Skip to content
Legal

Data Processing Agreement

Version 1 · Effective 7 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Convertfy S.L., a company incorporated in Spain with its registered office at Urb. La Giralda 8, 11300 La Línea de la Concepción (Cádiz), Spain (“Processor”, “Convertfy”) and the operator customer (“Controller”) for use of the Convertfy service (the “Service”). It governs Convertfy’s processing of personal data on the Controller’s behalf. Capitalised terms not defined here have the meaning in the Terms of Service. Where this DPA conflicts with the Terms on data protection, this DPA prevails.

In this DPA, “UK GDPR”, “EU GDPR”, “personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” have the meanings given in applicable data-protection law (“Data Protection Law”).

1. Roles

For the visitor data the Service collects on the Controller’s websites, the Controller is the controller and Convertfy is the processor. Convertfy processes that personal data only to provide the Service and only on the Controller’s documented instructions, including as set out in this DPA and the Terms. Convertfy processes operator-account data as a controller under its Privacy Policy; that processing is outside the scope of this DPA.

2. Controller instructions and compliance

  • Convertfy will process personal data only on the Controller’s documented instructions, including with regard to international transfers, unless required by law (in which case Convertfy will inform the Controller unless legally prohibited).
  • The Controller is responsible for the lawfulness of its instructions and for having a valid legal basis and any required consent for the collection and processing of visitor data via the SDK, and for providing visitors with a compliant privacy notice (see the suggested clause on the Sub-processors page).
  • Convertfy will inform the Controller if, in its opinion, an instruction infringes Data Protection Law.

3. Confidentiality

Convertfy ensures that persons authorised to process the personal data are bound by confidentiality obligations and process the data only as instructed.

4. Security

Taking into account the state of the art and the nature of the data, Convertfy implements appropriate technical and organisational measures, including those described in Annex 2, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

5. Sub-processors

  • The Controller provides general authorisation for Convertfy to engage the sub-processors listed at /subprocessors, each under a written contract imposing data-protection obligations no less protective than this DPA.
  • Convertfy will give the Controller 30 days’ prior notice of any intended addition or replacement of a sub-processor (by updating the list and/or notifying the Controller). The Controller may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, failing which the Controller may terminate the affected part of the Service.
  • Convertfy remains liable for its sub-processors’ performance of their data-protection obligations.

6. Data subject rights

Taking into account the nature of the processing, Convertfy will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If Convertfy receives a request directly from a data subject relating to Controller data, it will not respond except to direct the data subject to the Controller, unless legally required.

7. Assistance to the Controller

Convertfy will assist the Controller, taking into account the nature of processing and the information available to it, with the Controller’s obligations on security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities (Articles 32 to 36).

8. Personal data breach

Convertfy will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data, and will provide information reasonably available to it to help the Controller meet its breach-notification obligations.

9. Deletion or return

On termination of the Service, Convertfy will, at the Controller’s choice, delete or return the Controller’s personal data, and delete existing copies, within 90 days, unless retention is required by law. Residual copies in encrypted back-ups are deleted in the ordinary course of back-up rotation, within a further 30 days, and are not restored except for disaster recovery.

10. Audits

Convertfy will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits (no more than once per year unless required by a supervisory authority or following a personal data breach). Audit requests are satisfied first through written documentation and security summaries; an on-site or remote inspection applies only where documentation is reasonably shown to be insufficient.

11. International transfers

Where Convertfy or its sub-processors process Controller personal data outside the EEA / UK, the transfer is protected by the safeguards set out in Annex 3 (EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and/or the EU-U.S. Data Privacy Framework, as applicable), together with any supplementary measures required.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms.

13. Term

This DPA takes effect when the Controller accepts the Terms or begins using the Service and continues until Convertfy has ceased processing Controller personal data.


Annex 1 — Details of processing

  • Subject matter: provision of the Convertfy conversion-recovery service.
  • Duration: the term of the Controller’s use of the Service (and the wind-down period in Section 9).
  • Nature and purpose: displaying on-site messages to the Controller’s visitors, running on-page content experiments (A/B tests), and measuring campaign performance (impressions, clicks, dismissals, conversions, aggregate experiment counters, and aggregate heatmap analytics).
  • Categories of data subject: the Controller’s website visitors and registered users.
  • Categories of personal data:
    • interaction events: event type, device type, browser, operating system, language, page URL, referrer, and coarse geolocation (country / region / city) derived from IP (IP not stored);
    • conversion data: the Controller’s own opaque user identifier, and for deposits the amount, currency and transaction reference, together with a campaign attribution and, where applicable, a control-group or experiment-variant label;
    • aggregate experiment counters (versions shown and tested-element clicks, per day and device, with no visitor identifier);
    • aggregate heatmap counters and, where enabled by the Controller, value-free form-interaction statistics and masked structural page snapshots (no field values).
  • Special category data: none intended. The Controller must not configure the Service to collect special category data.
  • Frequency: continuous, for the duration of the Service.

Annex 2 — Technical and organisational measures

  • Encryption of data in transit (HTTPS/TLS) and enforced HTTPS (HSTS); security headers applied across the application.
  • Logical tenant isolation: all dashboard data access is scoped per organisation, and write operations verify organisation ownership server-side.
  • Authentication through a dedicated identity provider (Clerk) with organisation-scoped membership; conversion reporting authenticated by per-customer secret keys that are never exposed in browser code.
  • Access controls and least-privilege access to production systems and secrets; production credentials held in environment configuration, not source code.
  • Data minimisation by design: no cookies and no persistent visitor identifiers; session-scoped storage only; IP addresses used transiently for coarse geolocation and not stored; aggregation of heatmap and experiment data at collection; masking of all form input values in page snapshots.
  • Input validation on server endpoints; per-IP rate limiting at the edge on all public endpoints (web application firewall).
  • Managed, reputable infrastructure sub-processors (Annex 3 / Sub-processors) providing encryption at rest, network security and physical security of data centres; database point-in-time recovery back-ups.
  • Logging and monitoring of application errors and access through the hosting platform; documented incident-response handling with Controller notification per Section 8.

Annex 3 — Sub-processors and transfer mechanisms

The current list of sub-processors, with each provider’s role and processing location, is maintained at /subprocessors.

Convertfy is established in Spain (EEA). For sub-processors located in the United States, transfers are protected by, in order of application: (a) the sub-processor’s current certification under the EU-U.S. Data Privacy Framework (and the UK Extension to it, where UK data is concerned); and/or (b) the EU Standard Contractual Clauses (Module Three, processor to processor) incorporated into Convertfy’s agreement with the sub-processor, completed with the UK International Data Transfer Addendum where applicable, together with supplementary measures where a transfer impact assessment identifies them as necessary.