Data Processing Addendum (DPA)
This DPA forms part of the agreement between you (Controller) and Scriplume (Processor) under the GDPR / UK GDPR / CCPA. Last updated 2026-05-10. For a signed bilateral copy email hello@clawwww.pw.
1. Subject matter & duration
Processor processes Personal Data on behalf of the Controller for the duration of the subscription, plus a 90-day post-termination retention window for export.
2. Nature & purpose
To deliver the Scriplume service: topic discovery, drafting, voice analysis, SEO scoring, repurpose, conversion-toolkit assets, and integrations to publishing platforms named by the Controller.
3. Categories of data subjects
- The Controller and the Controller's authorised users.
- Subscribers / readers indirectly referenced via integrations chosen by the Controller.
4. Categories of personal data
- Account: email, name.
- Content: drafts, voice profiles (text + embeddings), CTA / popup assets.
- Integration tokens (encrypted at rest with libsodium).
- Usage events: model name, tokens, cost, latency.
5. Sub-processors
See Privacy Policy for the complete list. We notify of changes via the changelog.
6. International transfers
Where data is transferred outside the EEA / UK, we rely on EU Standard Contractual Clauses (2021/914) plus the UK IDTA, and apply supplementary measures (encryption in transit + at rest, named-egress sub-processors).
7. Security
Technical and organisational measures currently in place:
- TLS in transit, enforced by HSTS; Content-Security-Policy and frame-ancestors denial.
- Integration tokens encrypted at rest with libsodium secretbox.
- Every data query is scoped to the owning account at the query layer, so one tenant cannot read another's content.
- Inbound payment webhooks are rejected unless their HMAC signature verifies in constant time, and each event is processed at most once.
- Access to hosting, database, and payment dashboards requires two-factor authentication.
We notify of breaches without undue delay and within 72 hours where applicable. Report a suspected vulnerability to security@clawwww.pw.