provider Keys" means the Customer's own API credentials for its Provider accounts.
2. Roles of the Parties; Conduit / Service-Provider Characterization
2.1 Service provider / processor, not third party. With respect to Covered Personal Information, the Customer is the business/controller and Recovea is a service provider (CCPA) and a processor (VCDPA, CPA, CTDPA, UCPA, TDPSA, and the other US State Privacy Laws). The Customer discloses, makes available, or causes to be transmitted Covered Personal Information to Recovea solely so that Recovea may perform the Services on the Customer's behalf, for the following limited and specified business purposes (collectively, the "Permitted Purpose"): (a) receiving, routing, and proxying the Customer's inference requests in path to the Customer's chosen Providers on the Customer's own Provider Keys; (b) metering and attributing the Customer's inference spend and usage by request, model, route, and tenant, and presenting that observability to the Customer; (c) operating the Customer's configured cost-control mechanisms, including spend caps, kill-switches, budget thresholds, alerts, and rate and route controls; (d) serving byte-identical exact-cache responses and performing de-duplication and single-flight collapsing of redundant requests to reduce the Customer's Provider spend; (e) generating, maintaining, and re-deriving the hash-chained, append-only metering ledger and the associated billing, invoicing, and reconciliation records that evidence the Customer's spend and Recovea's Fees; (f) providing security, fraud-prevention, troubleshooting, support, and service-improvement activities directly in furtherance of the foregoing; and (g) performing any additional Service capability the Customer activates under the Agreement, including its incorporated schedules and addenda, for the business purposes specified there. Recovea does not receive Covered Personal Information as consideration for any service or for any other thing of value, and the disclosure of Covered Personal Information to Recovea is not a sale or a share.
2.2 The BYO-Key conduit; Providers are the Customer's recipients, not Recovea's sub-processors. The Services operate on a "bring-your-own-key" model. The Customer brings and owns its Provider accounts, relationships, and Provider Keys, and pays the Providers directly. Recovea is a neutral, in-path conduit that proxies the Customer's traffic to the Customer's chosen Providers on the Customer's own Provider Keys. Recovea does not resell, mark up, sponsor, fund, or take custody of Provider tokens or Provider spend, and is not a party to the Customer's agreement with any Provider. Accordingly, and as stated identically across the DPA, the BYO-Key Addendum, and Recovea's privacy and security documentation:
(a) when Covered Personal Information is routed to a Provider, that Provider is acting as the Customer's processor, recipient, or independent controller under the Customer's own agreement with that Provider — not as a Recovea sub-processor; and
(b) Recovea's only sub-processors with respect to Covered Personal Information are the cloud-infrastructure and platform vendors identified in the DPA's sub-processor schedule, which is the single source of truth for the current roster. Recovea does not engage the Providers as sub-processors and assumes no responsibility for the Customer's Provider relationships, the Providers' terms, or the Providers' Processing of Covered Personal Information once routed at the Customer's direction.
2.3 No sale or share by Recovea. Recovea does not "sell" or "share" (as those terms are defined under the CCPA, including for cross-context behavioral advertising) Covered Personal Information, and does not retain, use, or disclose Covered Personal Information for any of those purposes. Recovea does not engage in any activity with respect to Covered Personal Information that would constitute "targeted advertising," "selling," or a "sale" under any other US State Privacy Law.
2.4 No combining; no independent use. Recovea will not combine Covered Personal Information that it receives from or on behalf of the Customer with Personal Information that Recovea receives from or on behalf of any other person, or that Recovea collects from its own interaction with a consumer, except as expressly permitted by the applicable US State Privacy Law to perform a business purpose. Recovea does not build or augment consumer profiles, and does not enrich Covered Personal Information with data from other sources. The de-identification and aggregation reservation in Section 8 is the sole exception and is exercised only in accordance with that Section and applicable law.
2.5 Routing is not automated decision-making about consumers. The Services route, cache, meter, and record the Customer's inference traffic at the Customer's configuration. Recovea does not make, and the Services do not perform, decisions that produce legal or similarly significant effects concerning any consumer, and Recovea conducts no profiling of consumers. Any duties that a US State Privacy Law imposes on a controller in connection with profiling, automated decision-making, sensitive-data processing, or data-protection assessments sit with the Customer as controller/business.
