Last Updated: July 21, 2026
This Data Processing Addendum (this “DPA”) forms part of the Nara Creator Terms of Service (the “Terms”) between NASD Inc., Nara (“Nara”) and the Creator identified in the applicable account (“Creator”), and is automatically incorporated into and effective upon the Creator’s acceptance of the Terms. No separate signature is required. Capitalized terms not defined in this DPA have the meanings given in the Terms.
1. Definitions
i.“Applicable Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under this DPA, including, to the extent applicable, the California Consumer Privacy Act, as amended (“CCPA”), the Colorado Privacy Act, and other U.S. state privacy laws.
ii.“Personal Data” means End User Data (as defined in the Terms) that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person and that Nara processes on Creator’s behalf in connection with the Terms.
iii.“Process,” “Controller,” “Processor,” “Business,” “Service Provider,” “Sell,” and “Share” have the meanings given in Applicable Data Protection Laws.
iv.“Subprocessor” means a third party engaged by Nara to Process Personal Data on Creator's behalf.
2. Roles; Scope of Processing
i.As between the parties, Creator is the Controller (or Business) of Personal Data and Nara is the Processor (or Service Provider), except as provided in Section 2(iii). Nara will Process Personal Data on Creator’s behalf as described in Annex A.
ii.Creator’s instructions to Nara for the Processing of Personal Data are: (a) Processing as necessary to provide the Platform under the Terms (including hosting the Storefront, facilitating transactions, subscriptions, refunds, communications, and the AI Features); and (b) Processing documented in additional written instructions that are consistent with the Terms and reasonable in light of the Platform’s functionality. Nara will notify Creator if, in its opinion, an instruction violates Applicable Data Protection Laws (Nara is not obligated to monitor Creator’s compliance with law).
iii.Platform Purposes. Notwithstanding Section 2(i), Creator acknowledges that Nara Processes limited Personal Data as an independent Controller (or Business) solely for the following purposes: (a) securing the Platform and detecting and preventing fraud, abuse, and security incidents; (b) complying with Applicable Laws, responding to legal process, and enforcing the Terms and the AUP; and (c) creating de-identified or aggregated data as permitted by Section 6(iv). Nara’s independent Processing is described in Nara’s Privacy Policy.
3. Nara Obligations as Processor / Service Provider
i.Purpose limitation; CCPA certification. Nara will Process Personal Data only as described in this DPA and will not: (a) Sell or Share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in this DPA and the Terms, or outside the direct business relationship between the parties; or (c) combine Personal Data with personal information Nara receives from other sources, except as permitted for Service Providers under the CCPA and its regulations (including for the Platform Purposes and de-identification). Nara certifies that it understands and will comply with the restrictions of this Section 3(i).
ii.Confidentiality. Nara will ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations.
iii.Security. Nara will implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Personal Data, as described in Annex B.
iv.Rights requests. Taking into account the nature of the Processing, Nara will provide reasonable assistance to Creator in responding to verifiable consumer requests to exercise rights under Applicable Data Protection Laws (access, deletion, correction, portability, opt-out). If Nara receives such a request directly from an End User that relates to Creator’s use of Personal Data, Nara will route the request to Creator without undue delay and, where feasible, provide self-service tools to assist. Nara may fulfill deletion or access requests directly where required by Applicable Data Protection Laws.
v.Security incidents. Nara will notify Creator without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, and will provide information reasonably available to Nara to assist Creator in meeting its breach notification obligations.
vi.Deletion and return. Upon termination of the Terms and expiration of the export window described in the Terms, Nara will delete Personal Data Processed on Creator’s behalf, except to the extent retention is required or permitted by Applicable Laws or the data has been de-identified, in which case Nara will continue to protect the retained data under this DPA for so long as it is retained.
vii.Assessments; audits. Nara will make available information reasonably necessary to demonstrate compliance with this DPA, which Nara may satisfy by providing summaries of third-party audit reports or security assessments no more than once annually, and will allow and cooperate with reasonable assessments to the extent required by Applicable Data Protection Laws. Nara may take reasonable steps to remediate any unauthorized use of Personal Data identified by such assessments, and Creator may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data by Nara as provided under the CCPA.
