1. About this Addendum
This Data Processing Addendum (the “Addendum” or “DPA”) forms part of the Eden Platforms Subscription Terms of Service between Eden and the subscribing academy or clinic (“Client,” “you”) and applies whenever Eden processes Personal Data on Client’s behalf in providing the Eden Educate or Eden Elevate services (each a “Service,” together the “Services”). It applies automatically to every subscription — Client and Eden do not need to sign a separate copy for it to be in force.
Where this Addendum conflicts with the Terms of Service on the processing of Personal Data, this Addendum controls. Capitalised terms not defined here have the meanings given in the Terms.
2. Definitions
In this Addendum: “Personal Data” means information that identifies, relates to, or could reasonably be linked to a particular consumer or household, as defined by the California Consumer Privacy Act (as amended by the CPRA, together “CCPA”), and “personal data” as defined by the EU General Data Protection Regulation and the UK GDPR (together “GDPR”) where those laws apply. “Client Data” means Personal Data that Client submits to the Services or that Eden collects on Client’s documented instructions in providing the Services — including data about Client’s learners, patients, customers, reviewers, and website visitors. “Business,” “Service Provider,” “Sale,” “Sharing,” and “Business Purpose” have the meanings given in the CCPA. “Controller,” “Processor,” “Data Subject,” and “Personal Data Breach” have the meanings given in the GDPR. “Subprocessor” means any third party engaged by Eden to process Client Data. “Applicable Data Protection Law” means every privacy and data-protection law that applies to Eden’s processing under this Addendum.
3. Roles and applicability
For Client Data, Client is the Controller (or Business) and Eden is the Processor (or Service Provider). Eden does not sell or share Client Data and does not retain, use, or disclose it for any purpose other than the Business Purpose of providing the Services or as this Addendum otherwise permits.
For data about Client’s own owner and team accounts, billing information, security and audit logs, and product-usage analytics generated by Client’s use of the Services (together “Account Data”), Eden is an independent Controller. Eden’s processing of Account Data is governed by the Eden Educate and Eden Elevate Privacy Policies, not by this Addendum.
This Addendum applies whether or not any specific Applicable Data Protection Law applies at the time; where a law applies, its specific obligations attach to Eden’s processing of the Personal Data that law covers.
4. Processing instructions
Eden processes Client Data only on Client’s documented instructions, which consist of: the Terms of Service; this Addendum; the configuration options Client selects in the Services; Client’s use of the Services (including through the dashboard, the public Client site, and the Services’ APIs); and any other instructions Client gives in writing that both parties agree to. Eden will inform Client if, in Eden’s opinion, an instruction infringes Applicable Data Protection Law.
5. Service Provider commitments (CCPA)
Eden certifies that, with respect to Client Data:
- Eden will not sell or share Client Data;
- Eden will not retain, use, or disclose Client Data for any purpose other than the specific Business Purpose of providing the Services, including retaining, using, or disclosing it for a commercial purpose other than that Business Purpose, unless expressly permitted by the CCPA;
- Eden will not retain, use, or disclose Client Data outside the direct business relationship between Eden and Client;
- Eden will not combine Client Data with personal information Eden receives from or on behalf of another person, or collects from Eden’s own interaction with a consumer, except as permitted for a Service Provider by the CCPA;
- Eden will comply with the applicable obligations under the CCPA and provide the same level of privacy protection as required of Businesses; and
- Eden will notify Client if it can no longer meet its obligations under the CCPA, and Client may take reasonable and appropriate steps to stop and remediate any unauthorized use of Client Data.
Client grants Eden the right to take those actions with Client Data that are reasonably necessary and proportionate to perform the Services, to prevent, detect, and respond to security incidents, fraud, or illegal activity, to comply with applicable law, and to build or improve the quality of the Services provided that no combination or use for cross-context behavioral advertising takes place.
6. Confidentiality
Eden ensures that personnel authorized to process Client Data are subject to written confidentiality obligations of no less duration than Eden’s obligations under the Terms. Access to Client Data is limited to personnel who need it to perform their duties.
