Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") forms part of the agreement between Customer and 33Labs ("Processor") governing Customer's use of Productive, and applies where Customer's use of the Service involves the processing of personal data subject to data protection law (e.g. GDPR, UK GDPR, or CCPA). In case of conflict, this DPA controls over the Terms of Service with respect to data protection.
1. Roles
Customer is the controller (or, where Customer itself acts as a processor for its own customers, a processor) of personal data it submits to the Service. Productive is the processor, acting only on Customer's documented instructions as set out in the Terms of Service and this DPA.
2. Subject matter and duration
Processing covers the personal data contained in Customer Data (messages, workspace content, member/guest identity information) for as long as Customer uses the Service, plus the retention period described in the Privacy Policy.
3. Nature and purpose of processing
Personal data is processed to provide the Service: storing and routing messages, running AI agents against configured content, authenticating users, and generating usage/billing records.
4. Sub-processors
Customer authorizes the following categories of sub-processor. We'll give reasonable notice before adding a new sub-processor that materially changes this list.
| Sub-processor | Purpose |
|---|---|
| Hosting/infrastructure provider | Application hosting, database, backups |
| AI model provider(s) Customer configures (e.g. Anthropic, OpenAI, or others via OpenRouter) | Generating AI agent responses from Customer-supplied prompts/context |
| Stripe, Inc. | Payment processing and billing |
| Logto (or configured identity provider) | Social sign-in / authentication |
| Transactional email provider | Account and billing notifications |
5. Security measures
Productive maintains encryption in transit (TLS), access controls limiting internal access to Customer Data, and regular automated backups with a defined retention window. Productive will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of a confirmed security incident affecting Customer Data.
6. Data subject requests
Productive will assist Customer in responding to a verified data subject request (access, correction, deletion, portability) to the extent Productive is able to, given the nature of processing.
7. International transfers
Where personal data is transferred outside the customer's region in a way that requires a transfer mechanism under applicable law, the parties will rely on Standard Contractual Clauses or another lawful mechanism, incorporated into this DPA by reference upon request.
8. Deletion on termination
On termination of the Service, Productive will delete or, at Customer's written request, return Customer Data within a commercially reasonable period, except where retention is required by law or by an active backup cycle (currently up to 14 days for operational backups).
9. Audit rights
On reasonable request, no more than once per 12 months, Productive will provide information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a written summary in lieu of an on-site audit.
10. Contact
Data protection contact: joe@getnifty.xyz.