Data Processing Agreement

Version 0.3 · Last updated 7 August 2026

This agreement governs how we process personal data on your behalf when you use The Creators Base. It is designed to satisfy Article 28 of the EU GDPR and of the UK GDPR, and it forms part of our Terms of Service.

This is a living document. We are reviewing it with data protection counsel and will publish updates here; the version and date above tell you which text is current. If your own compliance requires a signed counterpart, write to legal@thecreatorsbase.com and we will provide one.

1. Parties and scope

This Data Processing Agreement (the “DPA”) is entered into between:

  • Amazing Codes OÜ, a private limited company incorporated in Estonia under registry code 17376927, VAT number EE102931572, with its registered office at Kotkapoja tn 2a-10, Kristiine District, 10615 Tallinn, Harju County, Estonia, operating the service known as The Creators Base (the “Processor”, “we”, “us”); and
  • the customer who has accepted the Terms of Service for The Creators Base (the “Customer”, “Controller”, “you”).

This DPA applies where and to the extent that we process Customer Personal Data on your behalf. In the event of conflict, it prevails over the Terms of Service in respect of that processing, and the Standard Contractual Clauses referred to in section 9 prevail over this DPA.

References to a provision of the EU GDPR include the corresponding provision of the UK GDPR and the Data Protection Act 2018 where those apply.

2. Who is controller, and of what

You are the controller. We are the processor. You decide why and how the data about your clients is processed; we process it only on your behalf.

You are responsible for the lawfulness of what you put into the Service — including having a lawful basis to process your clients’ personal data, giving them the information required by Articles 13 and 14, and ensuring that what you choose to share with them is lawful to share.

Where we act as controller, this DPA does not apply. We are an independent controller of your own account data (name, email, credentials, billing), of product analytics about your use of the Service, and of our own business records. That processing is governed by our Privacy Policy.

This distinction is load-bearing rather than cosmetic: the analytics, support and marketing tools we use observe you, and none of them is loaded on the pages your clients see (see section 4 and Annex II).

3. What we do, and do not do, with your data

  • We process Customer Personal Data only on your documented instructions. Your use of the Service, together with this DPA and the Terms, constitutes those instructions. We will tell you if, in our opinion, an instruction infringes data protection law.
  • Everyone we authorise to access Customer Personal Data is bound by an appropriate duty of confidentiality, and access is limited to those who need it to run or support the Service.
  • We implement the technical and organisational measures in Annex II, as required by Article 32.
  • We do not sell Customer Personal Data, do not use it for our own marketing, and do not use it to train machine learning models — neither ours nor anyone else’s.

4. The client portal

The Service lets you publish a read-only page where a client can follow the status of their projects. It is reached through a link containing a high-entropy token and no login.

Where you create such a link, you instruct us to make the data described in Annex I accessible to any person holding it. You decide who receives the link, and you can revoke it, replace it, or give it an expiry date at any time.

You can require the holder to confirm the email address you recorded for that client before the portal opens. Where you do, we email a single-use code to that address and, once it is used, keep a strictly necessary session in the client’s browser so they are not asked again on every visit. That session is the only cookie the portal can set; it carries no analytics, is scoped to the portal, and expires after 30 days. It is tied to the link, so revoking or replacing the link ends it.

You can also share individual documents on the portal, and attach links to files you host elsewhere. Sharing a document is always a deliberate act on your part: we never list a project’s documents automatically, and a document you have not shared is not reachable from the portal. What the holder can see, and what opening a shared document reveals, is described in Annex I.

The safeguards that apply to it are listed in Annex II, section 5.

5. Artificial intelligence features

Some features draft text using a third-party large language model (see Annex III). They send the model a description of the relevant project state, which can include the names of your clients and of your projects.

They never send authentication credentials, payment data, bank details, or the contents of uploaded files. We contract with the model provider on terms under which inputs and outputs are not used to train models.

These features can be disabled for your account on request.

