Data Processing Addendum
Current as of July 14, 2026 · v1.0 — July 2026
This Data Processing Addendum ("DPA") describes how CoreTV LLC ("CORE") processes personal data on your behalf when providing websites, hosting, portals, AI features, and communications services, and forms part of the agreement between you and CORE.
1. Roles
For personal data you or your end users submit through services CORE operates for you (your website forms, your project data, your knowledge base), you are the controller and CORE is a processor acting on your documented instructions. For CORE's own account, billing, and platform-security data, CORE is the controller as described in the Privacy Policy.
2. Scope of Processing
CORE processes personal data solely to deliver contracted services: building and hosting your website, operating your client portal, sending communications you initiate, powering AI features you enable, billing, and support. CORE does not sell personal data and does not process it for purposes beyond the services without your instruction.
3. Subprocessors
CORE uses vetted subprocessors to deliver the services, including: Supabase (database, authentication, storage), Vercel (application hosting and delivery), Railway (background compute), Cloudflare (DNS and network security), Stripe (payments), Twilio (voice and SMS), Resend (email delivery), Anthropic (AI models), Voyage AI (embeddings), Pinecone (vector search), and Upstash (caching). Each subprocessor is bound by data-protection obligations no less protective than this DPA. CORE will notify account owners of material subprocessor changes with reasonable advance notice.
4. Security Measures
CORE implements technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; AES-256-GCM encryption for stored credentials and secrets; role-based access with deny-by-default row-level security; mandatory two-factor authentication for staff; session logging with device and IP forensics; audit logging of administrative actions; and documented incident response.
5. Incident Notification
CORE will notify affected account owners without undue delay, and in any case within seventy-two (72) hours, after becoming aware of a personal-data breach affecting their data, providing the nature of the breach, likely consequences, and measures taken.
6. Data Subject Requests
Taking into account the nature of processing, CORE will assist you with reasonable technical measures to respond to data-subject requests (access, correction, deletion, portability). Requests received directly by CORE that concern your end users will be forwarded to you.
7. Retention & Deletion
Personal data is retained while services are active and as required for legal and accounting obligations. On termination and written request, CORE will delete or return personal data processed on your behalf within ninety (90) days, excluding backups that expire on their standard rotation and records CORE must retain by law.
8. International Transfers
Where processing involves transfers out of your jurisdiction, CORE relies on its subprocessors' compliance frameworks and standard contractual safeguards, and processes data in the United States by default.
9. Audit
Upon reasonable written notice, and no more than once annually absent a demonstrated incident, CORE will make available information reasonably necessary to demonstrate compliance with this DPA.
Download this document
Save a PDF copy for your records.
Questions about this document? Email legal@core.example — a human reads it.