Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the Terms of Service entered into between you, the Creator ("Controller" under the LGPD or GDPR), and Sevn Solutions LLC ("Connekit", "Processor" under the LGPD or GDPR), and governs the processing of personal data of Visitors to your Media Kit carried out by Connekit on your behalf.
This DPA does not apply to the data of your own Account as a Creator — that processing is governed by our Privacy Policy, under which Connekit acts as Controller.
1. Definitions
- Controller (LGPD/GDPR): you, the Creator, who decides which Visitor data is collected and displayed on your Media Kit.
- Processor (LGPD/GDPR): Connekit, which processes Visitor data solely to operate the Media Kit infrastructure on your behalf, following your documented instructions (the Terms of Service and this DPA).
- Personal Data: any information relating to an identified or identifiable natural person.
- Data Subject: the natural person to whom the Personal Data relates — in the context of this DPA, primarily Visitors to your Media Kit.
- Subprocessor: a third party engaged by Connekit to assist in processing Personal Data on the Controller's behalf, listed on our Subprocessors page.
2. Roles of the parties
With respect to your Media Kit's Visitor data, you act as Controller (LGPD/GDPR) and Connekit acts as Processor (LGPD/GDPR). Connekit processes this data only to operate and make your Media Kit available, in accordance with your documented instructions, and does not use it for any purpose of its own.
You are responsible for ensuring you have a legal basis to collect and publish the Visitor data displayed on your Media Kit (for example, information provided by a Visitor when contacting you through the channels you make available).
3. Subject matter, duration, nature and purpose of processing
| Aspect | Description |
|---|---|
| Subject matter | Hosting and technical operation of the Media Kit published by the Controller, including processing of Visitor interactions with that page. |
| Duration | For as long as the Controller's Account remains active on Connekit, ending under Section 8 (Deletion and return of data) after the contract ends. |
| Nature of processing | Storage, hosting, technical logging and making the Media Kit's public page available. |
| Purpose | Enabling the Controller's Media Kit to be accessed, displayed and used by Visitors, including aggregated audience metrics and abuse protection. |
4. Data types and categories of data subjects
Categories of data subjects: Visitors to the Media Kit published by the Controller (e.g. brand representatives, potential business partners).
- Technical browsing data: IP address, device type, pages accessed and access time;
- Data voluntarily provided by the Visitor when contacting through the channels shown on the Media Kit (name, email, message), where applicable;
- Aggregated audience metrics, with no individual identification of the Visitor.
5. Processor obligations
- Confidentiality: treat the Personal Data as confidential and ensure anyone authorized to process it is subject to a confidentiality obligation.
- Security: adopt technical and organizational measures consistent with the state of the art to protect the Personal Data against unauthorized access, loss or accidental destruction.
- Assistance with data subject requests (DSRs): assist the Controller, to a reasonable extent, in responding to Visitor requests relating to access, correction or deletion of their data, when Connekit is technically able to fulfill them.
- Incident notification: notify the Controller within 48 (forty-eight) hours of becoming aware of a security incident affecting the Personal Data processed under this DPA, describing the nature of the incident, the data possibly affected, and the measures taken or recommended.
- Documented instructions: process the Personal Data only in accordance with the Controller's documented instructions (the Terms of Service, this DPA, and settings made by the Controller in the Media Kit editor), except where otherwise required by applicable law.
6. Authorized subprocessors
The Controller generally authorizes Connekit to use the subprocessors listed on our Subprocessors page to help provide the service.
Connekit will notify the Controller, with reasonable advance notice, of the addition of a new subprocessor. The Controller may object to such addition, in writing and with reasonable justification related to data protection, within 10 (ten) calendar days of the notice, by emailing hello@connekit.me. If the parties cannot reach a resolution, the Controller may close their Account without penalty, solely on account of that objection.
7. International transfers
Personal Data processed under this DPA may be transferred to and stored in the United States, where Connekit and its subprocessors operate their infrastructure. Where applicable, these transfers are supported by Standard Contractual Clauses (SCCs), recognized by the LGPD and the GDPR as a valid international transfer mechanism, ensuring an adequate level of protection for the transferred Personal Data.
8. Deletion and return of data at the end of the contract
At the end of the contract between the Controller and Connekit, for any reason, Connekit will delete or return to the Controller, at the Controller's choice, all Personal Data processed under this DPA, except to the extent retention is required by applicable law.
Requests to return data must be sent to support@connekit.me within 30 days after the contract ends.
9. Incorporation into the Terms of Service
This DPA becomes an integral part of, and is automatically incorporated into, Connekit's Terms of Service as of its effective date, with no need for a separate signature, and applies to every Creator who uses Connekit to publish a Media Kit accessible to Visitors.
10. Contact
Questions about this DPA can be sent to hello@connekit.me.