Data Processing Agreement
Waitlister — operated by Lemon Tree Ventures, LLC
Version 2.0. Effective from 1 September 2026. Supersedes the version last updated 15 April 2026. Related documents: Terms of Use, Privacy Policy and Subprocessors.
This agreement applies automatically, without separate signature. To print it, use your browser's print command — nav and footer are removed from the printed page. If your procurement team needs a counter-signed copy, ask us at devin@waitlister.me (Section 2.2).
Preamble
This Data Processing Agreement ("DPA") is entered into between:
(1) the customer that has accepted the Waitlister Terms of Use (the "Company", acting as data controller); and
(2) Lemon Tree Ventures, LLC, a limited liability company incorporated in the State of Delaware, United States, of 1111B S Governors Ave, STE 55103, Dover, DE 19904, United States, trading as "Waitlister" (the "Processor", acting as data processor),
each a "Party" and together the "Parties".
WHEREAS
A. The Processor provides waitlist creation, hosting, subscriber management and related email services (the "Services"), as described at waitlister.me.
B. In providing the Services, the Processor processes personal data on behalf of the Company. In respect of that personal data the Company is the controller and the Processor is a processor.
C. This DPA sets out the terms on which the Processor processes that personal data, and is intended to satisfy Article 28(3) of the GDPR and the equivalent provisions of other applicable Data Protection Laws.
D. Where the processing involves a transfer of personal data out of the EEA, the United Kingdom or Switzerland, the Parties intend the transfer mechanisms in Section 13 and the Appendices to apply.
IT IS AGREED AS FOLLOWS.
1. Definitions and interpretation
1.1 In this DPA:
"Company Personal Data" means any Personal Data that the Processor Processes on behalf of the Company under or in connection with the Principal Agreement.
"Data Protection Laws" means all laws relating to data protection and privacy applicable to a Party's processing under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, and any national implementing or supplementing legislation.
"EEA" means the European Economic Area.
"EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
"GDPR" means Regulation (EU) 2016/679.
"Principal Agreement" means the Waitlister Terms of Use published at waitlister.me/terms-of-use, together with the plan or order the Company has purchased, as amended from time to time.
"Restricted Transfer" means a transfer of Company Personal Data to a country outside the EEA, the United Kingdom or Switzerland (as applicable) that is permitted only where an Article 46 GDPR safeguard, or its UK or Swiss equivalent, is in place.
"Subprocessor" means any third party engaged by the Processor to Process Company Personal Data.
"Swiss FADP" means the Swiss Federal Act on Data Protection of 25 September 2020, as amended.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0 in force 21 March 2022, as revised under its Section 18.
"UK GDPR" has the meaning given in section 3(10) of the Data Protection Act 2018.
1.2 The terms "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR, and cognate terms are construed accordingly.
1.3 Section headings do not affect interpretation. "Including" means "including without limitation".
2. Relationship to the Principal Agreement
2.1 This DPA forms part of, and is incorporated into, the Principal Agreement. It takes effect on the date the Company first accepts the Principal Agreement or, if later, the date the Company first submits Company Personal Data to the Services.
2.2 No signature is required. This DPA is binding on both Parties on the terms set out here. The Processor will, on written request, provide a counter-signed copy for the Company's records.
2.3 Order of precedence. In the event of a conflict, the following order applies, from highest to lowest:
(a) the EU SCCs, the UK Addendum and the Swiss provisions in Appendices 1 to 3;
(b) this DPA;
(c) the Principal Agreement, including the Privacy Policy.
2.4 Except as expressly amended by this DPA, the Principal Agreement remains in full force.
2.5 Effect of the Privacy Policy. The Waitlister Privacy Policy describes the Processor's processing as a controller of the Company's own account data. It does not govern the Processor's processing of Company Personal Data as a processor, which is governed exclusively by this DPA.
3. Roles and scope
3.1 The Company is the controller and the Processor is the processor in respect of Company Personal Data.
3.2 The Company is responsible for: establishing and maintaining a lawful basis for the processing; providing data subjects with the information required by Articles 13 and 14 GDPR; obtaining any consent required for the collection of Company Personal Data and for any marketing sent through the Services; and ensuring the accuracy of the instructions it gives.
3.3 The Company warrants that it is entitled to transfer Company Personal Data to the Processor and to instruct the processing described in Annex I, including in respect of any personal data the Company imports into the Services from another source.
3.4 The Processor acts as a controller in respect of: account registration and administration data of the Company's own personnel; billing data; support correspondence; and service telemetry used for security, abuse prevention, and to operate and improve the Services. That processing is governed by the Privacy Policy and not by this DPA.
4. Processing of Company Personal Data
4.1 The Processor shall Process Company Personal Data only on the Company's documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by a law to which the Processor is subject. Where such a law applies, the Processor shall inform the Company of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
4.2 The Company's documented instructions are: this DPA; Annex I; the Principal Agreement; the configuration choices the Company makes in the Services; and any further written instructions the Company gives that are consistent with the scope of the Services.
