Data Processing Addendum
โก๏ธ Quick summary:
- ๐ค Applies automatically โ This DPA is built into our standard agreement โ no signature needed. It kicks in whenever we handle personal data (like cast & crew contact info) on your behalf.
- ๐ Your data stays yours โ We only process personal data to provide the Services and on your instructions. We never sell it, share it, or use it for our own purposes.
- ๐ค AI never trains on your data โ Optional AI features run inside our own cloud environment. Model providers can’t see, store, or train on your data, and account owners can turn these features off anytime.
- ๐ Security built in โ Encryption at rest and in transit, least-privilege access controls, and background-checked and trained personnel.
- ๐งพ Transparent sub-processors โ Every vendor that touches your data is published on our sub-processor list, and we give 30 days’ advance notice (with a right to object) before adding new ones.
Version 1.0 ยท Effective: July 1, 2026 ยท Last updated: July 1, 2026
This Data Processing Addendum, including its Schedules and the Standard Contractual Clauses incorporated by reference (collectively, the "DPA"), forms part of the Terms and Conditions of Use or other written or electronic agreement (the "Agreement") between SetHero, LLC ("SetHero") and the customer that is a party to the Agreement ("Customer"), on behalf of itself and its Affiliates, and governs SetHero's Processing of Personal Data on Customer's behalf.
This DPA applies automatically to any Customer whose use of the Services involves SetHero Processing Personal Data on the Customer's behalf, and takes effect when the Customer accepts the Agreement or uses the Services. No signature is required for this DPA, or the Standard Contractual Clauses it incorporates, to be effective. A Customer that requires a countersigned copy for its records may request one at privacy@sethero.com. Capitalized terms not defined here have the meaning given in the Agreement.
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership or control of more than 50% of the voting interests of the subject entity.
"Applicable Data Protection Law" means all data protection and privacy laws and regulations applicable to the Personal Data in question, including, where applicable, European Data Protection Law and the laws of the United States, including the CCPA.
"CCPA" means the California Consumer Privacy Act of 2018 (Cal. Civ. Code ยงยง 1798.100โ1798.199.100), as amended by the California Privacy Rights Act and its implementing regulations.
"European Data Protection Law" means, in each case as amended, superseded, or replaced: (i) the EU GDPR; (ii) the UK GDPR and the UK Data Protection Act 2018 (together, "UK Data Protection Law"); (iii) the Swiss Federal Act on Data Protection and its ordinances ("Swiss DPA"); and (iv) any applicable national implementing legislation and related laws.
"EU GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation). "UK GDPR" means the EU GDPR as saved into UK law by section 3 of the European Union (Withdrawal) Act 2018 and supplemented by the UK Data Protection Act 2018.
"Europe" means the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland.
"Personal Data" means information provided or otherwise made available by or on behalf of Customer to SetHero in the course of SetHero's performance under the Agreement that identifies, can be used to identify, or can be used to authenticate an individual (a "data subject"), or is otherwise protected as "personal data," "personally identifiable information," or "personal information" under Applicable Data Protection Law, as further described in Schedule 1. Personal Data does not include data SetHero processes as an independent controller under Section 2.4.
"Restricted Transfer" means a transfer of Personal Data that is subject to the transfer restrictions of the EU GDPR, UK GDPR, or Swiss DPA to a country not covered by an applicable adequacy decision.
"Security Incident" means a personal data breach or any unauthorized or unlawful access to, or accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, Personal Data transmitted, stored, or otherwise Processed by SetHero (or any Sub-processor) under or in connection with the Agreement.
"Services" means the products and services SetHero provides to Customer under the Agreement.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced, or superseded.
"Sub-processor" means any third party or service provider (including any SetHero Affiliate) engaged by SetHero to Process Personal Data in connection with this DPA and/or the Agreement, including any third party appointed by a Sub-processor.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0) issued by the UK Information Commissioner under s.119A(1) of the UK Data Protection Act 2018, which came into force on 21 March 2022, as amended or replaced.
The terms "controller," "processor," "supervisory authority," "personal data breach," and "processing" have the meanings in European Data Protection Law (and "process," "processes," and "processed" are construed accordingly); the terms "business," "commercial purpose," "personal information," "sell," "share," and "service provider" have the meanings in the CCPA.
