Data Processing Agreement

Version 2.0 · Effective 6 August 2026

This Data Processing Agreement (“DPA”) is entered into between Titan Ventures Ltd, a company registered in Ireland under company number 773679, with its registered office at Peace Cottage, Nicholastown, Slieverue, Co. Waterford, Ireland, trading as PixelFlow (“Processor”, “we”), and the customer identified in the applicable Terms of Service (“Controller”, “you”).

This DPA forms part of the Terms of Service and governs the processing of personal data carried out by us on your behalf. Where this DPA conflicts with the Terms of Service in relation to the processing of personal data, this DPA prevails.

Contents
  1. Definitions

  2. Subject matter, roles and duration

  3. Processing instructions

  4. Controller responsibilities

  5. Processor responsibilities

  6. Personal data breaches

  7. Subprocessors

  8. Recipients acting as independent controllers

  9. International transfers

  10. Data retention and deletion

  11. Security measures

  12. Audit and inspection

  13. Assistance with compliance

  14. Liability

  15. Governing law and jurisdiction

  16. Annex I: Description of processing

  17. Annex II: Technical and organisational measures

  18. Annex III: Subprocessors

1. Definitions
  • Controller: the entity which determines the purposes and means of processing personal data.

  • Processor: the entity which processes personal data on behalf of the Controller.

  • Subprocessor: any third party engaged by the Processor to process personal data on behalf of the Controller.

  • Personal Data: any information relating to an identified or identifiable natural person, including pseudonymised data such as hashed identifiers.

  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

  • Applicable Law: all data protection and privacy legislation applicable to the processing, including the GDPR, the Irish Data Protection Act 2018, the ePrivacy Directive and related national implementations and guidance.

Terms not defined here have the meaning given in the GDPR.

2. Subject Matter, Roles and Duration

2.1. PixelFlow provides server-side event tracking and forwarding services. In connection with those services we process Personal Data on your behalf and on your instructions.

2.2. For that processing, you are the Controller and we are the Processor.

2.3. For our own account, billing, support and website visitor data, we act as Controller. That processing is described in our Privacy Policy and is outside the scope of this DPA.

2.4. Duration. This DPA takes effect when you accept the Terms of Service and continues for as long as we process Personal Data on your behalf. Clauses 10, 11, 12, 14 and 15 survive termination.

2.5. Full details of the processing are set out in Annex I.

3. Processing Instructions

3.1. We will process Personal Data only on your documented instructions, including in relation to international transfers, unless required to do otherwise by EU or member state law. Where we are required to process for such a reason, we will inform you before processing unless the law prohibits it.

3.2. Your instructions consist of the Terms of Service, this DPA, and the configuration you set within the platform.

3.3. Infringing instructions. If we consider that an instruction from you infringes Applicable Law, we will inform you without undue delay. We may suspend performance of the relevant instruction until it is amended or confirmed.

3.4. We will not use Personal Data processed on your behalf for our own purposes, including our own marketing, profiling, benchmarking, resale, or the training of models, except where the data has been fully and irreversibly anonymised.

4. Controller Responsibilities

You are responsible for:

  • Establishing and documenting a valid lawful basis for all processing carried out through the Service

  • Providing all required notices and obtaining valid end-user consent, for example through a cookie banner or consent management platform, before any tracking script loads or executes and before any Personal Data is transmitted to us

  • Ensuring that client-side scripts, pixels and tracking mechanisms on your websites and applications execute only after valid consent has been obtained where required

  • Ensuring only necessary Personal Data is transmitted to us, applying data minimisation

  • Not transmitting prohibited data as set out in the Terms of Service, including special category data, data relating to children, and consumer health data

  • Managing data subject rights requests received from your end users

  • The accuracy, quality and legality of the Personal Data you transmit and of the instructions you give us

You acknowledge that failure to obtain valid consent or otherwise comply with Applicable Law may result in liability for you, and that we do not guarantee your compliance.

5. Processor Responsibilities

We shall:

  • Process Personal Data only as set out in clause 3

  • Implement and maintain the technical and organisational measures set out in Annex II

  • Ensure that persons authorised to process Personal Data are bound by written confidentiality obligations

  • Assist you as set out in clause 13

  • Notify you of Personal Data Breaches as set out in clause 6

  • Maintain a record of processing activities carried out on your behalf, as required by Article 30(2) GDPR, and make it available to you or a supervisory authority on request

  • Maintain and publish an up-to-date list of subprocessors as set out in clause 7

  • Delete or return Personal Data as set out in clause 10

We do not guarantee compliance for client-side implementations. You remain responsible for ensuring scripts and tracking mechanisms deployed on your properties comply with Applicable Law.

6. Personal Data Breaches

6.1. We will notify you of a Personal Data Breach affecting Personal Data processed on your behalf without undue delay and in any event within 48 hours of becoming aware of it.