4.3 Unlawful instructions. The Processor shall immediately inform the Company if, in its opinion, an instruction infringes the GDPR, the UK GDPR, the Swiss FADP or other applicable Data Protection Laws. The Processor may suspend performance of the affected instruction until the Company confirms, amends or withdraws it, without liability for that suspension.
4.4 The Processor shall not sell Company Personal Data, and shall not use Company Personal Data to train machine learning or artificial intelligence models for its own purposes or those of any third party.
4.5 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
5. Confidentiality and personnel
5.1 The Processor shall ensure that any person authorised to Process Company Personal Data is subject to a binding duty of confidentiality, whether contractual or statutory, that survives the end of their engagement.
5.2 The Processor shall take reasonable steps to ensure the reliability of any such person, and shall limit access to Company Personal Data to those who need it to perform the Services or to comply with a legal obligation.
5.3 The Processor shall ensure that persons with access to Company Personal Data receive appropriate guidance on their data protection obligations.
6. Security
6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, the Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including as appropriate the measures referred to in Article 32(1) GDPR.
6.2 The measures in place as at the date of this DPA are described in Annex II.
6.3 The Processor may update the measures in Annex II from time to time, provided that no update materially reduces the overall level of security of the Services.
7. Subprocessing
7.1 General written authorisation. The Company gives the Processor general written authorisation to engage Subprocessors, subject to this Section 7. The Subprocessors authorised as at the date of this DPA are listed in Annex III. This constitutes the Company's authorisation for the purposes of Article 28(2) GDPR and Clause 9(a), Option 2 of the EU SCCs.
7.2 Notice of changes. The Processor shall give the Company at least thirty (30) days' prior written notice of any intended addition or replacement of a Subprocessor, together with sufficient information to allow the Company to assess the change. Notice may be given by email to the Company's registered account address, by notification within the Services, or through a subscription list the Processor makes available for this purpose.
7.3 Objection. The Company may object to an intended change on reasonable grounds relating to data protection by giving written notice within thirty (30) days of the Processor's notice. The Parties shall discuss the objection in good faith. If the Processor cannot accommodate the objection within a reasonable period, the Company may terminate the affected Services on written notice, and the Processor shall refund any fees prepaid for the terminated Services in respect of the period after termination. Termination on this ground is not a breach by either Party.
7.4 Subprocessor obligations and liability. The Processor shall impose on each Subprocessor, by written contract, data protection obligations that are the same as those imposed on the Processor under this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the requirements of the GDPR. The Processor remains fully liable to the Company for the performance of each Subprocessor's obligations, and for any act or omission of a Subprocessor as if it were the Processor's own.
7.5 On written request, the Processor shall provide a copy of its agreement with a Subprocessor, which may be redacted to remove commercial terms and information that is not relevant to data protection.
8. Data subject rights
8.1 Taking into account the nature of the processing, the Processor shall assist the Company by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Company's obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
8.2 The Services provide the Company with self-service functionality to access, correct, export and delete Company Personal Data. The Parties agree this functionality constitutes the principal means of assistance under Section 8.1.
8.3 If the Processor receives a request from a data subject relating to Company Personal Data, it shall not respond to the request itself other than to confirm that the request should be directed to the Company. The Processor shall notify the Company of the request without undue delay, unless prohibited by law.
8.4 Where the Company cannot fulfil a request through the Services, the Processor shall provide reasonable additional assistance at the Company's request.
9. Personal data breach
9.1 The Processor shall notify the Company without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Company Personal Data.
9.2 The notification shall include, to the extent known at the time and updated as further information becomes available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.
9.3 The Processor shall co-operate with the Company and take such reasonable steps as the Company directs to assist in the investigation, mitigation and remediation of the breach.
9.4 The Processor shall not notify a supervisory authority or any data subject of a breach affecting Company Personal Data on the Company's behalf, or identify the Company in any public communication about a breach, without the Company's prior written consent, unless required by law.
9.5 The Processor's notification under this Section is not an acknowledgement of fault or liability.
10. Data protection impact assessments
10.1 The Processor shall provide reasonable assistance to the Company with any data protection impact assessment and any prior consultation with a supervisory authority that the Company reasonably considers to be required under Articles 35 or 36 GDPR, in each case solely in relation to the processing of Company Personal Data and taking into account the nature of the processing and the information available to the Processor.
11. Return or deletion of Company Personal Data
11.1 At any time during the term, the Company may retrieve Company Personal Data. The Services provide self-service export in a structured, commonly used, machine-readable format; the fields included and the volume exported may vary with the Company's plan. Where the self-service export does not include all Company Personal Data, or does not cover all records, the Processor shall provide the remainder on the Company's written request, in such a format and at no charge.
11.2 On cessation. On termination or expiry of the Principal Agreement, or on cessation of any Service involving the processing of Company Personal Data (the "Cessation Date"), the Processor shall, at the Company's choice, either return the Company Personal Data to the Company or delete it.
11.3 Retrieval window. For thirty (30) days after the Cessation Date, the Processor shall retain the Company Personal Data and keep the export functionality available so that the Company can retrieve it. The Company may notify the Processor at any time during that window of its choice under Section 11.2. Return is effected by making the Company Personal Data available for export in a structured, commonly used, machine-readable format. Where the self-service export does not include all Company Personal Data, or where export through the Services is not reasonably practicable, the Processor shall provide an alternative method of return covering all Company Personal Data, at no charge. The Company's right of return under this Section does not vary with its plan.
