Data Processing Addendum

    Last updated: August 10, 2026

    This DPA governs the processing of Customer Personal Data by Cheaploy in connection with the Services. It is incorporated into the Terms of Service.

    1. Roles

    Customer is the Data Controller. Cheaploy acts as Data Processor and processes Personal Data only on documented instructions from the Customer.

    2. Sub-processors

    ProviderPurposeRegion
    Supabase (Lovable Cloud)Database, Auth, Edge FunctionsEU / US (selectable)
    Oracle Cloud InfrastructureCustomer-owned compute & storageCustomer-selected region
    ResendTransactional email (when configured)US
    GlitchTipError monitoringEU
    Google AI (Gemini)AI analysis featuresUS
    PaddlePayments, billing and tax (merchant of record)US / EU

    We will notify customers of any new sub-processor 30 days in advance.

    3. Security measures

    • AES-256-GCM encryption at rest for credentials and secrets
    • TLS 1.2+ in transit, HSTS preloaded
    • RBAC and Row-Level Security on all tenant data
    • MFA enforcement for administrators
    • Hash-chained, append-only audit logs
    • Daily encrypted backups with 30-day retention; monthly DR drills

    4. Data subject rights

    Customers can export or delete their data at any time from Settings → Privacy (Article 15 / 17 GDPR).

    5. Feedback submissions

    Page feedback submitted through the in-app feedback button stores the page URL, your message, optional name/email, any screenshot you attach, and basic browser/viewport details. Screenshots are stored in a private bucket and are only readable by Cheaploy administrators through short-lived signed links. Redact any sensitive data before uploading a screenshot.

    6. International transfers

    Where transfers leave the EEA, Cheaploy relies on EU Standard Contractual Clauses (2021/914).

    7. Contact

    Questions: privacy@cheaploy.com