Cookie Consent

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Learn more

You have declined cookies. Some features may not work properly. Change preferences

Cookie Preferences

Manage your cookie preferences. You can enable or disable different types of cookies below.

These cookies are essential for the website to function properly. They cannot be disabled.
These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously.
These cookies are used to deliver personalized advertisements and track campaign performance.
Rated 4.8/5 by podcasters · Read 240+ reviews →
Podpage
  • Why Podpage?
  • Features
  • Reviews
  • Pricing
  • Blog
  • Login
  • Try It Free
Try It Free

Data Processing Addendum

Last Updated: August 31, 2026

This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Agreement between Podpage, Inc. (“Podpage”) and the applicable Podcast Owner (“Customer”) and applies to the extent Podpage Processes Customer Personal Information on behalf of Customer in connection with the Platform. By agreeing to the Agreement, Customer also agrees to this DPA to the extent applicable. In the event of any conflict between the Agreement and this DPA with respect to the Processing of Customer Personal Information, this DPA will prevail.

1. Definitions

Capitalized terms used but not defined in this DPA shall have the same meaning given to them in the Agreement.

1.1. “Agreement” means Podpage’s Terms of Use available at https://www.podpage.com/terms/, as entered into between Customer and Podpage.

1.2. “Controller” means an entity that alone or jointly with others determines the purposes and means of Processing of Personal Information. For purposes of this DPA, a Controller includes a “business” as such term is defined by the CCPA or a similar or analogous designation under Data Protection Laws.

1.3. “Customer Personal Information” means any information protected as “personal information,” “personal data,” “personally identifiable information,” or an analogous term under Data Protection Laws that Podpage Processes on behalf of Customer in connection with the Platform, but excludes personal information that Podpage Processes for its own purposes as an independent Controller, as described in Podpage’s Privacy Policy.

1.4. “Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Information transmitted, stored or otherwise Processed by Podpage under the Agreement. A “Data Breach” will not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Information, including unsuccessful login attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

1.5. “Data Protection Laws” means, to the extent applicable, European Data Protection Laws and US Privacy Laws, as may be amended, superseded or replaced.

1.6. “Europe” means, for the purposes of this DPA, the European Economic Area and/or its member states, the United Kingdom (“UK”) and Switzerland.

1.7. “European Data Protection Laws” means (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Information and on the free movement of such data (General Data Protection Regulation) (“GDPR”); (b) Directive 2002/58/EC concerning the processing of Personal Information and the protection of privacy in the electronic communications sector; (c) in respect of the United Kingdom, the GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 (the “UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 as they continue to have effect by virtue of section 2 of the European Union (Withdrawal) Act 2018, and any other applicable laws in force in the UK (in whole or in part) to the processing of Personal Information (together, “UK Data Protection Laws”); (d) the Swiss Federal Act on Data Protection of 2020 and its Ordinance (“Swiss FADP”); and (e) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (a), (b), (c) and (d) above; in each case as may be amended, superseded or replaced from time to time.

1.8. “Permitted Purposes” means Processing Customer Personal Information as necessary to provide, maintain, secure, and support the Platform and the features enabled by Customer in accordance with the Agreement and Customer’s documented instructions.

1.9. “Process,” “Processes,” “Processing,” “Processed” means any operation or set of operations which is performed on data or sets of data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.

1.10. “Processor” means an entity that Processes Customer Personal Information on behalf, and in accordance with the instructions, of a Controller. For purposes of this DPA, a Processor includes a “service provider” as such term is defined by the CCPA or any similar or analogous designation under Data Protection Laws.

1.11. “Restricted Transfer” means a transfer (directly or via onward transfer) of Customer Personal Information that is subject to European Data Protection Laws to a country outside Europe which is not subject to an adequacy determination by the European Commission, UK or Swiss authorities (as applicable).

1.12. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Customer Personal Information to third countries annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021, as updated or amended from time to time.

1.13. “Sub-processor” means any third party engaged by Podpage to Process Customer Personal Information on behalf of Customer in connection with the Platform. The term “Sub-processor” may include Podpage affiliates but excludes Podpage personnel acting under Podpage’s authority.

1.14. “UK Addendum” means the International Data Transfer Addendum to the Standard Contractual Clauses (version B1.0) “UK Addendum to the EU Standard Contractual Clauses” issued by the Information Commissioner’s Office under s.119A(1) of the UK Data Protection Act 2018, as it is revised under Section 18 therein; as may be amended, superseded or replaced from time to time.

1.15. “US Privacy Laws” means all privacy laws and regulations of the United States in force and effect, including but not limited to (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”); (ii) the Virginia Consumer Data Protection Act; (iii) the Colorado Privacy Act; (iv) the Utah Consumer Privacy Act; (v) the Connecticut Data Privacy Act; and (vi) any and all binding regulations promulgated thereunder, pursuant to or that apply in conjunction with any of (i), (ii), (iii), (iv) and (v) above; in each case as may be amended, superseded or replaced from time to time.