11.4 Deletion. The Processor shall delete the Company Personal Data, and procure that each Subprocessor deletes it, within thirty (30) days after the earlier of (a) the end of the retrieval window and (b) the Company's written instruction to delete. The Company may instruct deletion at any time during the retrieval window, in which case the Processor shall delete without waiting for the window to expire.
11.5 Residual copies. Any residual copies of Company Personal Data remaining in routine, non-targeted system backups after deletion under Section 11.4 shall be deleted in the ordinary course of the Processor's backup rotation. Until deleted, such copies shall not be actively processed for any purpose and shall remain subject to this DPA, including its confidentiality and security obligations.
11.6 Retention required by law. The Processor may retain Company Personal Data to the extent, and for as long as, required by a law to which it is subject. Where it does so, the Processor shall inform the Company of the requirement (unless prohibited by law), shall ensure the confidentiality of the retained data, and shall process it only for the purpose the law requires.
11.7 Certification. The Processor shall, on the Company's written request, certify in writing that it has complied with this Section 11.
12. Audit and information rights
12.1 The Processor shall make available to the Company all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Company or an auditor it mandates.
12.2 Documentation first. The Parties agree that the Processor may discharge Section 12.1 in the first instance by providing: the description of measures in Annex II; the current Subprocessor list in Annex III; responses to a reasonable security questionnaire; and any third-party audit reports, certifications or attestations held by the Processor or available to it in respect of its Subprocessors.
12.3 Choice of audit method. Where the information provided under Section 12.2 does not enable the Company to verify compliance, the Company may audit by remote means, by on-site inspection, or by a combination of both, and may mandate an independent third-party auditor. The Parties expect that documentation review and remote audit will ordinarily be sufficient and will be used first. That expectation does not limit the Company's right to select another proportionate method where it reasonably considers it necessary, having regard to the circumstances and to the security of the Processor's systems.
12.4 Frequency. Audits under Section 12.3 take place at reasonable intervals, and in any event may be conducted where there are indications of non-compliance.
12.5 Conditions. Audits under Section 12.3 are subject to the following:
(a) the Company gives at least thirty (30) days' prior written notice;
(b) in the absence of any of the circumstances in Section 12.6, the Company does not ordinarily audit more than once in any twelve (12) month period;
(c) audits are conducted during business hours and in a manner that minimises disruption;
(d) the Company and any auditor it mandates are bound by obligations of confidentiality at least as protective as those in the Principal Agreement, and the auditor is not a competitor of the Processor;
(e) the audit does not extend to the personal data, configuration or commercial information of any other customer of the Processor, or to information subject to legal privilege or a binding confidentiality obligation owed to a third party; and
(f) the Company bears its own costs. For an on-site inspection the Company also bears the Processor's reasonable costs, save where the audit reveals a material breach of this DPA by the Processor, in which case the Processor bears its own costs. The Processor does not charge for documentation provided under Section 12.2 or for a remote audit. Any costs charged shall be reasonable and shall not be applied so as to deter or impair the Company's exercise of its audit rights.
12.6 Where the conditions do not apply. The conditions in Section 12.5(a), (b) and (f) do not apply where: there are indications of non-compliance with this DPA or applicable Data Protection Laws; a personal data breach affecting Company Personal Data has occurred; there has been a material change to the Services, to the Subprocessors or to the measures in Annex II; the information previously provided is insufficient to enable verification; or an audit or inspection is required by a supervisory authority or by applicable law.
12.7 Nothing in this Section limits the rights of a data subject or a supervisory authority, or the rights conferred on the Company by Clause 8.9 of the EU SCCs, including the Company's right to choose the form of audit and to mandate an auditor of its choice.
13. International transfers
13.1 The Processor is established in the United States. Company Personal Data is hosted in the United States, as further described in Annex I. Providing the Services therefore involves a Restricted Transfer.
13.2 The Processor is not certified under the EU–US Data Privacy Framework. The Parties accordingly rely on the standard contractual clauses set out in this Section and the Appendices.
13.3 EU transfers. For Restricted Transfers subject to the GDPR, the EU SCCs, Module Two (controller to processor), are incorporated into this DPA by reference and form an integral part of it. They apply as if set out in full, populated in accordance with the selections in Appendix 1, with Annexes I, II and III to this DPA serving as Annexes I, II and III to the EU SCCs. The Company is the "data exporter" and the Processor is the "data importer".
13.4 UK transfers. For Restricted Transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA by reference and applies to the EU SCCs as described in Section 13.3, completed in accordance with Appendix 2.
13.5 Swiss transfers. For Restricted Transfers subject to the Swiss FADP, the EU SCCs apply as modified by Appendix 3.
13.6 Precedence. If there is any conflict between this DPA and the EU SCCs, the UK Addendum or the Swiss provisions, those instruments prevail. Nothing in this DPA or the Principal Agreement is intended to contradict or restrict them, and any provision that would do so does not apply to the extent of the conflict.
