Data Processing Policy
Effective Date: July 20, 2026
Summary
This summary is for readability only and is not a set of binding terms.
- Customer Data is private to Customer, encrypted in transit and at rest, and not sold or shared for cross-context behavioral advertising.
- Dance processes Customer Data only to provide, secure, support, troubleshoot, bill, and improve Customer's deployment of the Dance services, and only according to Customer's documented instructions.
- Customer Data is not used to train or fine-tune any shared or foundation AI model, whether Dance's or a provider's.
- AI requests containing Customer Data are routed only through approved model-provider paths configured for Zero Data Retention or equivalent no-training/no-retention controls, as applicable to the feature used.
- Dance may retain general know-how and method-level learnings, but only where they contain no Customer Data, Customer Confidential Information, identifiers, metrics, keywords, page names, competitors, campaign names, customer-specific results, or business-specific facts.
- Customer controls access for its users and may request export or deletion of Customer Data as described below.
Introduction - Incorporated Terms and Underlying Agreement
| Field | Value |
|---|---|
| Underlying agreement | The master services agreement, order form, statement of work, design-partner agreement, pilot agreement, or other written agreement between the parties (the “Agreement”). |
| Incorporated terms | Common Paper DPA Standard Terms, Version 1.1, incorporated by reference. In case of conflict, the order of precedence is: (1) this Introduction and the Modifications and Additional Commitments; (2) the Common Paper Standard Terms; (3) the Agreement. |
Annex I: Details of Processing
| Item | Description |
|---|---|
| Subject matter | Marketing, analytics, advertising, search, website, AI-conversation, account, usage, and support data processed by the Dance platform on Customer's behalf. |
| Nature and purpose | Ingesting, storing, analyzing, classifying, searching, and generating marketing intelligence from the sources Customer connects; operating, securing, supporting, troubleshooting, improving Customer's deployment of the services; and billing or metering usage. |
| Documented instructions | Customer instructs Dance to process Customer Data as needed to provide the services under the Agreement, this DPA, Customer's product configuration, and any other written instructions accepted by Dance. |
| Personnel access | A limited authorized Dance team may access Customer Data only as reasonably necessary to configure, support, troubleshoot, secure, and improve Customer's deployment of the services, subject to confidentiality, least-privilege access, and access logging. |
| Duration | The Agreement term, plus return or deletion within 30 days of termination or request, except where law requires retention or data remains in backups until overwritten through ordinary backup cycles. |
| Categories of personal data | (a) Account information: names, work emails, roles, and authentication metadata of Customer team members; (b) connected marketing data: analytics, search, advertising, website, campaign, and performance data from sources Customer connects, which may include personal data of Customer customers or website visitors; (c) AI and support interactions: prompts, responses, transcripts, tickets, and related operational metadata; and (d) usage data: feature, cost, and metering information. |
| Categories of data subjects | Customer team members; Customer customers, prospects, website visitors, and end users as represented in connected marketing data; and any individuals included in AI or support interactions submitted by Customer. |
| Sensitive or special-category data | None expected. Dance does not request sensitive or special-category personal data, and Customer agrees not to submit it unless the parties have expressly agreed in writing to additional protections. |
| Processing operations | Collection, connection, retrieval, hosting, storage, organization, structuring, encryption, analysis, search, classification, generation, transmission, deletion, and return/export as required to provide the services. |
Annex II: Security Measures
Baseline measures as of 2026-07-08. Dance may update these measures over time, provided it does not materially reduce the overall protection of Customer Data.
- Encryption. Customer Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Connection credentials are separately encrypted using AES-256-GCM or an equivalent strong encryption method.
- Tenant isolation. Customer Data is kept private to Customer's workspace and is isolated through database-level controls, including row-level security or equivalent tenant-isolation enforcement, checked on requests to the service.
- Access control. Customer admins control access for Customer users. Dance personnel access is role-based, limited to authorized personnel, and governed by confidentiality and least-privilege requirements.
- Access logging and review. Administrative and AI-processing access is logged where reasonably available. Dance reviews access patterns and limits access when it is no longer needed.
- AI-call hygiene. Dance minimizes personal details before sending Customer Data to AI models where reasonably practical for the task. AI-call logs contain operational metadata unless content logging is necessary for support, debugging, abuse prevention, or security.
- Model-provider controls. AI requests containing Customer Data are routed only through approved model-provider paths configured for Zero Data Retention or equivalent no-training/no-retention controls, as applicable to the provider and feature. Dance does not route Customer Data to model endpoints that permit prompt or output training on Customer Data.
- Subprocessor management. Dance uses subprocessors under written terms designed to be no less protective than this DPA and remains responsible for their processing as required by the Standard Terms.
- Infrastructure and availability. Dance uses cloud infrastructure and service providers with commercially reasonable security programs, including SOC 2, ISO 27001, or comparable controls where applicable.
- Incident response. Dance maintains an incident-response process and will notify Customer of security incidents affecting Customer Data as described in the Modifications and Additional Commitments.
- Deletion and backups. Dance deletes or returns Customer Data as described in this DPA. Backup copies may remain until overwritten in the ordinary course, subject to confidentiality and security controls.
