DATA PROCESSING ADDENDUM · UPDATED 2026-08-14
The service provider terms, at signup.
California requires a specific set of promises before a vendor counts as your service provider rather than a third party. All ten are below, in the order the regulation lists them, and you accepted them with the terms at signup rather than by asking us for a copy.
How this document was written.
This is a first version, drafted with AI against the statute and the regulations it cites, and not reviewed by outside counsel. It is accurate to how DropDue actually works, which is the part we can vouch for. It will be reviewed by a lawyer before the first enterprise contract, and the date above changes when it is. If a clause matters to your deal, have your own counsel read it.
- 01
We will not sell or share it.
DropDue will not sell the personal information you disclose to us, and will not share it for cross context behavioural advertising, as those terms are defined in the CCPA. There is no version of this agreement in which that becomes allowed.
- 02
The business purpose, named specifically.
We process your data for one purpose: matching your records against the CPPA Delete Request and Opt out Platform list, and generating the deletion status files, for your own CCPA deletion cycle work.
That sentence is the whole permission. Anything not inside it, we may not do.
- 03
No other use, no other retention, no other disclosure.
We will not retain, use, or disclose your data outside that direct business relationship, or outside what the CCPA permits a service provider to do.
We do not combine it with another customer's data. We do not use it to build or improve anything unrelated to the service we provide you. We do not train models on it.
- 04
We help you meet your obligations.
We will assist you in responding to consumer requests that reach us through the service, cooperate with your reasonable assessments, and tell you promptly if we determine we can no longer meet our obligations under the CCPA.
- 05
Return or deletion at the end.
On termination we delete or return the personal information we hold on your behalf, on your instruction, except where the law requires us to keep it.
Your audit log survives that deletion, because it is the record of what was decided and by whom rather than a copy of the identifiers themselves. It stays available to you for 12 months after cancellation and is exportable at any point in that window.
- 06
Your right to check.
You may take reasonable and appropriate steps to verify that we are using the data consistently with this addendum, including a security questionnaire once a year at no charge. We do not hold a SOC 2 report yet and we say so plainly on the security page. When one exists you may accept it instead.
- 07
Our subprocessors carry the same terms.
We bind every subprocessor to restrictions equivalent to these. The current list is Vercel, Railway, Neon, Amazon Web Services, Cloudflare, Postmark, Stripe. We announce a material change to this list here before it takes effect. Every one of them is bound to the same restrictions we accept in the DPA.
- 08
Breach notification.
If we become aware of a security incident affecting your personal information, we will notify you without undue delay and in no event later than 72 hours after we become aware of it, with what we know at the time rather than after the investigation closes.
- 09
How we hold your DROP key.
The key is encrypted at rest, every access is logged, it is decrypted only inside the job that calls DROP, and it is used only for the purpose named above. You can revoke it in one click, and it is purged on termination or on your request.
Self serve may instead accept a key pasted for a single submit and discard run. That key lives in server memory for the length of one API call, is never written to disk or to a log, and is discarded when the call returns. It is the same permission and the same addendum, not a separate custody regime.
- 10
Term.
This addendum runs for as long as your subscription does, and the return and deletion obligations survive it. It forms part of the terms of service, and you accepted it by the same checkbox at signup. If it conflicts with the terms of service on the handling of personal information, this addendum wins.
Why this is not a PDF you have to request.
A DPA that arrives after a sales call is a gate. This one is the same text for every customer, on a public page, accepted by checkbox with the version and timestamp recorded. Send your counsel this link. If a clause needs to change for your deal, write to us and we will tell you straight away whether we can do it.
Questions about this document: legal@dropdue.com.
Terms →Privacy →Guarantee →DPA →Security →
DropDue is a software tool, not a law firm, and this page is not legal advice. Not affiliated with the CPPA.