Template — not legal advice. This document is a starting-point template. Review it with a qualified lawyer before relying on it for your business.

Data Processing Addendum

Seedwise · Terms · Privacy · Acceptable Use

Last updated: [LAST UPDATED — YYYY-MM-DD]

1. Scope & roles

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and Seedwise (“Seedwise,” the “Processor”) and applies when Seedwise processes personal data on the Controller’s behalf. Where GDPR applies, this DPA reflects Article 28 requirements.

2. Processing details

  • Subject matter: provision of the Seedwise outreach and attribution Service.
  • Duration: the term of the subscription plus the retention window in our Privacy Policy.
  • Nature & purpose: storing, organizing, transmitting, and analyzing Customer Data to run creator outreach and measure results.
  • Categories of data subjects: creators, contacts, and message recipients selected by the Controller.
  • Categories of personal data: names, email addresses, phone numbers, social handles, public profile data, and message content.

3. Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organizational security measures.
  • Assist the Controller with data-subject requests and breach notifications.
  • Delete or return personal data at the end of the engagement, subject to legal retention.
  • Make available information necessary to demonstrate compliance.

4. Subprocessors

The Controller authorizes Seedwise to engage the subprocessors below to provide the Service. We impose data-protection obligations on each subprocessor and remain responsible for their performance. We will give notice of new subprocessors so the Controller may object on reasonable grounds.

SubprocessorPurposeData processedLocation
SupabaseDatabase, authentication, and file storageAccount data, Customer DataUnited States / EU
StripeSubscription billing and payment processingBilling contact, payment metadataUnited States
AnthropicAI drafting and creator scoring (Claude)Prompt content, message draftsUnited States
ModashCreator discovery and audience enrichmentCreator handles and public profile dataEuropean Union
GoogleOAuth sign-in and Gmail/email sending integrationAuth tokens, email contentUnited States / Global
TwilioSMS outreach deliveryRecipient phone numbers, message contentUnited States
ShopifyE-commerce attribution and order data syncOrder and promo-code attribution dataUnited States / Canada

5. International transfers

Where personal data is transferred outside the EEA/UK, the parties rely on the Standard Contractual Clauses and any additional safeguards required by applicable law.

6. Security & breach notification

Seedwise maintains security measures appropriate to the risk, including encryption in transit, access controls, and monitoring. We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data.

7. Audits

Upon reasonable request and subject to confidentiality, Seedwise will provide information reasonably necessary to demonstrate compliance with this DPA.

8. Contact

For DPA or subprocessor questions, email support@getseedwise.io or write to Seedwise via getseedwise.io.