Data Processing Agreement
Version 1.0 · Effective as of August 20, 2026
This Data Processing Agreement (including its annexes, this “DPA”) is entered into by and between Players Club (“Company,” “we,” “us,” or “our”) and the business customer identified on the applicable Order Form (“Customer”) (each a “Party” and collectively the “Parties”). This DPA is the Data Processing Addendum contemplated by Section 2.4 of the Master Services Agreement posted on the Site at https://joinplayersclub.com/msa, and is incorporated into and forms part of that Master Services Agreement, together with all Order Forms (as amended, the “Agreement”), effective as of the Effective Date of the Agreement.
This DPA governs Company’s Processing of Personal Data on Customer’s behalf as part of the Services. Company’s Privacy Policy posted on the Site at https://joinplayersclub.com/privacy describes how Company handles personal information generally, and the Terms of Use posted on the Site at https://joinplayersclub.com/terms govern individual use of the Site.
1. Definitions
The following terms have the meanings set out below for purposes of this DPA. Any capitalized terms not defined in this DPA have the meanings given in the Agreement.
- “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract, or otherwise.
- “Applicable Data Protection Laws” means the privacy, data protection, and data security laws and regulations of any jurisdiction within the United States applicable to Company’s Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws.
- “Customer Data” means information provided or otherwise made available by or on behalf of Customer to Company for Processing on Customer’s behalf to perform the Services.
- “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
- “Information Security Incident” means a breach of Company’s security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Company’s possession, custody, or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
- “Personal Data” means Customer Data that constitutes “personal data,” “personal information,” or “personally identifiable information” defined in Applicable Data Protection Laws or information of a similar character regulated thereby, provided that Personal Data does not include such information pertaining to Customer’s business contacts who are Customer personnel, or such information that Company receives, collects, or generates independently of the Services and not from or on behalf of Customer.
- “Process” or “Processing” means any operation or set of operations which is performed by Company (or on Company’s behalf) for Customer under the Agreement on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Security Measures” has the meaning given in Section 4.1 (Company Security Measures).
- “Services” has the meaning given in the Agreement.
- “State Privacy Laws” means, collectively, the comprehensive state-specific data privacy laws (and any implementing regulations) currently in effect and applicable to Company’s Processing of Personal Data under the Agreement.
- “Subprocessors” means Company’s Affiliates and third parties that Company engages to Process Personal Data in relation to the Services.
2. Duration and Scope of DPA
2.1 Duration. This DPA will remain in effect so long as Company Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
2.2 State Privacy Laws. Processing of Personal Data subject to the State Privacy Laws with respect to which Customer is a Business, Controller, Processor, or Service Provider (as such terms are defined in the State Privacy Laws) shall be subject to Annex 2 (State Privacy Laws Annex) to this DPA.
3. Customer Instructions
Company will Process Personal Data only in accordance with Customer’s documented instructions to Company, including as set out in this DPA, the Agreement, any applicable Order Form(s), and any other written instructions provided by Customer from time to time that are consistent with the Agreement and this DPA. To the extent Customer requests instructions that are outside the scope of the Services or that would require Company to materially change the Services or undertake additional work not contemplated by the Agreement, the Parties will agree to such instructions in a mutually executed amendment to this DPA or other written agreement. By entering into the Agreement, Customer instructs Company to Process Personal Data to provide the Services and to perform Company’s other obligations and exercise Company’s rights under the Agreement. The Parties agree that the details of Company’s Processing of Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to this DPA.
4. Security
4.1 Company Security Measures. Company will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data as described in Annex 3 (Security Measures) (the “Security Measures”), taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing and the risks to Data Subjects. Company may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.
4.2 Security Compliance by Company Staff. Company will require that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.
