Data processing addendum
Proposed agreement · not executed or available for automatic acceptance.
Last updated September 22, 2026Status and parties
This draft is intended for a customer organization and Media Yard LLC. It would supplement a signed service agreement when Media Yard processes personal data on the organization’s behalf. No customer, execution date or underlying agreement has been completed. Do not rely on this page as a signed DPA.
1. Roles and instructions — proposed
For customer-directed workspace processing, the customer would act as controller and Media Yard as processor, where those roles apply. Account administration, service security and direct support may involve separate controller activities described in the Privacy notice. Processing would follow documented customer instructions and applicable law.
2. Processing schedule
- Subject: hosting and operating the customer’s bid-review workspace.
- Operations: collection, storage, retrieval, display, export and requested deletion.
- Data: account/business contact details and personal data the customer chooses to put into workspace notes or support messages.
- People: customer personnel and business contacts referenced by the customer.
- Duration: service period plus agreed deletion/backup periods; these periods must be completed before execution.
- Restricted data: sensitive personal information is not needed for this preview.
3. Confidentiality and security — proposed
Authorized personnel would be subject to confidentiality obligations and access limited to service needs. A final security schedule should document access controls, encryption, incident handling, backup practices and deletion. Current product controls include HTTPS, authentication and owner-scoped database access; no third-party security certification is claimed.
4. Service providers
Current providers relevant to the service include Cloudflare (hosting/mail routing), Supabase (authentication/database), Resend (sign-in email), and Google/Gmail (support correspondence). A final subprocessor schedule must identify contracting entities, relevant locations, onward processing terms and the notice/objection process for changes. This list is not a representation that those contract schedules have been completed.
5. Assistance and incidents — proposed
The final agreement should require reasonable assistance with applicable data requests, security obligations and assessments, and incident notification without undue delay after awareness of a relevant personal-data breach. Contacts, escalation procedures, scope and any contractual time limits must be agreed before execution.
6. Return, deletion and audit — proposed
On termination, customer data would be returned or deleted at the customer’s choice, subject to applicable legal retention. Backup treatment, completion periods, verification and a proportionate audit process must be specified in the executed schedule. The current preview does not promise immediate erasure of every provider backup.
7. International transfers
This draft does not establish a transfer mechanism or promise regional data residency. If restricted international transfers apply, the parties must verify processing locations and incorporate the required transfer terms and safeguards before covered processing.
Request a completed agreement
Email [email protected] with your organization name, jurisdiction and processing requirements. Do not attach customer datasets. Both parties need to complete the schedules and execute an appropriate agreement before relying on it.