Data Processing Addendum
Effective 21 September 2026. This Addendum forms part of the Terms of Service between Imperium Advisors, LLC ("Luna") and the customer that has accepted them ("Customer"). Where this Addendum conflicts with the Terms, this Addendum controls as to the processing of Personal Information.
A note on why this document is shaped the way it is. Most SaaS data addenda are written around the GDPR. Luna's customers are US investment advisers, so the obligations that actually bind them come from Regulation S-P, the FTC Safeguards Rule, Advisers Act Rule 204-2 and the California service provider regime. This Addendum is written to those, in that order.
1. Definitions
"Personal Information" has the meaning given in Cal. Civ. Code § 1798.140(v), and includes Customer Information as defined in 17 C.F.R. § 248.30(e).
"Customer Data" means all data Customer or its Authorized Users submit to, or that Luna generates on Customer's behalf within, the Services, including Personal Information.
"Business Purposes" means the purposes set out in Section 3.
"Security Incident" means unauthorized access to or use of Customer Data, or of any information system on which Customer Data resides, as described in 17 C.F.R. § 248.30(a)(5).
A Security Incident does not include an unsuccessful attempt or an activity that does not compromise the security of Customer Data, including a failed login attempt, a ping, a port scan, a denial of service attempt, or another network attack on a firewall or networked system that does not result in access.
"Access Person" has the meaning given in 17 C.F.R. § 275.204A-1(e)(1).
2. Roles of the parties
Customer is the business, controller and owner of Customer Data. Luna is a service provider within the meaning of Cal. Civ. Code § 1798.140(ag) and a processor for the purposes of any other applicable privacy law.
Customer determines what data enters the Services and for what purpose. Luna processes it only on Customer's documented instructions, which the Terms, this Addendum and Customer's configuration of the Services together constitute.
Luna is not a financial institution for the purposes of the Gramm-Leach-Bliley Act and does not maintain a customer relationship with any natural person whose Personal Information it processes on Customer's behalf.
3. Business Purposes, and the limits on them
Luna processes Customer Data only to:
- provide, maintain and secure the Services;
- schedule, track and give notice of Customer's regulatory obligations;
- review materials Customer submits against the rules Customer selects;
- compute the risk indicators Customer has enabled, for Customer's review;
- retain records Customer is required to keep, for the period Customer sets;
- provide support Customer requests; and
- detect and prevent fraud, abuse and security incidents.
3.1 Service provider restrictions
Luna certifies the following, and gives each item effect as a contractual obligation under 11 C.C.R. § 7051(a). Luna:
- processes Personal Information only for the Business Purposes specified in Section 3, and for no other purpose;
- does not retain, use or disclose Personal Information for any purpose other than those Business Purposes, including any commercial purpose of its own;
- does not sell or share Personal Information, as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah), and receives no consideration of any kind for it;
- does not retain, use or disclose Personal Information outside the direct business relationship between Luna and Customer;
- does not combine Personal Information received from Customer with Personal Information received from any other source, except as permitted by 11 C.C.R. § 7050(b) for the purpose of detecting security incidents or protecting against fraudulent or illegal activity;
- complies with the obligations applicable to service providers under the CCPA and provides the same level of privacy protection the CCPA requires of Customer;
- permits Customer to take reasonable and appropriate steps to verify that Luna's use of Personal Information is consistent with Customer's obligations, as set out in Section 8;
- notifies Customer promptly, and in any event within five business days, if Luna determines it can no longer meet its obligations under the CCPA; and
- permits Customer, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
The parties acknowledge that Customer's disclosure of Personal Information to Luna forms no part of any monetary or other valuable consideration exchanged between them.
3.2 No training on Customer Data
Luna does not use Customer Data to train, fine-tune or evaluate any machine learning model, whether its own or a third party's.
Luna's model provider, Anthropic, PBC, commits in its commercial terms that it may not train models on customer content submitted through its API. Luna submits Customer Data to that API under those commercial terms and not under consumer terms.
Where Customer marks a finding as a false positive, Luna retains that flag and the associated finding identifier as a quality record. Luna does not use it as training data without Customer's separate written agreement.
4. Security Incidents
4.1 Notification
Luna notifies Customer of a Security Incident affecting Customer Data without unreasonable delay, and in no event later than 72 hours after Luna becomes aware of it.
Customer should note, and Luna acknowledges, that the trigger in 17 C.F.R. § 248.30(a)(5)(i)(B) is unauthorized access to or use of an information system on which customer information resides, and not confirmed exfiltration of data. Luna's notification obligation under this Section follows that standard rather than a narrower one.
