Legal

Data Processing Addendum

Last Updated: July 4, 2026

This Data Processing Addendum ("DPA") forms part of the Customer Terms of Service (the "Agreement") between Datana Studios LLC ("BaaSdrop", "Processor", "we") and the customer that accepts the Agreement ("Customer", "Controller", "you"). It applies to our processing of personal data contained in Customer Data ("Customer Personal Data") on your behalf.

1. Definitions

"Personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in applicable Data Protection Law. "Data Protection Law" means all laws applicable to the processing of Customer Personal Data, including the GDPR (EU 2016/679), the UK GDPR, and the CCPA/CPRA. "SCCs" means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries (Decision (EU) 2021/914).

2. Roles and Scope

As between the parties, you are the controller (or a processor acting for another controller) of Customer Personal Data, and we are your processor. We will process Customer Personal Data only on your documented instructions — the Agreement, your configuration of the Platform, and your use of its APIs constitute your instructions — unless required otherwise by law, in which case we will inform you unless prohibited. The subject matter, duration, nature, purposes of processing, data categories, and data subject categories are described in Annex I.

For clarity: data about your own console users and billing relationship with us is processed by us as an independent controller under our Privacy Policy, not under this DPA.

3. CCPA

To the extent Customer Personal Data includes personal information subject to the CCPA, we act as your "service provider". We will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than performing the services, or combine it with other data except as permitted for service providers. We certify that we understand and will comply with these restrictions.

4. Confidentiality

We ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations.

5. Security

We implement and maintain the technical and organizational measures described in Annex II. We may update them from time to time, provided the overall security of the Platform is not materially reduced.

6. Subprocessors

You give general written authorization for our use of the subprocessors listed at /legal/subprocessors/. We will:

  • give at least 30 days' notice of new subprocessors (via that page and its notification mechanism) before they process Customer Personal Data;
  • impose data protection obligations on subprocessors no less protective than this DPA;
  • remain liable for our subprocessors' performance.

If you object to a new subprocessor on reasonable data-protection grounds and we cannot offer a workaround, you may terminate the affected services with a pro-rata refund of prepaid fees.

7. Data Subject Requests

Taking into account the nature of the processing, we will assist you with appropriate technical and organizational measures (including the Platform's deletion, export, and access APIs) to respond to data subject requests. If a data subject contacts us directly about Customer Personal Data, we will redirect them to you and not respond substantively except as legally required.

8. Personal Data Breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us about its nature, scope, and remediation, supplementing the notice as information becomes available. Notification is not an acknowledgement of fault.

9. Assistance

We will provide reasonable assistance with your data protection impact assessments and consultations with supervisory authorities, to the extent they relate to our processing and taking into account the information available to us.

10. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and security documentation. Where Data Protection Law grants you a mandatory audit right that cannot be satisfied by documentation, you may conduct (at your cost, once per 12 months, on 30 days' notice, under confidentiality, during business hours, without access to other customers' data) an audit of our relevant controls.

11. International Transfers

Where processing involves a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the SCCs (Module Two: controller-to-processor, or Module Three: processor-to-processor, as applicable) into this DPA by reference, with: Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 30 days); Clause 11 optional language excluded; Clause 17 governed by Irish law; Clause 18 courts of Ireland; and Annexes I and II of the SCCs populated by Annexes I and II of this DPA. For UK transfers, the UK IDTA Addendum applies; for Swiss transfers, the SCCs apply as adapted by the FDPIC.

12. Return and Deletion

Upon termination of the Agreement, we will make Customer Data available for export for 30 days (Agreement Section 8.4), then delete Customer Personal Data within 60 days, except where retention is required by law. Residual copies in encrypted backups are purged in the ordinary backup rotation. On request, we will confirm deletion in writing.

13. Liability and Precedence

Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Law does not permit such limitation. In case of conflict between this DPA and the Agreement, this DPA controls for data protection matters; the SCCs control over both where they apply.


Annex I — Description of Processing

Parties. Data exporter: Customer (controller). Data importer: Datana Studios LLC (processor), 971 US Highway 202N, Ste R, Branchburg, NJ 08876, USA, privacy@baasdrop.com.

Subject matter and duration. Provision of the BaaSdrop backend platform for the term of the Agreement plus the export/deletion windows.

Nature and purpose. Hosting, storage, transmission, and processing of Customer Applications' data to provide backend services: authentication, user profiles, content collections and items, messaging and real-time features, media storage and delivery, notifications, payments orchestration, analytics, search, and AI feature processing — in each case as configured and invoked by Customer.

Categories of data subjects. End users of Customer Applications; Customer's staff using the Platform.

Categories of personal data. Account identifiers (name, email, avatar); user-generated content (messages, posts, notes, documents, media, and any personal data they contain); usage and device data; approximate or precise location where the Customer Application collects it; transaction records; content submitted to AI features. Customer is responsible for not submitting special categories of data unless its applications require it and it has a lawful basis; the Platform is not designed for regulated health or payment-card data.

Frequency. Continuous, as driven by Customer Applications.

Annex II — Technical and Organizational Measures

  • Tenant isolation. Customer Data is logically isolated per tenant/cell at the data layer; operator controls (pause, maintenance mode) are scoped per tenant and per app.
  • Encryption. TLS 1.2+ in transit; encryption at rest for databases, object storage, and backups (AWS-managed KMS keys).
  • Access control. Role-scoped access (owner/tenant/app levels) with least privilege; short-lived credentials for operators; API access via scoped keys; admin actions logged.
  • Infrastructure. Hosted on AWS (serverless compute, managed PostgreSQL, object storage) in the United States; infrastructure defined as code; no customer-accessible shared compute.
  • Monitoring and logging. Centralized logging, error and crash monitoring, usage metering (including per-call AI metering with budgets and rate limits).
  • Resilience and backups. Automated encrypted backups with defined rotation; restoration procedures tested; backups purged on rotation after deletion.
  • Secure development. Code review, automated test suites (unit/integration/e2e), dependency scanning, separated environments (local/dev/test/stage/prod).
  • Personnel. Access limited to personnel who need it; confidentiality obligations; offboarding revocation.
  • Incident response. Documented triage and escalation; customer breach notification within 72 hours per Section 8.