DPAData Processing
Data Processing
Addendum
Supplements the Subscription Agreement: our role as Processor for guest data a campground uploads, security controls, breach notification, and data purging.
Effective date: August 3, 2026
This Data Processing Addendum (“DPA”) supplements and forms a part of the Master SaaS Subscription Agreement (“Agreement”) between Waypoints Digital LLC (“Processor”) and the subscribing Campground Customer (“Controller”).
1. Scope, Roles, and Processing Instructions
- Data Roles: The parties acknowledge and agree that with respect to the management of guest contact registries, camper email logs, and campground customer marketing lists uploaded into Compass, the Customer acts as the Data Controller and Waypoints Digital LLC acts strictly as the Data Processor.
- Instructions: Processor shall process this consumer data solely on behalf of, and in strict accordance with, the documented administrative configurations, platform actions, and instructions executed by the Controller within the Compass dashboard interface, or as otherwise required by applicable law.
2. Mandatory Technical Security and Personnel Controls
- Security Measures: Processor implements and maintains commercially reasonable administrative, physical, and technical safeguards designed to protect the integrity, confidentiality, and availability of data stored within our multi-tenant cloud environments (including Supabase and Vercel).
- Confidentiality: Processor ensures that all personnel authorized to process Controller data are subject to binding statutory or contractual confidentiality obligations.
3. Data Breach Notification and Incident Response
- Notification Obligation: In the event that Processor becomes aware of any unauthorized access to, alteration of, or acquisition, disclosure, or destruction of Controller data hosted on our infrastructure (a “Security Incident”), Processor shall notify Controller without undue delay, and in no event later than seventy-two (72) hours after confirming the breach.
- Content of Notice: To the extent available at the time of disclosure, the notification sent to the Controller will provide: a description of the nature of the Security Incident, including the categories and approximate number of data records impacted; the name and contact details of Processor’s data compliance point of contact; and measures taken or planned by the Processor to mitigate and remediate the effects of the incident.
- Remediation and Assistance: Processor shall immediately take reasonable steps to contain, control, and remediate any confirmed Security Incident. Processor will cooperate in good faith with the Controller to provide necessary information required for the Controller to fulfill its own statutory consumer notification obligations under applicable state laws.
4. Sub-Processor Management
- Authorized Vendors: Controller grants general authorization to Processor to engage the third-party sub-processors explicitly listed in our Application Privacy Policy (including Vercel, Supabase, and Stripe).
- Flow-Down Terms: Processor imposes written data protection obligations upon each sub-processor that are at least as restrictive as those imposed on the Processor under this DPA. Processor remains fully liable to the Controller for the performance of its sub-processors' obligations.
5. Audit Rights and Assistance
- Information Provision: Processor shall make available to Controller information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA.
- Regulatory Inquiries: Processor will provide reasonable assistance to help Controller respond to consumer privacy requests, data protection assessments, or inquiries from data protection authorities regarding the platform's processing of data.
6. Post-Cancellation Data Purging and Offboarding
Following the formal cancellation, termination, or expiration of a Compass account, Waypoints Digital LLC implements a definitive offboarding retention window of 60 days.
- During this 60-day buffer, saved layouts, account telemetry, and database records remain cached to facilitate swift account restoration should the Customer choose to reactivate.
- Upon the exact expiration of this 60-day timeline, all user-generated content, guest lists, and associated contact logs are permanently and irreversibly purged from our active Supabase relational databases and storage systems, except where archiving is explicitly mandated by law.