This Data Processing Addendum (“DPA”) forms part of the Agreement between DSLS PARTNERS LTD (“OnStat”) and the Customer. It applies when OnStat processes Customer Personal Data on Customer’s behalf.
1. Definitions and interpretation
“Applicable Data Protection Law” means laws applicable to the processing under the Agreement, including, where applicable, GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, and U.S. state privacy laws.
“Customer Personal Data” means personal data contained in Customer Data that OnStat processes as processor or service provider for Customer.
“Data Subject Request”, “Controller”, “Processor”, “Personal Data”, “Processing”, “Supervisory Authority”, and “Personal Data Breach” have the meanings given by Applicable Data Protection Law.
“Subprocessor” means a third party appointed by or for OnStat to process Customer Personal Data.
For California and similar U.S. laws, “Controller” includes “business”; “Processor” includes “service provider” or “contractor”; and relevant statutory terms such as “sell”, “share”, and “targeted advertising” retain their statutory meanings.
If this DPA conflicts with the Agreement on personal-data processing, this DPA controls.
2. Roles and scope
Customer is the Controller and OnStat is the Processor for Customer Personal Data described in Annex 1. If Customer is a Processor for another Controller, OnStat is Customer’s Subprocessor and Customer represents that it has authority to appoint OnStat and give all instructions.
The parties acknowledge that OnStat is an independent Controller for its own account administration, billing, tax, security, fraud prevention, support, legal compliance, and marketing purposes. Those activities are outside this DPA and are described in the Privacy Notice.
The labels in this DPA do not override the parties’ actual roles under law. If OnStat determines the purposes and essential means of a processing activity beyond Customer’s instructions, it will not treat that activity as processor processing.
3. Customer instructions and obligations
OnStat will process Customer Personal Data only:
- to provide, secure, support, and terminate the Service;
- as configured through enabled accounts, integrations, analytics modules, messaging functions, account actions, campaigns, attribution, AI features, queries, automations, API/OAuth/MCP connections, Shared Portals, exports, deletion controls, and retention settings;
- under written support, API, or Order Form instructions; and
- where Union, Member State, UK, or other applicable law requires, after informing Customer unless law prohibits notice.
Enabling, configuring, or using an account, integration, analytics module, messaging function, account action, campaign, attribution function, automation, AI feature, query, API/OAuth/MCP connection, Shared Portal, export, retention setting, or deletion control constitutes Customer’s documented instruction to process Customer Personal Data to provide that feature and, where applicable, perform the action selected by Customer. The Agreement, recorded Service configuration and user actions, API and MCP requests, OAuth grants, Order Forms, and documented support requests are Customer’s complete instructions unless the parties agree otherwise in writing.
For an approved automation, Customer's affirmative enablement and affirmative approval after a material change to the action, trigger, account scope, recipients, limits, or duration are documented instructions for later executions within that recorded configuration. A separate instruction is not required before each such execution. An immediate financial, destructive, externally visible publication, mass-message, or similarly high-impact action requires an action-specific Customer confirmation unless it is within a previously approved automation that OnStat has expressly made eligible for that execution model. These confirmations are Customer instructions and operational safeguards; they are not data-subject consent or a substitute for Customer's lawful basis, transparency, or rights obligations.
A feature instruction does not expand Customer’s authority or replace a required lawful basis, notice, consent, contract, platform permission, or data-subject choice. OnStat may present a feature-specific notice or require an additional confirmation for a materially different purpose, recipient, data category, or risk, including transfer of private messages to an external AI provider. OnStat will notify Customer if it reasonably believes an instruction infringes Applicable Data Protection Law and may pause the affected processing while the parties resolve it.
Where Customer configures an advertising, analytics, or postback integration, Customer instructs OnStat to transmit allowlisted click or conversion events server-to-server to the recipient selected and credentialed by Customer. Customer determines the recipient, event mapping, campaign, and purpose. Under the standard design, OnStat does not create an advertising identifier in the campaign visitor's browser and does not include raw creator-platform account, creator, or fan identifiers, message or media content, detailed adult-platform activity labels, complete URLs, or unfiltered query parameters in the advertising payload. OnStat may use platform click identifiers supplied in the requested URL and other minimized request and event data needed for Customer's configured delivery. For that Customer-directed processing, the Controller/Processor or Processor/Subprocessor allocation in Section 2 applies, subject to the parties' actual roles under mandatory law.
