Data Processing Agreement
Between The Cold Standard ("Processor") and the customer ("Controller").
Last updated: 8 October 2026
This DPA applies to any Personal Data The Cold Standard processes on the Controller's behalf in connection with the newsletter and its optional paid tiers. The Cold Standard is operated by R7AD (Yahia Riad Hanniz), sole proprietor, Markham, Ontario, Canada.
1. Roles & allocation of responsibility
The Controller is responsible for the lawfulness of its processing, the accuracy of the data it provides, and satisfying its own regulatory obligations (for example CASL where it applies, and GDPR where the Controller is in the EEA/UK). The Cold Standard is the Processor and processes data only on the Controller's documented instructions. The Cold Standard does not determine whether the Controller is compliant; providing the service is not a representation of compliance.
2. Permitted processing
Only to: provide and secure the service, deliver the editions the Controller (or its subscribers) asked for, comply with law, and improve the product with aggregate non-identifying data. The Cold Standard shall not use Personal Data for unrelated purposes.
3. Sub-processors
The Cold Standard uses the sub-processors Stripe (payments), Supabase (database), Resend (email delivery) and Netlify (hosting & CDN), maintains a current list of them, and informs the Controller of material changes.
4. Security
Appropriate technical and organisational measures (encryption in transit, access controls, least-privilege). The Cold Standard does not claim a specific certification (e.g. SOC 2, ISO 27001) unless separately obtained.
5. Data subject rights
The Cold Standard will assist the Controller in responding to data subject requests (access, correction, deletion, portability) and complying with applicable data protection law.
6. Retention & deletion
On termination, The Cold Standard will delete or return the data as directed, except where retention is required by law. Data is processed only as long as needed for the service or as required by law.
7. International transfers
Where data is transferred outside the EEA/UK, The Cold Standard will use appropriate safeguards (e.g. Standard Contractual Clauses) to the extent required by law.
8. Liability
Nothing in this DPA alters the liability allocation in The Cold Standard's Terms of Use.