Legal

Data processing agreement

Last updated: July 21, 2026

1. Scope and roles

This data processing agreement (“DPA”) forms part of the terms of service between TEXOOM Ltdand the customer. It applies whenever we process personal data on the customer’s behalf in providing the Service.

For that data the customer is the controller and Pivolio is the processor. Where the customer is itself a processor for another organisation, Pivolio acts as a subprocessor and this DPA is read accordingly.

Data we process for our own purposes — account, billing, and website data — is covered by our privacy policy, not by this DPA. In that context we are a controller.

2. Processing on documented instructions

We process customer personal data only on the customer’s documented instructions. The terms of service, this DPA, and the configuration the customer sets in the dashboard together constitute those instructions — including which advertising platforms receive data and which events are sent.

If we are required by law to process data beyond those instructions, we will tell the customer first unless the law forbids it. If we believe an instruction breaches data protection law, we will say so.

3. Details of the processing

  • Subject matter — capture, identity resolution, quality scoring, and delivery of conversion events to advertising platforms.
  • Duration— for the term of the customer’s subscription, plus the deletion period in section 10.
  • Nature and purpose — automated collection, storage, enrichment, aggregation, and transmission, solely to provide the Service.
  • Categories of data subject— the customer’s website visitors, leads, and customers.
  • Categories of personal data — online identifiers (IP address, user agent, device and browser characteristics, first-party identifiers, advertising click IDs); contact identifiers (email address, phone number) where the customer sends them; commercial data (events, order values, currencies, custom properties, customer traits).
  • Special category data — none. The Service is not designed for it and the customer must not send it.

4. Confidentiality

We ensure that everyone authorised to process customer personal data is bound by an appropriate duty of confidentiality, and that access is limited to those who need it to provide or support the Service.

5. Security measures

We implement appropriate technical and organisational measures under Article 32, including:

  • Encryption of data in transit (TLS) and at rest.
  • Tenant isolation enforced by row-level security in the database, so a query cannot reach another customer’s rows even if application code is wrong.
  • Separate encryption for connected platform credentials, which are never returned through the API after entry.
  • Role-based access control and authentication for production systems.
  • Audit logging, continuous error monitoring, and alerting.
  • Automated backups, and pseudonymisation where the Service allows it.

We review these measures periodically and may update them, provided the level of protection is not reduced.

6. Subprocessors

The customer gives general authorisation for us to engage subprocessors. Each is bound by written terms imposing data protection obligations no less protective than this DPA, and we remain liable for their performance.

Our current subprocessors are:

  • Amazon Web ServicesHosting, compute, and storage. United States.
  • StripeSubscription billing and payment processing. United States.
  • ResendTransactional email (account and alert notifications). United States.
  • SentryError monitoring and diagnostics. United States.
  • CloudflareDNS, CDN, and network protection. Global edge network.
  • IPLocateIP geolocation used in traffic-quality scoring. United States.
  • SoketiRealtime delivery of dashboard events. United States.

We give at least 30 days’ notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that period; if we cannot offer a workable alternative, the customer may terminate the affected part of the Service without penalty.

7. International transfers

Customer personal data is hosted in the United States (AWS, us-east-1) and accessed by our team in the United Arab Emirates and the United Kingdom.

Where this involves transferring personal data out of the EEA or the UK, the transfer is made under the European Commission’s Standard Contractual Clauses, and under the UK International Data Transfer Addendum for UK data, together with supplementary measures including encryption in transit and at rest. By entering into this DPA the parties are deemed to have signed the applicable clauses, with Pivolio as data importer and the customer as data exporter.

8. Data subject requests

The Service gives the customer the ability to access, correct, export, and delete the personal data it holds, including deleting an individual person from the identity graph. Where a data subject contacts us directly, we will not respond substantively but will refer them to the customer without undue delay. We will provide reasonable assistance if the customer cannot fulfil a request through the Service itself.

9. Personal data breach

We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, and in any case within 72 hours. The notification will describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed. We will assist the customer with their own notification obligations to supervisory authorities and data subjects.

10. Return and deletion

During the subscription the customer may export their data at any time. On termination, we delete customer personal data within 30 days, except where law requires retention. Backups are deleted on their normal rotation.

We do not otherwise delete data on a schedule: conversion events and delivery logs are retained for the life of the workspace. The customer controls removal before then — data can be deleted at any time. An erasure request for an individual data subject deletes their identity records and identifiers. Their conversion events and delivery logs are retained: the customer id on those events no longer resolves to any person, while the hashed identifiers, IP address and full page URLs recorded on them remain. The customer can delete those events itself at any time.

11. Audits and assistance

On reasonable written request, and no more than once in any twelve-month period unless a supervisory authority requires otherwise, we will make available the information necessary to demonstrate compliance with Article 28 and allow for an audit. We may satisfy this through documentation, written responses, or a third-party report. Any on-site audit is at the customer’s cost, subject to reasonable notice and confidentiality, and must not disrupt the Service or compromise another customer’s data. We will also provide reasonable assistance with data protection impact assessments and prior consultations.

12. Liability and precedence

Liability under this DPA is subject to the limitations in the terms of service.

If this DPA conflicts with those terms, this DPA prevails on data protection matters. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.

Questions, signed-copy requests, and subprocessor objections: privacy@pivolio.com.