Customer is responsible for:
- the lawfulness, fairness, transparency, accuracy, and minimization of Customer Personal Data and instructions;
- providing all Controller notices required for creators, fans, subscribers, purchasers, message participants, campaign visitors, and other data subjects represented in Customer Personal Data, including notices required when Customer obtains data indirectly, and maintaining an accessible rights-contact route;
- establishing an Article 6 legal basis and, where applicable, an Article 9 condition, ePrivacy consent, or other sensitive-data authorization;
- documenting creator-account authority, platform permission, performer consent, and age assurance;
- configuring Authorized Users, retention, AI, exports, and automation appropriately;
- conducting any required DPIA, legitimate-interests assessment, consultation, or records of processing;
- ensuring each Customer-selected advertising or postback recipient and event is permitted, providing any required visitor notice, obtaining and documenting any required consent or opt-out, and honoring withdrawal or objection; and
- not instructing processing that is unlawful or prohibited by a connected platform.
Customer may provide its Controller information through its own privacy notice or another lawful and reasonably accessible channel. If Customer relies on an exception to an individual-notice obligation, Customer must document the applicable legal test, its factual basis, and any required safeguards. OnStat does not ordinarily contact each data subject or collect a separate fan authorization on Customer's behalf. This operational allocation does not limit OnStat's obligations as Processor under this DPA or Applicable Data Protection Law, including its obligations to follow lawful documented instructions, protect Customer Personal Data, assist Customer, and notify Customer if an instruction appears unlawful.
Standard operational analytics and Customer-configured grouping by subscription status, purchases, spend, engagement, message or account activity do not authorize Customer to instruct OnStat to infer, label, score, rank, segment, target, or predict a data subject's sex life, sexual orientation, health, biometric identity, ethnicity, beliefs, or another special-category or comparably sensitive characteristic. Incidental sensitive information in messages, notes, profiles, purchases, or other Customer Personal Data may be processed only as necessary to provide the configured Service under Customer's lawful instructions. OnStat will not use it for OnStat advertising, cross-customer analytics, generalized model training, or another independent commercial purpose. Any purpose-built sensitive profiling requires a separate written agreement and prior role, lawful-basis, DPIA, notice, security, minimization, rights, retention, and product-control review.
4. Confidentiality and personnel
OnStat will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and receive privacy and security training appropriate to their role. Access will be limited according to role, tenant, and need to know. OnStat remains responsible for its personnel’s compliance with this DPA.
5. Security
Taking account of the state of the art, implementation costs, and the nature, scope, context, and purposes of processing and risk to individuals, OnStat will implement and maintain the Security Measures supplied with this DPA or the applicable Order Form.
OnStat will not materially decrease those measures during the subscription term. If a measure cannot be maintained, OnStat will implement an equivalent safeguard or notify Customer of a material reduction.
Customer acknowledges that the supplied Security Measures identify the storage layers that currently use encryption and disclose known limitations. Any customer-specific requirement must be stated in an Order Form.
6. Subprocessors
Customer gives general written authorization for OnStat to appoint the Subprocessors listed in the Subprocessor List.
OnStat will:
- impose written data-protection obligations that provide at least the level of protection required by this DPA for the relevant processing;
- remain responsible to Customer for a Subprocessor’s performance of those obligations;
- provide at least 30 days’ prior notice of a new Subprocessor that will process Customer Personal Data, unless an urgent security or legal need makes shorter notice necessary; and
- make available information reasonably necessary to evaluate the change.
Customer may object within the notice period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected feature or Order Form, and OnStat will refund prepaid unused fees for the terminated portion. An objection is not a right to continue using an unlawful configuration.
7. Data Subject Requests
Taking account of the nature of processing, OnStat will provide reasonable technical and organizational assistance for Customer to respond to access, correction, deletion, restriction, portability, objection, consent-withdrawal, and automated-decision requests.
If OnStat receives a request relating to Customer Personal Data, it will not substantively respond except on Customer’s documented instructions or as required by law. Where legally permitted, OnStat will direct the requester to Customer and notify Customer. Customer is responsible for verifying identity and determining the response.
Customer must maintain a working contact route for these requests and provide it to OnStat on request. OnStat may communicate with the requester as reasonably necessary to identify the relevant Customer, protect the requester or another person, preserve security, or comply with law, without assuming Customer's Controller responsibilities.
Standard self-service tools and reasonable assistance are included in the fees. OnStat may charge documented reasonable costs for disproportionate, repetitive, or custom assistance to the extent law permits.
8. DPIAs, consultation, and compliance assistance
OnStat will provide information reasonably available to it to assist Customer with:
- security obligations;
- Data Protection Impact Assessments;
- prior consultation with a Supervisory Authority;
- records of processing and transfer assessments; and
- breach notification duties.
