Data Processing Agreement
GDPR-compliant DPA between Customer and Rōmy
This Data Processing Agreement ("DPA") forms part of the Terms of Service between GetRomy LLC ("Processor", "Rōmy") and the customer that has accepted those Terms ("Controller", "Customer"). It applies whenever Rōmy processes Personal Data on behalf of the Customer.
By using the Service, the Customer accepts this DPA. If the Customer requires a counter-signed copy on its own paper, contact howard@getromy.app.
1. Definitions
Capitalised terms have the meaning given in Regulation (EU) 2016/679 (GDPR) and the UK GDPR, supplemented by:
- Affiliates — entities controlling, controlled by, or under common control with a party.
- Customer Personal Data — Personal Data within Customer Content that Rōmy processes on the Customer's behalf.
- Sub-processor — a third party engaged by Rōmy to process Customer Personal Data, listed at /subprocessors.
- Standard Contractual Clauses ("SCCs") — the EU SCCs adopted by Commission Decision 2021/914, and the UK International Data Transfer Addendum issued by the ICO under section 119A of the UK Data Protection Act 2018.
- Applicable Data Protection Law — GDPR, UK GDPR, the Swiss FADP, the California CCPA/CPRA and other US state privacy laws to the extent applicable, and any other privacy law applicable to the processing.
2. Roles
The Customer is the Controller of Customer Personal Data. Rōmy is the Processor. Each party complies with its respective obligations under Applicable Data Protection Law.
For Customer-account data Rōmy processes for its own purposes (e.g. billing the Customer), Rōmy acts as a Controller and the Privacy Policy governs.
3. Scope and details of processing
| Item | Details |
|---|---|
| Subject matter | Provision of the Rōmy Service (donor / prospect research and AI-assisted chat tools). |
| Duration | For the term of the Customer's subscription, plus the period needed for deletion or return of data. |
| Nature and purpose | Hosting, storage, processing, retrieval, and AI-assisted enrichment of Customer Content. |
| Categories of data subjects | Customer's authorised users; donors / prospects researched by the Customer; other individuals whose data the Customer chooses to upload. |
| Categories of Personal Data | Names, contact details, employer, professional title, postal address, public-source profile information, philanthropic indicators, custom notes, AI-generated enrichment derived from the above. The Customer agrees not to upload categories listed under §6 of the Terms of Service. |
| Special-category data | None permitted by default. The Customer must not upload Art. 9 GDPR data without our prior written agreement. |
4. Customer obligations
The Customer:
- Determines the purposes and means of processing and complies with Applicable Data Protection Law as a Controller, including establishing a lawful basis (typically legitimate interests or consent), providing required notices, and honouring data-subject rights.
- Warrants that it has the right and lawful basis to provide Customer Personal Data for processing under this DPA.
- Will use the Service in compliance with the Acceptable Use Policy, including the prohibition on uploading restricted data.
- Is responsible for the security of any data outside Rōmy's control (e.g. its own devices and exports).
5. Rōmy obligations
Rōmy will:
- Process only on documented instructions. Rōmy processes Customer Personal Data only on Customer's documented instructions, including for international transfers, except where required by Union or Member-State law (in which case Rōmy will inform the Customer unless the law prohibits it). Customer's instructions are: this DPA, the Terms, the Customer's settings and use of the Service, and any written instructions accepted by Rōmy.
- Confidentiality. Ensure personnel authorised to process Customer Personal Data are bound by confidentiality.
- Security. Implement and maintain the technical and organisational measures in Annex II below.
- Sub-processors. Engage Sub-processors only as set out in §6.
- Assist the Customer. Help with Article 32–36 obligations (security, breach notification, DPIA support, prior consultation) considering the nature of processing and the information available to Rōmy.
- Data-subject requests. Forward to the Customer any request from a data subject regarding their data, and assist by appropriate technical and organisational measures, including the in-app export and deletion endpoints.
- Return / delete. On termination, delete or return Customer Personal Data per §10.
- Make available information necessary to demonstrate compliance and allow audits per §8.
6. Sub-processors
The Customer authorises Rōmy to engage the Sub-processors listed at /subprocessors. Rōmy:
- Imposes contractual data-protection obligations on each Sub-processor that are no less protective than this DPA.
- Will give the Customer prior notice of any new Sub-processor by updating the /subprocessors page.
- The Customer may object on reasonable data-protection grounds within 30 days of notice. If the parties cannot agree a remedy, Customer may terminate the affected portion of the Service for the Sub-processor change reason.
- Remains liable to the Customer for the acts and omissions of Sub-processors as if performed by Rōmy.
7. Security
Rōmy implements appropriate technical and organisational measures (see Annex II) and reviews them periodically.
