FastComments Data Processing Agreement

Version 1.0. Effective 5 August 2026.
Between WinrickLabs LLC, doing business as FastComments, a limited liability company organised under the laws of the State of California, United States, of 50 Iron Point Circle, Suite 140, PMB 1019, Folsom, CA 95630, United States (the "Processor"), and the Customer identified in the FastComments account (the "Controller").

How this Agreement is entered into

This Data Processing Agreement (in Germany and Austria, an Auftragsverarbeitungsvertrag or AVV) forms part of the FastComments Terms of Service. It takes effect automatically, without signature and without any further action by either party, for every Customer that uses the Service to process personal data as a controller subject to the GDPR, the UK GDPR or the Swiss FADP. Article 28(9) GDPR requires this contract to be in writing, including in electronic form; acceptance of the Terms of Service satisfies that requirement.

WinrickLabs LLC has executed this Agreement in advance. Its signature appears at section 24. A Customer that requires a countersigned copy for its own records may complete its details on this page to produce one, or request one from privacy@fastcomments.com.

Recitals

A. The Controller and the Processor have entered into a commercial relationship under which the Processor provides a hosted online commenting, live chat and discussion platform (the "Service").

B. That relationship is governed by the Terms of Service published at https://fastcomments.com/terms-of-service (the "Principal Agreement").

C. The Controller's use of the Service involves the processing of personal data subject to Regulation (EU) 2016/679 (the "GDPR"), the United Kingdom General Data Protection Regulation as read with the Data Protection Act 2018 (together, the "UK GDPR"), and/or the Swiss Federal Act on Data Protection (the "FADP"). The parties therefore agree the terms required by Article 28 GDPR and, where relevant, Chapter V GDPR.

1. Definitions

"Customer Personal Data" means personal data contained in or derived from comments, chat messages, replies, votes, reactions, flags, uploads, end-user profiles, single sign-on attributes and moderation records submitted to or generated through the Service on the Controller's behalf.

"Account Data" means the Controller's own contact, billing, authentication, support and product-usage data.

"Data Protection Laws" means the GDPR, the UK GDPR, the FADP and any other data protection law applicable to a party's processing under this Agreement.

"Sub-processor" means any third party engaged by the Processor to process Customer Personal Data.

"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022.

"Sub-processor Page" means https://fastcomments.com/dpa/sub-processors.

"Effective Date" means the date on which the Controller first accepted the Principal Agreement, or the date this Agreement is countersigned, whichever is earlier.

"Controller", "processor", "personal data", "processing", "personal data breach", "data subject" and "supervisory authority" carry the meanings given in Article 4 GDPR.

2. Scope, incorporation and order of precedence

2.1 This Agreement forms an integral part of the Principal Agreement and applies to all processing of Customer Personal Data by the Processor.

2.2 This Agreement supersedes any prior data processing terms between the parties.

2.3 Where this Agreement conflicts with the Principal Agreement, including the Terms of Service and the Privacy Policy, this Agreement prevails in respect of the processing of Customer Personal Data. Where this Agreement conflicts with the SCCs, the SCCs prevail.

2.4 The Annexes and Appendices form an integral part of this Agreement.

3. Roles of the parties

3.1 In respect of Customer Personal Data, the Customer is the controller and WinrickLabs LLC is the processor.

3.2 In respect of Account Data, WinrickLabs LLC acts as an independent controller. That processing is governed by the Privacy Policy and not by this Agreement.

3.3 Where the Controller is itself a processor acting for a third-party controller, it warrants that it has authority to appoint the Processor as a sub-processor, and this Agreement applies mutatis mutandis with Module Three of the SCCs substituted for Module Two.

3.4 If the Processor determines the purposes and means of processing any Customer Personal Data, it is a controller in respect of that processing for the purposes of Article 28(10) GDPR.

4. Processing on documented instructions

4.1 The Processor processes Customer Personal Data only on the Controller's documented instructions, including in relation to transfers to a third country. This Agreement, the Principal Agreement, the Service documentation and the Controller's use of the configuration options exposed by the Service together constitute the Controller's complete documented instructions.

4.2 The Processor does not sell Customer Personal Data, does not disclose it other than as instructed or as required by law, and does not use it for any purpose other than providing the Service. The Processor does not use Customer Personal Data to develop, train, fine-tune or evaluate any machine learning or artificial intelligence model, and requires the same of any Sub-processor that receives it for automated classification or moderation.

