Glassy

Version 2026-10-01

Data Processing Addendum

This addendum ("DPA") forms part of the Terms of Service between Manuel Ortuno, Playa Grande, Cabo Velas, Santa Cruz, Guanacaste, Costa Rica ("Processor") and the customer ("Controller") whenever Glassy processes personal data on the customer's behalf, for example the comments and messages of people who interact with the customer's accounts, or data of the customer's clients.

1. Scope

2. Instructions

The Processor processes personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of Glassy's features, unless the law requires otherwise (in which case the Processor informs the Controller first unless legally prohibited).

3. Confidentiality

Everyone authorized to process the personal data is bound by confidentiality.

4. Security

The Processor maintains the measures in Annex 1 and keeps them appropriate to the risk.

5. Sub-processors

The Controller authorizes the sub-processors listed in the Privacy Policy. The Processor imposes data protection obligations on them equivalent to this DPA, remains responsible for them, and gives at least 30 days' notice of new sub-processors by updating the list and notifying account owners, during which the Controller may object on reasonable grounds and, if no solution is found, terminate the affected service with a pro-rata refund.

6. Assistance

The Processor helps the Controller, taking into account the nature of the processing, to respond to data subject requests (export and deletion tools are built into Glassy), and with security, breach notification, impact assessments and consultations with authorities.

7. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information available and updates as it becomes available.

8. Deletion

On termination, or when the Controller deletes data or a workspace, the Processor deletes the personal data, with backup copies overwritten within [7] days, unless the law requires retention. The Controller can export data at any time before deletion.

9. Audits

The Processor makes available the information needed to demonstrate compliance with this DPA and allows reasonable audits, no more than once a year, with 30 days' notice, during business hours and under confidentiality, at the Controller's cost.

10. International transfers

Where personal data is transferred to a country without an adequacy decision, the parties rely on the European Commission's standard contractual clauses (module 2 or 3 as applicable) and their UK and other equivalents, which are incorporated by reference.

11. Liability

Liability under this DPA is subject to the limitations in the Terms, to the extent permitted by law.

Annex 1: Security measures