Data Processing Addendum
1. Scope, order of precedence and roles
This Addendum applies where a customer supplies personal data for Femtechnology, Inc. to process on documented instructions in Troviii or Vivere. The customer is controller or processor as applicable; Femtechnology is processor or subprocessor. This Addendum controls over conflicting service terms for that processing.
2. Instructions and purpose limitation
Femtechnology processes customer personal data only to provide, secure, support and document the configured service; comply with documented lawful instructions; and meet legal obligations. If an instruction appears unlawful, Femtechnology will inform the customer unless prohibited. Product features that make Femtechnology an independent controller must be separately disclosed and are not silently treated as customer processing.
3. Confidentiality and personnel
Access is limited to personnel and contractors who need it, are bound by confidentiality and receive appropriate privacy and security instruction. Access is reviewed and revoked when no longer required.
4. Security measures
Measures include encryption in transit; managed encryption at rest; server-side authentication and authorization; row-level database security; service-role isolation; scoped secrets; least privilege; rate and provider-spend controls; logs and evidence records; input, URL and upload validation; environment separation; backups and recovery appropriate to the service; vulnerability and dependency review; incident response; and deletion/retention controls. Final Annex II must identify the exact production configuration and review cadence.
5. Subprocessors
The customer authorizes only subprocessors listed in the live schedule for the configured service. Femtechnology will contractually impose appropriate data-protection duties, remain responsible as required by law, and provide advance notice of material additions so the customer may raise a reasonable data-protection objection. Code support for a vendor does not mean that vendor processes production data.
6. Data-subject and regulator assistance
Taking account of the nature of processing, Femtechnology will reasonably assist with access, portability, correction, deletion, restriction, objection, consent withdrawal, regulator inquiries and DPIAs. The shared subject-store registry locates actor-bearing Supabase records; registered Firebase stores and configured processors must be included in the response workflow.
7. Security incidents
Femtechnology will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data, provide available information needed for the customer’s assessment and notices, take reasonable containment and remediation steps, and preserve an incident record. Notification is not an admission of fault.
8. Return, deletion and retention
At termination or documented request, Femtechnology will return or delete customer data unless law requires retention. Shared/public artifacts may require removal versus anonymization; financial, settlement, rights, fraud and legal evidence may be retained only for the applicable purpose and period, with access restricted. Backup deletion follows the documented backup cycle.
9. International transfers
Where required, the parties incorporate the appropriate controller-to-processor or processor-to-processor EU Standard Contractual Clauses, the UK addendum and Swiss adaptations. Annex I must specify parties, categories, purposes, frequency, retention, competent authority and transfer destinations; Annex II specifies measures; Annex III lists subprocessors. Transfer-impact assessments and supplementary measures are completed per enabled vendor.
10. Audit and evidence
Femtechnology will provide reasonably necessary compliance information and, where that is insufficient, permit a proportionate audit subject to confidentiality, security, scope, timing and cost safeguards. Independent reports may satisfy routine requests. Audits may not expose other customers or compromise security.
11. Customer duties
The customer is responsible for lawful instructions, notices, legal bases, data accuracy, minimization, user permissions, account administration and avoiding special-category or consumer-health data unless the order and compliance schedule expressly authorize it.
Schedule A · Processing details
Subject matter: the configured cultural experience, world, membership, event, partner, matching, commerce or reporting service. Data subjects may include members, subscribers, attendees, creators, contributors, staff, buyers, sellers and partner contacts. Data may include identity/contact, account/security, submitted content, imported sources, deliberate activity, event context, recommendations/intent, communications and commerce evidence. Special-category or consumer-health data is excluded unless a separate signed schedule authorizes it.
Schedule B · Required execution facts
Customer legal name/address/contact; Femtechnology legal address/contact; service/order; controller/processor roles; duration; enabled systems and subprocessors; storage/transfer regions; SCC modules; retention periods; deletion/export method; security contacts; and signatures.