Version 2026-10-01
Data Processing Addendum
This addendum ("DPA") forms part of the Terms of Service between Manuel Ortuno, Playa Grande, Cabo Velas, Santa Cruz, Guanacaste, Costa Rica ("Processor") and the customer ("Controller") whenever Glassy processes personal data on the customer's behalf, for example the comments and messages of people who interact with the customer's accounts, or data of the customer's clients.
1. Scope
- Subject matter and purpose: providing Glassy: publishing content, showing and answering comments and direct messages, analytics, and related features the Controller uses.
- Duration: for the term of the agreement and until deletion as described in section 8.
- Data subjects: the Controller's team members and clients; people who comment on, mention or message the Controller's connected accounts; the Controller's audience (aggregated demographics only).
- Personal data: names, usernames and platform IDs; comment and message content and attachment links; email addresses of team members; aggregated audience statistics. No special categories of data are intended.
2. Instructions
The Processor processes personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of Glassy's features, unless the law requires otherwise (in which case the Processor informs the Controller first unless legally prohibited).
3. Confidentiality
Everyone authorized to process the personal data is bound by confidentiality.
4. Security
The Processor maintains the measures in Annex 1 and keeps them appropriate to the risk.
5. Sub-processors
The Controller authorizes the sub-processors listed in the Privacy Policy. The Processor imposes data protection obligations on them equivalent to this DPA, remains responsible for them, and gives at least 30 days' notice of new sub-processors by updating the list and notifying account owners, during which the Controller may object on reasonable grounds and, if no solution is found, terminate the affected service with a pro-rata refund.
6. Assistance
The Processor helps the Controller, taking into account the nature of the processing, to respond to data subject requests (export and deletion tools are built into Glassy), and with security, breach notification, impact assessments and consultations with authorities.
7. Personal data breaches
The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information available and updates as it becomes available.
8. Deletion
On termination, or when the Controller deletes data or a workspace, the Processor deletes the personal data, with backup copies overwritten within [7] days, unless the law requires retention. The Controller can export data at any time before deletion.
9. Audits
The Processor makes available the information needed to demonstrate compliance with this DPA and allows reasonable audits, no more than once a year, with 30 days' notice, during business hours and under confidentiality, at the Controller's cost.
10. International transfers
Where personal data is transferred to a country without an adequacy decision, the parties rely on the European Commission's standard contractual clauses (module 2 or 3 as applicable) and their UK and other equivalents, which are incorporated by reference.
11. Liability
Liability under this DPA is subject to the limitations in the Terms, to the extent permitted by law.
Annex 1: Security measures
- Encryption in transit (HTTPS/TLS) and at rest for platform access tokens and two-factor secrets (AES-256-GCM); passwords hashed with scrypt.
- Optional two-factor sign-in; sign-in rate limiting; single-use, expiring password-reset and invitation links.
- Workspace isolation enforced on every request; role-based access (owner, manager, editor, client).
- Strict content security policy; no third-party scripts, trackers or fonts on application pages.
- Verified signatures on platform and payment webhooks.
- Daily backups with limited retention; documented data retention and automatic deletion.
- Access to production systems limited to authorized personnel.