Data Processing Addendum (DPA)
Last updated: 2026-05-19
Lawyer-reviewed copy pending (F#70). This DPA template summarises Ad Marginem's data-protection commitments for institutional customers and EU users. A counter-signed PDF version is available on request — email [email protected].
1. Parties & scope
This DPA applies between Ad Marginem (the "Processor") and you (the "Controller") when Ad Marginem processes Personal Data on your behalf in connection with the Services. It supplements the Terms of Service.
2. Roles & categories
- Controller: the institutional customer or end user.
- Processor: Ad Marginem.
- Categories of personal data: account identifiers (email, OAuth subject), device identifiers, library content (which may include personal data the Controller chooses to upload).
- Categories of data subjects: the Controller's authorised users.
3. Processor obligations
- Process Personal Data only on documented instructions from the Controller.
- Ensure persons authorised to process Personal Data are under a duty of confidentiality.
- Implement appropriate technical and organisational measures (TLS in transit, AES-256 at rest, access controls, audit logging — see Schedule 1 below).
- Assist the Controller with data-subject rights requests (access, erasure, rectification, portability) within 30 days.
- Notify the Controller of a Personal Data Breach without undue delay (target: within 72 hours).
- Make available all information necessary to demonstrate compliance.
- Submit to audits on reasonable notice.
4. Sub-processors
The Controller authorises Ad Marginem to engage the sub-processors listed at /legal/subprocessors. Ad Marginem provides at least 30 days' notice of any intended change to the sub-processor list via email to the Controller's billing contact. Ad Marginem remains liable for sub-processor performance to the same extent as for its own performance.
5. International transfers
Personal Data is transferred to the United States (Neon Postgres in AWS us-east-2; Cloudflare R2). For EU/UK data subjects, transfers rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated by reference into this DPA. For Canadian data subjects, PIPEDA cross-border notice is provided in our Privacy Policy.
6. Deletion & return
On termination of the Services, Ad Marginem deletes or returns all Personal Data within 30 days, except where retention is required by applicable law. Backups expire on their own retention schedule (Neon PITR: 7 days; R2 audit-archive: per the Privacy Policy).
7. Schedule 1 — Technical & organisational measures
- Transport: TLS 1.2+ on every public endpoint (Cloudflare-managed).
- Storage: AES-256 at rest (Neon Postgres + R2).
- Authentication: better-auth session cookies, optional TOTP 2FA, OAuth (Google, GitHub, ORCID).
- Authorisation: row-level security in Postgres scoped to userId per request.
- Audit: mutating operations recorded in
audit_log; archived to R2 after 90 days (P8.7). - Rate limiting: edge WAF rules + per-userId application limits (P9.2/P9.4).
- Disaster recovery: Neon PITR (7 days) + R2 → AWS S3 Glacier replication (P6.5).
8. Contact
Data Protection Officer: [email protected].
General DPA inquiries: [email protected].