Data Processing Agreement
Version 1.0 — effective August 23, 2026. All humanizes policies.
Applies to: Business and enterprise customers who submit personal data about other people to the Service
In plain language
- This DPA forms part of the Terms when a business customer asks us to process personal data on its behalf.
- The customer decides what free-text content to submit and acts as controller or business; we act as processor or service provider for that content.
- We use the listed subprocessors, apply the security measures in Annex II, and remain responsible for their performance of processing obligations.
- We assist with rights requests, impact assessments and breaches, but the customer remains responsible for its instructions and legal basis.
- The EU Standard Contractual Clauses, UK Addendum and Swiss adaptations apply when needed for a restricted international transfer.
Contents
- 1. Agreement, scope and priority
- 2. Definitions
- 3. Roles and compliance responsibility
- 4. Details of processing
- 5. Documented instructions and US service-provider restrictions
- 6. Confidentiality and security
- 7. Subprocessors
- 8. Data-subject rights, assessments and regulatory assistance
- 9. Personal Data Breach
- 10. International transfers
- 11. Return, deletion and retention
- 12. Information, audits, liability and general terms
- 13. Annex I — Parties and details of processing
- 14. Annex II — Technical and organisational measures
- 15. Annex III — Approved subprocessors
1. Agreement, scope and priority
This Data Processing Agreement (the DPA) is between the customer identified in the account, order or signed counterpart (Customer) and humanizes, the operator of humanizes.com (humanizes, we, us, our). It forms part of the Terms of Service when Customer uses the Service to submit or otherwise make available personal data about another person for processing on Customer’s behalf.
The DPA takes effect when Customer accepts the Terms, places an order that refers to it, or signs a counterpart, and continues while we process Customer Personal Data. If this DPA conflicts with the Terms, this DPA prevails only on the subject of processing Customer Personal Data. A signed order or counterpart prevails over this DPA only where it identifies the clause being changed and is signed by both parties.
Customer may request a signed counterpart by emailing jakemorris@humanizes.com. The request should identify Customer’s legal name, registered address, contact person, relevant account and the transfer mechanism, if any, to be completed. Electronic signatures and counterparts are permitted.
2. Definitions
- Applicable Data Protection Law
- All data-protection and privacy law that applies to the relevant processing, including the EU General Data Protection Regulation 2016/679 (EU GDPR), the EU GDPR as incorporated into UK law (UK GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and applicable comprehensive US state privacy laws.
- Controller, processor, personal data, processing, data subject and supervisory authority
- Have the meanings given in the EU GDPR or UK GDPR, as applicable. Their cognate terms under another Applicable Data Protection Law are interpreted consistently with their closest equivalent.
- Business, consumer, personal information, sell, share and service provider
- Have the meanings given in the CCPA/CPRA. For other US state laws, controller, consumer, personal data, processor, sale and targeted advertising have their statutory meanings.
- Customer Personal Data
- Personal data contained in content, writing samples, style profiles, prompts or messages that Customer or its authorised users submit to the Service and that we process on Customer’s behalf. It excludes data for which we act as an independent controller under section 3.
- Personal Data Breach
- A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed.
- Subprocessor
- A third party engaged by us to process Customer Personal Data on Customer’s behalf.
- Restricted Transfer
- A transfer of Customer Personal Data that requires a transfer mechanism under the EU GDPR, UK GDPR or Swiss Federal Act on Data Protection.
3. Roles and compliance responsibility
For Customer Personal Data, Customer is the controller and we are its processor. Where the CCPA/CPRA applies, Customer is the business and we are its service provider and contractor. If Customer itself acts as a processor, we act as its subprocessor and Customer confirms that its controller has authorised the instructions and subprocessing in this DPA.
Customer determines whether and what personal data to submit. Customer is responsible for the lawfulness, fairness and transparency of that collection and disclosure; its notices and legal basis; the accuracy and minimisation of the data; responding to data subjects; and ensuring its instructions comply with Applicable Data Protection Law. The Service is not designed for the regulated sensitive data prohibited by the Terms of Service.
We are an independent controller, not Customer’s processor, for personal data we determine how and why to use for our own account administration, billing, payment records, service security, audit, fraud and abuse prevention, legal compliance and direct communications with Customer. The Privacy Policy explains that separate processing.