2.1 Scope. This DPA applies only where and to the extent SetHero Processes Personal Data protected by Applicable Data Protection Law in the course of providing the Services, as follows:
- 2.1.1 Where Customer is a controller or business and SetHero Processes Personal Data on its behalf, SetHero acts as a processor or service provider, and this DPA applies accordingly; and
- 2.1.2 Where Customer is itself a processor or service provider acting on behalf of a third-party controller or business (a "Third Party Controller"), SetHero acts as a Sub-processor or service provider, and this DPA applies accordingly.
The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of data subjects are described in Schedule 1.
2.2 Compliance with Law. Each party will comply with its obligations under Applicable Data Protection Law in respect of the Personal Data it Processes under the Agreement and this DPA. If Applicable Data Protection Law changes, the parties will discuss in good faith any necessary amendments to this DPA.
2.3 California. With respect to Personal Data subject to the CCPA, the parties agree that Customer is the business and SetHero is the service provider. SetHero will not: (i) sell or share Personal Data; (ii) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including any commercial purpose other than providing the Services; or (iii) retain, use, or disclose Personal Data outside the direct business relationship between the parties. SetHero will not combine Personal Data with personal information received from another source, except as permitted by the CCPA. SetHero will notify Customer promptly if it determines that it can no longer meet its obligations under the CCPA. Upon such notice, or if Customer reasonably believes SetHero is using Personal Data in an unauthorized manner, Customer may take reasonable and appropriate steps, in accordance with the CCPA, to stop and remediate the unauthorized use of Personal Data. SetHero certifies that it understands and will comply with these restrictions.
2.4 Data SetHero Processes as a Controller. This DPA governs only Personal Data that SetHero Processes as a processor or Sub-processor on Customer's behalf. To the extent SetHero Processes personal data as an independent controller โ for example, the account holder's registration and billing details, usage and analytics data, security logs, and SetHero's own sales and marketing communications โ SetHero does so in accordance with Applicable Data Protection Law and its Privacy Policy, and not under this DPA. Each party is individually responsible for its own compliance when acting as a controller.
2.5 Other Jurisdictions. Where SetHero Processes Personal Data protected by other data protection laws that distinguish between controllers (or businesses) and processors (or service providers) โ for example, Brazil's Lei Geral de Proteรงรฃo de Dados (LGPD) or Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) โ the parties' respective roles under Section 2.1 and SetHero's processor obligations under this DPA apply equivalently, to the extent required by those laws.
2.6 Customer Responsibilities. Customer is responsible for the accuracy, quality, and legality of the Personal Data that it (and its authorized users) provides to the Services, and for the means by which Customer acquired that Personal Data. Customer represents and warrants that: (i) it has established, and will maintain throughout the term of the Agreement, a valid lawful basis for the Processing of Personal Data under this DPA; (ii) it has provided all notices to, and obtained all consents, permissions, and rights from, data subjects and any other relevant parties required under Applicable Data Protection Law for SetHero to lawfully Process Personal Data as contemplated by the Agreement and this DPA โ including any consents or authorizations required for SetHero to send emails and text (SMS) messages, such as call sheets and scheduling notifications, to production staff and other data subjects on Customer's behalf; (iii) its Processing instructions to SetHero comply with Applicable Data Protection Law; and (iv) where Customer acts on behalf of a Third Party Controller under Section 2.1.2, it is authorized to agree to this DPA (including the SCCs) on behalf of that Third Party Controller.
3.1 Permitted Purpose. SetHero will (and will ensure its Sub-processors will) Process Personal Data solely: (i) for the purposes set out in the Agreement and Schedule 1 (the "Permitted Purpose"); and (ii) in accordance with Customer's documented lawful instructions as set out in the Agreement and this DPA, or as otherwise agreed in writing, or as required by applicable law. SetHero will not Process Personal Data for its own purposes or those of any third party, and will not sell or share Personal Data. If SetHero is required by law to Process Personal Data otherwise than on Customer's instructions, it will (unless legally prohibited) inform Customer beforehand. If SetHero considers an instruction to infringe Applicable Data Protection Law, it will promptly inform Customer and is not required to comply with the infringing instruction until the matter is resolved.
3.2 Reservation of Rights. SetHero acquires no ownership, license, or other interest in Personal Data, which remains, as between the parties, the confidential information of Customer.
3.3 Processor Obligations. SetHero will: (i) ensure that persons authorized to Process Personal Data are bound by appropriate confidentiality obligations (contractual or statutory) and receive appropriate training; (ii) implement and maintain the technical and organizational measures described in Section 6 and Schedule 2; and (iii) taking into account the nature of the Processing and the information available to it, provide reasonable assistance to Customer, at Customer's expense, with Customer's obligations regarding security, Security Incident notification, data protection impact assessments, prior consultations, and responding to data subject requests.
