🚧 ctrlyoke is in active development and not yet released — follow progress on GitHub →
Back to home

ctrlyoke Data Processing Agreement

Processor: Fuzzy Nova LLC

Version: 1.0

Version Date: September 17, 2026

Effective Date: As to each Customer, the date that Customer accepts the Enterprise Terms or an Order incorporating this DPA, as described in Section 13.

This Data Processing Agreement (the DPA) forms part of the ctrlyoke Enterprise Subscription Terms (the Enterprise Terms), the ctrlyoke Commercial License (the EULA), and the applicable Order (collectively, the Agreement) between Fuzzy Nova LLC, a Texas limited liability company (Fuzzy Nova, Licensor, or Processor), and the customer identified in the Order (Customer). This DPA applies only to the extent Processor processes Customer Personal Data on Customer’s behalf in connection with the Enterprise subscription.

1. Definitions

Applicable Data Protection Law means data-protection and privacy laws applicable to the Processing of Customer Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation 2016/679 (EU GDPR), the EU GDPR as incorporated into United Kingdom law (UK GDPR), the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (Swiss FADP), and United States state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA).

Customer Personal Data means Personal Data Processed by Processor on Customer’s behalf to provide the Enterprise subscription, as further described in Annex I. It excludes Business Relationship Data.

Business Relationship Data means Personal Data that Licensor or a third party Processes as an independent Controller for its own business purposes, including payment and tax administration, product analytics and telemetry, account management, fraud and license-abuse prevention, legal compliance, and ordinary support correspondence.

Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It does not include unsuccessful attempts or events that do not compromise Customer Personal Data.

Sub-processor means a third party appointed by Processor to Process Customer Personal Data on Customer’s behalf.

EU SCCs means the standard contractual clauses for transfers of personal data to third countries adopted by European Commission Implementing Decision (EU) 2021/914, available through EUR-Lex.

UK Addendum means the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office, available from the ICO.

The terms Controller, Data Subject, Personal Data, Process, Processor, and Supervisory Authority have the meanings assigned by Applicable Data Protection Law. Sell and Share have the meanings assigned by the CCPA.

2. Roles and Scope

(a) Processing roles

Customer is a Controller of Customer Personal Data. If Customer acts as a Processor for another Controller, Processor is Customer’s Sub-processor, and Customer represents that it has authority from the relevant Controller to appoint Processor and give the instructions in this DPA.

Processor will Process Customer Personal Data only as a Processor or service provider on Customer’s behalf. Each party remains independently responsible for complying with Applicable Data Protection Law as it applies to that party.

(b) Independent-controller activities

This DPA does not govern Business Relationship Data. Licensor Processes that data as an independent Controller under the ctrlyoke Privacy Policy. In particular, product telemetry is collected for Licensor’s product analytics, reliability, debugging, and feature-planning purposes and is not Customer-directed Processing under this DPA.

Lemon Squeezy acts as merchant of record and authorized reseller for self-serve transactions. Its Processing of purchaser, payment, tax, and transaction data under its buyer terms is not Processing by a Sub-processor under this DPA.

(c) Local workspace content

The Software runs primarily on Customer-controlled infrastructure. It is not designed to send prompt text, workflow content, source code, file contents, file paths, workspace names, or AI output to Fuzzy Nova. Customer’s use of third-party AI services and locally installed harnesses is outside the scope of this DPA and is governed by Customer’s agreements with those providers.

3. Customer Instructions and Responsibilities

Customer instructs Processor to Process Customer Personal Data as necessary to provide and support Enterprise license issuance, delivery, activation, verification, renewal, and administration in accordance with the Agreement and Customer’s use of the Software. These instructions include transfers permitted by Section 12 and engagement of the Sub-processors in Annex II.

Processor will Process Customer Personal Data only on Customer’s documented instructions unless applicable law requires otherwise. If law requires Processing beyond Customer’s instructions, Processor will notify Customer before the Processing unless legally prohibited. Processor will promptly inform Customer if, in Processor’s opinion, an instruction infringes Applicable Data Protection Law.

Customer is responsible for:

  • the lawfulness, accuracy, and quality of Customer Personal Data and the means by which Customer obtained it;
  • providing required notices and obtaining required rights, authorizations, and consents;
  • ensuring its instructions comply with Applicable Data Protection Law; and
  • not providing special-category, sensitive, financial-account, health, or government-identification data for Processing under this DPA.

4. Confidentiality

Processor will ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and access the data only as necessary to perform the Agreement.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of the Processing, Processor will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The current measures are described in Annex IV.

Processor may update those measures as technology and the services evolve, provided an update does not materially reduce the overall protection of Customer Personal Data during a Subscription Term.

