convertlyft
How it works Pricing Sign in
Start free

Data Processing Agreement (DPA)

Effective date: 19 August 2026
Last updated: 19 August 2026

This DPA is designed to be referenced from, and incorporated into, the Terms of Service, and to be countersigned on request by customers who need a signed copy.

This Data Processing Agreement ("DPA") is between the customer identified in the Convertlyft account or order ("Customer", the controller/business) and Convertlyft LLC ("Convertlyft", the processor/service provider). It governs Convertlyft's processing of personal data submitted through Customer's use of the Service ("Customer Personal Data"), meaning personal data of Customer's website visitors collected via the Tag, custom events, or server-side reporting.

This DPA is part of the Terms of Service. In case of conflict regarding the processing of Customer Personal Data, this DPA prevails.


1. Roles and scope

1.1 The parties acknowledge that for Customer Personal Data, Customer is the data controller (or "business" under US state laws) and Convertlyft is the data processor (or "service provider"/"contractor"). Each party will comply with data-protection laws applicable to its role.

  • 1.2 Subject matter: website analytics and monitoring data collected on Customer's behalf via the Service.
  • Duration: the term of Customer's account, plus deletion per Section 9.
  • Nature and purpose: collection, storage, aggregation, analysis, and display of visitor event data to provide the Service, as described in the Terms.
  • Categories of data subjects: visitors to Customer's websites.
  • Categories of data: as listed in the Appendix to the Privacy Policy (page, behavior, technical, visit, and conversion data).

2. Customer obligations and warranty (this is the important part)

2.1 Customer warrants and undertakes that:

  • (a) it has provided, and will maintain, all notices and obtained all consents required by applicable law (including GDPR, ePrivacy/cookie laws, CCPA/CPRA, and similar laws) for the collection and transfer of Customer Personal Data to Convertlyft, including any consent required for the Tag's operation in the EEA/UK;
  • (b) it maintains a privacy policy on each tracked website disclosing its use of Convertlyft and the categories of data collected;
  • (c) it has a lawful basis for all Customer Personal Data it instructs us to process;
  • (d) it will not use the Tag, custom events, or server-side reporting to send us sensitive/special-category data, children's data (under 16), payment card data, authentication credentials, or form-field values containing personal data, and will use available masking/exclusion controls;
  • (e) its instructions to Convertlyft comply with applicable law.

2.2 Customer is solely responsible for the lawfulness of the collection of Customer Personal Data on its websites. Convertlyft does not determine, and has no obligation to monitor, whether Customer's use of the Service complies with law.

2.3 Indemnity. Customer will defend, indemnify, and hold Convertlyft harmless against claims, fines, penalties, and expenses (including reasonable attorneys' fees) arising from Customer's breach of this Section 2 or from any claim by a data subject or regulator relating to the collection of Customer Personal Data on Customer's websites, except to the extent caused by Convertlyft's breach of this DPA.

3. Convertlyft obligations

3.1 Convertlyft will:

  • (a) process Customer Personal Data only on Customer's documented instructions, including as needed to provide the Service per the Terms, unless law requires otherwise (in which case we will notify Customer unless prohibited);
  • (b) ensure personnel with access are bound by confidentiality;
  • (c) implement the technical and organizational measures set out in Annex II;
  • (d) not "sell" or "share" (as defined by US state laws) Customer Personal Data, and not use it for any purpose other than providing the Service to Customer, except for de-identified/aggregated Derived Data as described in the Terms, which no longer constitutes personal data;
  • (e) promptly notify Customer if we believe an instruction infringes applicable law (without obligation to actively review instructions).

4. Subprocessors

4.1 Customer authorizes the subprocessors listed at convertlyft.com/subprocessors, currently including

  • Vercel (application hosting and delivery),
  • Supabase (database, authentication and file storage),
  • Resend (transactional email),
  • Pipedream (OAuth credential brokering for channels you connect),
  • DataForSEO (search and ranking data) and
  • OpenRouter (model routing).

