{"id":256,"date":"2026-08-07T05:24:57","date_gmt":"2026-08-07T05:24:57","guid":{"rendered":"https:\/\/startandpower.com\/?page_id=256"},"modified":"2026-08-07T09:34:58","modified_gmt":"2026-08-07T09:34:58","slug":"dpa-encargo-de-tratamiento","status":"publish","type":"page","link":"https:\/\/startandpower.com\/nb\/dpa-encargo-de-tratamiento\/","title":{"rendered":"Data Processing Agreement (DPA)"},"content":{"rendered":"<section class=\"section band-dark page-hero\">\n<div class=\"container\">\n<p class=\"eyebrow\">Legal<\/p>\n<h1>Data Processing Agreement<\/h1>\n<p class=\"page-hero__lead\">The terms under which startandpower processes personal data on behalf of its clients.<\/p>\n<\/p><\/div>\n<\/section>\n<section class=\"section\" id=\"dpa\">\n<div class=\"container\">\n<div class=\"prose\">\n<p><strong>Last updated:<\/strong> 7 August 2026<\/p>\n<p>This Data Processing Agreement (&#8220;DPA&#8221;) forms part of the <a href=\"\/nb\/terms\/\">Terms of Service<\/a> between Start And Power LLC (&#8220;startandpower&#8221;, &#8220;we&#8221;, &#8220;us&#8221;, the &#8220;Processor&#8221;) and the client identified in the applicable quote or subscription (the &#8220;Client&#8221;, the &#8220;Controller&#8221;). It applies automatically, without needing a separate signature, whenever we process personal data on the Client&#8217;s behalf in the course of providing our services. If a Client requires a countersigned copy, we will provide one on request at <a href=\"mailto:hello@startandpower.com\">hello@startandpower.com<\/a>.<\/p>\n<p>This DPA covers our <strong>managed services<\/strong> (platform and website creation and management, email, automations, payments, CRM, bookings, and customer management run for the Client). docil.ai is a separate service with its own data processing terms at docil.ai.<\/p>\n<h3>1. Definitions<\/h3>\n<p>&#8220;Personal data&#8221;, &#8220;processing&#8221;, &#8220;controller&#8221;, &#8220;processor&#8221;, &#8220;data subject&#8221;, and &#8220;supervisory authority&#8221; have the meanings given in the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR. &#8220;Client Personal Data&#8221; means personal data that the Client, or its customers and users, provide to the services and that we process on the Client&#8217;s behalf \u2014 as distinct from data we process for our own purposes as controller (such as the Client&#8217;s own account and billing data), which is governed by our <a href=\"\/nb\/privacy-policy\/\">Privacy Policy<\/a>. Under the California Consumer Privacy Act (CCPA\/CPRA), we act as a &#8220;service provider&#8221; with respect to Client Personal Data, and this DPA constitutes the contract required by that law.<\/p>\n<h3>2. Roles, subject matter, and instructions<\/h3>\n<p>The Client is the controller of Client Personal Data and startandpower is its processor. We will process Client Personal Data only on the Client&#8217;s documented instructions \u2014 which consist of this DPA, the Terms of Service, the accepted quote, and any reasonable written instructions the Client gives us within the scope of the services \u2014 unless processing is required by law, in which case we will inform the Client before processing unless the law prohibits it. We will tell the Client if, in our opinion, an instruction infringes applicable data protection law. Details of the processing \u2014 its nature, purpose, duration, the types of data, and the categories of data subjects \u2014 are set out in Annex 1.<\/p>\n<h3>3. What we will never do with Client Personal Data<\/h3>\n<p>We will not sell Client Personal Data, share it for cross-context behavioral advertising, use it to train models, combine it with data from other clients, or process it for any purpose other than providing the services and complying with law. We will not retain, use, or disclose it outside the direct business relationship with the Client, and we certify that we understand and will comply with these restrictions.<\/p>\n<h3>4. Confidentiality<\/h3>\n<p>We ensure that every person we authorize to process Client Personal Data \u2014 employees and contractors \u2014 is bound by confidentiality obligations, contractual or statutory, and processes the data only as needed to perform their role in delivering the services.<\/p>\n<h3>5. Security<\/h3>\n<p>Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, we implement appropriate technical and organizational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include those described in Annex 2. We keep them under review and may update them, provided the overall level of protection does not decrease.