Processor: The Smart Fellows ("TSF," "Processor") Product: SmartPIM (the "Service") Effective date: 2026-09-18 · Last updated: 2026-09-18
This DPA forms part of the Terms of Service between The Smart Fellows ("Processor", "TSF") and the Customer ("Controller"). It applies where TSF processes personal data on the Customer's behalf.
Customer is the controller (or processor for its own customers); TSF is the processor. TSF processes personal data only to provide the Service and only on documented instructions from the Customer (these Terms and the Customer's use of the Service being such instructions).
Hosting, storing, and transmitting the Customer's product data and the account data of the Customer's authorized users, and — at the Customer's instruction — transmitting product data to channels the Customer connects. Duration: the subscription term + the post-termination export window.
Customer authorizes the sub-processors named in the sub-processor list provided to Customer on request (Annex B of the signed DPA). TSF will (a) impose data-protection obligations on each sub-processor no less protective than this DPA, and (b) give Customer reasonable advance notice of a new sub-processor, during which Customer may object on reasonable data-protection grounds. The named list is not published on this page — it is supplied to a Customer on request and annexed to the signed DPA, while the public Privacy Policy §6 describes sub-processors by category.
TSF will: (a) process only on documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement the technical & organizational measures in Annex A; (d) assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach, and DPIA obligations; (e) at Controller's choice, delete or return personal data at end of services, subject to legal retention; (f) make available information to demonstrate compliance, and allow audits on reasonable notice, no more than once in any twelve-month period unless a supervisory authority requires otherwise or a personal data breach has occurred.
Per Annex A. TSF maintains RLS tenant isolation, encryption in transit and at rest, vaulted secrets, least-privilege access, and access logging.
TSF will notify Customer without undue delay and within 72 hours of becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available. This matches the Security Incident clock in Terms of Service §6.3.
Data is processed in the United States (Supabase us-east-1). TSF does not currently offer an EEA or UK data region. Where the Customer is established in the EEA or the UK, the applicable transfer mechanism — Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful basis — is agreed and executed with that Customer before processing begins, and is incorporated into this DPA for them. TSF does not represent that any such mechanism is already in place by default.
On termination, Customer may export data for 30 days; thereafter TSF deletes or de-identifies Customer personal data within 60 days, subject to backup rotation and legal requirements, and will certify deletion on request. These windows match Terms of Service §12.5.
Liability is subject to the limitations in the Terms. In case of conflict on data-protection matters, this DPA controls.
brand_id + brand_member; verified cross-tenant isolation.