Data Processing Addendum

A Product of SoundBetter Inc. | Last Updated: July 22, 2026

This Data Processing Addendum (“DPA”) supplements and forms part of the Imagine Plugins Terms of Use (the “Agreement”) between SoundBetter Inc. (“SoundBetter,” “Processor”) and the customer who builds and distributes plugins through the Service (“Customer,” “Controller,” “you”). It applies only to SoundBetter's processing of End-User Data (defined below) on your behalf through the Service's licensing and copy-protection system. It does not apply to data for which SoundBetter is itself the controller, which is governed by the Imagine Plugins Privacy Policy.

Capitalized terms not defined here have the meaning given in the Agreement.

1. Definitions

1.1 “Data Protection Laws” means all privacy and data protection laws applicable to the processing of End-User Data, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended (CCPA).

1.2 “End-User Data” means personal data relating to your end users that SoundBetter processes on your behalf through the licensing and copy-protection system, as described in Annex I (for example license keys, activation and deactivation events, device or machine identifiers, and end-user email addresses provided during activation or trial requests).

1.3 “Controller,” “Processor,” “Data Subject,” “Personal Data Breach,” and “process” have the meanings given under Data Protection Laws. “Business,” “Service Provider,” and “sell” have the meanings given under the CCPA.

1.4 “Sub-processor” means any third party engaged by SoundBetter to process End-User Data.

2. Roles of the Parties

2.1 As between the parties, you are the Controller (and Business) of End-User Data and SoundBetter is your Processor (and Service Provider). SoundBetter processes End-User Data only on your behalf and at your direction to provide the Service.

2.2 You are responsible for the lawfulness of the End-User Data and of your instructions, for establishing a lawful basis for processing, for providing all required notices to and obtaining all required consents from your end users, and for honoring end-user rights. You represent and warrant that you have done and will continue to do so.

2.3 SoundBetter is not responsible for your compliance obligations as Controller and does not determine the purposes of processing End-User Data.

3. Processing on Instructions

3.1 SoundBetter will process End-User Data only on your documented instructions, including the instructions set out in this DPA, the Agreement, and your configuration and use of the Service, unless required to act otherwise by applicable law, in which case SoundBetter will inform you of that legal requirement before processing unless the law prohibits it on important grounds of public interest.

3.2 SoundBetter will inform you if, in its opinion, an instruction infringes Data Protection Laws. SoundBetter is not obligated to perform a legal review of your instructions and this does not diminish your responsibility for them.

4. Confidentiality

SoundBetter will ensure that personnel authorized to process End-User Data are bound by appropriate confidentiality obligations and process the data only as necessary to provide the Service.

5. Security

SoundBetter will implement and maintain technical and organizational measures designed to protect End-User Data appropriate to the risk, as described in Annex II, taking into account the nature, scope, and context of processing and the state of the art and cost of implementation. You acknowledge that the measures in Annex II are appropriate for the End-User Data processed and are your instruction as to the required security level. SoundBetter may update its measures from time to time provided the level of protection is not materially reduced.

6. Sub-processors

6.1 You provide SoundBetter general authorization to engage Sub-processors to process End-User Data. The Sub-processors engaged as of the effective date are listed in Annex III.

6.2 SoundBetter will impose on each Sub-processor data protection obligations that are substantially the same as those in this DPA to the extent applicable to the services the Sub-processor provides. SoundBetter remains responsible for its Sub-processors' performance of those obligations.

6.3 SoundBetter will notify you of any intended addition or replacement of a Sub-processor, giving you a reasonable opportunity to object on reasonable data-protection grounds before that Sub-processor begins processing End-User Data. Notice may be given by updating Annex III or a linked page, or by email. If you object on reasonable grounds and the parties cannot resolve the objection, your sole remedy is to stop using the affected part of the Service.

7. Assistance with Data Subject Requests

Taking into account the nature of the processing, SoundBetter will provide reasonable assistance, insofar as possible and by appropriate measures, to help you respond to Data Subject requests to exercise their rights. If SoundBetter receives such a request directly from a Data Subject relating to End-User Data, it will, where legally permitted, direct the Data Subject to you rather than respond to the substance. You are responsible for responding to Data Subject requests. SoundBetter may charge a reasonable fee for assistance beyond the functionality made available through the Service.

8. Personal Data Breach

8.1 SoundBetter will notify you without undue delay after becoming aware of a Personal Data Breach affecting End-User Data, and will provide information reasonably available to it to help you meet your own breach-notification obligations.

8.2 SoundBetter's notification is not an acknowledgment of fault or liability. You are responsible for any notifications to regulators or Data Subjects required in connection with a Personal Data Breach.

9. Data Protection Impact Assessments

Taking into account the nature of the processing and the information available to it, SoundBetter will provide reasonable assistance with your data protection impact assessments and prior consultations with supervisory authorities, insofar as they relate to SoundBetter's processing of End-User Data. SoundBetter may charge a reasonable fee for such assistance.

10. Return or Deletion

On termination of the Agreement, SoundBetter will, at your choice, delete or return End-User Data processed on your behalf, and delete existing copies, unless applicable law requires continued storage. SoundBetter may retain End-User Data to the extent and for the period required by law, and copies in routine backups will be deleted in the ordinary course of SoundBetter's backup rotation. This DPA continues to apply to any retained End-User Data.

