Skip to main content

Legal

Data Processing Agreement

Last updated April 17, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service available at joinsocialcard.com/terms or, if applicable, any other separate written agreement (the "Agreement" or "Services Agreement"), by and between Social Card, LLC, a Delaware LLC ("Social Card") and the Customer named in the Agreement, pursuant to which Customer has purchased a subscription to access and use the Service (as defined in the Agreement). The parties intend this DPA to be an extension of the Agreement that outlines certain requirements for Social Card's processing of personal data provided or made available by Customer, or collected or otherwise obtained by Social Card, in the course of providing services to Customer.

1. Definitions

For the purposes of this DPA, the following terms shall have the meanings set forth below. Capitalized terms used but not defined herein shall have the meanings given to them in the Agreement.

1.1. "Controller" means the Customer, which determines the purposes and means of the Processing of Personal Data, and has the meaning set forth in Article 4 of the GDPR.

1.2. "Customer" means the entity that has entered into the Agreement with Social Card and on whose behalf Social Card Processes Personal Data under this DPA.

1.3. "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.

1.4. "GDPR" means the General Data Protection Regulation (EU) 2016/679.

1.5. "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4 of the GDPR.

1.6. "Processing" means any operation or set of operations performed on Personal Data as defined in Article 4 of the GDPR.

1.7. "Processor" means Social Card, which Processes Personal Data on behalf of the Controller, and has the meaning set forth in Article 4 of the GDPR.

1.8. "Standard Contractual Clauses" means the standard contractual clauses for the transfer of Personal Data to third countries approved by the European Commission.

1.9. "Sub-processor" means any third party appointed by Social Card to Process Personal Data on behalf of the Controller.

1.10. "UK GDPR" means the GDPR as amended and incorporated into UK law under the UK’s European Union (Withdrawal) Act 2018, and the UK Data Protection Act 2018.

2. Scope and Applicability

2.1. This DPA applies to the processing of Personal Data by Social Card on behalf of the Customer in the course of providing the services under the Agreement.

2.2. The subject matter, nature, and purpose of the processing, the types of Personal Data, and categories of data subjects are described in Appendix 1 to this DPA.

3. Obligations of Social Card

3.1. Social Card shall process Personal Data in accordance with the functionalities and settings provided by the Service, which are configured by the Controller (the admin or user), unless required to do so by Union or Member State law.

3.2. Social Card shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3. Social Card shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to measures described in Appendix 2.

3.4. Social Card shall assist the Controller in ensuring compliance with the Controller's obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to Social Card.

3.5. Social Card shall, at the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data.

3.6. Social Card shall maintain documentation of its data processing activities and security measures and shall make this information available to the Controller upon reasonable written request to demonstrate compliance with this DPA.

3.7. The Controller may audit Social Card's compliance with this DPA by submitting reasonable written requests for information. In response, and subject to Social Card's obligations of confidentiality to other customers and to applicable law, Social Card shall provide written responses to reasonable questionnaires or other written inquiries regarding its data processing activities, security measures, and compliance with this DPA. If and when Social Card obtains independent third-party audit reports or certifications (such as SOC 2 reports or ISO 27001 certifications), Social Card may respond to audit requests by providing copies of such reports or certifications, subject to customary confidentiality obligations. The Controller may submit audit requests no more than once per calendar year, except where an audit is required by a supervisory authority or follows a confirmed Personal Data breach affecting the Controller's Personal Data. The Controller and any third-party representatives engaged by the Controller shall treat information provided by Social Card as confidential.

4. Sub-processors

4.1. The Controller authorizes the use of Sub-processors by Social Card.

4.2. Social Card shall maintain an up-to-date list of its Sub-processors, which shall be made available to the Controller upon request or accessible at joinsocialcard.com/subprocessors. Social Card will notify the Controller of any intended changes concerning the addition or replacement of Sub-processors by updating this list at least 30 days prior to any such changes. The Controller may object to such changes within 30 days of the update. If the Controller objects to a new Sub-processor, Social Card will work with the Controller in good faith to address the Controller's reasonable concerns. If the Controller cannot reach an agreement with Social Card, the Controller may terminate the Agreement by providing written notice to Social Card.

4.3. Social Card shall impose on any Sub-processor the same data protection obligations as set out in this DPA by way of a contract or other legal act.

5. Data Subject Rights

5.1. Taking into account the nature of the processing, Social Card shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.

6. International Transfers

6.1. The Controller acknowledges that Social Card is established in the United States and that the Processing of Personal Data under this DPA will involve the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland (as applicable) to the United States and to other jurisdictions in which Social Card or its Sub-processors operate.

6.2. Where Social Card transfers Personal Data to a third country that has not been the subject of an adequacy decision by the European Commission or the UK government, Social Card shall ensure that such transfer is carried out in compliance with the GDPR and UK GDPR by relying on one or more of the following safeguards, as applicable:

  • the Standard Contractual Clauses adopted by the European Commission on June 4, 2021 (Commission Implementing Decision (EU) 2021/914), as amended or replaced from time to time;
  • the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement, issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018;
  • the EU-U.S. Data Privacy Framework (and the UK Extension and Swiss-U.S. Data Privacy Framework), where the relevant Sub-processor receiving the Personal Data is certified under such framework; or
  • any other lawful transfer mechanism recognized under the GDPR or UK GDPR.

