Data Processing Addendum (DPA)

Effective September 11, 2026 · Version 2026.09 · Reviewed September 9, 2026

This DPA forms part of the agreement between Zealand Design Media (“Paperonic”) and a customer using Paperonic to process personal data. It applies to customer personal data that Paperonic processes on the customer's behalf.

1. Roles and scope

The customer is the controller or processor that determines the purpose and means of processing customer personal data. Paperonic is the processor or sub-processor. Processing covers hosting, organizing, transmitting, backing up, securing, retrieving, and deleting the data needed to provide the subscribed service.

Data subjects may include customer users, guests, invitees, attendees, vendors, and client contacts. Data may include identity and contact information, event details, RSVP and registration responses, communications, attendance records, device data, and any special category data the customer chooses to collect.

2. Customer instructions and obligations

Paperonic will process customer personal data only on documented instructions in the agreement, the customer's use and configuration of the service, and support requests, unless law requires otherwise. If we believe an instruction infringes applicable data-protection law, we will inform the customer unless prohibited.

The customer is responsible for lawful instructions, notices, consents, data accuracy, account permissions, and responding to data-subject requests as controller.

3. Confidentiality and security

People authorized to process customer personal data must be subject to confidentiality obligations. Paperonic maintains measures appropriate to the risk, including role-based access controls, hashed credentials and session tokens, encrypted transport, tenant-scoped authorization, audit logging, origin validation, rate limiting, and controlled provider credentials.

The customer must secure its own credentials, assign least-privilege roles, maintain accurate recipients, and promptly report suspected compromise.

4. Sub-processors

The customer gives general authorization for Paperonic to engage sub-processors necessary to provide the service. Depending on enabled features, these may include infrastructure and S3-compatible storage providers, Stripe for payments, Resend for email, Twilio for messaging, and configured analytics or error-monitoring providers.

Paperonic will require sub-processors to protect customer personal data on terms consistent with this DPA and remains responsible for their performance to the extent required by law. We will publish material changes through the policy version on this page or another reasonable customer notice channel.

5. International transfers

If processing involves an international transfer that requires safeguards, the parties will use an applicable lawful mechanism, including approved contractual clauses where available. Paperonic will provide information reasonably needed for the customer's transfer assessment.

6. Requests, assessments, and audits

Taking into account the nature of processing, Paperonic will provide reasonable assistance with data-subject requests, security and breach obligations, data-protection impact assessments, and regulator consultations. If Paperonic receives a request concerning customer data, it will direct the requester to the customer unless legally required to respond.

On reasonable written request, Paperonic will provide information needed to demonstrate compliance with this DPA. Any audit must protect other customers, confidential information, and service security, and avoid unreasonable disruption.

7. Personal-data breaches

Paperonic will notify the customer without undue delay after becoming aware of a breach of customer personal data and will provide available information reasonably needed for the customer's response. Notification is not an admission of fault.

8. Return and deletion

During the service term, the customer may use available exports. On termination or a valid deletion instruction, Paperonic will delete or anonymize customer personal data unless law requires retention. Limited pseudonymous billing, security, suppression, and audit records may be retained for legal compliance and system integrity, as described in the Privacy Policy.

9. Agreement terms

The agreement's liability, governing-law, and dispute terms apply to this DPA. If this DPA conflicts with another agreement term about processing customer personal data, this DPA controls for that conflict. Contact privacy@paperonic.com for DPA questions or an execution copy.

These policies are published by Zealand Design Media, contact@paperonic.com.

Privacy requests: privacy@paperonic.com. General support: support@paperonic.com.