SPRINKLING ACT · LEGAL
Data Processing Agreement
Version 3.0 · March 1, 2026
This document describes how Sprinkling Act processes personal data and lists our sub-processors, in accordance with GDPR Article 28.
1. Roles
Sprinkling Act determines the purposes and means of processing personal data collected through sprinklingact.com.
Data Subjects: Users of the Sprinkling Act service (account holders, diagnostic users, waitlist subscribers, newsletter subscribers, and site visitors who consent to analytics).
2. Sub-processors
Supabase Inc.
Service: Database, authentication, storage
Location: European Union
Data: Account, diagnostic, waitlist, newsletter, analytics
Vercel Inc.
Service: Hosting, CDN, serverless
Location: Global edge (EU primary)
Data: Server logs, request metadata
DPA: vercel.com/legal/dpa
Resend Inc.
Service: Transactional email
Location: United States
Data: Email addresses, email content
DPA: resend.com/legal/dpa
Stripe Payments Europe Ltd
Service: Payment processing
Location: Ireland (EU)
Data: Payment and billing info
DPA: stripe.com/legal/dpa
Sentry (Functional Software Inc.)
Service: Error monitoring
Location: United States
Data: Request metadata (IP, user agent, error context)
DPA: sentry.io/legal/dpa
3. Processing Instructions
· Providing the diagnostic and reporting service
· Sending transactional and notification emails
· Processing payments via Stripe
· Analytics (only with explicit consent)
Sprinkling Act will not process personal data for any other purpose without prior written instruction.
4. International Transfers
Resend Inc. (United States), Transactional emails. Transfer mechanism: EU Standard Contractual Clauses (SCCs) Module Two (Controller to Processor), as incorporated in Resend's DPA.
Vercel Inc. (Global edge network), Hosting. Transfer mechanism: EU Standard Contractual Clauses (SCCs) as incorporated in Vercel's DPA.
Sentry (United States), Error monitoring. Transfer mechanism: EU Standard Contractual Clauses (SCCs) as incorporated in Sentry's DPA.
Sub-processors located within the EU/EEA (Supabase, Stripe) do not require additional transfer mechanisms under GDPR Chapter V.
5. Security Measures
· HSTS with preloading
· Content Security Policy enforced
· Row Level Security on all database tables
· Passwords hashed (bcrypt via Supabase Auth)
· No plaintext storage of sensitive data
· Production access limited to data controller
· Regular dependency updates
· Session-based authentication with automatic expiry
6. Breach Notification
· Notify the Belgian Data Protection Authority (APD/GBA) within 72 hours (GDPR Article 33)
· Notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34)
· Provide a description of the breach, categories of data affected, estimated number of data subjects, and measures taken or proposed
7. Audit Rights
8. Data Deletion
9. Duration & Hierarchy
10. Contact
Email : legal@sprinklingact.com
BCE : BE 1034.962.482
Avenue des Arts 19 BT 2, 1210 Brussels, Belgium
Supervisory Authority : Autorité de protection des données (APD/GBA), Brussels, Belgium