7. Security
Eden implements and maintains the technical and organisational measures described in Annex II to protect Client Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Data. Eden regularly reviews and updates those measures to reflect changes in the Services, the state of the art, and the risks presented by processing.
8. Subprocessors
Client authorizes Eden to engage the Subprocessors listed in Annex III and any Subprocessor Eden adds by the notification process below. Eden imposes on each Subprocessor data-protection obligations no less protective than those in this Addendum through a written contract, and Eden remains liable to Client for each Subprocessor’s acts and omissions in performing under that contract to the same extent Eden would be liable if it performed the services itself.
Eden will give Client at least thirty (30) days’ prior notice of any addition or replacement of a Subprocessor by updating the list at Annex III and, if Client has provided an administrative contact address for this purpose, by e-mail to that address. Client may object on reasonable data-protection grounds by written notice within that period; the parties will work in good faith to resolve the objection, and if not resolved, Client may terminate the affected Service on written notice with a pro-rated refund of prepaid fees for the terminated portion.
9. Assistance with Data Subject requests and other obligations
Taking into account the nature of the processing, Eden will use appropriate technical and organisational measures to assist Client, insofar as this is possible, in fulfilling Client’s obligations to respond to Data Subject requests to exercise rights of access, correction, deletion, portability, restriction, and objection. The Services include self-service tools for the common cases (owner account and student profile management, review moderation, and data export). Where Eden receives a request directly from a Data Subject about Client Data, Eden will not respond except to acknowledge receipt and forward the request to Client without undue delay.
To the extent required by Applicable Data Protection Law and taking into account the information available to Eden, Eden will provide reasonable assistance to Client with data protection impact assessments and prior consultations with supervisory authorities relating to Eden’s processing of Client Data.
10. Personal Data Breach notification
Eden will notify Client without undue delay, and in any event within seventy-two (72) hours after Eden confirms a Personal Data Breach affecting Client Data. The notice will contain the information reasonably available to Eden at the time, including: the nature of the breach, the categories and approximate number of Data Subjects and records concerned to the extent known, the likely consequences of the breach, the measures Eden has taken or proposes to take to address it, and Eden’s contact for further information. Eden will update the notice as the investigation proceeds. Eden’s notice does not constitute an admission of fault or liability.
Client is responsible for its own notifications to Data Subjects and to supervisory authorities; Eden will provide reasonable cooperation and information Client requires to make those notifications.
11. Deletion and return of Client Data
On termination or expiry of a subscription, or on written request by Client, Eden will delete or return Client Data within thirty (30) days, except for: copies retained in Eden’s routine backups, which are purged according to Eden’s published retention schedule (currently seven days for database backups, ninety days for off-site storage snapshots); and Client Data Eden is required by law to retain. Copies retained under those exceptions remain subject to this Addendum until deleted.
12. Audit
Once per calendar year on at least thirty (30) days’ prior written notice, and additionally following a Personal Data Breach affecting Client Data, Eden will make available to Client the information reasonably necessary to demonstrate compliance with this Addendum. Eden may satisfy this obligation by providing summaries of independent third-party security assessments and current attestations. On-site audits are limited to circumstances where Applicable Data Protection Law requires them; each on-site audit is subject to reasonable confidentiality and security requirements, is limited to information relevant to Client Data, and takes place at Client’s cost.
13. International transfers
Eden processes Client Data in the United States: application hosting on Amazon Web Services in the us-east-2 (Ohio) region, and database, authentication and object storage on Supabase in the us-west-1 (Northern California) region. Where Applicable Data Protection Law requires an additional lawful transfer mechanism for a transfer of Client Data from outside the United States to Eden, the parties will use the mechanism specified in that law — including, where the GDPR applies, the European Commission’s Standard Contractual Clauses (Module 2 or Module 3 as applicable) and, where the UK GDPR applies, the UK International Data Transfer Addendum — which are incorporated into this Addendum by reference with Annexes I, II, and III of this Addendum populating the corresponding annexes.
