> ## Documentation Index
> Fetch the complete documentation index at: https://recurr.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing Addendum

> How Recurr processes subscriber personal data on your behalf — roles, purposes, security, sub-processors, and your rights as the controller.

**Version v1.1 · 10 Aug 2026.** This Data Processing Addendum forms part of the
migration agreement between Recurr Pty Ltd (ABN 31 693 957 809, "Recurr") and
the customer named in that agreement. It applies whenever Recurr processes
personal data of your subscribers on your behalf.

It is **set out in full inside the agreement itself** rather than linked from
it, so what you sign is the whole instrument and neither of us has to rely on a
page that can change afterwards. This copy is published so you can read it
before you sign — it is kept identical to the signed text by an automated
check. A countersigned copy is available on request.

> Questions about any of it — [matt@recurr.dev](mailto:matt@recurr.dev).

## Roles

You are the controller of your subscribers' personal data. Recurr is your
processor. Your own Stripe account holds and processes payment credentials
under your direct agreement with Stripe — full card data never passes through
or rests on Recurr systems.

## What we process, and why

* Data subjects: your app's subscribers.
* Data categories: subscriber identifiers and contact data (email address, name
  where provided), subscription state (plan, status, tenure, store-vs-web
  billing status, cohort assignment), payment metadata (amounts, currency,
  timestamps, outcome — never card numbers), and migration and support workflow
  status and motion outcomes.
* Purposes: operating your migration program and the Oikos platform — migration
  communications, checkout and billing surfaces, payment recovery, cancellation
  and win-back motions, statements and reporting. Also producing the anonymous
  record described below, which is an act of stripping data rather than of using
  it.
* Duration: the term of the migration agreement.

## How we process

* On your instructions only. The agreement, your configuration in the platform,
  and your written instructions are the complete set of processing
  instructions. We process for no other purpose.
* The anonymous record. We keep a record of what happens across the programs we
  run, and it is what our decisioning learns from. It is a separate store
  holding no identifiers and no key back to your systems or ours — nothing in it
  can be traced to a subscriber, to you, or to any other customer, by us or by
  anyone else. Because it identifies no one it is not personal data, and it is
  not governed by this addendum. Producing it is a one-way step: personal data
  goes in, and what comes out cannot be turned back into it.
* No sale, no advertising, and your subscribers' data never trains anyone else's
  model. Subscriber personal data is never sold, never used for advertising, and
  never sent to a third party to train their AI models. Where our decisioning
  learns from personal data, it learns from what happens in your account in
  order to serve your account, and never to serve another customer's.
* Confidentiality. Access is limited to personnel who need it to deliver the
  service, under confidentiality obligations.
* Security. Technical and organisational measures include encryption in transit
  and at rest, access controls, and audit logging. We review these measures
  regularly.
* Analytics hygiene. Product analytics run on opaque identifiers — never
  subscriber email addresses or names.

## Sub-processors

We use the following sub-processors to deliver the service: Supabase
(application database and authentication), Vercel (application hosting), Stripe
(payment processing, on your own account), Resend (transactional and campaign
email delivery), PostHog (product analytics, opaque identifiers only), and
Sentry (error monitoring, no subscriber personal data in events).

We will notify you at least 14 days before adding or replacing a sub-processor.
If you reasonably object on data-protection grounds, we will work with you to
resolve the objection, and you may end the engagement per the agreement's exit
terms if we cannot.

## International transfers

Recurr is an Australian company subject to the Privacy Act 1988 (Cth). Where
subscriber data of EU/UK data subjects is processed, transfers rely on the
applicable standard contractual clauses or an equivalent lawful mechanism, and
this addendum is read to include the obligations those clauses require of a
processor.

## Your rights and our assistance

* Data subject requests. We assist with access, correction, deletion, and
  portability requests relating to subscriber data we process, within 10
  business days of your request.
* Breach notification. We notify you without undue delay after becoming aware of
  a personal data breach affecting your subscriber data — targeting 72 hours —
  with the information you need for your own notification obligations.
* Audit. Once per year, on 30 days' notice, we will answer reasonable written
  security questionnaires and provide summaries of relevant assessments. On-site
  or technical audits are available where legally required, at shared cost.

## Return and deletion

At the end of the engagement, on your instruction we return subscriber data we
hold in a portable format and then delete it from our live systems within 14
days, except where retention is legally required. Managed backups are not
deleted on demand: data in them ages out on our provider's schedule, and if a
restore inside that window returns deleted data, the deletion is re-applied.
Your Stripe account — and everything in it — was always yours and simply remains
with you.

## Precedence

If this addendum conflicts with the migration agreement on the subject of
personal data, this addendum prevails. It is governed by the same law as the
agreement — Victoria, Australia.
