Data Processing Agreement (DPA)
Edition of 25.08.2026
This Data Processing Agreement (DPA) is an integral part of the Public Offer on providing access to the "Marketing Intelligence Hub" service between ФОП Діма Тетяна Маринівна (Tax ID (RNOKPP) 3146116888) (Data processor, "we") and the Customer (Data controller, "you"). It defines the procedure for the data processor's processing of personal data on behalf of the data controller. On matters of data protection, this DPA takes precedence over other terms.
1. Roles and scope
1.1. The data controller determines the purpose and means of processing its data; the data processor processes personal data only on the documented instructions of the data controller to provide the Service. Use of the Service and its configuration constitute such an instruction.
1.2. This DPA covers personal data from the advertising, analytics and CRM accounts connected by the Customer and the dashboard data (campaign and audience metadata, order data, the Customer's user accounts).
2. Obligations of the data processor
2.1. To process data only on the instructions of the data controller, except where otherwise required by law (in which case we notify, if the law does not prohibit this).
2.2. To ensure the confidentiality of persons authorized to process data.
2.3. To take appropriate technical and organizational measures (Annex 2): encryption of stored access keys, isolation of each Customer's data, access control, secure backups.
2.4. To comply with the conditions for engaging sub-processors (Section 4).
2.5. To assist the data controller in responding to data subjects' requests (access, rectification, erasure, portability, objection) and in fulfilling obligations regarding security and incident notification.
2.6. At the data controller's choice, to delete or return personal data after the provision of services ends, except where retention is required by law (Section 6).
2.7. To provide the information needed to demonstrate compliance and to assist audits on reasonable terms of confidentiality and security.
3. Security and incidents
3.1. The data processor maintains the measures from Annex 2 and reviews them periodically.
3.2. The data processor notifies the data controller of a security incident affecting its data without undue delay, providing the available information for the data controller to fulfill its obligations.
4. Sub-processors
4.1. The data controller grants a general authorization to engage the sub-processors from Annex 1 (hosting, payment provider for international payments, transactional email, notification service).
4.2. The data processor imposes on each sub-processor data protection obligations equivalent to this DPA and remains responsible for their actions.
4.3. The data processor notifies of the intention to add or replace a sub-processor; the data controller may object on reasonable data protection grounds.
The advertising and analytics platforms connected by the Customer (Google, Meta, etc.) are engaged by the Customer itself as its own data processors, not as sub-processors of the data processor.
5. Cross-border transfer
5.1. If processing involves the transfer of personal data outside the data controller's jurisdiction, the parties apply an appropriate transfer mechanism and additional safeguards in accordance with applicable law.
6. Retention and deletion
6.1. During the subscription, data is stored to provide the Service.
6.2. After the subscription ends or on the data controller's instruction, data is stored for a limited period for recovery, and then permanently deleted with prior notice (suspension → archiving → irreversible deletion). The data controller may export data before deletion.
7. Liability and term
7.1. This DPA is in effect for as long as the data processor processes personal data on behalf of the data controller. Liability is limited in accordance with the Public Offer.
Annex 1 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting and data storage | EU |
| Paddle.com Market Ltd | Payment Merchant of Record (for non-UA clients) | Ireland / United Kingdom |
| Resend | Transactional email (notifications, invitations) | EU / USA |
| Telegram | Owner service notifications | — |
| Anthropic PBC | AI adviser: the user's question text | USA |
| DataForSEO | Search competitors: the customer's domain name | USA |
Annex 2 — Technical and organizational measures
- Encryption of stored access keys to third-party systems (AES-256-GCM); secrets are not passed to the browser.
- Isolation of each dashboard's data (separate storage for each Customer).
- Role-based access model on the principle of least privilege.
- Limiting of concurrent sessions/devices and session control.
- Regular backups with access control.
- Masking of secrets in logs and error messages.
Data processor details
ФОП Діма Тетяна Маринівна · Tax ID (RNOKPP) 3146116888 · Address: Україна, 68803, Одеська обл., Ізмаїльський р-н, м. Рені, вул. Анадольська, буд. 13 · https://metriverra.com · cheize2020@gmail.com