2.6 Customer responsibilities; permitted data. As the business/controller, the Customer represents, warrants, and covenants that, with respect to all Covered Personal Information it or its Authorized Users transmit through the Services, the Customer (a) has provided all consumer privacy notices and disclosures, and has obtained or maintained all consents, required under the US State Privacy Laws and other applicable law; (b) has the lawful authority and a valid legal basis to disclose, make available, and cause the transmission of that Personal Information (including any sensitive Personal Information) to Recovea for Processing under the Permitted Purpose; and (c) will not transmit any category of Personal Information that it lacks authority to disclose. In addition, the Customer must not submit through the Services any protected health information governed by HIPAA, payment-card (PCI) cardholder data, biometric identifiers, government-issued identification numbers, children's data, or other special-category or regulated data, unless separately agreed in a signed writing. Recovea is not a HIPAA Business Associate, and the Services are not HIPAA-, PCI-, or otherwise compliance-validated for such data. The Customer is solely responsible for compliance with the laws applicable to such data and for not transmitting it absent such a signed writing.
3. Purpose Limitation and Use Restrictions
3.1 Limited and specified purposes. Recovea will Process Covered Personal Information only (a) for the Permitted Purpose; (b) on, and in accordance with, the Customer's documented instructions, including as expressed through the Customer's configuration and use of the Services; and (c) as otherwise required or permitted by the applicable US State Privacy Law. Recovea will not Process Covered Personal Information for any purpose other than those specified in this Addendum, the DPA, or the Agreement.
3.2 No retention, use, or disclosure outside the relationship. Recovea will not retain, use, or disclose Covered Personal Information:
(a) for any purpose other than the business purposes specified in this Addendum, the DPA, or the Agreement, including not for any commercial purpose other than performing those business purposes, except as expressly permitted by the applicable US State Privacy Law;
(b) outside the direct business relationship between Recovea and the Customer, except disclosures made at the Customer's documented direction to a Customer-designated recipient (which are disclosures by the Customer, not by Recovea); or
(c) for the purpose of selling or sharing the Covered Personal Information, or for cross-context behavioral advertising or targeted advertising.
3.3 No improper monetization; no training. Recovea derives its revenue from the Fees the Customer agrees to pay — never from the Covered Personal Information itself. Recovea may offer subscription, usage-based, and savings-/outcome-based pricing models; any savings- or outcome-based model applies only on the Customer's separate, affirmative election under a separate written schedule. Recovea does not, and will not, monetize, license, sell, or trade Covered Personal Information, and does not condition any Fee on the content of Covered Personal Information. Recovea will not use Covered Personal Information, Service outputs, or the Ledger to train, fine-tune, or develop any machine-learning or artificial-intelligence model, except as strictly necessary to perform the Permitted Purpose and as permitted by applicable law.
3.4 Same level of protection. Recovea will comply with all applicable provisions of the US State Privacy Laws with respect to Covered Personal Information and will provide the same level of privacy protection as is required of businesses/controllers by those laws.
3.5 Certification. Recovea understands the restrictions in this Section 3 and in Section 2, and hereby certifies that it will comply with them. This certification is given for purposes of, and satisfies, the contractual-certification requirements of the CCPA (Cal. Civ. Code § 1798.140(ag), (ai), (j)) and the analogous requirements of the other US State Privacy Laws.
4. Personnel, Confidentiality, and Security
4.1 Confidentiality. Recovea will ensure that each person it authorizes to Process Covered Personal Information is subject to a binding contractual or statutory duty of confidentiality with respect to that Personal Information.
4.2 Security. Recovea will implement and maintain reasonable security procedures and practices appropriate to the nature of the Covered Personal Information. Those measures are the measures described in, and never exceeding, Recovea's Security Statement (which is the conservative anchor that no other Recovea document exceeds) and the DPA, and the Security Statement is the sole and authoritative description of Recovea's technical and organizational measures, including with respect to encryption, tenant isolation, access control, and session authentication. Recovea does not, in this Addendum, represent any security measure beyond, or any certification not stated in, the Security Statement, and does not currently hold a SOC 2, ISO 27001, or PCI attestation. Measures, certifications, or attestations not described as live in the Security Statement are not represented as currently in place.