3.4 Third Party Controller Notices. Where Customer acts on behalf of a Third Party Controller (Section 2.1.2), Customer is SetHero's sole point of contact, and SetHero need not interact directly with, or seek authorizations from, the Third Party Controller. Where SetHero would otherwise provide information, assistance, or notification to the Third Party Controller, it will provide it to Customer.
4.1 Authorized Sub-processors. Customer provides SetHero with a general authorization to engage Sub-processors to Process Personal Data. SetHero's current Sub-processors are listed at sethero.com/legal/subprocessors (Schedule 3). SetHero will enter into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those in this DPA (including, where applicable, the SCCs), will engage only Sub-processors that provide sufficient guarantees of appropriate security, and will ensure each Sub-processor Processes Personal Data only for the Permitted Purpose. SetHero remains responsible for its Sub-processors' performance of those obligations.
4.2 Notice and Objection. SetHero will notify Customer of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance, by updating the Sub-processor list referenced in Schedule 3 and sending notice to Customer contacts subscribed to Sub-processor change notifications. New Customer accounts are subscribed to these notifications by default; Customer may opt out at any time and may (re)subscribe by contacting privacy@sethero.com. SetHero may unsubscribe a Customer contact where the associated account has been inactive for an extended period or where notifications to that contact repeatedly bounce or otherwise cannot be delivered. Customer is responsible for maintaining an active subscription and accurate contact details if it wishes to receive these notifications, and SetHero's updating of the Sub-processor list and delivery of notice to subscribed contacts fully satisfies its notification obligations under this Section and Clause 9 of the SCCs. Customer may object on reasonable data-protection grounds within thirty (30) days of the notice, and the parties will work together in good faith to resolve the objection. If it cannot be resolved, Customer's sole remedy is to terminate the portion of the Services that cannot be provided without the Sub-processor, in which case SetHero will refund Customer any prepaid, unused fees attributable to the terminated portion of the Services for the period after the effective date of termination.
4.3 Records. SetHero will maintain an up-to-date record of its Sub-processors and, upon request, provide it to Customer on a schedule that allows Customer to respond to any demand from a Third Party Controller or other third party.
5.1 Data Subject Requests. Taking into account the nature of the Processing, SetHero will reasonably cooperate with Customer, at Customer's expense, to enable Customer (or its Third Party Controller) to respond to requests from data subjects or consumers exercising their rights under Applicable Data Protection Law. If such a request is made directly to SetHero, SetHero will, unless prohibited by law, promptly notify Customer and will not respond except on Customer's written instructions or as required by law.
5.2 Government and Regulatory Requests. If SetHero receives a legally binding request from a government, regulatory, or judicial authority for Personal Data, SetHero will, unless legally prohibited: (i) promptly notify Customer; (ii) inform the authority that SetHero is a processor not authorized to disclose the data; (iii) attempt to redirect the authority to Customer; and (iv) reasonably cooperate, at Customer's expense, if Customer wishes to seek a protective order or otherwise limit or challenge disclosure. Where legally compelled, SetHero will use reasonable and lawful efforts to challenge the request and will disclose only the minimum Personal Data legally required. In no event will SetHero knowingly disclose Personal Data in a massive, disproportionate, and indiscriminate manner that goes beyond what is necessary in a democratic society.
5.3 DPIA Assistance. SetHero will provide reasonable assistance to Customer, at Customer's request and expense, with data protection impact assessments and related consultations with supervisory authorities, in each case to the extent relating to SetHero's Processing.
5.4 Customer Requests. SetHero will promptly address reasonable inquiries from Customer relating to its Processing of Personal Data and make available information reasonably necessary to demonstrate its compliance with this DPA.
6.1 Security Measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to data subjects, SetHero will implement and maintain appropriate technical and organizational measures designed to protect Personal Data and preserve its security and confidentiality, including, at minimum, the measures described in Schedule 2.
6.2 Updates. SetHero may modify its security measures through new or enhanced technologies, provided the changes do not materially diminish the overall level of protection of Personal Data.
6.3 Data Access and Training. SetHero will ensure that persons who Process Personal Data on its behalf are required to protect it consistent with this DPA and receive appropriate training before being granted access.
