Legal draft
Data Processing Addendum
Draft DPA for customers using ErgoBase.
Draft notice
DRAFT — pending legal review. This page is not legal advice and must be reviewed by qualified counsel before launch.
Founder confirmation required: DPA controller/processor roles, SCC module if needed, audit rights, security exhibit, and transfer mechanism.
Roles
For agency workspace data, the customer is expected to act as controller and ErgoBase as processor, subject to final legal review.
ErgoBase processes customer personal data only to provide, secure, support, and improve the service as documented.
Security measures
Measures include tenant-scoped access controls, Postgres row-level security, audit events, authentication through Clerk, production R2 evidence storage, and operational monitoring.
Founder confirmation required: Backup, retention, incident response, access-review, and encryption details.
Sub-processing
Planned sub-processors: Clerk, Neon, Cloudflare R2, Resend, Stripe, Sentry, Vercel, and Render.
Customer notice and objection mechanics must be finalized before launch.