Common Paper Data Processing Agreement 1.1, with the Cover Page below
Data Processing Agreement
In effect from 2026-09-24.
This agreement covers personal data that PRIORA, LLC processes on a customer's behalf when they use Data Cartel Cloud. It is the Common Paper Data Processing Agreement version 1.1, published at commonpaper.com/standards/data-processing-agreement, incorporated here in full together with the Cover Page below, and it forms part of the Terms of Service.
For this agreement the Customer is the controller and PRIORA, LLC is the processor: the Customer decides what goes into their portal and why, and we process it to provide the service.
Cover Page
Provider: PRIORA, LLC. Customer: the organization that accepted the Terms of Service. Agreement: those Terms.
Provider Security Contact: security@datacartel.io.
Security Policy: the security overview published at datacartel.io/security.
Governing Law and Chosen Courts: as in the Terms, being Delaware law and the state and federal courts located in New Hampshire.
DPA Covered Claims and DPA Liability Cap: the standard defaults, which tie this agreement to the cap in the Terms.
Service Provider Relationship: yes. Under US state privacy law PRIORA, LLC is a service provider. It processes personal data only to provide the service, does not sell or share it, and does not use it for its own purposes, including training machine learning models.
Restricted Transfers: yes. Every subprocessor is in the United States, so the EEA Standard Contractual Clauses and the UK Addendum apply. Governing Member State: Ireland.
Approved Subprocessors: the list published at datacartel.io/subprocessors, being Vercel, Neon, Resend and Stripe, all in the United States. We give at least 10 business days' notice by email to each organization's owners before that list changes, and 30 days to object.
Changes to the Agreement
One change is made to the standard terms, and it is stated plainly rather than buried. Section 5.2 of the standard terms is replaced with the following:
PRIORA, LLC has not been audited against its Security Policy by an independent third-party auditor and holds no such report. It will tell Customer if that changes, and will then provide a summary copy on written request, on a confidential basis. In the meantime it will provide its current security overview and will answer a reasonable written security questionnaire once in any 12-month period.
Section 5.1 is unchanged: Customer keeps the right to the information reasonably necessary to show compliance with this agreement.
Annex I(A): the parties
Data exporter: the Customer, as controller, contactable at the email address on its account. Data importer: PRIORA, LLC, as processor, contactable at legal@datacartel.io, with security matters at security@datacartel.io.
Annex I(B): the processing
Categories of data subjects: the Customer's own people who use the service, being owners, admins, business unit users and partners; and people the Customer names in its own content, such as logistics contacts and people mentioned in roadmaps, updates and documents.
Categories of personal data: account data, being email address, name and avatar link; membership and role data; contact details the Customer enters for logistics contacts, being name, email address and role; free text the Customer writes, which may name people; security records, being sign-in events with the email address masked, support session records and data export records; and the billing contact's email address, held by Stripe.
Special category data: none intended. Customers are asked not to upload it, in the Use Limitations in the Terms.
Nature and purpose of processing: hosting and displaying the Customer's portal; sending sign-in links, account notices and weekly digest emails; billing; providing support, including time-limited read-only support sessions that are recorded and visible to the Customer; and security and abuse prevention.
Frequency of transfer: continuous, for as long as the Customer uses the service.
Duration of processing: the length of the subscription, plus up to 30 days after an owner requests deletion, after which the data is purged. Copies persist in the database's point-in-time history for a further six hours.
Annex I(C) and Annex II
Competent supervisory authority: the Data Protection Commission of Ireland, following the Governing Member State above.
Technical and organisational measures: the security overview published at datacartel.io/security, which states the controls in place and the gaps that are not.
Questions: hello@datacartel.io.