1. Document status
This outline is a draft framework for business customers who require a Data Processing Agreement (DPA). It is not binding until executed with a signed order form naming the parties, effective date, and subprocessors schedule.
Contact navophoto@protonmail.com for enterprise paperwork.
2. Roles
For workspace data you upload (books, artifacts, webhook configs), you are typically the controller and the Operator is the processor.
For account, billing, and security data necessary to operate the Service, the Operator is an independent controller.
3. Processing instructions
The Operator processes personal data only on documented instructions from the customer, including these Terms, Privacy Policy, and configuration you set in the product (webhooks, exports, retention).
The Operator shall not sell customer personal data or use it for advertising unrelated to the Service.
4. Subprocessors (current list)
Typical subprocessors: cloud hosting, Clerk (identity), Stripe (payments), optional LLM providers when AI features are enabled, and email delivery if alerts are configured.
The Operator will maintain a subprocessor list and provide notice of material changes where contractually required.
5. Security and breach
The Operator implements administrative, technical, and organizational measures appropriate to risk, including encryption in transit, access controls, and audit logging for sensitive operations.
The Operator will notify the customer of personal data breaches without undue delay where required by applicable law and contract.
6. Return and deletion
Upon termination, the Operator will delete or return customer personal data per the Privacy Policy and any signed DPA, subject to legal retention and backup cycles.
7. Audit and SCCs
Enterprise customers may request reasonable audit information or certifications where available.
Cross-border transfers may rely on Standard Contractual Clauses or UK IDTA addenda as specified in the executed DPA and EU/UK Supplement.