Data Processing Agreement (DPA)
Effective Date: 2026-07-12 | Last Updated: 2026-07-12 | Version 1.0
This Data Processing Agreement ("DPA") forms part of the agreement between Northpunch Media Group Limited, operating as Klarvyn ("Klarvyn", "we", "us", or "Processor") and the customer ("Customer" or "Controller") that has entered into a subscription or service agreement to use Klarvyn's services (the "Services"). This DPA governs the processing of personal data by Klarvyn on behalf of Customer in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable data protection laws.
By using the Services, Customer accepts and agrees to be bound by this DPA in addition to Klarvyn's Terms and Conditions and Privacy Policy.
1. Definitions
Terms used in this DPA have the meanings given in the GDPR, including:
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Klarvyn on behalf of Customer.
- "Data Subject" means the individual to whom the Personal Data relates (typically Customer's website visitors, leads, and customers).
- "Controller" means Customer, who determines the purposes and means of processing.
- "Processor" means Klarvyn, who processes Personal Data on behalf of Customer.
- "Sub-Processor" means any third party engaged by Klarvyn to process Personal Data on behalf of Customer.
- "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the European Commission-approved contractual clauses for the transfer of personal data to third countries.
2. Roles and Responsibilities
2.1 Customer as Controller
Customer acts as the Controller of Personal Data processed through the Services. Customer is responsible for:
- Ensuring a lawful basis for processing Personal Data under the GDPR
- Obtaining any required consents from Data Subjects (including cookie consent for website visitors)
- Providing appropriate privacy notices to Data Subjects
- Ensuring the accuracy of the data provided to Klarvyn
- Responding to Data Subject requests as the primary point of contact
- Determining retention periods appropriate for their business and communicating them to Klarvyn
2.2 Klarvyn as Processor
Klarvyn acts as the Processor and will:
- Process Personal Data only on documented instructions from Customer, including those set out in this DPA, the Terms and Conditions, and the Services configuration
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Section 6)
- Assist Customer in fulfilling its obligations under GDPR, including responding to Data Subject requests
- Notify Customer of any Personal Data Breach without undue delay
- Delete or return Personal Data at the end of the service agreement (subject to legal retention requirements)
- Make available all information necessary to demonstrate compliance with this DPA
3. Subject Matter and Duration
3.1 Subject Matter
The processing under this DPA relates to the provision of marketing attribution, analytics, and conversion tracking services by Klarvyn to Customer, including:
- First-party tracking of website visitors on Customer's websites
- Multi-touch attribution across marketing channels
- Server-side conversion event forwarding to advertising platforms authorized by Customer (Conversions API integrations)
- Integration with third-party services (CRMs, e-commerce platforms, ad networks) as configured by Customer
- Reporting, dashboards, and analytics generated from the above
3.2 Duration
This DPA remains in effect for the duration of Customer's use of the Services and until all Personal Data has been deleted or returned in accordance with Section 10.
4. Nature and Purpose of Processing
Klarvyn processes Personal Data solely for the following purposes:
- Providing the Services to Customer as described in the applicable service agreement
- Sending server-side conversion events to advertising platforms authorized by Customer (Meta Conversions API, Google Enhanced Conversions, TikTok Events API, LinkedIn Conversions API, Reddit Conversion API, and similar)
- Generating attribution reports, analytics, and dashboards for Customer
- Providing customer support and troubleshooting
- Ensuring security, preventing fraud, and complying with legal obligations
- Improving service performance and reliability through aggregated, anonymized analysis
Klarvyn does not:
- Sell Personal Data to third parties
- Use Personal Data for Klarvyn's own marketing purposes beyond aggregated benchmarks
- Combine Customer's data with data from other Customers
- Use Personal Data to serve advertisements
5. Categories of Data Subjects and Personal Data
5.1 Categories of Data Subjects
- Customer's website visitors
- Leads and prospects captured through Customer's marketing funnels
- Customers and purchasers of Customer's products or services
- Contacts imported or synced from Customer's connected integrations (CRM, e-commerce, etc.)
