Data Processing Agreement

Last updated: September 15, 2026

1. Parties and roles

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and FILIPE ALCANTARA, UNIPESSOAL LDA, trading as Probecast, NIF 518790061, with registered address at Rua Afonso Lopes Vieira 23, 1700-011 Lisboa, Portugal(“Processor”).

It applies wherever the Processor processes personal data on behalf of the Controller under Regulation (EU) 2016/679 (“EU GDPR”) or the UK General Data Protection Regulation as retained in UK law (“UK GDPR”).

2. Subject matter, nature and purpose

The Processor provides monitoring, analytics, reporting and alerting services for the Controller's websites, APIs and connected business tools. Processing is limited to what is necessary to deliver these services and follows the Controller's documented instructions, as expressed through the service's configuration.

Duration: for the term of the underlying agreement. On termination, personal data is deleted in line with the retention windows described in the Privacy Policy, or earlier on written request.

3. Categories of data and data subjects

  • Account data: names, email addresses and roles of the Controller's team members.
  • End-visitor analytics: pseudonymous visitor identifiers, truncated IP addresses, page paths and referrers collected by the cookieless first-party pixel. No cross-site tracking.
  • Business metrics: aggregated revenue and support figures from tools the Controller connects with read-only credentials. Support integrations store counts and timings only — never ticket content.
  • Report recipients: names and email addresses of the Controller's client contacts, used solely to deliver reports the Controller sends.

4. Where data is processed

The production database and backend run in an EU region. Some sub-processors listed below are US entities; transfers to them rely on the European Commission's Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum.

5. Processor obligations

  • Process personal data only on the Controller's documented instructions.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Art. 32): encryption of credentials at rest, TLS in transit, role-based access with an append-only audit log, and data minimisation by design (aggregates over raw data wherever possible).
  • Assist the Controller in responding to data-subject requests and in meeting security, breach-notification and impact-assessment obligations.
  • Notify the Controller without undue delay after becoming aware of a personal data breach.
  • Delete or return personal data at the end of the engagement, at the Controller's choice.
  • Make available the information necessary to demonstrate compliance and allow audits, at reasonable intervals and on reasonable notice.

6. Sub-processors

The Controller authorises the following sub-processors. The Processor will give notice of intended changes to this list, giving the Controller the opportunity to object.

Sub-processorPurposeLocation
Railway Corp.Application hosting and PostgreSQL databaseEU region (database and backend)
Vercel Inc.Web application hosting and CDNGlobal edge network (US entity)
Stripe, Inc.Payment processing and invoicingUS / EU (Stripe Payments Europe)
Resend (Plus Five Five, Inc.)Transactional email deliveryUS
Anthropic, PBCAI-generated summaries (aggregated metrics only — never raw personal data; contractually excluded from model training)US
Google LLCGoogle Analytics data access — only when the customer connects their own GA accountUS / EU
Cloudflare, Inc.Bot protection (Turnstile) on signup formsGlobal (US entity)

7. Signature

This DPA applies automatically to every customer as part of the Terms of Service. If your organisation requires a countersigned copy, email support@probecast.io and we will return a signed PDF of this document.