• 1. Roles; Scope; Instructions
  • 2. Processor Obligations
  • 3. Retention; Deletion; Return
  • 4. Data Location
  • 5. Audits; Reports
  • 6. Security Incidents
  • 7. Government & Third-Party Requests
  • 8. Order of Precedence; Liability; Governing Law
  • Annex I: Description of Processing
  • Annex II: Technical & Organizational Measures (TOMs)
  • Annex III: Sub-processors
  • Changelog
  • Data Processing Addendum (DPA)


    Effective date: October 24, 2025 · Version: 1.0.0

    This DPA is incorporated into the Agreement between Blazing Cacti LLC (“Processor”) and the Customer (“Controller”) and applies only to Blazing Cacti’s hosted services, including Cloud Sync. Mix It Up Desktop stores data locally on the user’s device and is out of scope for this DPA.

    1. Roles; Scope; Instructions

    1.1 Roles. Customer is Controller (or “Business” under U.S. privacy laws). Blazing Cacti is Processor (or “Service Provider/Contractor”).
    1.2 Scope. Processor will process Personal Data solely to provide the hosted services under the Agreement and this DPA.
    1.3 Instructions. Processor will act only on Controller’s documented instructions, including with respect to retention, deletion, and disclosures to third parties.

    2. Processor Obligations

    2.1 Confidentiality. Processor ensures personnel with access to Personal Data are bound by confidentiality.
    2.2 Security. Processor implements appropriate technical and organizational measures described in Annex II.
    2.3 Sub-processors. Processor may engage sub-processors listed in Annex III under written contracts imposing data-protection obligations no less protective than this DPA. Processor will notify Controller of material changes and, if Controller objects on reasonable grounds, the parties will work in good faith to resolve; if not resolved, Controller may terminate affected services.
    2.4 Assistance. Taking into account the nature of processing, Processor will reasonably assist Controller with (a) security, (b) data subject requests (by routing requests to Controller and by making available export and deletion functionality), and (c) DPIAs/consultations where required by Controller’s law.
    2.5 Prohibitions (CPRA service provider/contractor). Processor will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for purposes other than providing the services to Controller; (c) combine Personal Data with data obtained from other sources except as permitted for service operation, security, or as instructed by Controller.

    3. Retention; Deletion; Return

    3.1 Hosted default. Processor retains Personal Data for the duration described in Annex I, unless Controller instructs otherwise. 3.2 Deletion/Return. Upon Controller’s deletion of the data or written request, Processor will delete or return Personal Data and delete remaining copies within standard backup cycles, except for limited security logs and disaster-recovery backups retained for integrity and legal defense and not used for any other purpose.

    4. Data Location

    Personal Data is processed and stored in the United States.

    5. Audits; Reports

    On reasonable written request no more than annually, Processor will provide available third-party security reports or complete a security questionnaire relating to Annex II. If additional audit rights are mandated by applicable law, the parties will agree on scope, timing, and controls to minimize disruption and protect confidentiality.

    6. Security Incidents

    Processor will notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data on Processor’s systems. Notification will include available information on the nature of the incident, likely consequences, and measures taken or proposed.

    7. Government & Third-Party Requests

    Processor will not disclose Personal Data to any government or third party except (a) as instructed by Controller; or (b) where required by valid U.S. legal process, in which case Processor will (where legally permitted) notify Controller to permit Controller to seek protection.

    8. Order of Precedence; Liability; Governing Law

    8.1 Precedence. If there is a conflict between this DPA and the Agreement, this DPA controls regarding Personal Data.
    8.2 Liability. Liability is governed by the Agreement’s limitations, except to the extent prohibited by applicable law.
    8.3 Governing Law. This DPA is governed by the laws of Nevada, USA, without regard to conflict-of-laws rules; venue as set in the Agreement.


    Annex I: Description of Processing

    • Data Subjects: the Customer (subscriber) and audience members/visitors whose data the Customer chooses to back up via Cloud Sync.
    • Categories of Personal Data: usernames/IDs, chat and event payloads received through the Customer’s connected platform pipelines (which may include incidental data relayed from services the Customer has not directly connected), timestamps, channel identifiers, and configuration/settings data; no special categories are intentionally processed.
    • Purpose: backup and synchronization of the Customer’s selected data at the Customer’s direction; security and abuse prevention; support.
    • Duration: until the Customer deletes the data, and in any event deleted 180 days after the Customer’s qualifying Patreon membership lapses; disaster-recovery backups age out within 365 days.

    Annex II: Technical & Organizational Measures (TOMs)

    • Access control: least-privilege IAM; MFA; role-based access; logging of privileged actions.
    • Data in transit/at rest: TLS 1.2+ in transit; encryption at rest for storage and backups; key management via reputable KMS.
    • Segregation: per-tenant logical separation; environment isolation.
    • Development & change: code review, CI/CD with artifact signing; secrets management.
    • Monitoring & logging: centralized logs (no audience message content mining), alerting, retention schedules published in Security Policy.
    • Incident response: runbook with triage, containment, eradication, recovery, post-mortems; customer comms “without undue delay.”
    • Vendor management: security review of sub-processors; contractual flow-downs; periodic reassessment.

    Annex III: Sub-processors

    Vendor Purpose Data types Region
    Vultr (The Constant Company, LLC) Cloud hosting and infrastructure (websites, Cloud Sync, self-hosted telemetry) Account/link data, Cloud Sync data, telemetry, operational logs US
    Google LLC Website analytics (Google Analytics 4); email and productivity (Google Workspace); mobile push notifications (Firebase Cloud Messaging, when the cross-platform application ships) Usage/device data; business correspondence; push tokens US
    Microsoft Corporation Crash and telemetry analytics (Azure Application Insights) Diagnostics and crash data US
    Cloudflare, Inc. CDN, DNS/edge, and network security Network metadata (IP addresses, request logs) US
    Apple Inc. Mobile push notifications (APNs) — planned with the cross-platform application Push tokens US

    Updates: Processor will post sub-processor changes at https://mixitup.bot/dpa/updates or notify by email; Controller may object on reasonable grounds within 10 business days.

    Contact (privacy): privacy@mixitup.bot

    Changelog

    • v1.0.0 (October 24, 2025): Initial published version of the consolidated Mix It Up legal suite.

    Site Settings

    Accessibility

    Choose how the site looks. System follows your device setting.

    Cookies

    Choose which cookies to allow. Your preference is saved for 6 months.

    Necessary
    Required for the site to function correctly. Cannot be disabled.
    Analytics
    Helps us understand how visitors use the site. No personal data is shared with third parties.