Legal
Data Processing Agreement
Last updated: May 2026
1. Definitions
- "Controller" means the Client, who determines the purposes and means of processing personal data.
- "Processor" means CommunityLauncher, which processes personal data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Personal Data" means any information relating to a Data Subject.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Sub-processor" means a third party engaged by CommunityLauncher to process Personal Data on behalf of the Controller.
- "Applicable Data Protection Law" means all applicable laws relating to data protection, including GDPR, CCPA, and equivalent regulations.
2. Scope and Purpose of Processing
This DPA applies to all Personal Data processed by CommunityLauncher on behalf of the Client in connection with the provision of community platform services. The categories of data processed include:
- Community Member Data: Names, email addresses, profile information, account credentials, and user-generated content
- Usage Data: Platform interaction logs, feature usage patterns, and session information
- Communication Data: Messages, forum posts, chat logs, and notification preferences
- Transaction Data: Payment information, purchase history, and subscription records (where applicable)
Processing is performed solely for the purpose of delivering the agreed-upon platform services as described in the Master Service Agreement.
3. Controller Instructions
CommunityLauncher shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country. The MSA and applicable SOWs constitute the Controller's initial instructions. Additional instructions may be provided in writing. If CommunityLauncher believes an instruction infringes Applicable Data Protection Law, it shall promptly notify the Controller.
4. Security Measures
CommunityLauncher shall implement and maintain appropriate technical and organizational measures to protect Personal Data, including:
- Encryption: TLS 1.3 for data in transit; AES-256 for data at rest
- Access Control: Role-based access with least-privilege principles; multi-factor authentication for administrative access
- Network Security: Firewalls, intrusion detection systems, and network segmentation
- Monitoring: Continuous logging, alerting, and anomaly detection
- Personnel: Background checks, confidentiality agreements, and regular security training for all staff with data access
- Physical Security: Data center access controls, surveillance, and environmental protections (managed by infrastructure providers)
- Incident Management: Documented incident response procedures with defined escalation paths
5. Sub-processors
The Controller provides general authorization for CommunityLauncher to engage Sub-processors. CommunityLauncher shall:
- Maintain an up-to-date list of Sub-processors at communitylauncher.com/subprocessors
- Notify the Controller of any intended additions or replacements at least 30 days in advance
- Ensure all Sub-processors are bound by data protection obligations no less protective than those in this DPA
- Remain fully liable for the acts and omissions of its Sub-processors
The Controller may object to a new Sub-processor within 14 days of notification. If a reasonable objection cannot be resolved, either party may terminate the affected services.
6. Data Subject Rights
CommunityLauncher shall assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection) by providing appropriate technical measures and information. CommunityLauncher shall notify the Controller without undue delay upon receiving a Data Subject request directly, and shall not respond to such requests without the Controller's authorization unless required by law.
7. Data Breach Notification
In the event of a Personal Data breach, CommunityLauncher shall:
- Notify the Controller without undue delay and in no event later than 48 hours after becoming aware of the breach
- Provide sufficient detail to enable the Controller to fulfill its own notification obligations, including: nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach
- Cooperate with the Controller's investigation and mitigation efforts
- Document all breaches, including their effects and remedial actions taken
8. Audit Rights
CommunityLauncher shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits, including inspections, no more than once per year with at least 30 days prior written notice. Audits shall be conducted during business hours and shall not unreasonably disrupt operations. CommunityLauncher may satisfy audit requests through provision of relevant third-party certifications, audit reports (SOC 2 Type II or equivalent), or penetration test results.
9. International Data Transfers
Where Personal Data is transferred outside the European Economic Area or other jurisdictions with data transfer restrictions, CommunityLauncher shall ensure adequate safeguards are in place. These may include: Standard Contractual Clauses (SCCs) as approved by the relevant authority, adequacy decisions, or other legally recognized transfer mechanisms. CommunityLauncher shall inform the Controller of the legal basis relied upon for any international transfer.
10. Data Retention and Deletion
Upon termination of the services or upon the Controller's written request:
- CommunityLauncher shall return all Personal Data to the Controller in a standard, machine-readable format within 14 days
- Upon confirmation of successful data return (or upon Controller instruction), CommunityLauncher shall permanently delete all copies of Personal Data within 60 days
- CommunityLauncher shall certify deletion in writing upon request
- Data may be retained beyond this period only where required by Applicable Data Protection Law, in which case CommunityLauncher shall inform the Controller and limit processing to the purposes required by law
11. Term
This DPA shall remain in effect for the duration of CommunityLauncher's processing of Personal Data on behalf of the Controller. The obligations contained herein survive termination to the extent necessary for the orderly cessation of processing and deletion of data.
12. Contact
For data protection inquiries related to this DPA, contact us at privacy@communitylauncher.com.
See also: Privacy Policy | Subprocessors | Master Service Agreement
