BookAuth

Legal Document

Data Processing Addendum

Effective Date: June 15, 2026 · Version 1.0

1. Purpose & Scope

This Data Processing Addendum ("DPA") sets out the terms under which BookAuth ("BookAuth," "we," "us") acts as a processor (or sub-processor) of personal data that you, as an author, professional, or account holder ("you," "Controller"), control and process through our Service — for example, your newsletter subscriber list, buyer shipping addresses, and client communications.

This DPA supplements and is incorporated into the Terms of Service, the Newsletter & Sending Terms, and the Seller Agreement. Capitalized terms have the meanings given in the GDPR and the Terms of Service unless defined here. This DPA reflects the requirements of Article 28 GDPR and comparable processor obligations.

2. Roles & Subject Matter

  • Roles: you are the Controller; BookAuth is the Processor. Where BookAuth engages third parties to help process the data, they are Sub-Processors.
  • Subject matter & duration: the processing is limited to providing the Service features you use, for the duration of your use and the applicable retention period in our Privacy Policy.
  • Nature & purpose: storing, sending to, and analyzing your subscribers and buyers as needed to operate the features you select (newsletters, order fulfillment, client messaging).
  • Data types: contact details (name, email), subscription and engagement data, and (for buyers) shipping address and order information.
  • Data subjects: your subscribers, buyers, and clients.

3. BookAuth's Obligations as Processor

  • Process Personal Data only on your documented instructions, including with regard to transfers, unless required by law (in which case we inform you unless prohibited).
  • Ensure persons authorized to process Personal Data are subject to confidentiality.
  • Implement appropriate technical and organizational security measures (see Section 5).
  • Assist you, so far as possible, in responding to data-subject requests and in your obligations regarding security, breach notification, and data-protection impact assessments.
  • Delete or return Personal Data at the end of the services (subject to legal retention obligations), upon your request.
  • Make available information necessary to demonstrate compliance and contribute to audits and inspections as described below.

4. Sub-Processors

We engage Sub-Processors to provide infrastructure and services. A current list of categories and representative Sub-Processors is in our Privacy Policy (Section 4.3). We enter into written agreements with Sub-Processors imposing data-protection obligations substantially equivalent to this DPA. We will give you notice of new or replacement Sub-Processors where practicable, and you may object on reasonable data-protection grounds, in which case you may stop using the affected feature.

5. Security Measures

We maintain measures appropriate to the risk, including: encryption in transit and at rest; access controls and least-privilege access; encryption of buyer shipping addresses; network segmentation; logging and monitoring; regular assessments; and incident-response procedures. Detailed security documentation is available to Controllers with a legitimate need upon reasonable request to [email protected].

6. Personal Data Breach

We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, describing (to the extent known) the nature, categories and approximate number of data subjects and records, likely consequences, and measures taken or proposed. This supports your GDPR obligation to notify the supervisory authority within 72 hours where required.

7. International Transfers

Where Personal Data is transferred from the EEA, UK, or Switzerland to a country lacking an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or the UK equivalent), which are deemed incorporated into this DPA by reference for such transfers, together with any supplementary measures identified in a transfer-impact assessment.

8. Your Obligations as Controller

  • You warrant you have a lawful basis and valid consent for processing you instruct.
  • You must inform your data subjects and respond to their rights requests.
  • You are responsible for the accuracy, lawfulness, and quality of data you provide.
  • You must comply with anti-spam laws for any sending (see Sending Terms).
  • You must not instruct us to process data in a way that violates applicable law.

9. Audits & Deletion

You may audit our compliance with this DPA to the extent required by Article 28(3)(h) GDPR, exercised reasonably and with notice; where possible, we will satisfy audit rights by providing independent third-party audit reports (such as SOC 2). Upon termination of a feature, you may request export of your Personal Data and we will delete it, subject to legal retention obligations.

10. Contact

Privacy / DPA inquiries: [email protected]