Skip to main content

Data Processing Agreement

How we handle personal data you entrust to us, and what we commit to in writing.

Last updated September 6, 2026

Scope and roles

This Data Processing Agreement ("DPA") forms part of the agreement between Fritter Factory Innovation Labs Inc., trading as Act More Human ("Processor", "we", "us"), and the customer identified in the order form ("Controller", "you") for the provision of the Act More Human service (the "Service"). It applies wherever we process personal data on your behalf, and it is incorporated into your agreement when you purchase a company plan. If your procurement process needs a signed copy, email hello@actmorehuman.com and we will send one.

Notices under this DPA may be sent by post to:

Fritter Factory Innovation Labs Inc.
1 Stan MacPherson Way, Unit 303
Charlottetown, PE C1A 0B4
Canada

Where this DPA conflicts with the Terms of Service, this DPA governs, but only for the processing of personal data.

You are the controller of the personal data you and your users submit to the Service. We are the processor. Where we process data for our own purposes — billing records, and analytics about the Service itself — we act as an independent controller, and our Privacy Policy governs.

Definitions

"Personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "supervisory authority" carry the meanings given in the UK GDPR and Regulation (EU) 2016/679 ("GDPR"). "Data Protection Law" means all privacy and data protection laws applicable to the processing under this DPA, including the GDPR, the UK GDPR, Canadian federal and provincial privacy legislation, and applicable US state privacy laws.

Our instructions

We process personal data only on your documented instructions, which are: this DPA, the Terms of Service, and your and your users' use of the Service. We will tell you if, in our opinion, an instruction infringes Data Protection Law.

We will not sell personal data, share it for cross-context behavioural advertising, or retain, use, or disclose it for any purpose other than performing the Service.

Training. We do not use your personal data, or any content you submit, to train, fine-tune, or improve any machine-learning model. Neither do our AI sub-processors, under our contracts with them. This obligation survives termination.

Confidentiality and security

Everyone we authorise to process personal data is bound by confidentiality obligations, contractual or statutory, and is granted access only as needed to perform the Service.

We implement the technical and organisational measures described in Annex III and will not materially reduce them during the term.

Sub-processors

You give general authorisation for the sub-processors listed in Annex II. We impose data protection obligations on each that are no less protective than this DPA, and we remain liable for their performance.

We will publish any new or replacement sub-processor on this page and in our Privacy Policy at least thirty (30) days before it begins processing your personal data. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

Data subject rights

The Service gives you and your users direct control over most rights. An account holder can see every voice and every evidence quote in it, delete individual quotes, revoke agent grants and API keys, disconnect a Google account, export their voice, and delete their account.

Where a request cannot be satisfied through the Service, we will assist you, taking into account the nature of the processing. If a data subject contacts us directly, we pass the request to you rather than answering it ourselves.

We will also provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, so far as they relate to our processing and the information is not otherwise available to you.

Breach notification

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your personal data, with the information available to us at the time, and will keep you updated as we learn more. We will assist you with your own notification duties.

Deletion and return

The retention schedule in Annex I applies throughout the term. On termination, and at your choice, we will delete or return your personal data within 30 days, except where storage is required by law — specifically the billing records described in Annex I, which are retained for seven years with account identifiers removed and which contain no content.

Deletion initiated by an account holder follows the product's own rule: agent grants, API keys, and any Google connection are revoked immediately; the account is recoverable by signing in for 30 days; and raw source material is deleted at the end of the build job regardless.

Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you mandate.

In the first instance we will answer a written security questionnaire and provide our current assessment reports, including the annual CASA Tier 2 assessment we maintain for Google API access. On-site audits are limited to once per twelve months, on 30 days' notice, at your cost, unless an audit reveals material non-compliance.

International transfers

Our sub-processors process personal data in the United States and elsewhere. Where personal data is transferred out of the EEA, UK, or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, and the Swiss equivalent, each incorporated by reference. Module Two (controller to processor) applies between you and us; Module Three (processor to processor) applies between us and our sub-processors.

For the purposes of those Clauses: the data exporter is you, the data importer is us, Annex I of the Clauses is Annex I below, Annex II of the Clauses is Annex III below, and the docking clause is not used.

Liability, term, and governing law

Each party's liability under this DPA is subject to the limitations in the Terms of Service.

