Data Processing Agreement
Last updated: August 17, 2026 · Forms part of the Terms of Service
1. Who is who
This agreement applies where you use Ploxir in the course of business and, in doing so, Ploxir processes personal data on your behalf. It supplements the Terms of Service and takes precedence over them on the subject of data protection.
- You are the controller. You decide which platforms to connect and why, and you are responsible for having a lawful basis to collect the personal data those platforms hold.
- Ploxir is the processor. Ploxir processes that data only to provide the service, and only on your documented instructions — of which your configuration of the product is the primary one.
- For your own account data — your name, email, and billing details — Ploxir is the controller, and the Privacy Policy governs instead.
No signature is required. This agreement is incorporated automatically when you use Ploxir for business purposes. If your organisation needs a countersigned copy, email [email protected].
2. What is processed, and why
Subject matter and purpose. Retrieving metrics from the platforms you connect, and presenting them back to you in your dashboards.
Duration. For as long as your account exists, subject to the retention periods in section 6.
Categories of data subjects — the individuals whose data may reach Ploxir:
- Your customers, subscribers, buyers and donors, as recorded by the platforms you connect
- Visitors to your websites and apps, where you connect an analytics platform
- Any individual described in data you send to your own webhook endpoint
Categories of personal data. This depends on which platforms you connect. It can include:
- Identifiers — name and email address, where a connected billing or commerce platform exposes them (for example Stripe, Shopify, Chargebee and Paddle customer records)
- Transaction data — order, charge, refund, subscription and payout records, and the amounts and currencies attached to them
- Usage and technical data — pageview, session and event counts, and coarse attributes such as country, device type and referrer
- Anything you choose to send — fields you POST to your own webhook endpoint are stored as received
No special category data. Ploxir is not designed to process the special categories in Article 9, nor criminal-offence data under Article 10, and you should not configure it to do so.
No cardholder data. Card numbers never reach Ploxir. Payments are processed entirely by Stripe.
3. Ploxir’s obligations
- Only on your instructions. Ploxir processes personal data only to provide the service and only as instructed, unless required otherwise by law — in which case Ploxir will tell you before processing, unless the law forbids it.
- Confidentiality. Everyone authorised to access personal data is bound by a duty of confidentiality.
- Security. The measures in section 5 are implemented and maintained.
- Subprocessors. Engaged only under section 4.
- Assistance with data subject requests. The product provides self-service export and deletion, which will satisfy most requests directly. Where it does not, Ploxir will assist you.
- Assistance with Articles 32 to 36. Ploxir will help you with security, breach notification, and data protection impact assessments, taking into account the nature of the processing and the information available.
- Deletion or return. Per section 7.
- Information and audit. Per section 8.
4. Subprocessors
You give general authorisation for Ploxir to engage the subprocessors listed below. Each is bound by data protection obligations no less protective than those in this agreement, and Ploxir remains fully liable to you for their performance.
- OVHcloud (Canada) — application and database hosting. Holds everything: account records, business and source configuration, encrypted credentials and retrieved metric data.
- Cloudflare — DNS, TLS termination, and R2 object storage for encrypted off-site database backups.
- Resend — transactional email (sign-in, verification, alerts). Holds recipient addresses and message contents.
- Stripe — subscription billing for paid plans. Holds your payment details; Ploxir never receives a card number.
- Sentry — error monitoring. Holds stack traces and technical metadata; credentials are scrubbed before an error is recorded.
The current list is maintained at /docs/security. Ploxir will give at least 30 days’ notice before adding or replacing a subprocessor. If you reasonably object on data protection grounds within that period, you may terminate the affected service without penalty for the remainder of the paid term.
The platforms you connect are not subprocessors. They are independent controllers you already have a relationship with. Ploxir reads from them at your instruction; your agreement with each of them governs their own processing.
5. Security measures (Article 32)
These are implemented, not aspirational. The control-by-control detail is in Ploxir’s CAIQ v4.1 self-assessment.
- Encryption at rest — credentials for connected platforms are encrypted with AES-256-GCM. Keys are versioned and held outside the database, so a copy of the database decrypts nothing.
- Encryption in transit — TLS 1.2 or higher; TLS 1.0 and 1.1 are refused.
- Access control — least-privilege roles (Owner, Admin, Editor, Viewer) enforced server-side on every change, with tenant isolation re-verified on every request.
- Authentication — passwords hashed with bcrypt; optional multi-factor authentication with single-use backup codes; sessions revoked within five minutes of a credential change.
- Least privilege toward platforms — read-only scopes are requested wherever a platform offers them.
- Audit logging — security-sensitive actions are recorded with actor, target, time and source address, and the record is never trimmed.
- Resilience — nightly integrity-verified backups, replicated off-site, with a rehearsed restore procedure.
- Segregation — production data is never used in development or testing.
- Vulnerability disclosure — a published policy at /.well-known/security.txt (RFC 9116).
6. Retention
Retention runs automatically, not on request:
- Cached platform responses — 7 days
- Processed provider events — 180 days
- Daily metric history — 400 days
- Transaction records from connected platforms — kept while the account exists, as they are the historical record your dashboards are built from
- Backups — 14 days locally, 30 days off-site, after which they age out automatically
7. Deletion and return
You can export your data at any time from the product, in JSON, without asking.
Deleting a connected source removes it and its data. Deleting your account schedules permanent deletion after a 7-day grace period, during which you can cancel; after that it cascades to everything beneath it. Copies present in backups age out on the schedule in section 6 and are not separately extracted, which is a limitation of holding restorable backups at all.
8. Audit and information rights
On written request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach affecting your data, Ploxir will provide the information reasonably necessary to demonstrate compliance with this agreement — including the current CAIQ self-assessment and answers to a security questionnaire.
Where that is genuinely insufficient for your obligations, an on-site or remote audit may be conducted on 30 days’ written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost.
9. Personal data breaches
Ploxir will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, so that you can meet your own 72-hour obligation under Article 33. The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed.
Where the full picture is not yet available, Ploxir will notify with what is known and supplement it as the investigation proceeds, rather than delaying the first notification until everything is confirmed.
10. International transfers
Application data is hosted in Canada, which benefits from a European Commission adequacy decision for commercial organisations, so transfers there do not require additional safeguards.
Where a subprocessor processes personal data outside the EEA or the UK without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses (Module Three, processor to subprocessor), together with the UK International Data Transfer Addendum where UK data is involved, and subject to a transfer risk assessment.
11. Your obligations
- You warrant that you have a lawful basis for the personal data held by the platforms you connect, and that any required notice or consent is in place.
- You are responsible for who you invite into your workspace and the role you assign them.
- You must not use Ploxir to process special category or criminal-offence data.
- Your instructions must not require Ploxir to act unlawfully. Ploxir will tell you if, in its opinion, an instruction infringes data protection law.
12. Liability, term and changes
This agreement takes effect when you begin using Ploxir for business purposes and continues until your account is deleted and the retention periods in section 6 have elapsed. Sections 6, 7 and 9 survive termination.
Liability under this agreement is subject to the limitations in the Terms of Service, except where those limitations are not permitted by data protection law.
Material changes will be announced at least 30 days in advance to the email on the account. Continued use after that constitutes acceptance.
13. Contact
Data protection questions: [email protected]. Security reports: [email protected] (see the disclosure policy).
