Data Processing Agreement
1. Parties & Scope
This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("Controller") and NC Construction LLC / Clark Properties, operator of Money/Hub ("Processor"). It applies whenever Money/Hub processes personal data on the Controller's behalf.
2. Nature & purpose of processing
- Providing the Money/Hub SaaS platform (dashboard, alerts, ledger, invoicing).
- Sending transactional and opt-in alert emails via Resend/SMTP.
- Processing platform-fee and marketplace payments via Stripe and PayPal.
- Generating AI-based side-hustle rankings via Claude (Emergent LLM).
3. Categories of data subjects & data
- Subjects: the Controller's end-users, contractors, and clients.
- Personal data: email, name, avatar URL, payment handles, earnings amounts, IP address on request, session cookies.
- Not processed: government ID, health data, biometric data, or card PANs.
4. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Maintain confidentiality, tenant isolation (
user_idscoping on every query), TLS in transit, and encryption of secrets at rest. - Notify Controller of any personal-data breach within 72 hours of confirmation.
- Assist Controller with data subject requests (access, rectification, deletion, portability).
- Delete or return all personal data at end of service, unless legally required to retain.
5. Sub-processors
The Processor engages the following sub-processors. The Controller consents to their use:
- Google LLC — OAuth sign-in (EU-US Data Privacy Framework certified).
- Stripe, Inc. — payments & Connect payouts (PCI-DSS Level 1).
- PayPal Holdings, Inc. — alternate payment rail.
- Resend, Inc. / SMTP host — transactional email delivery.
- MongoDB Atlas (or self-hosted MongoDB) — primary data store.
- Anthropic PBC (via Emergent LLM router) — AI opportunity ranking.
- Emergent Labs — hosting & deployment infrastructure.
The Processor will give 30 days' notice of any new sub-processor. Controller may object; if objection cannot be resolved, either party may terminate.
6. International transfers
Where personal data is transferred outside the customer's jurisdiction (e.g., EEA → US), the Processor relies on the sub-processor's Standard Contractual Clauses (Google, Stripe, MongoDB Atlas, Anthropic all publish SCCs and/or DPF certifications).
7. Security measures
- HTTPS/TLS 1.2+ everywhere; HSTS on the public domain.
- HttpOnly, SameSite=Lax session cookies rotated on sign-in.
- Per-user rate limits & signed Stripe/PayPal webhook verification.
- Least-privilege backend service accounts, secrets stored in environment variables (never in source).
- Automated backups of MongoDB; deletion is permanent within 30 days of request.
8. Audit rights
Once per calendar year (or after a confirmed breach), the Controller may request a written summary of the Processor's technical & organizational measures. On-site audits are available for enterprise customers under a mutually signed NDA.
9. Term & termination
This DPA remains in effect for as long as the Processor holds Controller data. Upon termination, the Controller may export via /api/user/export and then delete the account, wiping all records within seconds.
10. Contact / DPO
Data protection questions: moneyhubvip@outlook.com (Attn: Data Protection).