Operator Data Processing Addendum
Effective Date: August 1, 2026
Version: 2026-08-01
This Operator Data Processing Addendum (“DPA”) forms part of the Operator Platform Terms between Libramen, Inc. (“Libramen”) and the service business using the Platform (“Operator”). It applies when Libramen processes personal information on the Operator’s behalf.
1. Roles and scope
For buyer booking, inquiry, fulfillment, support, and Operator-led transaction records, the Operator determines the purposes and means of processing and acts as the controller or “business.” Libramen acts as the Operator’s processor, service provider, or contractor and stores and otherwise processes the record on documented Operator instructions.
Libramen acts as an independent controller or business for its own account administration, Platform billing and fee ledgers, service security and integrity, fraud and abuse prevention, legal compliance, and establishment, exercise, or defense of legal claims. This DPA does not make Libramen a processor for those independent purposes.
The parties use “personal information,” “controller,” “processor,” “business,” “service provider,” and “contractor” as defined by applicable privacy law. Where more than one definition applies, the term with the closest applicable meaning controls.
2. Processing details
Subject matter and purpose: operating Libramen transaction and booking infrastructure for the Operator, including qualification, booking, payment facilitation, receipts, support, reconciliation, dashboard history, and transaction evidence.
Duration: while the Operator uses Libramen and afterward until the Operator instructs deletion or return, subject to Section 10 and applicable law.
Data subjects: buyers, prospective buyers who reach transaction confirmation, Operator personnel, and individuals communicating about a booking.
Personal-information categories: buyer name, email, phone, optional agent-side customer identifier and account classification; booking scope and preferences; service date/options; amount, tax, payment, authorization, settlement, refund, dispute, receipt, and support information; transaction source; confirmation evidence; and security/audit metadata associated with the transaction.
Processing operations: collection, validation, organization-scoped encryption and storage, retrieval, display to authorized Operator users, transmission to configured payment/email/integration providers, status reconciliation, support, deletion, return, and de-identification.
3. Operator instructions and responsibilities
The Operator instructs Libramen to process the personal information as needed to provide the Platform under the Operator Platform Terms and the Operator’s documented configuration and support requests. Additional instructions must be lawful, technically feasible, and within the Platform’s scope; the parties may agree fees for material additional work.
The Operator is responsible for:
- providing all notices and having all rights or lawful bases required for the processing and its buyer communications;
- configuring access, services, policies, integrations, and retention instructions appropriately;
- responding to buyers and regulators as controller/business;
- ensuring its instructions comply with law; and
- any export, independent copy, or later use of buyer information outside Libramen.
If Libramen reasonably believes an instruction violates law, it may suspend that instruction and notify the Operator unless law prohibits notice.
4. Libramen obligations
Libramen will:
- process Operator personal information only on documented instructions, to provide the contracted business purposes, or as law requires;
- not sell or share Operator personal information for cross-context behavioral advertising;
- not retain, use, or disclose Operator personal information outside the direct business relationship or for an independent commercial purpose except as applicable law permits;
- not combine Operator buyer data with data from another Operator to build cross-Operator buyer profiles;
- ensure personnel authorized to process the information are subject to confidentiality obligations;
- implement and maintain reasonable technical and organizational safeguards appropriate to the processing risk;
- provide reasonable assistance with rights requests, security incidents, and legally required assessments, taking account of the nature of processing and information available to Libramen; and
- notify the Operator if Libramen can no longer meet applicable service-provider or contractor restrictions.
For California personal information, Libramen certifies that it understands and will comply with the restrictions applicable to a service provider or contractor. The Operator may take reasonable and appropriate steps to help ensure compliant use and to stop and remediate unauthorized use.
5. Security
Libramen’s measures include TLS in transit; encryption at rest for sensitive Operator credentials and buyer records; organization-scoped cryptographic separation for buyer information; role and organization-bound access controls; authentication and credential protections; rate limiting and anonymous-surface abuse controls; logging, monitoring, backup, incident response, and vulnerability-management practices appropriate to the Platform.