4.3 Where Union, Member State, United Kingdom or other applicable law requires the Processor to process Customer Personal Data otherwise than on the Controller's instructions, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

4.4 The Processor immediately informs the Controller if, in its opinion, an instruction infringes Data Protection Laws, and may suspend performance of the affected instruction until the parties resolve the matter.

5. Controller's obligations and warranties

5.1 The Controller determines the purposes and means of the processing of Customer Personal Data and is responsible for the lawfulness of that processing.

5.2 The Controller warrants that it has established a valid legal basis for the processing, that it has provided all information required by Articles 12 to 14 GDPR to the relevant data subjects, and that it has obtained any consents required for the processing and for the placing of any cookies or similar technologies by the Service.

5.3 The Controller is responsible for the content its end users submit through the Service and for its own moderation decisions.

5.4 The Service is not designed to process special categories of personal data within the meaning of Article 9 GDPR or personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The Controller instructs its end users accordingly and does not knowingly submit such data to the Service.

6. Confidentiality of personnel

6.1 Access to Customer Personal Data is restricted to those persons who require it in order to perform the Principal Agreement. As at 5 August 2026 no contractor has access to Customer Personal Data.

6.2 Every person authorised to process Customer Personal Data is bound by a duty of confidentiality that survives the end of their engagement. Before any contractor is granted access to Customer Personal Data, the Processor requires a written confidentiality undertaking on terms no less protective than this section.

7. Security of processing

7.1 The Processor implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk to the rights and freedoms of natural persons.

7.2 The Processor may update those measures provided that the overall level of security is not reduced. Material changes are published on this page.

7.3 The Controller is responsible for assessing whether those measures meet its own risk profile, and for configuring the Service securely, including its retention settings, its moderation settings, its IP address de-anonymisation setting and the handling of its single sign-on signing keys.

8. Sub-processors

8.1 The Controller gives the Processor a general written authorisation within the meaning of Article 28(2) GDPR to engage the Sub-processors listed in Annex III, and to engage further Sub-processors subject to this section. The Sub-processor Page is the canonical current list, and where it differs from Annex III the Sub-processor Page governs.

8.2 The Processor gives the Controller at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, or before the role of an existing Sub-processor changes materially. Notice is given by email to the account administrator and to any privacy contact designated in the FastComments administration console, and by publication on the Sub-processor Page with the effective date. No mailing-list signup or opt-in is required to receive that notice.

8.3 Where a change must be made urgently to preserve the security, integrity or continuity of the Service, including where an existing Sub-processor ceases to provide the relevant service, becomes insolvent, or its engagement ends, the Processor may engage a replacement and give notice as soon as reasonably practicable instead. The objection right in section 8.4 applies unchanged from the date of that notice.

8.4 The Controller may object to a new Sub-processor on reasonable grounds relating to data protection, by written notice to privacy@fastcomments.com within 30 days of notice under section 8.2 or 8.3.

8.5 On an objection the parties discuss the matter in good faith for 30 days and the Processor uses reasonable efforts to make available a change that avoids the objected-to processing. Depending on the Sub-processor concerned this may include disabling the optional feature that engages it, configuring the Service so that the objected-to processing does not occur, or migrating the Controller's account to the European Union region. The Processor performs that migration on request and at no charge. Where no such change is available, the Controller may terminate the affected part of the Service, or the Principal Agreement, on written notice without any early termination charge or other adverse consequence, and with a pro-rata refund of prepaid fees for the unused portion of the term. Termination on this ground is the Controller's exclusive remedy in respect of the objection.

8.6 The Processor imposes on each Sub-processor, by written contract, data protection obligations materially equivalent to those in this Agreement, including the security obligations in Article 32 GDPR and, where the Sub-processor is established outside the European Economic Area, an appropriate transfer mechanism. Where a Sub-processor has not yet entered into such a contract, that Sub-processor is identified as such in Annex III together with the processing it performs, and the Processor pursues the conclusion of a contract meeting this section.

8.7 The Processor remains fully liable to the Controller for the performance of each Sub-processor's obligations.

9. Assistance with data subject rights

9.1 The Processor promptly notifies the Controller of any request it receives directly from a data subject in relation to Customer Personal Data, and does not respond substantively to such a request other than to direct the data subject to the Controller, unless the Controller instructs otherwise.

