1. Parties and Scope
This Data Processing Agreement (“DPA”) supplements the AssetSnag Terms of Service and governs the processing of personal data by AssetSnag (acting as “Data Processor”) on behalf of the Agency or Customer (acting as “Data Controller”) when collecting data, files, and credentials from client contributors.
2. Subject Matter & Data Categories
- Categories of Data Processed: Full names, work email addresses, IP addresses, uploaded asset/file metadata, and encrypted Credential Vault secrets (passwords, API keys).
- Categories of Data Subjects: Agency team members, agency clients, and client contributors.
- Purpose of Processing: Client onboarding, digital asset collection, file deliverable management, encrypted credential sharing, and automated reminder notifications.
- Duration of Processing: For the duration of the Agency's active account plus a 30-day grace period for data export and permanent deletion.
3. Processor Obligations
AssetSnag agrees to:
- Process personal data strictly in accordance with documented instructions from the Agency.
- Ensure that all personnel authorized to process personal data have committed themselves to confidentiality.
- Implement appropriate technical and organizational measures pursuant to GDPR Article 32 (including TLS 1.3 transit encryption, infrastructure encryption at rest, AES-256-GCM application encryption for sensitive credentials, and strict access controls).
- Data Breach Notification: Notify the Agency without undue delay and at the latest within 72 hours of becoming aware of a personal data breach, providing details of the breach, affected data categories, and mitigation measures.
- Assist the Agency in responding to data subjects' requests to exercise their rights (access, rectification, deletion).
- At the choice of the Agency, delete or return all personal data upon termination of the Service after the 30-day export period, subject to standard automated backup rotation cycles.
4. Sub-processors
AssetSnag engages the following authorized sub-processors for infrastructure and service delivery:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Edge compute (Workers), edge database (D1), object storage (R2), KV, CDN, and security | Global / EU / US |
| Paddle.com | Payment processing, Merchant of Record, and global tax compliance | UK / EU / US |
| Resend | Transactional system email and magic login link delivery | US / EU |
| PostHog | In-app dashboard product analytics | EU / US Cloud |
| Google Analytics 4 | Public marketing site analytics (landing pages only) | Global / US |
AssetSnag will provide at least 15 days' advance notice prior to engaging any new sub-processor via email or dashboard notice, allowing the Agency an opportunity to object on reasonable grounds.
5. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, such transfers shall be governed by the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA). Copies of the applicable clauses are available to the Agency upon request.
6. Right of Audit
Upon reasonable prior written notice and not more than once annually, AssetSnag shall make available to the Agency information necessary to demonstrate compliance with this DPA or provide independent third-party security verification reports where applicable.
7. Limitation of Liability
Any liability arising under or in connection with this DPA shall be subject to the limitation of liability provisions set forth in Section 12 of the AssetSnag Terms of Service.