13.7 Onward transfers. The Processor shall not transfer Company Personal Data to a Subprocessor outside the EEA, the United Kingdom or Switzerland unless an appropriate safeguard under Article 46 GDPR, or its UK or Swiss equivalent, is in place for that transfer. The safeguard relied on for each Subprocessor is identified in Annex III.
13.8 Alternative mechanisms. If the Processor adopts an alternative lawful transfer mechanism — including certification under the EU–US Data Privacy Framework and its UK Extension, or a successor set of standard contractual clauses adopted by the European Commission — that mechanism applies in place of the mechanism in this Section for the transfers it covers, on written notice to the Company, provided it affords a level of protection at least equivalent to that required by applicable Data Protection Laws.
13.9 Government access requests. The Processor's obligations in respect of requests from public authorities are set out in Clauses 15.1 and 15.2 of the EU SCCs. In summary, and without limiting those Clauses, the Processor shall: notify the Company of any legally binding request for disclosure unless prohibited from doing so; challenge a request where it has reasonable grounds to consider it unlawful; seek to suspend or narrow any prohibition on notification; document each request; and disclose only the minimum amount of data permissible on a reasonable interpretation of the request.
13.10 Transfer impact assessment. The Processor has documented its assessment under Clause 14 of the EU SCCs of the laws and practices of the United States relevant to the transfer, and the supplementary measures it applies. That assessment is available to the Company on request.
14. Liability
14.1 Each Party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Principal Agreement. Claims under this DPA and claims under the Principal Agreement are aggregated and do not each benefit from a separate cap.
14.2 Section 14.1 does not apply to, and nothing in this DPA or the Principal Agreement limits, excludes or otherwise affects:
(a) any liability, indemnity or right of recourse arising under Clause 12 of the EU SCCs in its entirety — including the liability of each Party to the other under Clause 12(a), and the rights of recourse preserved by Clauses 12(d) and 12(f) — and the equivalent provisions of the UK Addendum and the Swiss provisions;
(b) either Party's liability to a data subject under the EU SCCs, the UK Addendum or the Swiss provisions;
(c) any right of compensation or recourse under Article 82 GDPR, including the apportionment and recovery provisions of Article 82(2) to (5), or under the UK or Swiss equivalents;
(d) either Party's liability for fraud or fraudulent misrepresentation; or
(e) any liability that cannot be limited or excluded under applicable law.
14.3 Where the Parties are jointly liable, liability is apportioned between them in accordance with each Party's responsibility for the damage, as provided in Clause 12 of the EU SCCs.
15. General
15.1 Duration. This DPA takes effect in accordance with Section 2.1 and remains in force for as long as the Processor Processes Company Personal Data, notwithstanding termination of the Principal Agreement. Sections 5, 9, 11, 12, 13, 14 and 15 survive termination.
15.2 Notices. Notices under this DPA shall be in writing. Notices to the Company may be sent to the email address registered on the Company's account or given within the Services. Notices to the Processor shall be sent to devin@waitlister.me. It is the Company's responsibility to keep its registered email address current.
15.3 Changes to this DPA. The Processor may amend this DPA where required to reflect a change in Data Protection Laws, a decision of a supervisory authority or court, the adoption of a new or revised set of standard contractual clauses, or a change in the Services, provided the amendment does not materially reduce the protection afforded to Company Personal Data. The Processor shall give the Company at least thirty (30) days' notice of any material amendment. Any other amendment requires the written agreement of both Parties.
15.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in force. This Section does not apply to the EU SCCs, the UK Addendum or the Swiss provisions, which are severable only in accordance with their own terms.
15.5 Third-party rights. Except for the rights conferred on data subjects by the EU SCCs, the UK Addendum, the Swiss provisions and applicable Data Protection Laws, no third party has any right to enforce this DPA.
16. Governing law and jurisdiction
16.1 Subject to Section 16.2, this DPA is governed by the laws of the State of Delaware, United States, and the Parties submit to the exclusive jurisdiction of the state and federal courts located in the State of Delaware.
16.2 Carve-out. Section 16.1 does not apply to the EU SCCs, the UK Addendum or the Swiss provisions. Those instruments are governed by, and disputes under them are subject to the jurisdiction determined by, their own terms — for the EU SCCs, Clauses 17 and 18 as completed in Appendix 1. To the extent of any conflict between Section 16.1 and those Clauses, those Clauses prevail.
16.3 Nothing in this Section deprives a data subject of the right to bring proceedings in the courts of the Member State in which they have their habitual residence, or of any other right conferred by applicable Data Protection Laws.
Version 2.0. Effective from 1 September 2026. Supersedes the version last updated 15 April 2026.
