This Data Processing Addendum (“DPA”) is part of the Terms of Service between you (“Customer”) and TurfGrown LLC, d/b/a Fresh Cut Boards (“Processor”). It applies when we process personal data contained in Customer Data on your behalf. If the DPA and the Terms conflict on data protection, the DPA controls.
It takes effect automatically when you accept the Terms. If you need a countersigned copy, email legal@freshcutboards.com.
1.Roles and instructions
You are the controller (or a processor acting for your own client) of personal data in Customer Data; we are your processor. We process it only on your documented instructions — which are the Terms, this DPA and your use of the service's features — unless the law requires otherwise, in which case we'll tell you first where allowed. We'll tell you if we believe an instruction violates data protection law.
2.Details of the processing
| Subject matter | Providing the Fresh Cut Boards compliance service. |
|---|---|
| Duration | While you use the service, plus the 30-day export window and backup expiry. |
| Nature and purpose | Hosting, storage, organization, retrieval, transmission (email) and deletion, to provide and secure the service. |
| Data subjects | Your staff and other users; your vendors' contacts; people named in documents or evidence you upload. |
| Personal data | Names, business email addresses, job roles, activity in the audit log, and any personal data inside documents, evidence or questionnaire answers. |
| Special categories | Not permitted: protected health information and the other sensitive data excluded by the Terms and Acceptable Use Policy. |
3.Confidentiality
Everyone we authorize to process Customer Data is bound by confidentiality obligations and gets access only as needed to run and support the service.
4.Security measures
- Encryption in transit (TLS) between browsers, the service and our providers; encryption at rest by our database and storage provider. (Email to recipients' own mail servers uses TLS where they support it.)
- Strict separation between organizations; every query is scoped to the requesting organization.
- Role-based access inside each organization through security groups; owners can never be locked out; nobody can change their own access.
- Private file storage; downloads use short-lived signed links checked against the user's permissions.
- An audit log of create, update, delete and access-changing actions.
- Sign-in by single-use email links with rate limits; 12-hour sessions.
- Daily managed database backups by our provider, kept up to 7 days (stored files aren't included in those backups).
- Production access limited to authorized personnel, for operating the service; development tools and AI assistants are not used to read Customer Data.
5.Subprocessors
You authorize the subprocessors listed on the Subprocessors page. Each is bound by written data protection terms as required by applicable law, and we remain responsible for them. We'll update that page and email organization owners at least 30 days before adding or replacing a subprocessor; you may object on reasonable data protection grounds, and if we can't resolve it you may stop using the affected service.
6.Data subject requests and assistance
You can view, correct and delete Customer Data in the service and download its files and audit log; on request we'll provide a full export in a common format. If we receive a request from a data subject about your data, we'll forward it to you and won't respond ourselves except to confirm the forwarding. We'll reasonably help with data protection impact assessments and regulator consultations relating to the service.
7.Personal data breaches
We'll notify your organization's owners without undue delay, and in any case within 72 hours, after confirming a personal data breach affecting Customer Data. We'll share what we know — the nature of the breach, likely consequences and the measures taken — and update you as we learn more.
8.Return and deletion
You can download your files and audit log at any time, and on request we'll provide a full export of Customer Data in a common format. After your organization is closed (on request to support@freshcutboards.com), you have 30 days to ask for that export; we then delete Customer Data from the live service, and backups expire on their normal rotation, unless the law requires us to keep something.
9.Information and audits
We'll make available the information reasonably needed to demonstrate compliance with this DPA, including written answers to security questionnaires. Fresh Cut Boards does not yet hold a SOC 2 report or similar certification; where one becomes available we'll provide it under confidentiality. On-site audits, where legally required, need 30 days' notice and are at your cost.
10.International transfers
Customer Data is hosted in the United States. Where a transfer from the EEA, UK or Switzerland requires it, the parties agree that the Standard Contractual Clauses are incorporated by reference — Module Two (controller to processor), or Module Three where you are a processor — with Customer as exporter, Processor as importer, the “Details of the processing” and “Security measures” sections above as Annexes I–II, and the UK Addendum or Swiss amendments applying as needed. We rely on our subprocessors' equivalent mechanisms.
11.Liability
Each party's liability under this DPA is subject to the limitations in the Terms, except where the law doesn't allow it.