4.3 No new sub-processors without the DPA's process. Recovea will engage sub-processors to Process Covered Personal Information only in accordance with the DPA, including the DPA's prior-notice and objection mechanics (advance notice of new sub-processors, an emergency carve-out providing as much notice as practicable, and an exclusive remedy of terminating the affected portion of the Services and receiving a pro-rata refund of pre-paid, unused Fees), which apply identically to Covered Personal Information. For the avoidance of doubt and as stated in Section 2.2, the Customer's Providers are not Recovea sub-processors.
5. Consumer-Request Flow-Down and Assistance
5.1 Enabling the Customer's compliance. Recovea will provide reasonable assistance to enable the Customer to comply with consumer requests made under the US State Privacy Laws, including requests to know/access, correct, delete, opt out of sale/share/targeted advertising, limit the use of sensitive personal information, appeal a controller's decision, and obtain a portable copy of Personal Information, in each case to the extent the relevant Covered Personal Information is within Recovea's possession, custody, or control and the Customer cannot reasonably fulfill the request through its own use of the Services (including the self-service controls and export and erasure tooling Recovea makes available).
5.2 Direct consumer contacts. If Recovea receives a request or complaint directly from a consumer (or a consumer's authorized agent) relating to Covered Personal Information, Recovea will not respond to the substance of the request other than to acknowledge receipt and to direct the consumer to the Customer, except where the applicable US State Privacy Law requires otherwise. Recovea will notify the Customer of the request without undue delay so that the Customer, as the business/controller, can respond, unless legally prohibited from doing so.
5.3 Opt-out preference signals and sensitive Personal Information. Because Recovea does not sell or share Covered Personal Information, does not engage in targeted advertising, and does not use sensitive Personal Information beyond performing the Permitted Purpose, Recovea does not undertake independent processing that would be governed by a consumer's opt-out preference signal (such as Global Privacy Control) or by a consumer's request to limit the use of sensitive Personal Information. Where the Customer, as business/controller, must give effect to such a signal or request with respect to Covered Personal Information, Recovea will, on the Customer's documented instruction, take the reasonable and proportionate steps within Recovea's control to assist. Recovea will treat any sensitive Personal Information within Covered Personal Information solely for the Permitted Purpose and the purposes that the applicable US State Privacy Law permits a service provider/processor to perform without separate consent.
5.4 Consumer appeals. Where a US State Privacy Law (including the VCDPA, CPA, CTDPA, and TDPSA) entitles a consumer to appeal the Customer's refusal to act on a request, Recovea will, on the Customer's documented instruction and taking into account the nature of the Processing and the information available to Recovea, provide reasonable cooperation and the information within Recovea's possession, custody, or control that the Customer reasonably needs to evaluate and respond to the appeal.
5.5 Manner and timing of assistance. Recovea will provide the assistance described in this Section taking into account the nature of the Processing and the information available to Recovea, and within a timeframe that allows the Customer to meet its statutory response deadlines, provided the Customer gives Recovea reasonable prior notice of the request. Recovea will provide such assistance at no additional charge for assistance reasonably necessary to respond to a routine, validly-verified consumer request; the Customer is responsible for verifying the identity and authority of the requesting consumer or agent.
5.6 Records and risk assessments. Recovea will make available to the Customer, on reasonable request, the information in Recovea's possession, custody, or control that is necessary to demonstrate Recovea's compliance with this Addendum and that the Customer reasonably needs to conduct or document the data-protection assessments, risk assessments, or records of processing required of the Customer under the US State Privacy Laws. Consistent with the VCDPA, CPA, and CTDPA, such a data-protection assessment may be conducted and documented through a reasonable and appropriate assessment, by the Customer (as controller) or by a qualified and independent assessor, and Recovea will reasonably cooperate with either approach. Recovea will not misrepresent any facts material to those assessments.