<\/p>\n<h3>6. Subprocessors<\/h3>\n<p>The Client gives general authorization for us to engage subprocessors to deliver the services. Our current subprocessors are listed in Annex 3. We will notify Clients of intended additions or replacements \u2014 by updating this page and, for active Clients, by email \u2014 at least 15 days before the change takes effect. If the Client has a reasonable, data-protection-related objection to a new subprocessor, we will work with the Client in good faith to find an alternative; if none is available, the Client may terminate the affected services under the Terms of Service. We impose data protection obligations on every subprocessor equivalent to those in this DPA, and we remain fully liable to the Client for their performance.<\/p>\n<h3>7. Assistance with data subject rights<\/h3>\n<p>Taking into account the nature of the processing, we will assist the Client with appropriate technical and organizational measures in fulfilling its obligation to respond to data subject requests \u2014 access, rectification, erasure, restriction, portability, and objection. If a data subject contacts us directly about Client Personal Data, we will not respond on the merits except on the Client&#8217;s instruction; we will forward the request to the Client without undue delay.<\/p>\n<h3>8. Assistance with compliance<\/h3>\n<p>We will assist the Client, taking into account the nature of processing and the information available to us, in meeting its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities under Articles 32 to 36 GDPR.<\/p>\n<h3>9. Personal data breaches<\/h3>\n<p>We will notify the Client without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Client Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will cooperate with the Client and take reasonable steps to mitigate the breach&#8217;s effects. Notification is not an admission of fault.<\/p>\n<h3>10. International transfers<\/h3>\n<p>We are established in the United States, and Client Personal Data is processed primarily in the United States (see Annex 3 for subprocessor locations). Where the transfer of Client Personal Data from the European Economic Area, the United Kingdom, or Switzerland to us is subject to GDPR or equivalent transfer rules, the parties incorporate by reference the European Commission&#8217;s Standard Contractual Clauses (Module 2: controller to processor), completed with the details in the Annexes to this DPA, with the Client as data exporter and startandpower as data importer; for UK transfers, the UK International Data Transfer Addendum applies. If those mechanisms are amended or replaced, the successor mechanism applies. We will not transfer Client Personal Data to a third country except under a valid transfer mechanism.<\/p>\n<h3>11. Audits<\/h3>\n<p>We will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA \u2014 including summaries of our security measures and subprocessor agreements \u2014 and will allow and contribute to audits conducted by the Client or an auditor it mandates. Audits require 30 days&#8217; written notice, take place at most once per year during business hours (except after a breach or where a supervisory authority requires one), must not unreasonably disrupt our operations, and are at the Client&#8217;s expense. Where a recognized third-party report covering the relevant controls exists, the Client agrees to accept it first before requesting an on-site audit.<\/p>\n<h3>12. Return and deletion<\/h3>\n<p>When the services end, we will, at the Client&#8217;s choice, return Client Personal Data in a standard format or delete it, and delete existing copies \u2014 in line with the export and 30-day migration window described in Section 6 of the Terms of Service \u2014 unless law requires us to keep it, in which case we will keep it isolated, protected, and only as long as the law requires. On request, we will confirm deletion in writing.<\/p>\n<h3>13. Liability and term<\/h3>\n<p>The liability of each party under this DPA is subject to the limitations of liability in the Terms of Service, except where applicable data protection law does not allow such limitation. This DPA takes effect when the services begin and remains in force as long as we process Client Personal Data, surviving termination of the Terms until all Client Personal Data is returned or deleted.<\/p>\n<h3>Annex 1 \u2014 Details of processing<\/h3>\n<ul>\n<li><strong>Subject matter and nature:<\/strong> hosting, storage, transmission, display, backup, and management of data within the platforms, email, automations, payment flows, CRM, booking, and customer-management systems we build and run for the Client.<\/li>\n<li><strong>Purpose:<\/strong> providing the services described in the Terms of Service and the Client&#8217;s quote and plan.