6.2. The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of this at once, we will provide it in phases without further undue delay.

6.3. We will take reasonable steps to contain and remediate the breach and will cooperate with you in your own notification obligations to supervisory authorities and data subjects.

6.4. We will not notify a supervisory authority or data subjects on your behalf unless you instruct us to, or we are independently required to do so.

7. Subprocessors

7.1. You give general authorisation for us to engage subprocessors, subject to this clause.

7.2. The current list of subprocessors is set out in Annex III and maintained on our subprocessor page. To be notified of changes, email support@pixelflow.so.

7.3. We will give you at least 30 days’ notice before a new subprocessor is given access to Personal Data.

7.4. Objection. You may object to a new subprocessor on reasonable data protection grounds by writing to support@pixelflow.so within the notice period. We will work with you in good faith to find a resolution. If no resolution is reached, you may terminate the affected part of the Service without penalty and receive a pro rata refund of prepaid fees for the unused period.

7.5. Flow-down. We will impose on each subprocessor data protection obligations that are no less protective than those in this DPA.

7.6. Liability. We remain fully liable to you for the performance of each subprocessor’s obligations.

8. Recipients Acting as Independent Controllers

8.1. Where you configure the Service to forward event data to Meta Platforms, Inc. or its affiliates (“Meta”) through the Conversions API, Meta does not act as our subprocessor. Meta processes that data as an independent controller, and in some cases as a joint controller with you, under Meta’s Business Tools Terms and associated data terms.

8.2. You are responsible for entering into and complying with Meta’s Business Tools Terms, Meta’s Data Processing Terms and any applicable controller addendum, and for the lawfulness of transmitting data to Meta.

8.3. We are not responsible for Meta’s processing of data once it has been transmitted in accordance with your configuration.

8.4. The same principle applies to any other advertising or analytics destination you configure the Service to forward data to.

9. International Transfers

9.1. Our production infrastructure is hosted on Amazon Web Services in the United States, in the us-east-2 (Ohio) region.

9.2. Where Personal Data is transferred outside the EEA, we ensure an appropriate safeguard is in place, being one or more of:

  • An adequacy decision by the European Commission, including the EU-US Data Privacy Framework where the recipient is certified under it

  • Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, using Module Three (processor to processor) where we act as your Processor

9.3. Transfer impact assessment. We have conducted a transfer impact assessment covering our use of Amazon Web Services, addressing the legal regime of the United States including the CLOUD Act and FISA Section 702 as material transfer risks. A copy is available to you on written request to support@pixelflow.so.

9.4. Supplementary measures. We implement encryption of data in transit (TLS) and at rest, access controls limiting production data access to a minimum number of authorised personnel, and a policy of challenging any government access request that is not legally binding and of notifying you where lawfully permitted.

10. Data Retention and Deletion

10.1. Account data is retained for the life of your account and deleted in accordance with our Privacy Policy after account closure.

10.2. Event data processed on your behalf is retained as follows: raw event payloads for 30 days, and event records for 6 months. After those periods the data is deleted.

10.3. On termination, we will delete or return all Personal Data processed on your behalf within 30 days, at your choice, unless retention is required by EU or member state law. Where retention is legally required, we will inform you of the reason and the period, and will continue to protect the data under this DPA.

10.4. Backups are deleted on our standard backup rotation cycle. Personal Data remaining in backups is not actively processed and is protected by the measures in Annex II until deletion.

10.5. You may configure shorter retention periods within the platform where that feature is available. Where you do, your configuration prevails over clause 10.2.

11. Security Measures

We implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.

We may update those measures over time, provided the level of protection is not reduced.

12. Audit and Inspection

12.1. We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

12.2. On written request, and no more than once per calendar year, we will respond to a reasonable written security and data protection questionnaire, and provide copies of any relevant third-party certifications, penetration test summaries or audit reports we hold.

12.3. Where the information provided under clause 12.2 is not sufficient to demonstrate compliance, or following a Personal Data Breach affecting your data, you may conduct an audit or appoint an independent auditor to do so, subject to:

  • At least 30 days’ prior written notice

  • Being carried out during normal business hours and without unreasonable disruption to our operations

  • The auditor being bound by confidentiality obligations and not being a competitor of ours

  • The scope being limited to systems and records relevant to the processing of your Personal Data

  • You bearing your own costs, and our reasonable costs where the audit exceeds one working day

12.4. We will contribute to audits conducted by a supervisory authority where legally required.

13. Assistance with Compliance

We will provide reasonable assistance to you, taking into account the nature of the processing and the information available to us, with:

  • Responding to data subject rights requests, including access, rectification, erasure, restriction, portability and objection

  • Conducting data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36

  • Ensuring compliance with your security obligations under Article 32

  • Managing and notifying Personal Data Breaches under Articles 33 and 34

Where a data subject contacts us directly about data we process on your behalf, we will refer them to you and will notify you of the request without undue delay.