Customer remains responsible for deciding whether a DPIA or consultation is required. Given the potential scale of private communications, profiling, and data revealing adult-industry participation, Customer should presume a DPIA is required unless qualified counsel documents otherwise.
9. Personal Data Breach
OnStat will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where feasible, provide an initial notice within 48 hours. The initial notice may be phased and will include information then reasonably available about:
- the nature and approximate scope of the breach;
- affected data and data-subject categories;
- likely consequences;
- containment, remediation, and mitigation; and
- a response contact.
OnStat will investigate, take reasonable mitigation steps, preserve relevant evidence, and provide updates. Notice is not an admission of fault. Customer is responsible for notifying authorities and individuals, except where law directly requires OnStat to notify.
Customer must promptly notify OnStat of compromised Authorized Users, devices, exports, platform sessions, or credentials that may affect the Service and cooperate in containment.
10. Government and third-party demands
Unless prohibited by law, OnStat will notify Customer before disclosing Customer Personal Data in response to binding legal process. OnStat will review the demand for validity, challenge overbroad or unlawful demands where reasonable, disclose only what is legally required, and document the response. OnStat may make emergency disclosures where it reasonably and in good faith believes necessary to prevent death, serious injury, or sexual exploitation and law permits.
11. Return, export, and deletion
During the term, Customer may use available export functions. When a paid subscription ends, access to paid features ends immediately. For the following 30 days, Customer may request a standard export or reactivate the subscription as stated in the Terms.
Each generated export download link expires 24 hours after issuance. Link expiry does not shorten the 30-day offboarding window; Customer may request a replacement link while that window remains open, subject to identity, authorization, law, and security checks.
After that 30-day period, OnStat will place Customer Personal Data in the active-system deletion process and may permanently delete it without further notice. Customer will have no right to access or recover it after the window. OnStat may begin deletion earlier on Customer’s verified written instruction. Subject to the timing above, OnStat will delete or return Customer Personal Data, at Customer’s choice, unless law requires retention.
Protected residual copies may remain in backups for legal, security, and disaster-recovery purposes until overwritten under the normal backup cycle. They will not be available for ordinary use or restored except for disaster recovery. If restored, the applicable access restrictions and deletion instructions will be re-applied.
OnStat may retain a restricted copy only where law, an active dispute, fraud, safety, or a legal hold requires it. The Privacy Notice, Annex 1, and Customer’s documented settings provide the applicable periods and criteria.
12. Information and audit
OnStat will make available information reasonably necessary to demonstrate compliance, including this DPA, Security Measures, Subprocessor information, and available independent assurance reports.
No more than once in any 12-month period, unless a material breach, Supervisory Authority, or reasonable evidence of non-compliance requires more, Customer may conduct an audit:
- first through written questions and available reports;
- then, if those are insufficient, through a mutually agreed remote review; and
- only where necessary, through a limited on-site audit by an independent auditor bound by confidentiality.
Audits require at least 30 days’ notice, must occur during business hours, must avoid disrupting operations or exposing another customer’s data, and must not include penetration testing without a separate written protocol. Customer bears its audit costs; OnStat may charge reasonable assistance costs unless the audit identifies a material breach by OnStat.
13. International transfers
Customer authorizes transfers described in the Subprocessor List, subject to valid transfer mechanisms and supplementary safeguards.
Where Customer Personal Data subject to GDPR is transferred to OnStat in a country without an adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914:
- Module Two applies when Customer is Controller and OnStat is Processor;
- Module Three applies when Customer is Processor and OnStat is Subprocessor;
- the optional docking clause applies;
- Option 2 general authorization and the 30-day notice period apply;
- for Clause 17, Option 1 applies and the Clauses are governed by the laws of the Republic of Cyprus, subject to the SCC requirement that the selected law permit third-party beneficiary rights;
- for Clause 18(b), the selected courts are the courts of the Republic of Cyprus, without limiting a data subject’s right under Clause 18(c) to bring proceedings in the EU Member State of that person’s habitual residence;
- Annexes 1–3 are completed by this DPA, the Subprocessor List, and Security Measures; and
- the clauses prevail over inconsistent terms.
For UK restricted transfers, the parties incorporate the then-current UK International Data Transfer Addendum to the EU SCCs, completed using this DPA. For Swiss transfers, references will be adapted to the Swiss FADP and the competent Swiss authority as required.
OnStat will conduct and support transfer-risk assessments and implement supplementary measures where reasonably required. If a transfer mechanism becomes invalid, the parties will promptly adopt a valid alternative or stop the affected transfer.
