Data Processing Agreement
Review draft — version 0.1, September 23, 2026
This draft is provided for discussion. It is not an executed agreement and does not become binding merely by being published or viewed. The customer details, processing schedules, and applicable international-transfer arrangements must be completed before signing or otherwise expressly incorporating a final version into a customer agreement.
Provider: Kelviq, Inc., a Delaware C corporation, operating ParityDeals. Contact: hi@paritydeals.com.
Email us to finalize the agreement, including the parties' registered addresses, customer legal entity, effective date, underlying services agreement, and notice contacts. These terms describe proposed commitments; they are not evidence that every operational procedure is already implemented.
1. Scope and roles
This Agreement governs personal data processed by Provider on Customer’s behalf in providing the services described in Schedule A (Customer Personal Data). Customer acts as controller and Provider as processor for that processing. If Customer acts as processor, Customer confirms its authority to appoint Provider as a subprocessor and communicate the relevant controller’s instructions.
Applicable Data Protection Law means data protection laws applicable to the processing, including the EU GDPR, UK GDPR and Data Protection Act 2018 where applicable, and the California Consumer Privacy Act as amended (CCPA) where applicable. Personal data, processing, controller, processor and personal data breach have their applicable statutory meanings.
This Agreement does not authorize Provider to use Customer Personal Data for its own independent analytics, advertising, profiling or other independent purposes. Any separate controller activities, including Provider account administration where applicable, must be separately identified and transparently documented; they are not authorized by this Agreement.
2. Instructions and confidentiality
Provider will process Customer Personal Data only on Customer’s documented instructions, including this Agreement and lawful written service instructions, and only for the specified purposes in Schedule A. Customer is responsible for the lawfulness of its instructions and required notices and legal grounds.
If applicable law requires other processing, Provider will inform Customer before processing unless that law prohibits notice. Provider will immediately inform Customer if, in its opinion, an instruction infringes applicable data protection law, and suspend the affected instruction pending resolution where appropriate.
Provider will ensure that authorized personnel are bound by confidentiality obligations and have access only as necessary for their duties.
3. Security
Provider will implement and maintain technical and organizational measures appropriate to the risks, taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of processing. Measures will address confidentiality, integrity, availability and resilience, restoration following incidents, and regular evaluation of their effectiveness as appropriate under applicable law.
The parties will complete Schedule B with the specific measures Provider will maintain. Provider will not materially reduce the agreed protection during the term. No certification or independent audit is represented by this Agreement.
4. Subprocessors
Customer authorizes only the subprocessors identified in completed Schedule C. Before permitting access, Provider will enter a written agreement imposing substantially the same applicable data protection obligations, including sufficient security guarantees. Provider remains responsible to Customer for its subprocessors' performance of these obligations.
Provider will give at least 30 days' advance written notice of an intended addition or replacement, including the entity, function, data and processing locations. Customer may object on reasonable data protection grounds within that period. The parties will seek an appropriate alternative. Provider will not disclose affected Customer Personal Data to the proposed subprocessor while the objection is unresolved; if no solution is available, Customer may terminate the affected service and receive a prorated refund of unused prepaid fees for that service.
5. Assistance with individual rights
Taking account of the nature of processing, Provider will assist Customer through appropriate technical and organizational measures with requests for access, correction, erasure, restriction, portability, objection and other applicable individual rights.
Provider will promptly forward requests concerning Customer Personal Data received directly from individuals and will not independently respond substantively except on Customer’s instructions or as required by law. Provider will promptly perform appropriately scoped searches, securely provide relevant results, and implement lawful instructions within timelines reasonably necessary for Customer to meet its legal deadlines.
A restriction instruction is distinct from deletion. Provider will preserve and restrict the relevant records as instructed, prevent prohibited use, and notify Customer of any technical limitations promptly. Provider will not disclose another person’s data merely because an IP address matches.
6. Personal data breaches
Provider will notify Customer without undue delay and, in any event, within 24 hours after becoming aware of a personal data breach affecting Customer Personal Data. This is a proposed contractual maximum, not a statement of historical response performance.
Initial notice will include available information about the incident, affected categories and approximate numbers of individuals and records where possible, likely consequences, mitigation measures, and an incident contact. Provider may provide information in phases without undue further delay and will not wait for a complete investigation before notifying.
Provider will promptly investigate, contain and remediate the breach, preserve relevant evidence, and cooperate with Customer’s notification and mitigation obligations. Customer controls notifications to individuals and authorities concerning processing on its behalf unless law requires Provider to notify independently.
Customer incident and backup contacts will be specified in the executed agreement. Provider privacy contact: hi@paritydeals.com.
7. Compliance assistance and audits
Taking account of the nature of processing and information available, Provider will assist Customer with security obligations, breach assessment and notifications, data protection impact assessments, and prior consultation with authorities.
Provider will make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by Customer or its mandated independent auditor. Routine audits may use reasonable advance notice and confidentiality safeguards. Those arrangements will not prevent urgent, regulator-required or incident-related audits, or otherwise defeat applicable statutory audit rights.
8. Retention, return and deletion
Provider will retain Customer Personal Data only for the periods and purposes specified in completed Schedule A. Upon an authorized deletion instruction, Provider will delete the relevant data without undue delay within the verified periods in Schedule A and confirm completion and any remaining exceptions in writing.
