DPA

Compliance

Complete legal, privacy, and compliance policies

Acceptable Use, Community Guidelines, Cookie Policy, Creator Agreement, DMCA, DPA, GDPR, Privacy Policy, Refund Policy, Subprocessors, Terms of Service

DPA

Effective Date: June 18, 2025

Last Updated: June 18, 2025

This Data Processing Agreement ("DPA") supplements the agreement between PopHop Technologies, Inc. ("PopHop") and the customer that agrees to the PopHop Terms of Service (the "Customer") in relation to the transfer and processing of Personal Data in connection with the performance of the Services.

1. Definitions

1.1 General Definitions

Capitalized terms used but not defined within this DPA will have the meaning set forth in the PopHop Terms of Service. The following capitalized terms used in this DPA will be defined as follows:

"Agreement" means the agreement between PopHop and Customer comprising the PopHop Terms of Service.

"Applicable Data Protection Laws" means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation): the GDPR, Swiss Data Protection Laws, UK Data Protection Laws, and the US Data Protection Laws.

... [truncated for brevity]

14. Deidentified Data

14.1 Deidentification Requirements

If PopHop receives Deidentified Data from or on behalf of Customer, PopHop shall:

14.1.1 Reidentification Prevention

Take reasonable measures to ensure the information cannot be associated with a Data Subject.

14.1.2 Public Commitment

Publicly commit to Process the Deidentified Data solely in deidentified form and not to attempt to reidentify the information.

14.1.3 Recipient Obligations

Contractually obligate any recipients of the Deidentified Data to comply with the foregoing requirements and Applicable Data Protection Laws.

15. General Provisions

15.1 Certification

The Parties hereby certify that they understand the requirements in this DPA and will comply with them.

15.2 Liability

The Parties agree that any limitations on either Party's liability under the Agreement shall not apply to any claims, losses or damages arising in respect of a breach of the SCCs.

15.3 Amendment

The Parties agree to negotiate in good faith any amendments to this DPA as may be required in connection with changes in Applicable Data Protection Laws.

15.4 Governing Law

This DPA shall be governed by the laws of the State of Delaware, consistent with the Agreement, except where the SCCs specify otherwise.

Schedule 1: Details of Processing

Part 1: Covered Data

A. LIST OF PARTIES

Party Role Contact Activities
Customer Data Exporter (Controller) The Community Creator/Administrator Receipt of Services under the Agreement
PopHop Data Importer (Processor) legal@pophopmail.us Performance of Services under the Agreement

B. DESCRIPTION OF PROCESSING

Categories of Data Subjects:

Categories of Personal Data:

Special Categories of Personal Data: None (explicitly prohibited under this DPA)

Frequency of Transfer: Continuous during the term of the Agreement

Nature of Processing: Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, and destruction

Purpose of Data Transfer and Further Processing:

Retention Period: Duration of the Agreement plus fourteen (14) days, except where longer retention is required by law

Subprocessors: As set out in Schedule 4

C. COMPETENT SUPERVISORY AUTHORITY

The competent supervisory authority will be determined based on the Customer's location and applicable data protection laws.

Part 2: Controller Processing

Platform Administration Data

Categories of Data Subjects:

Categories of Personal Data:

Purposes of Processing:

Usage Analytics Data

Categories of Data Subjects:

Categories of Personal Data:

Purposes of Processing:

Schedule 2: Technical and Organizational Measures

1. Introduction

PopHop employs a combination of policies, procedures, guidelines and technical and physical controls to protect the personal data it processes from accidental loss and unauthorized access, disclosure or destruction.

2. Governance and Data Protection

2.1 Security Governance

2.2 Data Protection Policies

3. Access Controls and Authentication

3.1 User Access Management

3.2 Administrative Controls

4. Data Security Measures

4.1 Encryption

4.2 Network Security

5. Infrastructure Security

5.1 Cloud Security

5.2 Application Security

6. Data Processing Controls

6.1 Data Minimization

6.2 Data Quality and Integrity

7. Monitoring and Logging

7.1 Security Monitoring

7.2 Audit Logging

8. Incident Response

8.1 Incident Management

8.2 Breach Notification

9. Vendor and Subprocessor Management

9.1 Third-Party Security

9.2 Supply Chain Security

10. Physical and Environmental Security

10.1 Facility Security

10.2 Equipment Security

Schedule 3: Standard Contractual Clauses

1. EU Standard Contractual Clauses

With respect to any transfers referred to in section 13, the Standard Contractual Clauses shall be completed as follows:

1.1 Module Application

Module Two (controller to processor) of the SCCs will apply.

1.2 Docking Clause

Clause 7 of the Standard Contractual Clauses (Docking Clause) does not apply.

1.3 Subprocessor Authorization

Option 2 of Clause 9(a) (General written authorization) shall apply, and the time period to be specified is determined in section 7.4 of the DPA.

1.4 Dispute Resolution

The option in Clause 11(a) of the Standard Contractual Clauses (Independent dispute resolution body) does not apply.

1.5 Governing Law

With regard to Clause 17 of the Standard Contractual Clauses (Governing law), the Parties agree that option 1 will apply and the governing law will be the laws of the State of Delaware.

1.6 Jurisdiction

In Clause 18 of the Standard Contractual Clauses (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of Delaware.

1.7 Processing Details

For the purpose of Annex I of the Standard Contractual Clauses, Part 1 of Schedule 1 of the DPA contains the specifications regarding the parties, the description of transfer, and the competent supervisory authority.

1.8 Technical Measures

For the purpose of Annex II of the Standard Contractual Clauses, Schedule 2 of the DPA contains the technical and organizational measures.

2. UK Addendum

This paragraph applies to any transfer of Covered Data from Customer to PopHop to the extent that UK Data Protection Laws apply to Customer when making that transfer. The UK Addendum (International Data Transfer Agreement) will form part of this DPA and execution of this DPA shall have the same effect as signing the UK Addendum.

3. Swiss Addendum

This Swiss Addendum applies to any Processing of Covered Data that is subject to Swiss Data Protection Laws. The Standard Contractual Clauses will be modified as necessary to comply with Swiss data protection requirements.

4. Other Jurisdictions

For transfers subject to other data protection laws, the SCCs will be interpreted and modified as necessary to provide appropriate safeguards under the applicable laws.

Schedule 4: Subprocessors

Subprocessor Location Contact Service Purpose
Stripe, Inc. 510 Townsend Street, San Francisco, CA 94103 dpo@stripe.com Payment processing and billing
Supabase, Inc. San Francisco, CA privacy@supabase.com Database hosting and real-time services
Vercel Inc. San Francisco, CA privacy@vercel.com Web hosting and content delivery
Cloudflare, Inc. 101 Townsend Street, San Francisco, CA 94107 privacyquestions@cloudflare.com CDN and security services
Google LLC 1600 Amphitheatre Pkwy, Mountain View, CA 94043 privacy@google.com Analytics and advertising services
Intercom, Inc. 55 2nd Street, San Francisco, CA 94105 privacy@intercom.com Customer support and communication
Loops Email marketing and communication privacy@loops.so Marketing automation
Resend Email delivery services privacy@resend.com Transactional email delivery

Future Subprocessors (Planned):

PopHop will provide 30 days' notice before adding new subprocessors as specified in Section 7.4 of this DPA.

Contact Information: PopHop Technologies, Inc.

2648 International Boulevard Ste 115 #1108

Oakland, CA 94601, US

Email: legal@pophopmail.us

Last Updated: June 18, 2025

_This Data Processing Agreement ensures compliance with global data protection regulations while enabling PopHop to provide comprehensive community platform services to business customers.