This Data Processing Addendum ("DPA") is an addendum to the Terms and Conditions ("Agreement") between EverCPE.com ("Processor", "we", "us", or "our") and you ("Customer", "Controller", or "you"). This DPA applies where the Customer uses the EverCPE.com Software-as-a-Service platform and the Processor processes Personal Data on behalf of the Customer.
In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail concerning the Processing of Personal Data.
Definitions
Capitalized terms used in this DPA but not defined herein shall have the meanings set forth in the Agreement.
- Data Controller
- The natural or legal person which determines the purposes and means of the Processing of Personal Data.
- Data Processor
- The natural or legal person which Processes Personal Data on behalf of the Controller.
- Data Subject
- An identified or identifiable natural person to whom Personal Data relates.
- Personal Data
- Any information relating to an identified or identifiable natural person.
- Processing
- Any operation performed on Personal Data, such as collection, storage, use, or disclosure.
- Personal Data Breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.
- Sub-processor
- Any third-party processor engaged by the Data Processor to assist in fulfilling its obligations under this DPA.
Data Status & Roles
For the purposes of the Service, the parties agree on the following classification:
Our User or Subscriber determines the purposes and means of the Processing of Personal Data submitted to the Service.
We Process Personal Data on behalf of the Customer strictly as outlined in this DPA and the Agreement.
Details of Data Processing
The "nature and purpose" of the Processing, as well as the data categories, are clearly defined below to comply with Article 28 of the GDPR and equivalent regulations.
- Nature and Purpose of Processing: The Processor shall Process Personal Data to provide the EverCPE.com SaaS platform, including but not limited to creating and managing user accounts, mapping payments, delivering services, and providing customer support.
- Categories of Data Subjects: The Personal Data belongs to the Customer's Users and Subscribers.
- Types of Personal Data: The Processor shall Process the following Personal Data — Names (full name of the user) and Email Addresses (contact and account identifier).
- Duration of Processing: The Processing shall occur for the lifetime of the Customer's active SaaS subscription. Upon termination or expiration of the subscription, the Processor shall handle the data as per the "Deletion and Return of Data" section below.
Processor Obligations
4.1 Processing Instructions
The Processor shall Process Personal Data only on the documented instructions of the Controller, which are set out in this DPA and the Agreement. The Processor shall not use Personal Data for any other purpose.
4.2 Confidentiality
The Processor shall ensure that any person authorized to process the Personal Data is subject to a duty of confidentiality, whether by contract or by applicable statutory obligations.
4.3 Security Measures
The Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
- Hosting & Infrastructure: The Service is hosted on Bubble.io, which in turn hosts its infrastructure on Amazon Web Services (AWS). AWS is SOC 2, CSA CAIQ, and ISO/IEC 27001 compliant. Data is encrypted in transit (TLS) and at rest (AES-256).
- Role-Based Access Control (RBAC): Access to Personal Data is restricted based on the principle of least privilege. Employees and contractors of EverCPE.com are granted access permissions strictly according to their job roles and only on a "need-to-know" basis.
- Monitoring and Auditing: Access to data is logged (including user ID, time, and resources accessed). These logs are protected against unauthorized access and tampering.
Sub-processors & Third-Party Disclosures
The Customer acknowledges and agrees that the Processor may engage third-party Sub-processors to Process Personal Data on its behalf. The Customer provides general authorization for the engagement of the following Sub-processors:
Used as the dedicated payment processor. Stripe handles financial transactions and maps payments to the Customer's account. Stripe is not granted access to data beyond what is necessary for payment processing.
The native hosting platform for the EverCPE.com app. Bubble stores and secures the Personal Data on its infrastructure (AWS) on behalf of the Processor.
The underlying cloud infrastructure provider used by Bubble to host the Service and data.
The Processor does not share, sell, or rent Personal Data to any other third parties for marketing or commercial purposes.
Breach Notification
6.1 Notification Timeline
In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay, and no later than 72 hours after becoming aware of the breach. The notification will include:
- A description of the nature of the breach.
- The categories and approximate number of Data Subjects and Personal Data records concerned.
- The likely consequences of the breach.
- A description of the measures taken or proposed to be taken to address the breach.
6.2 Audit Procedures
The Processor permits audits of its data processing activities. Such audits shall be conducted in accordance with Bubble.io's native security policies and procedures and the provisions of this DPA:
- Right to Audit: Upon reasonable request, the Controller or a third-party auditor may inspect the Processor's relevant data processing operations.
- Frequency: Audits are typically permitted once per calendar year.
- Notice: The Controller must provide at least 30 days' prior written notice.
- Constraints: Audits must be conducted during regular business hours and in a manner that minimizes disruption to the Processor's operations. All information obtained during an audit must be kept confidential.
Data Subject Requests
The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject requests (e.g., access, deletion, rectification). As the Controller has direct access to the data via the Platform, the Controller is primarily responsible for responding to such requests. The Processor will provide reasonable assistance to enable the Controller to respond to these requests.
Deletion and Return of Data
Upon the termination or expiration of the subscription, the Controller may request the return or deletion of Personal Data. Unless required to retain the data by law, the Processor shall delete all copies of Personal Data within a commercially reasonable time following the request, except to the extent that backup archives must be retained and securely stored until deletion in the ordinary course of business.
Governing Law
This DPA is governed by and construed in accordance with the laws of the Commonwealth of Virginia, USA, without regard to its conflict of law provisions.
Contact
If you have any questions about this DPA, please contact us: