Data Processing Addendum
Draft processing terms for enterprise and EEA customers: what we process, which processors we use, and the safeguards around it.
Draft for review. This text is not yet signed and is not legal advice. It becomes binding only after both sides sign a copy.
Definitions
Personal Data means any information relating to an identified or identifiable person. Processing means any operation performed on Personal Data, including collection, storage, use, and deletion. The Controller decides why and how Personal Data is processed. The Processor processes Personal Data only on the Controller's instructions.
Parties
PT BCB Academy Indonesia (reachable at iwan@snipset.belajarcarabelajar.com) provides the Snipset software and website. The customer named in the applicable license or order engages PT BCB Academy Indonesia to process Personal Data as described below. The unsigned text on this page is a template for review.
Scope and purpose of processing
Processing covers the operational records listed in our Privacy and Data Trust policy: license records, support tickets, QA reports, blog analytics, opt-in crash reports, and community forum profiles. The purpose is limited to delivering, supporting, and improving the licensed product. Snippet content, clipboard history, and on-device AI data never leave the customer's devices and are outside this addendum.
Subprocessors
The processors we rely on are listed on our public subprocessors page, with what each receives and the safeguard behind the transfer. We will notify customers of any new subprocessor before it handles Personal Data.
Security measures
We protect Personal Data with encrypted transport to our servers, access-limited admin tooling, and admin-gated data-subject endpoints. Desktop and Android content stays in on-device encrypted databases and is never uploaded.
Data-subject rights
We help customers answer access, correction, deletion, and portability requests. Individuals can write to us from the address tied to their license, ticket, or report, and we export or erase their records, including community forum data, as our policy describes.
Breach notification
If we learn of a breach affecting customer Personal Data, we will notify the affected customer without undue delay, describe what happened and what we are doing, and cooperate on any notifications the customer must make.
International transfers
Some processors operate outside the customer's country, including the United States. Such transfers rely on the safeguards named on our subprocessors page, including standard contractual clauses where the vendor terms provide them.
Audit
Once a year, the customer may ask for a written summary of the technical and organizational measures in this addendum. Deeper audits are agreed in writing and must not disrupt the service or expose other customers' data.
Return and deletion
During the relationship we keep operational records for the retention periods in our Privacy and Data Trust policy. When the relationship ends or a valid erasure request arrives, we delete or anonymize the related Personal Data, keeping the license itself working where the license requires it.
Liability
Each side's liability under this addendum follows the liability terms of the main license or order. Nothing here limits liability that applicable law does not allow to limit.
Signature
To countersign, write to iwan@snipset.belajarcarabelajar.com with the customer name, the license code, and the requested effective date. We return a signed copy and record the version above.
The current processor list lives on our subprocessors page.
To request a signed copy, write to support.