Data Processing Addendum (DPA)

Last updated September 14, 2026
Read this first: this is a starting template covering the standard terms a SaaS product like Productive needs - it is not legal advice, and it has not been reviewed by an attorney. Have a lawyer licensed in your jurisdiction review and customize it (entity name, governing law, liability caps, DPA sub-processor list) before treating it as binding.

This Data Processing Addendum ("DPA") forms part of the agreement between Customer and 33Labs ("Processor") governing Customer's use of Productive, and applies where Customer's use of the Service involves the processing of personal data subject to data protection law (e.g. GDPR, UK GDPR, or CCPA). In case of conflict, this DPA controls over the Terms of Service with respect to data protection.

1. Roles

Customer is the controller (or, where Customer itself acts as a processor for its own customers, a processor) of personal data it submits to the Service. Productive is the processor, acting only on Customer's documented instructions as set out in the Terms of Service and this DPA.

2. Subject matter and duration

Processing covers the personal data contained in Customer Data (messages, workspace content, member/guest identity information) for as long as Customer uses the Service, plus the retention period described in the Privacy Policy.

3. Nature and purpose of processing

Personal data is processed to provide the Service: storing and routing messages, running AI agents against configured content, authenticating users, and generating usage/billing records.

4. Sub-processors

Customer authorizes the following categories of sub-processor. We'll give reasonable notice before adding a new sub-processor that materially changes this list.

Sub-processorPurpose
Hosting/infrastructure providerApplication hosting, database, backups
AI model provider(s) Customer configures (e.g. Anthropic, OpenAI, or others via OpenRouter)Generating AI agent responses from Customer-supplied prompts/context
Stripe, Inc.Payment processing and billing
Logto (or configured identity provider)Social sign-in / authentication
Transactional email providerAccount and billing notifications

5. Security measures

Productive maintains encryption in transit (TLS), access controls limiting internal access to Customer Data, and regular automated backups with a defined retention window. Productive will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of a confirmed security incident affecting Customer Data.

6. Data subject requests

Productive will assist Customer in responding to a verified data subject request (access, correction, deletion, portability) to the extent Productive is able to, given the nature of processing.

7. International transfers

Where personal data is transferred outside the customer's region in a way that requires a transfer mechanism under applicable law, the parties will rely on Standard Contractual Clauses or another lawful mechanism, incorporated into this DPA by reference upon request.

8. Deletion on termination

On termination of the Service, Productive will delete or, at Customer's written request, return Customer Data within a commercially reasonable period, except where retention is required by law or by an active backup cycle (currently up to 14 days for operational backups).

9. Audit rights

On reasonable request, no more than once per 12 months, Productive will provide information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a written summary in lieu of an on-site audit.

10. Contact

Data protection contact: joe@getnifty.xyz.