Data Processing Agreement: HelpCCMS (Annex 1 to the Terms of Service)
Last updated: 3 August 2026.
This Data Processing Agreement (the "Agreement") is an integral part of the HelpCCMS Terms of Service and applies to the extent we process third-party personal data on your behalf.
1. Roles
- Controller: you, the customer. You determine which content (and therefore which third-party personal data) you place in HelpCCMS.
- Processor: Solimedia (HelpCCMS).
For your own account, billing and usage data, HelpCCMS is itself the controller; the privacy policy applies to that data, not this Agreement.
2. Subject matter and duration
We process third-party personal data appearing in your content solely to provide the service (storage, AI structuring, editing, publication). This Agreement runs for as long as you use HelpCCMS and ends with your account.
3. Nature, purpose and categories
- Purpose: providing the HelpCCMS service.
- Types of data: whatever you place in your content: typically names, job titles, contact details or other data in work instructions and documentation.
- No special categories: you place no special categories of personal data (such as health, race, religion, biometrics) or criminal-offence data in HelpCCMS without a prior written arrangement. Without such an arrangement HelpCCMS is not designed to process them, and that responsibility rests with you.
- Data subjects: the persons you name in your content (e.g. employees).
4. Our obligations as processor
- We process the data solely on your instructions and for the purpose stated in §3, not for our own purposes, and not to train AI models.
- We bind the persons working under our authority to confidentiality.
- We take appropriate technical and organisational security measures (encryption in transit, per-user isolation via row-level security, per-workspace isolated file storage).
- We assist you, to the extent reasonable, with data-subject requests and with your own obligations regarding security, data breaches and impact assessments.
5. Sub-processors
You give general authorisation for engaging sub-processors. For the processing of content personal data these are:
| Sub-processor | Role | Data stored in | Transfer basis for the US |
|---|---|---|---|
| Supabase | Storage of content + files | EU region | Standard Contractual Clauses |
| Vercel | Hosting | EU region | EU-US Data Privacy Framework (certified), supplemented by SCCs |
| Anthropic | AI structuring of content (paid plans only) | US | Standard Contractual Clauses |
On the Free plan no AI features are available, so content on a Free plan is never passed to an AI sub-processor.
The current list is on our sub-processors page at /legal/subprocessors. We impose the same obligations on each sub-processor as in this Agreement. For a new or replacement sub-processor we notify you by email, with a 30-day objection period before the change takes effect. If you raise a reasoned objection, we will seek a solution or you may terminate.
6. Transfers outside the EEA
Transfers to sub-processors outside the EEA take place on the basis stated per sub-processor in §5: the EU-US Data Privacy Framework where that sub-processor is certified with the U.S. Department of Commerce, and otherwise the Standard Contractual Clauses approved by the European Commission. Verified per sub-processor on 3 August 2026.
7. Data breaches
In the event of a personal-data breach we notify you without undue delay (as soon as reasonably possible) after becoming aware of it, with the information you need to comply with your own notification obligation. (Deliberate choice: no hard 48-hour deadline, because for a solo operation a fixed deadline is a breach-of-contract-in-waiting during absence; "without undue delay" is the sensible and customary alternative.)
8. Return and deletion
On termination we erase the content and the personal data it contains. If you delete your account yourself, this is carried out immediately and irreversibly. Invoices remain under the statutory tax retention obligation (see privacy policy §6); those contain your account/billing data, not content personal data.
9. Audit
On reasonable request we make available the information needed to demonstrate compliance with this Agreement; written information and the reports/certifications of our sub-processors suffice for this. A physical audit takes place only where legally required, at most once a year, with at least 14 days' prior notice, and at the controller's expense.
10. Liability
The liability regime from the Terms of Service applies mutatis mutandis to this Agreement.
11. Language
This Agreement is established in English; translations (including the Dutch one) are for information only. In case of any discrepancy, the English version prevails.