Data processing addendum

How Fabulous Limited processes personal data on behalf of a host running a community on success.digital.

Last updated 14 September 2026

This document is not yet in force.

It is a draft. 4 details are still outstanding, and it has not been reviewed by a lawyer. Do not rely on it.

How it fits

This addendum forms part of the terms of service. Where the two disagree about personal data, this one wins.

Roles

The host is the controller: they decide what their community collects and why. We are the processor: we hold and handle it on their documented instructions, which are the terms, this addendum, and the settings the host chooses in the product.

What is processed, and for whom

Subject matterRunning a community on success.digital
DurationWhile the host’s account is open, then thirty days
Nature and purposeStorage, retrieval, display and delivery of community content and membership
Types of personal dataEmail address, display name, profile picture and cover, biography, links, community and room membership, posts, discussions, replies, comments, direct messages, events and RSVPs, course enrolment and progress, moderation records
Categories of data subjectThe host, their members, and visitors to a public community
Special category dataNone is required by the product. A member may write anything in a post, so a host whose community is about health, belief or politics should assume it is present and say so in their own notice.

Our obligations

Security

Subprocessors

The host consents to these, and we will give notice before adding another:

WhoWhat they doWhere
SupabaseDatabase, file storage, authenticationMumbai, India (AWS ap-south-1)
VercelApplication hosting and deliveryGlobal edge network; requests are served from the nearest region
SocketLabsSending notification and transactional emailUnited States

Transfers

Fabulous Limited is a United States company and the data is held in Mumbai, India. For a host or member in the European Economic Area or the United Kingdom that is a restricted transfer, and the European Commission’s standard contractual clauses (module three, processor to processor, and module two where we act for a controller) apply and are incorporated here.

Data subject requests

The product answers most of these without us: a member can export everything they wrote and every record about them, leave a community, or delete their account, from their own settings. A host can export their community. Where a request needs us, we help the host rather than answering their member directly.

Return and deletion

On termination the host may export their community for thirty days. After that we delete it. Backups containing it roll off within thirty days of deletion.

Liability

The limits in the terms of service apply to this addendum.