4.3 Information Security Incidents. Company will notify Customer without undue delay of any Information Security Incident of which Company becomes aware. Such notifications will describe, to the extent then known, available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Company recommends Customer take to address the Information Security Incident. Company’s notification of or response to an Information Security Incident will not be construed as Company’s acknowledgement of any fault or liability with respect to the Information Security Incident. Company will reasonably cooperate with Customer and take such commercially reasonable steps, to the extent within Company’s control, as may be reasonably requested by Customer and mutually agreed in good faith by the Parties to assist in the investigation of any such Information Security Incident. Customer is solely responsible for complying with notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Information Security Incident. If Customer determines that an Information Security Incident must be notified to any regulatory authority, any Data Subject(s), the public, or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies Company, where permitted by applicable law, Customer agrees to (i) notify Company in advance, and (ii) in good faith, consult with Company and consider any clarifications or corrections Company may reasonably recommend or request to any such notification, which: (a) relate to Company’s involvement in or relevance to such Information Security Incident; and (b) are consistent with applicable law.
5. Customer’s Security Responsibilities and Assessment
5.1 Customer’s Security Responsibilities. Customer agrees that, without limitation of Company’s obligations under Section 4 (Security), Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (b) securing the account authentication credentials, systems, and devices Customer uses to access the Services; (c) securing Customer’s systems and devices that Customer provides or makes available for Company to access in order to provide the Services; and (d) backing up Personal Data, as applicable.
5.2 Customer’s Security Assessment. Customer acknowledges that it has evaluated the Services, the Security Measures, and Company’s commitments under this DPA and, based on information made available by Company, determines that they are adequate to meet Customer’s needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.
6. Data Subject Rights
6.1 Company’s Data Subject Request Assistance. Company will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (“Data Subject Requests”) with respect to Personal Data in Company’s possession or control. Customer will compensate Company for any such assistance, to the extent such assistance requires work beyond the Services, at Company’s then-current professional services rates, which shall be made available to Customer upon request, and Company will, upon request, provide Customer with a good-faith estimate of applicable fees.
6.2 Customer’s Responsibility for Requests. If Company receives a Data Subject Request, Company will (i) promptly notify Customer (unless prohibited by applicable law); and (ii) advise the Data Subject to submit the request to Customer. Customer will be solely responsible for responding to any such request, unless otherwise required by applicable law.
7. Customer Responsibilities
7.1 Notices and Consents. Customer will ensure (and is solely responsible for ensuring) that it has provided all notices to, and obtained all consents and permissions from, third parties (including, without limitation, Data Subjects), and has reserved all necessary rights, in each case, as may be required under Applicable Data Protection Laws for Company to Process Personal Data as contemplated by the Agreement.
7.2 Restricted Data. Customer represents and warrants to Company that Customer Data does not and will not contain any social security numbers or other government-issued identification numbers; protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; health insurance information; biometric information; passwords or other credentials for third-party online accounts (other than credentials created for and used solely to access the Services); credentials to any financial accounts; tax return data; any payment card information subject to the Payment Card Industry Data Security Standard; personal data of children under 16 years of age; or any other information that falls within any special categories of data (as defined in Applicable Data Protection Laws), in each case other than the categories of Personal Data expressly identified in Annex 1 (Data Processing Details) as Processed by the Services (collectively, “Restricted Data”).
8. Subprocessors
8.1 Consent to Subprocessor Engagement. Customer specifically authorizes the engagement of Company’s Affiliates as Subprocessors and generally authorizes Company to engage third parties as Subprocessors in accordance with this Section 8.
8.2 Information about Subprocessors. Information about Subprocessors, including their functions and locations, is set out in Annex 4 (List of Subprocessors) to this DPA. Company may continue to use those Subprocessors already engaged by Company as of the effective date of this DPA.
8.3 Requirements for Subprocessor Engagement. When engaging any Subprocessor, Company will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Company will remain responsible for the performance of all obligations subcontracted to the Subprocessor and will be liable for all acts and omissions of the Subprocessor to the same extent as Company would have been had it performed the Processing itself.
8.4 Opportunity to Object to Subprocessor Changes. When Company engages any new Subprocessor after the effective date of this DPA, Company will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating Annex 4 of this DPA as posted on the Site and providing written notice (including by email) to Customer’s designated contact for Services-related communications, or by other written means. If Customer objects to such engagement in a written notice to Company within 15 days after receipt of such notice on reasonable grounds relating to the protection of Personal Data, Customer and Company will work together in good faith to find a mutually acceptable resolution to address such objection. If the Parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by providing written notice to Company and pay Company for all amounts due and owing under the Agreement as of the date of such termination.
