Data Processing Addendum
Effective EFFECTIVE_DATE · Last updated LAST_UPDATED
In short
If you are a business using CreatorBase and you put other people's personal data into it, this is the contract that says how we handle it on your behalf. It applies automatically — you do not need to sign anything.
This summary is for orientation only. The numbered sections below are the actual terms.
1.When this applies, and to whom
This Addendum forms part of the Terms of Service and applies where you use CreatorBase to process personal data for which you are the controller — most obviously the details of other creators you ask us to analyse, and any personal data inside content you upload.
It takes effect automatically. There is nothing to countersign, which means you are covered from your first use rather than from whenever paperwork completes.
Two different relationships, deliberately kept separate. For your own account data — your email, your brand settings, your usage — we are the controller and our Privacy Policy governs it. For personal data you bring in and direct us to process, you are the controller and we are the processor, and this Addendum governs it.
2.Definitions
"GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR as retained in UK law. "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" carry their GDPR meanings. "Data Protection Laws" means all privacy laws applicable to a party, including the GDPR, the UK GDPR, and the CCPA/CPRA.
3.Scope of processing (Article 28(3))
| Item | Detail |
|---|---|
| Subject matter | Provision of CreatorBase — content creation, analysis, scheduling and publishing. |
| Duration | For as long as your account is open, plus the deletion period below. |
| Nature and purpose | Storage, retrieval, generation, transmission to the providers needed to fulfil your instructions, and deletion. |
| Types of personal data | Contact details and public profile information of creators you ask us to analyse; any personal data contained in content you upload or generate; and audience metrics, which are aggregate and not identifying. |
| Categories of data subject | Other creators whose public posts you analyse, people referenced in your content, and your own team members if you invite any. |
| Special category data | Not required, not expected, and not to be uploaded. CreatorBase is not designed for it and you should not put it in. |
4.Our obligations as processor
We will:
- Process personal data only on your documented instructions — using the product is the instruction — and only for the purposes above. If we believe an instruction breaches Data Protection Laws we will tell you and may decline it.
- Ensure anyone with access is bound by confidentiality.
- Apply the technical and organisational measures described in our Security Overview, appropriate to the risk.
- Not sell personal data, and not use it for our own purposes, for advertising, or to train our own models.
- Assist you with data subject requests, data protection impact assessments, and engagement with supervisory authorities, at no charge for anything of reasonable scale.
- Make available the information needed to demonstrate compliance, and allow an audit no more than once a year on reasonable notice, or sooner following a personal data breach. A reasonable-cost audit is at your expense; we may satisfy it with existing documentation where that genuinely answers the question.
5.Your obligations as controller
You will:
- Have a lawful basis for the personal data you put into the service, and give any notices required to the people concerned.
- Not upload personal data you are not entitled to process.
- Handle data subject requests that reach you, using the export and deletion tools we provide.
- Not use the analysis features to process personal data in a way that a platform's terms or applicable law prohibits.
Worth saying plainly: asking us to retrieve and store public posts by a named creator makes you the controller of that person's personal data, with the obligations that carries — including a lawful basis and, potentially, notifying them under GDPR Art. 14. If that is a problem for your use case, do not use those features on identifiable individuals in the UK or EEA.
6.Sub-processors
You give general authorisation for us to engage the sub-processors listed at /legal/subprocessors. We impose data protection obligations on each of them no less protective than these, and we remain liable to you for their performance.
We will give at least 30 days' notice before adding one. You may object on reasonable data-protection grounds; if we cannot offer an alternative, you may terminate the affected part of the service without penalty and receive a pro-rata refund.
7.International transfers
Where we transfer personal data out of the UK or EEA we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated here by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies.
For those clauses: you are the data exporter, we are the data importer; the annexes are populated by the tables in this Addendum and by the sub-processor list; the optional docking clause applies; and the governing law and forum are those of GOVERNING_LAW to the extent the clauses permit, defaulting to Ireland where they do not.
8.Personal data breach
- We will notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data.
- The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and what we are doing about it — and will say plainly what we do not yet know rather than waiting until we do.
- We will help you meet your own notification obligations to authorities and data subjects.
- Notifying you is not an admission of fault.
9.Deletion and return
- On termination, or on your written request, we will delete personal data processed on your behalf within 30 days, except where law requires us to keep it.
- Export your data before you delete your account. Deletion is designed to be irreversible.
- Encrypted backups are overwritten on their own rolling schedule, within 30 days.
10.Order of precedence
If this Addendum conflicts with the Terms of Service, this Addendum governs the processing of personal data. If it conflicts with the Standard Contractual Clauses, the Clauses govern.
Questions, or a request for a signed counterpart: [PRIVACY_EMAIL](mailto:PRIVACY_EMAIL).
Other documents
- Privacy PolicyWhat CreatorBase collects, why, who it is shared with, how long it is kept, and how to get it deleted.
- Terms of ServiceThe agreement between you and us: what you get, what you owe, who owns what, and how either side ends it.
- Acceptable Use PolicyWhat you may not do with CreatorBase. Short, specific, and enforced.
- Cookie PolicyEvery cookie and browser storage key CreatorBase uses, what it does, and why there is no consent banner.
- Security OverviewHow your data is protected, what we have not built yet, and how to report a vulnerability.
- Sub-processorsEvery third party that can process your data, what it does, and where it is.
- Copyright and DMCA PolicyHow to report content that infringes your copyright, and how to contest a report.
- Refund and Cancellation PolicyHow to cancel, what happens to your data, and when you get money back.