DPA
Compliance
Complete legal, privacy, and compliance policies
Acceptable Use, Community Guidelines, Cookie Policy, Creator Agreement, DMCA, DPA, GDPR, Privacy Policy, Refund Policy, Subprocessors, Terms of Service
DPA
Effective Date: June 18, 2025
Last Updated: June 18, 2025
This Data Processing Agreement ("DPA") supplements the agreement between PopHop Technologies, Inc. ("PopHop") and the customer that agrees to the PopHop Terms of Service (the "Customer") in relation to the transfer and processing of Personal Data in connection with the performance of the Services.
1. Definitions
1.1 General Definitions
Capitalized terms used but not defined within this DPA will have the meaning set forth in the PopHop Terms of Service. The following capitalized terms used in this DPA will be defined as follows:
"Agreement" means the agreement between PopHop and Customer comprising the PopHop Terms of Service.
"Applicable Data Protection Laws" means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation): the GDPR, Swiss Data Protection Laws, UK Data Protection Laws, and the US Data Protection Laws.
... [truncated for brevity]
14. Deidentified Data
14.1 Deidentification Requirements
If PopHop receives Deidentified Data from or on behalf of Customer, PopHop shall:
14.1.1 Reidentification Prevention
Take reasonable measures to ensure the information cannot be associated with a Data Subject.
14.1.2 Public Commitment
Publicly commit to Process the Deidentified Data solely in deidentified form and not to attempt to reidentify the information.
14.1.3 Recipient Obligations
Contractually obligate any recipients of the Deidentified Data to comply with the foregoing requirements and Applicable Data Protection Laws.
15. General Provisions
15.1 Certification
The Parties hereby certify that they understand the requirements in this DPA and will comply with them.
15.2 Liability
The Parties agree that any limitations on either Party's liability under the Agreement shall not apply to any claims, losses or damages arising in respect of a breach of the SCCs.
15.3 Amendment
The Parties agree to negotiate in good faith any amendments to this DPA as may be required in connection with changes in Applicable Data Protection Laws.
15.4 Governing Law
This DPA shall be governed by the laws of the State of Delaware, consistent with the Agreement, except where the SCCs specify otherwise.
Schedule 1: Details of Processing
Part 1: Covered Data
A. LIST OF PARTIES
| Party | Role | Contact | Activities |
|---|---|---|---|
| Customer | Data Exporter (Controller) | The Community Creator/Administrator | Receipt of Services under the Agreement |
| PopHop | Data Importer (Processor) | legal@pophopmail.us | Performance of Services under the Agreement |
B. DESCRIPTION OF PROCESSING
Categories of Data Subjects:
- Community creators and administrators
- Community members
- Digital product purchasers and sellers
- Course participants
- Event attendees
- Consultation service users
Categories of Personal Data:
- Name, email address, and contact information
- Profile and account information
- Community participation and engagement data
- Digital product and service transaction data
- Course progress and completion records
- Communication and messaging data
- Payment and billing information (processed through Stripe)
- Usage analytics and platform interaction data
Special Categories of Personal Data: None (explicitly prohibited under this DPA)
Frequency of Transfer: Continuous during the term of the Agreement
Nature of Processing: Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, and destruction
Purpose of Data Transfer and Further Processing:
- Provision of community platform services
- Digital product marketplace functionality
- Course and educational content delivery
- Member-to-member transaction facilitation
- Platform analytics and improvement
- Customer support and communication
- Security and fraud prevention
Retention Period: Duration of the Agreement plus fourteen (14) days, except where longer retention is required by law
Subprocessors: As set out in Schedule 4
C. COMPETENT SUPERVISORY AUTHORITY
The competent supervisory authority will be determined based on the Customer's location and applicable data protection laws.
