Purpose
This Data Processing Agreement ("DPA") describes how PVSN, Inc. ("PVSN", the Data Processor) processes personal data on behalf of you, the customer (the Data Controller), in connection with your use of the PVSN dynamic pricing platform.
It reflects our commitments under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA) as amended by the CPRA. Where this DPA conflicts with our Terms of Service, this DPA controls for the subject matter of personal-data processing.
What personal data we process
From you (your authorized users): name, email, hashed password, IP address, session tokens.
From your customers (whom you upload): typically name, email, phone, customer ID, segment, purchase history, predicted purchase dates. We do NOT process special categories under GDPR Art. 9 by default.
How we process it
- Only on your documented instructions, including any transfers to a third country
- By personnel under appropriate confidentiality obligations
- With the technical and organizational measures described in our Security overview (TLS, encryption at rest, RBAC, MFA, audit logging, brute-force protection, 72-hour breach notification)
- For the duration of your subscription plus the retention periods below
Sub-processors
We use a small number of sub-processors, each contractually bound by their own data-protection obligations. The current list is published on our Security overview page (Stripe, Railway, Vercel, Anthropic, Google Workspace, Sentry, GitHub at time of writing). We give you 30 days' notice of any addition or change.
International transfers
To the extent any processing involves transferring personal data of EEA, UK, or Swiss data subjects outside their respective jurisdictions to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Decision 2021/914), the UK International Data Transfer Addendum, or the Swiss SCCs as applicable.
Retention and deletion
- Active account: personal data is retained for the duration of your subscription.
- After cancellation: 90-day soft-delete window during which you can restore your account; after that, irreversible deletion via foreign-key cascade.
- Backups: existing backups may continue to contain deleted data until they roll off the standard backup retention (typically 30 days after deletion).
- Audit logs: 90 days (longer on enterprise plans).
- Billing records: as required by applicable tax law (typically 7 years).
- You can request deletion or return of personal data at any time via security@pvsnapp.com — we fulfill within 30 days unless legally required to retain.
Data Subject requests
We assist you in fulfilling rights-of-access, rectification, and erasure requests via our /v1/gdpr/export/{customer_id} and /v1/gdpr/delete/{customer_id} API endpoints. These endpoints let you respond to your end customers' requests without involving our team.
Security incidents
We notify you without undue delay and within 72 hours of becoming aware of a confirmed Security Incident affecting your personal data, with available details, likely consequences, and measures taken or proposed. We maintain a written incident-response runbook covering detection, triage, containment, and customer notification.
CCPA — Service Provider commitment
For personal information of California residents processed on your behalf, PVSN acts as a "Service Provider" under the CCPA. We do not sell or share your data, do not retain it for purposes beyond providing the Service, and do not combine it with data from other sources except as permitted.
Audits
Once per year and with at least 30 days' notice, you may audit our compliance with this DPA, subject to reasonable confidentiality and security restrictions. Our most recent SOC 2 report (when issued) will satisfy your audit rights for the period it covers.
Counter-signed copy
The full, signable DPA — including all annexes (Standard Contractual Clauses for EEA/UK/Swiss transfers, technical and organizational measures, signature blocks) — is available on request. Email legal@pvsnapp.com and we'll send a counter-signed PDF you can file with your compliance team.
Related documents: Terms of Service, Privacy Policy, SLA, Security overview.