9. Audits
Customer may audit Company’s compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct such additional audit or a competent regulatory authority with jurisdiction over Customer requires it, in each case upon Customer’s written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Company will contribute to such audits by providing Customer with the information and assistance reasonably necessary to conduct the audit. If a third party is to conduct the audit, Company may object to the auditor if the auditor is, in Company’s reasonable opinion, not independent, a competitor of Company, or otherwise manifestly unsuitable. Such objection by Company will require Customer to appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan to Company at least two weeks in advance of the proposed audit date, and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the Parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Company will review the proposed audit plan and provide Customer with any concerns or questions (for example, any request for information that could compromise Company security, privacy, employment, or other relevant policies). Company will work cooperatively with Customer to agree on a final audit plan. Nothing in this Section 9 will require Company to breach any duties of confidentiality. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Company’s safety, security, or other relevant policies, and may not unreasonably interfere with Company business activities. Customer will promptly notify Company of any non-compliance discovered during the course of an audit and provide Company any audit reports generated in connection with any audit under this Section 9, unless prohibited by Applicable Data Protection Laws. Customer may use the audit reports only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Customer’s sole expense. Customer will reimburse Company for any reasonable, documented costs (including reasonable internal time expended by Company and any third parties in connection with any audits or inspections under this Section 9 at Company’s then-current professional services rates, which shall be made available to Customer upon request). Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.
10. Return and Deletion
10.1 Cessation of Processing. Subject to Sections 10.2 and 10.3, upon the date of cessation of any Services involving the Processing of Personal Data (the “Cessation Date”), Company will promptly cease all Processing of Personal Data for any purpose other than for storage and Processing necessary to effect the return, deletion, or anonymization of such Personal Data, or as otherwise permitted or required under this DPA or applicable law.
10.2 Return or Deletion on Request. Subject to Section 10.4, to the extent technically possible in the circumstances, on written request to Company (to be made no later than 30 days after the Cessation Date (the “Post-cessation Storage Period”)), Company shall within a commercially reasonable period following receipt of such request (i) return a complete copy of all Personal Data within Company’s possession to Customer by secure file transfer or other commercially reasonable secure method, promptly following which Company shall delete or anonymize all other copies of such Personal Data, or (ii) (at its option) delete or anonymize all Personal Data within Company’s possession.
10.3 Deletion Without Instruction. If, during the Post-cessation Storage Period, Customer does not instruct Company in writing to either delete or return Personal Data under Section 10.2, Company shall, within a commercially reasonable time after the expiry of the Post-cessation Storage Period, either (at its option) delete or render anonymous all Personal Data then within Company’s possession, custody, or control to the fullest extent technically feasible in the circumstances. Residual copies of Personal Data in routine backups will be deleted in the ordinary course and remain protected by the Security Measures and the confidentiality obligations of the Agreement until deleted.
10.4 Legally Required Retention. Company may retain Personal Data to the extent permitted or required by applicable law, for no longer than such applicable law requires, provided that Company will (i) maintain the confidentiality of all such Personal Data and protect it in accordance with the Security Measures, (ii) Process such Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention, and (iii) delete or anonymize such Personal Data once it is no longer permitted or required to be retained under applicable law.
11. Artificial Intelligence and Automated Processing
11.1 No AI Training; No Advertising Use. Company will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether Company’s own or a third party’s, except as expressly authorized by Customer in writing. Company will not use Personal Data for advertising purposes and will not sell Personal Data, as further set out in Annex 2 (State Privacy Laws Annex).
11.2 Subprocessors. Company will prohibit its Subprocessors, including any AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as expressly authorized by Customer in writing.
11.3 Automated Decision-Making. The Services do not currently involve automated decision-making that produces legal or similarly significant effects concerning Data Subjects. If the Services come to involve any such processing, Company will: (a) disclose the existence of such processing to Customer; (b) to the extent reasonably available to Company, provide meaningful information about the logic involved without requiring disclosure of Company’s trade secrets or confidential information; and (c) reasonably cooperate with Customer, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights under such laws relating to automated decision-making.