6.4 Security Incident Response. SetHero will notify Customer without undue delay โ and, where feasible, within seventy-two (72) hours โ after becoming aware of a Security Incident, and will provide information as it becomes known, including the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and recommended steps for Customer. SetHero will promptly take reasonable steps to mitigate and secure Personal Data, and will maintain a record of Security Incidents.
6.5 Compliance Information and Audits. Upon reasonable written request, and no more than once in any twelve (12) month rolling period, SetHero will make available information reasonably necessary to demonstrate its compliance with this DPA, including written responses to reasonable security questionnaires, summary security documentation, and any third-party audit reports or certifications SetHero maintains from time to time. The parties agree that, to the fullest extent permitted by Applicable Data Protection Law, the information made available under this Section satisfies Customer's audit and information rights under this DPA (including under the SCCs). Any further audit or inspection required by Applicable Data Protection Law, the SCCs, or a supervisory authority, or following a Security Incident, will be at Customer's expense and subject to: reasonable prior written notice; a confidentiality agreement acceptable to SetHero signed by Customer and any auditor; the parties' advance agreement on scope, timing, and duration; conduct during business hours with minimal disruption; and reasonable limitations to protect the confidentiality and security of information SetHero Processes for others.
7.1 Processing Locations. Customer acknowledges that SetHero may transfer and Process Personal Data in the United States and elsewhere in the world where SetHero, its Affiliates, or its Sub-processors maintain Processing operations, and will ensure such transfers comply with Applicable Data Protection Law and this DPA.
7.2 European Data. SetHero will not make a Restricted Transfer of Personal Data protected by European Data Protection Law ("European Data") without ensuring an appropriate transfer mechanism is in place. Where the SCCs or UK Addendum apply, SetHero and Customer are deemed to have entered into and signed them (including their Annexes, completed as set out in this DPA and its Schedules) as of the date this DPA takes effect, without the need for any further signature.
7.3 EU Standard Contractual Clauses. Where Customer transfers European Data protected by the EU GDPR to SetHero and no adequacy decision applies, the SCCs are incorporated into this DPA by reference and completed as follows:
- Module Two (controller to processor) applies where Section 2.1.1 applies, and Module Three (processor to processor) applies where Section 2.1.2 applies;
- in Clause 7, the optional docking clause applies;
- in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 4.2;
- in Clause 11, the optional redress language does not apply;
- in Clause 17, Option 1 applies, governed by the law of Ireland;
- in Clause 18(b), disputes are resolved before the courts of Ireland;
- Annex I is completed with Schedule 1; Annex II with Schedule 2; and Annex III with Schedule 3.
7.4 UK Transfers. For European Data protected by the UK GDPR, the SCCs as completed in Section 7.3 apply as amended by the UK Addendum, incorporated by reference and completed as set out in Schedule 4.
7.5 Swiss Transfers. For European Data subject to the Swiss DPA, the SCCs apply as completed in Section 7.3, subject to: references to "Regulation (EU) 2016/679" read as the Swiss DPA; references to "EU," "Union," and "Member State" read as "Switzerland"; the competent authority is the Swiss Federal Data Protection and Information Commissioner; the SCCs are governed by Swiss law and disputes resolved before the Swiss courts; and the SCCs also protect the data of legal entities to the extent required under the Swiss DPA.
7.6 Alternative Mechanisms. If a supervisory authority or Applicable Data Protection Law no longer permits transfers under the above mechanisms, SetHero will work with Customer in good faith to implement an alternative lawful transfer mechanism.
8.1 SetHero uses third-party AI models (currently Anthropic's Claude models) to power certain optional, AI-assisted features. These models are accessed only through Amazon Web Services (Amazon Bedrock) and run inside SetHero's existing AWS environment.
8.2 With respect to these AI features: (a) Customer content is not sent to, accessible by, or stored by the AI model provider; (b) inputs and outputs are not retained by the model provider after a response is generated; (c) Customer content is not used to train any AI model; (d) Processing occurs in the same AWS region SetHero already uses for Customer's data; (e) the features are designed to minimize the Personal Data sent to the models; and (f) the features can be disabled at the account level by Customer's account owners. The relevant providers are identified in the Sub-processor list. More broadly, SetHero will not use Customer's Personal Data to train, fine-tune, or improve SetHero's or any third party's generative or machine-learning models, except that SetHero may use aggregated or de-identified data that no longer identifies any individual to operate and improve the Services. With respect to any de-identified data, SetHero publicly commits to maintain and use it only in de-identified form, will not attempt to re-identify it, and will contractually obligate any recipient of such data to comply with the same restrictions.
