Data Processing Addendum

Last updated May 10, 2026

TEMPLATE — replace before launch. This is a kit-shipped placeholder, not legal advice. Have counsel review and substitute GDPR/CCPA-appropriate text + sub-processor list before deploying to production. This is a go-live step — see the legal checklist in docs/rebrand.md §4 (and docs/go-live-runbook.md); remove the status: template frontmatter once replaced so this banner stops rendering.

1. Scope

This DPA applies when you (the customer) use the service to process personal data of EU/UK data subjects.

2. Roles

You are the data controller; we are the data processor.

3. Sub-processors

We use the following sub-processors:

  • Resend (email delivery)
  • Polar / PayPal / Sepay (payment processing)
  • Sentry (error tracking; optional, env-gated)
  • PostHog (analytics; optional, env-gated)

4. Data subject rights

We assist you in fulfilling data subject access, rectification, and erasure requests.

5. Security

We follow commercially reasonable security measures, including TLS in transit, encryption at rest (DB-managed), and least-privilege access controls.

6. Contact

For DPA questions, contact dpo@example.com.