Effective: February 06, 2026
This DPA supplements Terms for processing personal data under GDPR/CCPA.
We use Stripe, PayPal, MongoDB, Twilio, Cloudinary. We'll notify of changes; you can object within 10 days.
We assist with access/deletion requests within 30 days. Data subjects can exercise rights via jfeliciano@scottapplications.com.
Data encrypted (CSFLE in MongoDB); breaches notified within 72 hrs.
Services are provided in the United States. We do not operate an EU Standard Contractual Clauses program.
We do not currently issue SOC 2 reports. Written audit requests are considered case by case.
By using services, you agree. Contact for signed copy.