Upon expiration or termination of the Agreement, or upon Customer's earlier written request, SetHero will (and will procure that its Sub-processors will), at Customer's choice, delete or return all Personal Data and delete existing copies in its possession or control within sixty (60) days, unless retention is required by applicable law. Personal Data held in backup archives will be deleted in accordance with SetHero's standard backup rotation and retention cycles; until deletion, such data remains protected by the security measures in this DPA and is not restored to production or otherwise Processed except as required for disaster recovery or by applicable law. Where retention is legally required, SetHero will isolate and protect the security and confidentiality of such Personal Data and Process it only to the extent and for the period required by that law.
Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability set out in the Agreement. Customer acknowledges that SetHero relies on Customer's instructions as to the scope of Processing SetHero is authorized to perform on Customer's behalf; accordingly, SetHero will not be liable for any claim brought by a data subject or third party to the extent it arises from SetHero's Processing of Personal Data in accordance with Customer's documented instructions or from Customer's breach of its obligations under Section 2.6 or Applicable Data Protection Law. Nothing in this DPA limits either party's liability to a data subject or supervisory authority where such liability cannot be limited under applicable law.
11.1 Survival. SetHero's obligations under this DPA survive for as long as SetHero or its Sub-processors Process Personal Data on Customer's behalf, together with any provisions that by their nature are intended to survive.
11.2 Governing Law. Except as required otherwise by Applicable Data Protection Law or the SCCs, this DPA is governed by the laws of the State of Michigan, USA, consistent with the Agreement, and disputes are handled as set out in the Agreement.
11.3 Order of Precedence. In the event of a conflict between this DPA and the Agreement, this DPA prevails with respect to its subject matter. To the extent the SCCs conflict with the Agreement or this DPA, the SCCs prevail.
11.4 Updates to this DPA. This DPA is incorporated into and forms part of the Agreement, and SetHero may update it from time to time in accordance with the Agreement's provisions for changes to its terms. The current version is published at sethero.com/legal/dpa. SetHero will take reasonable steps to notify Customers of material changes; changes to Sub-processors are governed by Section 4.2. Continued use of the Services after a change takes effect constitutes acceptance of the updated DPA, except where the change requires the parties' agreement under Applicable Data Protection Law.
11.5 Severability. If any part of this DPA is held unenforceable, the remainder continues in effect and the unenforceable part is interpreted to give maximum effect to the parties' intent.
11.6 Acceptance. By accepting the Agreement or using the Services, Customer agrees to this DPA. This DPA does not require the signature of either party to be effective. A Customer that requires a countersigned copy may request one at privacy@sethero.com.
11.7 Data Protection Contact. Questions about this DPA or SetHero's Processing of Personal Data may be directed to privacy@sethero.com. Details of any representative appointed by SetHero in the EU or UK under Article 27 of the GDPR will be made available at SetHero's Legal Resource Hub or on request.
SetHero certifies that it and its personnel understand the restrictions in this DPA and will comply with them.
This Schedule completes Annex I of the SCCs.
| Data Exporter | Data Importer | |
|---|---|---|
| Name | The Customer, as identified in its account and the Agreement | SetHero, LLC |
| Address | As provided in Customer's account / the Agreement | 222 W Genesee St, PMB 116, Lansing, MI 48933, USA |
| Contact | The account owner or contact designated in Customer's account | Privacy Team, privacy@sethero.com |
| Role | Controller (or Processor, where Section 2.1.2 applies) | Processor (or Sub-processor) |
Categories of data subjects: Individuals who register for and use the Services on Customer's behalf, and production staff (e.g., cast and crew) and other individuals whose details a Customer enters into the Services.
Categories of Personal Data. The specific Personal Data is determined by how the Customer uses the Services and the data it chooses to enter; the following are representative examples, not an exhaustive list:
- Contact and identity data โ e.g., name; business phone number (personal phone number optional); business email address (personal email address optional); job position/role;
- Online identifiers โ e.g., IP address, mobile device ID;
- Other production-related details a Customer chooses to enter about production staff and productions โ e.g., dietary preferences, scheduling and call-time information, and similar operational details.
Financial/payment data is not Processed on Customer's behalf under this DPA; billing is handled by SetHero as an independent controller (see Section 2.4).
Sensitive data: SetHero does not require, and the Services are not designed to Process, special categories of Personal Data.
Frequency of the transfer: Continuous, for the term of the Agreement.