6. Security Incidents

Processor will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. As information becomes reasonably available, the notice will describe the nature of the Security Incident, affected data and Data Subjects, likely consequences, and measures taken or proposed to address it. Processor will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident and will reasonably cooperate with Customer’s legally required notices.

Notification is not an acknowledgment of fault or liability. Customer is responsible for notifying regulators and Data Subjects unless Applicable Data Protection Law assigns that duty to Processor.

7. Data-Subject Requests and Regulatory Assistance

Taking into account the nature of the Processing, Processor will provide reasonable assistance, including appropriate technical and organizational measures where feasible, for Customer to:

  • respond to requests by Data Subjects to exercise their rights;
  • comply with obligations concerning security, breach notification, data-protection impact assessments, and prior consultation with regulators; and
  • demonstrate compliance with Customer’s obligations concerning the Processing.

If Processor receives a request from a Data Subject concerning Customer Personal Data, Processor will notify Customer and will not respond except on Customer’s documented instructions or as required by law.

8. Return and Deletion

During the Subscription Term, Customer may request export or deletion of Customer Personal Data to the extent the applicable service supports it. After the services involving Processing end, Processor will, at Customer’s choice, delete or return Customer Personal Data and delete remaining copies, unless applicable law requires retention.

Unless Customer requests an earlier return or deletion, Processor will delete Customer Personal Data from systems under its control within ninety (90) days after the applicable services end. Deletion from backups and Sub-processor systems will occur under the applicable retention cycle. Data retained as required by law will be isolated and Processed only for the legally required purpose. These obligations do not apply to Business Relationship Data retained by Licensor as an independent Controller under the Privacy Policy.

9. Sub-processors

(a) General authorization

Customer generally authorizes Processor to engage the Sub-processors listed in Annex II. Processor will enter into a written agreement with each Sub-processor imposing data-protection obligations that provide at least the level of protection required by this DPA for the applicable Processing. Processor remains responsible to Customer for the Sub-processor’s performance of those obligations to the extent required by Applicable Data Protection Law.

(b) Changes and objections

Processor will give Customer at least thirty (30) days’ prior notice by email before authorizing a new or replacement Sub-processor to Process Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection, including by using a commercially reasonable alternative where available.

If the parties cannot resolve the objection, Customer may terminate the affected services by written notice before the new Sub-processor begins Processing. Licensor will refund prepaid fees attributable to the terminated portion of the affected services after the termination date. This termination and refund right is Customer’s sole remedy for an unresolved Sub-processor objection.

10. United States State Privacy Terms

To the extent the CCPA or a similar United States state privacy law applies to Customer Personal Data, Processor will:

  • Process Customer Personal Data only for the limited and specified business purposes in Annex I and the Agreement;
  • not Sell or Share Customer Personal Data;
  • not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the purposes specified in Annex I, except as permitted by Applicable Data Protection Law;
  • not combine Customer Personal Data with Personal Data received from another person or collected from Processor’s own interactions with a Data Subject, except as permitted by Applicable Data Protection Law;
  • provide the same level of privacy protection required of Customer by Applicable Data Protection Law;
  • notify Customer if Processor determines it can no longer meet those obligations; and
  • permit Customer to take reasonable and appropriate steps to monitor compliance and to stop and remediate unauthorized use of Customer Personal Data.

Processor certifies that it understands and will comply with the restrictions in this Section.

11. Information and Audit Rights

Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Audits ordinarily will begin with current third-party reports or certifications, if any, and a written security questionnaire.

If that information is not reasonably sufficient, Customer or an independent auditor mandated by Customer may conduct an audit, including an inspection, on reasonable prior written notice. Unless a Security Incident or regulator requires otherwise, an audit may occur no more than once in any twelve-month period, during normal business hours, and without unreasonable disruption. The auditor must not be a competitor of Licensor and must be bound by confidentiality. Customer will bear its audit costs, and Processor may charge reasonable costs for assistance beyond its ordinary compliance obligations. These restrictions do not limit audit rights that cannot lawfully be restricted.

Processor will promptly address material noncompliance identified by an audit and will inform Customer if an instruction requested in connection with an audit would violate Applicable Data Protection Law.

12. International Transfers

(a) Transfer mechanism and assessments

The parties will not transfer Customer Personal Data in violation of Applicable Data Protection Law. Where a transfer requires an adequacy mechanism, the parties will first rely on an applicable adequacy decision or data-privacy framework certification. Where no such mechanism applies, the relevant terms in this Section govern.

Each party will perform the transfer assessments required of it by Applicable Data Protection Law and the applicable transfer terms. Processor will provide information reasonably available to it, cooperate with Customer’s reasonable assessment requests, and implement mutually agreed supplementary measures where necessary to make a transfer lawful.

