Data Processing Addendum

Last updated: July 15, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between HeyCatch, Inc. (“HeyCatch”, “Processor”) and the customer (“Customer”, “Controller”) consisting of the HeyCatch Terms of Service (the "Agreement"). It applies automatically, without signature, to every Customer to the extent HeyCatch processes personal data on the Customer’s behalf — in particular, end-user data collected via the HeyCatch SDKinstalled on the Customer’s website, and any other personal data the Customer submits about its own customers or audience ("Customer Personal Data"). It does not apply to data HeyCatch processes as a controller (see the Privacy Policy).

1. Roles and scope

For Customer Personal Data, the Customer is the controller (or a processor acting for another controller, in which case HeyCatch is a sub-processor) and HeyCatch is the processor. Each party complies with the data-protection laws applicable to it, including the GDPR, UK GDPR, and applicable US state privacy laws.

2. Processing on instructions

HeyCatch will process Customer Personal Data only on the Customer’s documented instructions— the Agreement, this DPA, and the Customer’s configuration of the Services constitute those instructions — including with regard to international transfers, unless required otherwise by law (in which case HeyCatch will inform the Customer before processing, unless the law prohibits it). HeyCatch will promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.

3. Confidentiality

Persons authorized to process Customer Personal Data are bound by confidentiality obligations (contractual or statutory).

4. Security (Art. 32 GDPR)

HeyCatch implements appropriate technical and organizational measures described in Annex II, taking into account the state of the art, the nature of the data, and the risks of the processing. HeyCatch may update Annex II provided the overall level of protection is not reduced.

5. Sub-processors

The Customer grants a general authorization to engage the sub-processors listed at heycatch.ai/subprocessors (as reflected in the Privacy Policy §3). HeyCatch will (a) give 30 days’ notice of additions or replacements (via the subprocessors page and/or email), during which the Customer may object on reasonable data-protection grounds — if the objection cannot be resolved, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the unused period as its sole remedy; (b) impose data-protection obligations on each sub-processor no less protectivethan this DPA; and (c) remain liable for its sub-processors’ performance.

6. Data-subject requests

Taking into account the nature of the processing, HeyCatch will assist the Customer by appropriate technical and organizational measures in fulfilling data-subject requests (access, erasure, portability, objection, etc.). If a data subject contacts HeyCatch directly regarding Customer Personal Data, HeyCatch will pass the request to the Customer without undue delay and will not respond substantively except as legally required.

7. Assistance

HeyCatch will assist the Customer, insofar as reasonably possible and taking into account the information available to it, with the Customer’s obligations under Articles 32–36 GDPR (security, breach notification to authorities and data subjects, data-protection impact assessments, prior consultation).

8. Personal-data breach

HeyCatch will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably required for the Customer’s own notification obligations, updated as it becomes available.

9. Deletion and return

Upon termination or expiry of the Customer’s subscription, HeyCatch will delete or irreversibly anonymize Customer Personal Data (including SDK end-user data) within 2 months after subscription end — the reactivation window described in the Privacy Policy — unless the Customer reactivates, instructs earlier deletion, or retention is required by law. During the subscription, the Customer can export its data via the Services. Backup copies are purged on the backup rotation cycle (Annex II).

10. Audits

HeyCatch will make available information reasonably necessary to demonstrate compliance with this DPA (including summaries of third-party audits or certifications of its infrastructure providers, where available) and will allow and contribute to audits — normally satisfied by written responses and documentation; on-site audits require 30 days’ notice, at the Customer’s expense, no more than once per year, subject to confidentiality, and must not disturb other customers’ data.

11. International transfers

Where the GDPR/UK GDPR/Swiss DPA applies to a transfer of Customer Personal Data to HeyCatch in the United States (or onward to sub-processors outside an adequacy-covered country), the parties incorporate by reference the EU Standard Contractual Clauses (2021/914), Module Two (controller → processor) — or Module Three where the Customer is itself a processor — with: HeyCatch as data importer, the Customer as data exporter; Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 30 days); Clause 11 optional redress not included; Clause 17/18: Irish law and courts; Annexes populated by Annex I and II of this DPA. For UK transfers, the UK IDTA Addendum applies; for Swiss transfers, the Clauses apply as amended per Swiss FDPIC guidance. HeyCatch is not currently certified under the EU–US Data Privacy Framework; should it certify in the future, that certification may serve as an alternative transfer mechanism.

12. US state privacy laws (CCPA/CPRA and analogous)

To the extent Customer Personal Data includes personal information subject to the CCPA/CPRA or analogous state laws, HeyCatch acts as the Customer’s service provider/processor: it will not sell or share the data, will not retain, use or disclose it outside the direct business relationship or for purposes other than those in the Agreement, will comply with applicable obligations, will notify the Customer if it can no longer comply, and grants the Customer the right to take reasonable steps to stop unauthorized use.

13. Liability; order of precedence

Liability under this DPA is subject to the limitations of the Agreement (ToS §12), except where prohibited by law. In case of conflict: SCCs (for transfers they govern) → this DPA → the Agreement. This DPA is governed by the law governing the Agreement, except where the SCCs require otherwise.


Annex I — Description of processing

A. Parties. Exporter: the Customer (contact: as per account). Importer: HeyCatch, Inc., 1111B S Governors Ave STE 59736, Dover, DE 19904, USA — support@heycatch.ai.

B. Processing.

ItemDescription
Subject matterWebsite analytics and growth services provided via the HeyCatch SDK and platform
DurationSubscription term + 2-month post-expiry retention window (§9)
Nature & purposeCollection and analysis of the Customer’s website-visitor events to provide funnel/growth analytics to the Customer
Data subjectsVisitors and users of the Customer’s websites/products
Categories of dataSite visits, sessions, page events, signup and payment events, IP address, device/browser data, identifiers set by the SDK
Special categoriesNone intended; the Customer must not configure collection of special-category data
FrequencyContinuous while the SDK is enabled
RetentionSee §9 (2 months post-expiry)

C. Competent supervisory authority (SCC Annex I.C): determined per Clause 13 SCCs (exporter’s authority).

Annex II — Technical and organizational measures


© HeyCatch, Inc. All rights reserved.