Graytower legal

Data Processing Agreement

Additional terms for personal data Graytower processes on a customer’s behalf.

Effective and last updated: September 25, 2026

1. Scope and roles

This Data Processing Agreement (“DPA”) supplements the Terms of Service between the customer (“Customer”) and Graytower. It applies only when Graytower processes personal data submitted or collected through a Customer Website or customer-directed product feature (“Customer Personal Data”) on Customer’s behalf. Customer is the controller, or a processor authorized by a controller, and Graytower is its processor or subprocessor. Graytower is separately responsible for account, billing, security, and support data as explained in the Privacy Policy.

2. Processing instructions

Customer instructs Graytower to process Customer Personal Data to provide the configured service, including collection, storage, reporting, Stripe revenue matching, Explore analysis, opportunities, experiments, support, security, retention, and deletion. Graytower will process that data only on these documented instructions and later lawful written instructions consistent with the service, unless applicable law requires otherwise. If legally permitted, Graytower will inform Customer before processing required by law. If an instruction appears to violate applicable data protection law, Graytower will notify Customer.

Customer determines the categories of data it sends, its lawful basis, notices, tracking choices, and responses to its visitors. Customer must not submit categories of data the service is not designed to handle.

3. Confidentiality and security

Graytower will limit access to authorized personnel who are subject to confidentiality duties and will use appropriate technical and organizational measures. Current measures include access controls, Workspace and Website scoping, protected credentials, rate limits, restricted provider access, and deletion workflows. We will review measures as the service changes and provide further information reasonably needed to assess them.

4. Subprocessors

Customer gives general authorization for the service providers described on the Subprocessors page to process Customer Personal Data for the listed purposes. Graytower will require relevant providers to protect data under written terms appropriate to their service and will remain responsible for their processing as applicable law requires. Before adding a material new subprocessor that handles Customer Personal Data, Graytower will notify Customer through an account email or the service and provide a reasonable opportunity to object on data protection grounds. If an objection cannot reasonably be resolved, the parties will discuss ending the affected service.

5. Assistance and incidents

Taking into account the nature of processing and information available to us, Graytower will reasonably assist Customer with access, correction, deletion, and other data subject requests; security and breach obligations; and data protection assessments or regulator inquiries where required by law. A visitor to a Customer Website should normally direct a request to that Website’s operator. Graytower will inform Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, provide available details, and cooperate on remediation. Customer remains responsible for its own notices to individuals and authorities.

6. Retention and end of service

Customer’s plan controls analytics retention periods. Customer may initiate Website or Workspace deletion in the service; Graytower’s deletion workflow removes related operational and analytics records, subject to legal retention requirements and provider backup cycles. At the end of service, Customer may request an available export before deletion. Graytower will delete or return remaining Customer Personal Data in accordance with Customer’s reasonable choice, unless law requires retention. Our Privacy Policy explains the distinct retention of Graytower’s own controller data.

7. Information and audit

Graytower will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Where required by applicable law, Graytower will allow a reasonable audit or inspection by Customer or an independent auditor under confidentiality and security conditions, coordinated to minimize disruption and avoid exposing other customers’ information.

8. International transfers

Customer Personal Data may be processed outside Customer’s country. The parties will use a valid transfer mechanism where one is required. This DPA does not itself incorporate EU or UK standard contractual clauses or select their modules. If those clauses are needed for a specific transfer, contact support@graytower.app so the parties can complete an appropriate transfer addendum before that transfer.

Processing details

  • Subject matter and duration: Customer Personal Data processed during the Customer’s use of Graytower and any lawful transition or deletion period.
  • People: visitors and users of Customer Websites, Customer’s own users or contacts, and people represented in connected payment data.
  • Data: event and page data, pseudonymous visitor and session identifiers, optional customer-supplied identity values, campaign and device information, Stripe payment and customer references, Product Profile content, prompts, and experiment information.
  • Operations: collection, organization, storage, analysis, matching, display, retrieval, disclosure to authorized providers, retention, and deletion.

Questions

Contact support@graytower.app about these documents or a privacy request.