4. Subprocessors
i.Creator provides general authorization for Nara to engage Subprocessors to Process Personal Data, provided that Nara: (a) maintains a current list of Subprocessors, which, as of the effective date, includes Stripe, Inc. (payments and verification); Anthropic, PBC and OpenAI, LLC (AI model services); Google Cloud, Amazon Web Services, and Railway (cloud hosting, analytics, and communications providers), (b) provides notice of new Subprocessors (which may be by updating such list with a mechanism to receive notice), giving Creator the opportunity to object on reasonable data protection grounds, in which case the parties will work in good faith to resolve the objection, and if it cannot be resolved, Creator may terminate the Terms and receive a pro-rata refund of prepaid subscription fees; (c) imposes on each Subprocessor data protection obligations no less protective than those in this DPA; and (d) remains responsible for each Subprocessor’s performance.
ii.For the avoidance of doubt, Phyllo Inc. processes Creator social media information as Nara’s service provider as described in the Privacy Policy; that processing relates to Creator’s (not End Users’) information and is governed by the Terms and the Privacy Policy.
5. Creator Obligations
i.Creator will: (a) comply with Applicable Data Protection Laws in its use of the Platform and its own Processing of Personal Data, including maintaining and displaying its own privacy notice where required and establishing a lawful basis for Processing; (b) ensure its instructions to Nara comply with Applicable Data Protection Laws; (c) use Personal Data obtained through the Platform only to serve its relationship with its End Users, and not Sell or Share Personal Data or use it for targeted advertising off the Platform; and (d) promptly forward to Nara any rights request that implicates Nara’s Processing.
6. General
i.International transfers. Personal Data is Processed in the United States. If the parties later agree that Nara will Process personal data subject to the GDPR, UK GDPR, or other non-U.S. data protection laws, the parties will execute appropriate transfer mechanisms (such as the EU Standard Contractual Clauses), which are not included in this DPA as of the effective date.
ii.Liability. Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Terms, and this DPA does not create any third-party beneficiary rights.
iii.Order of precedence; term. This DPA controls over conflicting terms of the Terms with respect to the Processing of Personal Data. This DPA is effective for as long as Nara Processes Personal Data on Creator’s behalf.
Annex A — Description of Processing
i.Subject matter and duration: Processing of End User Data in connection with the operation of Creator’s Storefront, for the duration of the Terms plus the wind-down and retention periods described in the Terms and this DPA.
ii.Nature and purpose: hosting and operating the Storefront; facilitating purchases, subscriptions, tips, refunds, and chargebacks (with payment card data processed by Stripe); delivering purchased content; operating AI-assisted communications and support features; providing analytics to Creator about its own Storefront; and providing customer support.
iii.Categories of data subjects: End Users — visitors to and purchasers on Creator’s Storefront.
iv.Categories of Personal Data: identifiers and contact information (name, email address, shipping address); transaction and order data (purchases, subscriptions, tips, refunds); communications (messages, refund requests, AI chat transcripts); user-generated content (comments, reviews); and device and usage data associated with the Storefront. Not processed for Creator: full payment card numbers (held by Stripe); no sensitive data categories are intended to be collected through Storefronts.
Annex B — Security Measures (Summary)
i.Nara maintains a security program that includes, at a minimum: encryption of Personal Data in transit (TLS) and at rest; access controls based on least privilege, with multi-factor authentication for administrative access; logical separation of Creator environments; secure software development and code review practices; vulnerability management and patching; logging and monitoring; vendor security review for Subprocessors; personnel confidentiality obligations and security training; incident response procedures; and business continuity and backup procedures.