4.2 Contents of the notice
Each notice states, to the extent then known: what happened and when; the categories and approximate volume of Customer Data involved; which of Customer's Authorized Users or Access Persons are affected; what Luna has done to contain it; and what Luna recommends Customer do. Luna supplements the notice as further facts are established, without waiting for Customer to ask.
4.3 Cooperation with Customer's own obligations
Customer, not Luna, decides whether an incident requires Customer to notify affected individuals under 17 C.F.R. § 248.30(a)(4), and makes any such notification. Luna provides the information Customer reasonably requires to make that assessment and to meet the 30-day notification period, at no charge.
4.4 Luna's incident response program
Luna maintains a written incident response program covering detection, assessment, containment, notification and post-incident review. Customer may request a summary of it, which Luna provides under Section 8.
5. Recordkeeping under Advisers Act Rule 204-2
5.1 Records held on Customer's behalf
Customer Data includes records Customer is required to make and keep under 17 C.F.R. § 275.204-2, including advertisements and the record of their review, code of ethics reports, and records of Access Persons' personal securities transactions.
5.2 Luna's undertakings
For so long as Luna holds such records, Luna:
- keeps them in a manner that permits their production in a legible, true and complete form;
- arranges and indexes them so that a particular record can be identified and produced promptly;
- furnishes them to Customer, or at Customer's written direction to the Securities and Exchange Commission or its representatives, promptly on request, at no charge;
- does not alter or delete them except as Customer directs or as Section 7 provides; and
- maintains them for the retention period Customer configures, and in the absence of configuration for not less than five years from the end of the fiscal year in which the record was created.
5.3 Where the obligation sits
Rule 204-2 imposes the recordkeeping obligation on Customer, not on Luna, and nothing in this Addendum transfers it. Luna's undertakings above are given so that Customer's reliance on a third party does not impair Customer's ability to comply. Customer remains responsible for determining which records it must keep and for how long.
5.4 Broker-dealer undertakings
Exchange Act Rule 17a-4(i) requires an undertaking from a third party holding records on behalf of a broker-dealer. Rule 204-2 contains no equivalent provision for investment advisers. A Customer that is also registered as a broker-dealer, or that is a dual registrant, may request Luna's standard undertaking letter addressed to its regulator, which Luna provides on request.
6. Subprocessors
Luna engages the subprocessors listed at luna subprocessors, which forms part of this Addendum. Customer authorizes those engagements.
Luna imposes on each subprocessor data protection obligations no less protective than those in this Addendum, and remains responsible for their performance.
Luna conducts periodic security and compliance assessments of its subprocessors, and provides Customer with evidence of that diligence, and of any security certifications a subprocessor holds, on request.
Luna gives Customer at least 30 days' notice before adding a subprocessor that will process Personal Information. Customer may object on reasonable data protection grounds within that period, in which case the parties will discuss it in good faith; if it cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.
Subprocessors marked "planned" on that page are not yet processing Customer Data. Luna will move a subprocessor to active status, with notice under this Section, before that data flow begins.
6.1 One exception, stated plainly
Brokerage account linking, when Customer enables it, is provided by Plaid Inc. For account-data access Plaid acts as a controller in its own right, not solely as Luna's processor: it has its own agreement and privacy policy with the individual who links an account, captures its own consent, and offers that individual a portal in which to review and revoke the connection.
Luna cannot contract that relationship away and does not claim to. What Luna commits to is this: credentials are entered into Plaid and never reach Luna; Luna receives holdings and transaction data and nothing else; Luna obtains its own separate, recorded consent from each individual before a link is offered, covering the fact that Customer's chief compliance officer will receive that data; and where an individual revokes access at Plaid, Luna surfaces that to Customer as a compliance event rather than a technical error, because under Rule 204A-1 an access person's feed going dark is something Customer needs to know about.
7. Return and deletion
On termination, or at any time on Customer's written request, Luna:
- makes Customer Data available for export in a machine-readable format for 30 days; and
- deletes Customer Data from its production systems within 30 days of the export window closing, and from backups within a further 90 days as those backups age out.
Luna retains Customer Data beyond those periods only where law requires it, and where it does, the retained data remains subject to this Addendum.
One exception, and it matters. Where Customer Data constitutes a record Customer must retain under Rule 204-2, Luna does not delete it on request until Customer confirms in writing that Customer has taken possession of it or that the retention period has expired. Luna will not be the reason a required record ceases to exist.
8. Audits, and what Luna will actually give you
Luna makes available, on request and under a reasonable confidentiality undertaking:
- a description of its technical and organizational security measures;
- its current third-party audit report, when one exists. As at the effective date of this Addendum, Luna does not hold a SOC 2 report and no audit is in progress. Luna states that here rather than implying otherwise, and will update this page when it changes.