9.2 The Processor promptly notifies the Controller of any other request, complaint, notice or communication it receives from a supervisory authority or other competent regulator that relates to the processing of Customer Personal Data, and of any claim for damages made in relation to that processing.

9.3 Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests to exercise rights under Chapter III GDPR. The Service provides the Controller with tooling to look up an end user, to edit, delete or anonymise individual comments and chat messages, to delete an end user and the content associated with them, to export the comment and user data held for the Controller's account, and to configure whether IP addresses are stored in de-anonymised form. Where that tooling enables the Controller to respond without the Processor's involvement, its availability constitutes the assistance required by this section. The Processor provides further assistance at reasonable cost.

10. Personal data breach

10.1 The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

10.2 The notification describes, to the extent known at the time: the nature of the breach, including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of records concerned; the likely consequences of the breach; the measures taken or proposed to address it, including measures to mitigate its possible adverse effects; and a contact point from whom further information may be obtained. Where the information is not available at once, it is provided in phases as it becomes available.

10.3 The Processor provides reasonable cooperation and assistance to the Controller in relation to the Controller's own obligations under Articles 33 and 34 GDPR.

10.4 A notification under this section is not an acknowledgement of fault or liability.

11. Data protection impact assessments

Taking into account the nature of the processing and the information available to it, the Processor provides reasonable assistance to the Controller with data protection impact assessments under Article 35 GDPR and with prior consultation of a supervisory authority under Article 36 GDPR, principally by making available Annex II, the Sub-processor Page, the transfer information in section 14, and written answers to reasonable questions. Assistance beyond that is provided at reasonable cost.

12. Deletion and return of Customer Personal Data

12.1 At the Controller's choice, the Processor deletes or returns all Customer Personal Data after the end of the provision of the Service, and deletes existing copies subject to section 12.3, unless Union, Member State or other applicable law requires continued storage.

12.2 The Controller notifies its choice in writing before, or within 30 days after, the end of the provision of the Service. The Controller may export its data using the Service's export tooling during that period. Absent an election within that period, the Processor deletes.

12.3 Deletion from live systems and their replicas takes place within 30 days of the election or of the expiry of the period in section 12.2. Residual copies contained in rotational backups are erased when the backup in which they appear is overwritten in the ordinary course of its rotation cycle, and in any event within twelve months. Until then those copies remain encrypted at rest, are not actively processed and are not used for any purpose other than disaster recovery.

12.4 Individual records are deleted before the end of the Service on the instruction of the Controller or of a data subject, using the tooling described in section 9.3.

13. Audits and demonstration of compliance

13.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or by another auditor mandated by the Controller. Sections 13.2 to 13.5 describe how that right is exercised in practice.

13.2 Information on request. On the Controller's written request, and at no charge, the Processor provides within 30 days: Annex II as then in force; the current Sub-processor list; a completed copy of the Processor's standard security questionnaire; a summary of the results of its most recent security testing; and written responses to reasonable written questions concerning the processing of personal data carried out on that Controller's behalf. This is available once in any 12-month period, and additionally following a personal data breach affecting personal data processed on that Controller's behalf or where a supervisory authority requires it.

13.3 Audit interview. Where the Controller reasonably demonstrates that the information provided under section 13.2 is insufficient to demonstrate compliance, or following a personal data breach affecting personal data processed on that Controller's behalf, or where a supervisory authority requires it, the Processor makes a suitably qualified representative available for a remote audit interview by video conference of up to two hours, on at least 30 days' written notice and at a mutually agreed time. The Controller or its mandated auditor may put questions and request demonstration of specific controls by screen share. This is available at no charge once in any 12-month period.

13.4 Inspection. Where a supervisory authority or mandatory law requires it, or where sections 13.2 and 13.3 have not resolved a specific documented compliance concern, the Controller or an independent auditor mandated by it may inspect the systems and records relating to the processing of personal data carried out on that Controller's behalf, on 60 days' written notice, during normal business hours, once in any 12-month period, at the Controller's cost including the Processor's reasonable time at an hourly rate notified to the Controller in advance of the inspection. The Processor operates no data centre and no business premises open to visitors. Production systems are hosted in facilities operated by the Sub-processors listed in Annex III; physical inspection of those facilities is a matter for the Sub-processor concerned, and the Processor makes available the certifications those Sub-processors hold and supports a request to them where they permit it. Inspection under this section is accordingly conducted remotely by screen share and document review, or at a location agreed by both parties, and does not take place at a private residence. The auditor must not be a competitor of the Processor and must be bound by a written confidentiality undertaking. No access is given to another customer's personal data, to shared infrastructure in a manner that would compromise the security of another customer's data, or to source code other than by supervised inspection.

