Romy.

Data Processing Addendum

The terms that apply when Romy processes personal data for a business customer.

Last updated

Sections

01

Parties and scope

This Data Processing Addendum (DPA) forms part of the agreement between Alice Bull, trading as Romy (Romy, we, us) and the business customer that accepts the Romy Terms of Use (Customer, you). It applies when Romy processes personal data on the Customer's behalf to provide the service.

Processing covered by this DPA
ItemDetails
Subject matterRomy workspace, connected-account, and support processing.
DurationFor the Customer's use of Romy and the deletion period described in the Privacy Policy.
Nature and purposeTo host, secure, maintain, support, and provide the features the Customer chooses to use.
Data subjectsCustomer users and the people whose data the Customer chooses to place in or connect to Romy.
Personal dataWorkspace records, connected-account content, contact details, files, and related metadata selected or generated through the service.

02

Roles and instructions

The Customer is the controller and Romy is the processor for Customer Personal Data. Romy will process Customer Personal Data only on the Customer's documented instructions, including the Customer's use of the service and configuration of its features, unless applicable law requires otherwise. If law requires processing outside those instructions, Romy will tell the Customer unless law prohibits notice.

The Customer confirms it has a lawful basis for its instructions and has provided any notices and obtained any permissions required for Customer Personal Data, including data obtained through connected accounts.

03

Confidentiality and security

Romy limits access to Customer Personal Data to people and providers who need it to provide the service and who are bound by confidentiality obligations. Romy will maintain appropriate technical and organisational measures designed to protect Customer Personal Data, including workspace access controls, encryption in transit and at rest, and database-level workspace isolation.

Romy is not designed for the special-category and regulated data listed in the Privacy Policy. The Customer must not instruct Romy to process that data.

04

Subprocessors

The Customer authorises Romy to use the subprocessors identified in the Privacy Policy: Supabase, Vercel and Vercel AI Gateway, Stripe, PostHog, Vercel Web Analytics, Vercel Speed Insights, Google Analytics, Resend, and the connected services the Customer chooses to use, including Google Gmail and Calendar, Notion, and GitHub. Romy will ensure subprocessors handling Customer Personal Data are bound by written data-protection obligations appropriate to their role.

Romy may replace or add a subprocessor where reasonably necessary to operate the service. We will update the public Privacy Policy before the change takes effect. A Customer may object on reasonable data-protection grounds by emailing hello@romy.is within 30 days of that update; the parties will work in good faith on a reasonable solution.

05

Assistance and incidents

Taking into account the nature of processing, Romy will provide reasonable assistance for Customer requests from data subjects, data-protection impact assessments, prior consultations, and other obligations the Customer has under applicable data-protection law. Romy will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide information reasonably available to help the Customer meet its obligations.

06

Return and deletion

On the Customer's request or when the Customer's use of Romy ends, Romy will return or delete Customer Personal Data in accordance with the Privacy Policy, unless applicable law requires retention. Secured backup copies are not restored except for disaster recovery and age out under the provider backup schedule.

07

International transfers

Customer Personal Data is hosted in the EU. Where Romy transfers Customer Personal Data outside the EU, EEA, or UK, including through US-based model providers selected by Vercel AI Gateway, Romy will use an applicable adequacy decision or contractual safeguard such as the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum.

08

Information and audit

Romy will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. If that information is insufficient, the Customer may request a reasonable, written audit no more than once in any 12-month period, subject to reasonable confidentiality, security, and scheduling requirements. The Customer bears its own audit costs unless the audit identifies a material breach by Romy.

09

Order of precedence

If this DPA conflicts with the Terms of Use on the processing of Customer Personal Data, this DPA controls. Romy may assign this DPA to a successor entity in connection with incorporating or transferring the business, provided the successor assumes these obligations and Romy gives the Customer notice.

10

Contact

Questions about this DPA: hello@romy.is.

End of data processing addendum.