Legal

Data Processing Addendum

Effective Date: July 19, 2026Last Updated: July 19, 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Terms of Service or master services agreement between Be Belong Group Corp, a Delaware corporation ("Be Belong," "Processor"), and the Advertiser identified in the applicable order form ("Advertiser," "Controller"). It applies to the extent Be Belong Processes Personal Data on Advertiser's behalf in connection with the Launchpad platform and related services (the "Services").

In plain terms

This document is what your Data Protection Officer or privacy counsel needs. It says who is a controller and who is a processor, which vendors we use, how we move data across borders, and what happens if there is a breach. It sits on top of the Terms of Service — the Terms still govern commercial matters.

1. Parties & Roles

For Personal Data that Advertiser uploads or otherwise makes available to the Services in order to build, target, launch, or measure a Campaign — including business contacts, first-party audiences, and creative or product content ("Advertiser Personal Data") — Advertiser is the Controller and Be Belong acts as Processor (or Sub-Processor where Advertiser itself acts on behalf of another controller).

For Earner Personal Data collected by Be Belong through RentGain, CollegeGain, and related consumer-facing products (KYC data, wallet activity, engagement events, Consumer Insights), Be Belong acts as an independent Controller. See Section 15.

2. Definitions

Terms used but not defined in this DPA have the meaning given in the Terms of Service. "Applicable Data Protection Laws" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended by the CPRA, and every other data protection, privacy, or e-privacy law that applies to a party's Processing. "Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Supervisory Authority," and "Personal Data Breach" have the meanings given in the GDPR.

3. Scope & Duration

This DPA applies for the term of the Terms of Service and any period during which Be Belong retains Advertiser Personal Data under Section 13.

4. Details of Processing (Annex I to EU SCCs)

  • Subject matter: provision of the Services to Advertiser.
  • Nature and purpose: hosting, storage, formatting, matching, targeting, delivery, measurement, analytics, model training on Submitted Assets, security, fraud prevention, and customer support.
  • Categories of Data Subjects: Advertiser's employees, contractors, and Authorized Users; the Advertiser's own customers or prospects to the extent uploaded to the Services (e.g., suppression lists or first-party audiences).
  • Categories of Personal Data: contact identifiers (name, business email, phone), professional role, account credentials, IP address, device identifiers, campaign creative and metadata, and any Personal Data contained in files or datasets Advertiser chooses to upload.
  • Special categories: none intended. Advertiser must not upload special-category data unless previously agreed in writing with Be Belong.
  • Frequency: continuous for the duration of the Services.
  • Retention: as set out in the Terms of Service Section 12 and this DPA Section 13.

5. Processor Obligations

Be Belong will:

  • Process Advertiser Personal Data only on documented instructions from Advertiser (including through use of the Services) and as necessary to comply with Applicable Data Protection Laws;
  • ensure personnel authorized to Process Advertiser Personal Data are bound by confidentiality obligations;
  • implement and maintain the security measures described in Section 7 and Annex II;
  • engage Subprocessors only under Section 8;
  • assist Advertiser with Data Subject requests, DPIAs, prior consultations, and Supervisory Authority inquiries taking into account the nature of Processing and information reasonably available;
  • notify Advertiser of Personal Data Breaches under Section 11;
  • make available information necessary to demonstrate compliance under Section 12; and
  • on termination, return or delete Advertiser Personal Data under Section 13.

6. Controller Obligations

Advertiser (a) has and will maintain a valid legal basis for the Processing, including any onward transfer to Be Belong; (b) has provided all required notices and, where required, obtained all necessary consents from Data Subjects; (c) will not instruct Be Belong to Process Personal Data in violation of Applicable Data Protection Laws; and (d) is responsible for the accuracy of Advertiser Personal Data provided to the Services.

7. Security Measures (Annex II)

Be Belong maintains the following technical and organizational measures ("TOMs") appropriate to the risk presented by the Processing:

  • Encryption in transit using TLS 1.2 or higher for all public endpoints and internal service-to-service traffic where feasible.
  • Encryption at rest for production databases, object storage, and backups using AES-256 or provider-managed equivalent.
  • Access control: role-based access with least-privilege, SSO for internal tooling, and mandatory MFA for privileged accounts.
  • Network segmentation between production, staging, and analytics environments; private-network egress from the application tier to data stores.
  • Secrets management via a dedicated vault; no long-lived secrets in source code.
  • Logging & monitoring: centralized audit logs, alerting on anomalous access, and 12-month retention of application security logs.
  • Vulnerability management: automated dependency scanning, static analysis on merge, and remediation SLAs (critical: 7 days; high: 30 days).
  • Backup & recovery: encrypted daily backups with tested restore procedures.
  • Personnel: background checks where legally permissible, mandatory annual privacy and security training, and confidentiality obligations in employment or contractor agreements.
  • Vendor management: written contracts requiring equivalent safeguards for every Subprocessor.
  • Incident response: documented plan, defined roles, and post-incident review.