5.2 Categories of Personal Data
- Identifiers: IP addresses, cookie IDs, visitor IDs, session IDs, device identifiers
- Contact information (when provided by Data Subject or synced from Customer's systems): email addresses (typically stored hashed with SHA-256), first and last names, phone numbers (stored hashed), physical addresses
- Behavioral data: page views, click paths, ad interactions, form submissions, event data
- Transaction data: purchase amounts, order IDs, product information, currency
- Technical data: user agent strings, referrer URLs, geographic location (country, region, city — derived from IP)
- Advertising identifiers: Facebook Click ID (fbclid), Google Click ID (gclid), TikTok Click ID (ttclid), Reddit Click ID, LinkedIn Click ID, and similar platform identifiers
- Attribution data: UTM parameters, campaign identifiers, touchpoint sequences
Klarvyn does not intentionally process special categories of Personal Data (as defined in GDPR Article 9) such as health data, biometric data, or data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation.
6. Security Measures
Klarvyn implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
6.1 Encryption
- Data in transit: All data transmitted between Data Subjects, Customer, Klarvyn, and Klarvyn's Sub-Processors is encrypted using TLS 1.2 or higher
- Data at rest: All Personal Data stored in Klarvyn's databases is encrypted using industry-standard encryption (AES-256)
- Secrets and credentials: OAuth tokens, API keys, and other sensitive credentials are stored in encrypted vaults with restricted access
- Sensitive contact identifiers: Email addresses and phone numbers are hashed using SHA-256 for storage and cross-platform matching
6.2 Access Controls
- Role-Based Access Control (RBAC) limiting data access based on job function
- Multi-Factor Authentication (MFA) required for all production system access
- Principle of least privilege applied to employees and systems
- Unique credentials for all users; no shared accounts
6.3 Infrastructure Security
- Production environments logically isolated from development and staging
- Firewalls, intrusion detection, and DDoS protection at the network layer
- Regular vulnerability scanning and patch management
- Continuous security monitoring and alerting
6.4 Organizational Measures
- Confidentiality obligations for all employees, contractors, and Sub-Processors
- Security awareness training for personnel with access to Personal Data
- Documented incident response plan
- Regular review and update of security policies
7. Sub-Processors
7.1 General Authorization
Customer provides general authorization for Klarvyn to engage the Sub-Processors listed in Section 7.3, provided that Klarvyn:
- Enters into a written contract with each Sub-Processor imposing data protection obligations at least equivalent to those in this DPA
- Remains fully liable for the acts and omissions of its Sub-Processors
- Notifies Customer of any intended additions or replacements of Sub-Processors at least 30 days in advance
7.2 Right to Object
Customer may reasonably object to Klarvyn's use of a new Sub-Processor within 30 days of notification. If Customer objects on legitimate data protection grounds, Klarvyn will use commercially reasonable efforts to address the objection. If no resolution can be reached, Customer may terminate the affected Services with 30 days' notice.
7.3 Current Sub-Processors
The following Sub-Processors are engaged as of the effective date of this DPA:
Infrastructure and Hosting
| Sub-Processor | Purpose | Location |
|---|---|---|
| Tiger Data (Timescale, Inc.) | Database hosting (TimescaleDB) | Ireland (EU) |
| Northflank Limited | Application hosting and container orchestration | EU regions |
| Cloudflare, Inc. | Content delivery network, DDoS protection, edge security | Global (EU edge for EU traffic) |
Advertising Platforms (activated only when Customer connects the integration)
| Sub-Processor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. | Conversions API event forwarding | United States |
| Google LLC | Google Ads Enhanced Conversions | United States |
| TikTok Inc. | TikTok Events API | United States |
| LinkedIn Corporation | LinkedIn Conversions API | United States |
| Reddit, Inc. | Reddit Conversion API | United States |
| Adform A/S | Adform Conversion API | European Union |
Business Operations
| Sub-Processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing (billing only, not visitor data) | United States (with EU processing) |
| Sentry (Functional Software, Inc.) | Application error monitoring (with PII scrubbing) | United States |
| Anthropic PBC | AI-powered features (aggregated queries only, no Personal Data of Data Subjects) | United States |
An up-to-date list of Sub-Processors is available upon request by contacting support@klarvyn.com.
