Data processing

Data Processing Agreement

Parties

This Data Processing Agreement applies when Roast My Funnel OÜ processes personal data on behalf of a customer as part of providing website audit services. It forms part of the Terms unless the parties sign a separate written data processing agreement.

Roles

For customer-submitted website, audit configuration, and report data, the customer may act as controller and Roast My Funnel OÜ may act as processor. For account administration, product analytics, billing, security, legal compliance, fraud prevention, and service operations, Roast My Funnel OÜ may act as controller as described in the Privacy Policy.

Processing instructions

Roast My Funnel OÜ processes personal data only to provide and secure the service, generate reports, support customers, comply with law, maintain records, prevent abuse, and follow documented customer instructions consistent with the Terms. We may refuse an instruction that is unlawful, technically infeasible, unsafe, or outside the service scope.

Customer responsibilities

Customers are responsible for providing lawful instructions, having a lawful basis to submit URLs and content, providing required notices to their users or clients, honoring data subject rights, and ensuring submitted content does not include prohibited, sensitive, private, or unauthorized data unless expressly agreed in writing.

Categories of data

Processed data may include account details, email addresses, submitted URLs, visible website content, screenshots, audit configuration, buyer persona selections, generated reports, payment metadata, technical logs, consent records, and support communications. Customers must not submit special-category, high-risk, confidential, or unauthorized third-party personal data unless they have a lawful basis and our written agreement.

Data subjects

Data subjects may include customer users, employees, contractors, client contacts, website visitors whose information is visible on submitted public pages, and support contacts.

Subprocessors

Roast My Funnel OÜ may use subprocessors for hosting, CDN/security, storage, payments, email, analytics, browser automation, support, observability, and AI model processing. Current or expected subprocessors include Vercel, Cloudflare, Neon, Stripe, ZeptoMail, Google, OpenAI or other AI model providers, Google Cloud Platform, Cloudflare R2, and Sentry for frontend observability, each as applicable to the service.

We remain responsible for subprocessors we engage as required by applicable data protection law and will use reasonable contractual safeguards. Customers may contact [email protected] for current subprocessor information.

Security measures

Roast My Funnel OÜ uses reasonable technical and organizational measures including access controls, encrypted transport, vendor safeguards, security headers, monitoring, least-privilege operational practices, environment separation, secret management, rate limiting, and abuse-prevention controls. Security measures may evolve as the service changes.

Confidentiality

Personnel and contractors with access to customer personal data are expected to be subject to confidentiality obligations or equivalent professional duties. Access is limited based on role, need, and operational purpose.

International transfers

Where personal data is transferred outside the EEA, United Kingdom, or Switzerland, Roast My Funnel OÜ will use appropriate transfer mechanisms such as Standard Contractual Clauses, adequacy decisions, data processing terms, transfer impact assessments where required, or equivalent lawful safeguards.

Assistance and deletion

Roast My Funnel OÜ will reasonably assist with data subject requests, security incidents, audits, impact assessments, and deletion/export requests where required by applicable law and technically feasible. Assistance may be limited where requests are excessive, unsupported by the service, conflict with security or legal obligations, or require professional services outside the purchased plan.

Return and deletion

Upon verified request or account closure, we will delete or return customer personal data where required and technically feasible, subject to legal retention, payment and tax records, security logs, backups, dispute records, fraud-prevention needs, and records needed to establish or defend legal claims.

Security incidents

If we become aware of a confirmed personal data breach affecting customer personal data processed under this DPA, we will notify affected customers without undue delay as required by applicable law and provide information reasonably available to help customers meet their own obligations.

Audits

We may satisfy audit requests through security summaries, vendor documentation, certifications where available, written responses, or other reasonable evidence. On-site audits require prior written agreement, reasonable notice, confidentiality, and controls designed to protect other customers, our systems, and vendor information.

Contact

DPA questions can be sent to [email protected].