Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between HeyCatch, Inc. (“HeyCatch”, “Processor”) and the customer (“Customer”, “Controller”) consisting of the HeyCatch Terms of Service (the "Agreement"). It applies automatically, without signature, to every Customer to the extent HeyCatch processes personal data on the Customer’s behalf — in particular, end-user data collected via the HeyCatch SDKinstalled on the Customer’s website, and any other personal data the Customer submits about its own customers or audience ("Customer Personal Data"). It does not apply to data HeyCatch processes as a controller (see the Privacy Policy).
1. Roles and scope
For Customer Personal Data, the Customer is the controller (or a processor acting for another controller, in which case HeyCatch is a sub-processor) and HeyCatch is the processor. Each party complies with the data-protection laws applicable to it, including the GDPR, UK GDPR, and applicable US state privacy laws.
2. Processing on instructions
HeyCatch will process Customer Personal Data only on the Customer’s documented instructions— the Agreement, this DPA, and the Customer’s configuration of the Services constitute those instructions — including with regard to international transfers, unless required otherwise by law (in which case HeyCatch will inform the Customer before processing, unless the law prohibits it). HeyCatch will promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.
3. Confidentiality
Persons authorized to process Customer Personal Data are bound by confidentiality obligations (contractual or statutory).
4. Security (Art. 32 GDPR)
HeyCatch implements appropriate technical and organizational measures described in Annex II, taking into account the state of the art, the nature of the data, and the risks of the processing. HeyCatch may update Annex II provided the overall level of protection is not reduced.
5. Sub-processors
The Customer grants a general authorization to engage the sub-processors listed at heycatch.ai/subprocessors (as reflected in the Privacy Policy §3). HeyCatch will (a) give 30 days’ notice of additions or replacements (via the subprocessors page and/or email), during which the Customer may object on reasonable data-protection grounds — if the objection cannot be resolved, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the unused period as its sole remedy; (b) impose data-protection obligations on each sub-processor no less protectivethan this DPA; and (c) remain liable for its sub-processors’ performance.
6. Data-subject requests
Taking into account the nature of the processing, HeyCatch will assist the Customer by appropriate technical and organizational measures in fulfilling data-subject requests (access, erasure, portability, objection, etc.). If a data subject contacts HeyCatch directly regarding Customer Personal Data, HeyCatch will pass the request to the Customer without undue delay and will not respond substantively except as legally required.
7. Assistance
HeyCatch will assist the Customer, insofar as reasonably possible and taking into account the information available to it, with the Customer’s obligations under Articles 32–36 GDPR (security, breach notification to authorities and data subjects, data-protection impact assessments, prior consultation).
8. Personal-data breach
HeyCatch will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably required for the Customer’s own notification obligations, updated as it becomes available.
9. Deletion and return
Upon termination or expiry of the Customer’s subscription, HeyCatch will delete or irreversibly anonymize Customer Personal Data (including SDK end-user data) within 2 months after subscription end — the reactivation window described in the Privacy Policy — unless the Customer reactivates, instructs earlier deletion, or retention is required by law. During the subscription, the Customer can export its data via the Services. Backup copies are purged on the backup rotation cycle (Annex II).
10. Audits
HeyCatch will make available information reasonably necessary to demonstrate compliance with this DPA (including summaries of third-party audits or certifications of its infrastructure providers, where available) and will allow and contribute to audits — normally satisfied by written responses and documentation; on-site audits require 30 days’ notice, at the Customer’s expense, no more than once per year, subject to confidentiality, and must not disturb other customers’ data.
11. International transfers
Where the GDPR/UK GDPR/Swiss DPA applies to a transfer of Customer Personal Data to HeyCatch in the United States (or onward to sub-processors outside an adequacy-covered country), the parties incorporate by reference the EU Standard Contractual Clauses (2021/914), Module Two (controller → processor) — or Module Three where the Customer is itself a processor — with: HeyCatch as data importer, the Customer as data exporter; Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 30 days); Clause 11 optional redress not included; Clause 17/18: Irish law and courts; Annexes populated by Annex I and II of this DPA. For UK transfers, the UK IDTA Addendum applies; for Swiss transfers, the Clauses apply as amended per Swiss FDPIC guidance. HeyCatch is not currently certified under the EU–US Data Privacy Framework; should it certify in the future, that certification may serve as an alternative transfer mechanism.
12. US state privacy laws (CCPA/CPRA and analogous)
To the extent Customer Personal Data includes personal information subject to the CCPA/CPRA or analogous state laws, HeyCatch acts as the Customer’s service provider/processor: it will not sell or share the data, will not retain, use or disclose it outside the direct business relationship or for purposes other than those in the Agreement, will comply with applicable obligations, will notify the Customer if it can no longer comply, and grants the Customer the right to take reasonable steps to stop unauthorized use.
13. Liability; order of precedence
Liability under this DPA is subject to the limitations of the Agreement (ToS §12), except where prohibited by law. In case of conflict: SCCs (for transfers they govern) → this DPA → the Agreement. This DPA is governed by the law governing the Agreement, except where the SCCs require otherwise.
Annex I — Description of processing
A. Parties. Exporter: the Customer (contact: as per account). Importer: HeyCatch, Inc., 1111B S Governors Ave STE 59736, Dover, DE 19904, USA — support@heycatch.ai.
B. Processing.
| Item | Description |
|---|---|
| Subject matter | Website analytics and growth services provided via the HeyCatch SDK and platform |
| Duration | Subscription term + 2-month post-expiry retention window (§9) |
| Nature & purpose | Collection and analysis of the Customer’s website-visitor events to provide funnel/growth analytics to the Customer |
| Data subjects | Visitors and users of the Customer’s websites/products |
| Categories of data | Site visits, sessions, page events, signup and payment events, IP address, device/browser data, identifiers set by the SDK |
| Special categories | None intended; the Customer must not configure collection of special-category data |
| Frequency | Continuous while the SDK is enabled |
| Retention | See §9 (2 months post-expiry) |
C. Competent supervisory authority (SCC Annex I.C): determined per Clause 13 SCCs (exporter’s authority).
Annex II — Technical and organizational measures
- Encryption of data in transit (TLS) and at rest; connected-account and API tokens stored encrypted with strictly limited access.
- Access control: least-privilege, role-based access; MFA on infrastructure and admin accounts; access logging.
- Infrastructure: managed cloud providers (see subprocessors list) with their own certified physical/organizational security; production/dev separation.
- Data minimization: SDK collects the event set configured by the Customer; no card data (payments handled by Paddle/Stripe directly).
- Availability: daily managed-database backups, retained ~7 days (DigitalOcean Managed Postgres); monitored error and log pipelines (Sentry, Axiom).
- Incident response: detection, escalation, customer notification without undue delay (§8).
- Personnel: confidentiality undertakings; vendor due diligence for sub-processors.
- Deletion: automated retention enforcement per §9 and Privacy Policy §5.