Data Processing Agreement

Last updated: August 14, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Anneshy Royals Inc., a California corporation doing business as OptimizePlus, 28 Geary St., Suite 650, San Francisco, CA 94108 ("Processor", "we"), and the customer identified in the applicable order ("Controller", "you"). It applies where we process personal data on your behalf.

0. Scope — United States customers

This DPA is offered for customers whose data subjects are located in the United States. We do not currently offer standard contractual clauses, a UK international data transfer addendum, or any other EU or UK transfer mechanism. If you have data subjects in the EEA, the United Kingdom, or Switzerland, do not sign this DPA — contact us first so the right terms can be put in place.

1. Roles of the parties

You are the Controller and determine the purposes and means of processing. We are the Processor and process personal data only on your documented instructions, which for these purposes are the Terms of Service, this DPA, and your use of the service.

Where we process data for our own purposes — billing, fraud prevention, service security, and aggregate product improvement — we act as an independent controller for that limited processing.

2. Subject matter, duration, nature and purpose

Subject matter: provision of AI-assisted marketing content production, website audits, and related services.

Duration: for the term of the Terms of Service, subject to §9 below, which you should read carefully because it does not follow the usual pattern.

Nature and purpose: storing, transmitting to subprocessors, analyzing and generating content from the material you supply, in order to produce the deliverables you request.

3. Categories of data subjects

Your personnel and account users; individuals appearing in photographs, video or audio you upload; and individuals whose details appear in material you supply to us.

We do not require, and ask you not to upload, special-category data (health, biometric, racial or ethnic origin, religious belief, sexual orientation), payment card numbers, government identifiers, or data relating to children. If your business is such that uploaded imagery could constitute health-adjacent data — for example before-and-after treatment photographs — tell us before uploading so we can agree how it is handled.Do not upload patient images, treatment records, or any health information. We are not a HIPAA business associate and our systems are not designed to hold health data.

4. Categories of personal data

Contact and account data (name, business name, email address, telephone number, hashed password); business profile and brand information; files you upload (photographs, video, audio, documents); content generated for you; usage and metering records; and billing records.

We do not store payment card details. Card payments are processed by Stripe on Stripe-hosted pages, and card numbers never reach our systems.

5. Subprocessors

You give general written authorization for us to engage subprocessors. Our current subprocessors — including the AI providers that generate your deliverables, our object storage provider, and our payment and email providers — are listed and kept current at optimizeplus.agency/legal/subprocessors.

We remain responsible for our subprocessors' performance of their obligations. We will make reasonable efforts to notify you in advance of a new subprocessor and to give you a reasonable opportunity to object. We give at least thirty (30) days' notice by email before a new subprocessor begins processing your data.

We have not independently verified that a data processing agreement is in place with every subprocessor listed. Where one is required for your compliance posture, raise it with us before signing.

6. International transfers

Files you upload — photographs, audio, generated media, and PDF reports — are stored with our object storage provider in Nuremberg, Germany. Our application database and servers are operated from our hosting provider's infrastructure, and several of the AI providers that process your content are established in the United States.

Processing your content therefore involves transfers between the European Union and the United States. We describe this factually so you can assess it. We make no adequacy determination and offer no standard contractual clauses at this time.

7. Security measures

These are the measures we actually operate. We have deliberately not listed controls we do not have.

  • Encryption in transit (TLS) for all traffic to our public endpoints.
  • Passwords hashed with argon2. API keys stored only as a SHA-256 hash and shown once at creation.
  • Session cookies set httpOnly, secure and sameSite, with a fixed expiry, revocable, and all sessions invalidated on password reset.
  • AES-256-GCM encryption of stored third-party social credentials. This is the only application-layer encryption at rest we operate; other data, including uploaded files, is not separately encrypted at the application layer.
  • Tenant isolation enforced in middleware: a caller-supplied account identifier is overwritten with the authenticated principal's own and mismatches are rejected, so services never act on an account the caller does not own.
  • Rate limiting on authentication and signup endpoints. Internal services are not exposed publicly.
  • No staff impersonation capability. Staff access to a customer account is read-only for viewing and separately logged for actions.

We do not currently offer multi-factor authentication, and we hold no SOC 2, ISO 27001 or equivalent certification.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and provide the information reasonably available to us to assist your own notification obligations.

We do not currently commit to a fixed notification deadline, because we do not yet operate a documented incident response process and we will not promise a timeline we cannot demonstrate.

9. Deletion and return — read this clause carefully

This clause does not follow the usual pattern, and we would rather tell you than have you assume otherwise. We do not operate automatic deletion of your business data or the work we produce for you. That content is retained indefinitely unless you ask us to remove it.

We do run a daily sweep that removes expired login sessions, spent password-reset and email-verification tokens, and internal operational logs older than 90 days. That sweep touches no customer content, no account record and no financial record.

On written request to legal@optimizeplus.agency we will delete or return personal data we process on your behalf. Account deletion and data export are now real, implemented operations rather than manual database work, and a deletion is recorded in an audit log that outlives the account.

The following are retained after any such request, and you should factor this in:

  • Billing and payment records, including invoices and the record of what was charged, which we retain for tax and accounting purposes.
  • Internal cost and usage metering records. These are retained with the account identifier removed, and are kept because they are our own cost history rather than your personal data.
  • Records we are required to keep by law.

We will delete your personal data within thirty (30) days of a verified deletion request, except for the records listed above that we are required to keep.

10. Assistance and data subject rights

Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to data subject requests to access, correct, delete or port personal data we hold on your behalf, and to meet your obligations regarding security, breach notification and impact assessments.

If a data subject contacts us directly about data we process for you, we will refer them to you rather than respond substantively, unless you instruct otherwise.

Assistance is provided manually. We do not currently offer a self-service export or deletion tool to customers.

11. Confidentiality

We ensure that personnel authorized to process personal data are bound by an appropriate duty of confidentiality, and we limit access to those who need it to deliver the service or support your account.

12. Audit

On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, we will make available information reasonably necessary to demonstrate compliance with this DPA and respond to reasonable written security questionnaires.

13. AI processing of your content

Producing your deliverables necessarily involves transmitting the material you supply — including any personal data within it — to the AI providers listed in our subprocessor list. That transmission is the service, not an incidental feature of it.

We make no representation about whether any given AI provider uses submitted content to train its models. That is determined by each provider's own terms and must be verified provider-by-provider.

Deliverables are AI-generated. See our AI Content Disclosure for what that means for ownership and copyright.

14. Liability and governing law

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA is governed by the laws of the State of California, without regard to its conflict of laws rules.

15. Order of precedence

In the event of a conflict between this DPA and the Terms of Service in relation to the processing of personal data, this DPA prevails.

Requesting a signed copy

To request an executable copy of this agreement, email legal@optimizeplus.agency. Note that the items marked for review above are unresolved, and this document should not be executed until they are.