13.5 WinrickLabs LLC does not hold a SOC 2 report or ISO/IEC 27001 certification and does not undertake to obtain either. If it obtains an independent third-party audit report or certification during the term, provision of that report satisfies sections 13.2 and 13.3 in respect of the matters it covers.

13.6 Nothing in this section limits or derogates from the Controller's rights under Article 28(3)(h) GDPR or Clause 8.9 of the SCCs. Where a supervisory authority requires an audit or inspection on terms other than those set out above, the Processor complies with that requirement.

14. International transfers

14.1 Where Customer Personal Data is stored

European Union region. Accounts created on eu.fastcomments.com are provisioned to the European Union region. Customer Personal Data for those accounts is stored and processed on infrastructure located within the European Economic Area, including all live replicas and all backup copies. That data is not replicated to any region outside the European Economic Area.

Global region. For accounts created on fastcomments.com, Customer Personal Data is replicated across multiple regions, hosting providers and countries, including regions in the United States, in order to provide availability and to serve data close to end users. Each region maintains a live replica in a different region and with a different hosting provider.

The regions, hosting providers and countries applicable to each are listed in Annex III.

14.2 Remote administration

WinrickLabs LLC is established in the United States. Its personnel administer, maintain, monitor, support and provide incident response for all regions, including the European Union region, by remote access from the United States. The parties acknowledge that such remote access constitutes a transfer of personal data to a third country within the meaning of Chapter V GDPR, including in respect of data that is stored exclusively within the European Economic Area. The SCCs incorporated by section 14.3 therefore apply to all Customer Personal Data processed under this Agreement.

14.3 Standard Contractual Clauses

The SCCs, Module Two (transfer controller to processor), are incorporated into this Agreement by reference and form an integral part of it. Their text is published at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. The Controller is the data exporter and WinrickLabs LLC is the data importer. Where section 3.3 applies, Module Three is substituted.

The parties make the following elections under the SCCs:

Provision Election
Clause 7 (docking clause) Included. An entity that is not a party may accede as a data exporter by completing Annex I and signing Annex I.A.
Clause 9(a) (sub-processors) Option 2, general written authorisation. The notice period is 30 days, as set out in section 8.2.
Clause 11(a), optional paragraph (independent dispute resolution body) Not adopted. The optional paragraph does not apply.
Clause 13 and Annex I.C (competent supervisory authority) As determined under Annex I.C.
Clause 17 (governing law) Option 1. The SCCs are governed by the law of Ireland.
Clause 18(b) (choice of forum) The courts of Ireland. Clause 18(c) is preserved: a data subject may bring proceedings in the Member State of their habitual residence.

Clauses 8.9, 12, 14, 15 and 16 of the SCCs apply without modification. Sections 13 and 15 of this Agreement describe how those clauses are exercised in practice and do not limit them.

14.4 United Kingdom

For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference and applies to the SCCs as incorporated by section 14.3. Its tables are completed in Appendix 1.

14.5 Switzerland

For transfers subject to the FADP, the SCCs apply as amended by Appendix 2.

14.6 Transfer impact

The parties have no reason to believe, having regard to the circumstances of the transfer, the laws and practices of the United States and the safeguards applied, that the laws and practices applicable to WinrickLabs LLC prevent it from fulfilling its obligations under the SCCs.

Circumstances of the transfer. Customer Personal Data consists predominantly of content that the Controller publishes publicly on its own properties, together with display names, optional email addresses and, by default, salted cryptographic hashes of IP addresses rather than IP addresses themselves. No special categories of personal data are requested or required. The volume of personal data relating to each data subject is minimal by design.

United States surveillance law. WinrickLabs LLC is a privately held limited liability company. It has never received a directive, order, request or other process issued under Section 702 of the Foreign Intelligence Surveillance Act, under Executive Order 12333, in the form of a National Security Letter, or under the Clarifying Lawful Overseas Use of Data Act. It has no relationship of any kind with any United States intelligence agency, and it has never provided any government with direct or indirect access to Customer Personal Data. It is not among the large communications and cloud providers to which Section 702 directives have historically been directed, and it operates no facility to which such collection has been applied.

