GDPR Data Processing Addendum
Effective July 22, 2026
This Data Processing Addendum ("DPA") supplements the Privacy Policy and Terms of Service of the InPsychNow™ platform ("Service"). It applies where the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the UK GDPR governs the processing of your personal data. In the event of a conflict, this DPA controls with respect to the processing of personal data of individuals in the EU, EEA, or United Kingdom.
Important: InPsychNow™ is not offered to residents of the European Economic Area, the United Kingdom, or Switzerland, and access from those regions is technically blocked. This Addendum applies only to any residual processing and to the users we serve outside those regions.
1. Roles and Definitions
ASA Family Investments LLC (d/b/a InPsychNow) ("we," "us") acts as the data controller for personal data processed through the Service. Terms such as "personal data," "processing," "data subject," "controller," and "processor" have the meanings given in Article 4 of the GDPR.
2. Scope and Purpose of Processing
- Subject matter: provision of the Cadence Method™ Service.
- Duration: for the life of your account, plus retention periods described in the Privacy Policy.
- Nature and purpose: account management, personality and timing assessment, personalized recommendations, billing, and transactional communication.
- Categories of data: identity and contact data, assessment responses, usage data, and billing status. We process limited special-category data (wellness and mood inputs, wearable health metrics, and an optional spiritual-tradition preference) only with your explicit consent under Article 9(2)(a); these features are optional and off by default.
- Categories of data subjects: registered users of the Service.
3. Legal Bases for Processing
- Contract performance (Art. 6(1)(b)): processing your account, assessment, and subscription data to deliver the Service.
- Consent (Art. 6(1)(a)): analytics cookies, marketing emails, and behavioral tracking. You may withdraw consent at any time via your Privacy Settings or the cookie banner, without affecting the lawfulness of prior processing.
- Legitimate interest (Art. 6(1)(f)): product improvement, fraud prevention, and system security, balanced against your rights and freedoms.
4. Sub-Processors
We engage the following sub-processors, each bound by data protection terms no less protective than those in this DPA:
- Supabase: database and authentication (US).
- Vercel: hosting and edge functions (US).
- Stripe: payment processing (PCI-DSS compliant).
- Resend: transactional and sequence email delivery.
- PostHog: product analytics (data minimized; no full IP storage).
We will give you the opportunity to object to any new sub-processor by notifying registered users at least 14 days before a new sub-processor begins processing personal data.
5. International Data Transfers
Personal data may be transferred to and processed in the United States by our sub-processors. Such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum, together with supplementary measures including encryption in transit (TLS) and at rest, and access controls enforced by Row-Level Security.
6. Data Subject Rights
If you are located in the EU, EEA, or UK, you have the following rights, which you may exercise from your Privacy & Data settings or by emailing legal@inpsychnow.com:
- Access (Art. 15): request a copy of the personal data we hold about you.
- Rectification (Art. 16): correct inaccurate personal data.
- Erasure (Art. 17): request deletion ("right to be forgotten").
- Restriction (Art. 18): request limited processing during a dispute.
- Portability (Art. 20): export your data in machine-readable JSON.
- Objection (Art. 21): object to processing based on legitimate interest.
- Withdraw consent (Art. 7): withdraw any previously given consent.
We respond within 30 days as required by Article 12. For complex requests we may extend by up to 60 days and will notify you within the initial period.
7. Security Measures
Consistent with Article 32, we maintain encryption in transit and at rest, Row-Level Security at the database layer, least-privilege access controls, and regular security reviews. Each user can only access their own records.
8. Personal Data Breaches
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware, and notify affected data subjects without undue delay where the breach is likely to result in a high risk, in accordance with Articles 33 and 34.
9. Data Retention and Deletion
We retain personal data for as long as your account is active. Upon deletion, data is purged within 30 days except where longer retention is required by law (e.g., billing records). You may initiate deletion from Settings → Account → Delete Account.
10. Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights under the GDPR have been infringed.
11. Contact
Data protection questions: legal@inpsychnow.com
ASA Family Investments LLC (d/b/a InPsychNow) (Data Controller) · Dallas, TX
https://inpsychnow.com