Privacy & Data
Data Processing Addendum
Last updated: June 15, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Production Central ("Processor") and the customer ("Controller") and applies where Production Central processes Personal Data on the Controller's behalf in providing the Service.
Capitalized terms not defined here have the meaning given in the GDPR or the Terms. To request a countersigned copy, contact [email protected].
1. Roles and scope
The Controller determines the purposes and means of processing; Production Central acts as Processor and processes Personal Data only on the Controller's documented instructions, including as set out in the Terms and this DPA. The subject matter, duration, nature, and purpose of processing, and the categories of data and data subjects, are described in Annex I.
2. Processor obligations
- Process Personal Data only on documented instructions, including for international transfers, unless required by law.
- Ensure persons authorized to process Personal Data are bound by confidentiality.
- Implement the technical and organizational measures described in Annex II.
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
- At the Controller's choice, delete or return Personal Data at the end of the services, unless retention is required by law.
- Make available information necessary to demonstrate compliance and allow for audits as described below.
3. Sub-processing
The Controller authorizes Production Central to engage sub-processors listed on our Sub-processors page. We impose data-protection obligations on each sub-processor that are no less protective than this DPA and remain responsible for their performance. We will give notice of new sub-processors and an opportunity to object.
4. Data-subject requests
Taking into account the nature of processing, we will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. If we receive such a request directly, we will direct the individual to the Controller.
5. Personal data breaches
We will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data and will provide information reasonably available to help the Controller meet its notification obligations.
6. Audits
We will make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and frequency limits. We may satisfy audit requests by providing third-party certifications or reports (for example, SOC 2 or ISO 27001) where available.
7. International transfers
Where processing involves transferring Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) are incorporated by reference and apply to that transfer.
8. Deletion and return; precedence
On termination, the Controller may export Personal Data for a limited period, after which we will delete it in the ordinary course unless retention is legally required. In the event of any conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA controls.
Annex I — Description of processing
- Categories of data subjects — the Controller's authorized users, their end users, and their contacts.
- Categories of Personal Data — name, email, account credentials, content submitted to the Service, and usage and device data.
- Special categories — none are requested; the Controller should not submit special-category data except as incidentally contained in Customer Content.
- Nature and purpose — hosting, storing, and processing data to provide the Service.
- Duration — the term of the subscription plus any retention period.
Annex II — Technical and organizational measures
The measures are described on our Security page and include encryption in transit and at rest, access controls and least privilege, network security, logging and monitoring, secure development, vulnerability management, backups and business continuity, and personnel security and training.
More legal documents