Safeguards. Full-disk encryption at rest on all servers including backup targets; TLS 1.2 or higher for all data in transit; European Union region data residency with no replication of that data outside the European Economic Area; storage of IP addresses as salted hashes unless the Controller elects otherwise; multi-factor authentication on all production, provider, domain registrar and source control accounts; access to production systems restricted to named individuals on the principle of least privilege; and the commitments in section 15 to challenge unlawful requests, to disclose only the minimum required and to notify the Controller wherever legally permitted.

Reassessment. The Processor re-performs this assessment at least annually, and on becoming aware of any change in applicable law or practice that could affect it. Where it can no longer comply with the SCCs it notifies the Controller in accordance with Clauses 14(f) and 16.

14.7 Data Privacy Framework

WinrickLabs LLC is not certified under the EU-US Data Privacy Framework, the UK Extension to it, or the Swiss-US Data Privacy Framework, and does not rely on an adequacy decision as its transfer mechanism. It relies on the SCCs.

15. Government and law enforcement requests

On receiving a legally binding request from a public authority for disclosure of Customer Personal Data, the Processor: notifies the Controller promptly unless legally prohibited from doing so, and where prohibited uses reasonable efforts to obtain a waiver of that prohibition; challenges the request where it is unlawful, overbroad, or conflicts with the law of the European Union or a Member State; discloses no more than the minimum required under a careful assessment of the request; and documents the request and makes that documentation available to the Controller and to the competent supervisory authority on request.

As at 5 August 2026, WinrickLabs LLC has received no such request.

16. Records of processing

The Processor maintains a record of all categories of processing activities carried out on behalf of controllers containing the information required by Article 30(2) GDPR, and makes that record available to a supervisory authority on request.

17. Liability

17.1 The liability of each party under this Agreement is subject to the exclusions and limitations of liability set out in the Principal Agreement, to the extent those exclusions and limitations apply to that party. Those same exclusions and limitations apply equally to claims under this Agreement and to claims under the Principal Agreement. This Agreement does not create any separate or additional limitation of liability.

17.2 Section 17.1 does not limit or exclude: any liability that cannot be limited or excluded under applicable law; the liability of either party to a data subject under Clause 12 of the SCCs or under Article 82 GDPR; or either party's obligations to a supervisory authority.

17.3 The arbitration and class action waiver provisions of the Terms of Service do not apply to any claim arising under this Agreement or under the SCCs.

18. Term, termination and survival

This Agreement takes effect on the Effective Date and continues for as long as the Processor processes Customer Personal Data, notwithstanding any termination of the Principal Agreement. Sections 6, 7, 10, 12, 13, 14, 15 and 17 survive termination.

19. Governing law and jurisdiction

19.1 This Agreement, and any dispute or claim arising out of or in connection with it including a non-contractual dispute or claim, is governed by the laws of the Republic of Ireland, and the courts of Ireland have jurisdiction. This section prevails over the governing law, venue, arbitration and class action waiver provisions of the Terms of Service in respect of disputes arising under this Agreement.

19.2 Section 19.1 is without prejudice to Clause 18(c) of the SCCs, under which a data subject may bring proceedings in the Member State of their habitual residence.

19.3 For transfers subject to the UK GDPR, the governing law and forum provisions of the UK Addendum apply in place of section 19.1.

20. Changes to this Agreement

20.1 The Processor may update this Agreement where a change in Data Protection Laws, a decision of a supervisory authority or court, a change to the SCCs or the UK Addendum, or a change to the Service requires it.

20.2 The Processor notifies the Controller's account administrator by email at least 30 days before a material change takes effect, and publishes the updated Agreement on this page. Non-material changes take effect on publication.

20.3 Where the Controller objects to a material change on reasonable data protection grounds within 30 days of notice, the parties discuss the matter in good faith. Failing agreement, the Controller may terminate the affected Service without any early termination charge or other adverse consequence, and with a pro-rata refund of prepaid fees for the unused portion of the term.

21. General

21.1 Notices. Notices to the Processor under this Agreement are sent to privacy@fastcomments.com. Notices to the Controller are sent to the account administrator's email address and to any privacy contact designated in the administration console. A notice sent by email is deemed received on the next business day after sending.

21.2 Electronic form. The parties agree that this Agreement in electronic form satisfies Article 28(9) GDPR and any requirement that the contract be in writing.

