Draft for legal review

This is a plain-English draft for the Human Made pilot. A lawyer has not reviewed it yet, and it may change before the final version.

Data Processing Agreement

How Human Made handles personal data on behalf of each brand. It is part of the Brand Terms.

Version 2026-10-02. Last updated 2 October 2026. Human Made, operated by Kyle Yeoman.

1. About this agreement

This agreement is between the brand that accepts the Brand Terms ("the brand" or "you") and Human Made, operated by Kyle Yeoman ("Human Made", "we" or "us"). It is part of the Brand Terms and applies whenever we process personal data on the brand's behalf.

Where this agreement and the Brand Terms disagree about personal data, this agreement applies.

2. Who is responsible for what

The brand is the controller, and Human Made is the processor, of the personal data in the brand's workspace. This includes:

  • Designer contact data the brand receives: a designer's name and contact email once they accept one of the brand's briefs, and their payee name, country and payment contact email once the brand finalizes a statement for them.
  • Designer display names, codes and submissions, as they appear in the brand's workspace.
  • Data the brand adds: team members it invites, internal notes and ratings about designers, review notes and feedback, briefs, brand kit files and uploaded exports.
  • Records of what the brand's team members do in the workspace, such as the brand's audit log.

Human Made is a separate controller for the account data each person gives us to run their own account, such as their sign-in details, security records and designer profile, and for data we must keep to meet the law, protect the service or prevent abuse. Our Privacy Policy covers that data.

3. Your instructions

We process the brand's personal data only to provide Human Made to the brand, as described in the Brand Terms and this agreement, and as the brand directs through its use and settings of the product. These are the brand's complete instructions. We will tell you if we believe an instruction breaks data protection law.

We do not sell the brand's personal data, use it for advertising, or use it for any purpose of our own beyond running, securing and supporting Human Made.

4. Details of the processing

ItemDetails
Subject matterRunning the brand's Human Made workspace: briefs, review, leaderboards, statements and team management.
DurationWhile the brand uses Human Made, then until deletion under section 11.
What we do with itStore it, show it to the people allowed to see it, send emails about it, and calculate earnings from it.
Whose dataDesigners who accept the brand's briefs or appear in its workspace; the brand's team members and the people it invites.
Kinds of dataNames, email addresses, designer display names and codes, payee name, country and payment contact email, submissions and the feedback on them, notes, and records of actions with IP address and browser.
Sensitive dataNone expected. The brand must not upload sensitive data such as health or financial account details.

5. Who at Human Made can access it

Only people who need access to run and support Human Made, and who are bound to keep it confidential. During the pilot that is the operator.

Support access to a brand's workspace is read only, needs a written reason, lasts at most 60 minutes, and is recorded in the brand's audit log.

6. Subprocessors

The brand agrees that we use these subprocessors to provide Human Made:

ServiceWhat it does for Human MadeWhat it handles
Vercel Inc.Hosts the website and app, runs the server code, and stores uploaded files (Vercel Blob).Everything the app shows or stores passes through it, including uploaded files, and request logs with IP addresses.
Neon (Postgres database)Stores the database: accounts, briefs, submissions, statements, logs, and its backups.All account and workspace records.
Google LLC (Gmail)Sends account, security and work emails during the pilot, from a Human Made Gmail account.Recipient name and email address, and the email's content, which can include sign-in links.
Cloudflare, Inc. (Turnstile)Checks that a person, not a bot, is signing up, requesting brand access, resetting a password, or signing in after failed tries.IP address and browser signals during the check.

Each subprocessor works under its own data processing terms, which require it to protect the data. We remain responsible to the brand for their work. The list is also at Subprocessors.

These providers may process data in the United States and other countries. Where the law requires a safeguard for a transfer, we rely on each provider's own transfer terms.

7. Changes to subprocessors

We will email the brand's Owners and update the list at least 30 days before we add or replace a subprocessor. The brand may object for a reasonable data protection reason within that time. If we cannot address the objection, the brand may close its workspace, and the change does not apply to it before then.

8. Security measures

We protect the brand's personal data with these measures:

  • All traffic uses HTTPS, with strict security headers. Our database and file storage providers encrypt stored data.
  • Every brand's data is kept apart in the database by row-level security, checked on every request, as well as by the app. Another brand's id returns not found.
  • The app runs with database roles that can only read and write data; separate roles run sign-in and database changes.
  • Passwords are hashed with argon2id. Two-factor secrets are encrypted. Recovery codes and sign-in links are stored only as hashes.
  • Two-factor sign-in is required for every brand role except Viewer, and for the operator.
  • Sessions are checked on every request and end after 12 hours, or 30 minutes idle, for brand roles. A brand can make these shorter.
  • Sign-in attempts are rate limited and bot-checked. Uploaded images are checked and re-saved, which removes hidden data such as location.
  • Important actions are written to an audit log that the app cannot edit, chained so any change can be detected.
  • Emergency switches can turn off sign-ups or uploads, put the service in read-only mode, and sign everyone out.

We review these measures as Human Made grows, and we will not make them weaker in a way that reduces the protection of the brand's data.

9. Helping with requests

If a person asks us to see, correct, export or delete personal data that the brand controls, we will tell the brand and not answer for it, unless the law requires us to. We will help the brand answer such requests, and with data protection assessments, as far as Human Made's features and the information we hold allow.

10. Breach notice

If we become aware of a breach of security that leads to the brand's personal data being lost, changed, disclosed or accessed without permission, we will tell the brand's Owners without undue delay, and within 72 hours of becoming aware of it.

The notice will say what happened, what data and roughly how many people are affected, the likely effects, what we have done and will do about it, and who to contact. If we do not know everything yet, we will send what we know and update the brand as we learn more.

We will work with the brand on its own notices. A notice from us is not an admission of fault.

11. Return and deletion

When the brand closes its workspace, an Owner can ask for an export of the brand's data during a 30-day grace period. After it, we delete the brand's personal data within 30 days, except finalized statements, which we keep for tax and accounting records, and records the law requires us to keep. During the pilot exports and deletions are done by hand. Deleted data can remain in backups until those backups expire.

12. Showing that we comply

On reasonable written request, at most once a year unless there has been a breach, we will answer the brand's questions about how we protect its data and give the information needed to show we meet this agreement.

13. How long this agreement lasts

This agreement lasts as long as we process personal data for the brand. The limits on liability in the Brand Terms apply to it, and so does the governing law line in the Brand Terms.

14. Contact

Questions about this agreement or a data protection request: kylepyeoman@gmail.com.