14. U.S. state privacy commitments
To the extent a U.S. state privacy law applies to Customer Personal Data, OnStat will:
- process it only for the limited and specified purposes in the Agreement;
- not sell or share it, retain/use/disclose it outside the business relationship, or combine it with personal data from another source, except as the law permits for a service provider or contractor;
- provide the same level of privacy protection required of Customer for the processing;
- notify Customer if it can no longer meet that obligation;
- permit Customer to take reasonable steps to stop and remediate unauthorized use; and
- ensure Subprocessors are contractually bound as required.
OnStat’s independent-controller data is outside this section.
15. Liability
Each party’s liability under this DPA is subject to the Agreement’s limitation of liability, except to the extent Applicable Data Protection Law prohibits the limitation. No contractual allocation affects a data subject’s or Supervisory Authority’s statutory rights.
16. Duration and termination
This DPA begins with the Agreement and remains effective while OnStat processes Customer Personal Data. Obligations that by nature continue after deletion or termination, including confidentiality, audit, transfer, and liability obligations, survive.
Annex 1 — Processing details
Subject matter and purpose
Providing and securing multi-tenant account connection, synchronization, team access, analytics, campaigns, attribution, messaging, lists/funnels, automation, AI features, API/OAuth/MCP access, Shared Portals, support, export, and deletion according to Customer’s configuration and instructions.
Duration
For the Agreement term and the export/deletion, backup, and legally required retention periods described above.
Data subjects
- Customer owners, employees, contractors, chatters, and agency personnel;
- creators and connected account owners;
- fans, subscribers, payers, purchasers, message participants, and campaign visitors;
- Telegram invite users or channel participants to the limited extent captured by enabled attribution; and
- other individuals whose data Customer submits or makes accessible.
Personal-data categories
- identity, contact, account, tenant, role, device, authentication, and audit data;
- API-key, OAuth-client, selected account/scope, grant, token-family, tool/endpoint, and connection-audit metadata;
- Shared Portal recipient/relationship, visibility/action configuration, token identifier/status, access/write audit, revocation actor/time/reason, and affected business-record metadata;
- creator-platform session cookies, tokens, fingerprint/cookie values, signing and connection parameters;
- creator/fan profile, subscription, interaction, purchase, spend, transaction, tax, tip, and campaign attribution data;
- private communications, message/tip text, dialog metadata, raw payloads, and media identifiers/previews;
- allowlisted click URL/query fields, platform click and OnStat event identifiers, referrer, IP, user agent, approximate location, postback, and conversion data;
- content, media metadata/thumbnails, lists, campaigns, automations, notes, AI prompts, generated queries, outputs, and sampled query rows; and
- any other data selected by Customer through an enabled integration or feature.
Original adult photo and video files are outside the standard persistent-storage scope. OnStat may process media identifiers and metadata, persist minimized thumbnails or technical previews needed for an authorized product view, and temporarily proxy media bytes without persistent storage. Stored thumbnails/previews remain Customer Personal Data and may be retrieved only after tenant/account authorization; any signed delivery URL is short-lived and issued only after that authorization check.
Sensitive or special-category data
Customer Personal Data may reveal or permit inferences about sex life, sexual orientation, adult-industry participation, financial circumstances, private communications, or criminal allegations. It may include intimate content metadata. Customer must not provide government identity documents, biometric templates, health data, or content involving minors unless a feature and written agreement expressly authorize it.
Sensitive information may appear incidentally in Customer Personal Data, but purpose-built sensitive profiling is outside the standard processing instructions and Service scope.
Processing operations
Collection, receipt, authentication, authorization, recording, organization, storage, retrieval, query, matching, enrichment, aggregation, analysis, AI inference, display, transmission to Customer-selected recipients, modification, action execution, export, restriction, deletion, backup, security monitoring, and support.
For original adult media bytes, standard operations are limited to transient authorized proxying and transmission without persistent storage.
Frequency
Continuous or event-driven while accounts and features are enabled.
Annex 2 — Security measures
The current Security Measures supplied with this DPA or the applicable Order Form are incorporated by reference. Any customer-specific measures must be stated in a signed Order Form.
Annex 3 — Subprocessors
The current Subprocessor List is incorporated by reference.
Signatures
This DPA may be accepted electronically with the Agreement. If signatures are required:
Customer: the Customer identified in the applicable Order Form or electronic acceptance record Name/title: ____________________ Date/signature: ____________________
OnStat: DSLS PARTNERS LTD Name/title: ____________________ Date/signature: ____________________