No measure eliminates all risk. Libramen may update safeguards as technology and risk change, provided it does not materially reduce overall protection during the term.
6. Security incidents
Libramen will notify the Operator without undue delay after confirming a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Operator personal information (“Security Incident”). Notice will include available information reasonably needed for the Operator’s response and will be supplemented as facts develop.
Unsuccessful attempts, scans, pings, blocked requests, and events that do not compromise Operator personal information are not Security Incidents. Notification is not an admission of fault. The Operator is responsible for notifications it must make to buyers or authorities, with Libramen’s reasonable assistance.
7. Subprocessors
The Operator generally authorizes Libramen to engage subprocessors needed to provide the Platform. Current categories and providers are listed in the Privacy Policy. Libramen will contractually require each subprocessor that processes Operator personal information to protect it consistently with applicable obligations in this DPA.
Libramen will provide notice of a material new subprocessor through an updated subprocessor list, email, or in-product notice. The Operator may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate the affected processing.
8. Rights requests and government requests
If Libramen receives a buyer request relating to Operator-controlled booking data, Libramen may direct the requester to the Operator and notify the Operator. Taking account of processing and Platform capabilities, Libramen will reasonably assist the Operator with access, correction, deletion, restriction, portability, or objection requests the Operator is legally required to honor.
Libramen may require verification and may withhold or preserve data where the Operator directs, applicable law permits or requires, or the information is part of Libramen’s independent records. Libramen will notify the Operator of a legally binding government demand for Operator personal information unless prohibited and will challenge overbroad demands where reasonably appropriate.
9. Audits and information
Libramen will provide information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, policies, questionnaires, certifications, or independent audit reports when available.
No more than once per year, unless a confirmed Security Incident or regulator requires more, the Operator may request a reasonable audit. Audits must protect other customers and Libramen confidential information, avoid access to source code or vulnerability-sensitive material unless legally necessary, occur during business hours with advance notice, and use an independent auditor bound by confidentiality. The Operator bears its audit costs unless the audit identifies a material Libramen breach.
10. Return, deletion, retention, and backups
The complete Operator booking ledger is retained while the Operator uses Libramen and afterward until an authorized Operator instruction requests return or deletion. Libramen will fulfill a technically valid instruction within a reasonable period, subject to applicable law, security, fraud, tax, billing, payment, dispute, and legal-claim requirements.
Deletion from active systems does not require immediate deletion from disaster-recovery or backup media. Residual copies remain protected, are not restored except for recovery, and are removed or overwritten through the applicable backup lifecycle. If restored, the deletion instruction will be reapplied.
Libramen may retain records it controls independently under the Privacy Policy, including account, Platform fee, security, fraud, dispute, and legal-claim records. Where feasible, Libramen will minimize or de-identify buyer information in those independent records.
11. De-identified information
Libramen may create and use aggregate or genuinely de-identified information that cannot reasonably identify or be linked to a person or household. Libramen will maintain measures designed to prevent reidentification and will not attempt to reidentify the information except to test whether de-identification controls remain effective where law permits.
12. International processing
The Platform is operated primarily from the United States. If applicable law requires a transfer mechanism for Operator personal information, the parties will cooperate to put an appropriate mechanism in place. This DPA does not claim that foreign law can never apply.
13. Liability, order of precedence, and termination
The liability limitations in the Operator Platform Terms apply to this DPA to the maximum extent permitted by law. If this DPA conflicts with the Operator Platform Terms on processing of Operator personal information, this DPA controls.
This DPA terminates when Libramen no longer processes Operator personal information, except provisions that must survive to protect retained information.
14. Contact
Privacy and data-protection requests: founders@libramen.ai
Libramen, Inc., 1111B S Governors Ave # 49139, Dover, DE 19904, United States
Publication control: This DPA must not be published as effective until external counsel validates the controller/service-provider allocation, California contract terms, rights-request process, audit language, international-transfer posture, and deletion/return commitments against production operations.