Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Client") and Media Yard LLC, doing business as Findwell Studio ("Processor"). It applies automatically whenever we process Client Personal Data on your behalf while providing the services. You don't need to sign anything. If you need a countersigned copy, email [email protected].
1. Definitions
"Client Personal Data" means personal data or personal information that we process on your behalf in providing the services. "Data Protection Laws" means the laws that apply to that processing, which may include US state privacy laws (such as the New Jersey Data Privacy Act and the California Consumer Privacy Act), the EU and UK GDPR, and similar laws. "Controller", "processor", "service provider", "personal data breach" and "processing" have the meanings given in the applicable Data Protection Laws.
2. Roles
You are the controller (or business) and we are your processor (or service provider) for Client Personal Data. You are responsible for having a lawful basis and giving any required notices for the data you ask us to process.
3. Details of processing
| Item | Details |
|---|---|
| Subject matter and purpose | Designing, building, configuring, migrating and supporting your website, forms, listings, AI assistants and automations |
| Duration | The project and the 30-day post-launch fix period, plus any support you order |
| Types of data | Contact details, messages, form and chat submissions, booking details, and user or customer records in systems you give us access to |
| Data subjects | Your website visitors, customers, leads, employees and contacts |
| Sensitive data | Not intended. You agree not to instruct us to process sensitive data unless we agree in writing |
4. Our obligations
We will:
- process Client Personal Data only on your documented instructions (these Terms, your brief and your written requests), unless the law requires otherwise, and tell you if we believe an instruction breaks Data Protection Laws;
- not sell or share Client Personal Data, retain, use or disclose it outside our direct business relationship with you, or combine it with other data except as allowed by Data Protection Laws;
- make sure everyone who accesses it is bound by confidentiality;
- apply appropriate technical and organizational measures (section 6);
- help you, where reasonable, respond to requests from individuals exercising their rights and with data protection assessments;
- provide information needed to show we comply with this DPA.
5. Subprocessors
You authorize us to use the subprocessors listed on our Subprocessors page, and any platform you choose for your project (such as your website host or CRM), which you contract with directly. We will impose data protection terms on our subprocessors that are at least as protective as this DPA and remain responsible for their performance. We will post changes to our list at least 30 days before a new subprocessor processes Client Personal Data. You may object on reasonable data protection grounds within that period. If we can't reasonably address the objection, either of us may end the affected services.
6. Security
- Encrypted connections (TLS) for data in transit, and reputable providers that encrypt data at rest.
- Two-factor authentication on accounts that can access Client Personal Data.
- Access limited to the people and systems that need it, using your accounts in your name wherever possible.
- Passwords stored only in a password manager and never in email or AI tools.
- Access removed or handed back when the project ends.
7. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours after becoming aware of a personal data breach affecting Client Personal Data. We will give you the information we reasonably have to help you meet your own notification duties, and take reasonable steps to contain it.
8. Return and deletion
At the end of the services, we will delete or return Client Personal Data in our possession within 30 days, at your choice, unless the law requires us to keep it. Data in your own accounts and platforms stays with you.
9. Audits
Once a year, on 30 days' written notice, you may request written answers to a reasonable security questionnaire. Any further audit must be reasonable in scope, at your cost, during business hours, and subject to confidentiality.
10. International transfers
We are based in the United States. Where Data Protection Laws require a transfer mechanism, the EU Standard Contractual Clauses (Module 2 or 3 as applicable) and the UK Addendum are incorporated by reference, with the governing law and courts of Ireland for the EU clauses and England and Wales for the UK Addendum.
11. Liability and precedence
This DPA is subject to the liability limits in the Terms, except where Data Protection Laws don't allow those limits. If this DPA conflicts with the Terms on data protection, this DPA controls.
12. Contact
Media Yard LLC (Findwell Studio)PO Box 73, Pennsauken, NJ 08110
[email protected]