Acme Notes
Prohttps://acmenotes.exampleDownload
Translate
Set ANTHROPIC_API_KEY in .env.local to enable translations.
Data Processing Agreement
Acme Notes · Last updated: October 7, 2026
1. Scope and parties
This Data Processing Agreement ("DPA") forms part of the agreement between Acme Labs ApS, Example Street 1, 1000 Copenhagen, Denmark ("we", "us" or the "Processor"), and the customer that uses Acme Notes (the "Customer" or "Controller") under our Terms of Use or another written agreement (the "Agreement").
It applies when we process personal data on the Customer's behalf while providing Acme Notes (the "Service"). It does not cover personal data we process as a controller, such as account and billing details, which our Privacy Policy describes.
2. Definitions
- Data Protection Law means all laws that apply to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018; and US state privacy laws, including the California Consumer Privacy Act as amended ("CCPA").
- Customer Personal Data means personal data that we process on the Customer's behalf in providing the Service.
- Subprocessor means a third party we engage to process Customer Personal Data.
- Terms such as "controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in Data Protection Law.
3. Roles and instructions
The Customer is the controller and we are the processor of Customer Personal Data. We process Customer Personal Data only on the Customer's documented instructions, which are the Agreement, this DPA and the Customer's use and configuration of the Service, unless the law requires otherwise. In that case we will tell the Customer before processing, unless the law prohibits it. We will tell the Customer if we believe an instruction breaks Data Protection Law.
The Customer is responsible for having a lawful basis for the processing and for the accuracy of the Customer Personal Data it submits.
4. Our obligations
We will:
- ensure that everyone authorised to process Customer Personal Data is bound by confidentiality;
- implement and maintain the technical and organisational measures in Annex II, which we may update as long as the overall level of protection does not decrease;
- not sell Customer Personal Data or use it for our own purposes, except to provide, secure and improve the Service in aggregated or de-identified form where Data Protection Law permits it.
5. Subprocessors
The Customer gives us general authorisation to engage Subprocessors. Our current Subprocessors are listed in Annex III and on our subprocessor list. We will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance.
We will notify the Customer at least 30 days before engaging a new Subprocessor. The Customer may object on reasonable data protection grounds within that period. If we cannot reasonably address the objection, either party may terminate the affected part of the Service, and we will refund any prepaid fees for the remaining term.
6. International transfers
We may transfer Customer Personal Data outside the European Economic Area, the United Kingdom or Switzerland only in compliance with Data Protection Law. Where a transfer goes to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module Two between controller and processor; Module Three for onward transfers to Subprocessors) and, for the UK, the International Data Transfer Addendum are incorporated into this DPA. The Subprocessors in Annex III marked "SCCs" receive data under such safeguards.
7. Assistance
Taking into account the nature of the processing, we will assist the Customer with appropriate measures to respond to requests from data subjects exercising their rights, and with data protection impact assessments, prior consultations with supervisory authorities and security obligations. If we receive a request directly from a data subject about Customer Personal Data, we will pass it on to the Customer and not respond ourselves, except to confirm that the request relates to the Customer.
8. Personal data breaches
We will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We will take reasonable steps to contain the breach and limit its effects.
9. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA. The Customer may audit our compliance, at its own cost and no more than once a year (unless required by a supervisory authority or after a personal data breach), with at least 30 days' written notice, during business hours and subject to confidentiality. Where available, we may meet this obligation by providing recent third-party audit reports or certifications.
10. Return and deletion
When the Agreement ends, we will, at the Customer's choice, return or delete Customer Personal Data within 30 days, unless the law requires us to keep it. Data in backups will be deleted as the backups expire in the normal course and kept protected until then.
11. US state privacy laws
For the purposes of the CCPA and similar US state laws, we act as the Customer's "service provider" or "processor". We will not sell or share Customer Personal Data; retain, use or disclose it for any purpose other than the business purposes specified in the Agreement; retain, use or disclose it outside the direct business relationship with the Customer; or combine it with personal data we receive from other sources, except as those laws permit. We will notify the Customer if we can no longer meet these obligations, and the Customer may take reasonable steps to stop and remediate unauthorised use.
12. Term and precedence
This DPA stays in force for as long as we process Customer Personal Data. If it conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data; if it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail. Each party's liability under this DPA is subject to the limitations in the Agreement, to the extent Data Protection Law allows. This DPA is governed by the law that governs the Agreement.
13. Annex I: Details of processing
| Item | Details |
|---|---|
| Subject matter | Providing Acme Notes to the Customer under the Agreement |
| Duration | The term of the Agreement, plus the period until deletion under this DPA |
| Nature and purpose | Hosting, storing, transmitting and otherwise processing Customer Personal Data to provide, secure and support the Service |
| Data subjects | The Customer's authorised users, and individuals whose personal data the Customer submits to the Service |
| Personal data | Contact details (name, email address); Identifiers (user ID, IP address, advertising ID); Usage data (pages and features used, clicks, session duration); Communications (support conversations, emails you send us); Device and technical data (browser type, operating system, device model, language); Content you provide (files, text and other material you submit); Approximate location (country or city derived from IP address); Payment and transaction data (billing address, purchase history, last four digits of your card); Account information (login credentials, profile settings) |
| Special categories | None intended. The Customer will not submit special category data unless agreed in writing |
| Frequency | Continuous, for the duration of the Agreement |
14. Annex II: Technical and organisational measures
- Encryption: data is encrypted in transit (TLS 1.2 or higher) and at rest.
- Access control: access to production systems and Customer Personal Data is limited to personnel who need it, protected by strong authentication, and reviewed regularly.
- Separation: Customer data is logically separated from other customers' data.
- Availability: regular backups, redundant infrastructure and a tested recovery process.
- Monitoring: logging of access to production systems and alerting on suspicious activity.
- Secure development: code review, dependency updates and vulnerability fixes in a reasonable time.
- Vendor management: Subprocessors are assessed before use and bound by written data protection terms.
- People: confidentiality commitments and security awareness for everyone with access to Customer Personal Data.
- Incident response: a documented process for detecting, containing and reporting personal data breaches.
15. Annex III: Subprocessors
| Subprocessor | Purpose | Personal data | Location |
|---|---|---|---|
| Intercom (Intercom R&D Unlimited Company) | Live chat, support conversations and in-app messages. | Contact details, Communications, Identifiers, Usage data, Device and technical data | European Union |
| OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd) | Generates AI responses for features you use. | Content you provide | United States (SCCs) |
| PostHog (PostHog, Inc.) | Product analytics, feature flags and session replay. | Identifiers, Usage data, Device and technical data, Approximate location | European Union |
| Resend (Resend, Inc.) | Sends account and transactional emails. | Contact details, Communications | United States (SCCs) |
| Stripe (Stripe, Inc. and Stripe Payments Europe, Ltd.) | Processes payments and subscriptions and prevents fraud. | Contact details, Payment and transaction data, Identifiers, Device and technical data | United States (SCCs) |
| Supabase (Supabase, Inc.) | Hosts the application database, user authentication and uploaded files. | Identifiers, Contact details, Account information, Content you provide | Frankfurt, Germany |
This draft was assembled automatically from your answers and the clause library. It is not legal advice and may not cover everything your product does. Have a qualified lawyer review it before you publish.