<\/li>\n<li><strong>Duration:<\/strong> the term of the Client&#8217;s subscription, plus the migration and deletion period in Section 12.<\/li>\n<li><strong>Categories of data subjects:<\/strong> the Client&#8217;s customers, prospective customers, website visitors, newsletter and form respondents, employees and collaborators whose accounts or data appear in the managed systems.<\/li>\n<li><strong>Types of personal data:<\/strong> identification and contact details (name, email, phone, address); account credentials; commercial data (orders, bookings, invoices, subscriptions, payment status \u2014 not full card numbers, which are handled by the payment processor); communications and support messages; technical data (IP addresses, device and usage data) generated by the managed platforms; and any other personal data the Client chooses to store in the managed systems.<\/li>\n<li><strong>Special categories:<\/strong> the services are not designed for special-category data (health, biometrics, etc.). The Client agrees not to store it in the managed systems without agreeing additional safeguards with us in writing first.<\/li>\n<\/ul>\n<h3>Annex 2 \u2014 Technical and organizational measures<\/h3>\n<ul>\n<li>Encryption of data in transit (TLS) across managed platforms; encryption at rest where supported by the hosting environment;<\/li>\n<li>access control on a need-to-know basis, with individual credentials, strong authentication for administrative access, and prompt revocation on role change or departure;<\/li>\n<li>network and application security: firewalls, security updates and patching of managed platforms, and hardening of administrative interfaces;<\/li>\n<li>regular backups with restoration testing, and uptime and failure monitoring with alerting;<\/li>\n<li>logging of administrative access to managed systems;<\/li>\n<li>confidentiality undertakings from all personnel, and security awareness in our working procedures;<\/li>\n<li>vendor selection that takes data protection into account, and written data protection terms with subprocessors;<\/li>\n<li>a documented procedure for detecting, escalating, and notifying personal data breaches.<\/li>\n<\/ul>\n<h3>Annex 3 \u2014 Subprocessors<\/h3>\n<ul>\n<li><strong>Namecheap, Inc.<\/strong> (United States) \u2014 hosting and domain services for the website and managed platforms;<\/li>\n<li><strong>Payment processor<\/strong> (as identified in the Client&#8217;s setup) \u2014 processing of payments on the Client&#8217;s platforms; the processor receives the data needed to process transactions;<\/li>\n<li><strong>Email service provider<\/strong> (as identified in the Client&#8217;s setup) \u2014 provision of the professional email accounts included in the Client&#8217;s plan.<\/li>\n<\/ul>\n<p>The current version of this list is always available on this page. Clients with an active subscription are notified of changes as described in Section 6.<\/p>\n<h3>Contact<\/h3>\n<p>Questions about this DPA, requests for a countersigned copy, or notices under it: <a href=\"mailto:hello@startandpower.com\">hello@startandpower.com<\/a>, or Start And Power LLC, 1621 Central Ave, Cheyenne, WY 82001, United States.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>","protected":false},"excerpt":{"rendered":"<p>Legal Data Processing Agreement The terms under which startandpower processes personal data on behalf of its clients. Last updated: 7 August 2026 This Data Processing Agreement (&#8220;DPA&#8221;) forms part of the Terms of Service between Start And Power LLC (&#8220;startandpower&#8221;, &#8220;we&#8221;, &#8220;us&#8221;, the &#8220;Processor&#8221;) and the client identified in the applicable quote or subscription (the &#8230; <a title=\"Data Processing Agreement (DPA)\" class=\"read-more\" href=\"https:\/\/startandpower.com\/nb\/dpa-encargo-de-tratamiento\/\" aria-label=\"Read more about Data Processing Agreement (DPA)\">Les mer<\/a><\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"pmpro_default_level":"","footnotes":""},"class_list":["post-256","page","type-page","status-publish","pmpro-has-access"],"_links":{"self":[{"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/pages\/256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/comments?post=256"}],"version-history":[{"count":3,"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/pages\/256\/revisions"}],"predecessor-version":[{"id":283,"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/pages\/256\/revisions\/283"}],"wp:attachment":[{"href":"https:\/\/startandpower.com\/nb\/wp-json\/wp\/v2\/media?parent=256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}