← All legal documents

Data Processing Addendum

Applies to Autonoma. Last updated 2026-08-07.

Not reviewed by a lawyer. This document was drafted to describe what the software actually does, but it has not had legal review and is not legal advice. If anything here matters to you, ask us at support@autonoma-studio.com before relying on it.

Autonoma
Effective Date: January 2026
Last Updated: January 2026


1. INTRODUCTION

This Data Processing Addendum (“DPA”) forms part of the Agreement between Autonoma (“Processor,” “we,” “us”) and the Customer (“Controller,” “you”) for the provision of Autonoma services.

This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller and ensures compliance with applicable data protection laws including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

This DPA applies primarily to Enterprise customers. Standard customers are covered by our Privacy Policy.


2. DEFINITIONS

“Agreement” means the Terms of Service, Software License Agreement, and related agreements.

“Controller” means the entity that determines the purposes and means of processing Personal Data.

“Data Subject” means an identified or identifiable natural person whose Personal Data is processed.

“Personal Data” means any information relating to an identified or identifiable natural person.

“Processing” means any operation performed on Personal Data.

“Processor” means the entity that processes Personal Data on behalf of the Controller.

“Sub-processor” means a third party engaged by the Processor to process Personal Data.

“Supervisory Authority” means an independent public authority responsible for data protection.

“GDPR” means the General Data Protection Regulation (EU) 2016/679.

“CCPA” means the California Consumer Privacy Act of 2018.


3. SCOPE AND APPLICATION

3.1 Scope

This DPA applies to all Processing of Personal Data by the Processor in connection with providing the Services.

3.2 Roles

3.3 Application

This DPA applies when:


4. DATA PROCESSING

4.1 Processing Instructions

The Processor shall:

4.2 Permitted Processing

Processing is permitted for:

4.3 Processing Details

Categories of Data Subjects:

Types of Personal Data:

Processing Activities:

Duration:


5. CONTROLLER OBLIGATIONS

The Controller shall:

5.1 Lawful Basis

5.2 Accuracy

5.3 Instructions

5.4 Data Subject Rights

5.5 Compliance


6. PROCESSOR OBLIGATIONS

The Processor shall:

6.1 Confidentiality

6.2 Security

6.3 Sub-processors

6.4 Assistance

6.5 Data Return/Deletion


7. SUB-PROCESSORS

7.1 Authorized Sub-processors

The Controller authorizes the use of the following Sub-processors:

Sub-processorPurposeLocation
Amazon Web ServicesCloud hostingUSA/EU
Google Cloud PlatformAI processingUSA/EU
Stripe, Inc.Payment processingUSA
LemonSqueezy, LLCPayment processingUSA
OpenAI, LLCAI content generationUSA
Anthropic, PBCAI content generationUSA
Sendgrid (Twilio)Email deliveryUSA

7.2 Sub-processor Changes

7.3 Sub-processor Agreements

All Sub-processors are bound by data processing agreements with equivalent protections.


8. SECURITY MEASURES

8.1 Technical Measures

The Processor implements:

Encryption:

Access Controls:

Network Security:

Application Security:

8.2 Organizational Measures

8.3 Physical Security


9. DATA BREACH NOTIFICATION

9.1 Notification Obligation

The Processor shall notify the Controller without undue delay (within 72 hours) upon becoming aware of a Personal Data breach.

9.2 Notification Contents

Notification shall include:

9.3 Cooperation

The Processor shall:

9.4 Documentation

The Processor shall document all breaches including:


10. DATA SUBJECT RIGHTS

10.1 Assistance

The Processor shall assist the Controller in responding to Data Subject requests for:

10.2 Response Time

The Processor shall respond to Controller requests within 10 business days.

10.3 Direct Requests

If Data Subjects contact the Processor directly:


11. INTERNATIONAL TRANSFERS

11.1 Transfer Locations

Personal Data may be transferred to:

11.2 Transfer Mechanisms

For transfers outside the EEA, we rely on:

11.3 Standard Contractual Clauses

The EU Standard Contractual Clauses are incorporated by reference and shall apply to transfers of Personal Data from the EEA to countries without an adequacy decision.


12. AUDIT RIGHTS

12.1 Audit Right

The Controller may audit the Processor’s compliance with this DPA.

12.2 Audit Process

12.3 Documentation

The Processor shall make available:

12.4 Confidentiality

Audit results shall be treated as confidential.


13. LIABILITY

13.1 Limitation

Liability under this DPA is subject to the limitations in the Agreement.

13.2 Allocation

13.3 Indemnification

The Processor shall indemnify the Controller for fines or penalties resulting solely from Processor’s breach of this DPA.


14. TERM AND TERMINATION

14.1 Term

This DPA remains in effect for the duration of the Agreement.

14.2 Termination Effects

Upon termination:

14.3 Survival

Sections regarding confidentiality, liability, and data deletion survive termination.


15. CCPA ADDENDUM (CALIFORNIA)

15.1 CCPA Compliance

For Personal Information of California residents:

15.2 CCPA Certification

The Processor certifies that it:

15.3 Consumer Rights

The Processor shall assist with CCPA consumer rights requests including:


16. GDPR SPECIFIC PROVISIONS

16.1 GDPR Compliance

This DPA incorporates GDPR requirements including:

16.2 Records of Processing

The Processor maintains records of processing activities as required by Article 30.

16.3 DPO Contact

Data Protection Officer: dpo@autonoma-studio.com


17. AMENDMENTS

This DPA may be amended:


18. CONTACT

Data Protection Inquiries:
Email: dpo@autonoma-studio.com

Enterprise Support:
Email: enterprise@autonoma-studio.com

Legal:
Email: legal@autonoma-studio.com


19. EXECUTION

This DPA is incorporated into and forms part of the Agreement. By using the Services, the Controller agrees to this DPA.

For Enterprise customers requiring a signed DPA, contact enterprise@autonoma-studio.com.


This Data Processing Addendum is effective as of the date the Controller begins using the Services.


© 2026 Autonoma. All rights reserved.


Questions about this document? Get in touch.