2. Scope and Roles of the Parties

2.1. This DPA applies where and to the extent Podpage Processes Customer Personal Information on behalf of Customer under the Agreement.

2.2. Customer is the Controller of Customer Personal Information, and Podpage Processes Customer Personal Information as a Processor on behalf of Customer. Podpage will Process Customer Personal Information only as necessary to provide the Platform and features enabled by Customer, in accordance with Customer’s documented instructions, or as otherwise required by applicable law. The Parties agree that the Agreement, this DPA, and Customer’s use and configuration of the Platform constitute Customer’s documented instructions regarding Podpage’s Processing of Customer Personal Information. For clarity, this DPA does not apply to personal information that Podpage Processes for its own purposes as an independent Controller, as described in Podpage’s Privacy Policy.

2.3. The Parties agree that Podpage may aggregate, anonymize or de-identify Customer Personal Information as part of its provision and ongoing improvement of the Platform.

2.4. To the extent Podpage Processes or possesses de-identified Personal Information, Podpage will not re-identify such data, except as permitted by applicable law.

2.5. The Processing under this DPA consists of the collection, storage, transmission, use, disclosure, deletion, and other Processing of Customer Personal Information necessary to provide the Platform for the duration of the Agreement. Customer Personal Information may include names, email addresses, contact-form submissions, survey responses, voicemail recordings, IP addresses, and other personal information submitted through features enabled by Customer, and may relate to listeners, subscribers, Podcast Website visitors, guests, and other individuals whose personal information Customer submits to or collects through the Platform.

3. Obligations of the Parties

3.1. Both Parties shall comply with their respective obligations under Data Protection Laws, and each Party shall be solely responsible for determining its own legal and regulatory obligations. Customer further acknowledges that Customer is responsible for its secure use of the Platform, including securing its account credentials and taking appropriate steps to back up any Customer Personal Information Processed in connection with the Platform.

3.2. Each Party shall reasonably cooperate with the other in any activities contemplated by this DPA and to enable each Party to comply with its respective obligations under Data Protection Laws.

4. Podpage’s Obligations

4.1. Permitted Purposes

4.1.1. Podpage shall notify Customer if it reasonably determines that it received an instruction that infringes Data Protection Laws.

4.1.2. Podpage shall not (except as permitted under Data Protection Laws): (i) retain, use, or disclose any Customer Personal Information outside its direct business relationship with Customer or for any purpose other than the Permitted Purposes, (ii) sell or share Customer Personal Information for cross-context behavioral advertising; or (iii) combine Customer Personal Information with Personal Information received from other sources.

4.2. Security Measures

4.2.1. Podpage shall implement and maintain appropriate technical and organizational security measures designed to protect Customer Personal Information from Data Breaches and preserve the security and confidentiality of Customer Personal Information, taking into account the nature of the Processing and the risks presented by such Processing and as required by applicable Data Protection Laws. If Podpage determines that it can no longer meet these obligations, it shall notify Customer as required by applicable Data Protection Laws, and Customer shall have the right to take reasonable and appropriate steps to stop or remediate any unauthorized Processing of its data.

4.2.2. Podpage maintains reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Information against unauthorized access, acquisition, loss, misuse, alteration, or disclosure and to provide a level of security appropriate to the risks presented by the Processing, as required by applicable Data Protection Laws. Podpage may update such safeguards from time to time, provided that such updates do not materially reduce the overall level of protection provided for Customer Personal Information. Additional information regarding Podpage’s security measures is available upon reasonable request.

4.3. Access and Confidentiality

Podpage shall restrict its personnel from Processing Customer Personal Information without authorization and shall ensure that any person who is authorized by Podpage to Process Customer Personal Information is under an appropriate contractual or statutory obligation of confidentiality.

4.4. Data Breaches

Podpage shall notify Customer without undue delay upon becoming aware of a Data Breach. Podpage shall provide Customer with timely information relating to the Data Breach as it becomes known or is reasonably requested by Customer to fulfill its obligations under Data Protection Laws. Podpage shall take reasonable steps to contain, investigate, and mitigate any Data Breach. Podpage’s notification of or response to a Data Breach in accordance with this section shall not be construed as an acknowledgment by Podpage of any fault or liability with respect to the Data Breach.

4.5. Cooperation

4.5.1. Security

Taking into account the nature of the Customer Personal Information and related Processing activities, Podpage shall provide such reasonable assistance as Customer may reasonably request to help it fulfill its security obligations under Data Protection Laws.