ANNEX I — Description of the processing
A. List of Parties
Data exporter
| Name | The Company — the customer that has accepted the Waitlister Terms of Use. The Company's identity and contact details are those recorded on its Waitlister account. |
| Address | As recorded on the Company's Waitlister account. |
| Contact person | The account owner's name, position and email address, as recorded on the Company's Waitlister account. |
| Activities relevant to the transfer | Collection and management of waitlist and sign-up form submissions from the Company's own prospects, customers and contacts, and sending email communications to them. |
| Role | Controller |
| Signature and date | Acceptance of the Terms of Use constitutes signature. The date is the date of acceptance. |
Data importer
| Name | Lemon Tree Ventures, LLC, trading as Waitlister |
| Address | 1111B S Governors Ave, STE 55103, Dover, DE 19904, United States |
| Contact person | The data protection contact of Lemon Tree Ventures, LLC, at devin@waitlister.me |
| Activities relevant to the transfer | Provision of the Services: hosting waitlist landing pages and sign-up forms; storing and managing subscriber records; sending confirmation, welcome, notification and broadcast emails on the Company's instruction; referral tracking; analytics and reporting; and export of data to the Company. |
| Role | Processor |
| Signature and date | Making the Services available constitutes signature. The date is the date of the Company's acceptance. |
B. Description of the transfer
Categories of data subjects
- Individuals who submit a waitlist sign-up or form submission operated by the Company through the Services.
- Individuals who refer, or are referred by, such individuals under a referral programme operated by the Company.
- Individuals whose details the Company imports into the Services from another source.
- Individuals whom the Company invites to collaborate on its Waitlister account.
Categories of personal data
- Email address.
- Name (first name, last name or full name), where collected by the Company.
- IP address of the device used to sign up.
- Approximate geographic location (country, region, city) derived from IP address.
- Browser, device and user-agent information, and request characteristics used for abuse detection.
- Referral source, referral code, referral relationships, and UTM campaign parameters.
- Sign-up timestamp, confirmation status and waitlist position.
- Email engagement and delivery data: sends, deliveries, opens, clicks, bounces, complaints, unsubscribes and suppression status.
- Phone number, where the Company configures a phone field.
- Any additional data the Company chooses to collect through custom form fields it defines.
Sensitive data
The Services are not designed for, and the Processor does not request, special categories of personal data within the meaning of Article 9 GDPR, or personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
The Company shall not configure custom form fields to collect such data, and shall not import such data into the Services. If the Company does so in breach of this restriction, it does so on its own responsibility and shall apply any additional restrictions and safeguards required by Article 9 or 10 GDPR. No additional restrictions or safeguards beyond those in Annex II are applied by the Processor.
Frequency of the transfer
Continuous, for the duration of the Principal Agreement.
Nature of the processing
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission by email, disclosure to the Company, erasure and destruction — in each case as necessary to provide the Services.
Purpose of the processing
- Creating and hosting waitlist landing pages and sign-up forms for the Company.
- Collecting, storing and managing sign-up records on the Company's behalf.
- Sending confirmation, double opt-in, welcome, notification and broadcast emails on the Company's instruction.
- Detecting and preventing fraudulent, automated and abusive sign-ups, and screening outbound email content for fraud and abuse.
- Verifying email deliverability where the Company enables that feature.
- Operating referral programmes configured by the Company.
- Providing analytics and reporting to the Company.
- Enabling the Company to export its data.
- Providing support to the Company.
Duration of the processing
For the duration of the Principal Agreement, plus the retention and deletion periods set out in Section 11.
Transfers to subprocessors
As set out in Annex III. Each Subprocessor processes for the subject matter, nature and duration described against it in that Annex.
Place of processing
Company Personal Data is hosted on Google Cloud Platform / Firebase infrastructure in the United States. Cloud Firestore is located in the nam5 United States multi-region. Cloud Storage buckets are located in the United States. Cloud Functions run in us-central1.
C. Competent supervisory authority
The competent supervisory authority is determined in accordance with Clause 13 of the EU SCCs, as follows:
- where the Company is established in an EEA Member State: the supervisory authority of that Member State;
- where the Company is not established in an EEA Member State but has appointed a representative under Article 27(1) GDPR: the supervisory authority of the Member State in which that representative is established;
- where the Company is not established in an EEA Member State and has not appointed a representative, but its processing falls within Article 3(2) GDPR: the supervisory authority of a Member State in which the data subjects whose personal data is transferred under these Clauses are located.
Where more than one authority is competent on these facts, each such authority is a competent supervisory authority for the purposes of Clause 13. The Company shall provide the identity of the competent supervisory authority to the Processor on request, and the Parties shall record it in a populated copy of this Annex where one is required for the Company's records.
For UK transfers, the competent authority is the UK Information Commissioner. For Swiss transfers, it is the Federal Data Protection and Information Commissioner.
ANNEX II — Technical and organisational measures
The Processor operates the Services on Google Cloud Platform and Firebase. Certain measures below are inherited from that infrastructure and are identified as such.
Pseudonymisation and encryption of personal data
- All data in transit between data subjects, the Company and the Services is encrypted using TLS. HTTPS is enforced.
- All data at rest in Cloud Firestore and Cloud Storage is encrypted by Google Cloud using AES-256 as standard, with key management handled by Google Cloud.
- API keys, both account-level and per-waitlist, authenticate access to Company Personal Data through the API and are stored only as SHA-256 hashes. A plaintext key is displayed once at creation and is not recoverable thereafter.
