Skip to content
The Autist
  • Home
  • About
  • Blog
  • Wiki
  • Sign in
  • Sign up
Menu
Home About Blog Wiki Sign in Sign up

Data Processing Addendum

The extra terms that apply when we process personal data on your behalf.

This Data Processing Addendum (“DPA”) is between AWFixer, LLC (“Processor”, “we”) and the customer who accepts the Terms of Service (“Controller”, “you”). It is part of the Terms. It applies only where we process personal data on your documented instructions as a processor — for example if you use the Site in a business context and we handle personal data you provide about other people. For your own account, newsletter, and ordinary site use, we are the controller; see the Privacy Policy. Effective 17 September 2026.

1. Definitions

“Personal data”, “processing”, “controller”, “processor”, “sub-processor”, and “data subject” have the meanings in the EU GDPR, UK GDPR, and similar laws that apply (“Data Protection Law”). “Services” means theautist.me as described in the Terms.

2. Roles and instructions

You are the controller of Customer Personal Data you submit to the Services. We are the processor. We will process that data only to provide the Services, to follow your reasonable written instructions, and as required by law. The Terms and this DPA are your standing instructions. If we must process data for a legal obligation, we will tell you unless the law forbids it.

3. Details of processing

  • Subject: hosting and delivery of the Site, accounts, memberships, and email you request.
  • Duration: for the term of the Services, then deletion or return as in section 9.
  • Nature: storage, transmission, display, backup, and support.
  • Types of data: names, email addresses, account and billing identifiers, messages you send, and technical logs.
  • Data subjects: your users, subscribers, staff, and other people whose data you submit.

4. Confidentiality and security

People who process Customer Personal Data for us are bound to confidentiality. We use appropriate technical and organizational measures for a small membership site: TLS in transit, access control, signed sessions, passkey authentication, and subprocessors who publish their own security programs. No method is perfectly secure. You are responsible for what you submit and for keeping your passkeys under your control.

5. Sub-processors

You authorize us to use the sub-processors listed below (and their successors) to deliver the Services. We will impose data-protection terms on them that are no less protective than this DPA. We will post material changes to this list on this page. If you object to a new sub-processor on reasonable data-protection grounds, we will discuss alternatives; if we cannot agree, you may stop using the affected Service.

  • Fly.io — application hosting.
  • Supabase — database and authentication.
  • Stripe — payment processing.
  • Resend — email delivery.
  • PostHog — product analytics, feature flags, experiments, session replay, error tracking, and the support widget.

6. International transfers

Processing takes place in the United States and in the regions our sub-processors operate. Where Data Protection Law requires a transfer tool, the parties agree that the EU Standard Contractual Clauses (processor-to-processor or controller-to-processor, as the roles require), and the UK IDTA/Addendum where applicable, are incorporated by reference. You appoint us to enter into those clauses with sub-processors on your behalf as needed to provide the Services.

7. Assistance

Taking into account the nature of processing, we will help you respond to data-subject requests, and with DPIAs and consultations with authorities, by providing information we actually have. We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will share facts we know so you can meet your own notice duties.

8. Audits

On written request, no more than once per year unless a competent authority requires more, we will provide a written description of our measures and, where available, third-party reports from sub-processors (SOC 2, ISO 27001, or equivalent). On-site audits are limited to what is reasonable, at your cost, with reasonable notice, and without access to other customers’ data.

9. Return and deletion

When the Services end, we will delete Customer Personal Data from production systems within 30 days, except copies in backups that expire in the ordinary cycle, and except data we must keep for law, disputes, or security. You may request a reasonable export before deletion by emailing hello@theautist.me.

10. Liability and order

Liability under this DPA is subject to the limits in the Terms, except where Data Protection Law forbids limiting liability. If this DPA and the Terms conflict on data-protection duties for processor activity, this DPA controls. This DPA lasts as long as we process Customer Personal Data.

  • Legal
  • Privacy Policy
  • Terms of Service
The Autist
The Autist

The Autist is the Founder of AWFixer Church Group, a sociologist, and a curious technologist.

Subscribe
  • Site
    • Home
    • About
    • Blog
    • Wiki
    • Membership
    • Subscribe
  • Account
    • Sign in
    • Sign up
  • Legal
    • Overview
    • Privacy
    • Terms
    • DPA
  • AWFixer's Church
  • AWFixer's Army
  • AWFixer Political Party
  • AWFixer, LLC
© 2026 The Autist. All rights reserved.

We can't find the internet

Attempting to reconnect

Something went wrong!

Attempting to reconnect