21.3 Severability. If a provision of this Agreement is held invalid or unenforceable, the remainder continues in effect.

21.4 No waiver. A failure to exercise a right under this Agreement is not a waiver of it.

21.5 Assignment. The Processor may assign this Agreement to a successor in connection with a merger, acquisition or sale of all or substantially all of its assets, on notice to the Controller.

21.6 Entire agreement. This Agreement is the entire agreement between the parties in respect of the processing of Customer Personal Data.

22. Language

This Agreement is drafted and executed in the English language. Translations are made available for convenience. In the event of any inconsistency, ambiguity, conflict or difference of interpretation between the English version and a translation, the English version prevails and is the sole authoritative and binding version for all purposes, including interpretation, performance and the resolution of any dispute. Entity names, addresses, statutory citations and the text of the SCCs are not translated. Each party confirms that it acts in the course of its business and has had the opportunity to obtain independent translation and legal advice. This section does not affect the Controller's own obligations under Articles 12 to 14 GDPR to provide information to data subjects in clear and plain language.

23. Contact point and regulatory status

23.1 The contact point for all data protection matters, including requests under sections 8.4, 13.2 and 13.3, is privacy@fastcomments.com, WinrickLabs LLC, 50 Iron Point Circle, Suite 140, PMB 1019, Folsom, CA 95630, United States.

23.2 WinrickLabs LLC has not appointed a Data Protection Officer, having assessed that the criteria in Article 37(1) GDPR are not met.

23.3 WinrickLabs LLC does not hold, and does not claim to hold, SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 27701, FedRAMP, HITRUST, PCI DSS or CSA STAR certification. Any certification referred to in this Agreement in respect of a Sub-processor is held by that Sub-processor in respect of its own facilities and services and is not a certification of WinrickLabs LLC.

24. Execution

Processor

WinrickLabs LLC, doing business as FastComments
50 Iron Point Circle, Suite 140, PMB 1019
Folsom, CA 95630, United States

Chief Executive Officer
Executed 5 August 2026

Controller

To be completed by Controller

To be completed by Controller

Accepted by the Controller on acceptance of the Terms of Service, or by countersignature of this Agreement.

Annex I

A. List of parties

Data exporter

Name To be completed by Controller
Address To be completed by Controller
Contact person To be completed by Controller
Activities relevant to the data transferred Operating one or more websites, applications or services on which the FastComments commenting, live chat and discussion Service is deployed, and administering the user-generated content submitted through it.
Signature and date Effected by acceptance of the Terms of Service, or by countersignature of this Agreement, on the Effective Date.
Role Controller. Processor where section 3.3 applies.

Data importer

Name WinrickLabs LLC, doing business as FastComments, a limited liability company organised under the laws of the State of California, United States.
Address 50 Iron Point Circle, Suite 140, PMB 1019, Folsom, CA 95630, United States.
Contact person Chief Executive Officer, privacy@fastcomments.com
Activities relevant to the data transferred Provision, hosting, administration, maintenance, support and security of a multi-tenant online commenting, live chat and discussion platform, including remote administration of European Union and non-European Union region infrastructure from the United States.
Signature and date Executed 5 August 2026.
Role Processor.

B. Description of the transfer

Categories of data subjects

Categories of personal data

Sensitive data

The Service is not designed for special categories of personal data, and under section 5.4 the Controller does not knowingly submit them and instructs its end users accordingly. Where an end user includes such data in free-text content of their own volition, the following restrictions apply: encryption at rest; access restricted to the minimum number of authorised persons; no secondary use; no profiling; no disclosure other than as instructed by the Controller or required by law; and no use for the development or training of any model.

Frequency of the transfer

Continuous, on an ongoing basis, for the duration of the Principal Agreement.

Nature of the processing

Collection, recording, organisation, structuring, storage, retrieval, consultation, transmission and public display on the Controller's properties, moderation and content filtering, automated spam and image moderation scoring where the Controller enables it, notification delivery, backup and replication, restriction, erasure and destruction.

Purpose of the transfer and further processing

Provision of the Service to the Controller, delivery of notifications, moderation and abuse prevention, security, availability and disaster recovery, and technical support, in each case solely on the Controller's documented instructions.

Retention period

For the duration of the Principal Agreement and thereafter as set out in section 12. Individual records are erased earlier on the instruction of the Controller or a data subject.

