Data processing agreement
Last updated: July 21, 2026
1. Scope and roles
This data processing agreement (“DPA”) forms part of the terms of service between TEXOOM Ltdand the customer. It applies whenever we process personal data on the customer’s behalf in providing the Service.
For that data the customer is the controller and Pivolio is the processor. Where the customer is itself a processor for another organisation, Pivolio acts as a subprocessor and this DPA is read accordingly.
Data we process for our own purposes — account, billing, and website data — is covered by our privacy policy, not by this DPA. In that context we are a controller.
2. Processing on documented instructions
We process customer personal data only on the customer’s documented instructions. The terms of service, this DPA, and the configuration the customer sets in the dashboard together constitute those instructions — including which advertising platforms receive data and which events are sent.
If we are required by law to process data beyond those instructions, we will tell the customer first unless the law forbids it. If we believe an instruction breaches data protection law, we will say so.
3. Details of the processing
- Subject matter — capture, identity resolution, quality scoring, and delivery of conversion events to advertising platforms.
- Duration— for the term of the customer’s subscription, plus the deletion period in section 10.
- Nature and purpose — automated collection, storage, enrichment, aggregation, and transmission, solely to provide the Service.
- Categories of data subject— the customer’s website visitors, leads, and customers.
- Categories of personal data — online identifiers (IP address, user agent, device and browser characteristics, first-party identifiers, advertising click IDs); contact identifiers (email address, phone number) where the customer sends them; commercial data (events, order values, currencies, custom properties, customer traits).
- Special category data — none. The Service is not designed for it and the customer must not send it.
4. Confidentiality
5. Security measures
We implement appropriate technical and organisational measures under Article 32, including:
- Encryption of data in transit (TLS) and at rest.
- Tenant isolation enforced by row-level security in the database, so a query cannot reach another customer’s rows even if application code is wrong.
- Separate encryption for connected platform credentials, which are never returned through the API after entry.
- Role-based access control and authentication for production systems.
- Audit logging, continuous error monitoring, and alerting.
- Automated backups, and pseudonymisation where the Service allows it.
We review these measures periodically and may update them, provided the level of protection is not reduced.
6. Subprocessors
The customer gives general authorisation for us to engage subprocessors. Each is bound by written terms imposing data protection obligations no less protective than this DPA, and we remain liable for their performance.
Our current subprocessors are:
- Amazon Web Services — Hosting, compute, and storage. United States.
- Stripe — Subscription billing and payment processing. United States.
- Resend — Transactional email (account and alert notifications). United States.
- Sentry — Error monitoring and diagnostics. United States.
- Cloudflare — DNS, CDN, and network protection. Global edge network.
- IPLocate — IP geolocation used in traffic-quality scoring. United States.
- Soketi — Realtime delivery of dashboard events. United States.
We give at least 30 days’ notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that period; if we cannot offer a workable alternative, the customer may terminate the affected part of the Service without penalty.
7. International transfers
Customer personal data is hosted in the United States (AWS, us-east-1) and accessed by our team in the United Arab Emirates and the United Kingdom.
Where this involves transferring personal data out of the EEA or the UK, the transfer is made under the European Commission’s Standard Contractual Clauses, and under the UK International Data Transfer Addendum for UK data, together with supplementary measures including encryption in transit and at rest. By entering into this DPA the parties are deemed to have signed the applicable clauses, with Pivolio as data importer and the customer as data exporter.
8. Data subject requests
9. Personal data breach
10. Return and deletion
During the subscription the customer may export their data at any time. On termination, we delete customer personal data within 30 days, except where law requires retention. Backups are deleted on their normal rotation.
We do not otherwise delete data on a schedule: conversion events and delivery logs are retained for the life of the workspace. The customer controls removal before then — data can be deleted at any time. An erasure request for an individual data subject deletes their identity records and identifiers. Their conversion events and delivery logs are retained: the customer id on those events no longer resolves to any person, while the hashed identifiers, IP address and full page URLs recorded on them remain. The customer can delete those events itself at any time.
11. Audits and assistance
12. Liability and precedence
Liability under this DPA is subject to the limitations in the terms of service.
If this DPA conflicts with those terms, this DPA prevails on data protection matters. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Questions, signed-copy requests, and subprocessor objections: privacy@pivolio.com.