Data Processing Agreement
The agreement required by Art. 28(3) GDPR between the studio using RetainLens (the controller) and RetainLens (the processor). It applies to every account automatically and forms part of the Terms of Service. A counter-signed PDF is available on request at hello@retainlens.com.
1. Parties and roles
Controller: the business named on the RetainLens account.
Processor: Eldridge Kaboth, Bromberger Straße 69, 28237 Bremen, Germany.
The controller decides the purposes and means of processing the member data it brings to RetainLens. The processor acts only on the controller's documented instructions. Using the product as it is built is such an instruction; anything beyond it has to be in writing (email is enough).
2. Subject-matter, duration, nature and purpose
Subject-matter: hosting and analysis of member and attendance data so that the controller can see which members are at risk of leaving.
Duration: for as long as the account exists, plus the deletion period in section 10.
Nature and purpose: storing, structuring, scoring and displaying attendance data; sending the controller summary emails.
3. Categories of data subjects and of data
Data subjects: the controller's members and its own staff users.
Member data: name, join date, membership type, membership status, check-in timestamps, and an email address where the controller chooses to include one; notes the controller's staff write against a member.
User data: name, email address, password hash, log-in metadata.
Never processed: health data, injury information, body metrics, payment card data or any other special category under Art. 9 GDPR. The importer does not accept those fields.
4. Instructions
The processor processes personal data only on documented instructions, including for transfers to a third country, unless required otherwise by Union or Member State law, in which case it informs the controller before processing, unless that law forbids it. If an instruction appears to infringe data protection law, the processor says so and may suspend it.
5. Confidentiality
Everyone the processor lets near this data is bound to confidentiality and instructed on their obligations before they get access. The obligation survives the end of their engagement.
6. Security of processing
The processor implements the measures required by Art. 32 GDPR. They are described on the Security page, which forms Annex 3 of this agreement: read-only integrations, data minimisation by design, isolation per account, encryption in transit and at rest, restricted production access, and backups. Measures may be updated as the state of the art moves, provided the level of protection is not reduced.
7. Sub-processors
The controller grants general authorisation for the sub-processors below:
- Vercel Inc., USA: hosting and delivery. EU region.
- Resend: transactional email.
- Supabase: application database. EU region.
- Stripe Payments Europe Ltd., Ireland: billing, from the first paid plan.
The processor informs the controller at least 30 days before adding or replacing a sub-processor. The controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, either party may terminate the affected service to the date the change takes effect. Each sub-processor is bound by the same obligations by contract.
8. Data subject requests
If a member contacts the processor directly, it forwards the request to the controller and does not answer it itself. The product's export, correction and deletion functions are how the processor assists the controller with Art. 12–22; beyond that the processor helps as far as it reasonably can.
9. Breach notification
The processor notifies the controller without undue delay after becoming aware of a personal data breach, and in any event in time for the controller to meet its own 72-hour deadline under Art. 33. The notification describes what happened, which data and how many people are affected as far as known, the likely consequences and the measures taken.
10. Deletion and return
When the account ends, the data stays available for export for 60 days, then it and all copies are deleted, unless Union or Member State law requires storage. Backups age out on their own cycle, which is no longer than 35 days. Deletion is confirmed on request.
11. Audits and information
The processor makes available the information needed to demonstrate compliance with Art. 28 and allows audits, including inspections, by the controller or an auditor it mandates. Audits are announced with reasonable notice, happen during business hours, may not disrupt operations, and are limited to what is necessary. In the ordinary case the processor's written answers and documentation are the first step.
12. Transfers to third countries
Where a sub-processor processes data outside the EU or EEA, the transfer rests on the Standard Contractual Clauses of Implementing Decision (EU) 2021/914, complemented by the EU–US Data Privacy Framework where the recipient is certified.
13. Order of precedence and term
This agreement runs for as long as the processor holds personal data for the controller. Where it conflicts with the Terms of Service, this agreement prevails for questions of data protection. Nothing here limits the parties' obligations under the GDPR itself.