Data Processing Addendum
Applies to Autonoma. Last updated 2026-08-07.
Not reviewed by a lawyer. This document was drafted to describe what the software actually does, but it has not had legal review and is not legal advice. If anything here matters to you, ask us at support@autonoma-studio.com before relying on it.
Autonoma
Effective Date: January 2026
Last Updated: January 2026
1. INTRODUCTION
This Data Processing Addendum (“DPA”) forms part of the Agreement between Autonoma (“Processor,” “we,” “us”) and the Customer (“Controller,” “you”) for the provision of Autonoma services.
This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller and ensures compliance with applicable data protection laws including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
This DPA applies primarily to Enterprise customers. Standard customers are covered by our Privacy Policy.
2. DEFINITIONS
“Agreement” means the Terms of Service, Software License Agreement, and related agreements.
“Controller” means the entity that determines the purposes and means of processing Personal Data.
“Data Subject” means an identified or identifiable natural person whose Personal Data is processed.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on Personal Data.
“Processor” means the entity that processes Personal Data on behalf of the Controller.
“Sub-processor” means a third party engaged by the Processor to process Personal Data.
“Supervisory Authority” means an independent public authority responsible for data protection.
“GDPR” means the General Data Protection Regulation (EU) 2016/679.
“CCPA” means the California Consumer Privacy Act of 2018.
3. SCOPE AND APPLICATION
3.1 Scope
This DPA applies to all Processing of Personal Data by the Processor in connection with providing the Services.
3.2 Roles
- Controller: You (the Customer)
- Processor: Autonoma
3.3 Application
This DPA applies when:
- You use the Services to process Personal Data
- Personal Data is transferred to us for processing
- We access systems containing Personal Data
4. DATA PROCESSING
4.1 Processing Instructions
The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Inform the Controller if instructions violate applicable law
- Process data only for the purposes specified in this DPA
4.2 Permitted Processing
Processing is permitted for:
- Providing the Services as described in the Agreement
- Fulfilling legal obligations
- Responding to Controller instructions
- Technical support and maintenance
4.3 Processing Details
Categories of Data Subjects:
- Controller’s customers
- Controller’s employees (if applicable)
- End users of Controller’s products
Types of Personal Data:
- Contact information (name, email)
- Transaction records
- Product listing data
- Usage analytics
- Payment information (processed by third parties)
Processing Activities:
- Storage and retrieval
- Synchronization with marketplaces
- AI processing for content generation
- Analytics and reporting
- Support and troubleshooting
Duration:
- Duration of the Agreement plus retention period
- As specified in our Privacy Policy
5. CONTROLLER OBLIGATIONS
The Controller shall:
5.1 Lawful Basis
- Ensure a valid lawful basis exists for processing
- Obtain necessary consents from Data Subjects
- Provide required privacy notices
5.2 Accuracy
- Ensure Personal Data is accurate and up-to-date
- Correct or delete inaccurate data upon discovery
5.3 Instructions
- Provide clear, lawful processing instructions
- Ensure instructions comply with applicable law
5.4 Data Subject Rights
- Handle Data Subject requests
- Notify us of requests requiring our assistance
5.5 Compliance
- Comply with all applicable data protection laws
- Conduct necessary data protection impact assessments
6. PROCESSOR OBLIGATIONS
The Processor shall:
6.1 Confidentiality
- Ensure personnel are bound by confidentiality obligations
- Limit access to authorized personnel only
- Implement appropriate access controls
6.2 Security
- Implement appropriate technical and organizational measures
- Protect against unauthorized access, disclosure, alteration, or destruction
- Maintain security measures as described in Section 8
6.3 Sub-processors
- Only engage Sub-processors with Controller’s authorization
- Ensure Sub-processors are bound by equivalent obligations
- Remain liable for Sub-processor compliance
6.4 Assistance
- Assist with Data Subject requests
- Assist with data protection impact assessments
- Assist with regulatory consultations
- Notify Controller of data breaches
6.5 Data Return/Deletion
- Upon termination, return or delete Personal Data as requested
- Certify deletion upon request
- Retain data only as required by law
7. SUB-PROCESSORS
7.1 Authorized Sub-processors
The Controller authorizes the use of the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting | USA/EU |
| Google Cloud Platform | AI processing | USA/EU |
| Stripe, Inc. | Payment processing | USA |
| LemonSqueezy, LLC | Payment processing | USA |
| OpenAI, LLC | AI content generation | USA |
| Anthropic, PBC | AI content generation | USA |
| Sendgrid (Twilio) | Email delivery | USA |
7.2 Sub-processor Changes
- We will notify Controller of new Sub-processors
- Controller may object within 14 days
- If objection cannot be resolved, Controller may terminate
7.3 Sub-processor Agreements
All Sub-processors are bound by data processing agreements with equivalent protections.