8. International Data Transfers
8.1 Primary Data Location
Personal Data processed by Klarvyn is primarily stored and processed within the European Union:
- Database: Ireland (Tiger Data EU-WEST-1)
- Application processing: EU regions (Northflank)
8.2 Transfers Outside the EEA
Where Personal Data is transferred to Sub-Processors located outside the European Economic Area (such as advertising platforms for Conversions API integrations authorized by Customer), Klarvyn ensures adequate protection through:
- Standard Contractual Clauses (SCCs): Klarvyn has entered into SCCs with all non-EEA Sub-Processors
- EU-U.S. Data Privacy Framework: Where applicable, Klarvyn relies on Sub-Processors' certification under the DPF
- Adequacy decisions: Klarvyn transfers data to countries recognized by the European Commission as providing adequate data protection where applicable
- Transfer Impact Assessments: Klarvyn conducts assessments to verify that the legal framework in recipient countries provides adequate protection
8.3 Customer-Authorized Transfers
Transfers to advertising platforms (Meta, Google, TikTok, LinkedIn, Reddit) occur only when Customer has explicitly connected the corresponding integration. Customer authorizes such transfers by activating the integration through Klarvyn's Services.
9. Data Subject Rights
9.1 Klarvyn's Assistance
Klarvyn will assist Customer, insofar as this is possible, to fulfill Customer's obligation to respond to requests for exercising Data Subject rights under the GDPR, including:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure / right to be forgotten (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
9.2 Response Process
Customer or Data Subjects may submit requests by emailing privacy@klarvyn.com. Klarvyn will:
- Acknowledge receipt within 2 business days
- Verify the identity of the requester as required
- Complete the requested action within 30 days per GDPR Article 12(3)
- Provide written confirmation upon completion
- Extend the response period by up to 60 additional days for complex requests, notifying the requester within the initial 30 days
For deletion requests specifically:
- Klarvyn will delete or anonymize the requested Personal Data from active production systems
- Encrypted backups containing residual data may retain the data for up to 90 days before automatic expiration
- Deletion is coordinated with Customer where the request relates to Customer's Data Subjects
9.3 Customer Responsibility
Customer remains responsible for:
- Verifying the identity of the Data Subject making the request
- Determining whether the request is valid under applicable law
- Forwarding valid requests to Klarvyn with sufficient information to process them
- Communicating the outcome to the Data Subject
Data Subjects may also contact Klarvyn directly at privacy@klarvyn.com, in which case Klarvyn will notify Customer of the request and coordinate response.
10. Data Retention and Deletion
10.1 Retention Approach
Klarvyn retains Personal Data for as long as necessary to provide the Services to Customer, in accordance with GDPR data minimization principles.
During active subscription:
Klarvyn retains Personal Data associated with Customer's workspace to enable the ongoing provision of attribution, analytics, and reporting services. This includes:
- Contact records and identity information
- Contact-level attribution data (channel, campaign, revenue attribution)
- Events associated with Customer's tracking
- Visitor identity data
- Ad click data
- Aggregated and anonymized analytics
Customer determines the appropriate retention period for their own business needs and Data Subjects' expectations. If Customer requires specific retention periods for particular categories of data, Customer may request custom arrangements by contacting privacy@klarvyn.com.
Individual Data Subject deletion:
Data Subjects or Customer may request deletion of specific Personal Data at any time by contacting privacy@klarvyn.com. Klarvyn will:
- Acknowledge receipt within 2 business days
- Complete deletion within 30 days of verified request
- Provide written confirmation upon completion
- Delete data from active production systems immediately upon processing the request
Backups:
Encrypted backups containing residual data may retain deleted Personal Data for up to 90 days after deletion from production systems, after which backups are automatically expired.
10.2 Retention Upon Subscription Termination
When Customer terminates their Klarvyn subscription:
- Recovery period (60 days): All Customer data is retained. Customer may reactivate their subscription without data loss. This period allows for business continuity in case of accidental cancellation, billing disputes, or subscription changes.
- After 60 days: Klarvyn will delete all Personal Data associated with Customer's workspace from active production systems within 30 days, including:
- Contact records
- Attribution data
- Events and visitor identity data
- Ad click records
- Workspace configuration and integration credentials
- Retained after termination:
- Billing records (up to 7 years, as required by tax and financial regulations)
- Aggregated, anonymized platform analytics (cannot identify individuals)
- Data subject to specific legal hold obligations
Customer may request expedited deletion during the recovery period by contacting privacy@klarvyn.com.
