Digitaura Data Processing Addendum (DPA)
Effective Date: August 14, 2026
Last Updated: August 14, 2026
This Data Processing Addendum (“DPA”) supplements the Master Services Agreement or Terms of Service (“Agreement”) entered into by and between Digitaura, Inc. (“Processor,” “Provider,” “we,” “us”) and the customer party to the Agreement (“Controller,” “Customer”).
1. Purpose & Scope
1.1 Purpose
This DPA governs the Processing of Personal Data (as defined under Applicable Data Protection Law) by Processor on behalf of Controller in connection with the provision of the Digitaura software platform and related services under the Agreement.
1.2 Applicable Privacy Frameworks
This DPA applies to the extent Processor processes Personal Data subject to:
- The EU General Data Protection Regulation 2016/679 (“GDPR”);
- The UK General Data Protection Regulation (“UK GDPR”);
- The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”); and
- Other applicable state, federal, or international data protection statutes.
2. On-Device Edge Compute Architecture & Data Processing Scope
2.1 On-Premises Edge Compute Exception
The Parties explicitly acknowledge and agree to the following structural technical reality of the Software:
- Local Execution: The Software operates as an on-device local-first platform on Controller’s Apple Silicon hardware.
- Controller Custody: All primary processing of Controller’s records, files, vector embeddings, optical character recognition (OCR) extractions, financial journal entries, audio recordings, and work orders occurs locally on Controller’s physical devices (
~/Vault/). - Zero Processor Access: Processor does not store, possess, or have network access to Controller’s local Vault files or on-device databases. Processor does not act as a remote data host or cloud repository for Controller Data.
2.2 Limited Processor Role
To the extent Processor receives, processes, or transmits any Personal Data directly (such as account credentials, subscription metadata, billing contact details, or support communications), Processor shall act strictly as a Processor (or “Service Provider”) under the direction and instruction of Controller (the Controller).
3. Obligations of Processor
When acting as a Processor or Service Provider, Processor agrees that it shall:
- Processing Instructions: Process Personal Data only in accordance with Controller’s documented lawful instructions, including with respect to transfers of Personal Data outside the EEA/UK, unless required to do so by applicable law.
- Confidentiality: Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- No Commercial Exploitation: Not “sell” or “share” (as defined under the CCPA/CPRA) Personal Data, nor retain, use, or disclose Personal Data for any commercial purpose other than providing the services specified in the Agreement.
4. Technical & Organizational Measures (TOMs)
Processor implements and maintains appropriate technical and organizational measures to safeguard any account or administrative Personal Data within its custody against unauthorized or unlawful processing, accidental loss, destruction, or damage.
4.1 Security Specifications
- Local Application Security: The Software implements strict local POSIX permission controls (
0600) restricting local data files and sockets to the local user account on macOS, iOS, and watchOS. - Local Network Encryption: Device-to-device synchronization between macOS compute host, iOS client, and watchOS companion across local Wi-Fi networks utilizes ephemeral session keys and local TLS transport encryption.
- Transit Security: Administrative API calls (e.g., license validation, billing requests) enforce TLS 1.3 encryption in transit over public networks.
- Access Control: Administrative access to payment processor tokens and support ticketing systems is restricted to authorized personnel using multi-factor authentication (MFA).
5. Subprocessors
5.1 Authorized Subprocessors
Controller grants Processor general written authorization to engage third-party Subprocessors strictly necessary to operate billing, license validation, and transactional email infrastructure. A current list of authorized Subprocessors is detailed below:
| Subprocessor Name | Role / Function | Location |
|---|---|---|
| Stripe, Inc. | Payment card processing and subscription billing | United States |
| Apple Inc. | iOS/macOS App Store distribution and in-app purchase validation | United States |
| Postmark / SendGrid | Transactional administrative email delivery | United States |
5.2 Subprocessor Obligations
Processor shall enter into a written agreement with each Subprocessor containing data protection obligations no less protective than those set forth in this DPA.
5.3 Notification of Subprocessor Changes
Processor shall notify Controller at least fourteen (14) days prior to appointing any new Subprocessor by updating its online Subprocessor documentation or issuing an administrative email alert. Controller may object to a new Subprocessor on reasonable data protection grounds within ten (10) days of notification.
6. Personal Data Breaches
6.1 Breach Notification
In the event Processor becomes aware of a confirmed Security Incident or Personal Data Breach affecting account or administrative Personal Data within Processor’s direct systems or Subprocessor networks, Processor shall:
- Notify Controller without undue delay, and in any event within seventy-two (72) hours of confirmation;
- Provide Controller with sufficient details regarding the nature of the incident, categories of data affected, and remedial actions taken; and
- Co-operate reasonably with Controller in investigating and mitigating the impact of the breach.
7. Data Subject Rights & Regulatory Assistance
7.1 Data Subject Assistance
Taking into account the nature of the processing, Processor shall assist Controller by implementing appropriate technical measures, insofar as possible, to fulfill Controller’s obligations to respond to requests from Data Subjects exercising their rights under GDPR or CCPA (e.g., access, deletion, rectification).
Direct Local Data Management: Because Controller retains sole direct physical control over local device hardware and Vault files (~/Vault/), Controller can directly fulfill local Data Subject access, export, or deletion requests directly on its local hardware without Processor intervention.
8. International Data Transfers
8.1 Transfer Mechanisms
To the extent processing of Personal Data involves cross-border data transfers outside the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognized as providing an adequate level of data protection, such transfers shall be governed by the Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Addendum (IDTA), which are hereby incorporated into this DPA by reference.
9. Term & Termination
This DPA shall remain in effect for as long as Processor processes Personal Data on behalf of Controller under the Agreement. Upon termination of the Agreement, Processor shall, at Controller’s election, delete or return all administrative Personal Data in its possession, except to the extent retained to satisfy statutory legal or tax obligations.
Signatures & Acceptance
IN WITNESS WHEREOF, this Data Processing Addendum is executed and forms an integral part of the Agreement between Processor and Controller.
Digitaura, Inc. (Processor)
By: ______________________________
Name: ____________________________
Title: _____________________________
Date: _____________________________
Customer / Client (Controller)
By: ______________________________
Name: ____________________________
Title: _____________________________
Date: _____________________________