- Waitlist form keys are a separate mechanism. They are public identifiers that the Company embeds in its own pages to address its sign-up endpoint, and are not credentials: they permit a sign-up to be submitted to that waitlist but confer no access to stored Company Personal Data. Requests to that endpoint are subject to origin checks, rate limiting and bot verification.
Ensuring ongoing confidentiality, integrity, availability and resilience of processing systems
- Company Personal Data is logically separated by tenant. Every record carries the owning account and waitlist identifier, and all queries are constrained by those identifiers.
- Firestore security rules enforce access control at the database layer, independently of application logic.
- The Services run on Google Cloud's managed, redundant infrastructure, which provides automatic replication across zones.
- Rate limiting is applied per IP address and per endpoint on public sign-up and API paths.
- Automated abuse controls include Cloudflare Turnstile bot verification on sign-up forms, blocked-domain and blocked-network lists, disposable-email detection, and request-characteristic scoring of sign-up traffic.
Ability to restore availability and access to personal data in a timely incident
- The Services run on Google Cloud's managed infrastructure in the
nam5United States multi-region, which replicates data automatically across zones. - Cloud Firestore Point-in-Time Recovery is enabled, providing a seven (7) day recovery window.
- The Processor does not operate scheduled backup exports beyond the recovery window described above.
Regular testing, assessment and evaluation of effectiveness
- Firestore security rules, access rules and HTTP security headers are held in version control and are reviewed on each change.
- Independent penetration testing and automated dependency vulnerability scanning are not currently carried out.
User identification and authorisation
- Access to the Company's account requires authentication through Firebase Authentication.
- Access to Company Personal Data within the Services is restricted to the account owner and to collaborators the Company has invited; the Company controls that access and can revoke it.
- Administrative access by the Processor's personnel is limited to the minimum number of individuals necessary to operate and support the Services, and is used only for support, security and abuse investigation.
Protection of data during transmission and during storage
- As described under "Pseudonymisation and encryption" above.
- A Content Security Policy restricts the origins from which application resources may be loaded.
- Outbound email is sent over authenticated, encrypted connections to the email Subprocessor, with SPF, DKIM and DMARC alignment on sending domains.
Physical security of locations at which personal data is processed
- Inherited from Google Cloud Platform data centres, which operate under Google's physical security programme and are covered by Google's ISO/IEC 27001 certification and SOC 2 reporting.
- The Processor operates no data centre or server of its own.
Events logging
- Application and infrastructure logs are captured through Google Cloud Logging.
- Administrative and security-relevant events, including authentication events, are recorded by Firebase Authentication and Google Cloud.
- Sign-up requests are recorded with the request characteristics used for abuse detection.
- Logs are retained in the Google Cloud Logging
_Defaultbucket for thirty (30) days, being the standard retention period applied by Google Cloud. - No application-level audit trail of administrative access to Company Personal Data is maintained. Access to Google Cloud resources is recorded in Google Cloud Logging.
System configuration, including default configuration
- Infrastructure configuration is managed through version-controlled configuration files and Firebase project settings.
- Security rules, access rules and HTTP security headers are defined in version control and deployed with the application.
Internal IT and IT security governance and management
- Responsibility for information security sits with the Processor's management.
- Access to production systems is limited to personnel with a demonstrable operational need, each bound by confidentiality obligations.
- Security configuration is managed through version control rather than a separate written information security policy.
Certification and assurance of processes and products
- The Processor does not currently hold ISO/IEC 27001, SOC 2 or equivalent certification.
- The Processor's principal infrastructure Subprocessors hold such certifications, as identified in Annex III.
Data minimisation
- The fields collected at sign-up are determined by the Company. The Processor collects only the fields the Company configures, together with the technical data listed in Annex I necessary for delivery, security and abuse prevention.
- Email content sent through the Services is composed by the Company.
- Records created solely to carry an outbound webhook payload are deleted once delivery has been attempted, rather than retained as a duplicate of the subscriber record.
- Deleting a subscriber removes every copy of that subscriber held by the Services, including any pending double opt-in record.
Data quality
- Data subjects enter their own details. The Company can correct records through the Services.
- Optional email verification and double opt-in features are available for the Company to enable.
Limited data retention
- Company Personal Data is retained for the duration of the Principal Agreement and deleted in accordance with Section 11.
- The Company can delete individual subscriber records, groups of records, or an entire waitlist at any time through the Services.
- Closing an account, or deleting an individual waitlist, removes the associated subscriber records, the related subcollections and the account's uploaded files.
Accountability
- This DPA, Annex III and the transfer impact assessment referred to in Section 13.10 constitute the Processor's processing records for Company Personal Data.
Data portability and erasure
- The Company can export subscriber data in CSV format through the Services. The fields available and the volume exported vary with the Company's plan, and API access to subscriber records is available on certain plans. A complete export of all Company Personal Data is available on written request at no charge, as provided in Section 11.
- Erasure is as described in Section 11.
Measures to be taken by Subprocessors
Each Subprocessor listed in Annex III is required by contract to implement technical and organisational measures appropriate to the processing it performs. The infrastructure Subprocessors identified in Annex III maintain independently audited security programmes. The terms governing each Subprocessor, including its security commitments, are linked in that Annex.
