E EverCPE.com Back to home
Legal

Data Processing Addendum

Last updated: June 19, 2026

On this page
1Definitions 2Data Status & Roles 3Details of Data Processing 4Processor Obligations 5Sub-processors & Disclosures 6Breach Notification 7Data Subject Requests 8Deletion & Return of Data 9Governing Law 10Contact

This Data Processing Addendum ("DPA") is an addendum to the Terms and Conditions ("Agreement") between EverCPE.com ("Processor", "we", "us", or "our") and you ("Customer", "Controller", or "you"). This DPA applies where the Customer uses the EverCPE.com Software-as-a-Service platform and the Processor processes Personal Data on behalf of the Customer.

In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail concerning the Processing of Personal Data.

1

Definitions

Capitalized terms used in this DPA but not defined herein shall have the meanings set forth in the Agreement.

Data Controller
The natural or legal person which determines the purposes and means of the Processing of Personal Data.
Data Processor
The natural or legal person which Processes Personal Data on behalf of the Controller.
Data Subject
An identified or identifiable natural person to whom Personal Data relates.
Personal Data
Any information relating to an identified or identifiable natural person.
Processing
Any operation performed on Personal Data, such as collection, storage, use, or disclosure.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.
Sub-processor
Any third-party processor engaged by the Data Processor to assist in fulfilling its obligations under this DPA.
2

Data Status & Roles

For the purposes of the Service, the parties agree on the following classification:

Data Controller
The Customer

Our User or Subscriber determines the purposes and means of the Processing of Personal Data submitted to the Service.

Data Processor
EverCPE.com

We Process Personal Data on behalf of the Customer strictly as outlined in this DPA and the Agreement.

3

Details of Data Processing

The "nature and purpose" of the Processing, as well as the data categories, are clearly defined below to comply with Article 28 of the GDPR and equivalent regulations.

  • Nature and Purpose of Processing: The Processor shall Process Personal Data to provide the EverCPE.com SaaS platform, including but not limited to creating and managing user accounts, mapping payments, delivering services, and providing customer support.
  • Categories of Data Subjects: The Personal Data belongs to the Customer's Users and Subscribers.
  • Types of Personal Data: The Processor shall Process the following Personal Data — Names (full name of the user) and Email Addresses (contact and account identifier).
  • Duration of Processing: The Processing shall occur for the lifetime of the Customer's active SaaS subscription. Upon termination or expiration of the subscription, the Processor shall handle the data as per the "Deletion and Return of Data" section below.
4

Processor Obligations

4.1  Processing Instructions

The Processor shall Process Personal Data only on the documented instructions of the Controller, which are set out in this DPA and the Agreement. The Processor shall not use Personal Data for any other purpose.

4.2  Confidentiality

The Processor shall ensure that any person authorized to process the Personal Data is subject to a duty of confidentiality, whether by contract or by applicable statutory obligations.

4.3  Security Measures

The Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

  • Hosting & Infrastructure: The Service is hosted on Bubble.io, which in turn hosts its infrastructure on Amazon Web Services (AWS). AWS is SOC 2, CSA CAIQ, and ISO/IEC 27001 compliant. Data is encrypted in transit (TLS) and at rest (AES-256).
  • Role-Based Access Control (RBAC): Access to Personal Data is restricted based on the principle of least privilege. Employees and contractors of EverCPE.com are granted access permissions strictly according to their job roles and only on a "need-to-know" basis.
  • Monitoring and Auditing: Access to data is logged (including user ID, time, and resources accessed). These logs are protected against unauthorized access and tampering.
5

Sub-processors & Third-Party Disclosures

The Customer acknowledges and agrees that the Processor may engage third-party Sub-processors to Process Personal Data on its behalf. The Customer provides general authorization for the engagement of the following Sub-processors:

S
Stripe Inc.

Used as the dedicated payment processor. Stripe handles financial transactions and maps payments to the Customer's account. Stripe is not granted access to data beyond what is necessary for payment processing.

B
Bubble Group Inc.

The native hosting platform for the EverCPE.com app. Bubble stores and secures the Personal Data on its infrastructure (AWS) on behalf of the Processor.

A
Amazon Web Services (AWS)

The underlying cloud infrastructure provider used by Bubble to host the Service and data.

The Processor does not share, sell, or rent Personal Data to any other third parties for marketing or commercial purposes.

6

Breach Notification

6.1  Notification Timeline

In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay, and no later than 72 hours after becoming aware of the breach. The notification will include:

  • A description of the nature of the breach.
  • The categories and approximate number of Data Subjects and Personal Data records concerned.
  • The likely consequences of the breach.
  • A description of the measures taken or proposed to be taken to address the breach.

6.2  Audit Procedures

The Processor permits audits of its data processing activities. Such audits shall be conducted in accordance with Bubble.io's native security policies and procedures and the provisions of this DPA:

  • Right to Audit: Upon reasonable request, the Controller or a third-party auditor may inspect the Processor's relevant data processing operations.
  • Frequency: Audits are typically permitted once per calendar year.
  • Notice: The Controller must provide at least 30 days' prior written notice.
  • Constraints: Audits must be conducted during regular business hours and in a manner that minimizes disruption to the Processor's operations. All information obtained during an audit must be kept confidential.
7

Data Subject Requests

The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject requests (e.g., access, deletion, rectification). As the Controller has direct access to the data via the Platform, the Controller is primarily responsible for responding to such requests. The Processor will provide reasonable assistance to enable the Controller to respond to these requests.

8

Deletion and Return of Data

Upon the termination or expiration of the subscription, the Controller may request the return or deletion of Personal Data. Unless required to retain the data by law, the Processor shall delete all copies of Personal Data within a commercially reasonable time following the request, except to the extent that backup archives must be retained and securely stored until deletion in the ordinary course of business.

9

Governing Law

This DPA is governed by and construed in accordance with the laws of the Commonwealth of Virginia, USA, without regard to its conflict of law provisions.

10

Contact

If you have any questions about this DPA, please contact us:

Email
support@evercpe.com
Mail
9890 Liberia Ave #1128, Manassas, VA 20110, United States.
E EverCPE.com
Gaaptive Learning, LLC dba EverCPE.com
9890 Liberia Ave #1128
Manassas, VA 20110
United States

Sitemap

How it works Benefits Quality FAQ Eligibility Join the waitlist

Email

support@evercpe.com
© 2026 Gaaptive Learning, LLC dba EverCPE.com
Terms of Use Privacy Policy Cookie Policy DPA Admin Policies