6. Customer Oversight Rights; Recovea Notice of Inability to Comply
6.1 Right to monitor. The Customer has the right to take reasonable and appropriate steps to help ensure that Recovea Processes Covered Personal Information in a manner consistent with the Customer's obligations under the US State Privacy Laws. Those steps include the audit and information rights set out in the DPA, which the Customer may exercise with respect to Covered Personal Information, and may include a reasonable and appropriate assessment conducted by the Customer or by a qualified and independent assessor as described in Section 5.6.
6.2 Right to stop and remediate. Upon reasonable notice, the Customer has the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Covered Personal Information by Recovea.
6.3 Recovea's notice of inability. Recovea will notify the Customer without undue delay after Recovea makes a determination that it can no longer meet its obligations under the applicable US State Privacy Laws with respect to Covered Personal Information. Following such a notice, the Customer may, in addition to its other remedies, instruct Recovea to take reasonable and appropriate steps to stop and remediate the unauthorized Processing.
7. Deletion, Return, and Retention; Ledger Integrity Carve-Out
7.1 Deletion or return on termination. Upon expiration or termination of the Agreement, or earlier on the Customer's written request, Recovea will, at the Customer's election and as further specified in the DPA, delete or return Covered Personal Information in Recovea's possession or control, and delete existing copies, except to the extent retention is required or permitted by applicable law. Recovea's standard retention windows are as stated in the DPA and Recovea's Retention practices, which are the single source of truth for those periods, and which apply identically across the pack.
7.2 Deletion in support of consumer delete requests. When the Customer instructs Recovea to delete specific Covered Personal Information in order to honor a consumer's deletion request, Recovea will delete that Personal Information from its active systems and instruct any applicable sub-processors to do the same, in each case within a commercially reasonable period and subject to Section 7.3.
7.3 Immutable Ledger integrity carve-out. The Services include the Ledger — a hash-chained, append-only, offline-re-derivable record of cost and usage events that serves as the integrity basis for Recovea's metering and invoicing. Deleting or altering rows within the Ledger would break the cryptographic chain that gives the Ledger its evidentiary value and would impair Recovea's ability to meet its own legal, tax, and accounting obligations. Accordingly, and as permitted by the US State Privacy Laws (which allow a business/processor to retain records as reasonably necessary for billing, security, legal compliance, and internal uses compatible with the consumer's expectations, and to maintain a record sufficient to honor an opt-out or deletion), when Covered Personal Information is subject to a deletion instruction or consumer deletion request, Recovea will:
(a) remove or render inaccessible the underlying Covered Personal Information from its active stores;
(b) sever the linkage between any retained Ledger entry and the consumer by nulling the identifier that links the entry to a particular consumer or tenant and replacing deleted content with a content-free tombstone that preserves the hash chain's integrity without retaining the Personal Information itself; and
(c) make an operator-run, customer-wide erasure workflow available to effect such erasure on request.
The record that Recovea retains under this Section is a content-free integrity record and is retained only as, and for as long as, permitted by applicable law. This carve-out is stated identically across Recovea's Privacy Notice, the DPA, its Retention practices, the Security Statement, the Acceptable Use Policy, and its Data-Rights handling.
7.4 Statutory retention. Recovea may retain Covered Personal Information to the extent and for the period required by applicable law (for example, billing and tax records retained for the period required under applicable law), in which case Recovea will continue to protect such Personal Information in accordance with this Addendum and limit its Processing to the purpose that requires its retention.
7.5 Body persistence. Recovea states the following identically in the DPA, the Privacy Notice, and the Security Statement. By default, Recovea persists only the Usage Data metadata derived from the Customer's traffic; request and response bodies (Inference Content payloads) are Processed in memory to perform the Services and are not written to durable storage by default. The byte-identical exact-cache is the exception: to serve a later byte-identical request without a redundant Provider call, Recovea persists the cached response content keyed by a salted hash of the request for a default time-to-live of twenty-four (24) hours, after which the cached entry expires and is purged. Any Customer-enabled (opt-in) captured-body retention is subject to the same twenty-four (24) hour default time-to-live unless the Customer configures a different value within the limits the Services allow. While cached or captured body content is stored, it is Covered Personal Information and is subject to the deletion, no-sale, security, and de-identification covenants of this Addendum; nothing in this Section is a representation that body content is never stored.
