DATA PROCESSING ADDENDUM (DPA)
for Checklists ’R Us
Last updated: June 17, 2026
This Data Processing Addendum (“Addendum” or “DPA”) forms part of the Terms & Conditions or other written agreement (“Agreement”) between the customer (“Customer,” “you,” or “your”) and Checklists ’R Us (“Company,” “we,” “our,” or “us”).
This Addendum governs our processing of Personal Data on your behalf when you use our Services.
1. Definitions
For purposes of this Addendum:
-
“Personal Data” means any information relating to an identified or identifiable natural person.
-
“Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
-
“Controller” means the party that determines the purposes and means of processing Personal Data.
-
“Processor” means the party that processes Personal Data on behalf of the Controller.
-
“Applicable Data Protection Laws” includes GDPR, CCPA/CPRA, and any other privacy laws relevant to the Customer’s jurisdiction.
-
“Services” means the digital products, checklists, frameworks, and related tools provided by Checklists ’R Us.
2. Roles of the Parties
-
Customer is the Controller of Personal Data submitted through the Services.
-
Checklists ’R Us acts as a Processor with respect to that Personal Data.
-
For Personal Data we collect directly (e.g., for account creation, billing, analytics), we act as an independent Controller.
3. Scope of Processing
We process Personal Data solely for:
-
Providing and maintaining the Services
-
Delivering purchased digital products
-
Supporting account access and authentication
-
Handling customer support requests
-
Improving product performance and user experience
-
Complying with legal obligations
We do not process Personal Data for any purpose not described in this Addendum.
4. Customer Responsibilities
Customer agrees to:
-
Ensure lawful collection and transfer of Personal Data
-
Provide accurate instructions to Checklists ’R Us
-
Maintain appropriate legal bases for processing
-
Comply with all applicable privacy laws
If you need help understanding your responsibilities, use Privacy Guidance.
5. Company Responsibilities
We will:
-
Process Personal Data only according to Customer’s documented instructions
-
Maintain appropriate technical and organizational security measures
-
Ensure personnel with access to Personal Data are bound by confidentiality
-
Notify Customer of any data breach affecting Personal Data
-
Assist Customer with data‑subject requests where legally required
-
Delete or return Personal Data upon termination of the Agreement
6. Sub‑Processors
We may engage third‑party service providers (“Sub‑Processors”) to support the Services (e.g., hosting, analytics, payment processing).
We will:
-
Use only reputable Sub‑Processors
-
Require Sub‑Processors to meet equivalent data‑protection obligations
-
Remain responsible for their performance
A list of Sub‑Processors is available upon request via Sub‑Processor Inquiry.
7. International Data Transfers
If Personal Data is transferred outside the Customer’s jurisdiction:
-
We will use lawful transfer mechanisms (e.g., Standard Contractual Clauses)
-
We will ensure adequate protection consistent with Applicable Data Protection Laws
8. Security Measures
We implement administrative, technical, and physical safeguards appropriate to the risk, including:
-
Encryption in transit
-
Access controls and authentication
-
Secure hosting environments
-
Regular monitoring and vulnerability management
-
Data minimization and retention controls
For a detailed overview, request Security Overview.
9. Data Breach Notification
In the event of a confirmed Personal Data breach, we will:
-
Notify Customer without undue delay
-
Provide known details of the breach
-
Cooperate in remediation and mitigation efforts
10. Data Subject Rights
Where legally required, we will assist Customer in responding to:
-
Access requests
-
Correction requests
-
Deletion requests
-
Objections or restrictions
-
Data portability requests
We will not respond directly to data subjects unless legally obligated.
11. Data Retention & Deletion
Upon termination of the Agreement or upon Customer request:
-
We will delete or return Personal Data, unless retention is required by law
-
Backups containing Personal Data will be deleted on their normal lifecycle schedule
To request deletion, use Data Deletion Request.
12. Audit Rights
Customer may request information necessary to demonstrate compliance with this Addendum.
Formal audits may be conducted:
-
With reasonable notice
-
Without disrupting operations
-
Subject to confidentiality obligations
13. Liability
Liability under this Addendum is subject to the limitations set forth in the Agreement.
Nothing in this Addendum expands either party’s liability beyond what is stated in the Agreement.
14. Conflicts
If any provision of this Addendum conflicts with the Agreement, this Addendum controls with respect to data‑processing obligations.
15. Governing Law
This Addendum is governed by the same jurisdiction as the Agreement:
The State of Florida, without regard to conflict‑of‑law principles.
16. Contact Information
For privacy or data‑processing questions, contact us through the Support Page.