Transfers to sub-processors

As set out in Annex III, which states for each Sub-processor the subject matter and nature of its processing and its duration, being the term of the Principal Agreement or, for a Sub-processor engaged only by an optional feature, the period for which the Controller enables that feature.

C. Competent supervisory authority

  1. Where the data exporter is established in a Member State of the European Union: the supervisory authority of that Member State.
  2. Where the data exporter is not established in a Member State of the European Union but falls within the territorial scope of the GDPR under Article 3(2) and has appointed a representative under Article 27: the supervisory authority of the Member State in which that representative is established.
  3. Where the data exporter is not established in a Member State of the European Union and has not appointed a representative under Article 27: the Data Protection Commission of Ireland.
  4. For transfers subject to the UK GDPR: the Information Commissioner's Office.
  5. For transfers subject to the FADP: the Federal Data Protection and Information Commissioner.

Annex II - Technical and organisational measures

The measures below are those implemented by WinrickLabs LLC. Measures described as applying to a data centre or to a Sub-processor's platform are implemented by that Sub-processor in respect of its own facilities.

1. Pseudonymisation and encryption of personal data

2. Confidentiality, integrity, availability and resilience of processing systems

3. Restoring availability and access after an incident

4. Regular testing, assessing and evaluating of effectiveness

5. User identification and authorisation

6. Protection of data during transmission

7. Protection of data during storage

8. Physical security

9. Event logging

10. System configuration and governance

11. Certification and assurance

WinrickLabs LLC does not hold, and does not claim to hold, SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 27701, FedRAMP, HITRUST, PCI DSS or CSA STAR certification, and makes no representation that it will obtain any such certification. Any certification referred to in this Agreement in respect of a Sub-processor is held by that Sub-processor in respect of its own facilities and services. Payment card data is not stored or processed by WinrickLabs LLC; card details are collected and processed directly by its payment Sub-processor.

12. Data minimisation, quality and retention

13. Portability and erasure

14. Measures for transfers to Sub-processors

Annex III - List of Sub-processors

The Controller gives a general written authorisation to the engagement of the Sub-processors listed below. The Sub-processor Page is the canonical current list and is incorporated into this Agreement by reference. "Region" states whether the Sub-processor processes data for European Union region accounts, global region accounts, or both.

Sub-processor Processing activity Location of processing Region
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
Hosting of application and database servers. Hetzner Finland Oy, Huurrekuja 10, 04360 Tuusula, Finland, is engaged by Hetzner Online GmbH for building rental and technical support at the Finnish site. Falkenstein, Germany. Tuusula, Finland. Both
OVH SAS
2 rue Kellermann, 59100 Roubaix, France
Hosting of application and database servers. Gravelines, France European Union
OVH GmbH
Oskar-Jäger-Str. 173/K6, 50825 Köln, Germany
Hosting of application and database servers. Limburg an der Lahn, Germany European Union
OVH US LLC
11950 Democracy Drive, Suite 300, Reston, VA 20190, United States
Hosting of application and database servers. Hillsboro, Oregon and Vint Hill, Virginia, United States Global
BrainStorm Network, Inc., trading as OneProvider
3275 Av Francis-Hughes, Laval, QC H7L 5A5, Canada
Hosting of application and database servers. OneProvider resells capacity operated by third parties at this location. São Paulo, Brazil Global
Wasabi Technologies LLC
75 Arlington Street, Suite 810, Boston, MA 02116, United States
Object storage of encrypted periodic backup copies. Frankfurt, Germany for European Union region backups. Oregon, United States for global region backups. Both
Akamai Technologies, Inc.
145 Broadway, Cambridge, MA 02142, United States
Delivery of outbound webhook events to endpoints nominated by the Controller. United States Both
Deep Infra, Inc.
2625 Middlefield Road #460, Palo Alto, CA 94306, United States
Automated spam classification, image content moderation, and the moderation agent and assistant features. Engaged only where the Controller enables one or more of those features. United States Both, where enabled
Mailgun Technologies, Inc.
112 E Pecan Street #1135, San Antonio, TX 78205, United States
Delivery of notification and transactional email to end users and administrators. United States or the European Union, according to the region selected for delivery Both
SIB INC. US, trading as Brevo
2140 South Dupont Highway, Camden, DE 19934, United States, part of the group headed by Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France
Delivery of notification and transactional email to end users and administrators. France and Belgium Both

Contractual status of Sub-processors. Each Sub-processor listed above is engaged under a written contract incorporating that provider's data processing terms, with the following two exceptions, which are stated here so that the Controller can assess them.

