profits-compass

GDPR Article 28 compliant

Data Processing Addendum

Last Updated: July 2026 — Effective immediately

This Data Processing Addendum ("DPA") forms part of the Terms of Service between profits-compass and the user or customer ("you" / "Customer") and reflects the parties' agreement with respect to the Processing of Personal Data. It is designed to satisfy the requirements of GDPR Article 28, the UK GDPR, and equivalent local data-protection law.

1. Definitions

  • "Personal Data", "Processing", "Controller", "Processor", "Sub-processor", and "Data Subject" have the meanings given in GDPR Article 4.
  • "Customer Personal Data" means the Personal Data you submit to or generate through the Service (chat messages, profile data, payment metadata).
  • "Services" means the profits-compass AI monetization consultation platform and related offerings.

2. Roles

With respect to Customer Personal Data, you are the Controller and profits-compass is the Processor, acting on your documented instructions (these Terms + this DPA + your in-product configurations).

Where profits-compass determines the purpose and means of Processing (e.g. for fraud prevention, security logging, product analytics on aggregated, de-identified data), profits-compass acts as an independent Controller and processes such data under our Privacy Policy.

3. Scope and purpose of Processing

profits-compass will Process Customer Personal Data only for the following purposes:

  • Operating the Service per your instructions.
  • Generating AI consultation responses, including streaming report generation and PDF assembly.
  • Processing payments and refunds via Stripe.
  • Sending transactional email (login codes, receipts) via Resend.
  • Fraud prevention, security, and abuse detection (legitimate interest).
  • Aggregated, de-identified analytics (no re-identification attempted).

4. Sub-processors

You authorize profits-compass to engage the sub-processors listed below. We will notify you at least 30 days in advance of adding a new sub-processor, giving you the opportunity to object on reasonable grounds related to data protection.

Sub-processorPurposeLocation
StripePayment processing (PCI-DSS L1)US / EU
OpenAIAI text generation, optional speech-to-textUS (zero-retention API)
ResendTransactional emailUS
Managed cloud hostApplication + database hostingUS / EU regions

5. Security of Processing

profits-compass implements appropriate technical and organizational measures to protect Customer Personal Data, including:

  • TLS 1.2+ in transit; AES-256 encryption at rest.
  • bcrypt password hashing (no plaintext credentials).
  • Rate-limited admin endpoints with token-based auth.
  • Least-privilege access controls with audit logging.
  • Regular vulnerability scanning and dependency updates.
  • Documented incident response plan with breach notification.

6. Data Subject rights

profits-compass will, taking into account the nature of the Processing, assist you by appropriate technical and organizational measures (including the self-service tools in the user's profile) to fulfill your obligation to respond to requests from Data Subjects exercising their rights under GDPR Articles 15–22.

7. International data transfers

Where Customer Personal Data is transferred outside the European Economic Area, the United Kingdom, or other jurisdictions with an adequacy decision, profits-compass relies on the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK international data transfer agreements. Supplementary safeguards include encryption in transit and at rest, strict access controls, and data minimization.

8. Personal data breach notification

profits-compass will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data breach affecting Customer Personal Data. The notification will describe the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.

9. Data return and deletion

You may export your Customer Personal Data at any time from your profile (Profile → Account & security → Export my data). On termination of the Services, profits-compass will delete Customer Personal Data within 30 days, except where retention is required by law (e.g. tax records, retained for 7 years).

10. Audit rights

profits-compass will make available to you, on reasonable request, information necessary to demonstrate compliance with this DPA, including summaries of our most recent security assessments and our sub-processor list. On at least 30 days' written notice, and no more than once per year, you may request an audit; audits will be conducted during business hours and subject to confidentiality obligations.

11. Changes to this DPA

We may update this DPA to reflect changes in law or in our sub-processor list. Material changes will be communicated in line with our Privacy Policy. Continued use of the Service after the effective date constitutes acceptance.

12. Contact

For any DPA-related question, sub-processor objection, or audit request, contact our Data Protection Officer: