1. Roles and instructions
The customer is the controller and SmartTeddy Inc is the processor for Customer Personal Data contained in ProjectOS project content. Each party will comply with applicable data-protection law. We will process Customer Personal Data only to provide ProjectOS, on documented customer instructions, or as law requires. The agreement, configured features, submitted content, and authorised support requests constitute instructions.
2. Processing details
The subject matter is operation of the ProjectOS service. Processing lasts for the account term and the deletion period. Operations can include collection, storage, organisation, retrieval, analysis, generation, transmission, export, restriction, and deletion. Data subjects may include customer personnel, contractors, clients, suppliers, and other people described in project content. Data may include identifiers, contact details, professional information, project instructions, correspondence, supplied documents, and generated work. Customers must not submit special-category, protected health, payment-card, government-identifier, criminal-offence, or similarly regulated data unless a separate written agreement expressly permits it.
3. Confidentiality and personnel
We ensure that people authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed for their duties.
4. Security measures
ProjectOS maintains measures appropriate to the service risk, including private passwordless authentication, row-level account isolation, least-privilege service access, encryption in transit and provider-managed encryption at rest, controlled AI disclosure, project and account cost limits, audit and provenance records, secure response headers, incident references that exclude project content, tested backups, and recovery procedures.
5. Subprocessors
The customer authorises the subprocessors needed for the configured service: Supabase (database and authentication), Vercel (hosting), SiteGround (email), OpenRouter and the task’s selected model provider (only for consented AI processing), GitHub (only for an approved integration), and Stripe (commercial billing). We remain responsible for subprocessor obligations to the extent required by applicable law. Material changes will be notified through the service or account contact, and the customer may object on reasonable data-protection grounds.
6. Assistance
Taking account of the processing and information available to us, we will reasonably assist the customer with data-subject requests, security obligations, incident assessment, data-protection impact assessments, and regulator consultation. The customer remains responsible for determining whether ProjectOS is appropriate for its processing and for responding to requests as controller.
7. Security incidents
We will notify the customer without undue delay after confirming a breach of Customer Personal Data and provide available information needed for the customer’s obligations. Notice is not an admission of fault. The customer must keep its account contact current.
8. Return and deletion
During the account term, ProjectOS provides account and project export. On verified account deletion or termination, we delete live Customer Personal Data unless law requires retention. Encrypted recovery copies remain protected and expire under infrastructure schedules. Data already sent through a customer-authorised third-party integration is subject to that third party and the customer’s instructions.
9. International transfers
If Customer Personal Data protected by the EEA, UK, or Swiss transfer rules is transferred to a country without an adequacy decision, the applicable controller-to-processor standard contractual clauses are incorporated by reference, with this DPA and the service description supplying their annex information. The UK Addendum applies to restricted UK transfers. In a conflict, the applicable transfer terms control.
10. Audit information
We will make information reasonably necessary to demonstrate compliance available on request. If that information is insufficient, the customer may conduct one proportionate audit per year through an independent auditor under confidentiality, with reasonable notice, without accessing other customers’ data or disrupting the service. Additional or customer-specific audit costs may be charged where permitted.
11. Order of precedence and contact
If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. Other capitalised terms have the meaning given in the Terms. DPA requests may be sent to admin@smartteddy.ai; operational support is available at support@smartteddy.ai.