ANNEX III — List of Subprocessors
The Company authorises the engagement of the following Subprocessors to Process Company Personal Data. Each is engaged under a written agreement that imposes the data protection obligations required by Section 7.4 and that provides the transfer mechanism identified against it.
1. Google LLC — Google Cloud Platform and Firebase
| Service | Cloud hosting, Cloud Firestore, Firebase Authentication, Cloud Functions, Cloud Storage, Cloud Logging |
| Data | All categories of Company Personal Data |
| Locations | United States. Cloud Firestore in the nam5 multi-region; Cloud Functions in us-central1; Cloud Storage in the United States |
| EU transfer | Google Cloud Data Processing Addendum, incorporating the EU SCCs |
| UK transfer | UK Addendum, as incorporated by that Addendum |
| Swiss transfer | Swiss adaptations, as incorporated by that Addendum |
| Terms | https://cloud.google.com/terms/data-processing-addendum |
2. Cloudflare, Inc.
| Service | DNS, content delivery, Turnstile bot verification, edge caching, custom domain routing |
| Data | IP address, browser and device information, request metadata |
| Locations | United States, with processing at global edge locations |
| EU transfer | Cloudflare Data Processing Addendum, incorporating the EU SCCs |
| UK transfer | UK Addendum, as incorporated by that Addendum |
| Swiss transfer | Swiss adaptations, as incorporated by that Addendum |
| Terms | https://www.cloudflare.com/cloudflare-customer-dpa/ |
3. Plus Five Five, Inc., trading as Resend
| Service | Delivery of transactional and broadcast email; delivery, engagement and suppression events |
| Data | Recipient email address, name, email content composed by the Company, delivery and engagement data |
| Locations | United States |
| EU transfer | Resend Data Processing Addendum, incorporating the EU SCCs (Modules One, Two and Three) |
| UK transfer | UK Addendum, incorporated by reference under that Addendum |
| Swiss transfer | EU SCCs as modified for Switzerland under that Addendum |
| Terms | https://resend.com/legal/dpa |
4. IPinfo Inc.
| Service | Resolution of IP address to approximate geographic location at sign-up |
| Data | IP address |
| Locations | United States |
| EU transfer | IPinfo Data Processing Agreement, incorporating the EU SCCs (Modules Two and Three) |
| UK transfer | UK Addendum, as incorporated by that agreement |
| Swiss transfer | EU SCCs as modified for Switzerland under that agreement |
| Terms | https://ipinfo.io/data-processing-agreement |
5. Anthropic, PBC
| Service | Automated screening of outbound email content for fraud and abuse; generation of landing page content and marketing copy at the Company's request |
| Data | Email subject and body composed by the Company, sender name and address, reply-to address and waitlist name; and any prompts or content the Company submits to AI generation features |
| Locations | United States |
| EU transfer | Anthropic Data Processing Addendum, incorporating the EU SCCs (Modules Two and Three), governed by the law of Ireland |
| UK transfer | UK Addendum, Schedule 3 to that Addendum |
| Swiss transfer | Swiss Addendum, Schedule 3 to that Addendum |
| Terms | https://www.anthropic.com/legal/data-processing-addendum |
6. Google LLC — Gemini API, via Google Cloud
| Service | In-product support assistant |
| Data | Support messages submitted by the Company's personnel, together with account context comprising aggregate counts, waitlist configuration settings and fraud-signal identifiers. Subscriber records — including email addresses, IP addresses and device identifiers — are removed before that context is assembled. Company Personal Data reaches this Subprocessor only if the Company's personnel enter it into a support message |
| Locations | United States |
| EU transfer | As entry 1 |
| UK transfer | As entry 1 |
| Swiss transfer | As entry 1 |
| Terms | As entry 1 |
Basis of the mechanisms
The Processor relies on the standard contractual clauses identified above as the transfer mechanism for every Subprocessor. Where a Subprocessor additionally participates in the EU–US Data Privacy Framework, that participation is treated as supplementary and does not displace the clauses relied on in this Annex.
Parties that are not Subprocessors of Company Personal Data
The following receive no Company Personal Data and are therefore not Subprocessors for the purposes of this DPA. They are listed for transparency.
- Stripe, Inc. — payment processing and subscription billing for the Company's own account. Processes the Company's billing contact and payment data, which the Processor handles as a controller under Section 3.4 and the Privacy Policy.
- OpenAI, L.L.C. — image generation in the logo tool. Receives only the prompt the Company submits.
Customer-configured integrations
Where the Company connects a third-party service to the Services — including Zapier, the Waitlister plugin operating on the Company's own site, or an email marketing platform such as Klaviyo, Kit or SendFox — the Company does so as controller and instructs a transfer directly to that provider under its own agreement with it. Those providers are not Subprocessors of the Processor.
Current list
The current list of Subprocessors is maintained at https://waitlister.me/subprocessors.