11. Audit and Demonstration of Compliance

11.1 SoundBetter will make available to you information reasonably necessary to demonstrate compliance with this DPA, primarily through written responses to reasonable questionnaires and any third-party certifications or audit reports SoundBetter holds.

11.2 To the extent the mechanisms in 11.1 do not satisfy a mandatory audit right you have under Data Protection Laws, you may conduct an audit no more than once per twelve-month period, on at least thirty (30) days' written notice, during business hours, without unreasonably disrupting SoundBetter's operations, subject to confidentiality, and at your expense. On-site audits are limited to SoundBetter's own facilities and systems and exclude Sub-processor facilities and any data of other customers.

12. International Transfers

Where SoundBetter transfers End-User Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference and completed as set out in Annex IV, or another lawful mechanism. In the event of conflict between such clauses and this DPA as to transferred data, the clauses control.

13. CCPA Service Provider Terms

13.1 With respect to End-User Data subject to the CCPA, SoundBetter acts as a Service Provider. SoundBetter will not sell or share End-User Data, will not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, and will not retain, use, or disclose it outside the direct business relationship between the parties.

13.2 SoundBetter will not combine End-User Data with personal data it receives from other sources, except as permitted by the CCPA. SoundBetter certifies that it understands and will comply with the restrictions in this Section.

14. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's total liability applies in the aggregate to all claims under both the Agreement and this DPA. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws.

15. General

15.1 This DPA forms part of the Agreement. In the event of a conflict between this DPA and the Agreement as to the processing of End-User Data, this DPA controls. In all other respects the Agreement remains in full force.

15.2 This DPA is governed by the same law and dispute-resolution terms as the Agreement, except where Data Protection Laws require otherwise.

15.3 This DPA takes effect on the effective date of the Agreement and continues while SoundBetter processes End-User Data on your behalf.

Annex I: Details of Processing

  • Subject matter: Provision of the Imagine Plugins licensing and copy-protection system.
  • Duration: For the term of the Agreement and any period of permitted retention thereafter.
  • Nature and purpose: Issuing, validating, activating, deactivating, and enforcing licenses for plugins you distribute; provisioning trials; surfacing activation information in your dashboard; and supporting these functions.
  • Categories of Data Subjects: Your end users (purchasers and trial users of plugins you distribute).
  • Categories of End-User Data: License keys; activation and deactivation events; device or machine identifiers (including device name and operating system); and end-user email addresses provided during activation or trial requests.
  • Special categories: None intended to be processed.

Annex II: Technical and Organizational Security Measures

  • Encryption of End-User Data in transit using TLS.
  • Encryption of End-User Data at rest where provided by the underlying hosting and licensing platforms.
  • Access to End-User Data restricted to authorized personnel on a least-privilege basis.
  • Multi-factor authentication required for administrative access to systems processing End-User Data.
  • Use of reputable infrastructure and Sub-processors that maintain recognized security certifications (for example SOC 2 or ISO 27001).
  • Logging and monitoring of access to systems processing End-User Data.
  • Timely application of security updates to systems under SoundBetter's control.
  • A documented process for responding to security incidents affecting End-User Data.
  • Data minimization: collection limited to the data needed to operate the licensing system.

Annex III: Approved Sub-processors

Sub-processorService providedLocation
KeygenLicense issuance, validation, and activationUnited States
Google Cloud PlatformHosting and storageUnited States
SupabaseDatabase hostingUnited States
ResendTransactional license-delivery emailUnited States

Annex IV: International Transfer Details

These transfer elections apply where End-User Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision. See the incorporation note below for how the official clause text is incorporated.

  • Standard Contractual Clauses module: Module Two (Controller-to-Processor).
  • Docking clause (Clause 7): Not used.
  • Clause 11 optional redress language: Not used.
  • Governing law of the SCCs (Clause 17): Ireland.
  • Supervisory authority (Clause 13): The Irish Data Protection Commission.
  • Time-period and other options within the clauses: As set out in the body of this DPA; no additional or inconsistent periods are elected.
  • UK International Data Transfer Addendum: Applies to transfers of UK data. It attaches to the EU SCCs (Module Two) completed above. Table 1 (parties) is populated from the parties to this DPA; Table 2 identifies the EU SCCs above; Table 3 is supplied by Annexes I, II, and III of this DPA; and under Table 4, the party that may end the addendum if the UK approved version changes is the data importer (SoundBetter).
  • Swiss transfers: Where Swiss data is in scope, the EU SCCs apply with the amendments required by Swiss law (references to the GDPR read as references to the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority).
  • Annexes to the SCCs: Annex I of this DPA supplies the processing details; Annex II supplies the security measures; Annex III supplies the list of Sub-processors.

How the official clause text is incorporated

This Annex sets out the parties' elections only. The operative clauses are the official texts, incorporated by reference and completed with the elections above:

  • The EU Standard Contractual Clauses are the version approved by European Commission Implementing Decision (EU) 2021/914, Module Two, available from the European Commission.
  • The UK International Data Transfer Addendum is the version issued by the UK Information Commissioner's Office (ICO) under section 119A of the Data Protection Act 2018.

By entering into this DPA, the parties agree to those official clauses as completed by this Annex.