SETROASFLOW — DATA PROCESSING AGREEMENT
Version: Draft — 25 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the Merchant (“Controller”) and SetRoasFlow (“Processor”) for processing personal data through the Service.
1. SUBJECT MATTER
SetRoasFlow processes personal data to provide server-side tracking, customer data infrastructure, CDP functions, segmentation, audience activation, analytics, reporting, personalization, exports and configured integrations.
2. DURATION
Processing continues for the duration of the applicable Merchant account/project. CDP profiles are retained while the account/project remains active unless the Merchant requests deletion earlier. Event records are retained for a rolling period of 24 months.
3. NATURE AND PURPOSE
Processing may include collection, transmission, normalization, hashing, matching, storage, organization, analysis, segmentation, activation, export and deletion.
4. DATA SUBJECTS
Depending on the Merchant's implementation: website visitors, customers, prospects and other individuals whose data the Merchant lawfully supplies.
5. DATA CATEGORIES
Email, phone, external identifiers, name, location fields, IP address, user-agent, advertising click IDs, event data, attribution data, country/region, device type and derived analytics as described in the Processing Details Annex.
SetRoasFlow is not intended for the processing of special categories of personal data or criminal-offence data. The Merchant must not submit such data to the Service.
6. CONTROLLER INSTRUCTIONS
The Merchant determines purposes and lawful bases and instructs SetRoasFlow through configuration, integration and documented requests.
7. CONFIDENTIALITY AND PERSONNEL ACCESS
Authorized SetRoasFlow personnel may have technically possible administrative access to production data stores where necessary to operate, maintain, debug or support the Service. Such access is subject to organizational and contractual restrictions and is not performed as part of routine operations. The Service does not rely on a technical barrier preventing the operator from accessing production data.
8. SECURITY
SetRoasFlow implements the technical and organizational measures described in the TOMs Annex.
9. SUBPROCESSORS AND THIRD-PARTY DESTINATIONS
The Merchant authorizes the subprocessors listed in the Subprocessor Annex, subject to the applicable change mechanism.
SetRoasFlow may also transmit data to third-party advertising, analytics, CRM and other destinations configured by the Merchant. The legal classification of each destination (including whether it acts as an independent controller, joint controller, processor or other recipient) is determined separately and is not implied merely by its inclusion as a Service destination.
10. DATA SUBJECT RIGHTS
SetRoasFlow will provide reasonable assistance to the Merchant for applicable access, deletion, correction, restriction, objection and portability requests.
11. SECURITY INCIDENTS
SetRoasFlow will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting the Merchant's data, subject to applicable law and available facts.
12. DELETION
Upon project deletion, SetRoasFlow will erase the applicable live data associated with the project within 24 hours, subject to technical deletion and disaster-recovery processes described below.
Residual copies may persist in provider disaster-recovery systems for a limited period and then automatically expire. Such residual copies are not accessible through normal operations and are not used for ongoing processing.
Data already transmitted to third-party destinations is outside SetRoasFlow's direct control and remains subject to the applicable third party's policies, retention periods and deletion mechanisms.
13. DISASTER-RECOVERY COPIES
Cloudflare D1 point-in-time recovery is currently retained for up to 30 days on the applicable paid Workers configuration. Durable Objects recovery is expected to operate on a similar approximate period; the exact current retention is subject to technical verification. Cloudflare KV has no backup copy. Supabase currently operates on a Free plan without automatic backups; a future Pro configuration may retain database backups for up to 7 days.
14. AUDITS
[LAWYER REVIEW REQUIRED: finalize audit rights, evidence package, frequency and cost allocation.]
15. INTERNATIONAL TRANSFERS
Transfers outside the EEA will use an applicable lawful mechanism. Vendor-specific mechanisms are documented in the Transfer Matrix.
16. ORDER OF PRECEDENCE
[LAWYER REVIEW REQUIRED: confirm interaction between the DPA, Terms and any applicable SCCs.]