# Data Processing Agreement

_Last Updated: September 2, 2026_

This Data Processing Agreement ("DPA") forms part of the Terms of Service between MediaCreators, LLC ("MediaCreators," "we," "us," or "Processor") and the customer agreeing to these terms ("Customer," "you," or "Controller") for the provision of creator analytics, streaming community, and related SaaS services (the "Services").

This DPA applies where MediaCreators processes Personal Data on behalf of Customer in the course of providing the Services, and sets out the parties' obligations with respect to data protection.

---

## 1. Definitions

**"Data Protection Laws"** means all applicable laws relating to data protection and privacy, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act ("CCPA"), and any other applicable data protection legislation.

**"Personal Data"** means any information relating to an identified or identifiable natural person that is processed by MediaCreators on behalf of Customer in connection with the Services.

**"Processing"** means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.

**"Security Incident"** means any unauthorized access to, or acquisition, use, or disclosure of Personal Data that compromises the security, confidentiality, or integrity of such data.

**"Subprocessor"** means any third party engaged by MediaCreators to process Personal Data on behalf of Customer.

---

## 2. Scope and Applicability

### 2.1 Scope of Processing

This DPA applies to the processing of Personal Data by MediaCreators on behalf of Customer as described in **Annex 1** (Details of Processing).

### 2.2 Customer as Controller

For purposes of this DPA, Customer is the data controller with respect to Customer Personal Data, and MediaCreators is the data processor.

### 2.3 Compliance with Laws

Each party shall comply with its respective obligations under applicable Data Protection Laws. MediaCreators shall process Personal Data only in accordance with Customer's documented instructions and this DPA.

---

## 3. Processing of Personal Data

### 3.1 Customer Instructions

MediaCreators shall process Personal Data only on documented instructions from Customer, including with respect to transfers of Personal Data to a third country or international organization, unless required to do so by applicable law. In such case, MediaCreators shall inform Customer of that legal requirement before processing, unless prohibited by law.

### 3.2 Purpose Limitation

MediaCreators shall process Personal Data solely for the purposes of providing the Services as described in the Terms of Service and this DPA, and shall not process Personal Data for any other purpose without Customer's prior written consent.

### 3.3 Data Minimization

MediaCreators shall ensure that Personal Data processed is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

---

## 4. Confidentiality and Personnel

### 4.1 Confidentiality Obligations

MediaCreators shall ensure that any person authorized to process Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

### 4.2 Personnel Training

MediaCreators shall ensure that personnel processing Personal Data:

- Are informed of the confidential nature of the Personal Data;
- Have received appropriate training on their responsibilities; and
- Are bound by appropriate confidentiality obligations.

### 4.3 Access Limitations

MediaCreators shall limit access to Personal Data to those personnel who require such access to perform obligations under this DPA.

---

## 5. Security Measures

### 5.1 Technical and Organizational Measures

MediaCreators shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure. These measures include:

**a) Encryption:**

- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256 encryption

**b) Access Controls:**

- Role-based access control (RBAC) for all systems
- Multi-factor authentication for administrative access
- Regular access reviews and audit logging

**c) Network Security:**

- Firewalls and intrusion detection systems
- Regular vulnerability scanning and penetration testing
- DDoS protection and mitigation

**d) Physical Security:**

- Data hosted with infrastructure providers that maintain industry-standard physical and environmental controls
- Physical access controls and continuous monitoring by those providers

**e) Business Continuity:**

- Regular data backups with encryption
- Disaster recovery procedures
- Incident response plans

### 5.2 Security Assessment

Upon Customer's written request (not more than once per year), MediaCreators shall provide Customer with documentation demonstrating MediaCreators's compliance with its security obligations under this DPA.

---

## 6. Subprocessors

### 6.1 Authorization

Customer provides general authorization for MediaCreators to engage Subprocessors to process Personal Data. The current list of Subprocessors is set forth in **Annex 2** and available at [https://mediacreators.io/legal/subprocessors](https://mediacreators.io/legal/subprocessors).

### 6.2 Subprocessor Requirements

Before engaging any Subprocessor, MediaCreators shall:

- Conduct appropriate due diligence to ensure the Subprocessor can provide the required level of protection;
- Enter into a written agreement with the Subprocessor imposing data protection obligations no less protective than those in this DPA; and
- Remain fully liable to Customer for the Subprocessor's performance.

### 6.3 Notification of Changes

MediaCreators shall notify Customer at least thirty (30) days before authorizing any new Subprocessor. Customer may object to the appointment of a new Subprocessor within fourteen (14) days of notification by providing written notice with reasonable grounds for the objection. The parties shall negotiate in good faith to resolve any objection.

---

## 7. Data Subject Rights

### 7.1 Assistance with Requests

MediaCreators shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures to fulfill Customer's obligation to respond to requests from data subjects to exercise their rights under Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.

### 7.2 Notification

If MediaCreators receives a request from a data subject relating to Customer Personal Data, MediaCreators shall promptly notify Customer and shall not respond to such request without Customer's prior written authorization, unless required by law.

---

## 8. Security Incidents

### 8.1 Notification

MediaCreators shall notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Security Incident affecting Customer Personal Data.

### 8.2 Incident Details

Such notification shall include:

- A description of the nature of the Security Incident;
- The categories and approximate number of data subjects concerned;
- The categories and approximate number of Personal Data records concerned;
- The name and contact details of MediaCreators's data protection contact;
- A description of the likely consequences of the Security Incident; and
- A description of the measures taken or proposed to address the Security Incident.

### 8.3 Cooperation

MediaCreators shall cooperate with Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of each Security Incident.

