Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Savi LoopIQ Terms of Service between the customer (“Controller”) and Lee Savage, Savage Management Holdings Inc. (“Processor”). It governs processing of personal data on Controller's behalf. Team-tier customers may execute a signed copy by emailing legal@savagetechnicalsolutions.com.
1. Subject matter and duration
Subject matter: provision of the Savi LoopIQ Service.
Duration: for the term of Controller's subscription, plus wind-down and legally-required retention periods.
2. Nature and purpose of processing
Hosting, storage, transmission, retrieval, and computation on personal data submitted by Controller so that Controller's authorized users can use Savi LoopIQ.
3. Categories of data subjects and personal data
- Data subjects: Controller's employees, contractors, and authorized users.
- Personal data: email addresses, authentication tokens, IP addresses, in-app usage logs, and any personal data Controller chooses to embed in uploaded files or AI Instructor prompts.
4. Processor obligations
Processor will:
- Process personal data only on documented instructions from Controller, including these Terms.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organizational measures (see §7).
- Assist Controller in responding to data-subject requests.
- Assist Controller with data-protection impact assessments where reasonably requested.
- Notify Controller without undue delay (and within 72 hours) of a personal-data breach affecting Controller's data.
- Delete or return personal data at Controller's election within 30 days of contract end.
5. Sub-processors
Controller authorizes engagement of the following sub-processors:
- Supabase Inc. — authentication and database hosting (US).
- Vercel Inc. — web hosting and edge network (US, global).
- Stripe Inc. — subscription billing (US, global).
- Perplexity AI Inc. — AI Instructor inference (US).
Processor will give 30 days' notice of any new or replacement sub-processor and allow Controller to object on reasonable data-protection grounds. Each sub-processor is bound by contract to confidentiality and security terms substantially similar to those in this DPA.
6. International transfers
For personal data originating in the EEA, UK, or Switzerland transferred outside those regions, Processor relies on the EU Standard Contractual Clauses (Module 2, Controller-to-Processor), the UK IDTA Addendum, and, where applicable, the EU-US Data Privacy Framework. Executing this DPA incorporates those clauses by reference.
7. Security measures
- TLS 1.2+ encryption in transit; provider-managed AES-256 encryption at rest.
- Passwordless magic-link authentication.
- Row-level security in the primary database.
- Least-privilege access for personnel; annual review.
- 30-day server log retention; audit logging of billing and admin actions.
- Documented incident-response procedure.
8. Audits
Once per year, Controller (or an independent auditor bound by confidentiality) may audit Processor's compliance with this DPA on 30 days' notice, during normal business hours, at Controller's expense, and in a manner that does not compromise the confidentiality or security of other customers. Processor may satisfy this obligation by providing recent third-party audit reports from its sub-processors.
9. Return or deletion of data
At contract end, Processor will, at Controller's election: (a) return personal data in a common machine-readable format, or (b) delete it. Backups will be deleted per Processor's standard rotation (up to 90 days).
10. Order of precedence
In case of conflict, this DPA controls over the Terms of Service with respect to processing of personal data. The Standard Contractual Clauses control over both, where they apply.
11. Signing
Team-tier customers who require a countersigned copy: email legal@savagetechnicalsolutions.com with your legal entity name and billing address. We use DocuSign for execution.