4. Details of processing
| Element | Details |
|---|---|
| Subject matter | Providing AI-assisted rewriting, drafting, style matching, scoring, history, conversation and related support functions selected by Customer. |
| Duration | For the term of Customer’s use and then for the deletion periods in section 11, unless law requires a longer period. |
| Nature and purpose | Receiving, hosting, organising, transmitting to approved subprocessors, generating, rewriting, analysing, scoring, displaying, returning, retaining and deleting content in order to provide, secure and support the Service on Customer’s instructions. |
| Personal-data types | Identity and contact details; employment, education or professional details; identifiers; correspondence; opinions; and any other personal data Customer chooses to place in submitted free text, writing samples, style profiles, prompts or conversations. The content is free text and its contents are chosen and controlled by Customer. |
| Data-subject categories | Customer’s authorised users, personnel, clients, suppliers, students, authors, correspondents and any other person whom Customer chooses to identify or describe in submitted content. |
| Frequency | On demand when an authorised user submits, stores, retrieves, scores, exports or deletes content, with continuous hosting during the applicable retention period. |
Customer must not infer from the Service accepting free text that a particular category of personal data is appropriate to submit. Customer will use reasonable means to remove unnecessary identifiers and will not submit special-category, highly sensitive or regulated data unless the parties first agree suitable written safeguards and the Service is lawfully capable of processing it.
5. Documented instructions and US service-provider restrictions
We will process Customer Personal Data only on Customer’s documented instructions, including instructions about international transfers, unless applicable law requires otherwise. The Terms, this DPA, Customer’s configured use of the Service, support requests and lawful written directions are documented instructions. If law requires processing outside those instructions, we will tell Customer before processing unless that law prohibits notice on important grounds of public interest.
We will promptly inform Customer if, in our opinion, an instruction infringes Applicable Data Protection Law. We may suspend the affected processing while the parties clarify or correct it; this does not transfer Customer’s responsibility for the instruction to us.
CCPA/CPRA certification
We certify that, for Customer Personal Information, we understand and will comply with the restrictions applicable to a service provider and contractor. We will not sell or share Customer Personal Information; retain, use or disclose it outside the direct business relationship with Customer; retain, use or disclose it for a purpose other than the business purposes specified in this DPA and the Terms; or combine it with personal information received from another person or collected from our own interaction with a consumer, except as the CCPA/CPRA permits.
Customer may take reasonable and appropriate steps to help ensure that we use Customer Personal Information consistently with these obligations and may, on notice, require us to stop and remediate unauthorised use. We will notify Customer if we determine we can no longer meet these obligations.
6. Confidentiality and security
We ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality, receive access only where needed for their work, and process the data only as instructed.
Taking account of the state of the art, implementation cost, and the nature, scope, context and purposes of processing as well as the risks to people, we maintain the technical and organisational measures in Annex II. We may update those measures to reflect technical and operational developments, but will not materially degrade the overall security of the Service during the term.
7. Subprocessors
Customer gives general written authorisation for us to use the subprocessors in Annex III and the current Subprocessor list. We impose written data-protection obligations that provide at least the protection required of us by this DPA, to the extent applicable to the service each subprocessor performs. We remain liable to Customer for a subprocessor’s performance of those obligations.
We will give at least 30 days’ notice before authorising a new subprocessor that will process Customer Personal Data, normally by updating the published list and notifying the account contact. Customer may object during that period on reasonable, documented data-protection grounds specific to the proposed processing.
The parties will work in good faith on a commercially reasonable alternative. If we cannot resolve a valid objection, we may choose not to appoint the subprocessor or Customer may terminate the affected part of the Service before the appointment takes effect. Where the affected part cannot reasonably be separated, Customer may terminate the relevant order. This is Customer’s sole remedy for an unresolved subprocessor objection, without affecting rights the law does not permit this DPA to limit.
8. Data-subject rights, assessments and regulatory assistance
Taking account of the nature of processing, we will provide reasonable technical and organisational assistance for Customer to respond to requests to access, copy, correct, delete, restrict, port or object to processing of Customer Personal Data. Customer controls requests from its own users and other data subjects and remains responsible for identifying the applicable right, verifying the requester and giving us a lawful instruction.
If a request concerning Customer Personal Data reaches us directly, we will not respond on Customer’s behalf unless authorised or legally required. Where we can identify Customer, we will redirect the requester to Customer and notify Customer. Our public privacy request form remains available for requests concerning processing for which we are controller; verified requests are answered within 30 days and appeals within 45 days.
On request, we will provide information reasonably available to us to assist Customer with data-protection impact assessments and prior consultation with a supervisory authority, taking account of the processing and information already available to Customer. Assistance requiring substantial custom work may be charged at a reasonable rate agreed in advance, except to the extent the work is needed because we breached this DPA.
9. Personal Data Breach
We will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification is not an admission of fault or liability. Where information is not available at once, we may provide it in phases without undue further delay.