8. SECURITY MEASURES
8.1 Technical Measures
The Processor implements:
Encryption:
- TLS 1.2+ for data in transit
- AES-256 encryption for data at rest
- Encrypted backups
Access Controls:
- Role-based access control (RBAC)
- Multi-factor authentication for personnel
- Unique user credentials
- Regular access reviews
Network Security:
- Firewalls and intrusion detection
- Regular security scanning
- DDoS protection
Application Security:
- Secure development practices
- Regular security testing
- Vulnerability management
8.2 Organizational Measures
- Security policies and procedures
- Employee security training
- Background checks for personnel
- Incident response procedures
- Business continuity planning
8.3 Physical Security
- Secure data center facilities (via cloud providers)
- Access controls and monitoring
- Environmental controls
9. DATA BREACH NOTIFICATION
9.1 Notification Obligation
The Processor shall notify the Controller without undue delay (within 72 hours) upon becoming aware of a Personal Data breach.
9.2 Notification Contents
Notification shall include:
- Nature of the breach
- Categories and number of Data Subjects affected
- Categories and number of records affected
- Likely consequences
- Measures taken or proposed
9.3 Cooperation
The Processor shall:
- Cooperate with breach investigation
- Preserve evidence
- Assist with regulatory notifications
- Assist with Data Subject notifications
9.4 Documentation
The Processor shall document all breaches including:
- Facts and circumstances
- Effects and consequences
- Remedial actions taken
10. DATA SUBJECT RIGHTS
10.1 Assistance
The Processor shall assist the Controller in responding to Data Subject requests for:
- Access to Personal Data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Objection to processing
10.2 Response Time
The Processor shall respond to Controller requests within 10 business days.
10.3 Direct Requests
If Data Subjects contact the Processor directly:
- We will redirect them to the Controller
- Notify the Controller of the request
- Assist as directed by the Controller
11. INTERNATIONAL TRANSFERS
11.1 Transfer Locations
Personal Data may be transferred to:
- United States
- European Economic Area
- Other locations where Sub-processors operate
11.2 Transfer Mechanisms
For transfers outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Binding Corporate Rules (where applicable)
- Derogations under GDPR Article 49 (where applicable)
11.3 Standard Contractual Clauses
The EU Standard Contractual Clauses are incorporated by reference and shall apply to transfers of Personal Data from the EEA to countries without an adequacy decision.
12. AUDIT RIGHTS
12.1 Audit Right
The Controller may audit the Processor’s compliance with this DPA.
12.2 Audit Process
- Provide 30 days’ written notice
- Conduct during normal business hours
- Limited to once per year (unless breach occurs)
- Controller bears audit costs
12.3 Documentation
The Processor shall make available:
- Security documentation
- Audit reports (SOC 2, if available)
- Relevant policies and procedures
12.4 Confidentiality
Audit results shall be treated as confidential.
13. LIABILITY
13.1 Limitation
Liability under this DPA is subject to the limitations in the Agreement.
13.2 Allocation
- Each party is liable for damages caused by its breach
- Processor liability for Sub-processor breaches is subject to Agreement limitations
13.3 Indemnification
The Processor shall indemnify the Controller for fines or penalties resulting solely from Processor’s breach of this DPA.
14. TERM AND TERMINATION
14.1 Term
This DPA remains in effect for the duration of the Agreement.
14.2 Termination Effects
Upon termination:
- Processing shall cease except as legally required
- Personal Data shall be returned or deleted within 30 days
- Deletion shall be certified upon request
14.3 Survival
Sections regarding confidentiality, liability, and data deletion survive termination.
15. CCPA ADDENDUM (CALIFORNIA)
15.1 CCPA Compliance
For Personal Information of California residents:
- Processor is a “Service Provider” under CCPA
- Processing is limited to providing Services
- Processor shall not sell Personal Information
- Processor shall not retain, use, or disclose data except as permitted
15.2 CCPA Certification
The Processor certifies that it:
- Understands CCPA restrictions
- Will comply with CCPA requirements
- Will not sell Personal Information
15.3 Consumer Rights
The Processor shall assist with CCPA consumer rights requests including:
- Right to know
- Right to delete
- Right to opt-out of sale (N/A - we don’t sell data)
- Right to non-discrimination
16. GDPR SPECIFIC PROVISIONS
16.1 GDPR Compliance
This DPA incorporates GDPR requirements including:
- Article 28 (Processor obligations)
- Article 32 (Security)
- Article 33 (Breach notification)
- Article 35 (DPIA assistance)
16.2 Records of Processing
The Processor maintains records of processing activities as required by Article 30.
16.3 DPO Contact
Data Protection Officer: dpo@autonoma-studio.com
17. AMENDMENTS
This DPA may be amended:
- By written agreement of both parties
- By Processor to reflect regulatory changes (with notice)
- Updates effective upon posting or as specified
18. CONTACT
Data Protection Inquiries:
Email: dpo@autonoma-studio.com
Enterprise Support:
Email: enterprise@autonoma-studio.com
Legal:
Email: legal@autonoma-studio.com
19. EXECUTION
This DPA is incorporated into and forms part of the Agreement. By using the Services, the Controller agrees to this DPA.
For Enterprise customers requiring a signed DPA, contact enterprise@autonoma-studio.com.
This Data Processing Addendum is effective as of the date the Controller begins using the Services.
© 2026 Autonoma. All rights reserved.
Questions about this document? Get in touch.