← Home

Data Processing Agreement: HelpCCMS (Annex 1 to the Terms of Service)

Last updated: 3 August 2026.

This Data Processing Agreement (the "Agreement") is an integral part of the HelpCCMS Terms of Service and applies to the extent we process third-party personal data on your behalf.

1. Roles

For your own account, billing and usage data, HelpCCMS is itself the controller; the privacy policy applies to that data, not this Agreement.

2. Subject matter and duration

We process third-party personal data appearing in your content solely to provide the service (storage, AI structuring, editing, publication). This Agreement runs for as long as you use HelpCCMS and ends with your account.

3. Nature, purpose and categories

4. Our obligations as processor

5. Sub-processors

You give general authorisation for engaging sub-processors. For the processing of content personal data these are:

Sub-processorRoleData stored inTransfer basis for the US
SupabaseStorage of content + filesEU regionStandard Contractual Clauses
VercelHostingEU regionEU-US Data Privacy Framework (certified), supplemented by SCCs
AnthropicAI structuring of content (paid plans only)USStandard Contractual Clauses

On the Free plan no AI features are available, so content on a Free plan is never passed to an AI sub-processor.

The current list is on our sub-processors page at /legal/subprocessors. We impose the same obligations on each sub-processor as in this Agreement. For a new or replacement sub-processor we notify you by email, with a 30-day objection period before the change takes effect. If you raise a reasoned objection, we will seek a solution or you may terminate.

6. Transfers outside the EEA

Transfers to sub-processors outside the EEA take place on the basis stated per sub-processor in §5: the EU-US Data Privacy Framework where that sub-processor is certified with the U.S. Department of Commerce, and otherwise the Standard Contractual Clauses approved by the European Commission. Verified per sub-processor on 3 August 2026.

7. Data breaches

In the event of a personal-data breach we notify you without undue delay (as soon as reasonably possible) after becoming aware of it, with the information you need to comply with your own notification obligation. (Deliberate choice: no hard 48-hour deadline, because for a solo operation a fixed deadline is a breach-of-contract-in-waiting during absence; "without undue delay" is the sensible and customary alternative.)

8. Return and deletion

On termination we erase the content and the personal data it contains. If you delete your account yourself, this is carried out immediately and irreversibly. Invoices remain under the statutory tax retention obligation (see privacy policy §6); those contain your account/billing data, not content personal data.

9. Audit

On reasonable request we make available the information needed to demonstrate compliance with this Agreement; written information and the reports/certifications of our sub-processors suffice for this. A physical audit takes place only where legally required, at most once a year, with at least 14 days' prior notice, and at the controller's expense.

10. Liability

The liability regime from the Terms of Service applies mutatis mutandis to this Agreement.

11. Language

This Agreement is established in English; translations (including the Dutch one) are for information only. In case of any discrepancy, the English version prevails.