Deep Infra, Inc. does not publish a data processing agreement or standard contractual clauses, and no such contract is in place as at 5 August 2026. WinrickLabs LLC is pursuing one. This Sub-processor is engaged only where the Controller enables the automated spam classification, image content moderation, moderation agent or assistant features. Those features are off by default. Where the Controller does not enable them, no Customer Personal Data is disclosed to this Sub-processor at any time. A Controller that does not wish its data to be processed by this Sub-processor may leave those features disabled, or disable them, at any time and without charge. The provider's published terms state that data submitted to its interfaces is not stored, sold or used to train models. The models used by the Service are hosted by that provider on its own infrastructure; no data is passed through to any further model vendor.

BrainStorm Network, Inc. does not publish a data processing agreement, and no such contract is in place as at 5 August 2026. WinrickLabs LLC is pursuing one. This Sub-processor hosts servers in the global region only. No Customer Personal Data belonging to a European Union region account is processed by this Sub-processor at any time.

Vendors that do not process Customer Personal Data. Stripe, LLC, Corporation Trust Center, 1209 Orange Street, Wilmington, DE 19801, United States, processes the Controller's own billing and payment data. That is Account Data within the meaning of section 3.2, for which WinrickLabs LLC acts as an independent controller, and it is therefore not a Sub-processor under this Agreement. Payment card details are collected and processed directly by Stripe and are not stored by WinrickLabs LLC.

Services operated without a third party. Content delivery, application logging, error reporting and support ticketing are operated by WinrickLabs LLC on the infrastructure listed above. No third-party content delivery network, logging service, error tracking service, analytics service or support desk receives Customer Personal Data.

Appendix 1 - UK International Data Transfer Addendum

For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference and its tables are completed as follows. Where the UK Addendum's mandatory clauses conflict with the SCCs as incorporated by section 14.3, the UK Addendum prevails in respect of those transfers.

Table 1: Parties Start date: the Effective Date. Exporter: the Controller, as set out in Annex I.A. Importer: WinrickLabs LLC, as set out in Annex I.A. Key contacts: as set out in Annex I.A.
Table 2: Selected SCCs, modules and selected clauses The Approved EU SCCs as incorporated by section 14.3, Module Two, with the elections stated in that section: Clause 7 included; Clause 9 Option 2 with a 30 day notice period; the optional paragraph of Clause 11 not adopted; Clause 17 Option 1, Ireland; Clause 18(b) Ireland.
Table 3: Appendix information Annex 1A List of Parties: Annex I.A of this Agreement. Annex 1B Description of Transfer: Annex I.B. Annex II Technical and Organisational Measures: Annex II. Annex III List of Sub-processors: Annex III.
Table 4: Ending this Addendum when the Approved Addendum changes Neither Party.

In the SCCs as they apply to transfers subject to the UK GDPR: references to the GDPR are read as references to the UK GDPR; references to Regulation (EU) 2016/679 are read as references to that Regulation as retained in United Kingdom law and to the Data Protection Act 2018; references to a supervisory authority are read as references to the Information Commissioner; references to a Member State are read as references to the United Kingdom; and references to the European Economic Area are read as references to the United Kingdom.

Appendix 2 - Swiss amendments

Where a transfer is subject to the FADP, the SCCs apply with the following amendments.

  1. The competent supervisory authority under Clause 13 and Annex I.C is the Federal Data Protection and Information Commissioner in respect of transfers governed exclusively by the FADP. Where a transfer is governed by both the FADP and the GDPR, the Federal Data Protection and Information Commissioner is competent for the Swiss aspects and the authority identified under Annex I.C for the European Union aspects.
  2. References to the GDPR are read as references to the FADP where the transfer is governed by it, and references to European Union or Member State law are read as references to Swiss law where applicable.
  3. The term "Member State" is not interpreted so as to exclude data subjects in Switzerland from the possibility of bringing proceedings in their place of habitual residence in accordance with Clause 18(c).
  4. The SCCs also protect the personal data of legal entities to the extent required by applicable Swiss law.
  5. Clause 17 and Clause 18(b) apply as elected in section 14.3, without prejudice to paragraph 3 of this Appendix.