8. Subprocessors (Annex III)

Advertiser grants general written authorization for Be Belong to engage Subprocessors. Current Subprocessors:

SubprocessorRoleProcessing location
Supabase, Inc. (Postgres, Auth, Storage, Edge)Application database, authentication, file storage, serverless computeUnited States (primary region)
Cloudflare, Inc.Edge compute (Workers), CDN, DNS, DDoS protectionGlobal edge network
Google LLC (Gemini via Lovable AI Gateway)Generative AI for onboarding, matching prompts, support triageUnited States / EU
Stripe, Inc.Card acceptance, invoicing, taxUnited States / EU (region-based)
KYC / identity-verification vendor [COMPANY TO CONFIRM]Government-ID verification, liveness, sanctions screeningUnited States
Email / SMS delivery vendor [COMPANY TO CONFIRM]Transactional notifications, magic links, alertsUnited States
Analytics / product telemetry [COMPANY TO CONFIRM]Aggregated product-usage analyticsUnited States / EU

Be Belong will (a) enter written agreements with each Subprocessor imposing data protection obligations no less protective than this DPA, (b) remain liable for each Subprocessor's acts and omissions, and (c) provide at least thirty (30) days' prior notice of the addition or replacement of a Subprocessor via email or an in-app notice. Advertiser may object in writing on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Advertiser may terminate the affected Services on notice.

9. International Data Transfers

Where the Processing involves the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not subject to an adequacy decision, the parties agree that:

  • EEA transfers: the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, "EU SCCs") are incorporated by reference. Where Advertiser is the data exporter and Be Belong the importer, Module Two (Controller-to-Processor) applies. Where Advertiser itself acts on behalf of another controller, Module Three (Processor-to-Processor) applies. Clause 7 (docking) is included; Clause 9(a) Option 2 (general written authorization) applies with the notice period in Section 8; Clause 11(a) Option (independent dispute resolution) does not apply; Clause 17 Option 1 — governing law: Ireland; Clause 18(b) — supervising court: Ireland. Annexes I, II, and III of the EU SCCs are populated by Sections 4, 7, and 8 respectively.
  • UK transfers: the UK International Data Transfer Addendum (Version B1.0, in force 21 March 2022) is incorporated and modifies the EU SCCs accordingly.
  • Swiss transfers: the EU SCCs apply as modified to comply with the FADP, references to the GDPR are read as references to the FADP where applicable, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed exclusively by Swiss law.
  • U.S. transfers: Be Belong will, where certified and available, rely on the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework, as a further safeguard for its onward transfers to certified U.S. Subprocessors. [COMPANY TO CONFIRM current DPF self-certification status.]
  • Supplementary measures: encryption in transit and at rest, minimization to what is required to deliver the Services, contractual challenge of overbroad government access requests, and publication of any transparency reports the law permits.

10. Data Subject Rights & Assistance

Be Belong will make available to Advertiser, through the Services or on written request, functionality to respond to Data Subject requests concerning Advertiser Personal Data (access, rectification, erasure, restriction, portability, and objection). If Be Belong receives a Data Subject request directly, it will (unless legally prohibited) redirect the Data Subject to Advertiser without responding on Advertiser's behalf. Advertisers can manage their own Data Subject requests through the in-product Data Controls page at /data-controls.

11. Personal Data Breach

Be Belong will notify Advertiser without undue delay and in any event within seventy-two (72) hours after becoming aware of a confirmed Personal Data Breach affecting Advertiser Personal Data. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects. Be Belong will cooperate with Advertiser's investigation and, where legally required, with the competent Supervisory Authority.

12. Audits & Records

Be Belong will make available to Advertiser, on written request, the information necessary to demonstrate compliance with this DPA, including its then-current SOC 2 Type II or equivalent third-party report where available. Advertiser may audit no more than once every twelve (12) months, on at least thirty (30) days' written notice, at Advertiser's cost, during business hours, subject to reasonable confidentiality and security controls. Supervisory Authority audits required by Applicable Data Protection Laws are not subject to these limits.

13. Return / Deletion

On termination of the Services, or on Advertiser's written request, Be Belong will delete or return Advertiser Personal Data within a reasonable period, except (a) to the extent required by law (e.g., KYC/AML records up to seven (7) years, tax and billing records up to seven (7) years, security and audit logs up to twenty-four (24) months); and (b) copies retained in encrypted backups, which will be deleted in the ordinary backup cycle. Retained Personal Data remains subject to this DPA.

14. Liability & Order of Precedence

The liability provisions of the Terms of Service apply to claims arising under this DPA. In the event of a conflict between this DPA and the Terms of Service with respect to the Processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the EU SCCs / UK IDTA / Swiss addendum, those instruments control to the extent legally required.

15. Consumer-Facing Data (Independent Controller)

Nothing in this DPA makes Be Belong a Processor of Earner Personal Data. Be Belong is an independent Controller of (i) all data collected directly from Earners through RentGain and CollegeGain, (ii) all engagement events generated by Earners on the Be Belong network, and (iii) all Consumer Insights derived therefrom. Advertiser has no independent right to Earner Personal Data, other than as expressly granted for a specific opted-in fulfillment (e.g., a shipping address for a physical product sample), and only for that fulfillment. Any use of Consumer Insights for external publication or advertising requires Be Belong's prior written consent, captured through the in-product consent flow.

16. U.S. State Privacy Addendum

For Personal Information subject to the CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA, FDBR, DPDPA, and other applicable U.S. state privacy laws, Be Belong acts as a "service provider" or "processor" (as defined in the relevant law) with respect to Advertiser Personal Data. Be Belong will not (a) sell or share such Personal Information, (b) retain, use, or disclose it outside the direct business relationship, or (c) combine it with Personal Information received from other sources except to perform a business purpose permitted by law. Be Belong will notify Advertiser if it can no longer meet these obligations.

17. Signature & Effective Date

Advertiser accepts this DPA by (i) clicking "I agree" during checkout or in-product, (ii) executing a written order form that references this DPA, or (iii) continuing to use the Services after the effective date at the top of this page. A countersigned PDF is available on written request to privacy@bebelong.group.