Addendum

Data Processing Addendum

Processor terms for personal data processed by TrueFans CONNECT™ on behalf of Creators and enterprise customers, consistent with GDPR Article 28 and analogous laws.

Effective: June 10, 2026
Last updated: June 10, 2026

This Data Processing Addendum ("DPA") supplements the Master Terms of Service, the Creator Agreement, and our Privacy Policy. It applies when Lightwork Digital LLC ("Processor," "we," "us") processes personal data on behalf of a Creator, Developer, or enterprise customer ("Controller," "you") in connection with the Service.

When this applies

If you collect Fan or visitor personal data through TrueFans CONNECT™ (for example via CRM, RSVP, Pixel, or checkout) and determine the purposes and means of that processing, you are generally the Controller and we act as your Processor for data we handle on your behalf.

1.Scope & Roles

  • This DPA applies to personal data processed by Processor solely to provide the Service under your instructions, as described in the applicable agreement and Privacy Policy.
  • Processor will process personal data only on documented instructions from Controller, including with regard to transfers to third countries, unless required by applicable law (in which case Processor will inform Controller unless prohibited).
  • Controller is responsible for establishing a lawful basis for processing (such as consent or contract), providing required notices to data subjects, and responding to data-subject requests where Controller is the primary obligor.

2.Processing Instructions

Controller's instructions are the Service features Controller enables (CRM sends, RSVP capture, ticketing, Pixel events, API integrations, and similar) and documented settings in Controller's dashboard. Controller will not instruct Processor to process personal data in violation of applicable law.

3.Security Measures

Processor implements appropriate technical and organizational measures to protect personal data, including access controls, encryption in transit, logging, employee confidentiality obligations, and vendor security review for subprocessors. Details are described in our Privacy Policy and security documentation available on request at [email protected].

4.Subprocessors

Controller authorizes Processor to engage subprocessors that support the Service, including without limitation Everyware, Manifest Financial, GoHighLevel, cloud hosting providers, email/SMS delivery vendors, and analytics tools. Processor will impose data-protection obligations on subprocessors substantially similar to this DPA. Processor will provide notice of material subprocessor changes where required by law and allow Controller to object on reasonable grounds relating to data protection.

5.International Transfers

Personal data may be processed in the United States and other countries where Processor or its subprocessors operate. Where GDPR or UK GDPR requires appropriate safeguards for transfers, Processor relies on applicable mechanisms such as Standard Contractual Clauses (SCCs) and supplementary measures as described in our Privacy Policy. Controller may request copies of applicable transfer mechanisms by contacting [email protected].

6.Data Subject Rights

Processor will assist Controller, taking into account the nature of processing, in fulfilling data-subject requests to access, correct, delete, restrict, port, or object to processing, and to withdraw consent where applicable (including GDPR Articles 15–22 and CCPA/CPRA rights). Controller should route requests through in-product tools or [email protected]. Processor may direct individuals to Controller when Controller is better positioned to respond.

7.Security Incidents

Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Controller's data and will provide information reasonably available to assist Controller in meeting breach-notification obligations under GDPR Article 33 and analogous laws.

8.Deletion & Return

Upon termination of the Service for a Controller account, Processor will delete or return personal data processed on Controller's behalf within a reasonable period, except where retention is required by law, for dispute resolution, fraud prevention, or backup cycles with defined purge schedules.

9.Audit & Cooperation

Processor will make available information necessary to demonstrate compliance with this DPA and allow audits conducted by Controller or a mutually agreed third-party auditor, subject to confidentiality, reasonable notice, frequency limits, and scope limited to Processor's processing on Controller's behalf. Processor may satisfy audit requests with current third-party certifications or reports where appropriate.

10.Liability

Each party's liability under this DPA is subject to the limitation of liability and dispute-resolution provisions in the Master Terms, except where prohibited by applicable data- protection law. Nothing in this DPA limits either party's liability for violations of applicable data-protection law to the extent such limitation is not permitted.

Questions: [email protected] (privacy) or [email protected] (legal notices).