---

## 9. Data Protection Impact Assessments

Where required by Data Protection Laws, MediaCreators shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to MediaCreators.

---

## 10. International Data Transfers

### 10.1 Transfer Mechanisms

MediaCreators shall not transfer Personal Data to any country outside the European Economic Area ("EEA") or the United Kingdom unless:

- The transfer is to a country deemed to provide an adequate level of protection; or
- Appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

### 10.2 Standard Contractual Clauses

Where Standard Contractual Clauses are required for transfers, the parties agree to incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Addendum.

### 10.3 Current Safeguards

MediaCreators's primary data processing occurs in the United States. For transfers from the EEA/UK to the US, MediaCreators relies on Standard Contractual Clauses and additional technical safeguards including encryption.

---

## 11. Audits and Inspections

### 11.1 Audit Rights

MediaCreators shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or a third-party auditor mandated by Customer.

### 11.2 Audit Procedures

Audits shall be conducted:

- No more than once per calendar year, unless required by a supervisory authority or following a Security Incident;
- Upon at least thirty (30) days' prior written notice;
- During normal business hours with minimal disruption to operations;
- Subject to confidentiality obligations regarding any proprietary information accessed.

### 11.3 Audit Reports

In lieu of an on-site audit, Customer may request MediaCreators to provide copies of relevant third-party audit reports (e.g., SOC 2 Type II) and certifications.

---

## 12. Data Retention and Deletion

### 12.1 Retention Period

MediaCreators shall retain Personal Data only for as long as necessary to provide the Services and fulfill obligations under this DPA.

### 12.2 Return or Deletion

Upon termination or expiration of the Services, MediaCreators shall, at Customer's election:

- Return all Personal Data to Customer in a commonly used format; or
- Delete all Personal Data and certify such deletion in writing.

### 12.3 Deletion Timeline

Deletion shall be completed within ninety (90) days of termination, except where retention is required by applicable law. MediaCreators shall inform Customer of any such legal requirement.

### 12.4 Backup Copies

MediaCreators may retain Personal Data in backup systems for the period necessary to complete normal backup cycles, after which such data shall be deleted in accordance with standard backup deletion procedures.

---

## 13. Liability and Indemnification

### 13.1 Liability Cap

Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Terms of Service, except as expressly provided otherwise.

### 13.2 Indemnification

MediaCreators shall indemnify Customer for any damages arising from MediaCreators's breach of this DPA or applicable Data Protection Laws, to the extent such damages are not caused by Customer's instructions or Customer's own breach of Data Protection Laws.

---

## 14. Term and Termination

### 14.1 Term

This DPA shall remain in effect for the duration of the Terms of Service and for as long as MediaCreators processes Personal Data on behalf of Customer.

### 14.2 Survival

Provisions of this DPA that by their nature should survive termination shall survive, including Sections 4 (Confidentiality), 8 (Security Incidents), 12 (Data Retention and Deletion), and 13 (Liability and Indemnification).

---

## 15. Miscellaneous

### 15.1 Conflicts

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

### 15.2 Amendments

This DPA may be amended only by a written agreement signed by both parties, except that MediaCreators may update the Subprocessor list and security measures as necessary to comply with Data Protection Laws or improve security.

### 15.3 Governing Law

This DPA shall be governed by the same law that governs the Terms of Service.

### 15.4 Contact Information

For questions about this DPA or to exercise rights hereunder:

- **Email:** legal@mediacreators.io
- **Address:** MediaCreators, LLC, 2810 N Church St, STE 89584, Wilmington, DE 19802, USA
- **Phone:** +1 (740) 990-2600

---

## Annex 1: Details of Processing

### Categories of Data Subjects

- Customer's employees and authorized users
- Creators and their community members / fans who use the Services
- Public creator channel identifiers referenced for intelligence and estimate features

### Categories of Personal Data

- Account information (name, email, company)
- User preferences and settings
- Usage, analytics, and support communications
- Payment-related identifiers processed via payment providers
- Authorized and public YouTube / social channel data as described in the Privacy Policy

### Processing Activities

- Storage and management of user accounts
- Streaming community, membership, and content delivery operations
- Analytics and Creator Business Score / estimate features
- API request handling and authentication
- Customer support communications

### Duration of Processing

Personal Data will be processed for the duration of the Services agreement and deleted within 90 days of termination, except as required by law.

### Sensitive Data

MediaCreators does not intentionally collect or process special categories of personal data (health, biometric, genetic, religious, political data) on behalf of Customer.

---

## Annex 2: Subprocessors

| Subprocessor         | Purpose                                         | Location |
| -------------------- | ----------------------------------------------- | -------- |
| PlanetScale          | Managed PostgreSQL database                     | USA      |
| Cloudflare           | CDN, edge delivery, Workers, security           | Global   |
| Railway              | Application hosting for backend services        | USA      |
| Mux                  | Video hosting and streaming                     | USA      |
| Stripe               | Payment processing                              | USA      |
| PostHog              | Product analytics                               | USA / EU |
| Resend               | Transactional email delivery                    | USA      |
| Google OAuth         | Authentication                                  | USA      |
| YouTube API Services | YouTube account linking and analytics ingestion | USA      |
| Cal.com              | Scheduling / booking                            | USA      |
| Datadog              | Infrastructure monitoring and observability     | USA      |
| BetterStack          | Uptime monitoring and status                    | EU / USA |
| Google Maps          | Maps and location display where used            | USA      |

For the most current list of Subprocessors, visit: [https://mediacreators.io/legal/subprocessors](https://mediacreators.io/legal/subprocessors)

---

**By using the Services, Customer acknowledges and agrees to this Data Processing Agreement.**
