Draft — pending legal review. This document is a first draft and does not constitute legal advice.
Data Processing Agreement
Last Updated: August 4, 2026
This DPA forms part of the Agreement between EverConvert ("Processor") and the Customer ("Controller") and applies wherever EverConvert processes Personal Data on the Customer's behalf via the Revenue Tracking feature.
1. Roles
The Customer is the Controller; EverConvert is the Processor of the buyer/visitor Personal Data processed through Revenue Tracking. The Customer's payment platforms and automation tools (Zapier, n8n, etc.) operate under the Customer's own control.
2. Subject matter, nature & purpose
EverConvert processes Personal Data solely to provide revenue attribution — matching a buyer's purchase to the headline/variant the visitor saw, and reporting net revenue per variant. Processing is limited to this purpose and to the Customer's documented instructions (this DPA + the product configuration).
3. Categories of data & data subjects
Data subjects: the Customer's website visitors and buyers. Personal Data: a one-way HMAC hash of the email (no raw email stored at rest); order metadata (amount, currency, order id, timestamp); pseudonymous visitor identifiers. Raw email is transmitted in transit (on-page beacon + the Customer's payment webhook), hashed server-side, and discarded — never stored, logged, or placed in audit records.
4. Processor obligations
EverConvert will:
- (a) process only on the Customer's documented instructions;
- (b) bind personnel to confidentiality;
- (c) implement the security measures in §5;
- (d) assist the Customer with data-subject requests and with Arts. 32–36 obligations;
- (e) notify the Customer without undue delay of a Personal Data breach;
- (f) delete or return Personal Data at the end of the service.
5. Security measures
- TLS in transit
- Pseudonymisation at rest (email stored only as a keyed HMAC; raw email never persisted)
- Multi-tenant row-level isolation per organisation
- Least-privilege admin access
- Ingestion audit logging
6. Sub-processors
The Customer authorises: Supabase (hosting, database, edge compute) [+ any alerting/email vendor EverConvert uses]. The Customer's own connected tools (payment platforms, Zapier/n8n) are engaged by the Customer, not EverConvert. EverConvert will give prior notice of any new sub-processor and an opportunity to object.
7. Data-subject rights & erasure
EverConvert will assist the Customer with data-subject requests and, on request, erase a specified buyer's data (by recomputed hash) and record a suppression marker so later events for that buyer aren't re-created.
8. Retention
Personal Data is retained for as long as the Customer's integration is active, or until the Customer requests deletion. [A fixed window, if later adopted, will be stated here.]
9. International transfers
Data is hosted in [Supabase region — fill in]. Transfers outside the UK/EEA rely on an appropriate mechanism (UK IDTA / EU SCCs).
10. Audit
EverConvert will make available information reasonably necessary to demonstrate compliance (Art. 28(3)(h)), subject to reasonable notice and confidentiality.
11. General
[Term, liability, governing law, order of precedence — to be completed by legal. First draft; not legal advice.]