- responses to a reasonable security questionnaire, once per twelve-month period, which Customer may use to satisfy its own vendor oversight obligations under 17 C.F.R. § 248.30(a)(2)(ii) or 16 C.F.R. § 314.4(f); and
- written confirmation of the matters in Section 3.1 and Section 3.2.
Where Customer's regulator requests information about Luna's processing directly, Luna cooperates with Customer in responding.
9. Individual rights requests
Luna does not respond directly to a request from an individual to access, delete, correct or port Personal Information it processes on Customer's behalf. Luna refers the individual to Customer and tells Customer it has done so within five business days.
Where Customer needs Luna's help to respond, Luna provides it, including by locating, exporting, correcting or deleting the relevant records.
10. Territorial scope
The Services are offered in the United States, to advisers registered with the Securities and Exchange Commission or with a state securities regulator.
Customer will not submit to the Services the Personal Information of any individual located in the European Economic Area, the United Kingdom or Switzerland without Luna's prior written agreement. This is a limitation Luna accepts openly rather than a claim of compliance it has not earned: Luna does not represent that the Services are GDPR compliant, and no standard contractual clauses are in place.
Where Customer has employees or Access Persons located in those territories and wishes to bring them within the Services, Customer should contact Luna before doing so.
11. Automated processing
Luna computes risk indicators about individual Access Persons from the data Customer supplies. Customer should understand three things about that.
The output is a recommendation to a human, not a decision. Every indicator surfaces to a person at Customer with the underlying factors shown, and no action follows automatically.
Customer is the party deciding what, if anything, to do with it. Where Customer uses that output as an input into an employment-related decision, Customer is responsible for compliance with the laws applicable to that decision, which in some states now include specific requirements for automated decision-making.
Luna will provide, on request, a written description of how an indicator is calculated and which factors contributed to a particular score, so that Customer can meet any obligation it has to explain the decision.
12. Government and third-party requests
If Luna receives a legally binding demand for Customer Data, Luna notifies Customer before disclosing, unless prohibited by law. Where prohibited, Luna seeks a waiver of that prohibition and documents its efforts. Luna discloses only the minimum the demand requires.
13. Liability
Each party's liability under this Addendum is subject to the limitations of liability in the Terms of Service, save that nothing in this Addendum limits either party's liability for a breach of its obligations under applicable privacy or securities law to the extent such limitation is unenforceable.
14. Annex: what is processed
| Category | Data | Whose | Purpose |
|---|---|---|---|
| Account | Name, work email, role, firm | Authorized Users | Access control, audit trail |
| Personal securities | Holdings, transactions, preclearance requests, broker and account identifiers | Access Persons and their household members | Code of ethics monitoring, preclearance, restricted list screening |
| Conduct | Gifts, entertainment, political contributions, outside business activities, conflicts, violations | Access Persons | Code of ethics recordkeeping and reporting |
| Firm documents | Policies, procedures, Form ADV, advertisements, marketing materials | Customer, and any individual named in them | Review, retention, semantic search |
| Communications | Email and message content, where Customer enables archiving | Authorized Users, and their correspondents | Retention and supervisory review |
| Risk indicators | Scores and contributing factors generated by Luna | Access Persons | Presented to Customer for review |
Retention follows Section 7 and the period Customer configures.
15. Term
This Addendum takes effect when Customer accepts the Terms of Service and remains in effect for as long as Luna processes Customer Data, and thereafter for so long as Luna retains any Customer Data under Section 7.
16. Governing law and disputes
This Addendum is governed by the laws of the State of California, without regard to its conflict of laws rules.
Any dispute arising out of this Addendum is resolved under the dispute resolution provisions of the Terms of Service.
17. Miscellaneous
Changes. Luna may update this Addendum where a change in law requires it, or to add protections, on 30 days' notice to Customer's administrative contact. A change that materially reduces Customer's protections requires Customer's agreement.
Severability. If any provision is held invalid, the rest continues in force.
Precedence. Where this Addendum conflicts with the Terms of Service or with any order form, this Addendum controls as to the processing of Personal Information.
No signature required. This Addendum is incorporated into the Terms of Service and takes effect on acceptance of them. Customer does not need to sign or return anything. A Customer whose own procurement process requires a countersigned copy may request one at legal@lunacompliance.io, and Luna will provide it at no charge.
Notices under this Addendum go to legal@lunacompliance.io and, for Customer, to the administrative contact on Customer's account.
Imperium Advisors, LLC, a California limited liability company.
490 Post St, Ste 500 PMB 2216 San Francisco, CA 94102 United States