Data Processing Addendum
Last updated May 10, 2026
TEMPLATE — replace before launch. This is a kit-shipped placeholder, not legal advice. Have counsel review and substitute GDPR/CCPA-appropriate text + sub-processor list before deploying to production. This is a go-live step — see the legal checklist in
docs/rebrand.md§4 (anddocs/go-live-runbook.md); remove thestatus: templatefrontmatter once replaced so this banner stops rendering.
1. Scope
This DPA applies when you (the customer) use the service to process personal data of EU/UK data subjects.
2. Roles
You are the data controller; we are the data processor.
3. Sub-processors
We use the following sub-processors:
- Resend (email delivery)
- Polar / PayPal / Sepay (payment processing)
- Sentry (error tracking; optional, env-gated)
- PostHog (analytics; optional, env-gated)
4. Data subject rights
We assist you in fulfilling data subject access, rectification, and erasure requests.
5. Security
We follow commercially reasonable security measures, including TLS in transit, encryption at rest (DB-managed), and least-privilege access controls.
6. Contact
For DPA questions, contact dpo@example.com.