This Data Processing Agreement (“DPA”) forms part of the Powerdash Terms of Service between Fast Hippo Media LLC(“Powerdash”, “Processor”) and the Powerdash customer (“Customer”, “Controller”).
1. Roles
Customer is the Controller of personal data that flows through the Powerdash Service — for example, customer leads, rental bookings, or order records that the Customer uploads or collects through their storefront.
Powerdash is the Processor of that data, processing it only on the Customer's documented instructions to provide the Service.
2. Scope
This DPA covers any personal data of EU, UK, or Swiss data subjects, California residents, or other individuals where applicable data-protection law (GDPR, UK GDPR, CCPA, etc.) requires a written processing arrangement.
For personal data of Customer's own employees and team members where Powerdash is the Controller (account info, billing, etc.), our Privacy Policy applies.
3. Processing instructions
Powerdash processes personal data only to:
- Provide the Service to the Customer.
- Comply with documented instructions from the Customer.
- Meet our own legal obligations.
We will tell the Customer if we believe an instruction violates applicable law.
4. Confidentiality
Anyone we authorize to access Customer personal data is bound by written confidentiality obligations.
5. Security
We maintain a security program appropriate for the data we process. At a minimum:
- Encryption in transit (TLS 1.2 or higher).
- Encryption at rest (AES-256).
- Role-based access controls and audit logging for production data.
- Hardened cloud infrastructure with regular patching.
- Background checks on personnel with production access.
- Annual security review and penetration testing.
We are pursuing SOC 2 Type I certification (target: Q4 2026). We will provide our current security documentation on request.
6. Subprocessors
We use the following subprocessors to help us provide the Service:
| Subprocessor | Service | Region |
|---|---|---|
| DigitalOcean, LLC | Application, database, and object storage hosting | United States |
| Resend, Inc. | Transactional email | United States |
| Stripe, Inc. | Payment processing | United States |
We will give Customer at least 30 days' notice before adding or replacing a subprocessor. If Customer objects to a new subprocessor for a legitimate reason, they may terminate the affected Service for a prorated refund.
7. Personal-data breach
If we become aware of a personal-data breach affecting Customer data we will:
- Notify the Customer in writing without undue delay and no later than 72 hours after discovery.
- Include the nature of the breach, categories and approximate number of records affected, likely consequences, and the steps we have taken or propose to take.
- Cooperate with the Customer's investigation and remediation.
Notification will be sent to the email on file for the account.
8. Assistance with data-subject requests
If a data subject contacts Powerdash directly with a request to access, correct, port, or delete their data, we will forward the request to the relevant Customer within 7 days. We will assist the Customer in responding by providing reasonable tools and information.
9. International transfers
Where applicable law requires it, the parties incorporate the Standard Contractual Clauses (Module Two, Controller-to-Processor) issued by the European Commission, with the following selections:
- Clause 7 (Docking Clause): applies.
- Clause 9(a) Option 2 (General Authorisation): applies with 30 days' notice.
- Clause 11 (Redress): no independent dispute-resolution body.
- Clause 17 (Governing Law): Republic of Ireland.
- Clause 18 (Choice of Forum): Republic of Ireland.
10. Audit
We will respond to reasonable written requests from the Customer for information about our processing once per twelve-month period, subject to confidentiality. We will provide the most recent third-party security audit or penetration test summary on request.
On-site audits are available for Enterprise customers under a separate audit agreement.
11. Return or deletion of personal data
On termination of the underlying Service the Customer may export their data for 90 days. After that period we delete all personal data within 30 days, except where law requires retention. Backups containing personal data are purged on a 90-day rolling cycle.
12. Liability
Liability under this DPA is subject to the limits in the Terms of Service.
13. Contact
DPA contact: privacy@fasthippomedia.com
General contact: hello@powerdash.io
