← Back to DLV Insight

Data Processing Agreement

Version 1.0 · Effective 7 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between DLV Insight OÜ ("Processor", "we") and the customer identified in the account ("Controller", "you"). It governs our processing of personal data on your behalf and is concluded under Article 28(3) GDPR. No signature is required: it takes effect automatically when you accept the Terms of Service. If your organisation requires a countersigned copy, write to privacy@dlvinsight.com.

1. Definitions and scope

"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "supervisory authority" and "personal data breach" have the meanings given in Article 4 GDPR. "Applicable Data Protection Law" means the GDPR, the UK GDPR and Data Protection Act 2018 where relevant, and any other data-protection law applicable to a party.

This DPA applies where and only where we process personal data on your behalf in the course of providing the Service. It does not apply to personal data for which we are the controller — your account, billing and technical data — which is governed by our Privacy Policy.

Where this DPA conflicts with the Terms of Service on a matter of data protection, this DPA prevails.

2. Roles of the parties

You are the controller of the personal data contained in the sales-channel data you instruct us to retrieve and analyse — principally end-customer data received from Amazon and other platforms you connect. We are your processor in respect of that data.

You warrant that you have a lawful basis for the processing you instruct, that you have provided any notice and obtained any consent required from your end customers, and that your instructions do not breach Applicable Data Protection Law or the terms of the platforms you connect.

3. Subject matter and details of processing

The subject matter, duration, nature and purpose of the processing, the categories of data subject and the types of personal data are set out in Annex I. Annex I forms the documented scope of processing required by Article 28(3).

4. Processing on documented instructions

  1. We process personal data only on your documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law to which we are subject. In that case we will inform you of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  2. Your instructions are: (a) this DPA; (b) the Terms of Service; (c) your configuration of and use of the Service, including which channels you connect and which features you enable; and (d) any further written instruction you give us.
  3. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law. We may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
  4. We will not process the personal data for our own purposes, and specifically will not sell it, use it for advertising, disclose it to third parties other than the sub-processors listed in Annex III, use it to train machine-learning or artificial-intelligence models, or use it to build or improve any product other than the Service provided to you.

5. Confidentiality

We ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is limited to personnel who need it to provide, secure or support the Service.

6. Security

We implement the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to data subjects, as required by Article 32 GDPR.

We may update those measures over time, provided the level of protection is not reduced. Annex II reflects the measures in place as at the effective date.

7. Sub-processors

  1. You give us general written authorisation to engage sub-processors, on the terms of this clause.
  2. The sub-processors engaged as at the effective date are listed in Annex III.
  3. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor, by email to your account address or by notice in the Service, so that you have the opportunity to object.
  4. You may object on reasonable grounds relating to data protection within that period. We will work with you in good faith to resolve the objection. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused period.
  5. We impose on each sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA. We remain fully liable to you for the performance of each sub-processor's obligations.

8. International transfers

Personal data processed under this DPA is stored and processed within the European Union, except for the transfers identified in Annex III. Where personal data is transferred to a third country without an adequacy decision, that transfer is governed by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference and completed with the information in Annexes I to III.

Where the SCCs apply between you and us, Module Two (controller to processor) applies; where they apply between us and a sub-processor, Module Three (processor to processor) applies. Clause 7 (docking) applies. For Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in clause 7 above. For Clause 11, the optional independent-dispute-resolution wording does not apply. For Clause 17, the governing law is that of Estonia. For Clause 18(b), the forum is the courts of Estonia.

We will provide copies of the relevant clauses and any transfer impact assessment on request.

9. Assistance with data subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

The Service provides export and deletion functions that allow you to respond to most requests yourself. Where you need our direct assistance, we act without undue delay and in any event within a period that allows you to meet your own statutory deadline.

If we receive a request directly from one of your end customers, we will not respond to it ourselves except to acknowledge receipt and redirect. We will forward it to you without undue delay.

10. Assistance with your other obligations

Taking into account the nature of processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR — security of processing, breach notification and communication, data protection impact assessments, and prior consultation with a supervisory authority.

11. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe, to the extent known and as it becomes available: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for further information.

We will not delay an initial notification in order to complete our investigation, and we will provide further information in phases as it becomes available. We do not notify your end customers or a supervisory authority on your behalf unless you instruct us to do so.

12. Audit and information

  1. We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
  2. In the first instance we will respond to reasonable written information requests, including security questionnaires, and provide documentation of our technical and organisational measures.
  3. Where that is not sufficient to demonstrate compliance, you may conduct an on-site or remote audit, on at least 30 days' written notice, no more than once in any 12-month period, during business hours, subject to confidentiality undertakings, and conducted so as to minimise disruption to the Service. This frequency limit does not apply where an audit is required by a supervisory authority or follows a personal data breach.
  4. Each party bears its own costs, save that we may charge a reasonable fee for audits that go materially beyond what is necessary to demonstrate compliance.
  5. An auditor you mandate must not be a competitor of ours.

13. Deletion and return of data

At your choice, we delete or return all personal data processed on your behalf after the end of the provision of services, and delete existing copies, unless Union or Member State law requires storage of the personal data.

In practice: you may export your data at any time while your subscription is active. On termination we retain it for 90 days so you can reactivate or export, and then delete it. You may instruct us to delete it sooner, and we will do so within 30 days of that instruction. Data in backups is deleted as those backups expire on their normal rolling cycle, within 35 days; until then it remains protected by the measures in Annex II and is not processed for any other purpose.

We retain records we are legally required to keep — in particular accounting records under Estonian law — for the statutory period, and only for that purpose.