We may charge a reasonable fee for assistance that goes materially beyond what is required by Applicable Law or that results from your own configuration choices.

14. Liability

14.1. Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions set out in the Terms of Service, including the aggregate liability cap.

14.2. Clause 14.1 does not limit any liability that cannot be limited under Applicable Law, including a data subject’s rights under Article 82 GDPR.

15. Governing Law and Jurisdiction

This DPA is governed by the laws of Ireland. Any disputes arising from or in connection with it are subject to the exclusive jurisdiction of the courts of Ireland.

Annex I: Description of Processing

Nature and purpose of processing

Collection, storage, structuring, deduplication, enrichment and transmission of website and application event data to advertising and analytics destinations configured by the Controller, and provision of reporting on that data through the PixelFlow dashboard.

Duration of processing

For the term of the Controller’s subscription, plus the retention and deletion periods in clause 10.

Categories of data subjects

Visitors to, and users of, the Controller’s websites and applications.

Categories of personal data

  • IP addresses, processed for event transmission, geolocation at country level and deduplication

  • Browser and device information, including user agent, operating system, screen and language settings

  • Online identifiers, including cookie identifiers, click identifiers such as fbclid, and internal event and session identifiers

  • Referrer URLs, page URLs, UTM parameters and page activity data

  • Event metadata defined by the Controller, which may include purchase value, currency, order or transaction identifiers, product identifiers and custom parameters

  • Hashed identifiers where the Controller configures advanced matching, which may include hashed email addresses, hashed phone numbers, hashed names and hashed location fields

Special category data

The Controller is prohibited from transmitting special category data under Article 9 GDPR, data relating to children, and consumer health data. We do not knowingly process such data. Where we become aware that such data has been transmitted, we may suspend processing under the Terms of Service.

Frequency of transfer

Continuous, in real time as events occur.

Annex II: Technical and Organisational Measures

We implement and maintain the following measures. We keep them under review and may update them, provided the level of protection is not reduced.

Access control

  • Authentication and access control mechanisms for production systems

  • Access to production Personal Data limited to personnel who require it for an operational purpose

Encryption

  • TLS for data in transit, including customer-facing endpoints

  • Encryption at rest for stored data where supported by the underlying service

Pseudonymisation

  • Identifiers are hashed before transmission where the destination supports it

Segregation

  • Logical separation of customer data within shared database infrastructure

Availability and resilience

  • Automated backups with documented recovery procedures

  • Network-level protection of production infrastructure

Personnel

  • Written confidentiality obligations for personnel with access to Personal Data

Vendor management

  • Written data processing agreements with subprocessors

  • Hosting with established infrastructure providers

Annex III: Subprocessors

The current list is also published on our subprocessor page.

Part A: Subprocessors processing end-user Personal Data on behalf of Controllers

Amazon Web Services, Inc.

  • Purpose: Infrastructure, compute, storage and networking

  • Location: United States (us-east-2, Ohio)

  • Transfer safeguard: Standard Contractual Clauses and a transfer impact assessment, plus the EU-US Data Privacy Framework where certified

Cloudflare, Inc.

  • Purpose: DNS, CDN and network security in front of our tracking endpoints

  • Location: United States, with processing at global edge locations

  • Transfer safeguard: Standard Contractual Clauses, plus the EU-US Data Privacy Framework where certified

IPinfo, Inc. (ipinfo.io)

  • Purpose: IP address lookup for country-level geolocation of events

  • Location: United States

  • Transfer safeguard: Standard Contractual Clauses

Part B: Vendors processing Controller account data, where PixelFlow is Controller

These are listed for transparency. They do not process end-user Personal Data on behalf of Controllers.

  • Stripe, Inc. and Stripe Payments Europe, Ltd. — payment processing for PixelFlow subscriptions — Ireland and United States

  • Google Ireland Limited — Google Workspace for support email, and Google Tag Manager on pixelflow.so — Ireland and United States

  • Resend — transactional and marketing email — United States

  • PostHog, Inc. — website and product analytics — United States

  • Slack Technologies, LLC — internal communication — United States

  • Rewardful — affiliate and referral programme tracking — Canada and United States

  • Calendly, LLC — meeting and demo scheduling — United States

  • Framer B.V. — marketing website hosting — Netherlands and United States

  • GitHub, Inc. — source code hosting and continuous integration — United States

  • Fathom Video Inc. — recording, transcription and summarisation of sales and support calls — United States

  • Ferndesk — help centre hosting and AI support assistant conversations — United States

  • Notion Labs, Inc. — internal documentation and project management — United States

We also use Grafana for infrastructure monitoring and Anthropic for software development tooling. Neither receives Personal Data processed on behalf of Controllers.