8. De-Identified and Aggregated Data Covenant
8.1 Reservation. Recovea may create and use Aggregated/De-identified Data derived from Covered Personal Information and Usage Data for the purposes described in the DPA and Privacy Notice, including operating, securing, supporting, troubleshooting, analyzing, and improving the Services and producing aggregated, non-identifying statistical insights, analytics, and measurement. The de-identification and aggregation of Covered Personal Information across the Customer's own traffic, and Recovea's use of the resulting Aggregated/De-identified Data to operate, secure, and improve the Services, are within the business purposes that the US State Privacy Laws permit a service provider/processor to perform. Aggregated/De-identified Data is not Covered Personal Information and is not subject to the consumer-rights or deletion provisions of this Addendum, provided Recovea meets the covenant in Section 8.2.
8.2 De-identification covenant. With respect to any information that Recovea treats as deidentified or as aggregate consumer information, Recovea will, in accordance with Cal. Civ. Code § 1798.140(m) and the analogous standards of the other US State Privacy Laws:
(a) take reasonable measures to ensure that the information cannot be associated with, and cannot reasonably be linked, directly or indirectly, to a particular consumer, household, or device;
(b) maintain and use the information only in a deidentified/aggregated form and not attempt to reidentify the information, except as a US State Privacy Law expressly permits solely to test that the de-identification is effective. Recovea's public commitment to this effect is published in, and incorporated by reference from, the de-identification section of the Recovea Privacy Notice; and
(c) contractually obligate any recipient of the information to comply with clauses (a) and (b).
8.3 Legitimate basis. Recovea's creation and use of Aggregated/De-identified Data is supported by a documented legitimate-interests/legitimate-business-purpose basis and is conducted consistent with the consumer's reasonable expectations. Recovea takes no position on the ownership of any Provider Output and asserts no ownership over Covered Personal Information.
9. Notification of Security Incidents
9.1 Recovea will notify the Customer of a confirmed breach of security leading to the unauthorized access, acquisition, disclosure, or loss of Covered Personal Information in Recovea's possession or control without undue delay after Recovea becomes aware of it, and will provide the information and cooperation described in the DPA's incident-response provisions to enable the Customer to meet its own breach-notification obligations under the US State Privacy Laws and applicable breach-notification statutes. The standard across all Recovea documents is "without undue delay"; Recovea does not commit to a fixed notification-hour deadline that its operations cannot reliably meet. Security-specific notices to Recovea may be sent to security@recovea.ai.
10. Relationship to the DPA, the Agreement, and US-Only Posture
10.1 One framework; this Addendum is US-state-specific. This Addendum supplements and forms part of the DPA. It addresses the requirements of the US State Privacy Laws specifically. The DPA's general processing terms (instructions, security, sub-processors, audit, incident response, deletion/return, and definitions) apply to Covered Personal Information except as expressly supplemented here.
10.2 Not the EU SCC module. This Addendum is not the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss amendments, and does not effect any international data transfer. Those mechanisms reside solely in the DPA's transfer annexes, apply only to Processing subject to EEA/UK/Swiss law, and remain dormant given Recovea's US-only operating posture. Recovea's ToS, MSA, and Privacy Notice point to the DPA for transfer mechanics and make no independent transfer representations.
10.3 Order of precedence. For matters concerning the Processing of Covered Personal Information, the order of precedence is: a signed Order Form (where it so states) → the MSA → the DPA (which controls for the Processing of personal data) → this Addendum (which controls for matters specific to the US State Privacy Laws) → the BYO-Key Addendum (which controls only on Provider Key handling, Provider Terms, Provider Charges, and runaway-spend allocation) → other incorporated policies → the ToS body. In the event of an irreconcilable conflict between this Addendum and another component of the Agreement with respect to a requirement of a US State Privacy Law applicable to Covered Personal Information, this Addendum controls to the extent of that conflict, but only as to such Personal Information and only to the extent necessary to comply with that law. The BYO-Key Addendum does not displace this Addendum, the DPA, or the liability and indemnity architecture of the Agreement.