6. Helping you meet your obligations

  • Data subject requests. The Service is the primary means: you can access, correct, export and delete Customer Personal Data yourself, at any time, without involving us. Where a request reaches us directly from one of your clients, we will not answer it substantively — we will refer the person to you and tell you without undue delay.
  • Personal data breach. We will notify you without undue delay, and in any event within 48 hours of becoming aware of a breach affecting Customer Personal Data, with the information available to us at the time and the rest as soon as we have it. As controller, notifying the supervisory authority or the affected people is your decision and your duty.
  • Articles 32 to 36. We assist you with security, impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.

7. Subprocessors

You give us general authorisation to engage subprocessors. The current list is in Annex III.

We will tell you at least 30 days before adding or replacing one, by email to your account address and by updating Annex III. You may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

Each subprocessor is bound by written obligations no less protective than those in this DPA, and we remain fully liable to you for what they do.

8. Audits and information

We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits by you or an auditor you mandate.

In the first instance we will answer with our current documentation on security and subprocessors. Where that is genuinely insufficient, you may request an audit once in any twelve-month period, on 30 days’ notice, during business hours and subject to confidentiality. A supervisory authority exercising a statutory power is not subject to those limits.

9. Where data is processed, and international transfers

Customer Personal Data is stored at rest in the European Union, in Frankfurt, Germany.

Some subprocessors process data outside the EEA and the UK, as identified in Annex III. Where we transfer data to a country without an adequacy decision, we rely on the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented by additional measures where required. For transfers subject to the UK GDPR, those clauses apply as modified by the International Data Transfer Addendum issued by the UK Information Commissioner.

Where a subprocessor is covered by an adequacy decision — including certification under the EU-US Data Privacy Framework — the transfer relies on that decision for as long as it remains valid, with the Standard Contractual Clauses as a fallback.

For the Standard Contractual Clauses: the docking clause applies; clause 9 operates under Option 2 (general written authorisation) with the notice period in section 7 above; the governing law is the law of Estonia and the forum is the courts of Estonia. Annexes I, II and III of the Clauses are populated by the Annexes to this DPA.

10. Deletion and return

During the term you can export or delete Customer Personal Data at any time through the Service.

Deleting your account triggers immediate and irreversible deletion of your profile and, by cascade, of the clients, projects, tasks, documents and portal links belonging to it. Deleted data may persist in point-in-time recovery snapshots for up to 6 hours, after which it is unrecoverable; during that window it is not accessible in the ordinary course and is not used for any purpose.

There is no exception for invoices. Statutory duties to keep accounting records apply to you, in respect of your own business, and are met in your own accounting records — not in our database. Export anything you need before deleting your account.

11. Term, liability and contact

This DPA takes effect when you accept the Terms of Service and remains in force for as long as we process Customer Personal Data on your behalf. The confidentiality, audit and deletion sections survive termination.

Each party’s liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits liability where data protection law does not permit it to be limited.

Data protection enquiries, requests for a signed counterpart, and notices under this DPA: legal@thecreatorsbase.com, or by post to Amazing Codes OÜ, Kotkapoja tn 2a-10, Kristiine District, 10615 Tallinn, Harju County, Estonia.

Annex I — What we process on your behalf

Categories of data subjects

  • Your clients — the people and companies you do business with, as recorded by you.
  • The contacts you record for them.
  • People to whom you send documents or project updates through the Service.

Categories of personal data

  • Identification and contact: name, company, email, phone, country.
  • Business relationship: projects, services, scope, deliverables, milestones, tasks, dates, status and progress.
  • Commercial documents: proposals, contracts and invoices, including values, terms and signature records.
  • Communications: the subject and body of updates you send your clients, and the record that they were sent.
  • Portal access records: that a portal link was opened, and when. Where you enable email verification, also the address an invitation or code was sent to, how many attempts were made recently, and an irreversible hash of the code — never the code itself in readable form.
  • Payment records where a client pays through the Service. Card details are never seen or stored by us — they go directly to the payment provider.

What the client portal exposes

Where you create a portal link, whoever holds it can see: the client’s name or company, the titles, descriptions and status of the projects visible to them, what each project includes and excludes, progress and dates, the updates you have already sent them, any links you have attached, and the documents you have chosen to share.

The portal pages themselves display no prices and no payment details. The list of shared documents shows only each document’s name, type, status and date — which does reveal that a proposal, contract or invoice exists, but not what it is worth.