So far as known, the notice will describe:
- the nature of the breach, including the categories and approximate number of affected data subjects and records;
- the likely consequences;
- the measures taken or proposed to contain, investigate, remediate and mitigate it;
- the date or period in which it occurred and when we detected it; and
- a contact point from whom Customer can obtain further information.
We will take reasonable steps to contain and remediate the breach, preserve relevant evidence and co-operate with Customer’s lawful notification duties. Customer is responsible for deciding whether and how to notify affected people or authorities. Where the EU GDPR requires us as controller to notify a supervisory authority, our incident process targets the applicable 72-hour period.
10. International transfers
Customer authorises the transfers necessary to provide the Service, including processing in the United States by the approved subprocessors, subject to this section. The parties will first rely on an adequacy decision or another lawful mechanism where one validly covers the transfer.
For a Restricted Transfer from the EEA not otherwise covered, the European Commission’s standard contractual clauses adopted by Decision (EU) 2021/914 (EU SCCs) are incorporated by reference. Module Two, controller to processor, applies where Customer is controller; Module Three, processor to processor, applies where Customer is processor. Clause 7 docking applies; option 2 and the 30-day notice period in section 7 apply to Clause 9; the optional language in Clause 11 does not apply; and the parties select the law and courts of an EU Member State that permits third-party beneficiary rights in the applicable order or signed counterpart. Annexes I–III of this DPA complete the corresponding SCC annexes.
For a Restricted Transfer governed by the UK GDPR, the UK Information Commissioner’s International Data Transfer Addendum to the EU Commission SCCs, as laid before Parliament and in force at the transfer date (UK Addendum), is incorporated. The information in Annexes I–III completes Tables 1–3; either party may end the Addendum as permitted by its mandatory change provisions; and the exporter selects the applicable UK option and supplies any exporter-specific details in the order or signed counterpart.
For a transfer governed by Swiss law, the EU SCCs apply with these adaptations: references to the EU GDPR include the Swiss Federal Act on Data Protection; references to Member State or EU law include Swiss law where applicable; the competent supervisory authority includes the Swiss Federal Data Protection and Information Commissioner; and data subjects in Switzerland may enforce the SCCs. The term personal data includes data protected under Swiss law.
If a transfer instrument requires information specific to Customer — including its legal identity, establishment, competent supervisory authority, chosen EU Member State law or signature — that information is supplied through Customer’s account, order or signed counterpart. If this section conflicts with a mandatory term of the EU SCCs or UK Addendum, that mandatory term prevails.
11. Return, deletion and retention
Customer can download a full data export from its account page. Customer should export data it needs before deleting the account. Account deletion is self-serve and immediate from the Security section of the account page, is irreversible, and also cancels billing.
At Customer’s choice, on termination of processing we will return Customer Personal Data through the available export and delete it, unless applicable law requires retention. If Customer ends a paid plan without deleting the account, stored data remains subject to the periods below because the account and its history may remain available; Customer may instruct deletion at any time by deleting the account.
| Record | Operational retention |
|---|---|
| Humanization history, writing samples, style profiles, conversations and messages | Deleted by the automated retention process after 180 days, or sooner when the account is deleted. |
| Account, API-key metadata, quota, plan and credit records | Life of the account; deleted with it. |
| Usage counters, daily word usage and internal API cost ledger | 400 days, unless deleted earlier with the account where applicable. |
| Queued humanize jobs and idempotency records | Jobs remain only until their lease expires; idempotency records remain about 24 hours. |
| Contact-form support messages | 365 days, or 730 days for business and sales enquiries. |
| Tamper-evident audit log | Kept indefinitely as a hash chain. After account erasure, only the minimal fact that the relevant identifier was erased, and when, remains; submitted content is not preserved in that residual record. |
The audit exception exists to preserve the integrity of the security record and evidence erasure. It does not permit us to reconstruct deleted Customer content. We will provide written confirmation of deletion on reasonable request.
12. Information, audits, liability and general terms
We will make available information reasonably necessary to demonstrate compliance with this DPA. The parties will use current documentation and written responses first. If those are insufficient, Customer may conduct one audit in any 12-month period on reasonable advance notice, during normal business hours, at Customer’s cost and without disrupting the Service. An additional audit is permitted after a material Personal Data Breach or where a supervisory authority requires it.
An audit may be performed by Customer or an independent auditor that is not our competitor and is bound by confidentiality. Access is limited to systems, records and personnel relevant to Customer Personal Data; it must not expose another customer’s data, security-sensitive information beyond what is necessary, or a third party’s confidential information. Customer will give us a copy of the final report and promptly disclose any material finding.