10.4 No guarantee of savings, availability, or output. Nothing in this Addendum modifies, narrows, or supersedes the conspicuous AS-IS / AS-AVAILABLE disclaimers, the no-guarantee-of-savings posture, the absence of a contractual uptime SLA, or the fail-open design objective described in the Agreement. Recovea's cost levers that are live at launch are byte-identical exact-cache and de-duplication/single-flight only, the effects of which are described as "measured" or "applied," never "verified." Recovea does not represent that it can fail over a request mid-stream. Any additional or future cost-optimization, measurement, verification, or assurance capabilities are not active and bill nothing unless and until activated under a separate written schedule with separately disclosed terms. None of these commercial mechanics affects Recovea's status or obligations as a service provider/processor under this Addendum.
11. General Provisions
11.1 Limitation of liability. Each party's liability arising out of or related to this Addendum is subject to, and counts toward, the aggregate limitations of liability set out in the Agreement, which the parties restate here as follows so that the consequence of breaching this Addendum is determinate:
(a) Exclusion (mutual). Neither party is liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any lost profits, revenue, goodwill, or data, even if advised of the possibility.
(b) General cap. Subject to clauses (c) and (d), each party's aggregate liability is limited to the greater of (i) the total Fees paid by the Customer to Recovea in the twelve (12) months before the event giving rise to the liability, and (ii) US $25,000.
(c) Enhanced (super) cap. For a breach of confidentiality obligations or a breach of the data-protection or security obligations set out in this Addendum, the DPA, or the Agreement, each party's aggregate liability is limited to two times (2×) the General Cap in clause (b). This super-cap is symmetric and identical across the Agreement, the DPA, and the policies that incorporate this architecture by reference.
(d) Uncapped exclusions. The exclusion in clause (a) and the caps in clauses (b) and (c) do not apply to: a party's indemnification obligations; the Customer's payment obligations; the Customer's breach of the license, Acceptable Use, or IP-ownership terms; and a party's fraud or willful misconduct, in each case to the extent liability for it may not be limited under applicable law. A party's liability for gross negligence remains subject to the caps in clauses (b) and (c) to the fullest extent permitted by applicable law; where, and only to the extent, applicable law does not permit liability for gross negligence to be so limited, such liability is limited to the maximum extent that law permits.
(e) Basis of the bargain. The foregoing allocation of risk is a fundamental basis of the bargain between the parties and applies notwithstanding the failure of essential purpose of any limited remedy. This Addendum does not expand the Agreement's caps except where applicable law prohibits limiting a particular liability.
11.2 Indemnification. Indemnification obligations relating to the subject matter of this Addendum are governed by, and limited as set out in, the Agreement, and are restated here as follows:
(a) Recovea → Customer. Recovea will defend the Customer against any third-party claim that the Services as provided by Recovea infringe a US patent, copyright, or trade secret, and will indemnify the Customer for amounts finally awarded or agreed in settlement. This obligation does not apply to claims arising from: Provider outputs or Provider models; the Customer's Content, Data, or Provider Keys; any combination or modification of the Services not made by Recovea; or use outside the Documentation or in breach of the Agreement. Recovea's sole remedy obligation is, at its option, to procure the right to continue use, modify or replace the affected portion of the Services, or terminate the affected portion and refund prepaid, unused Fees. This indemnity is subject to the General Cap in Section 11.1(b) and is not uncapped.
(b) Customer → Recovea. The Customer will defend and indemnify Recovea against any third-party claim arising from the Customer's Content or Data, the Customer's BYO-Key and Provider use, or the Customer's use of the Services in violation of the Acceptable Use Policy or applicable law.
(c) Procedure. Indemnification is conditioned on the indemnified party giving prompt written notice of the claim, granting the indemnifying party sole control of the defense and settlement (subject to a settlement not imposing non-monetary obligations on the indemnified party without consent), and providing reasonable cooperation.
11.3 Warranty disclaimer. Except for the express commitments in this Addendum and the Agreement, the Services are provided AS IS and AS AVAILABLE, and Recovea disclaims all other warranties to the fullest extent permitted by law, as set out in the Agreement. This Addendum does not warrant any privacy or compliance outcome for the Customer, whose own compliance with the US State Privacy Laws as a business/controller remains its responsibility.