Annex III: Approved Subprocessors
Dance may use the subprocessors below to provide the services. Optional subprocessors only receive Customer Data if the relevant feature is enabled or used by Customer. Vendor attestations are available via each provider's trust portal or under NDA where applicable. Dance will provide notice of material changes to the list as required by the Standard Terms or the Agreement.
Core Infrastructure
| Provider | Role | Data it handles |
|---|---|---|
| Supabase | Database and authentication | Stored application data, account and identity data, connected marketing data, usage metadata. |
| Vercel | Application hosting and AI request routing, including AI Gateway | Application traffic, logs, and AI context in transit. |
| Anthropic (Claude, via Vercel AI Gateway) | AI model for text and reasoning | Marketing context sent for analysis through approved no-training/no-retention paths. |
| OpenAI (via Vercel AI Gateway) | Embeddings, classification, and optional image/vision features if enabled | Text snippets, embeddings inputs, classification prompts, and optional image prompts or outputs through approved no-training/no-retention paths. |
| DigitalOcean | Website-crawling worker and related infrastructure | Customer public web pages, crawl results, and related operational metadata. |
| Deepgram (optional, only if voice input is enabled) | Speech-to-text | Audio recorded by Customer users and resulting transcripts. |
Connected Data Sources and Communications
| Provider | Role | Data it handles |
|---|---|---|
| Google (Analytics, Search Console, Ads, PageSpeed, sign-in) | Connected data sources and authentication | Customer analytics, search, advertising, website-performance data, and sign-in identity. |
| DataForSEO | Search ranking and keyword data | Customer tracked keywords, domains, and related SEO/search data. |
| Semrush | SEO and competitive-search data | Customer domains, keywords, and related SEO data. |
| Profound | AI-visibility data | Customer brand, query, keyword, and AI-visibility data. |
| Resend | Transactional email | Recipient name and email; report and notification content. |
| Slack (optional, only if Customer connects it) | Notifications and connector | Alerts and messages Customer routes through Slack. |
Internal operational tools. GitHub and Asana are used internally by Dance for product development and project management. Dance does not intentionally store Customer Data in these systems. Dance personnel may reference limited non-sensitive support metadata where necessary to resolve an issue, subject to internal data-handling rules.
Modifications and Additional Commitments
These commitments strengthen or clarify the incorporated Standard Terms and apply to all customer arrangements unless an executed agreement states otherwise.
- No model training. Customer Data is never used to train or fine-tune any shared or foundation AI model, whether Dance's or a provider's. Dance will not route Customer Data to AI model endpoints that permit prompt or output training on Customer Data.
- AI retention controls. AI requests containing Customer Data are routed only through approved model-provider paths configured for Zero Data Retention or equivalent no-training/no-retention controls, as applicable to the provider and feature. Dance will maintain reasonable documentation of the applicable gateway or provider settings.
- Limited service-improvement processing. Dance may use Customer Data to configure, support, troubleshoot, secure, and improve Customer's deployment of the services. Dance may not use Customer Data to build or improve another customer's workspace, report, recommendation, model, or output.
- Breach notice. Dance will notify Customer without undue delay and, in any event, within 72 hours after becoming aware of a security incident affecting Customer Data, with the information then reasonably available. Notice will be sent to the Customer notice contact or another security/privacy contact designated by Customer.
- Export and deletion on request. Customer may request export or deletion of Customer Data at any time. Dance will complete the request within 30 days unless law requires retention, the data is needed to complete an active transaction or support request, or the data remains in backups until overwritten through ordinary backup cycles.
- General know-how and shared playbooks. Dance may retain and use general know-how, ideas, methods, workflows, product learnings, and non-customer-specific marketing techniques developed while providing the services, provided they do not include Customer Data, Customer Confidential Information, Customer identifiers, metrics, amounts, keywords, page names, competitors, campaign names, customer-specific results, or other business-specific facts. Customer Data is excluded from shared playbooks; it is not anonymized and reused for other customers.
- US state privacy laws. To the extent US state privacy laws apply, including the CCPA/CPRA, Dance acts as Customer's service provider/processor. Dance will not sell or share personal information; will process personal information only for the business purposes described in this DPA and the Agreement; will not retain, use, or disclose personal information outside the direct business relationship except as permitted by law; will not combine personal information with other data except as permitted by law; will assist Customer with reasonable consumer-request obligations; will flow down materially similar obligations to subprocessors; and will notify Customer if Dance determines it can no longer meet these obligations.
- Transfers. Processing takes place primarily in the United States. If EEA, UK, or Swiss data-transfer laws apply, the transfer mechanisms in the incorporated Standard Terms, including applicable SCC mechanics, apply unless the parties execute a different transfer mechanism.
- Audits and assistance costs. The Standard Terms' audit limits apply unless the Agreement states otherwise. Each party bears its own internal costs for audits and data-subject-request assistance, and Customer bears any third-party auditor fees unless the audit reveals a material breach by Dance.
- Optional features. Optional features and related subprocessors, including voice input, Slack notifications, image or vision features, and any connected data source, apply only if Customer enables, connects, or uses the relevant feature.