At the end of services, Provider will, at Customer’s choice, return or delete Customer Personal Data and delete existing copies, unless applicable law requires retention. Any required retention will be limited to that requirement, with the data protected and isolated from further service use; Provider will explain the basis and duration unless prohibited by law.
Schedule A must specify treatment and maximum expiry of backup copies. Any agreed backup expiry arrangement must comply with applicable law and Customer’s instructions. Copies awaiting expiry must be protected against ordinary use; if restored, applicable deletion and restriction instructions must be reapplied. A pending access or restriction request will be handled according to Customer’s documented lawful instructions rather than automatically treated as an erasure request.
9. International transfers
Provider will process and permit access to Customer Personal Data only in the locations identified in Schedule C and Schedule A. Before any transfer requiring safeguards, the parties will establish a valid mechanism under applicable law, assess its applicability, and implement necessary supplementary measures.
Where required, the parties must execute the applicable European Commission Standard Contractual Clauses, including the correct module, completed annexes and options, and any required UK transfer instrument. References in this draft alone do not execute or complete those instruments. Any applicable transfer clauses prevail over inconsistent provisions of this Agreement.
10. California terms
Where Provider acts as a service provider or contractor under the CCPA, Customer discloses personal information only for the limited and specified business purposes in Schedule A. Provider will comply with applicable CCPA obligations and provide the same level of privacy protection required by that law.
Provider will not sell or share that personal information; retain, use or disclose it for purposes other than the specified purposes or outside the direct business relationship except as permitted by the CCPA; or combine it with personal information from other customers or Provider’s own interactions except as expressly permitted by the CCPA. Provider certifies that it understands and will comply with these restrictions.
Customer may take reasonable and appropriate steps to verify compliant use, including the audit rights above, and to stop and remediate unauthorized use. Provider will notify Customer if it determines it can no longer meet its obligations. Provider will assist with applicable consumer requests and require any authorized downstream recipient to meet applicable contractual requirements.
11. Term and precedence
This Agreement remains effective while Provider or its subprocessors hold Customer Personal Data. It prevails over conflicting services agreement terms concerning personal data processing, subject to mandatory transfer clauses and applicable law. Other commercial terms remain governed by the underlying agreement to the extent legally permitted. No provision limits individuals' statutory rights or authorities' powers.
Schedule A — Processing details
- Service: Geographical pricing and unique-visitor reporting through ParityDeals.
- Individuals: Visitors and end users of the customer’s integrated websites or applications.
- Data: IP addresses processed for approximate location; IP addresses and timestamps retained in an AWS-hosted database for unique-visitor reports. No names, emails, or user accounts are attached to those visitor-counting records.
- Purpose: Provide geographical pricing and merchant reports on the customer’s instructions, rather than independent Provider analytics using these visitor-counting records.
- Operations: Receipt, use, storage, retrieval, restriction, and deletion, as applicable to the service.
- Location: AWS hosting in the United States. Authorized remote-access countries must be identified in the final schedule.
- Duration: The service term, subject to the agreed retention and deletion schedule.
- Opt-out: Customers can email hi@paritydeals.com to disable IP-based unique-visitor counting. Existing records remain subject to applicable retention, access, and restriction instructions.
- Retention: Visitor-counting records are automatically deleted 13 months after collection, or earlier upon the customer’s request to delete its account or those records, or other authorized deletion instruction.
- Logs: Operational and security logs are retained for 90 days and do not contain visitor IP addresses.
Before execution, the parties must complete the processing frequency, backup inclusion and expiry, and remote-access locations. The proposed service targets are acknowledgment of opt-out requests within one business day, disabling counting within two business days after verification, and active-system deletion without undue delay within seven calendar days after an authorized request or account closure, subject to lawful preservation and restriction instructions. These targets require implementation verification before execution.
Schedule B — Security measures
The Provider reports the following implemented measures:
- HTTPS/TLS for data in transit.
- MFA for AWS administrative access.
- Restricted production access.
- AWS WAF protection.
- Authorization controls and tenant isolation.
- 90-day log retention.
Before execution, the security schedule must also document the applicable encryption-at-rest configuration, confidentiality and access-review procedures, vulnerability management, recovery and backup arrangements, rights-request handling, incident escalation, and control testing. This draft does not claim SOC 2 or ISO 27001 certification.
Schedule C — Subprocessors and transfers
Amazon Web Services (AWS): server and database hosting and AWS WAF protection in the United States. The applicable AWS contracting entity, services, data access, vendor DPA, and transfer safeguards must be recorded in the final schedule.
No additional external recipient has been identified by Provider for the integrated visitor-data flow. Google Analytics on the ParityDeals marketing website is a separate activity and is not automatically a subprocessor for customer service data.
Supported payment integrations are Stripe, Gumroad, Lemon Squeezy, Whop, Paddle, Polar, and Dodo Payments. Integration availability does not by itself authorize a provider as a subprocessor. Any actual subprocessor for the customer’s deployment must be identified and authorized under this Agreement.
Before execution, complete the applicable international-transfer mechanism, including any required Standard Contractual Clauses, annexes, assessment, and UK transfer instrument. US hosting or a hosting provider’s certifications alone do not establish that all transfers are covered.
Finalizing this agreement
Contact hi@paritydeals.com for a completed version to review and execute. The executed version must identify the parties and their authorized signatories or other express acceptance mechanism. Please also read our Privacy Policy.