11.4 Governing law; dispute resolution; venue. This Addendum is governed by, and construed in accordance with, the laws of the State of Delaware, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods, consistent with the Agreement. Any dispute arising out of or relating to this Addendum will be resolved by binding arbitration before the American Arbitration Association (AAA) under its Commercial Arbitration Rules, by one arbitrator, seated in Wilmington, Delaware; judgment on the award may be entered in any court of competent jurisdiction. Each party brings claims only in an individual capacity and waives any class, collective, or representative action. Notwithstanding the foregoing, either party may bring (a) a claim for injunctive or other equitable relief for actual or threatened infringement or misuse of intellectual property or breach of confidentiality, and (b) a matter within the jurisdiction of a small-claims court, in the state or federal courts located in Wilmington, Delaware, to whose jurisdiction the parties consent. Each party bears its own fees as provided under the AAA Commercial Arbitration Rules; the parties intend the AAA Commercial Arbitration Rules to apply, subject to the Agreement's Consumer-Rules fallback and mass-arbitration protocol (Terms of Service §24.2 and §24.7 / MSA §23.2 and §23.6): if the AAA or a court of competent jurisdiction determines that the AAA Consumer Arbitration Rules apply to a dispute involving an individual, those rules govern that dispute and Recovea pays the filing, administrative, and arbitrator fees the AAA consumer fee schedule assigns to the business, this being a business-to-business service. Nothing in this Section subjects a non-contracting consumer to arbitration.
11.5 Assignment. Neither party may assign this Addendum except as permitted under the assignment provision of the Agreement; this Addendum assigns with the Agreement and the DPA to which it is attached.
11.6 Force majeure. The force-majeure provision of the Agreement applies to this Addendum, except that a force-majeure event does not excuse either party's core obligations to protect Covered Personal Information against unauthorized access, use, or disclosure.
11.7 Notices. Notices under this Addendum are given as provided in the Agreement, and may be sent to Recovea at 2810 N Church St STE 89986, Wilmington, DE 19802. Privacy- and data-protection-specific notices to Recovea may also be sent to privacy@recovea.ai; legal notices to legal@recovea.ai; and security notices to security@recovea.ai. Recovea is a US-only business and does not name an EU/UK data-protection officer or Article 27 representative, because none is required for its current operations.
11.8 Entire agreement. This Addendum, together with the DPA and the Agreement, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior or contemporaneous understandings on that subject.
11.9 Severability. If any provision of this Addendum is held invalid or unenforceable, that provision will be modified or severed to the minimum extent necessary, and the remaining provisions will continue in full force and effect.
11.10 Modification; updates for legal change. Recovea may update this Addendum as reasonably necessary to reflect changes in the US State Privacy Laws or Recovea's operations, provided that no update will materially diminish the protections afforded to Covered Personal Information. Updates are made in accordance with the change-and-notice mechanics of the Agreement and the DPA. The "Last updated" date above reflects the current version.
11.11 Survival. The provisions of this Addendum that by their nature should survive — including the definitions, the service-provider/processor characterization and BYO-key conduit terms, the purpose-limitation and use restrictions, the de-identification covenant, the Ledger integrity carve-out and retention terms, the body-persistence and fail-open disclaimers, the limitation of liability, indemnification, warranty disclaimer, and governing-law and dispute-resolution provisions — survive any expiration or termination of the Agreement, the DPA, or this Addendum.
11.12 Electronic signature and acceptance. The parties consent to the electronic formation, delivery, and acceptance of this Addendum. Acceptance of the Agreement or the DPA — including by clicking to accept, executing an Order Form, or continuing to use the Services — constitutes acceptance of this Addendum, which takes effect on the same date as, and for the term of, the DPA. An electronic record of acceptance has the same legal effect as a handwritten signature under the US E-SIGN Act and applicable state law.
11.13 No third-party beneficiaries. Except for the rights expressly conferred on consumers by the US State Privacy Laws themselves (which are not enlarged by this Addendum), this Addendum confers no rights on any third party.
End of US State Privacy / Service-Provider Addendum.