Data Processing Agreement
Last updated: August 17, 2026
When you collect email addresses and phone numbers through BetterPopup, you are the data controller and we are your processor. This agreement sets out how we handle that data on your behalf — what we process, who helps us, how we secure it, and what happens when you leave. It applies automatically to every customer; there is nothing to sign.
1. Scope and how this agreement applies
This Data Processing Agreement ("DPA") is entered into between Digitonica SRL ("BetterPopup", "we", the processor) and the customer identified on the BetterPopup account ("you", the controller). It forms part of our Terms of Service and applies whenever we process personal data on your behalf.
You do not need to sign anything. This DPA takes effect automatically when you accept the Terms of Service, and it applies to every customer. If your procurement or security review requires a countersigned copy on your own paper, email [email protected] and we will arrange it.
Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA prevails. Terms defined in the GDPR — controller, processor, personal data, processing, data subject, personal data breach, sub-processor and supervisory authority — carry the same meaning here. "Data Protection Law" means Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, applicable ePrivacy rules, and US state privacy laws, each as applicable.
2. Roles of the parties
You are the controller of the personal data collected through your popups — the email addresses, phone numbers, consent records and related visitor information described in Annex I. You decide what to collect, why, and on what legal basis, and you are responsible for the lawfulness of the instructions you give us.
We are your processor for that data. We process it only to provide the service to you and only on your documented instructions.
We act as an independent controller for the account, billing, support and product-usage data we hold about you as our customer. That processing is governed by our Privacy Policy, not by this DPA.
3. Our processing instructions
Your instructions to us are made up of the Terms of Service, this DPA, and the configuration choices you make in the product — the popups you publish, the fields you ask for, the audiences you target, the retention settings you choose, and the integrations you connect. Your use of the service in the ordinary way constitutes an instruction to process personal data accordingly.
We will:
- process personal data only on those instructions, including for transfers, unless required otherwise by EU or member-state law — in which case we will tell you before processing, unless the law forbids it on important grounds of public interest;
- immediately inform you if, in our opinion, an instruction infringes Data Protection Law;
- not sell personal data, not use it for our own purposes, and not use it to train machine-learning models.
4. Confidentiality
We ensure that every person authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality, is trained on their obligations, and has access limited to what their role genuinely requires.
5. Security of processing
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Art. 32 GDPR. Those measures are described in Annex II. We may update them as the service evolves, provided the level of protection is not reduced.
6. Sub-processors
You give us general authorisation to engage sub-processors to help deliver the service. The current list is in Annex III.
Before adding or replacing a sub-processor we will give you at least 30 days' notice by email to account owners. If you have a reasonable objection on data-protection grounds, tell us within that period and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
We impose data-protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. Assisting with data subject requests
The service gives you direct access to the personal data we hold for you: you can search, export and delete subscriber records from your dashboard at any time. In most cases this lets you answer access, correction, erasure and portability requests yourself without needing us.
Where a request cannot be handled through the product, we will provide reasonable assistance, taking into account the nature of the processing. If a data subject contacts us directly about data we process for you, we will not respond substantively — we will redirect them to you and, where we can identify you, tell you promptly.
8. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information — supplying details in phases where they are not all available at once. We will assist you in meeting your own obligations under Art. 33 and 34 GDPR. Our notification is not an acknowledgement of fault or liability.
9. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under Art. 35 and 36 GDPR. Annex I and Annex II, together with our Privacy Policy, are designed to supply most of the information such an assessment requires.
10. Return and deletion
You can export your subscriber data from the dashboard at any time while your account is open, and can delete individual records or your whole account yourself.
On termination we delete the personal data we process for you within 30 days, with encrypted backups purged on their normal rotation within a further 30 days. We retain data beyond that only where EU or member-state law requires it — for example accounting records — and in that case we keep it protected and process it only for the purpose that requires retention.
11. Audits and demonstrating compliance
We will make available the information reasonably necessary to demonstrate compliance with this DPA. You may request an audit no more than once in any 12-month period, on at least 30 days' written notice, at your cost, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. An audit may not extend to other customers' data or to our systems where access would compromise their security. Where a supervisory authority requires an audit, we will cooperate as the law directs.
12. International transfers
Where we transfer personal data outside the EU/EEA or the UK, we do so on the basis of an adequacy decision or, in its absence, the European Commission's Standard Contractual Clauses (Decision 2021/914) — Module Two (controller to processor) between you and us, and Module Three (processor to processor) between us and our sub-processors — together with the UK International Data Transfer Addendum where UK data is involved. By agreeing to this DPA, the parties are deemed to have signed those clauses, with Annex I and Annex II of this DPA supplying the corresponding annexes, and the governing law and forum being Romania. We apply supplementary measures including encryption in transit and at rest, and we will challenge unlawful government access requests where there is a reasonable basis to do so.