Stripe processes payments for paid plans; card details go to Stripe and are never stored by us. We use no third-party support-desk tool at this time.

We will update the list and notify customers by email to the account’s registered address at least 30 days before adding a subprocessor, during which Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, Customer may terminate the affected Service.

4.2 We remain liable for our subprocessors' performance to the same extent as for our own.

5. Data subject requests and regulatory assistance

5.1 As between the parties, Customer is responsible for responding to data-subject requests (access, deletion, portability, objection) relating to its visitors.

5.2 Convertlyft will provide reasonable assistance, taking into account the nature of processing, to help Customer respond to such requests — including, where technically feasible, tools or exports to locate and delete a visitor's data. Requests sent directly to us will be forwarded to Customer; we will not respond to the data subject except to refer them to Customer, unless instructed.

5.3 Convertlyft will provide reasonable cooperation with Customer's responses to supervisory authorities, at Customer's reasonable expense where the request exceeds routine assistance.

6. Security incidents

6.1 We will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide reasonable information for Customer to meet its notification obligations. Customer is responsible for assessing and making any legally required notifications to data subjects and authorities regarding its visitors.

7. International transfers

7.1 Customer Personal Data is stored and processed in Germany (database) and the United States (application servers). Where data is transferred from the EEA/UK/Switzerland to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (Module 2: controller-to-processor) and/or the UK IDTA/Addendum, which are incorporated by reference, with Convertlyft as data importer and Customer as data exporter.

8. Audits

8.1 On written request, no more than once per 12 months (unless required by a regulator or following a breach), Convertlyft will make available reasonable documentation of its compliance — such as third-party reports, security documentation, and completed questionnaires — in lieu of on-site audits. Any on-site audit, where legally required, will be at Customer's expense, during business hours, with reasonable notice, and subject to confidentiality and security policies.

9. Return and deletion

9.1 Customer may export its Service Data via the dashboard, or by request during the term. Within 90 days after account termination, we will delete or anonymize Customer Personal Data, except where retention is required by law or data resides in backups (deleted on their normal cycle).

10. Liability

10.1 Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, which apply to this DPA in aggregate with all other claims. Nothing in this DPA limits liability where such limitation is prohibited by law.

11. Miscellaneous

  • Term: effective on account creation or execution and co-terminous with the Terms.
  • Amendment: we may update this DPA with notice; updates apply prospectively and do not reduce the protections for Customer Personal Data already processed.
  • Governing law: same as the Terms of Service.
  • Signed copies: email legal@convertlyft.com for a countersigned version.

Annex I — Processing details

ItemDescription
Subject matterWebsite analytics and monitoring
DurationTerm of account + deletion per Section 9
Nature/purposeCollection, storage, aggregation, analysis, display of visitor event data
Data subjectsCustomer's website visitors
Data categoriesPage data; behavior data (clicks, scrolls, form interactions); technical data (device, browser, errors, performance); visit data (session IDs, timestamps); conversion events; transient IP processing for bot filtering/geolocation
Special categoriesNone permitted — Customer contractually prohibited from sending them
Processing locationsGermany (database) and the United States (application servers)

Annex II — Technical and organizational measures (summary)

  • Encryption in transit (TLS) and at rest
  • Access limited to personnel with operational need; credential hashing; workspace key separation
  • Bot and automation filtering before storage; event deduplication; timestamp validation
  • Internal-visit exclusion by default
  • Backups: managed, encrypted database backups taken by our database provider and retained on its standard cycle; restores are tested against a non-production copy.
  • Logging and monitoring: application, access and error logging with alerting on anomalous rates and on failed authentication.
  • Incident response: a documented process covering detection, triage, containment, notification under Section 6, and post-incident review.
Product How it works Product The agent Live demo SEO audit Funnel audit Pricing CRO consultant alternative API
Legal Privacy Terms DPA Subprocessors
Company Convertlyft LLC, Dubai, UAE Hosted on Vercel (United States); database on Supabase (Germany) privacy@convertlyft.com legal@convertlyft.com
convertlyftConvertlyft LLC · Dubai, UAE