Data Processing Agreement
Last updated: September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you and Beijing Zhisuan Cube Technology Co., Ltd., registered in China as Beijing Zhisuanlifang Keji Youxian Gongsi ("FoundeReview"), for foundereview.com.
1. Scope and roles
This DPA governs personal data processed through the Service. FoundeReview is the controller for the data it collects from account holders and visitors (account, content, subscription, and technical data).
2. Subject-matter and duration
FoundeReview processes personal data to provide the Service for the duration of your account, and afterwards only as required to meet legal obligations before deletion or anonymization. Published contributions remain in the public archive after account deletion, pseudonymized as described in the Privacy Policy.
3. Categories of data
- Account data: name, email, and identity-provider profile basics.
- Content data: the contributions you publish — public by design, carrying your byline and your product.
- Subscription data: your email and the unsubscribe tokens for occasional review emails.
- Technical data: logs, device, usage information, and technical error diagnostics.
4. Sub-processors
We engage a limited set of sub-processors, each under its own data-processing terms:
- Dodo Payments — payment merchant of record.
- Alibaba Cloud RDS — PostgreSQL database hosting.
- Cloudflare — edge hosting, caching, and object storage.
- Resend — transactional email and occasional review emails.
- Alibaba Cloud — screenshot rendering and public-metadata fetching servers.
We will give notice of changes to this list and remain responsible for our sub-processors' compliance.
5. International transfers
Personal data is processed in the regions where we and our sub-processors operate. Where data is transferred internationally, we rely on appropriate safeguards under our sub-processors' data-processing terms.
6. Security
We apply technical and organizational measures appropriate to the risk, including access controls, encryption in transit, and least-privilege service credentials.
7. Assistance with data-subject rights
We respond to data-subject requests — access, correction, export, and deletion — taking into account the nature of the processing. Deletion means pseudonymization: published contributions remain, detached from your identity.
8. Personal-data breach notification
We will notify affected users without undue delay after becoming aware of a personal-data breach, with the information needed to meet their own obligations.
9. Deletion on termination
On termination, we will delete or pseudonymize personal data, except where retention is required by law. We make available the information reasonably necessary to demonstrate compliance with this DPA.