4.5.2. Data Subject Requests

To the extent that Customer is unable to independently access the relevant Customer Personal Information within the Platform, Podpage shall, taking into account the nature of the Processing, provide reasonable cooperation to assist Customer in responding to any requests from individuals relating to the Processing of Customer Personal Information under the Agreement. If any such request is made to Podpage directly, Podpage shall promptly notify Customer and will not respond to the request directly except to direct the Data Subject to the Customer without Customer’s prior authorization, unless and to the extent legally compelled to do so.

4.5.3. Law Enforcement Requests

If a law enforcement agency sends Podpage a demand for Customer Personal Information (including through a subpoena or court order), Podpage will attempt to redirect the law enforcement agency to request that Customer Personal Information directly from Customer. As part of this effort, Podpage may provide Customer’s basic contact information to the law enforcement agency. If compelled to disclose Customer Personal Information to a law enforcement agency, Podpage will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy, unless Podpage is legally prohibited from doing so.

4.5.4. Data Protection Impact Assessment and Prior Consultation

Podpage agrees to provide reasonable assistance to Customer where the type of Processing performed by Podpage requires a data protection impact assessment, risk assessment, cybersecurity audit or similar under Data Protection Laws and/or queries, inquiry, complaint or prior consultation with any regulatory, supervisory, governmental, state agency, Attorney General or other competent authority with jurisdiction or oversight over compliance with Data Protection Laws.

4.5.5. Audits

Podpage shall provide Customer (on a confidential basis) with written responses (which may include summaries/extracts of audit reports or independent assessments) to all reasonable requests made by Customer for information relating to Podpage’s Processing of Customer Personal Information that (i) are necessary to confirm Podpage’s compliance with this DPA; and/or (ii) are required of Customer under Data Protection Law. Customer shall not exercise this right more than once per calendar year or when Customer is expressly requested or required to provide this information to a supervisory authority, or Podpage has experienced a Data Breach, or on another reasonably similar basis. Nothing herein shall be construed to require Podpage to provide: (i) trade secrets or any proprietary information; (ii) any information that would violate Podpage’s confidentiality obligations, contractual obligations, or applicable laws; or (iii) any information, the disclosure of which could threaten, compromise, or otherwise put at risk the security, confidentiality, or integrity of Podpage’s infrastructure, networks, systems, or data.

5. Customer Obligations

5.1. Compliance with Laws

Customer shall (i) comply with its obligations under Data Protection Laws regarding its use of the Platform and the Processing of Customer Personal Information; (ii) ensure its instructions are lawful and that the Processing of Customer Personal Information in accordance with such instructions will not violate Data Protection Laws; and (iii) notify Podpage if it is unable to comply with its obligations under Data Protection Laws or its Processing instructions will cause Podpage or its Sub-processors to be in breach of Data Protection Laws.

5.2. Notices and Permissions

Customer recognizes that Customer alone is in a position to decide for which data it uses the Platform, and that it is thus Customer’s sole responsibility to determine whether the Platform is appropriate for the Processing of Customer Personal Information. Customer represents and warrants that it (i) has provided all required information and notices concerning the Processing of Personal Information in connection with Customer’s use of the Platform; (ii) has all necessary rights, permissions, and consents to make Personal Information available to Podpage for the purposes contemplated by the Agreement; and (iii) will not use the Platform for the kinds of Personal Information for which Data Protection Laws require protections that are outside the scope of the Agreement.

5.3. Regulatory Inquiries

Unless prohibited by applicable laws, Customer shall notify Podpage promptly of any governmental, regulatory or other third-party inquiry or complaint concerning Customer’s use of the Platform.

6. Sub-processors

6.1. Customer provides a general authorization to Podpage to engage Sub-processors to Process Customer Personal Information on Customer’s behalf. A current list of Podpage’s Sub-processors is available upon reasonable request by contacting info@podpage.com. Podpage will restrict Sub-processors’ access to Customer Personal Information to what is necessary to assist Podpage in providing the Platform and will remain responsible for any acts or omissions of Sub-processors to the extent they cause Podpage to breach its obligations under this DPA.

6.2. Sub-processor Obligations. Podpage shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective of Customer Personal Information as required by this DPA.

6.3. Changes to Sub-processors. Where required by applicable Data Protection Laws, Podpage will provide Customer reasonable notice of any intended addition or replacement of a Sub-processor and provide Customer an opportunity to object on reasonable data-protection grounds. If Customer objects on reasonable data-protection grounds, the Parties will discuss the objection in good faith. If the Parties cannot reasonably resolve the objection, Customer may discontinue use of the affected portion of the Platform in accordance with the Agreement.

7. Deletion or Return of Customer Personal Information

7.1. Upon termination or expiry of the Agreement, Podpage shall, at Customer’s choice, delete or return all Customer Personal Information in its possession or control in accordance with the terms of the Agreement. This requirement shall not apply to the extent Podpage or its Sub-processors are required by applicable law to retain some or all of the Customer Personal Information, or to Customer Personal Information archived on back-up systems, which shall be securely isolated and protected from any further Processing until securely deleted.