Each party’s liability arising from this DPA is subject to the exclusions and aggregate limitation in the Terms of Service, and claims under this DPA count toward the same aggregate cap, except to the extent Applicable Data Protection Law forbids that limitation. Nothing limits a data subject’s rights under the EU SCCs or another right that cannot lawfully be limited.
The governing law and venue are the laws of the State of Delaware, United States, without regard to its conflict-of-laws rules and the state and federal courts located in New Castle County, Delaware, United States, respectively, except where a mandatory transfer instrument or Applicable Data Protection Law requires otherwise. Customer gives formal notice by email to jakemorris@humanizes.com. The severability, assignment, waiver, survival and entire-agreement provisions of the Terms apply to this DPA.
Regional annexes
13. Annex I — Parties and details of processing
| SCC field | Data exporter | Data importer |
|---|---|---|
| Name and address | Customer’s legal name and address in its account, order or signed counterpart. | humanizes, the operator of humanizes.com. Website: https://humanizes.com. |
| Contact | Customer’s account owner or privacy contact stated in the order or signed counterpart. | jakemorris@humanizes.com |
| Activities relevant to transfer | Using the Service and submitting Customer Personal Data for the purposes described in section 4. | Providing, securing and supporting the processing described in section 4. |
| Role | Controller; or processor where Customer processes for its own controller. | Processor; or subprocessor where Customer is a processor. |
| Signature and accession | Acceptance of the Terms and this DPA, or signature of an order or counterpart. | Acceptance of the applicable order and provision of the Service by humanizes. |
| Transfer description | Data subjects, categories, nature, purpose, frequency and duration are stated in section 4; retention is stated in section 11. | The same. |
| Competent supervisory authority | Determined under Clause 13 of the EU SCCs from Customer’s establishment and the affected data subjects; Customer identifies it in the order or counterpart where needed. | As determined for the transfer under Clause 13. |
14. Annex II — Technical and organisational measures
| Control area | Measures |
|---|---|
| Identity and access | Clerk-managed authentication; every user-facing endpoint scoped to the caller’s identifier; administrative surfaces restricted by an allowlist; least-necessary personnel access. |
| Application security | Zod request validation; a JSON request-body size limit; Drizzle parameterised database queries rather than string-interpolated SQL. |
| Network and browser security | TLS terminated by the hosting layer; HTTPS only in production; Helmet security headers with Content Security Policy and HTTP Strict Transport Security in production; CORS restricted by an allowlist rather than a wildcard. |
| Abuse and availability controls | Rate limiting, per-user quotas, request limits and an optional self-managed Redis layer for queue and rate-limit coordination. |
| Credentials and secrets | API keys stored as hashes; service secrets kept out of the source repository and supplied through controlled environment configuration. |
| Data lifecycle | Automated enforcement of the retention periods in section 11; self-serve export; immediate self-serve account deletion; queued-job leases and short-lived idempotency records. |
| Logging and integrity | A tamper-evident, hash-chained audit log used to investigate security events and preserve an integrity-verifiable record. |
| Incident response | Contain the event; assess scope and impact using the audit chain; notify Customer and authorities as applicable, including the 72-hour supervisory-authority period where the EU GDPR requires it; remediate the cause; and record actions taken. |
| Vendor controls | Subprocessors limited to documented functions, subject to contractual data-protection terms, transfer safeguards where required, change notice and ongoing responsibility under section 7. |
15. Annex III — Approved subprocessors
The current Subprocessor list, including its description of locations and data received, is incorporated into this Annex III. As at the effective date, the subprocessors relevant to Customer Personal Data are:
| Subprocessor | Processing function | Location |
|---|---|---|
| Replit | Hosting, PostgreSQL database infrastructure and the AI Integrations proxy through which OpenAI is reached. | United States |
| OpenAI, through the Replit AI Integrations proxy | Receives submitted text, writing samples, style profiles and writer or chat messages to produce rewrites, drafts and detector-perplexity signals. | United States |
| StealthGPT | Receives candidate text for an optional secondary rewrite pass on paid plans. | United States |
| GPTZero | Receives submitted or generated text to return the user-facing AI-detection score. | United States |
| Clerk | Authentication and account management for Customer’s authorised users, including email address and user identifier. | As stated on the Subprocessor list |
| Resend | Transactional email delivery, including quota notices, support replies and privacy-request verification; receives recipient address and message body. | As stated on the Subprocessor list |
Stripe processes billing identifiers and card data for its payment function; we never receive or store card numbers. Processing for billing is described in the Privacy Policy and the full current provider description remains on the Subprocessor list.
Version history
- v1.0 — August 23, 2026: First version establishing controller-to-processor terms, US service-provider restrictions, security and assistance commitments, international-transfer safeguards, retention rules and processing annexes.