Rib Creative
DocsCommunityPricing
Get Started
DocsCommunityPricing

Data Processing Addendum

This Data Processing Addendum applies when Rib Creative processes personal data on behalf of a workspace customer through hosted apps, builder workflows, storage, databases, integrations, support, or runtime infrastructure. It supplements the Terms of Service and Privacy Policy.

Processing details

Subject matterAI-assisted building, preview, publishing, hosted runtime, support, security, billing, and integrations.
DurationThe customer's subscription, active workspace use, and any retention period required for backups, logs, billing, security, or law.
Data subjectsWorkspace users, invited collaborators, app visitors, authenticated app end users, support contacts, and payment or integration contacts.
Customer personal dataAccount data, project content, prompts, files, generated code, app runtime data, logs, auth records, storage objects, metadata, and support records.
Sensitive dataNot intended unless the customer has confirmed the feature and agreement are suitable for that data.

Roles

For personal data that a customer submits to Rib Creative or collects through a customer app, the customer is usually the controller or business, and Rib Creative is usually the processor or service provider. Rib Creative may act as an independent controller for account administration, billing, fraud prevention, security, legal compliance, and platform analytics.

Processing instructions

Rib Creative will process customer personal data to provide the platform, operate hosted apps, process exports, run builds, manage storage and databases, provide support, secure the service, comply with law, and follow documented instructions expressed through the product, agreement, or authorized support requests.

Rib Creative personnel and contractors who access customer personal data must be bound by confidentiality obligations. Rib Creative will not process customer personal data for unrelated purposes except where required by law or where Rib Creative acts as an independent controller under the Privacy Policy.

Customer responsibilities

  • Customers are responsible for lawful collection, use, disclosure, and deletion of end-user data.
  • Customers must provide their own privacy notices, consent flows, legal bases, and end-user terms.
  • Customers must not submit regulated or highly sensitive data unless the feature and contract allow it.
  • Customers control project configuration, exported environments, app logic, permissions, and secrets.

Subprocessors and transfers

Rib Creative may use subprocessors listed on the Subprocessors page to provide hosting, AI processing, storage, database, email, payments, analytics, monitoring, support, and security services. Where required for international transfers, Rib Creative will rely on appropriate transfer safeguards such as Standard Contractual Clauses, UK transfer mechanisms, adequacy decisions, or other lawful mechanisms.

Customer authorizes Rib Creative to use the listed subprocessors for the services. Rib Creative will require subprocessors to protect customer personal data under written obligations that are materially consistent with this DPA. Rib Creative may give notice of material subprocessor changes by updating the Subprocessors page or through another reasonable channel. Where required by applicable law or a signed agreement, customers may object to subprocessor changes on reasonable data protection grounds.

For transfers from the EEA, UK, or Switzerland to a country without an adequacy decision, the applicable Standard Contractual Clauses, UK Addendum, or successor transfer mechanism will apply as needed.

Security and incidents

Rib Creative will maintain technical and organizational measures designed to protect customer personal data, including access controls, encryption where appropriate, logging, operational safeguards, and provider controls. Rib Creative will notify affected customers without undue delay after confirming a personal data breach that requires notification under applicable law.

Where feasible, Rib Creative will provide notice within 72 hours after confirming a reportable personal data breach affecting customer personal data. Notices may include available information about the nature of the incident, affected systems or data, mitigation steps, and customer actions. Rib Creative may update that information as the investigation develops.

Deletion, export, and assistance

Rib Creative will provide product features or reasonable support to help customers export supported project data, delete projects, respond to data subject requests, and meet security or compliance obligations. Some data may remain in backups, logs, billing records, fraud records, or legal records for limited periods where retention is required or technically necessary.

After termination, verified account deletion, or verified project deletion, Rib Creative will delete or return customer personal data within 30 days where technically feasible, except for backups, security logs, billing records, fraud-prevention records, legal holds, and provider records that must be retained for a limited period.

Assistance and audit

Rib Creative will provide reasonable assistance for data subject requests, security questionnaires, data protection impact assessments, regulator inquiries, and customer audits related to customer personal data. Audit support may be satisfied through security summaries, documentation, written responses, certifications, or a mutually agreed review process designed to protect other customers and platform security.

Rib Creative

Create custom apps and websites by chatting with AI.

Company

  • Home
  • Contact
  • Security

Product

  • Start building
  • Pricing
  • Payments

Resources

  • Learn
  • Legal Center
  • Cookies
  • Subprocessors

Legal

  • Terms
  • Privacy
  • Acceptable Use
  • DPA
  • Copyright

Community

  • Discord
  • Reddit
  • Instagram

© 2026 Rib Creative Lab - All rights reserved.