This Data Processing Agreement (the “DPA”) forms part of the Terms of Service, an Order Form, or another written agreement between Streamforge Inc. (“Streamforge”) and the customer identified in that agreement (“Customer”) (collectively, the “Agreement”).

This DPA applies only to the extent Streamforge Processes Customer Personal Data on Customer’s behalf in providing the Services. It becomes effective on the effective date of the Agreement or, if later, when Streamforge first Processes Customer Personal Data for Customer.

1. Definitions

“Applicable Data Protection Law” means privacy, data protection, and data security law applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Canada’s PIPEDA and substantially similar provincial laws, and U.S. state comprehensive privacy laws.

“Customer Personal Data” means Personal Data contained in data, content, or communications that Customer or its Authorized Users submit to, upload to, connect to, or generate through the Services and that Streamforge Processes on Customer’s behalf. It does not include Personal Data Streamforge Processes as an independent Controller, including publicly available creator intelligence obtained independently of Customer, business-contact data used to manage the commercial relationship, or service data used for Streamforge’s own security, fraud prevention, billing, and legal-compliance purposes.

“Security Incident” means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans, pings, or login attempts.

“Subprocessor” means a third party appointed by Streamforge to Process Customer Personal Data on Customer’s behalf. “Controller,” “Data Subject,” “Personal Data,” “Process,” “Processor,” and “Service Provider” have the meanings given by Applicable Data Protection Law.

2. Scope and roles

Customer is the Controller or Business of Customer Personal Data and Streamforge is its Processor or Service Provider. If Customer acts as a Processor for another Controller, Streamforge acts as Customer’s Subprocessor. Each party will comply with the obligations applicable to its role.

The Agreement, Customer’s configuration and authorized use of the Services, and any additional written instructions agreed by the parties are Customer’s documented instructions. Streamforge will Process Customer Personal Data only on those instructions, including for transfers, unless law requires otherwise. If legally permitted, Streamforge will notify Customer before Processing required by law.

Streamforge will promptly inform Customer if, in Streamforge’s reasonable opinion, an instruction violates Applicable Data Protection Law. Streamforge may suspend the affected Processing while the parties resolve the issue.

Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; providing required notices; obtaining required consents or other legal bases; and ensuring its instructions and use of the Services comply with Applicable Data Protection Law.

3. Details of Processing

The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex 1. Customer may provide reasonable additional instructions consistent with the Agreement. If an instruction requires a material change to the Services or creates disproportionate cost, the parties will agree on scope, timing, and fees before Streamforge implements it.

4. Confidentiality

Streamforge will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and receive access only as necessary for their responsibilities.

5. Security

Taking into account the state of the art, implementation cost, and the nature, scope, context, purposes, and risks of the Processing, Streamforge will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The current measures are summarized in Annex 2 and the Trust Center. Streamforge may update them provided the overall protection of Customer Personal Data is not materially reduced.

6. Subprocessors

Customer gives Streamforge general written authorization to engage the Subprocessors on Streamforge’s Subprocessor List. A provider Processes Customer Personal Data only when the relevant Service or feature is used.

Streamforge will give reasonable advance notice of a material new Subprocessor by updating the Subprocessor List and, where practicable, by email or in-product notice. Customer may object within ten (10) days on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If no reasonable solution is available, Customer may discontinue the affected feature or terminate the affected portion of the Services without penalty.

Streamforge will impose data-protection obligations on each Subprocessor that provide a level of protection appropriate to the Processing and will remain responsible for the Subprocessor’s performance as required by Applicable Data Protection Law.

7. Data Subject requests

Taking into account the nature of the Processing, Streamforge will provide reasonable assistance through appropriate technical and organizational measures so Customer can respond to requests to exercise Data Subject rights. If Streamforge receives a request relating to Customer Personal Data, Streamforge will promptly direct the requester to Customer unless law prohibits doing so. Customer remains responsible for responding to the request.

8. Security Incidents

Streamforge will notify Customer without undue delay after becoming aware of a Security Incident. As information becomes available, the notice will describe the nature of the incident, affected data and Data Subjects where known, likely consequences, mitigation taken or proposed, and a contact for follow-up. Streamforge will take reasonable steps to contain, investigate, and remediate the Security Incident and will reasonably cooperate with Customer.

Streamforge’s notice or response is not an admission of fault or liability. Customer is responsible for determining whether to notify a regulator or Data Subject and for making those notifications, except where law places that obligation directly on Streamforge.

9. Compliance assistance

Taking into account the nature of the Processing and information available to Streamforge, Streamforge will provide reasonable assistance with Customer’s obligations concerning security, breach notification, data protection impact assessments, and prior consultation with regulators. Customer will reimburse reasonable costs for assistance that is unusually burdensome or outside the ordinary operation of the Services, unless the need results from Streamforge’s breach of this DPA.

10. Demonstrating compliance and audits

On reasonable request, Streamforge will make available information necessary to demonstrate compliance with this DPA, including relevant security documentation and summaries of independent assessments, if available. Customer will first use that information to satisfy its audit needs.

If that information is reasonably insufficient, Customer may conduct one audit in any twelve-month period through an independent, qualified auditor bound by confidentiality, on at least thirty (30) days’ notice and during normal business hours. Additional audits are permitted following a Security Incident or when required by a regulator. An audit must avoid unreasonable disruption and access to other customers’ data. Customer bears its audit costs unless the audit identifies Streamforge’s material breach of this DPA.

11. Return and deletion

On termination or expiration of the Services, and at Customer’s choice where technically available, Streamforge will return or delete Customer Personal Data within a reasonable period, unless law requires retention. Customer is responsible for exporting data it wishes to keep before termination. Customer Personal Data remaining in protected backups will be put beyond ordinary use and deleted through the applicable backup lifecycle, subject to legal retention obligations.

