Legal draft

Data Processing Addendum

Draft DPA for customers using ErgoBase.

DRAFT — pending legal review.

Draft notice

DRAFT — pending legal review. This page is not legal advice and must be reviewed by qualified counsel before launch.

Founder confirmation required: DPA controller/processor roles, SCC module if needed, audit rights, security exhibit, and transfer mechanism.

Roles

For agency workspace data, the customer is expected to act as controller and ErgoBase as processor, subject to final legal review.

ErgoBase processes customer personal data only to provide, secure, support, and improve the service as documented.

Security measures

Measures include tenant-scoped access controls, Postgres row-level security, audit events, authentication through Clerk, production R2 evidence storage, and operational monitoring.

Founder confirmation required: Backup, retention, incident response, access-review, and encryption details.

Sub-processing

Planned sub-processors: Clerk, Neon, Cloudflare R2, Resend, Stripe, Sentry, Vercel, and Render.

Customer notice and objection mechanics must be finalized before launch.