Part 2: Controller Processing
Platform Administration Data
Categories of Data Subjects:
- Community creators and administrators
- Platform users and members
Categories of Personal Data:
- Account and profile information
- Platform usage and interaction data
- Support and communication records
- Billing and subscription information
- Marketing preferences and engagement data
Purposes of Processing:
- Platform administration and user account management
- Customer support and communication
- Service improvement and feature development
- Marketing and promotional communications (with consent)
- Security and fraud prevention
- Legal compliance and regulatory requirements
Usage Analytics Data
Categories of Data Subjects:
- All platform users
Categories of Personal Data:
- Device and browser information
- Platform usage patterns and interactions
- Feature engagement and performance data
- Anonymized demographic information
Purposes of Processing:
- Platform performance monitoring and optimization
- User experience analysis and improvement
- Product development and feature planning
- Security monitoring and threat detection
Schedule 2: Technical and Organizational Measures
1. Introduction
PopHop employs a combination of policies, procedures, guidelines and technical and physical controls to protect the personal data it processes from accidental loss and unauthorized access, disclosure or destruction.
2. Governance and Data Protection
2.1 Security Governance
- Designated personnel responsible for security policies and implementation
- Regular review and update of security measures and policies
- Security considerations integrated into development and deployment processes
- Incident response procedures documented and regularly tested
2.2 Data Protection Policies
- Comprehensive data protection and privacy policies
- Regular staff training on data protection requirements
- Clear data handling and processing procedures
- Data retention and deletion policies aligned with legal requirements
3. Access Controls and Authentication
3.1 User Access Management
- Role-based access controls limiting data access to authorized personnel
- Multi-factor authentication for sensitive system access
- Regular access reviews and privilege management
- Automated user account provisioning and deprovisioning
3.2 Administrative Controls
- Separation of administrative and user privileges
- Logging and monitoring of administrative access
- Change management procedures for system modifications
- Regular password policy enforcement and updates
4. Data Security Measures
4.1 Encryption
- Data encrypted at rest using AES-256 encryption
- Data encrypted in transit using TLS 1.2 or higher
- Encryption key management with separate key storage
- Regular encryption key rotation and security assessment
4.2 Network Security
- Firewall protection with intrusion detection and prevention
- Network segmentation and access controls
- Regular vulnerability assessments and penetration testing
- DDoS protection and traffic monitoring
5. Infrastructure Security
5.1 Cloud Security
- Secure cloud hosting with reputable providers (Vercel, Supabase, AWS)
- Regular security assessments of cloud infrastructure
- Data residency controls and geographic restrictions
- Backup and disaster recovery procedures
5.2 Application Security
- Secure coding practices and code review procedures
- Regular security testing and vulnerability scanning
- Web application firewalls and security monitoring
- Secure API design and authentication mechanisms
6. Data Processing Controls
6.1 Data Minimization
- Collection limited to necessary data for specified purposes
- Regular data audits and unnecessary data purging
- Privacy by design in system development
- Data anonymization and pseudonymization where appropriate
6.2 Data Quality and Integrity
- Data validation and quality assurance procedures
- Regular data backup and integrity verification
- Version control and change tracking
- Data correction and rectification procedures
7. Monitoring and Logging
7.1 Security Monitoring
- Continuous monitoring of system security and performance
- Automated threat detection and response systems
- Regular log analysis and security event correlation
- Real-time alerting for security incidents
7.2 Audit Logging
- Comprehensive logging of data access and processing activities
- Tamper-evident log storage and retention
- Regular log review and analysis procedures
- Compliance reporting and audit trail maintenance
8. Incident Response
8.1 Incident Management
- Documented incident response procedures and playbooks
- Designated incident response team and escalation procedures
- Regular incident response training and simulation exercises
- Post-incident analysis and improvement processes
8.2 Breach Notification
- Procedures for timely breach detection and assessment
- Customer and regulatory notification processes
- Breach containment and remediation procedures
- Documentation and reporting requirements
9. Vendor and Subprocessor Management
9.1 Third-Party Security
- Security assessments of all subprocessors and vendors
- Contractual security requirements and obligations
- Regular security reviews and compliance monitoring
- Incident coordination and notification procedures
9.2 Supply Chain Security
- Vendor risk assessment and management procedures
- Secure software development lifecycle practices
- Third-party security certification requirements
- Regular vendor security audits and assessments
10. Physical and Environmental Security
10.1 Facility Security
- Physical access controls and monitoring systems
- Environmental monitoring and protection measures
- Secure disposal of physical media and equipment
- Business continuity and disaster recovery planning
10.2 Equipment Security
- Asset inventory and lifecycle management
- Secure configuration and hardening standards
- Regular maintenance and security patching
- Secure decommissioning and data destruction
Schedule 3: Standard Contractual Clauses
1. EU Standard Contractual Clauses
With respect to any transfers referred to in section 13, the Standard Contractual Clauses shall be completed as follows:
1.1 Module Application
Module Two (controller to processor) of the SCCs will apply.
