Legal
Data Processing Addendum
Last updated 12 February 2026
1. Roles and scope
This addendum applies whenever Cardline processes personal data on your behalf under the terms of service. You act as controller, we act as processor, and we process only on your documented instructions — the instructions being the terms, this addendum, and your configuration of the product.
2. Subject matter and duration
Subject matter: providing digital business cards and the surrounding admin. Duration: the term of the subscription plus the deletion window in section 8.
3. Categories of data and data subjects
- Data subjects — your members with cards, and recipients who choose to share their details back through a card.
- Personal data — names, job titles, work contact details, photos, organization, social links, and any contact fields a recipient submits.
- No special categories. The product is not designed for special-category or children's data, and you agree not to upload it.
4. Our obligations
- Process only on your instructions, and tell you if we believe an instruction breaches data protection law.
- Keep personnel with access bound by confidentiality and least-privilege access.
- Maintain the technical and organisational measures described on our security page.
- Assist you with data-subject requests, impact assessments, and regulator enquiries.
- Make available the information needed to demonstrate compliance, and allow audits on reasonable notice.
5. Subprocessors
You give general authorisation for the subprocessors below. Each is under a written agreement with obligations no less protective than this addendum. We publish changes and email account admins at least 30 days before a new subprocessor starts processing, so you can object on reasonable data-protection grounds.
- Cloud hosting and database — infrastructure, EU or US region depending on your plan.
- Transactional email — account, billing, and notification email.
- Payment processing — subscription billing and invoices.
- Error monitoring — diagnostics with personal data scrubbed before transmission.
6. International transfers
Where personal data leaves the EEA, UK, or Switzerland, transfers are covered by the EU Standard Contractual Clauses (2021/914) with the UK International Data Transfer Addendum where relevant, plus a transfer impact assessment on request. EU data residency is available on the Business plan.
7. Personal data breach
We notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data. The notice describes what we know, the likely consequences, the measures taken, and a contact point, and we follow up as the picture develops.
8. Deletion and return
On termination, or on your written request, we delete or return your personal data within 30 days, including from backups on their normal rotation, except where law requires us to keep a copy. Admins can export card and contact data as CSV or vCard at any time before then.
9. Liability and precedence
The liability provisions of the terms of service apply to this addendum. Where this addendum conflicts with the terms on the processing of personal data, this addendum prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Questions a lawyer needs answered?
Email legal@gocardline.com and you will get a person, not a ticket number.