Data Processing Addendum
1. Roles
This Addendum is entered into between the Customer and Data At Scale LLC, a Delaware (USA) limited liability company. For the search inputs and account data Customer submits, Customer is the controller and Data At Scale LLC is a processor acting on Customer's documented instructions. For the creator personal data contained in delivered search results, each party acts as an independent controller — we source and retain that data on our own legitimate-interest basis, as described in the Privacy Policy, and Customer determines its own purposes once delivered. For customer-account data, Data at Scale is an independent controller as described in the Privacy Policy.
2. Subject matter and duration
Processing consists of discovering, extracting, storing, and delivering publicly available creator profile and contact data at Customer's request, for the duration of the agreement plus the retention window (12 months per result set, deletable earlier on request).
3. Instructions
We process result data only to (a) deliver it to Customer, (b) operate and secure the Service, and (c) comply with law. We will inform Customer if we believe an instruction violates applicable data-protection law.
4. Confidentiality and security
Personnel with access to Customer data are bound by confidentiality. We implement appropriate technical and organizational measures including encryption in transit, hashed credentials, tenant isolation at the query layer, and least-privilege operational access.
5. Sub-processors
Customer authorizes the sub-processors listed in the Privacy Policy (Railway, Stripe, Resend, Cloudflare, GitHub, Google Fonts). We will give at least 14 days' notice before adding or replacing a sub-processor, during which Customer may object on reasonable data-protection grounds.
6. International transfers
Where personal data originating in the EEA/UK is transferred to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses — Module 2 (controller → processor) for search inputs and account data, and Module 1 (controller → controller) for delivered result data — which are incorporated by reference and deemed executed by the parties' acceptance of these terms.
7. Assistance
Taking into account the nature of the processing, we assist Customer with data-subject requests, security, breach notification, and impact assessments as reasonably needed. We notify Customer of a personal-data breach affecting Customer data without undue delay.
8. Deletion and return
On termination, or earlier on request, we delete Customer's result data and account data, except records we must retain by law. Deletion of the organization is available from the dashboard and takes effect after a 14-day grace period.
9. Audit
We make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures and sub-processor lists, and will allow audits as required by Article 28(3)(h) GDPR, no more than annually and with reasonable notice.