Data Processing Agreement
Last updated: March 2026
1. Scope
This Data Processing Agreement ("DPA") applies to Enterprise users of Pipeline who require enhanced data processing terms beyond our standard Privacy Policy. This DPA supplements and is incorporated into our Terms of Service.
This DPA applies when Pipeline processes Personal Data on behalf of Enterprise customers in connection with the provision of our services.
2. Definitions
- "Personal Data": Any information relating to an identified or identifiable natural person, as defined under GDPR and other applicable data protection laws.
- "Processing": Any operation performed on Personal Data, including collection, storage, use, transmission, or deletion.
- "Controller": The Enterprise user who determines the purposes and means of processing Personal Data.
- "Processor": Christex Foundation (Pipeline) who processes Personal Data on behalf of the Controller.
- "Sub-processor": Third parties engaged by the Processor to process Personal Data.
- "Data Protection Laws": GDPR, CCPA, PIPEDA, and other applicable data protection regulations.
3. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure personnel processing Personal Data are subject to confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests
- Delete or return all Personal Data upon termination of the agreement
- Make available information necessary to demonstrate compliance
4. Sub-Processors
We use the following sub-processors to provide and improve our services:
Supabase
Database and authentication services. Data stored in AWS US/EU regions.
Privacy: supabase.com/privacy
Vercel
Web hosting and edge network distribution.
Privacy: vercel.com/legal/privacy-policy
Sentry
Error tracking and performance monitoring. No personal data processing.
Privacy: sentry.io/privacy
We will notify Enterprise customers of any changes to sub-processors. Enterprise customers may object to changes within 30 days.
5. Data Security
We implement appropriate technical and organizational measures to ensure security appropriate to the risk:
Encryption
Data encrypted in transit (TLS 1.3) and at rest (AES-256).
Access Controls
Role-based access control, principle of least privilege.
Network Security
Firewall protection, intrusion detection, DDoS mitigation.
Backup & Recovery
Automated backups with encrypted offsite storage.
Monitoring
24/7 security monitoring and alerting.
6. Data Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA).
For transfers outside the EEA, we ensure appropriate safeguards through:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions where available
- Binding Corporate Rules for intra-group transfers
Enterprise users may request information about specific transfer mechanisms in place.
7. Audits
Enterprise customers have the right to audit our compliance with this DPA. We provide:
- Annual SOC 2 Type II audit reports
- ISO 27001 certification
- GDPR compliance documentation
Enterprise customers may request additional audits at their own expense, with reasonable notice (minimum 30 days).
8. Data Breaches
In the event of a Personal Data breach, we shall:
- Notify the Controller without undue delay, and within 72 hours of becoming aware
- Provide details of the nature of the breach
- Describe likely consequences
- Describe measures taken to address the breach
- Cooperate with the Controller in responding to the breach
9. Termination
- Termination: Either party may terminate this DPA with 30 days written notice
- Effect: Upon termination, we will delete or return all Personal Data within 30 days
- Retention: We may retain Personal Data as required by law, with documentation
- Survival: Confidentiality and security obligations survive termination
10. Contact
For questions about this DPA or to request a custom agreement, contact us:
- Email: hello@christex.foundation
- General: hello@christex.foundation
Questions?
If you have any questions about this Data Processing Agreement, please contact us at hello@christex.foundation.