12. International transfers

Streamforge may Process Customer Personal Data in Canada, the United States, and other locations used by authorized Subprocessors. Where Applicable Data Protection Law restricts a transfer, Streamforge will use a legally recognized transfer mechanism, such as an adequacy decision, approved contractual clauses, or another valid safeguard.

If no other valid mechanism applies to a transfer from the European Economic Area, the relevant module of the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 will apply to the extent required. For restricted transfers from the United Kingdom or Switzerland, the parties will apply the legally required UK or Swiss adaptations. The parties will reasonably cooperate to complete required transfer documentation and assessments.

13. U.S. state privacy terms

To the extent a U.S. state privacy law applies and Streamforge acts as a Service Provider, Contractor, or Processor, Streamforge will Process Customer Personal Data only for the specific business purposes described in Annex 1 and the Agreement. Streamforge will not sell or share Customer Personal Data; retain, use, or disclose it outside those purposes or the direct business relationship; or combine it with Personal Data received from another person or collected from Streamforge’s own interaction with a consumer, except as permitted by law.

Streamforge will provide the same level of privacy protection required by applicable law, notify Customer if Streamforge determines it can no longer meet those obligations, and cooperate with reasonable monitoring and remediation steps. Streamforge certifies that it understands and will comply with these restrictions.

14. Liability, conflict, and term

Each party’s liability under this DPA is subject to the exclusions and limitations in the Agreement, except to the extent prohibited by Applicable Data Protection Law. If this DPA conflicts with the Agreement, this DPA controls only for the Processing of Customer Personal Data. Mandatory transfer terms control over both where they conflict.

This DPA remains in force while Streamforge Processes Customer Personal Data. Except where mandatory transfer terms require otherwise, it is governed by the governing-law and dispute provisions of the Agreement.

15. Contact

Questions, notices, and Subprocessor objections may be sent to privacy@streamforge.com or Streamforge Inc., Attn: Privacy Team, 5605 Av de Gaspe, Suite 108, Montreal, QC H2T 2A4, Canada.

Annex 1 — Details of Processing

Subject matter and duration. Processing Customer Personal Data to provide, secure, maintain, support, and improve the contracted Services for the term of the Agreement and the limited retention period described in Section 11.

Nature and purpose. Hosting and organizing customer workspaces; influencer discovery and intelligence; CRM records, lists, campaigns, deliverables, analytics, and reporting; connected-email synchronization and sending; document handling; AI-assisted analysis and workflow features; authentication, support, security, and service administration.

Processing operations. Collection, recording, organization, storage, retrieval, consultation, analysis, enrichment, segmentation, transmission, display, export, restriction, deletion, and other operations initiated by Customer’s authorized use of the Services.

Categories of Data Subjects

  • Customer administrators, Authorized Users, employees, contractors, and business contacts.

  • Creators, influencers, campaign participants, prospects, and other contacts whose data Customer submits or manages.

  • Senders and recipients of messages in an email account Customer connects to the Services.

  • People identified in Customer-uploaded files, CRM notes, support messages, or other Customer Data.

Categories of Customer Personal Data

  • Identifiers and contact data, including names, work details, usernames, social handles, email addresses, and phone numbers.

  • Account, organization, permission, authentication, subscription, and billing metadata.

  • CRM records, notes, tags, lists, campaign data, contracts, deliverables, performance data, and communications.

  • Connected-email content, headers, metadata, recipients, attachments, and authorization tokens.

  • Uploaded documents and other Customer Content.

  • Usage, device, browser, IP address, event, log, diagnostic, support, and bug-report data.

  • AI feature inputs and outputs, including prompts, selected records, analysis context, and generated results.

Sensitive data. The Services are not designed to require Customer to submit special-category, highly sensitive, health, biometric, financial-account credential, or criminal-conviction data as Customer Personal Data. Customer must not submit such data unless the parties expressly agree in writing on the Processing and safeguards. This restriction does not characterize Streamforge’s separate, independent-controller processing of public creator intelligence.

Frequency. Continuous or on demand, depending on Customer’s use and configuration of the Services.

Annex 2 — Technical and Organizational Measures

Streamforge’s security program uses measures proportionate to the Services and risk, including:

  • Access control and tenant isolation. Role- and organization-aware authorization, least-privilege access, and logical separation of customer workspaces.

  • Authentication and secrets. Controlled authentication flows, time-limited account-recovery codes, and managed handling of credentials and service secrets.

  • Encryption. Encryption in transit and storage-level encryption at rest provided by managed infrastructure where applicable.

  • Data minimization and logging controls. Collection limited to service purposes, with sensitive authorization data and designated request or response content removed from relevant diagnostics and session-replay paths.

  • Change and software security. Version-controlled code and security-relevant configuration, controlled deployment processes, and risk-based dependency and vulnerability remediation.

  • Availability and recovery. Service monitoring, protected backups and recovery procedures appropriate to the system, and capacity and resilience practices.

  • Incident response. Monitoring, escalation, investigation, containment, remediation, and customer-notification procedures for suspected security events.

  • Personnel security. Confidentiality obligations and access limited to personnel with a business need.

  • Supplier oversight. Selection and review of providers that support the Services, with contractual flow-down of applicable data-protection obligations.

  • Data lifecycle. Processes designed to support Customer export, deletion, or return requests and secure disposal at the end of the applicable retention lifecycle.

  • Physical security. Reliance on the physical and environmental controls of vetted cloud and data-center providers.

Annex 3 — Authorized Subprocessors

The current authorized Subprocessors, their functions, relevant data, and general processing locations are listed on the Streamforge Subprocessor List.