8. International Transfers

8.1. Customer acknowledges and agrees that Podpage and its Sub-processors may transfer and Process Customer Personal Information to and in the United States and the other locations in which Podpage or its Sub-processors maintain data processing operations. If Podpage transfers Customer Personal Information to a Sub-processor, it shall ensure that such transfers are made in compliance with Data Protection Laws and this DPA.

9. Jurisdiction-Specific Terms

9.1. United States

9.1.1. To the extent that Customer Personal Information is subject to US Privacy Laws, the terms in this Section 9.1 shall apply in addition to the terms in the remainder of this DPA. In the event of any conflict or ambiguity between the terms in this Section 9.1 and any other terms in this DPA, the terms in this Section 9.1 shall take precedence but only to the extent they apply to the Customer Personal Information in question.

9.1.2. Podpage is a service provider under the CCPA and receives Customer Personal Information pursuant to and solely for the business purpose of providing the Platform to Customer in accordance with the Agreement.

9.1.3. Podpage shall not, unless otherwise permitted by US Privacy Laws, (a) retain, use or disclose Customer Personal Information for any purpose other than the Permitted Purposes, including to retain, use or disclose Customer Personal Information for a commercial purpose other than the Permitted Purposes; (b) “sell” or “share” Customer Personal Information (as defined and interpreted within the requirements of US Privacy Laws); and (c) retain, use, or disclose the Customer Personal Information outside the direct business relationship between the Parties. Podpage will comply with any applicable restrictions under the CCPA or other US Privacy Laws on combining Customer Personal Information received from Customer with personal information that Podpage receives from, or on behalf of, another person, or that Podpage collects from any interaction between it and an individual. The Parties agree that Customer’s transfer of Customer Personal Information to Podpage is not a “sale” (as defined and interpreted under US Privacy Laws), and Customer provides no monetary or other valuable consideration to Podpage in exchange for the Customer Personal Information.

9.1.4. As applicable under US Privacy Laws, Podpage acknowledges Customer’s right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Information by Podpage.

9.2. Europe

9.2.1. To the extent that Customer Personal Information is subject to European Data Protection Laws, the terms in this Section 9.2 shall apply in addition to the terms in the remainder of this DPA. In the event of any conflict or ambiguity between the terms in this Section 9.2 and any other terms in this DPA, the terms in this Section 9.2 shall take precedence but only to the extent they apply to the Customer Personal Information in question.

9.2.2. Processing Instructions. Without prejudice to Section 5 (Customer Obligations), Podpage shall notify Customer in writing, unless prohibited from doing so under Data Protection Laws, if it becomes aware or believes that any Processing instructions from Customer violate European Data Protection Laws.

9.2.3. Restricted Transfers. Where a Restricted Transfer requires the Standard Contractual Clauses or, where applicable, the UK Addendum, the applicable Standard Contractual Clauses and/or UK Addendum will apply to such Restricted Transfer, and Podpage will make a copy available to Customer upon reasonable request.

10. Limitation of Liability

10.1. Podpage’s liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, except to the extent such limitations or exclusions are prohibited by applicable law.

11. Miscellaneous

11.1. The provisions of this DPA are severable. If any phrase, clause or provision is invalid or unenforceable in whole or in part, such invalidity or unenforceability shall affect only such phrase, clause or provision, and the rest of this DPA or the remainder of the Agreement shall remain in full force and effect.

11.2. This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by Data Protection Laws.

Company

  • About Podpage
  • For Podcast Hosts
  • For Podcast Agencies
  • For Podcast Coaches
  • For Podcast Networks
  • Integrations
  • Pricing
  • Affiliate Program
  • Community
  • Blog
  • Product Updates

Use Cases

  • For Business Podcasts
  • For Churches & Ministries
  • For True Crime
  • For Education
  • For YouTube Creators
  • For Comedy Podcasts
  • For Health & Wellness

Customers

  • Customer Stories
  • Reviews

Resources

  • How to Start a Podcast
  • Podcast Name Generator
  • Podcast Website Templates
  • SEO for Podcasts
  • Comparing WordPress and Podpage
  • Monetizing your Podcast
  • Apple Smart Banner for Podcasts
  • Podcast Player Badge Set
  • School of Podcasting

Guides

  • WordPress Migration
  • Libsyn Podcast Websites
  • Podbean Podcast Websites
  • Buzzsprout Podcast Websites
  • Simplecast Podcast Websites
  • Megaphone Podcast Websites
  • Omny Podcast Websites
  • © 2026 Podpage™
  • Sitemap
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Cookie Preferences
  • Data Processing Addendum
  • Terms of Use