Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between MNFST INC — d/b/a Forever Cited ("Forever Cited," "we") and the client firm ("Client") and governs our processing of personal data that Client submits to the platform or provides in connection with the services ("Client Personal Data").
1. Roles and Scope
For Client Personal Data, Client is the business/controller and Forever Cited is a service provider / processor (as those terms are defined in the California Consumer Privacy Act and other applicable US state privacy laws). This DPA does not cover data Forever Cited processes for its own purposes as a business (e.g., Client's billing contacts, website analytics), which is governed by our Privacy Policy.
Note for law firms: Client should not submit end-client confidential or privileged information to the platform except where necessary for the services and permitted by Client's professional obligations. Client is responsible for any notices or consents required to share personal data with us.
2. Our Processing Commitments
Forever Cited will:
- Process Client Personal Data only to provide the services under the agreement and Client's documented instructions, and for no other commercial purpose;
- Not sell or share Client Personal Data, and not retain, use, disclose, or combine it outside the direct business relationship, except as permitted for service providers under applicable law (e.g., security, deidentified analytics, legal compliance);
- Ensure personnel and contractors with access are bound by confidentiality obligations;
- Assist Client, taking into account the nature of the processing, in responding to consumer rights requests (access, correction, deletion, portability, opt-out) that relate to Client Personal Data;
- Notify Client without undue delay, and in any event within 72 hours, after becoming aware of a confirmed breach of security affecting Client Personal Data, with information reasonably needed for Client's own notification obligations;
- Notify Client if we determine we can no longer meet our obligations under applicable privacy law, in which case Client may take reasonable steps to stop and remediate unauthorized use;
- Upon written request at termination, delete or return Client Personal Data within 30 days, except copies required for legal compliance or retained in routine backups (which expire on backup rotation and remain protected);
- Make available information reasonably necessary to demonstrate compliance and permit reasonable assessments no more than annually — satisfied where possible by summaries of third-party audit reports (e.g., SOC 2) for our subprocessors and a written security questionnaire response.
3. Security Measures
- Encryption of Client Personal Data in transit (TLS 1.2+) and at rest;
- Multi-factor authentication for administrative access and available for all client portal users; role-based, least-privilege access controls;
- Logical tenant separation via row-level security in our database layer;
- Vendor selection limited to providers maintaining recognized security certifications (e.g., SOC 2 Type II, ISO 27001) as noted below;
- Error monitoring configured to scrub sensitive fields; secrets management and key rotation;
- Regular software updates and dependency patching; automated backups with tested restoration;
- No storage of full payment card numbers by Forever Cited — payments are handled by Stripe, a PCI-DSS Level 1 provider;
- Incident response procedure with defined severity levels and the breach-notice commitment in Section 2.
4. Subprocessors
Client provides general authorization for the following subprocessors. We will post updates to this list and give account holders at least 15 days' email notice of new subprocessors, during which Client may object on reasonable data-protection grounds; if we cannot resolve an objection, Client may terminate the affected services.
| Subprocessor | Purpose | Location | Security posture |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, and storage for the client portal | United States | SOC 2 Type II; encryption at rest and in transit |
| Vercel, Inc. | Application hosting and content delivery | United States | SOC 2 Type II; ISO 27001 |
| Resend (Plus Five Five, Inc.) | Transactional and account email delivery | United States | SOC 2 Type II |
| Functional Software, Inc. (Sentry) | Error tracking and application diagnostics (PII scrubbing enabled) | United States | SOC 2 Type II; ISO 27001 |
| Stripe, Inc. | Payment processing, invoicing, and billing | United States | PCI-DSS Level 1; SOC 2 |
| Google LLC | Analytics (GA4) and business tooling | United States | ISO 27001; SOC 2/3 |
| Anthropic, PBC | AI processing for support chat and platform AI features | United States | SOC 2 Type II; API inputs not used to train models per commercial terms |
Each subprocessor is bound by a written agreement imposing data-protection obligations no less protective than this DPA to the extent applicable to the services it provides. Forever Cited remains responsible for its subprocessors' performance.
5. Data Location and Transfers
Client Personal Data is processed in the United States. If we ever process Client Personal Data subject to non-US data-protection law, the parties will execute appropriate transfer mechanisms before such processing.
6. Term, Precedence, and Contact
This DPA applies for as long as we process Client Personal Data and survives termination until deletion is complete. If this DPA conflicts with the Terms of Service regarding personal-data processing, this DPA controls. Questions and privacy requests: hello@forevercited.ai, MNFST INC — d/b/a Forever Cited, [ADDRESS]. Clients requiring a countersigned copy of this DPA may request one at the same address.