Opening a shared document is different. Where a document has been signed, the holder can open the signed PDF, and that PDF contains its full terms and values. It is a document you have already sent that client, and opening it requires the email verification described in section 4. This is the one place where a value can reach the portal, and it does so only because you shared that document and the holder proved access to the address you recorded.

Special categories of data

None is required and none is requested. Free-text fields could contain such data if you choose to enter it; you should not. If you do, you remain the controller and are responsible for the additional obligations under Articles 9 and 10.

Nature, purpose and duration

Storing, organising, retrieving, displaying, generating documents from and transmitting the above, to provide you with a platform to manage your creative business. Processing is continuous for as long as you use the Service, and thereafter as set out in section 10.

Annex II — Technical and organisational measures

1. Encryption

  • TLS on all connections, with HSTS covering subdomains.
  • Database and object storage encrypted at rest.
  • We never store passwords: authentication is delegated to a specialist provider.

2. Access control and tenant isolation

  • Every server-side read and write resolves the user’s identity on the server and scopes every database query by it. Identity is never accepted from the browser.
  • This applies to reads as well as writes: a non-guessable identifier is not treated as authorisation.
  • Administrative access is restricted to an explicit allowlist and fails closed when unset.
  • Access to production data is limited to personnel who need it to operate the Service.

3. Application security

  • A strict Content Security Policy with per-request nonces is enforced in production.
  • Every webhook endpoint verifies its cryptographic signature and fails closed if the signing secret is absent — it never verifies against an empty secret.
  • Uploads are restricted to an allowlist of image types, with a size cap and a file extension derived from the verified content type rather than from the supplied filename.
  • Security headers in force: X-Content-Type-Options, X-Frame-Options, Referrer-Policy and a restrictive Permissions-Policy.

4. Segregation and minimisation

  • Production and preview environments are isolated, with separate databases and separate authentication.
  • The pages served to your clients receive a minimal shell: no analytics, no tag manager, no consent banner, no support widget, no authentication provider.

5. Client portal safeguards

  • Access tokens are 32 characters of high-entropy random data, generated per client.
  • Portal pages are excluded from search engine indexing.
  • Links can be revoked, replaced, or given an expiry date after which they stop working.
  • The portal is read-only as regards your business data: it exposes no endpoint that can change a project, a client, a document or an update. The single endpoint that writes anything is the one that verifies a client’s email address and issues their session, and it accepts nothing else. This is enforced by an automated check that fails our build if a data-changing operation is ever reachable from a portal page.
  • The portal pages display no monetary values. A signed document that you have shared can be opened as a PDF, and that PDF contains its own values — see Annex I.
  • It runs no analytics and no tracking of any kind. The only cookie it can set is the strictly necessary session issued when a client verifies their email: signed, restricted to the portal path, not readable by scripts, and expiring after 30 days. The only access record kept is that a link was opened, and when.
  • URLs of client-facing pages are masked before they reach any logging or monitoring system, so access tokens never appear in telemetry.

6. Resilience

Managed infrastructure with automated backups and point-in-time recovery, within the window described in section 10.

Annex III — Subprocessors

Subprocessors that process Customer Personal Data

SubprocessorPurposeProcessing location
NeonManaged PostgreSQL database — the primary storeEuropean Union (Germany)
VercelApplication hosting, edge network and file storageUnited States, with edge processing near the request
ResendSending transactional email to your clientsUnited States
StripeProcessing payments made by your clients, and payouts to youEuropean Union / United States
AnthropicGenerating draft client updates and business insights (see section 5)United States
FirmaElectronic signature of contractsEuropean Union
SentryError monitoringEuropean Union (Germany)

Not subprocessors of Customer Personal Data

These services process data about you and your own use of the Service, for which we are the independent controller. They are listed for transparency — and because none of them is loaded on the pages your clients see: Clerk (authentication), PostHog (product analytics), Intercom (support), Loops (product email), Google Tag Manager and Meta Pixel (marketing measurement on public pages), Termly (cookie consent on public pages) and Sanity (blog content).

Version 0.3 · Last updated 7 August 2026 · Amazing Codes OÜ, registry code 17376927