13. Your obligations as controller
You are responsible for:
- establishing a valid legal basis for the personal data you collect through your popups, and providing data subjects with the information Art. 13 and 14 GDPR require — normally in your own privacy notice;
- obtaining and recording valid consent where it is required, including for email and SMS marketing, and honouring withdrawals;
- not collecting special categories of personal data (Art. 9) or criminal-offence data (Art. 10) through the service, and not using it to collect data from children;
- the accuracy and lawfulness of your instructions, and the security of your own account credentials.
14. Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by Data Protection Law. This DPA takes effect when you accept the Terms of Service and continues for as long as we process personal data on your behalf, after which the deletion obligations in section 10 apply.
15. Annex I — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the BetterPopup on-site campaign platform — display of popups, capture of signups, analytics, and delivery of captured data to the integrations you connect |
| Duration | The term of your subscription, plus the deletion periods in section 10 |
| Nature and purpose | Collection, recording, storage, structuring, retrieval, use, transmission to your chosen integrations, and erasure — all to provide the service on your instructions |
| Categories of data subjects | Visitors to your website or store, and the subscribers among them who submit a popup form. Where you invite colleagues, your own team members |
| Categories of personal data | Contact data — email address, phone number, and any additional form field you configure. Consent data — what was shown and agreed, when, and any double opt-in confirmation. Technical and behavioural data — page URL, path and title, referrer, device type, approximate screen size, browser language, time zone, approximate country, browser privacy signals, and the bp_session and bp_visitor identifiers |
| Special categories | None. The service is not intended for, and must not be used to collect, special-category or criminal-offence data |
| Frequency | Continuous, for as long as your campaigns are published |
| Controller | You — the customer identified on the BetterPopup account |
| Processor | Digitonica SRL, Str. Dr. Victor Gomoiu, Craiova, Dolj, Romania. [email protected] |
| Competent supervisory authority | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) |
Data minimisation note. The platform does not store visitors' full IP addresses. An IP address is held in memory only long enough to rate-limit abusive requests and is then discarded. Campaign analytics are stored as daily aggregate counts per popup rather than as per-visitor records.
16. Annex II — Technical and organisational measures
- Encryption — TLS for all data in transit; encryption at rest for the database and backups; AES-256-GCM encryption of the access tokens for the integrations you connect.
- Access control — authentication managed by a specialist provider, administrative access limited to named personnel on a least-privilege basis, and separate database roles so the public capture endpoint can insert records but cannot read or modify existing data.
- Tenant isolation — every record is scoped to an organisation identifier and queries are constrained to the authenticated organisation, so one customer cannot reach another's data.
- Payment data — card details are handled entirely by Stripe or Shopify and never reach our systems.
- Resilience and recovery — managed hosting with automated encrypted backups and documented restore procedures.
- Abuse protection — rate limiting on public write endpoints, signed webhook verification, CDN-level protection, and filtering of automated crawler traffic.
- Secure development — code review before release, automated test coverage, dependency monitoring, and secrets held in environment configuration rather than in source control.
- Data minimisation by design — full IP addresses are never persisted, analytics are aggregated rather than per-visitor, and optional double opt-in is available to confirm consent.
- Organisational — confidentiality obligations for all personnel, data-protection agreements with every sub-processor, and periodic review of these measures.
17. Annex III — Authorised sub-processors
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting and database infrastructure | United States (provider incorporated in Germany) | SCCs |
| Cloudflare, Inc. | CDN, DNS and abuse protection for the embed script | Global edge network | SCCs / EU-US DPF |
| Clerk, Inc. | Authentication and account management | United States | SCCs / EU-US DPF |
| Stripe, Inc. | Payments and subscription billing | United States / Ireland | SCCs / EU-US DPF |
| Resend, Inc. | Transactional email — double opt-in confirmations and lead notifications | United States | SCCs / EU-US DPF |
| PostHog, Inc. | Product analytics and error tracking — consent-gated | United States | SCCs / EU-US DPF |
| Shopify Inc. | Store integration and billing — for Shopify installations only | Canada / United States | SCCs |
Not sub-processors. The email and SMS platforms you connect — such as Klaviyo, Mailchimp, Omnisend, Attentive, Postscript and Drip — receive data at your direction under your own agreement with them. They are independent recipients, not our sub-processors, and we are not responsible for their processing.
18. Contact
Questions about this DPA, requests for a countersigned copy, or requests for transfer safeguards: [email protected].
Digitonica SRL
Str. Dr. Victor Gomoiu
Craiova, Dolj, Romania
CUI 46142569 · Trade Register J18/1195/2022