Data Processing Agreement
Last updated: August 14, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Anneshy Royals Inc., a California corporation doing business as OptimizePlus, 28 Geary St., Suite 650, San Francisco, CA 94108 ("Processor", "we"), and the customer identified in the applicable order ("Controller", "you"). It applies where we process personal data on your behalf.
1. Roles of the parties
You are the Controller and determine the purposes and means of processing. We are the Processor and process personal data only on your documented instructions, which for these purposes are the Terms of Service, this DPA, and your use of the service.
Where we process data for our own purposes — billing, fraud prevention, service security, and aggregate product improvement — we act as an independent controller for that limited processing.
2. Subject matter, duration, nature and purpose
Subject matter: provision of AI-assisted marketing content production, website audits, and related services.
Duration: for the term of the Terms of Service, subject to §9 below, which you should read carefully because it does not follow the usual pattern.
Nature and purpose: storing, transmitting to subprocessors, analysing and generating content from the material you supply, in order to produce the deliverables you request.
3. Categories of data subjects
Your personnel and account users; individuals appearing in photographs, video or audio you upload; and individuals whose details appear in material you supply to us.
We do not require, and ask you not to upload, special-category data (health, biometric, racial or ethnic origin, religious belief, sexual orientation), payment card numbers, government identifiers, or data relating to children. If your business is such that uploaded imagery could constitute health-adjacent data — for example before-and-after treatment photographs — tell us before uploading so we can agree how it is handled.[REVIEW: whether a medspa/aesthetics client's before-and-after imagery is health data in your view]
4. Categories of personal data
Contact and account data (name, business name, email address, telephone number, hashed password); business profile and brand information; files you upload (photographs, video, audio, documents); content generated for you; usage and metering records; and billing records.
We do not store payment card details. Card payments are processed by Stripe on Stripe-hosted pages, and card numbers never reach our systems.
5. Subprocessors
You give general written authorisation for us to engage subprocessors. Our current subprocessors — including the AI providers that generate your deliverables, our object storage provider, and our payment and email providers — are listed and kept current at optimizeplus.agency/legal/subprocessors.
We remain responsible for our subprocessors' performance of their obligations. We will make reasonable efforts to notify you in advance of a new subprocessor and to give you a reasonable opportunity to object.[REVIEW: a fixed advance-notice period (30 days is the market norm) — we currently operate an opt-in notification list, not a committed notice window]
We have not independently verified that a data processing agreement is in place with every subprocessor listed. Where one is required for your compliance posture, raise it with us before signing.[REVIEW: whether counsel requires vendor DPAs to be confirmed before this document is offered to any customer]
6. International transfers
Files you upload — photographs, audio, generated media, and PDF reports — are stored with our object storage provider in Nuremberg, Germany. Our application database and servers are operated from our hosting provider's infrastructure, and several of the AI providers that process your content are established in the United States.
Processing your content therefore involves transfers between the European Union and the United States. We describe this factually so you can assess it. We make no adequacy determination and offer no standard contractual clauses at this time.[REVIEW: whether SCCs or a UK/EU transfer addendum are required before offering this DPA to any customer with EU or UK data subjects — this is the single largest open item in this document]
7. Security measures
These are the measures we actually operate. We have deliberately not listed controls we do not have.
- Encryption in transit (TLS) for all traffic to our public endpoints.
- Passwords hashed with argon2. API keys stored only as a SHA-256 hash and shown once at creation.
- Session cookies set httpOnly, secure and sameSite, with a fixed expiry, revocable, and all sessions invalidated on password reset.
- AES-256-GCM encryption of stored third-party social credentials. This is the only application-layer encryption at rest we operate; other data, including uploaded files, is not separately encrypted at the application layer.
- Tenant isolation enforced in middleware: a caller-supplied account identifier is overwritten with the authenticated principal's own and mismatches are rejected, so services never act on an account the caller does not own.
- Rate limiting on authentication and signup endpoints. Internal services are not exposed publicly.
- No staff impersonation capability. Staff access to a customer account is read-only for viewing and separately logged for actions.
We do not currently offer multi-factor authentication, and we hold no SOC 2, ISO 27001 or equivalent certification.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and provide the information reasonably available to us to assist your own notification obligations.
We do not currently commit to a fixed notification deadline, because we do not yet operate a documented incident response process and we will not promise a timeline we cannot demonstrate.[REVIEW: whether a 72-hour commitment is required for your customers, and whether an incident response plan must exist before this DPA is offered]
9. Deletion and return — read this clause carefully
This clause does not follow the usual pattern, and we would rather tell you than have you assume otherwise. We do not operate automatic deletion of your business data or the work we produce for you. That content is retained indefinitely unless you ask us to remove it.
We do run a daily sweep that removes expired login sessions, spent password-reset and email-verification tokens, and internal operational logs older than 90 days. That sweep touches no customer content, no account record and no financial record.
On written request to legal@optimizeplus.agency we will delete or return personal data we process on your behalf. Account deletion and data export are now real, implemented operations rather than manual database work, and a deletion is recorded in an audit log that outlives the account.
The following are retained after any such request, and you should factor this in:
- Billing and payment records, including invoices and the record of what was charged, which we retain for tax and accounting purposes.
- Internal cost and usage metering records. These are retained with the account identifier removed, and are kept because they are our own cost history rather than your personal data.
- Records we are required to keep by law.
[REVIEW: a defined retention schedule and a deletion SLA. Offering a deletion commitment with no tooling and no named owner behind it is itself a risk — this clause should not be relied on at scale until an enforced mechanism exists]
10. Assistance and data subject rights
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to data subject requests to access, correct, delete or port personal data we hold on your behalf, and to meet your obligations regarding security, breach notification and impact assessments.
If a data subject contacts us directly about data we process for you, we will refer them to you rather than respond substantively, unless you instruct otherwise.
Assistance is provided manually. We do not currently offer a self-service export or deletion tool to customers.
11. Confidentiality
We ensure that personnel authorised to process personal data are bound by an appropriate duty of confidentiality, and we limit access to those who need it to deliver the service or support your account.
12. Audit
On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, we will make available information reasonably necessary to demonstrate compliance with this DPA and respond to reasonable written security questionnaires.
[REVIEW: whether on-site or third-party audit rights should be granted, and who bears the cost]
13. AI processing of your content
Producing your deliverables necessarily involves transmitting the material you supply — including any personal data within it — to the AI providers listed in our subprocessor list. That transmission is the service, not an incidental feature of it.
We make no representation about whether any given AI provider uses submitted content to train its models. That is determined by each provider's own terms and must be verified provider-by-provider.[REVIEW: whether to commit to using only providers offering a no-training-on-customer-data guarantee, and to verify this for each subprocessor]
Deliverables are AI-generated. See our AI Content Disclosure for what that means for ownership and copyright.
14. Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA is governed by the laws of the State of California, without regard to its conflict of laws rules.
[REVIEW: whether California law is appropriate where a customer has EU or UK data subjects, and whether a separate governing-law provision is needed for those engagements]
15. Order of precedence
In the event of a conflict between this DPA and the Terms of Service in relation to the processing of personal data, this DPA prevails.
Requesting a signed copy
To request an executable copy of this agreement, email legal@optimizeplus.agency. Note that the items marked for review above are unresolved, and this document should not be executed until they are.