14. Health information
The Services are not designed to receive Protected Health Information as defined by HIPAA. Eden Elevate directs bookings to Client’s external booking provider and, when Client enables the callback form, collects only name, e-mail address, and optional phone number with instructions to the visitor not to include medical details. Client agrees not to submit Protected Health Information to the Services, and Eden does not offer and is not a party to any Business Associate Agreement. If Client requires the Services to process Protected Health Information, Client must not enable that use until the parties enter into a separate Business Associate Agreement.
15. Liability
Each party’s liability arising out of or related to this Addendum is subject to the limitations and exclusions of liability set out in the Terms of Service. For the avoidance of doubt, all amounts payable under the Terms and this Addendum count toward the same aggregate cap.
16. Term, survival, and governing law
This Addendum takes effect on the effective date shown above (or, for a later-arising Subscription, on the start of that Subscription) and continues while Eden processes Client Data. Sections that by their nature should survive termination — including confidentiality, the CCPA commitments, breach notification for events discovered after termination, deletion, and liability — survive. Eden may update this Addendum from time to time; a material change takes effect thirty (30) days after Eden posts the updated Addendum at edenplatforms.io/dpa and notifies Client through the Services, subject to Client’s right to terminate the affected Subscription on written notice within that period. This Addendum is governed by the laws of the State of Arizona (subject to any mandatory Applicable Data Protection Law).
Annex I — Description of processing
Annex II — Technical and organisational measures
Eden maintains the following measures. Eden may update this Annex from time to time to reflect changes in the Services and the state of the art, provided the overall level of protection is not reduced.
- Access control. Multi-factor authentication is available to every owner and admin account and is recommended; where an account has enrolled, the platform enforces the second factor at the API level on every session. Authentication events are logged; server-issued session cookies use SameSite=Lax with HttpOnly and Secure flags.
- Tenant isolation. Row-level security is enabled on every application table; every browser-reachable table is either protected by a policy that isolates by tenant, or has no grant to the anonymous or authenticated roles. Two-tenant isolation is enforced by row-level security policies and is verified as part of Eden’s launch controls process.
- Encryption. Client Data is transmitted over TLS 1.2 or higher, is encrypted at rest by Amazon RDS-managed AES-256 encryption in the Supabase-provisioned database, and by Amazon S3 server-side encryption in Storage.
- Least privilege. Database roles for the anonymous and authenticated web sessions have SELECT-only rights on the tables the browser needs, mediated by policies. Write operations go through server-only routes authenticated by the service role, and the service role is never exposed to the browser.
- Application security. Content Security Policy, HTTP Strict Transport Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are enforced on all Eden origins. Uploaded images are validated by their magic bytes and stored only in raster formats. Structured data is serialised through an escape routine that prevents script-tag breakout. Public rate limits use the CloudFront viewer address, not client-supplied forwarded-for headers.
- Change management. Source code and infrastructure configuration are versioned in Git. Continuous-integration tests run on every change, including automated regression tests for the specific defects identified in Eden’s security audits.
- Backups. Daily encrypted database backups are retained for seven (7) days. Storage objects (uploaded media) are copied weekly to encrypted off-site storage and retained for ninety (90) days. Eden’s operational runbook includes a documented restore procedure exercised at least once every twelve (12) months.
- Incident response. Eden maintains an incident-response plan describing containment, evidence preservation, notification obligations, and lessons-learned steps. Eden will conduct tabletop exercises against that plan at least twice per year beginning in its first year of operation.
- Vulnerability management. Eden enables dependency alerts and code scanning on its source repository as the hosting plan permits; identified vulnerabilities are tracked and remediated according to severity.
- Personnel. Eden’s personnel are subject to written confidentiality obligations that survive termination of engagement.
Annex III — Authorised Subprocessors
Eden engages the following Subprocessors to process Client Data as of the effective date. The current list is always available at edenplatforms.io/dpa; changes are notified as described in Section 8.
FedEx and UPS are engaged only at Client’s direction, under Client’s own carrier account and that carrier’s terms with Client; a Client that does not connect a carrier sends it no Client Data.