Data Processing Addendum

Effective date: August 2026 · Incorporated into the Terms of Service for all client accounts

This Data Processing Addendum ("DPA") forms part of the agreement between [MNFST, LLC — d/b/a Forever Cited] ("Forever Cited," "we") and the client firm ("Client") and governs our processing of personal data that Client submits to the platform or provides in connection with the services ("Client Personal Data").

1. Roles and Scope

For Client Personal Data, Client is the business/controller and Forever Cited is a service provider / processor (as those terms are defined in the California Consumer Privacy Act and other applicable US state privacy laws). This DPA does not cover data Forever Cited processes for its own purposes as a business (e.g., Client's billing contacts, website analytics), which is governed by our Privacy Policy.

Note for law firms: Client should not submit end-client confidential or privileged information to the platform except where necessary for the services and permitted by Client's professional obligations. Client is responsible for any notices or consents required to share personal data with us.

2. Our Processing Commitments

Forever Cited will:

  • Process Client Personal Data only to provide the services under the agreement and Client's documented instructions, and for no other commercial purpose;
  • Not sell or share Client Personal Data, and not retain, use, disclose, or combine it outside the direct business relationship, except as permitted for service providers under applicable law (e.g., security, deidentified analytics, legal compliance);
  • Ensure personnel and contractors with access are bound by confidentiality obligations;
  • Assist Client, taking into account the nature of the processing, in responding to consumer rights requests (access, correction, deletion, portability, opt-out) that relate to Client Personal Data;
  • Notify Client without undue delay, and in any event within 72 hours, after becoming aware of a confirmed breach of security affecting Client Personal Data, with information reasonably needed for Client's own notification obligations;
  • Notify Client if we determine we can no longer meet our obligations under applicable privacy law, in which case Client may take reasonable steps to stop and remediate unauthorized use;
  • Upon written request at termination, delete or return Client Personal Data within 30 days, except copies required for legal compliance or retained in routine backups (which expire on backup rotation and remain protected);
  • Make available information reasonably necessary to demonstrate compliance and permit reasonable assessments no more than annually — satisfied where possible by summaries of third-party audit reports (e.g., SOC 2) for our subprocessors and a written security questionnaire response.

3. Security Measures

  • Encryption of Client Personal Data in transit (TLS 1.2+) and at rest;
  • Multi-factor authentication for administrative access and available for all client portal users; role-based, least-privilege access controls;
  • Logical tenant separation via row-level security in our database layer;
  • Vendor selection limited to providers maintaining recognized security certifications (e.g., SOC 2 Type II, ISO 27001) as noted below;
  • Error monitoring configured to scrub sensitive fields; secrets management and key rotation;
  • Regular software updates and dependency patching; automated backups with tested restoration;
  • No storage of full payment card numbers by Forever Cited — payments are handled by Stripe, a PCI-DSS Level 1 provider;
  • Incident response procedure with defined severity levels and the breach-notice commitment in Section 2.

4. Subprocessors

Client provides general authorization for the following subprocessors. We will post updates to this list and give account holders at least 15 days' email notice of new subprocessors, during which Client may object on reasonable data-protection grounds; if we cannot resolve an objection, Client may terminate the affected services.

SubprocessorPurposeLocationSecurity posture
Supabase, Inc.Database, authentication, and storage for the client portalUnited StatesSOC 2 Type II; encryption at rest and in transit
Vercel, Inc.Application hosting and content deliveryUnited StatesSOC 2 Type II; ISO 27001
Resend (Plus Five Five, Inc.)Transactional and account email deliveryUnited StatesSOC 2 Type II
Functional Software, Inc. (Sentry)Error tracking and application diagnostics (PII scrubbing enabled)United StatesSOC 2 Type II; ISO 27001
Stripe, Inc.Payment processing, invoicing, and billingUnited StatesPCI-DSS Level 1; SOC 2
Google LLCAnalytics (GA4) and business toolingUnited StatesISO 27001; SOC 2/3
Anthropic, PBCAI processing for support chat and platform AI featuresUnited StatesSOC 2 Type II; API inputs not used to train models per commercial terms

Each subprocessor is bound by a written agreement imposing data-protection obligations no less protective than this DPA to the extent applicable to the services it provides. Forever Cited remains responsible for its subprocessors' performance.

5. Data Location and Transfers

Client Personal Data is processed in the United States. If we ever process Client Personal Data subject to non-US data-protection law, the parties will execute appropriate transfer mechanisms before such processing.

6. Term, Precedence, and Contact

This DPA applies for as long as we process Client Personal Data and survives termination until deletion is complete. If this DPA conflicts with the Terms of Service regarding personal-data processing, this DPA controls. Questions and privacy requests: [PRIVACY-EMAIL], [MNFST, LLC — d/b/a Forever Cited], [ADDRESS]. Clients requiring a countersigned copy of this DPA may request one at the same address.