Ssavekit.
Start publishing

DPA

A practical data-processing addendum for teams.

This DPA applies when a creator or business customer uses SaveKit to process personal data in hosted pages, forms or analytics.

Effective date: [DATE]Operator: [OPERATOR LEGAL NAME] (individual service provider trading as SaveKit)[OPERATOR LEGAL NAME] (individual service provider trading as SaveKit) · [SERVICE ADDRESS / COUNTRY] · [COMPANY / REGISTRATION NUMBER, IF APPLICABLE]

This page is a launch draft. Configure the operator identity, service address, provider list, effective date and governing law before accepting paid customers.

Roles and scope

For customer content containing personal data, the customer is Controller and SaveKit is Processor. SaveKit remains an independent Controller for account administration, billing, security, abuse prevention, legal compliance and its own service analytics. Paddle or another payment provider may be an independent Controller for payment and tax processing.

Instructions and confidentiality

SaveKit processes customer personal data only to provide hosting, publishing, storage, forms, analytics, support and security under the agreement, configuration and written instructions. Personnel with access are bound by confidentiality duties. Do not submit sensitive data unless a written addendum permits it.

Security

Measures include TLS, provider encryption, separate least-privilege secrets, hashed credentials, tenant checks, short-lived upload credentials, rate limiting, audit logs, isolated origins, malware/ZIP checks and fail-closed moderation. Actual providers and regions are listed in the data-residency notice.

Subprocessors and transfers

Cloudflare, hosting/database/queue, email, moderation, monitoring and Paddle may process data as listed in the current subprocessor register. We provide notice of material additions where practicable. Transfers outside the EEA/UK use adequacy decisions or safeguards such as applicable SCCs and the UK transfer addendum.

Requests, incidents and deletion

SaveKit reasonably assists with access, correction, deletion, restriction and portability requests. Notify [email protected]. We notify the customer without undue delay after confirming a breach affecting customer data. On termination, we delete or return data within [30] days, subject to law, security records and backup rotation.

Enterprise copy

This page is a summary. The signed DPA at [email protected], including processing details, technical measures and the then-current subprocessor schedule, controls for enterprise customers.

Questions: [email protected]. See also Privacy, Terms, Refunds and DPA.

Data Processing Addendum · SaveKit