10.3 Third-Party Integrations
- Google user data is deleted within 30 days of account disconnection or upon Customer's request, whichever comes first, in accordance with the Google API Services User Data Policy
- Meta (Facebook) user data is deleted within 30 days of account disconnection or upon Customer's request
- Other ad platform integrations (TikTok, LinkedIn, Reddit, Adform) follow the same 30-day deletion policy upon disconnection
10.4 Return or Destruction of Personal Data
Upon termination of the Agreement and completion of the recovery period, or upon Customer's earlier written request, Klarvyn shall:
- Delete all Personal Data from active systems within 30 days
- Certify deletion completion in writing upon request
- Delete residual copies from encrypted backups within 90 days of primary deletion
- Return Personal Data to Customer in machine-readable format if requested in writing before termination
Customer's right to export data via the Klarvyn dashboard remains available during the subscription and the recovery period.
11. Personal Data Breach Notification
11.1 Klarvyn's Obligations
In the event of a Personal Data Breach affecting Personal Data processed on behalf of Customer, Klarvyn will:
- Notify Customer without undue delay, and in any event within 72 hours of becoming aware of the breach
- Provide details including:
- The nature of the breach, including categories and approximate number of Data Subjects and Personal Data records affected
- The name and contact details of Klarvyn's Data Protection contact
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
- Cooperate with Customer to investigate the breach and comply with Customer's regulatory notification obligations
- Document all Personal Data Breaches, including facts, effects, and remedial actions taken
11.2 Customer's Obligations
Customer is responsible for:
- Determining whether to notify supervisory authorities and Data Subjects
- Complying with its own regulatory notification obligations under GDPR Articles 33 and 34
- Public communications about the breach
12. Audit Rights
12.1 Right to Audit
Klarvyn will, upon reasonable prior written notice (at least 30 days), make available to Customer information necessary to demonstrate compliance with this DPA, including:
- Copies of relevant security certifications when available
- Written responses to reasonable data protection questionnaires
- Summary of policies, procedures, and controls
12.2 On-Site Audits
For Customers subject to specific regulatory requirements, on-site audits may be conducted no more than once per year, subject to:
- Advance written notice of at least 60 days
- Reasonable scope and duration
- Confidentiality obligations
- Conducted at Customer's expense
- Audits by qualified independent third parties, not competitors of Klarvyn
Klarvyn may make available third-party audit reports or attestations in lieu of on-site audits where appropriate.
13. Governing Law and Jurisdiction
This DPA is governed by the laws of Cyprus, without regard to conflict of law principles. Any disputes arising out of or in connection with this DPA will be subject to the exclusive jurisdiction of the courts of Limassol, Cyprus, without prejudice to any mandatory legal provisions.
Where the GDPR or UK GDPR applies, this DPA will be interpreted in accordance with those regulations.
14. Modifications to This DPA
Klarvyn may update this DPA from time to time to reflect changes in law, Sub-Processors, or business practices. Material changes will be:
- Communicated to Customer at least 30 days in advance via email or through the Klarvyn platform
- Reflected in the "Last Updated" date at the top of this document
Continued use of the Services after material changes constitutes acceptance of the updated DPA. Customer may terminate the Services in accordance with the Terms and Conditions if it does not accept material changes.
15. Contact Information
For questions, requests, or concerns regarding this DPA, please contact:
Northpunch Media Group Limited
Limassol, Cyprus
- General privacy inquiries: privacy@klarvyn.com
- Data Subject requests (access, deletion, correction): privacy@klarvyn.com
- Sub-Processor list requests: support@klarvyn.com
- Security incidents: privacy@klarvyn.com
16. Order of Precedence
In the event of a conflict between this DPA and any other agreement between Klarvyn and Customer (including the Terms and Conditions), this DPA will prevail with respect to matters concerning the processing of Personal Data.
This DPA is designed to satisfy the requirements of GDPR Article 28. Customer is responsible for reviewing this DPA to determine whether it meets its specific compliance needs. For enterprise or regulated industries requiring negotiated terms, please contact privacy@klarvyn.com.