Data Processing Agreement
Effective July 16, 2026 · Last updated July 16, 2026
This Data Processing Agreement ("DPA") applies where Salvatorre, LLC ("Processor") processes Personal Data on behalf of a client (the "Controller") in the course of providing services. It forms part of, and is subject to, the services agreement or other written agreement between the parties (the "Agreement"). Where this DPA conflicts with the Agreement on data protection, this DPA controls.
1. Definitions
"Personal Data", "Controller", "Processor", "Processing", "Data Subject", and "Supervisory Authority" have the meanings given in applicable Data Protection Laws. "Data Protection Laws" means all privacy and data protection laws applicable to the Processing, which may include the EU/UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), and other U.S. state privacy laws.
2. Roles and scope
The Controller determines the purposes and means of the Processing; the Processor processes Personal Data only to provide the services. The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.
3. Processor obligations
- Process Personal Data only on the Controller's documented instructions, including the Agreement and this DPA, unless required by law (in which case the Processor will notify the Controller where legally permitted).
- Ensure personnel authorized to process Personal Data are bound by confidentiality.
- Implement and maintain the technical and organizational security measures in Annex II.
- Assist the Controller, taking into account the nature of the Processing, in responding to Data Subject requests and in meeting the Controller's security, breach-notification, and data-protection-impact-assessment obligations.
- At the Controller's choice, delete or return all Personal Data at the end of the services and delete existing copies unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable confidentiality and security safeguards.
4. Subprocessors
The Controller provides general authorization for the Processor to engage the subprocessors listed in Annex III to help deliver the services. The Processor will impose data protection obligations on each subprocessor no less protective than those in this DPA and remains responsible for their performance. The Processor will give the Controller reasonable notice of any intended addition or replacement of a subprocessor and a chance to object on reasonable data-protection grounds.
5. Security and personal data breaches
The Processor maintains the safeguards in Annex II. On becoming aware of a Personal Data breach affecting the Controller's data, the Processor will notify the Controller without undue delay and provide the information reasonably available to help the Controller meet its own notification duties.
6. International transfers
Where Processing involves transferring Personal Data across borders in a way that triggers transfer requirements under Data Protection Laws, the parties will put in place an appropriate transfer mechanism (for example, the applicable Standard Contractual Clauses), which are incorporated by reference where required.
7. Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the laws of the State of Florida, without regard to conflict-of-laws rules, consistent with the Agreement.
Annex I — Details of processing
- Subject matter & duration: Processing for the term of the services and any wind-down period.
- Nature & purpose: Providing the engineering, software, and related services described in the Agreement.
- Categories of Data Subjects: the individuals whose Personal Data the Controller provides or makes accessible for the services, such as the Controller's customers, employees, or end users.
- Types of Personal Data: the Personal Data the Controller provides for the services, which may include names, contact details, account identifiers, and usage data.
- Special categories: the services are not intended to process special categories of Personal Data unless the parties agree otherwise in writing.
Annex II — Security measures
The Processor maintains administrative, technical, and physical safeguards appropriate to the risk, including: encryption of data in transit (TLS); access controls and least-privilege administration; strong authentication for privileged accounts, including two-factor authentication; secrets kept out of source control; regular dependency and vulnerability review; segregation of client environments; and logging of security-relevant events. Current details are available on request.
Annex III — Authorized subprocessors
- Stripe — payment processing.
- Mailgun (Sinch) — transactional and marketing email delivery.
- Printify — print-on-demand order fulfillment (shop orders).
- Google — AI features (Gemini API) used in certain interactive tools.
- HostKoala — web hosting (application and database hosting).
Contact
Data protection questions or requests: please use our contact form.