11.1 Customer Is Sole Controller. You are the sole controller, business, owner, operator, and responsible party for all Customer Data and all Personal Data processed in or through AdvisorClaw or Customer Infrastructure.
11.2 IDX Is Not a Processor. IDX is not a processor, service provider, vendor, subprocessor, business associate, custodian, managed service provider, data host, or data operator with respect to Customer Data or Personal Data processed in Customer Infrastructure or AdvisorClaw. No data processing relationship is created with respect to your deployments, prompts, inputs, outputs, memory, workspaces, files, logs, client data, regulated records, or Personal Data.
11.3 Limited IDX Data. IDX may collect limited information directly through its websites, onboarding processes, marketing, communications, license administration, acceptance logging, or other IDX-operated systems. Such information may include firm name, contact name, email, phone number, title, RIA or firm details, voluntarily submitted onboarding information, timestamped acceptance records, IP address, browser and device information, referring URLs, pages visited, anonymous analytics, cookies or similar technologies, inquiries, emails, and limited support or implementation communications.
11.4 No Customer Deployment Visibility. Except for temporary, Customer-authorized implementation access under Section 4.5, IDX does not host, operate, monitor, store, process, or have ongoing visibility into Customer deployments, prompts, inputs, outputs, memory, configurations, client data, regulated records, or Personal Data processed in AdvisorClaw.
11.5 Customer Data Must Not Be Sent to IDX. You shall not upload, input, transmit, email, disclose, or otherwise make available to IDX any client PII, nonpublic personal information, confidential client data, regulated records, financial information, protected data, or other sensitive Customer Data unless IDX expressly requests such information in writing for a limited purpose. If you provide such information without written request, you do so at your sole risk and remain solely responsible for all consequences.
11.6 Customer Privacy Compliance. You are solely responsible for compliance with all privacy, data protection, cybersecurity, consumer protection, and financial privacy laws and rules, including Regulation S-P, GDPR, CCPA/CPRA, state privacy laws, data breach notification laws, financial services privacy rules, contractual privacy commitments, and any client consents or notices required for use of AdvisorClaw.
11.7 Customer Security Measures. You represent, warrant, and covenant that you have implemented and will maintain appropriate technical, administrative, physical, and organizational measures, policies, procedures, training, access controls, encryption, monitoring, logging, incident response, breach response, and vendor oversight for all Customer Data and Customer Infrastructure.
11.8 Data Subject Requests. You are solely responsible for responding to all data subject requests, consumer privacy requests, client requests, deletion requests, access requests, correction requests, portability requests, opt-out requests, regulator requests, and similar obligations related to Customer Data or Customer Infrastructure. IDX has no ability or obligation to assist with data in Customer Infrastructure. IDX may provide reasonable assistance only for limited data it directly controls, subject to reimbursement of all costs and these Terms’ liability limitations.
11.9 Security Incidents and Breach Notification. You are solely responsible for security, breach prevention, breach detection, incident response, investigation, remediation, notification, regulatory reporting, client communication, and all related obligations for Customer Infrastructure and Customer Data. IDX has no access obligation and assumes no responsibility for such matters. For any limited data IDX directly holds in IDX-operated systems, IDX will notify you without undue delay of a confirmed security incident affecting that data where required by law.
11.10 Audits. You may not audit IDX systems, code, processes, controls, infrastructure, software, deployments, or operations except as required by applicable law and only upon reasonable advance written notice, at your sole expense, subject to IDX security, confidentiality, legal, and operational requirements. Any audit is strictly limited to IDX’s limited website and onboarding data practices. No audit of AdvisorClaw code, IDX proprietary materials, deployments, customer environments, security architecture, or implementation methods is permitted except as expressly required by law.
11.11 Return or Deletion. You are solely responsible for managing, retaining, deleting, exporting, backing up, archiving, or destroying all data in Customer Infrastructure and AdvisorClaw deployments. Upon termination of access to IDX-operated onboarding or licensing systems, IDX may delete limited onboarding data it controls in accordance with its retention practices, except that IDX may retain acceptance logs and other information as necessary for legal, evidentiary, compliance, enforcement, or legitimate business purposes.
11.12 No Sale of Personal Information. IDX does not sell or rent limited personal information collected through IDX-operated onboarding or website systems and does not share such information for third-party marketing.
11.13 Limited Uses of IDX-Collected Data. IDX may use limited information it directly collects to process onboarding, verify legal acceptances, administer licenses, respond to inquiries, provide limited implementation communications, perform internal analytics, maintain website security, prevent fraud, comply with law, send mandatory notices, enforce these Terms, and protect IDX rights.
11.14 Limited Disclosures by IDX. IDX may disclose limited information it directly collects to service providers under confidentiality obligations, to comply with law, regulation, subpoena, court order, or government request, including SEC or FINRA requests, in connection with a merger, acquisition, financing, restructuring, sale, or corporate transaction, or to enforce these Terms and protect IDX rights.
11.15 No Automated Legal Decisions. IDX does not use limited onboarding or website data for automated decision-making with legal or similarly significant effects, profiling, or sale of personal information.
11.16 Rights and Choices. Subject to applicable law, you may request access, correction, or deletion of personal information IDX directly controls by contacting IDX. IDX may verify requests and may retain information as required or permitted for legal, evidentiary, compliance, enforcement, security, or legitimate business purposes. IDX does not honor Do Not Track signals at this time.
11.17 Children. IDX-operated websites, onboarding systems, and AdvisorClaw are not intended for persons under 18. You shall not permit persons under 18 to use AdvisorClaw.
11.18 International Transfers. IDX is based in the United States. Limited information collected directly by IDX may be processed in the United States or other jurisdictions. By using IDX-operated websites, onboarding systems, or related services, you consent to such transfers. IDX assumes no additional liability for international transfers.
11.19 Privacy Updates. IDX may update its privacy practices and these Terms at any time. Continued use after updates constitutes acceptance.
11.20 Privacy and Data Indemnity. You agree to defend, indemnify, and hold harmless IDX from and against all claims, damages, losses, liabilities, fines, penalties, costs, and expenses, including attorneys’ fees, arising from Customer Data, your processing of Personal Data, your breach of privacy or data protection laws, any security incident in Customer Infrastructure, any regulatory action related to AdvisorClaw use, or any claim that IDX is responsible for data handling, security, privacy, breach response, or compliance in Customer Infrastructure.