Skip to main content

Data Processing Addendum

Last updated: October 2026 · Version: 2026-10-10

This addendum forms part of our Terms of Service (Section 19). It applies automatically to every creator who uses Facet Cloud; there is nothing extra to sign. If you need a countersigned copy for your records, email [email protected].

1. Who this is between

This addendum is between you, the creator who holds a Facet Cloud account ("you", the controller), and the Operator named in Section 16 of the Terms ("we", the processor). It covers personal data about your audience that we process on your behalf to run your site: your members, subscribers, buyers, students, community participants, site visitors and teammates.

It does not cover personal data we handle for our own purposes as a controller, such as your account, billing and support records, which our Privacy Policy covers. Stripe processes card and payout data on your own connected Stripe account under its own terms, as an independent controller, not as our subprocessor (see Section 17 of the Terms).

2. Details of the processing

  • Subject matter and purpose: hosting, operating, securing and supporting your site, and delivering your pages, emails, videos, courses, community and checkout.
  • Nature: storage, retrieval, display, transmission, email delivery, video encoding and streaming, backups, and deletion.
  • Duration: while your account is active, then until deletion under Section 10.
  • Categories of people: your members, subscribers, buyers, students, community participants, site visitors, and teammates you invite.
  • Categories of data: names, email addresses, sign-in details (passwords are stored only as hashes), membership, purchase and access records, course progress, posts, comments and messages, form answers, newsletter delivery and engagement events, and connection data such as IP address and browser in logs.
  • Special category data: the Service is not designed for health, biometric or similar sensitive data. Do not collect it through your site unless you have a lawful basis and have checked the Service meets your obligations for it.

3. Your instructions

We process your audience's personal data only on your documented instructions. Your instructions are the Terms, this addendum, and the way you set up and use the Service (for example, the emails you send, the forms you publish, and the deletions you make). If the law requires us to process data in another way, we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks data protection law, and we may decline to follow it.

4. Confidentiality

Only people who need access to operate or support the Service can reach your audience's data, and each of them is bound by a duty of confidentiality. We look at site data only to run the Service, to answer a support request you make, to investigate abuse or a security problem, or where the law requires it.

5. Security

We keep technical and organisational measures appropriate to the risk, including:

  • encryption in transit (HTTPS/TLS) for every site, the dashboard and our APIs;
  • a separate database for each site, so one site's data is never stored with another's;
  • server access limited to named operators using key-based authentication from restricted networks, with administrative tools not reachable from the public internet;
  • regular backups, monitored for freshness, so data can be recovered after a failure;
  • passwords stored only as salted hashes, and payment card data never stored by us;
  • prompt security updates to the servers and software we run.

6. Subprocessors

You authorise us to use the subprocessors listed in Section 8 of our Privacy Policy. Each is bound by written terms giving your data at least the protection in this addendum, and we remain responsible to you for their work.

We will update that list and email account owners at least 30 days before a new subprocessor starts processing your audience's data. If we must replace one urgently for security or to keep the Service running, we will tell you as soon as we can. You may object on reasonable data protection grounds by emailing [email protected]. If we cannot resolve the objection, you may cancel, and we will refund the unused part of any prepaid subscription fee.

7. International transfers

Site data is stored in the European Union (Helsinki, Finland). Where a subprocessor processes data outside the EU or UK, the safeguards in Section 9 of our Privacy Policy apply. We operate from New Zealand, which the European Commission and the United Kingdom recognise as providing adequate protection for personal data.

8. Helping you meet your obligations

Your dashboard lets you find, export, correct and delete your audience's data. Where those tools are not enough to answer a request from someone in your audience, we will help on request. If someone contacts us directly about your site, we will pass the request to you rather than answer it ourselves. We will also give you the information you reasonably need for a data protection impact assessment or a consultation with a regulator about the Service.

9. Personal data breaches

If we become aware of a breach of security that affects your audience's personal data, we will notify you without undue delay, and in any case within 48 hours, at your account email. We will tell you what happened, the kinds and rough number of people and records affected, the likely consequences, and what we have done and will do about it, adding detail as we learn it. We will help you meet any duty you have to notify a regulator or the people affected.

10. Deletion and return

You can export your site's data at any time while your account is active, and during any notice period under Section 18 of the Terms. When your account ends, we delete your site's data within 30 days, as our Privacy Policy describes, and copies in backups are overwritten on their normal cycle. We keep data longer only where the law requires it, and then only for that purpose.

11. Showing that we comply

On request, we will give you the information reasonably needed to show that we meet this addendum, including written answers to a reasonable security questionnaire once a year. If a regulator requires it, or after a breach affecting your data, we will allow an audit by you or an independent auditor bound by confidentiality, on reasonable notice, scoped to your data, and at your cost.

12. Your responsibilities

As controller, you decide what you collect from your audience and why. You are responsible for having a lawful basis for it, for telling your audience how you use their data (for example in your own privacy notice), and for any consent you need, such as for marketing email.

13. Precedence and changes

If this addendum and the Terms conflict about the processing of your audience's personal data, this addendum wins. The limitation of liability in the Terms applies to this addendum to the extent the law allows. We will email account owners at least 30 days before a material change to this addendum takes effect.

14. Contact

Questions about this addendum or a data protection request: [email protected].