Data Processing Addendum
Simcha Solutions LLC
1. Scope and roles
This Data Processing Addendum ("DPA") supplements the agreement between Simcha Solutions LLC ("Simcha Solutions") and the customer or participant ("Customer") for the relevant service (the "Principal Agreement"). It applies where Simcha Solutions processes personal information on Customer's behalf.
Important scope limitation. Simcha DB Studio is self-hosted. When Customer runs the software in its own environment, Customer alone controls the databases and data it connects, and Simcha Solutions does not receive, host, or access that data. In that context there is no processing by Simcha Solutions to which this DPA applies. This DPA governs only the limited personal information Simcha Solutions actually processes, namely: (a) hosted beta sandbox account and usage data; (b) any data Customer chooses to connect to the hosted sandbox; and (c) contact and administrative data used to manage the relationship, licensing, and support.
For the personal information in scope, Customer is the business or controller and Simcha Solutions acts as a service provider or processor, as those terms are used under applicable United States state privacy laws. This DPA is drafted for United States processing only; Simcha Solutions does not offer services to individuals in the EEA, the UK, or Switzerland, and cross-border transfer mechanisms such as Standard Contractual Clauses do not apply.
2. Processing details
- Subject matter: provision of the hosted sandbox, support, and administration of the relationship.
- Duration: the term of the Principal Agreement, plus limited retention as described in the Privacy Policy.
- Nature and purpose: hosting an evaluation workspace, authenticating users, supporting the account, and communicating.
- Categories of individuals: Customer's authorized users and contacts, and any individuals whose data appears in content Customer connects to the sandbox.
- Categories of personal information: names, email addresses, account and usage metadata, and any personal information present in content Customer connects to the sandbox. Customer agrees not to introduce sensitive or high-risk personal information into the sandbox.
3. Service-provider and processor obligations
Simcha Solutions will:
- process personal information only on Customer's documented instructions, including as set out in the Principal Agreement and this DPA, and only for the limited, specified business purpose of providing the services, unless otherwise required by law;
- not sell or share the personal information, and not retain, use, or disclose it for any purpose other than the specific business purpose of performing the services, including not combining it with information from other sources except as permitted by law;
- certify that it understands and will comply with these restrictions;
- ensure persons authorized to process the data are bound by confidentiality;
- implement and maintain the security measures described in Section 6;
- engage subprocessors only under Section 4;
- assist Customer, taking into account the nature of the processing, in responding to individual rights requests and in meeting Customer's security and breach-notification obligations;
- at Customer's choice, delete or return the personal information at the end of the services, except where retention is required by law; and
- make available information reasonably necessary to demonstrate compliance, and allow for and contribute to audits as described in Section 7.
Simcha Solutions will notify Customer if it determines it can no longer meet its obligations under applicable law, and Customer may take reasonable steps to stop and remediate unauthorized processing.
4. Subprocessors
Customer authorizes Simcha Solutions to engage the following subprocessors to provide the services:
| Subprocessor | Service | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, serverless compute, transactional email | United States |
| Cloudflare, Inc. | Bot-protection challenge on forms | United States |
| Google LLC | Business email and domain services; fonts | United States |
| HubSpot, Inc. | Customer relationship management | United States |
Simcha Solutions will impose data-protection obligations on each subprocessor no less protective than those in this DPA and remains responsible for its subprocessors' performance. Simcha Solutions will give Customer a reasonable means to be informed of any intended change to this list and a reasonable opportunity to object.
5. Individual rights requests
Taking into account the nature of the processing, Simcha Solutions will assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to requests from individuals exercising their rights under applicable law. If Simcha Solutions receives such a request directly, it will, where appropriate, refer the individual to Customer.
6. Security measures
Simcha Solutions maintains the following administrative, technical, and organizational measures for the personal information it processes on Customer's behalf:
- Encryption: data encrypted in transit (TLS) and at rest for data Simcha Solutions hosts.
- Access control: least-privilege access, unique credentials, and multi-factor authentication for administrative access to systems that hold the data.
- Logging and monitoring: audit logging of administrative actions and monitoring for anomalous activity.
- Network protection: segmentation and provider-managed network controls in the hosting environment.
- Change and vulnerability management: controlled changes and timely application of security updates to systems under Simcha Solutions' control.
- Personnel: confidentiality obligations for personnel with access.
- Resilience: backups of the hosted environment with defined retention.
Because the production Simcha DB Studio product is self-hosted, security of that environment is Customer's responsibility. Simcha Solutions may update these measures provided the level of protection is not materially reduced.
7. Audits
Upon reasonable prior written notice, no more than once per twelve-month period (unless required by a regulator or following a security incident), Simcha Solutions will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow Customer (or an independent auditor Customer engages, subject to confidentiality) to conduct an audit of the relevant controls during normal business hours, in a manner that does not disrupt Simcha Solutions' operations. Where available, Simcha Solutions may satisfy an audit request by providing current third-party reports or provider attestations.
8. Personal data breach
Simcha Solutions will notify Customer without undue delay, and in any case within seventy-two (72) hours, after confirming a security incident that affects personal information it processes on Customer's behalf, and will provide information reasonably available to assist Customer in meeting its notification obligations.
9. Deletion and return
On termination of the services, Simcha Solutions will, at Customer's choice, delete or return the personal information it processes on Customer's behalf and delete existing copies, except to the extent retention is required by law. Sandbox data is deleted in accordance with the Privacy Policy when participation ends.
10. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Principal Agreement. In case of conflict between this DPA and the Principal Agreement regarding the processing of personal information, this DPA controls.
11. Contact
Data protection inquiries: contactus@simchasolutions.com.
Last updated: July 23, 2026