Nature and purpose of Processing: Emailing and texting production staff their daily schedules (call sheets) on behalf of registered Customers; storing details about production staff and productions entered by registered Customers; and providing related production-management, scheduling, and optional AI-assisted features.
Duration / retention: For the term of the Agreement; deleted or returned within sixty (60) days thereafter under Section 9, unless longer retention is required by law.
The Irish Data Protection Commission, consistent with the governing law selected under Clause 17 โ or, where the data exporter is established in another EEA Member State, the supervisory authority of that Member State.
The measures SetHero implements to ensure a level of security appropriate to the risk:
| # | Type of measure | Implemented measure |
|---|---|---|
| 1 | Encryption of Personal Data | Passwords hashed with bcrypt using a unique, auto-generated salt; databases encrypted at rest; TLS 1.2+ (or minimally equivalent) for data in transit over public networks. |
| 2 | Ongoing confidentiality, integrity, availability, and resilience of systems | Least-privilege access; confidentiality agreements for personnel; secured-network requirement for remote work; regular backups; audit logging. |
| 3 | Ability to restore availability and access after an incident | Business continuity and disaster recovery plan for failure of facilities, infrastructure, or systems; backups performed on defined schedules. |
| 4 | Regular testing, assessing, and evaluating effectiveness | Change management with testing and approval before deployment; regular access reviews/audits; security incident response plan reviewed regularly. |
| 5 | User identification and authorization | Principle of least privilege; two-factor authentication where possible; unique, complex passwords stored only in an approved password manager. |
| 6 | Protection of data during storage | Encryption at rest; database access only via direct SSH tunnel over VPN. |
| 7 | Physical security of processing locations | Production infrastructure hosted with AWS (see Sub-processor list); clear-desk, clear-screen policy for personnel. |
| 8 | Events logging | Audit logs from production systems and servers collected, monitored, and stored. |
| 9 | System configuration, including default configuration | Change Management Policy governs configuration changes; changes documented, tested, and approved before deployment. |
| 10 | Internal IT and IT security governance and management | Security policies; personnel background checks; security awareness training; vendor security assessments before onboarding third-party products/services. |
| 11 | Certification/assurance of processes and products | Vendor security assessments before onboarding third-party products/services; periodic internal security reviews. |
| 12 | Data minimization and accountability | Personal Data collected and retained only as needed to provide the Services; personnel required to handle Personal Data with appropriate security. |
| 13 | Data quality | Customers can view, update, and correct data via the Services. |
| 14 | Limited data retention | Data retained only while an account is active and as needed to provide the Services; disposed of on Customer request. |
| 15 | Data portability and erasure | Data deleted or returned on request or termination under Section 9; export features provided where available. |
SetHero's current Sub-processors โ including the nature of each one's Processing and SetHero's use of AI model providers (see also Section 8) โ are published at sethero.com/legal/subprocessors. That page is maintained as SetHero's authoritative Sub-processor list and forms Annex III to the SCCs.
Changes to Sub-processors, including advance notice and Customer's right to object, are governed by Section 4.2 of this DPA. New Customer accounts are subscribed to Sub-processor change notifications by default; Customers may opt out, (re)subscribe, or object to a proposed Sub-processor by contacting privacy@sethero.com.
This Schedule applies under Section 7.4 (UK Transfers) and completes the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0) issued by the UK Information Commissioner under s.119A(1) of the UK Data Protection Act 2018 (in force 21 March 2022).
Table 1 โ Parties. Exporter: the Customer, as identified in Schedule 1(A). Importer: SetHero, LLC, 222 W Genesee St, PMB 116, Lansing, MI 48933, USA; contact: privacy@sethero.com.
Table 2 โ Selected SCCs, Modules and Clauses. The EU SCCs as completed in Section 7.3, including the Modules, clauses, and optional provisions selected there.
Table 3 โ Appendix Information. As set out in Schedules 1, 2, and 3 (Annexes I, II, and III).
Table 4 โ Ending the Addendum when the Approved Addendum changes. Neither party may end the UK Addendum when the Approved Addendum changes, except as permitted by its mandatory clauses.
Mandatory Clauses. Part 2 of the UK Addendum (Mandatory Clauses), as revised under Section 18 of those Mandatory Clauses, is incorporated by reference. By accepting this DPA, the parties are deemed to have entered into the UK Addendum without further signature.
Related policies. Terms of Service ยท Privacy Policy ยท Acceptable Use Policy ยท Sub-Processor List ยท Legal Resource Hub
This Data Processing Addendum is published by SetHero, LLC. Questions: privacy@sethero.com.
