Data Processing Agreement

    Draft — pending legal review. This document is a first draft and does not constitute legal advice.

    Data Processing Agreement

    v1

    Last Updated: August 2, 2026

    This DPA forms part of the Agreement between EverConvert ("Processor") and the Customer ("Controller") and applies wherever EverConvert processes Personal Data on the Customer's behalf via the Revenue Tracking feature.

    1. Roles

    The Customer is the Controller; EverConvert is the Processor of the buyer/visitor Personal Data processed through Revenue Tracking. The Customer's payment platforms and automation tools (Zapier, n8n, etc.) operate under the Customer's own control.

    2. Subject matter, nature & purpose

    EverConvert processes Personal Data solely to provide revenue attribution — matching a buyer's purchase to the headline/variant the visitor saw, and reporting net revenue per variant. Processing is limited to this purpose and to the Customer's documented instructions (this DPA + the product configuration).

    3. Categories of data & data subjects

    Data subjects: the Customer's website visitors and buyers. Personal Data: a one-way HMAC hash of the email (no raw email stored at rest); order metadata (amount, currency, order id, timestamp); pseudonymous visitor identifiers. Raw email is transmitted in transit (on-page beacon + the Customer's payment webhook), hashed server-side, and discarded — never stored, logged, or placed in audit records.

    4. Processor obligations

    EverConvert will:

    • (a) process only on the Customer's documented instructions;
    • (b) bind personnel to confidentiality;
    • (c) implement the security measures in §5;
    • (d) assist the Customer with data-subject requests and with Arts. 32–36 obligations;
    • (e) notify the Customer without undue delay of a Personal Data breach;
    • (f) delete or return Personal Data at the end of the service.

    5. Security measures

    • TLS in transit
    • Pseudonymisation at rest (email stored only as a keyed HMAC; raw email never persisted)
    • Multi-tenant row-level isolation per organisation
    • Least-privilege admin access
    • Ingestion audit logging

    6. Sub-processors

    The Customer authorises: Supabase (hosting, database, edge compute) [+ any alerting/email vendor EverConvert uses]. The Customer's own connected tools (payment platforms, Zapier/n8n) are engaged by the Customer, not EverConvert. EverConvert will give prior notice of any new sub-processor and an opportunity to object.

    7. Data-subject rights & erasure

    EverConvert will assist the Customer with data-subject requests and, on request, erase a specified buyer's data (by recomputed hash) and record a suppression marker so later events for that buyer aren't re-created.

    8. Retention

    Personal Data is retained for as long as the Customer's integration is active, or until the Customer requests deletion. [A fixed window, if later adopted, will be stated here.]

    9. International transfers

    Data is hosted in [Supabase region — fill in]. Transfers outside the UK/EEA rely on an appropriate mechanism (UK IDTA / EU SCCs).

    10. Audit

    EverConvert will make available information reasonably necessary to demonstrate compliance (Art. 28(3)(h)), subject to reasonable notice and confidentiality.

    11. General

    [Term, liability, governing law, order of precedence — to be completed by legal. First draft; not legal advice.]

    We use cookies to improve your experience.Learn more