1. Parties and priority
The customer is a controller or processor lawfully instructing processing; 160418 OÜ is processor. This DPA applies during the Service and prevails on data protection.
2. Processing
Purpose: workspace, brand analysis, content generation, support and security. Duration: contract plus deletion period. Subjects may include staff, contractors, customers, prospects, followers and others lawfully submitted.
Data may include contacts, public social data, workspace content, brand context, identifiers and technical logs. Do not submit special-category or criminal-offence data without written agreement.
3. Instructions
We process only on documented instructions, including Terms, settings and product requests, unless law requires otherwise. We notify the customer if we believe an instruction is unlawful.
4. Confidentiality and security
People with access are bound by confidentiality. Measures include access control, least privilege, encryption in transit, backups, logging, vulnerability management and incident procedures.
5. Subprocessors
The customer gives general authorisation. We remain responsible, contract providers as required and announce material changes. Customers may reasonably object on data-protection grounds.
| Provider | Function |
|---|---|
| Supabase | Database, authentication, storage |
| Vercel | Hosting, delivery, runtime logs |
| Anthropic, OpenAI, Google, xAI, Moonshot, Replicate | Requested AI generation |
| Resend | Transactional email |
| Social/API providers | Requested import |
| Operational notification providers | Optional support/incident notifications |
Stripe generally independently controls payment/compliance data. Google Analytics is consent-based and not core.
6. Transfers
Outside the EEA we use adequacy or SCC 2021/914. Where needed, SCCs are incorporated with the appropriate module and this DPA supplies Annex I/II details.
7. Data subject rights
We notify the customer of requests unless prohibited and reasonably assist with access, correction, deletion, restriction, portability and objection. The customer responds as controller.
8. Breach
We notify without undue delay after confirming a personal data breach and provide available nature, consequence, measure and contact information.
9. DPIA
We provide reasonable information for DPIAs and regulator consultation. Non-standard work may be charged if agreed.
10. Deletion
On termination the customer exports available data. We delete or return it under standard periods, except backups and legally required records, which remain protected.
11. Audit
Once yearly we provide available Article 28 evidence. If insufficient, parties arrange a narrow audit without exposing other customers, trade secrets or security. Customer bears cost unless material breach is confirmed.
12. Contact
DPA, SCC and subprocessors: illia@160418.com. Version 2026-08-21.