14. Amazon Selling Partner data

Where the personal data originates from the Amazon Selling Partner API, both parties additionally comply with Amazon's Data Protection Policy and Acceptable Use Policy. In particular, and notwithstanding any broader instruction from you:

This clause survives any conflicting instruction and reflects obligations we owe to Amazon independently of this DPA.

15. Liability and duration

This DPA takes effect when you accept the Terms of Service and continues for as long as we process personal data on your behalf. Clauses 5, 12, 13 and 14 survive termination.

Liability under this DPA is subject to the limitations in the Terms of Service, except that nothing in either document limits or excludes either party's liability to a data subject under Article 82 GDPR, or any liability that cannot be limited under Applicable Data Protection Law.

Annex I — Details of the processing

A. List of parties

Data exporter (controller): the customer identified in the DLV Insight account, whose contact details are those held in that account. Activities relevant to the transfer: use of DLV Insight to analyse the profitability of its e-commerce business.

Data importer (processor): DLV Insight OÜ (registry code 17299306), Ruunaoja tn 3, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia. Contact: privacy@dlvinsight.com. Activities relevant to the transfer: provision of a profit-analytics software service.

B. Categories of data subject

C. Categories of personal data

CategoryDetail
End-customer identifiersBuyer email address, buyer name, buyer telephone number, platform order and buyer identifiers. Pseudonymised on ingestion; plaintext deleted within 30 days of delivery.
End-customer delivery dataRecipient name, delivery and billing address, city, postal code, country. Reduced to region or country within 30 days of delivery.
Transaction dataOrder contents, quantities, prices, currency, refunds, returns and related financial records, linked to a pseudonymous buyer identifier.
Supplier contact dataContact name, email, telephone and address, where entered by the Controller.

Special categories of data: none. The Service is not designed to process data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation, and the Controller must not instruct such processing. Data relating to criminal convictions and offences is likewise out of scope.

D. Nature and purpose of the processing

Automated collection from connected sales channels via API; storage in a database hosted in the European Union; aggregation, calculation and analysis to produce profit-and-loss, cost, advertising, inventory, forecasting and lifetime-value reporting; presentation of that reporting to authorised users of the Controller; export at the Controller's request; deletion in accordance with clause 13.

E. Frequency of the transfer

Continuous, on an automated schedule, for as long as a sales channel remains connected.

F. Duration of the processing

For the term of the subscription, plus the retention periods in section 9 of the Privacy Policy and clause 13 of this DPA.

G. Competent supervisory authority

For the purposes of Clause 13 SCCs: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia.

Annex II — Technical and organisational measures

The measures below are in place as at the effective date. They may be updated provided the level of protection is not reduced.

AreaMeasure
PseudonymisationEnd-customer direct identifiers are converted to an irreversible keyed hash at the point of ingestion. Analytics operate on the pseudonymous identifier. The hashing key is held in a managed secret store, logically separated from the database.
Encryption in transitTLS 1.2 or higher on all external connections; HTTPS enforced; encrypted connections to the database.
Encryption at restAES-256 across database, object storage and backups.
Credential protectionThird-party OAuth refresh tokens and API credentials are additionally encrypted at the application layer with AES-256-GCM before storage. No credential is stored in the source repository.
Secret managementAll keys, credentials and connection strings are held in a managed secret store with access logging and versioned rotation.
Tenant isolationEvery record is scoped to a single organisation. Isolation is enforced at the database layer through row-level security policies and mandatory organisation-scoped queries, not by application logic alone.
Access controlRole-based permissions with separate administrator and read-only roles, and a graduated permission ladder for write operations that reach external platforms. Multi-factor authentication is available to all users.
Least privilegeService accounts are scoped to the minimum permissions necessary. Production access is limited to personnel who require it and is individually attributable.
Logging and monitoringApplication and infrastructure events are logged to a managed logging service with defined retention. Alerting is configured on error-rate, queue-health and resource thresholds.
Data minimisationEnd-customer personal information is excluded from application logs by design and is not exposed through the Service's API or agent interfaces.
Resilience and recoveryManaged database with automated backups and point-in-time recovery. Infrastructure is reproducible from version-controlled configuration.
Change managementAll changes pass through version control with code review, automated type checking, linting and an automated test suite before deployment.
Vulnerability managementAutomated dependency scanning with prioritised patching of security advisories. Managed platform components receive vendor security updates.
PersonnelEveryone with access is bound by confidentiality obligations that survive the end of their engagement.
Sub-processor governanceEach sub-processor is bound by a written contract imposing obligations no less protective than this DPA, with transfer safeguards documented in Annex III.

Annex III — Authorised sub-processors

As at the effective date:

Sub-processorProcessingLocation of processingTransfer safeguard
Google Cloud EMEA Ltd
Ireland
Application hosting, managed database, object storage, secret management, logging European Union — europe-west1 (Belgium) No transfer outside the EEA for storage. SCCs cover any support access from outside the EEA.
Clerk.com Inc.
United States
Authentication, session and organisation management for the Controller's users United States Standard Contractual Clauses, Module Three, with supplementary technical measures. Processes user account data only; no end-customer data.
Stripe Payments Europe Ltd
Ireland
Subscription billing and payment processing European Union, with onward transfer to Stripe, Inc. (United States) Standard Contractual Clauses for the onward transfer. Processes Controller billing data only; no end-customer data.

Neither Clerk nor Stripe processes end-customer personal data. End-customer data remains within the European Union at all times.

Questions about this DPA, requests for a countersigned copy, copies of the Standard Contractual Clauses, or security documentation: privacy@dlvinsight.com.