This DPA takes effect when you accept it or begin using the Service, whichever is earlier, and continues until we have deleted or returned your personal data under Deletion and return.

This DPA is governed by the laws of the Province of Prince Edward Island and the federal laws of Canada applicable in it, and the courts of Prince Edward Island have exclusive jurisdiction, without regard to conflict-of-laws rules.

Annex I — Details of processing

Subject matterProvision of the Act More Human service: building, storing, and serving a writing-voice profile derived from writing the data subject supplies.
DurationThe term of the agreement, plus the deletion window above.
Nature and purposeCollection, normalisation, classification, analysis, storage, retrieval, and deletion, for the purpose of producing and serving a voice profile.
Categories of data subjectYour personnel and other authorised users of the Service; and incidentally, the recipients of correspondence a user chooses to submit.
Categories of personal dataAccount identifiers (email address, name, profile picture). Content submitted for a build: sent email messages, uploaded documents, pasted text, crawled web pages. Derived data: the voice profile and its evidence quotes. Usage records: job status, tool calls, credit and billing records.
Special category dataNot requested and not required. Correspondence a user submits may incidentally contain it. The Service classifies and unticks messages flagged sensitive or personal by default, and the user reviews the selection before any build runs.
FrequencyContinuous for the duration of the agreement; source material is processed only during a build job.

Retention

WhatHow longDeleted by
Message and document text gathered for a buildLife of the jobThe worker at job end, plus an hourly sweep
Uploaded filesLife of the jobThe same sweep
Google refresh tokenLife of the jobRevoked at Google and deleted at job end
Voices, versions, evidence quotes, exclusions, drift reportsUntil deleted by the userThe user, or account deletion at T+30 days
Build job records — status, stage, counts, error codes90 days after completionAutomatic sweep
API and Connector call logs180 daysAutomatic sweep
Billing and usage records7 years, as tax law requiresRetained with account identifiers removed; they hold counts and amounts, never content
Prompts sent to the AI sub-processor30 daysAnthropic

Annex II — Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, file storage, background jobsUnited States (us-east-1)
AnthropicAI models that build and use the voice. 30-day retention, no trainingUnited States
VercelApplication hosting and serverless functionsUnited States (iad1)
StripePayments, subscriptions, invoicingUnited States, Ireland
ResendTransactional emailUnited States
SentryError and performance monitoringUnited States
PostHogProduct analyticsUnited States

Annex III — Technical and organisational measures

Encryption

TLS for all data in transit. Encryption at rest for the database and object storage. OAuth tokens encrypted before storage; the Google refresh token encrypted a second time with a key held outside the database, so a database compromise alone does not yield it. API keys stored only as SHA-256 hashes — the raw key is displayed once and cannot be recovered by us.

Access control

Row-level security is enabled and forced on every table. The application connects with a database role that does not have the privilege to bypass it, and every request sets the acting user and organisation inside the transaction, so an unset identity denies access rather than leaking. Sessions are signed with a per-environment secret. Administrative access is limited to named individuals and separated from the production application credentials.

Minimisation

Source material is never retained beyond the job that consumes it. What persists is the derived voice and the evidence quotes the user chose to keep. Exclusion lists are stored as opaque identifiers rather than as addresses. Session replays mask text by default. Usage records hold counts and amounts, not content.

Resilience

Managed database with automated backups. Stateless application tier with automatic failover. Metered work runs through a durable queue with checkpoints, so a failure resumes rather than restarting.

Monitoring

Error and performance monitoring with identifying fields scrubbed. Rate limits per account, per grant, per key, and per IP. Per-key spend caps set by the customer. Anomaly alerting when a key's daily spend exceeds five times its trailing average. An append-only audit log of sign-ins, grants, keys, member changes, plan changes, refunds, and deletions, readable by the account owner.

Vulnerability handling

A published security contact and disclosure preference at /.well-known/security.txt. An annual CASA Tier 2 assessment by a Google-authorised assessor, required for our Google API access and covering the application as a whole.

Personnel

Confidentiality obligations for everyone with access. No employee reads customer content in the ordinary course; the technical controls above are what make that true, rather than a promise.

Ayúdanos a mejorar esta página

¿Encontraste un error o tienes una sugerencia? Nos encantaría saberlo.