Last updated: October 1, 2026
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”) and Rulewize LLC (“Rulewize”) and applies when Rulewize processes personal information on Customer’s behalf, for example employee or applicant details that Customer enters into handbooks, policies and documents. Customer’s acceptance of the Terms includes this DPA. To request a countersigned copy, email privacy@rulewize.com.
1. Roles and scope
Customer is the controller (or business) and Rulewize is the processor (or service provider) of “Customer Personal Data,” meaning personal information in Your Data that Rulewize processes to provide the Service. For account, billing and website data about Customer’s users, Rulewize acts as an independent controller under the Privacy Policy.
2. Instructions and purpose
Rulewize will process Customer Personal Data only to provide, secure and support the Service under the Terms and Customer’s documented instructions (including its use of the product), and as required by law. Rulewize will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship, or combine it with other data except as the law allows a service provider to do. Rulewize will tell Customer if it believes an instruction violates law.
3. Confidentiality
Rulewize limits access to Customer Personal Data to personnel who need it and are bound by confidentiality obligations.
4. Security
Rulewize maintains reasonable technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest through its hosting providers, row-level separation of each organization’s data, role-based access and restricted service credentials.
5. Sub-processors
Customer authorizes the following sub-processors. Rulewize will give notice (by email or on this page) of changes and Customer may object on reasonable grounds within 30 days; Rulewize will remain responsible for its sub-processors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | United States |
| Vercel | Application hosting and infrastructure | United States |
| Anthropic | AI generation, editing and translation of documents | United States |
| Resend | Transactional and notification email delivery | United States |
| Stripe | Payment processing (acts largely as an independent controller for payment data) | United States |
6. Data subject requests
Rulewize will, taking into account the nature of the processing, reasonably help Customer respond to requests from individuals to exercise their privacy rights. Customer owners can export and delete organization data at Settings, then Account & Data. If an individual contacts Rulewize directly about Customer Personal Data, Rulewize will refer them to Customer where it can identify Customer.
7. Incidents
Rulewize will notify Customer without undue delay after becoming aware of a confirmed security breach affecting Customer Personal Data, and provide information reasonably available to help Customer meet its notification duties.
8. Return and deletion
Customer owners can export their data as a JSON file at Settings, then Account & Data, including after the subscription ends. When Customer deletes its organization, the subscription is canceled, access is revoked immediately and Customer Personal Data is permanently deleted after 30 days, except where law requires retention. Copies in backups are overwritten in the ordinary cycle.
9. Audits
On reasonable written request, no more than once a year, Rulewize will provide information reasonably necessary to show compliance with this DPA. Rulewize does not currently hold its own SOC 2 or ISO 27001 report; it relies on the security programs of its infrastructure providers.
10. Order of precedence; contact
If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. Contact: Rulewize LLC, 315 San Pedro Blvd NE, Suite A, Albuquerque, NM 87108, privacy@rulewize.com.