APPENDIX 1 — EU Standard Contractual Clauses: selections
The EU SCCs apply as incorporated by Section 13.3, with the following selections. Where the EU SCCs offer an option that is not addressed below, the option is not selected.
| Item | Selection |
|---|---|
| Instrument | Standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as published in the Official Journal L 199, 7 June 2021, p. 31 |
| Module | Module Two — transfer controller to processor |
| Data exporter | The Company (controller) |
| Data importer | Lemon Tree Ventures, LLC (processor) |
| Clause 7 — Docking clause | Does not apply. The Parties do not adopt the optional docking clause. |
| Clause 9(a) — Use of subprocessors | Option 2 — general written authorisation. Time period for prior notice of subprocessor changes: 30 days. The agreed list is Annex III. |
| Clause 11(a) — Redress | The optional paragraph providing for an independent dispute resolution body does not apply. |
| Clause 13 — Supervision | The competent supervisory authority is identified in Annex I.C. |
| Clause 17 — Governing law | Option 1. The Clauses are governed by the law of Ireland, being the law of an EU Member State that allows for third-party beneficiary rights. |
| Clause 18(b) — Choice of forum | The courts of Ireland. |
| Annex I.A — List of Parties | Annex I.A of this DPA |
| Annex I.B — Description of transfer | Annex I.B of this DPA |
| Annex I.C — Competent supervisory authority | Annex I.C of this DPA |
| Annex II — Technical and organisational measures | Annex II of this DPA |
| Annex III — List of subprocessors | Annex III of this DPA |
The full text of the EU SCCs is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. In the event of any discrepancy between that text and any reproduction or summary of it, the text published in the Official Journal prevails. The Parties do not modify the EU SCCs; the selections above complete them only where the Clauses themselves require a selection.
APPENDIX 2 — UK International Data Transfer Addendum
The UK Addendum (version B1.0, in force 21 March 2022) applies to Restricted Transfers subject to the UK GDPR, completed as follows.
Part 2 of the UK Addendum is incorporated by reference in the form prescribed by the Information Commissioner for that purpose:
Mandatory Clauses: Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
Table 1: Parties
| Exporter | Importer | |
|---|---|---|
| Start date | The date this DPA takes effect under Section 2.1 | |
| Parties' details | As set out in Annex I.A | As set out in Annex I.A |
| Key contact | The account owner, as recorded on the Company's Waitlister account | The data protection contact of Lemon Tree Ventures, LLC, at devin@waitlister.me |
| Signature | Acceptance of the Terms of Use constitutes signature of this Addendum | Making the Services available constitutes signature of this Addendum |
Table 2: Selected SCCs, modules and selected clauses
The Addendum EU SCCs are the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, including the Appendix Information, as incorporated by Section 13.3 of this DPA.
| Module | In operation | Clause 7 (Docking) | Clause 11 (Option) | Clause 9(a) | Clause 9(a) time period | Personal data received from the Importer combined with personal data collected by the Exporter? |
|---|---|---|---|---|---|---|
| 1 | No | — | — | — | — | — |
| 2 | Yes | Excluded | Excluded | General authorisation | 30 days | No |
| 3 | No | — | — | — | — | — |
| 4 | No | — | — | — | — | — |
Table 3: Appendix information
| Annex 1A — List of Parties | Annex I.A of this DPA |
| Annex 1B — Description of Transfer | Annex I.B of this DPA |
| Annex II — Technical and organisational measures | Annex II of this DPA |
| Annex III — List of Subprocessors | Annex III of this DPA |
Table 4: Ending this Addendum when the Approved Addendum changes
| Which Parties may end this Addendum as set out in Section 19 | Neither Party |
Note: the ICO has stated it intends to update the IDTA and the Addendum during 2026. Section 19 permits the Party selected above to end the Addendum only where a revised Approved Addendum would cause it a substantial, disproportionate and demonstrable increase in its direct costs. Until a revised version is issued, version B1.0 continues to apply.
UK interpretation
For Restricted Transfers subject to the UK GDPR, references in the EU SCCs to the GDPR are read as references to the UK GDPR; references to EU Member State law are read as references to UK law; the competent supervisory authority is the UK Information Commissioner; and Clauses 17 and 18 are replaced by the governing law and jurisdiction provisions of the UK Addendum, being the laws of England and Wales and the courts of England and Wales.
APPENDIX 3 — Switzerland
For Restricted Transfers subject to the Swiss FADP, the EU SCCs apply with the following modifications, in line with the guidance of the Swiss Federal Data Protection and Information Commissioner ("FDPIC"):
- References to the GDPR are read as references to the Swiss FADP, insofar as the transfer is subject to it.
- The competent supervisory authority under Clause 13 and Annex I.C is the FDPIC, insofar as the transfer is governed by the Swiss FADP. Where a transfer is subject to both the GDPR and the Swiss FADP, the FDPIC is competent for the Swiss element and the authority identified in Annex I.C for the EEA element.
- References to a "Member State" do not prevent data subjects in Switzerland from exercising their rights in their place of habitual residence, in accordance with Clause 18(c).
- The governing law under Clause 17 is Swiss law insofar as the transfer is governed exclusively by the Swiss FADP.
APPENDIX 4 — Contact
Questions about this DPA, requests for a counter-signed copy, and requests for the transfer impact assessment referred to in Section 13.10 should be sent to devin@waitlister.me.
