Last updated: October 1, 2026

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”) and Rulewize LLC (“Rulewize”) and applies when Rulewize processes personal information on Customer’s behalf, for example employee or applicant details that Customer enters into handbooks, policies and documents. Customer’s acceptance of the Terms includes this DPA. To request a countersigned copy, email privacy@rulewize.com.

1. Roles and scope

Customer is the controller (or business) and Rulewize is the processor (or service provider) of “Customer Personal Data,” meaning personal information in Your Data that Rulewize processes to provide the Service. For account, billing and website data about Customer’s users, Rulewize acts as an independent controller under the Privacy Policy.

2. Instructions and purpose

Rulewize will process Customer Personal Data only to provide, secure and support the Service under the Terms and Customer’s documented instructions (including its use of the product), and as required by law. Rulewize will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship, or combine it with other data except as the law allows a service provider to do. Rulewize will tell Customer if it believes an instruction violates law.

3. Confidentiality

Rulewize limits access to Customer Personal Data to personnel who need it and are bound by confidentiality obligations.

4. Security

Rulewize maintains reasonable technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest through its hosting providers, row-level separation of each organization’s data, role-based access and restricted service credentials.

5. Sub-processors

Customer authorizes the following sub-processors. Rulewize will give notice (by email or on this page) of changes and Customer may object on reasonable grounds within 30 days; Rulewize will remain responsible for its sub-processors.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, storageUnited States
VercelApplication hosting and infrastructureUnited States
AnthropicAI generation, editing and translation of documentsUnited States
ResendTransactional and notification email deliveryUnited States
StripePayment processing (acts largely as an independent controller for payment data)United States

6. Data subject requests

Rulewize will, taking into account the nature of the processing, reasonably help Customer respond to requests from individuals to exercise their privacy rights. Customer owners can export and delete organization data at Settings, then Account & Data. If an individual contacts Rulewize directly about Customer Personal Data, Rulewize will refer them to Customer where it can identify Customer.

7. Incidents

Rulewize will notify Customer without undue delay after becoming aware of a confirmed security breach affecting Customer Personal Data, and provide information reasonably available to help Customer meet its notification duties.

8. Return and deletion

Customer owners can export their data as a JSON file at Settings, then Account & Data, including after the subscription ends. When Customer deletes its organization, the subscription is canceled, access is revoked immediately and Customer Personal Data is permanently deleted after 30 days, except where law requires retention. Copies in backups are overwritten in the ordinary cycle.

9. Audits

On reasonable written request, no more than once a year, Rulewize will provide information reasonably necessary to show compliance with this DPA. Rulewize does not currently hold its own SOC 2 or ISO 27001 report; it relies on the security programs of its infrastructure providers.

10. Order of precedence; contact

If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. Contact: Rulewize LLC, 315 San Pedro Blvd NE, Suite A, Albuquerque, NM 87108, privacy@rulewize.com.