12. Miscellaneous
12.1 Relationship to the Agreement. Except as expressly modified by this DPA, the terms of the Agreement remain in full force and effect. To the extent of any conflict or inconsistency between this DPA and the other terms of the Agreement with respect to the Processing of Personal Data, the provision providing the higher level of privacy or data protection for Personal Data will govern. Notwithstanding anything in the Agreement or any Order Form entered in connection therewith to the contrary, the Parties acknowledge and agree that Company’s access to Personal Data does not constitute part of the consideration exchanged by the Parties in respect of the Agreement.
12.2 Notices. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Company to Customer under this DPA may be given (a) in accordance with any notice clause of the Agreement; (b) to Customer’s contact details for data protection set out in Annex 1; (c) to Company’s primary points of contact with Customer; or (d) to any email address designated by Customer in writing for the purpose of receiving Services-related communications or alerts. Customer is solely responsible for ensuring that such email addresses are valid. Notices to Company under this DPA may be given by emailing club@joinplayersclub.com.
12.3 Amendments for Compliance. Company agrees to cooperate in good faith with Customer to consider any amendments to this DPA that may be reasonably necessary to address compliance with Applicable Data Protection Laws. Company may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, provided that any such variation will not materially reduce the protections afforded to Personal Data or materially increase Customer’s obligations under this DPA without Customer’s written agreement.
12.4 Liability. The total aggregate liability of either Party to the other Party, however arising, under or in connection with this DPA will under no circumstances exceed any limitations or caps on, and will be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement.
12.5 Governing Law. This DPA forms part of the Agreement and does not contain a separate governing law or dispute resolution provision; it is governed by, and any dispute arising under it will be resolved in accordance with, the section of the Agreement titled Miscellaneous — the laws of the Commonwealth of Pennsylvania, with arbitration conducted in Berks County, Pennsylvania.
Annex 1 — Data Processing Details
Company details.
- Name: Players Club
- Address: the mailing address posted on the Site
- Contact details for data protection: Privacy contact — club@joinplayersclub.com
- Company activities: Provision of the Players Club hosted membership, check-in, promotional-credit, and marketing platform that participating businesses — such as bars, restaurants, gas stations, and smoke shops — use to run their own customer membership programs.
Customer details.
- Name: the business customer that is the counterparty to the Agreement, as identified on the applicable Order Form
- Address: as set forth on the applicable Order Form
- Contact details for data protection: the email address set forth on the applicable Order Form, or such other contact as Customer designates in writing
- Customer activities: Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Categories of Data Subjects. Relevant Data Subjects include Members (end customers of Customer who join or participate in Customer’s membership program through the Services) and, to the extent their Personal Data is Processed in the Services on Customer’s behalf, Customer’s personnel and other Authorized Users.
Categories of Personal Data. Relevant Personal Data comprises the categories Customer causes Company to Process as part of the provision of the Services, including:
- Member identity and contact details — name, email address, and phone number.
- Birthday and age attestation — a Member’s birthday and confirmation of legal age.
- Membership and marketing records — venue membership status and preferences, and marketing consent records.
- Visit and check-in history — the venue, date, and time of check-ins, including brief device-location coordinates collected at check-in solely to confirm the Member’s presence at the venue (see Sensitive categories below).
- Promotional credit records — promotional credits and offers issued, credit balances, and redemption history.
- Email records — records of emails sent and their delivery status (for example, delivered, bounced, or suppressed), together with related consent records.
- Authentication details — credentials used to access the Services, stored only in one-way hashed form.
- Technological details — internet protocol (IP) addresses, device and browser data, and first-party activity logs.
Sensitive categories of data, and associated additional safeguards.
- Categories of sensitive data: precise device-location coordinates collected at check-in, and account log-in credentials. No other sensitive categories are intended to be Processed; as set out in Section 7.2 of this DPA, Customer must not submit Restricted Data to the Services.
- Additional safeguards for sensitive data: location coordinates are collected with the Member’s device permission, used solely to confirm presence at the venue at the time of check-in, stored encrypted, and deleted on a short schedule, after which the check-in record retains only the venue, date, and time. Credentials are stored only in one-way hashed form. Company does not use sensitive data to infer characteristics about Data Subjects.
Frequency of transfer: ongoing — as initiated by Customer, its Authorized Users, and Members in and through the use of the Services.
Nature of the Processing: Processing operations required in order to provide the Services and perform Company’s obligations in accordance with the Agreement and this DPA.
