Data Processing Agreement

Data Processing Addendum (DPA)

Last updated: June 23, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Domain DESGNR ("PresenceOS", "Processor") and the customer agreeing to the Agreement ("Customer", "Controller"). It applies where and to the extent PresenceOS processes Customer Personal Data on Customer's behalf in providing the Service. If there is a conflict with the Agreement on data-protection matters, this DPA controls.

1. Definitions

"Applicable Data Protection Laws" means privacy and data-protection laws applicable to a party's processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws (e.g., the CCPA/CPRA), as amended. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Sub-processor" have the meanings in Applicable Data Protection Laws. "Customer Personal Data" means Personal Data that PresenceOS processes on Customer's behalf under the Agreement, as described in Annex I. "SCCs" means the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).

2. Roles and scope of processing

2.1 Roles. As between the parties, Customer is the Controller (or a processor acting on behalf of a third-party controller) and PresenceOS is the Processor (or sub-processor) of Customer Personal Data. This includes Personal Data of Customer's own end customers, content recipients, and visitors to websites PresenceOS generates and hosts for Customer.

2.2 For PresenceOS's own purposes. PresenceOS acts as an independent Controller for limited data it processes for its own account administration, billing, security, and Service improvement, as described in the Privacy Policy. This DPA governs only the Processor relationship.

2.3 Instructions. PresenceOS will process Customer Personal Data only (a) to provide, secure, and support the Service, (b) per Customer's documented instructions (including configuration and use of the Service and this DPA), and (c) as required by law (in which case PresenceOS will, where permitted, inform Customer first). PresenceOS will inform Customer if it believes an instruction infringes Applicable Data Protection Laws.

3. Customer responsibilities

Customer warrants that (a) it has a lawful basis and has provided all required notices and obtained all required consents for the Personal Data it submits or directs PresenceOS to process or publish; (b) its instructions comply with Applicable Data Protection Laws; and (c) for AI features, it will not submit special-category or other sensitive Personal Data unless it has a lawful basis and accepts that such data will be transmitted to third-party AI providers (see Annex III and the AI Usage Disclosure). Customer is responsible for the privacy notices and choices presented to visitors of its Generated Site.

4. Confidentiality

PresenceOS ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and are trained on their responsibilities.

5. Security

PresenceOS implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II, taking into account the state of the art, costs, and the nature and risk of the processing. PresenceOS may update measures provided protection is not materially reduced.

6. Sub-processors

6.1 Customer provides general authorization for PresenceOS to engage Sub-processors to provide the Service. The current Sub-processors are listed in Annex III (and maintained at [sub-processor list URL]).

6.2 PresenceOS will impose data-protection obligations on each Sub-processor substantially equivalent to those in this DPA and remains responsible for its Sub-processors' performance.

6.3 PresenceOS will give Customer notice of intended additions or replacements of Sub-processors (e.g., via the list and/or email) with a reasonable opportunity to object on reasonable data-protection grounds. [Confirm notice period — e.g., 30 days — and objection/termination remedy.]

7. Assistance to Customer

Taking into account the nature of the processing, PresenceOS will assist Customer, by appropriate technical and organizational measures and insofar as possible:

  • to respond to Data Subject requests (access, correction, deletion, portability, objection, restriction);
  • to ensure security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.

Where PresenceOS receives a Data Subject request directed at Customer's data, it will, where permitted, redirect the Data Subject to Customer and assist Customer in responding.

8. Personal Data Breach

PresenceOS will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its breach-notification obligations. Notice of a Breach is not an acknowledgment of fault.

9. International transfers

9.1 PresenceOS and its Sub-processors may process Customer Personal Data in the United States and other countries.

9.2 Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply, with the UK International Data Transfer Addendum and Swiss amendments as applicable. [Module selection to be confirmed by counsel — typically Module Two (Controller→Processor) and, where Customer is itself a processor, Module Three (Processor→Processor); complete the SCC annexes using Annexes I–III of this DPA and set the docking/option choices and governing-law/forum.]

10. Return and deletion

On termination or expiry of the Agreement, PresenceOS will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, except to the extent retention is required by law. Residual copies in routine backups are deleted on a rolling basis. [Confirm post-termination retention window — e.g., up to 30–90 days.]

11. Audits

PresenceOS will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by Customer or an auditor it mandates, on reasonable prior notice, no more than [once per year] (or following a Breach), subject to confidentiality and to minimizing disruption. PresenceOS may satisfy audit requests by providing relevant third-party certifications or reports where available.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.

13. Term

This DPA takes effect when incorporated into or referenced by the Agreement and remains in force while PresenceOS processes Customer Personal Data.


Annex I — Details of processing

  • Roles: Customer = Controller (or processor); PresenceOS = Processor (or sub-processor).
  • Subject matter & duration: processing of Customer Personal Data to provide the Service for the term of the Agreement (and any wind-down period in §10).
  • Nature and purpose: hosting, storage, generation, transformation, transmission to AI and infrastructure providers, publishing to Customer's Connected Accounts, and hosting of Generated Sites.
  • Categories of Data Subjects: Customer's personnel/account users; Customer's end customers and prospects; recipients of published content; and visitors to Customer's Generated Site.
  • Categories of Personal Data: identifiers and contact details (name, email); business/brand information submitted as Inputs; uploaded assets that may contain images of individuals; Connected Account identifiers and access tokens; content and engagement data; site-visitor data (e.g., IP address, device/usage data, and any data collected through forms on a Generated Site).
  • Special-category / sensitive data: not intentionally processed. ⚠️ Voice/face data submitted to or generated by AI features (e.g., AI voice profiling) may implicate biometric-privacy laws — Customer must not submit such data without a lawful basis (see attorney notes).
  • Frequency: continuous, for the term.

Annex II — Technical and organizational measures

  • Tenant isolation: per-tenant separation enforced at the database layer (row-level security keyed to each business).
  • Encryption: in transit (TLS) and at rest via our database/storage providers.
  • Access control: role-based access, least privilege, authentication via our auth provider; restricted production access.
  • Secrets management: credentials and tokens stored outside source control (environment-based).
  • Monitoring & logging: error monitoring and operational logging.
  • Resilience: managed, backed-up database and storage via our infrastructure providers.
  • Vendor management: Sub-processors engaged under data-protection terms (Annex III).
  • [Add: incident-response process, data-retention schedules, employee confidentiality/training, vulnerability management — confirm specifics with counsel/security.]

Annex III — Sub-processors

Sub-processor Purpose Processing location
Hosting provider Application hosting [confirm]
Database / auth / storage provider Database, authentication, file storage [US/region — confirm]
Media-processing provider Media rendering worker [confirm]
CDN provider Asset storage & delivery [confirm]
Payment processor Billing & payments [confirm]
Publishing provider Social publishing on Customer's behalf [confirm]
Analytics provider Product analytics [confirm]
Error-monitoring provider Error & performance monitoring [confirm]
Third-party AI model providers AI text, image, video, and voice generation [confirm]

(Confirm completeness, legal names, and processing locations of each Sub-processor before publishing.)