(b) European Economic Area

For a restricted transfer governed by the EU GDPR, the parties enter into and are bound by the unmodified EU SCCs, incorporated by reference and completed as follows:

  • Module Two applies where Customer is a Controller and Processor is a Processor.
  • Module Three applies where Customer is a Processor and Processor is a Sub-processor.
  • Clause 7 (docking) applies.
  • In Clause 9, Option 2 (general written authorization) applies, with the thirty-day notice period in Section 9(b).
  • The optional language in Clause 11 does not apply.
  • In Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland.
  • Under Clause 18, disputes will be resolved by the courts of Ireland.
  • Annex III of this DPA completes Annex I of the EU SCCs; Annex IV completes Annex II of the EU SCCs. The Sub-processors in Annex II are authorized under the general authorization in Clause 9, Option 2.
  • The competent Supervisory Authority under Clause 13 is determined by the data exporter’s establishment, representative, or affected Data Subjects as provided in that clause.

(c) United Kingdom

For a restricted transfer governed by the UK GDPR, the EU SCCs as completed above apply together with the UK Addendum. The UK Addendum’s Part 1 tables are completed as follows:

  • Table 1 (Parties and start date): The parties and their key contacts are identified in Annex III.A and III.B. The start date is the effective date of this DPA.
  • Table 2 (Selected EU SCCs): The Approved EU SCCs are the clauses dated 4 June 2021 and adopted by European Commission Implementing Decision (EU) 2021/914. The selected modules, clauses, and options are those stated in Section 12(b).
  • Table 3 (Appendix information): Annex III of this DPA completes Annex I.A and I.B of the EU SCCs; Annex IV of this DPA completes Annex II of the EU SCCs; and Annex II of this DPA identifies the Sub-processors for Annex III of the EU SCCs.
  • Table 4 (Ending the Addendum): Both the Importer and the Exporter may end the UK Addendum as set out in Section 19 of its mandatory clauses.

The parties incorporate the UK Addendum’s Part 2 by reference using the ICO’s required wording: “Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.” Those mandatory clauses control over conflicting terms.

(d) Switzerland

For a restricted transfer governed by the Swiss FADP, the EU SCCs as completed above apply with these adaptations: references to the EU GDPR include the Swiss FADP as applicable; references to EU Member States include Switzerland; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; and Clauses 17 and 18 are governed by Swiss law and the competent Swiss courts. If a transfer is also governed by the EU GDPR, its provisions and the selections in Section 12(b) remain applicable without limitation.

(e) Priority

The EU SCCs or UK Addendum control over this DPA to the extent of a conflict concerning a restricted transfer. Nothing in the Agreement modifies the EU SCCs or UK Addendum or prejudices Data Subject rights under them.

13. Liability, Term, and Priority

The limitations of liability in Section 13 of the EULA apply in aggregate across the Agreement and this DPA, except to the extent Applicable Data Protection Law or the applicable EU SCCs or UK Addendum prohibit that limitation.

This DPA takes effect when Customer accepts the Enterprise Terms or an Order incorporating it and remains in effect while Processor Processes Customer Personal Data. If this DPA conflicts with another part of the Agreement concerning Processing of Customer Personal Data, this DPA controls. Section 12(e) governs conflicts involving international-transfer terms.


Annex I — Details of Processing

Topic Description
Subject matter Enterprise license issuance, delivery, activation, verification, renewal, and administration.
Duration For the applicable Subscription Term and the deletion period in Section 8.
Nature and purpose Receive purchaser and order data from the merchant of record; create and administer an Enterprise license; deliver the license credential to Customer’s designated contact; register and validate Customer-authorized machines; renew, suspend, or revoke the license as required by the Agreement.
Frequency On purchase and renewal, and intermittently when an Authorized User activates, validates, refreshes, or deactivates a machine or when Customer requests license support.
Categories of Data Subjects Customer’s purchasing, billing, licensing, and administrative contacts; Authorized Users who activate or use the Enterprise license.
Categories of Personal Data Name; business email address; business address and official registration number of the contracting entity where provided or required for international-transfer documentation; order and subscription identifiers; license key, license status, and license metadata; the terms-acceptance record for the purchase (accepted document versions, acceptance method and timestamp, order identifier, purchaser email address); pseudonymous machine fingerprint and machine identifier; operating-system platform; IP address and request metadata associated with online license operations.
Sensitive or special-category data None intended or permitted. Customer must not submit such data for Processing under the DPA.
Retention criteria Active Subscription Term plus the deletion periods in Section 8; shorter or longer periods may apply where Customer requests deletion or applicable law requires retention.

Product telemetry, payment-card data, tax records, general website logs, and ordinary sales or support correspondence are Business Relationship Data or third-party Controller data and are not part of the Processing described in this Annex.