Purpose of the Processing: as necessary to provide the Services as initiated by Customer in its use thereof, and to comply with Customer’s documented instructions as permitted under and in accordance with the terms of this DPA and the Agreement.
Duration of Processing / retention period: for the period determined in accordance with the Agreement and this DPA, including Section 10 (Return and Deletion).
Transfers to Subprocessors: transfers to Subprocessors are as, and for the purposes, described in Annex 4 (List of Subprocessors).
Annex 2 — State Privacy Laws Annex
For purposes of this Annex 2, the terms “business,” “controller,” “processor,” “commercial purpose,” “sell,” “share,” “service provider,” and “contractor” shall have the respective meanings given thereto in the applicable State Privacy Laws, and “personal information” shall mean Personal Data to the extent it constitutes “personal information” or “personal data” (or a similar term) governed by the State Privacy Laws.
It is the Parties’ intent that with respect to any personal information, Company is a service provider, contractor, and/or processor, as applicable under the State Privacy Laws. Company (a) acknowledges that personal information is disclosed by Customer only for the limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Company’s Processing of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Company that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon reasonable notice, including under the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
Company will not (a) sell or share any personal information; (b) retain, use, or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use, or disclose the personal information outside of the direct business relationship between Company and Customer; or (d) combine personal information received under the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Company’s own interaction with any Data Subject to whom such personal information pertains, except as and to the extent permitted by the State Privacy Laws and necessary as part of Company’s provision of the Services. Company hereby certifies that it understands its obligations under this Annex 2 and will comply with them.
Giving Customer notice of Subprocessor engagements in accordance with Section 8 of this DPA will satisfy Company’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
Customer may conduct audits, in accordance with Section 9 of this DPA, to help ensure that Company’s use of personal information is consistent with Company’s obligations under the State Privacy Laws.
The Parties acknowledge that Company’s retention, use, and disclosure of personal information authorized by Customer’s instructions documented in the Agreement and this DPA are integral to Company’s provision of the Services and the business relationship between the Parties.
Annex 3 — Security Measures
Company implements and maintains the following technical and organizational measures for the protection of Personal Data. These are the measures actually in place for the Platform; Company may update them as described in Section 4.1, provided the updates do not materially decrease the overall protection of Personal Data.
- Encryption. Personal Data fields are encrypted at rest, and Personal Data is encrypted in transit using TLS. Check-in location coordinates are stored encrypted and are deleted on a short schedule after presence at the venue is confirmed.
- Data isolation. Customer Data is isolated per organization, with the isolation enforced in the database itself, so that one Customer’s data cannot be accessed through another Customer’s account.
- Access control. Access to Personal Data is role-based and limited to what each role requires. Platform administrators must sign in with a mandatory authenticator (TOTP) second factor.
- Administrative access auditing. Administrative access to Customer Data requires a recorded reason, is subject to time limits, and is recorded in an audit log, with actions attributed to the individual administrator.
- Credential protection. Passwords and PINs are stored only in one-way hashed form; Company does not store plain-text credentials.
- Deletion workflow. A deletion-request workflow removes or anonymizes Personal Data on request while preserving records Company is legally required to keep.
- Personnel. Access to Personal Data is limited to personnel who need it to provide the Services, and such personnel are subject to confidentiality obligations as described in Section 4.2.
- Hosting. The Platform runs on the infrastructure of the Subprocessors listed in Annex 4, whose facilities provide physical and environmental security for the systems storing Personal Data; Company does not operate its own physical data centers. Routine backups are maintained through that infrastructure and are protected and deleted as described in Section 10.
- Incident response. Company investigates suspected Information Security Incidents, takes steps to mitigate them, and provides notifications in accordance with Section 4.3.
Annex 4 — List of Subprocessors
Customer approves Company’s engagement of the following Subprocessors to provide services under the Agreement:
- Supabase, Inc. — United States — managed database, authentication, and hosting infrastructure for the Platform.
- Vercel, Inc. — United States — application hosting and content delivery.
- Resend, Inc. — United States — email delivery, including service emails and, where the Member has consented, marketing emails sent on Customer’s behalf.
Company will update this Annex and notify Customer of any new Subprocessor engagement as described in Section 8.4.