Firevibe Data Processing Addendum
This Data Processing Addendum ("Addendum") is part of the Firevibe Terms of Service between you ("Customer") and CREART LLC ("Firevibe"), 364 E Main St Ste 1001, Middletown, Delaware, USA. It applies to users located outside Turkey. If you are located in Turkey, the Turkish customer data processing addendum applies instead.
This Addendum applies when Firevibe processes personal data on your behalf in the sites and apps you build with Firevibe, such as data about your visitors, users, customers or employees ("Customer Personal Data").
1. Roles
For Customer Personal Data, you are the controller (or "business") and Firevibe is your processor (or "service provider"). If you act on behalf of another controller, you are responsible for having the authority to engage Firevibe as a subprocessor.
Firevibe's own processing for accounts, billing, security and legal compliance is not covered by this Addendum. It is described in our Privacy Policy.
2. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Providing the Services for your projects |
| Nature of the processing | Hosting your projects, storing files and database data, authorized access, AI features you start or enable in your projects, necessary technical support, and deletion |
| Data subjects | Visitors, users, customers and employees connected with your projects, and other people included in your lawful instructions |
| Types of data | Depending on your project: identity and contact data, account data, transaction data, access logs, prompts, and personal data contained in uploaded files. Only what your instructions require. |
| Special categories of data | Only if your project actually includes them, and only with the safeguards the law requires |
| Duration | For as long as Firevibe provides the Services for your projects. Project data continues to be hosted after a subscription ends, until it is deleted. A site going offline because a plan ended is not a deletion of data. |
Your project settings, data structures, chosen features and recorded instructions define the processing in more detail. Nothing in this Addendum allows unlimited collection or processing for other purposes.
3. Instructions
Firevibe processes Customer Personal Data only on your documented instructions, which include the Terms of Service, the configuration of your projects and your use of the Services. If Firevibe believes an instruction is unlawful, it will tell you. If the law requires Firevibe to process data in another way, it will tell you first unless the law prohibits it.
4. Your responsibilities
You are responsible for collecting Customer Personal Data lawfully, for giving the required notices, for obtaining any required consents, and for the legal basis of the processing. You are responsible for the sign-in flows, user roles, permissions and data and file visibility you configure in your projects. Uploading a file does not by itself give a legal basis to process the personal data of the people in it.
5. Confidentiality and security
Firevibe limits access to Customer Personal Data to personnel who need it and who are bound by confidentiality obligations. Firevibe applies technical and organizational measures appropriate to the risk of the processing, including separation of accounts and projects, protection of secrets, and secure transfer and storage. This Addendum does not promise any specific certification or encryption standard.
Each party is responsible for the risks and settings under its own control. A security weakness in Firevibe's systems remains Firevibe's responsibility, and keys or permissions you expose or over-grant remain yours.
6. Subprocessors
You authorize Firevibe to use subprocessors. Depending on the features you use, these are:
- Infrastructure and storage: Supabase, Amazon Web Services, Modal, Neon and Cloudflare.
- AI processing: Anthropic, OpenAI, xAI and Replicate.
Subprocessors receive only the Customer Personal Data needed for the feature in use, and they are bound by written data protection obligations. Processing may take place in any region the subprocessors operate in. Firevibe does not promise storage in a specific region.
Firevibe will give you reasonable notice before adding or replacing a subprocessor. You may object on reasonable data protection grounds by emailing help@firevibe.ai. If we cannot resolve the objection, you may stop using the affected feature or end your subscription.
Stripe and marketing tools are not subprocessors under this Addendum unless they actually process Customer Personal Data.
7. US state privacy laws
Where US state privacy laws apply, Firevibe acts as your service provider and will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data for any purpose other than providing the Services to you, or outside its direct business relationship with you; or
- combine Customer Personal Data with personal data it receives from others, except as those laws permit.
Firevibe will tell you if it can no longer meet these obligations.
8. Requests from individuals
Firevibe will give you reasonable assistance, appropriate to the Services, to respond to requests from individuals about Customer Personal Data. If Firevibe receives such a request directly, it will forward it to you.
9. Security incidents
If Firevibe becomes aware of a security incident affecting Customer Personal Data, it will notify you without undue delay. The notice will describe what is known about the incident, the data affected, the likely consequences and the measures taken or planned, and Firevibe will update you as more becomes known.
10. Deletion and return
You can delete your projects and your account in the app. To request access to, or a copy of, the personal data in your projects, email help@firevibe.ai. After verifying your authority, we will agree on a secure way to deliver it. The fact that web project source code cannot be exported does not limit these requests.
After deletion, Customer Personal Data is removed from active systems and from subprocessors on their deletion schedules. Backups follow their own cycles, and data that the law requires us to keep is retained only as required, with restricted access, and used for no other purpose.
11. Audits
Firevibe will make available the information reasonably necessary to show that it meets this Addendum. Any audit must be reasonable in scope and frequency, with prior notice, and must protect the confidentiality of other customers and the security of the Services.
12. Liability and order of precedence
Each party's liability under this Addendum is subject to the limitations in the Terms of Service, except where the law does not allow them. On data protection matters, this Addendum takes precedence over the Terms of Service.
13. Contact
Email help@firevibe.ai, or write to CREART LLC, 364 E Main St Ste 1001, Middletown, Delaware, USA.