1.2 Docking Clause
Clause 7 of the Standard Contractual Clauses (Docking Clause) does not apply.
1.3 Subprocessor Authorization
Option 2 of Clause 9(a) (General written authorization) shall apply, and the time period to be specified is determined in section 7.4 of the DPA.
1.4 Dispute Resolution
The option in Clause 11(a) of the Standard Contractual Clauses (Independent dispute resolution body) does not apply.
1.5 Governing Law
With regard to Clause 17 of the Standard Contractual Clauses (Governing law), the Parties agree that option 1 will apply and the governing law will be the laws of the State of Delaware.
1.6 Jurisdiction
In Clause 18 of the Standard Contractual Clauses (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of Delaware.
1.7 Processing Details
For the purpose of Annex I of the Standard Contractual Clauses, Part 1 of Schedule 1 of the DPA contains the specifications regarding the parties, the description of transfer, and the competent supervisory authority.
1.8 Technical Measures
For the purpose of Annex II of the Standard Contractual Clauses, Schedule 2 of the DPA contains the technical and organizational measures.
2. UK Addendum
This paragraph applies to any transfer of Covered Data from Customer to PopHop to the extent that UK Data Protection Laws apply to Customer when making that transfer. The UK Addendum (International Data Transfer Agreement) will form part of this DPA and execution of this DPA shall have the same effect as signing the UK Addendum.
3. Swiss Addendum
This Swiss Addendum applies to any Processing of Covered Data that is subject to Swiss Data Protection Laws. The Standard Contractual Clauses will be modified as necessary to comply with Swiss data protection requirements.
4. Other Jurisdictions
For transfers subject to other data protection laws, the SCCs will be interpreted and modified as necessary to provide appropriate safeguards under the applicable laws.
Schedule 4: Subprocessors
| Subprocessor | Location | Contact | Service Purpose |
|---|---|---|---|
| Stripe, Inc. | 510 Townsend Street, San Francisco, CA 94103 | dpo@stripe.com | Payment processing and billing |
| Supabase, Inc. | San Francisco, CA | privacy@supabase.com | Database hosting and real-time services |
| Vercel Inc. | San Francisco, CA | privacy@vercel.com | Web hosting and content delivery |
| Cloudflare, Inc. | 101 Townsend Street, San Francisco, CA 94107 | privacyquestions@cloudflare.com | CDN and security services |
| Google LLC | 1600 Amphitheatre Pkwy, Mountain View, CA 94043 | privacy@google.com | Analytics and advertising services |
| Intercom, Inc. | 55 2nd Street, San Francisco, CA 94105 | privacy@intercom.com | Customer support and communication |
| Loops | Email marketing and communication | privacy@loops.so | Marketing automation |
| Resend | Email delivery services | privacy@resend.com | Transactional email delivery |
Future Subprocessors (Planned):
- Zapier, Inc. - Workflow automation
- Make (Integromat) - Integration platform
- n8n - Workflow automation (open source)
PopHop will provide 30 days' notice before adding new subprocessors as specified in Section 7.4 of this DPA.
Contact Information: PopHop Technologies, Inc.
2648 International Boulevard Ste 115 #1108
Oakland, CA 94601, US
Email: legal@pophopmail.us
Last Updated: June 18, 2025
_This Data Processing Agreement ensures compliance with global data protection regulations while enabling PopHop to provide comprehensive community platform services to business customers.