Skip to content
EMPWERNETWORK

Data Processing Addendum

Data Processing Addendum

Plain English, and binding. A law firm did not write this page; the founder did, in plain English, so you can actually read it. That does not make it any less real: these are the operative terms of the Platform, and using the Platform means you agree to them. We will have counsel review these terms as the company grows, and any material change comes with at least 30 days notice, the same as our Terms of Use promise.

The short version: your subscriber list is yours. Legally, that makes you the controller of your subscribers’ personal data and makes us your processor: we handle that data only to run your blog and send your emails, on your instructions, and never for ourselves. We name every company that touches the data, we tell you within 72 hours if something goes wrong, we help you answer your subscribers’ privacy requests, and we delete the data when you leave.

1. What This Addendum Is

This Data Processing Addendum (“DPA”) is part of the Platform Terms between Empower Network (“we,” “us,” “the Processor”) and each Blogging System member (“you,” “the Controller”). It governs our processing of personal data belonging to your subscribers and leads (“Subscriber Data”) on your behalf. It applies wherever data-protection law makes the controller/processor distinction, including the EU and UK GDPR, and its commitments are our standard everywhere.

To be clear about the boundary: this DPA covers your subscribers’ data, which you control. Your own account data (your name, email, billing, blog content) is covered by our Privacy Policy, where we act as an independent controller.

2. Roles and Scope of Processing

Plain English: you decide why and how your subscribers’ data is used; we only execute.

1. Subject matter and purpose: hosting your blog’s lead-capture and subscriber list, storing subscriber records, sending your emails, processing unsubscribes and bounces, and producing exports for you.

2. Data subjects: people who subscribe to your blog or submit their details through your lead-capture forms.

3. Categories of data: name (if provided), email address, and the source and date of each signup. When email sending is live this will also include double-opt-in confirmation records and email engagement events (delivery, opens, clicks, bounces, and complaints). We use the visitor’s IP address briefly to block spam signups; we do not store it against a subscriber’s record.

4. Duration: the life of your membership plus the deletion schedule in section 8.

5. We process Subscriber Data only on your documented instructions, which are: the Platform Terms, this DPA, and the actions you take in your dashboard (capture, send, export, delete). We will not process Subscriber Data for our own purposes, will not email your list for ourselves, and will not sell or rent it, ever. If we believe an instruction from you violates data-protection law, we will tell you before acting on it.

3. Confidentiality and Security

Plain English: the data is encrypted at rest, access is limited to people who need it, and everyone with access is bound to confidentiality. We limit access to Subscriber Data to personnel who need it to operate the Platform, all of whom are under confidentiality obligations. We maintain technical and organizational measures appropriate to the risk, including storage on encrypted server volumes, encryption in transit over HTTPS, access limited to the accounts that operate the Platform, a database that is not exposed to the public internet, nightly backups with verified restores, and a written breach-response procedure. We keep these measures current as the Platform evolves.

4. Subprocessors

Plain English: three infrastructure companies help us run the Platform, each sees only what its job requires, and we tell you before adding more. You authorize the following subprocessors:

1. Amazon Web Services (Amazon SES), United States: email delivery. Once email sending is enabled, SES will see recipient addresses and message content in order to deliver your emails. It is not active yet.

2. Cloudflare (R2), United States: file storage for blog media and for our nightly backups. Those backups include the subscriber database; your day-to-day subscriber records are served from the primary server, not from R2.

3. Oracle Cloud Infrastructure, United States: server hosting. The Platform, including the subscriber database, runs on infrastructure it provides.

Each subprocessor is bound by a written agreement imposing data-protection obligations no weaker than this DPA. We remain fully responsible to you for their performance. If we plan to add or replace a subprocessor, we will notify you at least 30 days in advance (by email and on this page). If you object on reasonable data-protection grounds and we cannot resolve the objection, you may cancel and export everything per the Platform Terms; that is a real remedy here because export is free and complete.

5. International Transfers

Plain English: the servers are in the United States; for subscribers protected by EU or UK law, the standard legal transfer contracts apply automatically. Where Subscriber Data is subject to the EU GDPR and is transferred to us or our subprocessors outside the European Economic Area, the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference, with you as data exporter and us as data importer, and with the annexes completed by the processing details in sections 2 to 4 of this DPA. For data subject to UK law, the UK International Data Transfer Addendum to the SCCs is incorporated on the same basis. If a competent authority replaces or invalidates these mechanisms, we will implement the successor mechanism.

6. Personal Data Breaches

Plain English: if your subscribers’ data is breached, you hear it from us within 72 hours, with the facts you need to meet your own legal duties. If we become aware of a personal data breach affecting Subscriber Data, we will notify you without undue delay and in any case within 72 hours of becoming aware. The notice will describe what happened, the categories and approximate number of subscribers and records affected, the likely consequences, what we have done and are doing about it, and a contact for follow-up. We will cooperate with you on your own notification obligations to authorities and to your subscribers, and we will not notify your subscribers directly unless the law requires it or you ask us to.

7. Helping You With Subscriber Rights and Compliance

Plain English: when a subscriber asks you for their data, a correction, or deletion, the tools to comply are in your dashboard, and we handle what the tools do not. Taking into account the nature of the processing, we will assist you in responding to data-subject requests (access, correction, deletion, portability, objection). Your dashboard lets you view, correct, export, and delete individual subscriber records directly. If a request needs something the dashboard cannot do, contact support and we will assist within 10 business days. If a subscriber contacts us directly about your list, we will pass the request to you rather than answer for you. We will also provide reasonable assistance with your data-protection impact assessments and consultations with supervisory authorities, where they concern the Platform.

We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and we will allow and contribute to audits, on these honest terms: no more than once per year absent a breach or regulator requirement, on 30 days notice, during business hours, without access to other members’ data, and at your expense. A written response to a security questionnaire satisfies an audit request where it reasonably can.

8. Deletion When You Leave

Plain English: export your list any time; after your membership ends and the 90-day grace period runs out, we delete it. You can export your full subscriber list at any time. If your access has ended and you can no longer reach the export tool, request your list from support and we will send it to you. When your membership ends, Subscriber Data is retained through the 90-day grace period (so you can reactivate or re-export), then deleted. Note that this is deliberately shorter than the 12-month content archive in the Platform Terms: your archived blog posts stay readable for a year, but your subscribers’ personal data does not linger; it is deleted at day 90. Data may persist in our nightly backups for up to 30 days beyond deletion, after which the backups roll off and it is unrecoverable. On written request we will confirm deletion. We retain nothing except records the law requires us to keep, and we will tell you if that applies.

9. Precedence

If this DPA conflicts with the Platform Terms or Terms of Use on a data-protection matter, this DPA controls. If the Standard Contractual Clauses conflict with this DPA, the Clauses control.

Last updated: July 2026.

Partner ProgramShare Empower Network. Partners earn 30% on referred sales — free to join, no purchase required.
Become a partner free →