Data Processing Addendum
Last updated: August 10, 2026
This DPA governs the processing of Customer Personal Data by Cheaploy in connection with the Services. It is incorporated into the Terms of Service.
1. Roles
Customer is the Data Controller. Cheaploy acts as Data Processor and processes Personal Data only on documented instructions from the Customer.
2. Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Supabase (Lovable Cloud) | Database, Auth, Edge Functions | EU / US (selectable) |
| Oracle Cloud Infrastructure | Customer-owned compute & storage | Customer-selected region |
| Resend | Transactional email (when configured) | US |
| GlitchTip | Error monitoring | EU |
| Google AI (Gemini) | AI analysis features | US |
| Paddle | Payments, billing and tax (merchant of record) | US / EU |
We will notify customers of any new sub-processor 30 days in advance.
3. Security measures
- AES-256-GCM encryption at rest for credentials and secrets
- TLS 1.2+ in transit, HSTS preloaded
- RBAC and Row-Level Security on all tenant data
- MFA enforcement for administrators
- Hash-chained, append-only audit logs
- Daily encrypted backups with 30-day retention; monthly DR drills
4. Data subject rights
Customers can export or delete their data at any time from Settings → Privacy (Article 15 / 17 GDPR).
5. Feedback submissions
Page feedback submitted through the in-app feedback button stores the page URL, your message, optional name/email, any screenshot you attach, and basic browser/viewport details. Screenshots are stored in a private bucket and are only readable by Cheaploy administrators through short-lived signed links. Redact any sensitive data before uploading a screenshot.
6. International transfers
Where transfers leave the EEA, Cheaploy relies on EU Standard Contractual Clauses (2021/914).
7. Contact
Questions: privacy@cheaploy.com