Social Card is not currently certified under the EU-U.S. Data Privacy Framework.

6.3. The Standard Contractual Clauses and UK International Data Transfer Addendum, where they apply to transfers under this DPA, are incorporated by reference into this DPA, with Social Card acting as the "data importer" and the Controller acting as the "data exporter." The parties agree that Modules 2 (controller to processor) or 3 (processor to processor) of the Standard Contractual Clauses apply, as appropriate.

7. Security Breach Notification

7.1. Social Card shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data breach affecting the Controller's Personal Data. Notification under this Section 7 is made to the Controller only; any notification to affected Data Subjects or to supervisory authorities is the responsibility of the Controller in accordance with Articles 33 and 34 of the GDPR and other applicable law.

7.2. The initial notification to the Controller may be based on preliminary information known to Social Card at that time. Such notification shall include, to the extent then known, a description of the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences of the breach, and the measures taken or proposed to address and mitigate the breach. Social Card shall provide further information and updates as they become available.

7.3. Social Card shall cooperate with the Controller and provide such additional information as the Controller may reasonably request to enable the Controller to meet its own notification obligations under the GDPR, UK GDPR, or other applicable data protection laws.

8. Term and Termination

8.1. This DPA shall remain in effect for the duration of the Agreement between the parties, unless terminated in accordance with its terms.

8.2. Upon termination of this DPA for any reason, Social Card shall, at the choice of the Controller, delete or return all Personal Data processed on behalf of the Controller and certify to the Controller that it has done so, unless Union or Member State law requires the storage of such data.

9. Order of Precedence

9.1. In the event of any conflict or inconsistency between this DPA and the Agreement, the terms of this DPA shall prevail with respect to the subject matter of this DPA (namely, the Processing of Personal Data).

9.2. In the event of any conflict or inconsistency between this DPA and the Standard Contractual Clauses or the UK International Data Transfer Addendum (where they apply), the Standard Contractual Clauses or the UK International Data Transfer Addendum shall prevail.

10. CCPA Service Provider Terms

Where Social Card Processes personal information (as defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA")) on behalf of the Controller, and the Controller is a "business" and Social Card is a "service provider" (as those terms are defined in the CCPA), the following additional terms apply to Social Card's Processing of such personal information:

10.1. Social Card shall Process personal information solely for the business purposes set forth in the Agreement, for the purposes of performing the services specified in the Agreement, or as otherwise permitted by the CCPA.

10.2. Social Card shall not (a) sell or share personal information, as those terms are defined in the CCPA; (b) retain, use, or disclose personal information outside of the direct business relationship between Social Card and the Controller, or for any purpose other than the business purposes specified in the Agreement, including retaining, using, or disclosing personal information for a commercial purpose other than providing the services specified in the Agreement; or (c) combine personal information received from the Controller with personal information received from or on behalf of another person, or collected from Social Card's own interactions with consumers, except to the extent permitted by the CCPA.

10.3. Social Card certifies that it understands the restrictions set forth in Section 10.1 and Section 10.2 and will comply with them.

10.4. Social Card shall notify the Controller promptly if it determines that it can no longer meet its obligations under the CCPA. Upon such notice, the Controller may take reasonable and appropriate steps to stop and remediate the unauthorized use of personal information.

10.5. Social Card shall cooperate with the Controller's response to verifiable consumer requests under the CCPA, including requests to delete, access, or correct personal information, to the extent Social Card has Processed such personal information on behalf of the Controller.

Appendix 1: Subject Matter and Details of the Data Processing

  • Subject Matter: The processing of Personal Data as necessary to provide the services described in the Agreement.
  • Nature and Purpose: Processing Personal Data to provide digital business card services.
  • Duration: For the duration of the Agreement.
  • Types of Personal Data: First and last name, email address, telephone number, mailing address, IP address, photographs, social media profiles, job titles, and company information.
  • Categories of Data Subjects: Customers, individual contacts of the Customer, and any other data subjects whose data may be processed pursuant to the Agreement.

Appendix 2: Technical and Organizational Security Measures

  • Access Control: Access to systems that process Personal Data is limited to personnel authorized by Social Card. End-user authentication to the Service uses email-based sign-in links and/or password-based authentication with session management.
  • Data Encryption: Personal Data is encrypted in transit using industry-standard TLS and encrypted at rest using the encryption provided by Social Card's cloud infrastructure providers.
  • Network and Platform Security: Social Card relies on its cloud infrastructure providers for network-level protections, including DDoS mitigation, firewalls, and related controls. Current infrastructure providers are listed on the Social Card Sub-Processors page.
  • Monitoring and Vulnerability Management: Social Card conducts ongoing monitoring of its systems for security issues and performs periodic vulnerability scans.
  • Incident Response: Social Card maintains procedures for identifying, investigating, containing, and responding to security incidents affecting Personal Data, including the notification procedures set forth in Section 7 of this DPA.
  • Data Minimization and Retention: Social Card limits the collection of Personal Data to what is necessary for the purposes for which it is Processed and retains Personal Data only for as long as necessary for those purposes or as required by applicable law.