8. Audits
Rōmy will, upon reasonable written request and no more than once per 12 months (except where required by law or following a Personal Data Breach), make available:
- A summary of its security controls
- Sub-processor list and SCC copies
- Penetration test or vulnerability scan summaries (if available)
- Responses to a reasonable security questionnaire
On-site audits are not generally available; the Customer may engage an independent third-party auditor under NDA at the Customer's cost, subject to scope and scheduling agreed in advance, for material grounds for concern that Rōmy cannot otherwise resolve.
9. Personal Data Breach
Rōmy will notify the Customer without undue delay (and in any event no later than 72 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include known information per Art. 33(3) GDPR. Rōmy will document and remediate the Breach and assist the Customer with its own notification obligations as reasonably required.
10. Return or deletion of data
On termination of the Service or at the Customer's written request, Rōmy will delete Customer Personal Data within 30 days, except as required to be retained by law (e.g. billing records) and copies that may persist briefly in routine backups until rotated out. Customers can also self-serve immediate deletion via Settings → Data & Privacy → Delete account, which removes data from active systems in a single operation.
11. International transfers
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate by reference:
- The EU SCCs (Modules 2 (Controller-to-Processor) and where applicable 3 (Processor-to-Processor)) — Module 2 between Customer and Rōmy with: docking clause selected, optional clause 7 not used, Clause 8.9 audits as in §8, governing law of Ireland for EU transfers, supervisory authority of the data exporter's competent authority.
- The UK Addendum for UK transfers, with default selections.
- The Swiss FADP is supported via the EU SCCs with country-specific adjustments.
The data exporter is the Customer; the data importer is Rōmy. Annex I details (parties, processing) are at §3 above and the Customer's account record. Annex II (security measures) is below. Annex III (Sub-processors) is at /subprocessors.
12. Liability
The parties' respective liability under this DPA is governed by, and subject to, the limitations and exclusions in the Terms of Service. Where the Terms cap liability, that cap also applies to claims under this DPA, except as required by Applicable Data Protection Law.
13. Order of precedence
If there is a conflict between this DPA and the Terms, this DPA controls for matters relating to the processing of Personal Data. The SCCs prevail over this DPA where required by Applicable Data Protection Law.
14. Term and changes
This DPA terminates with the Terms. Rōmy may update this DPA to reflect changes in Sub-processors, security measures, or applicable law; material changes are posted at intel.getromy.app/dpa with reasonable notice.
Annex II — Technical and Organisational Security Measures
The following measures are implemented or in progress. Specific implementations may evolve over time consistent with industry practice.
Access control
- All production access requires individual user authentication.
- Multi-factor authentication enabled for personnel administering production systems via providers that support it (e.g. Vercel, Supabase, GitHub).
- Least-privilege model: separate environments for development and production.
- Access reviews on personnel changes; immediate revocation on departure.
Encryption
- TLS 1.2+ for all data in transit.
- Encryption at rest for the production database (Supabase) and file storage (Vercel Blob).
- Cookie sessions over Secure, HttpOnly cookies.
Network and platform security
- Hosting on Vercel with edge-network DDoS protection and WAF capabilities.
- Database hosting on Supabase with managed network controls.
- Sandboxed compute for AI agent execution.
Logical separation
- Customer data is logically segregated by user identifier and access-controlled at the application layer.
- Sub-processor isolation per the upstream provider's controls.
Software security
- Authentication via Better Auth (Google OAuth + email/password). Passwords are never stored in plaintext; they are hashed using Better Auth's built-in scheme. New / changed passwords are checked against the Have I Been Pwned breach database. Email verification is required before sign-in.
- API keys (where used) are stored hashed and shown to the user once at creation.
- Input validation, output encoding, parameterised queries.
- Dependency monitoring and timely patching.
Logging and monitoring
- Application and access logs collected for security and debugging.
- Anomaly detection at the platform level (Vercel, Supabase).
Personnel
- Confidentiality obligations in employment / contractor agreements.
- Security awareness expectations for personnel with production access.
Vendor management
- Sub-processors subject to written agreements, data-protection terms, and (where applicable) SCCs.
Backups and restoration
- Standard backups via Supabase. Restoration is tested through the provider's mechanisms.
Incident response
- Defined breach-response procedure with 72-hour notification target.
- Post-incident review for each material incident.
Data subject rights
- In-app data export (Settings → Data & Privacy → Export) — GDPR portability.
- In-app account deletion (Settings → Data & Privacy → Delete account) — immediate erasure.
- Privacy intake at /privacy/request for non-customers.
Signatures
This DPA is incorporated by reference when the Customer accepts the Terms. A counter-signed copy is available on request to howard@getromy.app.
For Rōmy:
- Company: GetRomy LLC, a Texas limited liability company based in Kerrville, Texas
- Signatory: Howard, Chief Executive Officer
- Email: howard@getromy.app
Published at intel.getromy.app/dpa.