Data Processing Agreement
Last updated: May 1, 2026
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Snapn, Inc. ("Processor") for the provision of the Services.
For personal data processed on the Controller's behalf, the Controller determines the purposes and means of processing, and Snapn acts as Processor.
2. Nature and purpose of processing
Snapn processes personal data only to provide and support the Services, in accordance with the Controller's documented instructions, including the configuration choices made in the product (such as hosting region and AI model selection).
3. Categories of data and data subjects
Data subjects may include the Controller's personnel and any individuals appearing in captured guide content. Categories of data may include:
- Identifiers such as names and work email addresses.
- Guide content, including screenshots and annotations that may contain personal data.
- Usage and diagnostic data associated with accounts.
4. Data residency and sub-processing
Personal data is stored in the region selected by the Controller (US, EU, Canada, or UAE) and is not replicated to other regions.
Snapn engages vetted sub-processors (for example, cloud infrastructure providers) under written terms no less protective than this DPA. A current list of sub-processors is available on request, and we provide notice of material changes.
5. Security measures
Snapn implements appropriate technical and organizational measures, including encryption in transit and at rest, access controls, audit logging, and regular security testing.
Sensitive fields are masked at capture, and Enterprise plans support automated PII redaction.
6. International transfers
Where processing involves a transfer of personal data across borders, Snapn relies on appropriate safeguards such as the Standard Contractual Clauses, supplemented by additional measures where required.
7. Assistance with data subject rights
Taking into account the nature of processing, Snapn assists the Controller with appropriate measures to respond to data subject requests and to fulfil obligations relating to security, breach notification, and impact assessments.
8. Personal data breach
Snapn notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides information reasonably necessary for the Controller to meet its notification obligations.
9. Return and deletion
On termination of the Services, Snapn deletes or returns personal data in accordance with the Terms — typically a 30-day export window followed by permanent deletion — unless retention is required by law.
10. Audits
Snapn makes available information necessary to demonstrate compliance, including its security packet and relevant certifications, and accommodates reasonable audits subject to confidentiality.
11. Requesting a signed DPA
To execute a signed DPA or request our sub-processor list and security packet, contact security@snapn.io or use our contact page.