BIGSPAWN

Legal

Data Processing Addendum

Last updated: June 11, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Big Spawn LLC (“Big Spawn”, “we”, “us”) and the customer that subscribes to a paid Service (“Customer”, “you”). It applies whenever Big Spawn processes Personal Data on Customer's behalf in connection with a paid subscription to one of our Services (the “Service(s)”), and is automatically incorporated into your subscription agreement on the effective date listed at the top of this page.

Roles of the parties

For Personal Data of Customer's own end customers, prospects, contacts, employees, contractors, and other identifiable individuals that Customer chooses to store in, or send through, the Services (collectively, “Customer Personal Data”), Customer is the Data Controller / Business and Big Spawn is the Data Processor / Service Provider. Customer is responsible for the lawful basis under which Customer Personal Data is collected and shared with Big Spawn.

For Personal Data Big Spawn collects directly about Customer's authorized users (such as login email, IP address, and security logs) for the purpose of operating, securing, and billing the Services, Big Spawn acts as an independent Controller / Business and processes that data under our Privacy Policy rather than under this DPA.

Subject matter, duration, nature, and purpose of processing

  • Subject matter. Big Spawn’s processing of Customer Personal Data as needed to provide the Services described in the Terms of Service and in the Service-specific product documentation.
  • Duration. For the duration of Customer’s subscription plus the retention periods described in our Privacy Policy (typically up to 90 days after account deletion for Customer Content, longer for tax/audit records).
  • Nature. Storage, retrieval, organization, structuring, display, transmission, backup, deletion, and any related operations performed by the Services on Customer’s behalf.
  • Purpose. Providing the Services to Customer, securing those Services, providing support, satisfying applicable law, and the legitimate purposes described in the Terms of Service.

Categories of data subjects and types of Personal Data

Categories of data subjects:

  • Customer's own end customers and prospects.
  • Customer's employees, contractors, and operators.
  • Reviewers, testimonial authors, and other contacts whose information Customer chooses to publish or store.

Types of Personal Data typically processed:

  • Business contact information (name, email, phone, business address).
  • Customer-uploaded testimonials, reviews, and free-text content.
  • Photographs and other media that Customer chooses to upload, which may include identifiable images of people.
  • Appointment metadata (date, time, contact name, contact email, service requested).

Big Spawn does not request, and Customer must not upload, Special Categories of Personal Data (GDPR Article 9) such as health, racial/ethnic origin, religious belief, or political opinion data through the standard Service interface.

Subprocessors

Big Spawn engages the third-party service providers listed at /subprocessors as subprocessors. Customer provides general authorization for Big Spawn to use these subprocessors, and any future subprocessors, for the processing of Customer Personal Data. We will give at least 30 days' notice before engaging a new subprocessor that processes Customer Personal Data, by updating the subprocessors page and (if Customer has subscribed to subprocessor-update notifications) by email.

Customer may object in writing to a new subprocessor on reasonable grounds relating to data protection within 30 days of notice. If we cannot reasonably accommodate the objection, Customer may terminate the affected Services for convenience and receive a pro-rated refund of any pre-paid fees for the unused remainder of the term.

Technical and organizational security measures

Big Spawn maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. These measures include:

  • Encryption in transit: TLS 1.2+ for all Service traffic over public networks.
  • Encryption at rest: AES-256 (or equivalent) for stored data, via Supabase managed encryption.
  • Access controls: Row-level security policies on every multi-tenant table, scoped so that Customer Personal Data is only readable and writable by Customer's own authenticated session.
  • Principle of least privilege: Internal access to production data is limited to a small number of named operators on a need-to-know basis, with audit logging on privileged access.
  • Network segmentation: Production environments are isolated from development and preview environments; service-role credentials never appear in client bundles.
  • Vulnerability management: Automated dependency scanning and security advisories, with triage and remediation timelines proportional to severity.
  • Logging and monitoring: Application and infrastructure logs are retained for security investigation and incident response.

Assisting with data subject rights

Customer remains the controller of Customer Personal Data and is primarily responsible for responding to requests from data subjects exercising their rights under applicable law (GDPR Articles 15-22, CCPA/CPRA, and comparable regimes).

Big Spawn will provide reasonable assistance to enable Customer to fulfill these requests, including:

  • Access & portability: Customer can export Customer Personal Data from the platform UI and via the /api/account/export endpoint, which returns the requesting user’s data in a machine-readable JSON format.
  • Rectification: The Services let Customer correct stored Customer Personal Data directly through the dashboard.
  • Erasure: Customer can delete records through the platform UI, and full-account deletion is available via the /api/account/delete endpoint or by emailing privacy@bigspawn.com.
  • Restriction & objection: Customer may suspend or cancel a subscription to halt further processing of Customer Personal Data; ongoing storage outside those operations is described in the Privacy Policy retention section.

International data transfers

The Services are hosted in the United States (Vercel and Supabase U.S. regions). Where Customer transfers Personal Data from the European Economic Area, the United Kingdom, or Switzerland to Big Spawn in the United States, the parties adopt the EU Commission's Standard Contractual Clauses (Module 2: Controller to Processor) and the UK International Data Transfer Addendum to those clauses, which are incorporated into this DPA by reference. The Annexes to the SCCs are deemed completed with the information set out in “Subject matter, duration, nature, and purpose of processing,” “Categories of data subjects and types of Personal Data,” and “Technical and organizational security measures” above; the supervisory authority is the competent authority of the EU Member State of the data exporter, and the governing law is that of the same Member State.

Personal Data breach notification

Big Spawn will notify Customer without undue delay, and in any case within 72 hours of becoming aware of a Personal Data breach affecting Customer Personal Data (as required by GDPR Article 33(2)). The notification will describe, to the extent known at the time, the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and the measures taken or proposed to address the breach.

Audit rights

Big Spawn will, on reasonable request and no more than once per calendar year, provide Customer with a written summary of Customer-relevant security measures and any independent third-party reports we hold from our hosting and database subprocessors. Where applicable law or a material confirmed breach requires more, the parties will cooperate in good faith on an additional audit, conducted on at least 30 days' notice, during normal business hours, in a manner that does not unreasonably interfere with Big Spawn's ordinary operations, and subject to confidentiality.

Term and termination

This DPA takes effect on the effective date at the top of this page and continues for the duration of the Terms of Service between the parties. On termination of the Services, Big Spawn will delete or, at Customer's written request, return Customer Personal Data within the timeframes described in the Privacy Policy, except where applicable law requires longer retention.

Contact

Data-protection inquiries and DPA execution requests: privacy@bigspawn.com.

Mailing address:
Big Spawn LLC
c/o Northwest Registered Agent
8735 Dunwoody Place STE N
Atlanta, GA 30350

Service of process and formal legal notices should be sent to the address above, not via email.

Back to home