Template — not legal advice. This document is a starting-point template. Review it with a qualified lawyer before relying on it for your business.
Data Processing Addendum
Seedwise · Terms · Privacy · Acceptable Use
Last updated: [LAST UPDATED — YYYY-MM-DD]
1. Scope & roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and Seedwise (“Seedwise,” the “Processor”) and applies when Seedwise processes personal data on the Controller’s behalf. Where GDPR applies, this DPA reflects Article 28 requirements.
2. Processing details
- Subject matter: provision of the Seedwise outreach and attribution Service.
- Duration: the term of the subscription plus the retention window in our Privacy Policy.
- Nature & purpose: storing, organizing, transmitting, and analyzing Customer Data to run creator outreach and measure results.
- Categories of data subjects: creators, contacts, and message recipients selected by the Controller.
- Categories of personal data: names, email addresses, phone numbers, social handles, public profile data, and message content.
3. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Assist the Controller with data-subject requests and breach notifications.
- Delete or return personal data at the end of the engagement, subject to legal retention.
- Make available information necessary to demonstrate compliance.
4. Subprocessors
The Controller authorizes Seedwise to engage the subprocessors below to provide the Service. We impose data-protection obligations on each subprocessor and remain responsible for their performance. We will give notice of new subprocessors so the Controller may object on reasonable grounds.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | Account data, Customer Data | United States / EU |
| Stripe | Subscription billing and payment processing | Billing contact, payment metadata | United States |
| Anthropic | AI drafting and creator scoring (Claude) | Prompt content, message drafts | United States |
| Modash | Creator discovery and audience enrichment | Creator handles and public profile data | European Union |
| OAuth sign-in and Gmail/email sending integration | Auth tokens, email content | United States / Global | |
| Twilio | SMS outreach delivery | Recipient phone numbers, message content | United States |
| Shopify | E-commerce attribution and order data sync | Order and promo-code attribution data | United States / Canada |
5. International transfers
Where personal data is transferred outside the EEA/UK, the parties rely on the Standard Contractual Clauses and any additional safeguards required by applicable law.
6. Security & breach notification
Seedwise maintains security measures appropriate to the risk, including encryption in transit, access controls, and monitoring. We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data.
7. Audits
Upon reasonable request and subject to confidentiality, Seedwise will provide information reasonably necessary to demonstrate compliance with this DPA.
8. Contact
For DPA or subprocessor questions, email support@getseedwise.io or write to Seedwise via getseedwise.io.