Annex II — Authorized Sub-processors

Sub-processor Address and contact Purpose Processing location Customer Personal Data
Keygen LLC 1606 Headway Cir, Suite 9246, Austin, TX 78754, USA; support@keygen.sh Enterprise license issuance, activation, verification, and administration United States Name, business email, order/subscription identifiers in license metadata, license key/status, pseudonymous machine fingerprint/identifier, operating-system platform, IP address and request metadata
Netlify, Inc. 101 2nd Street, San Francisco, CA 94105, USA; privacy@netlify.com Hosting the serverless webhook that receives purchase/subscription events and provisions licenses United States; global delivery network Name, business email, contracting-entity name, business address and official registration number where provided, order/subscription/product identifiers, terms-acceptance record, license key/status, and related request logs
Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, USA; privacy@resend.com Transactional delivery of the license credential and related service email United States; global email delivery network Recipient name and business email, license key, transactional message content and delivery metadata

For clarity, Lemon Squeezy is the merchant of record for the purchaser transaction, and Microsoft Azure Application Insights and Google Workspace may Process Business Relationship Data for Licensor’s independent purposes. They are disclosed in the Privacy Policy but are not Sub-processors for the Customer-directed Processing covered by this DPA.

Annex III — EU SCC and UK Addendum Party Details

A. Data exporter

  • Name and address: Customer, as identified in the Order or Enterprise checkout record
  • Contact: Customer’s billing or privacy contact identified in the Order or later provided to Processor
  • Official registration number: Customer’s official registration number stated in the Order or later provided to Processor, if any
  • Activities relevant to the transfer: Use and administration of the ctrlyoke Enterprise subscription
  • Role: Controller (Module Two) or Processor (Module Three)
  • Signature and date: Customer’s acceptance of the Agreement constitutes signature on the Agreement’s effective date

B. Data importer

  • Name and address: Fuzzy Nova LLC, 5518 Roosevelt Ave, Austin, TX 78756, USA
  • Contact: Privacy contact, privacy@ctrlyoke.dev
  • Official registration number: Texas Secretary of State file number 806796772
  • Activities relevant to the transfer: Provision and administration of the ctrlyoke Enterprise subscription as described in Annex I
  • Role: Processor (Module Two) or Sub-processor (Module Three)
  • Signature and date: Processor’s offering of the Agreement and Customer’s acceptance constitute signature on the Agreement’s effective date

C. Transfer description and Supervisory Authority

The categories of Data Subjects, Personal Data, sensitive data, frequency, nature, purposes, and retention period are stated in Annex I. The competent Supervisory Authority is determined under Section 12(b) for EU transfers, the UK Information Commissioner’s Office for UK transfers, and the Swiss Federal Data Protection and Information Commissioner for Swiss transfers.

Annex IV — Technical and Organizational Measures

Processor’s current measures for Customer Personal Data include:

  • Data minimization: The licensing workflow is limited to the fields in Annex I. The Software is designed not to send workspace content, prompts, source code, file contents, file paths, workspace names, or AI output to Processor.
  • Pseudonymous machine identity: The Software generates a random, persistent machine fingerprint rather than collecting a hardware serial number or hostname for license activation.
  • Encryption in transit: Browser, webhook, licensing, and transactional-email API traffic uses TLS.
  • License integrity: Offline license files are signed with Ed25519 and verified locally. Online activation credentials and signed license files are stored through the Software’s host-provided secret-storage abstraction rather than in workspace files.
  • Credential isolation: Keygen administrative credentials, Lemon Squeezy webhook secrets, and Resend API credentials are held in server-side environment configuration and are not shipped in the extension package.
  • Webhook authentication: Lemon Squeezy webhook signatures are verified over the raw request body using HMAC-SHA256 and constant-time comparison before a purchase event is processed.
  • Access control: Administrative access to licensing, payment, hosting, email, source-control, and deployment systems is limited to authorized personnel and protected by non-SMS multi-factor or phishing-resistant authentication where supported.
  • Sub-processor safeguards: Processor evaluates relevant vendor security and privacy documentation and maintains written data-protection terms with Sub-processors that satisfy Section 9.
  • Retention and deletion: Customer Personal Data is retained and deleted under Section 8 and the applicable Sub-processor retention cycle.
  • Incident response: Processor maintains contact channels for vulnerability and privacy reports, investigates suspected Security Incidents, takes reasonable containment and remediation steps, and gives notice under Section 6.
  • Review: Processor reviews these measures as the service and threat environment change and addresses material identified weaknesses on a risk-prioritized basis.

Copyright © 2026 Fuzzy Nova LLC. All rights reserved.