Enterprise & Compliance

Data Processing Addendum (DPA)

Between Viewsmo Technologies Inc. (“Processor”) and Customer (“Controller”) · Effective Date: October 11, 2026

1. Introduction & Scope

This Data Processing Addendum (“DPA”) supplements the Viewsmo Terms of Service entered into between Viewsmo Technologies Inc. (“Viewsmo”, “Processor”) and the business entity or creator customer (“Customer”, “Controller”).

This DPA governs the processing of Personal Data in connection with Customer’s use of the Viewsmo audience intelligence, Shorts video clipping, and content autopilot platform, ensuring compliance with the European Union General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).

2. Roles and Processing Instructions

  • Controller Status: Customer is the Controller of Customer Data, determining the purposes and means of processing video footage, channel metrics, and metadata.
  • Processor Status: Viewsmo acts solely as a Data Processor, processing Customer Data strictly in accordance with Customer’s documented instructions and the Terms of Service.
  • No Sale or Sharing: Viewsmo does not sell, lease, or monetize Customer Data or use Customer video footage to train foundation public models without explicit contractual permission.

3. Authorized Sub-processors

Customer grants general written authorization for Viewsmo to engage the following third-party infrastructure and service sub-processors:

Sub-processorPurpose & ScopeLocationTransfer Safeguard
Supabase, Inc.PostgreSQL database, user authentication, and secure video storage bucketsUnited States / EUEU Standard Contractual Clauses (SCCs)
Railway Corp.Application runtime and server-side container orchestrationUnited StatesSCCs / DPA
Stripe, Inc.Payment processing, recurring subscription billing, and tax calculationsUnited States / GlobalPCI-DSS Level 1 / SCCs
OpenAI, LLCAutomated Whisper word transcription and title/hook synthesisUnited StatesBusiness DPA (Zero Training Retention)
Google LLC (YouTube API Services)Audience analytics retrieval and user-authorized scheduled publishingGlobalGoogle API Services User Data Policy

4. Technical & Organizational Security Measures

Viewsmo maintains strict security controls to protect Customer Data against unauthorized access, destruction, or disclosure:

  • Encryption in Transit: TLS 1.3 enforced across all external web, API, and worker communication.
  • Encryption at Rest: AES-256 encryption applied to all relational databases and media object storage buckets.
  • Row-Level Security (RLS): Cryptographically isolated multi-tenant database policies preventing cross-user data leakage.
  • Ephemeral Processing: Video files and intermediate clipping frames are deleted on automated lifecycle schedules.

5. Incident Notification & Audit Rights

In the event of a confirmed Personal Data Breach impacting Customer Data, Viewsmo will notify Customer without undue delay and within forty-eight (48) hours of becoming aware of the breach via the security contact on record.

Viewsmo provides annual compliance documentation and will cooperate reasonably with Customer audits upon thirty (30) days advance written request.

6. Execution & Inquiries

To execute a countersigned copy of this DPA for your enterprise account, contact:

Viewsmo Technologies Inc. · Legal & Data Protection

Email: privacy@viewsmo.com

Security: security@viewsmo.com