Founding Beta is open. A limited cohort shaping the platform.  Apply for access →
Legal

Data Processing Agreement

Last updated: May 1, 2026

How Snapn processes personal data on your behalf as a processor, including residency, sub-processing, and security commitments. A signed copy is available on request.

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Snapn, Inc. ("Processor") for the provision of the Services.

For personal data processed on the Controller's behalf, the Controller determines the purposes and means of processing, and Snapn acts as Processor.

2. Nature and purpose of processing

Snapn processes personal data only to provide and support the Services, in accordance with the Controller's documented instructions, including the configuration choices made in the product (such as hosting region and AI model selection).

3. Categories of data and data subjects

Data subjects may include the Controller's personnel and any individuals appearing in captured guide content. Categories of data may include:

  • Identifiers such as names and work email addresses.
  • Guide content, including screenshots and annotations that may contain personal data.
  • Usage and diagnostic data associated with accounts.

4. Data residency and sub-processing

Personal data is stored in the region selected by the Controller (US, EU, Canada, or UAE) and is not replicated to other regions.

Snapn engages vetted sub-processors (for example, cloud infrastructure providers) under written terms no less protective than this DPA. A current list of sub-processors is available on request, and we provide notice of material changes.

5. Security measures

Snapn implements appropriate technical and organizational measures, including encryption in transit and at rest, access controls, audit logging, and regular security testing.

Sensitive fields are masked at capture, and Enterprise plans support automated PII redaction.

6. International transfers

Where processing involves a transfer of personal data across borders, Snapn relies on appropriate safeguards such as the Standard Contractual Clauses, supplemented by additional measures where required.

7. Assistance with data subject rights

Taking into account the nature of processing, Snapn assists the Controller with appropriate measures to respond to data subject requests and to fulfil obligations relating to security, breach notification, and impact assessments.

8. Personal data breach

Snapn notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides information reasonably necessary for the Controller to meet its notification obligations.

9. Return and deletion

On termination of the Services, Snapn deletes or returns personal data in accordance with the Terms — typically a 30-day export window followed by permanent deletion — unless retention is required by law.

10. Audits

Snapn makes available information necessary to demonstrate compliance, including its security packet and relevant certifications, and accommodates reasonable audits subject to confidentiality.

11. Requesting a signed DPA

To execute a signed DPA or request our sub-processor list and security packet, contact security@snapn.io or use our contact page.

This document is provided for general informational purposes and does not constitute legal advice.