Skip to content

Data Processing Agreement

Version dpa-v3 · Effective 15 September 2026. Ropely, Inc., Delaware, United States.

This is not an executed DPA until you and Ropely sign a copy. Using the service to send merchant-customer data still applies these processor terms.

1. Status

This Data Processing Agreement (DPA) is Ropely's processor terms for merchant-customer personal data. It applies when you use the service to send that data. It is not a separately countersigned paper unless we both sign a copy. Account email and name stay controller data of Ropely as described in the Privacy Policy.

2. Roles and instructions

You are the controller. Ropely is the processor. We will process merchant customer data only to provide the service, on your documented instructions in the product (connect a source, upload a snapshot, send access events, dismiss or export a finding), and as required by law. If an instruction appears unlawful we will tell you.

3. Subject matter and duration

Subject matter: compare purchase evidence with granted credits or allowance and retain the evidence trail. Duration: the life of your workspace plus the retention period in the Privacy Policy. Nature: hosting, matching, display, and export. Purpose: your commercial operations. Types of data: identifiers, commercial facts, purchased and granted units, and encrypted source payloads. Data subjects: your customers and payers.

4. Security

We apply technical and organizational measures appropriate to a read-only observability service: encryption in transit, encryption of stored credentials and source payloads, access control inside a workspace, host allowlisting for sessions, and no card data. Details are listed on /security.

5. Personnel and confidentiality

People who can access processor data are under confidentiality and may access it only to operate or secure the service.

6. Subprocessors

You authorize the subprocessors on /subprocessors. We will post additions on that page before production use. If you object on reasonable data-protection grounds you may stop using the service before the addition takes effect. We remain responsible for our subprocessors.

7. Transfers

If a confirmed subprocessor processes personal data outside the EEA, we will use a lawful transfer tool, including Standard Contractual Clauses where that is the vendor mechanism. Candidate US hosts (Fly.io, Cloudflare) are disclosed on the subprocessors page before they are confirmed.

8. Assistance, incidents, and deletion

We will assist you with data-subject requests, DPIAs, and consultations with a supervisory authority, to the extent the request concerns data we process for you. We will notify you without undue delay after becoming aware of a personal-data breach affecting that data.

After the service ends, we will delete or return processor data at your choice, except copies we must keep under applicable law. Deletion follows the lifecycle in the Privacy Policy.

9. Audit

On written request we will provide information reasonably needed to show these clauses are met, including the current security page. On-site audit is limited to once per year unless a breach requires more, and must not interrupt other customers.

10. Law

This DPA is governed by the laws of the State of Delaware. EU and UK data-protection law still applies to personal data of people in those places. This DPA prevails over the Terms where they conflict on processor issues.

Data Processing Agreement | Ropely