Data Processing Agreement

Last updated: October 3, 2026

This Data Processing Agreement ("DPA") is part of the Terms of Service between CXFormula LLC("CXFormula", the processor) and the customer that uses RAVE™ ("Customer", the controller). It applies whenever CXFormula processes personal data on the Customer's behalf, and it takes effect when the Customer accepts the Terms. If the Customer needs a countersigned copy, email support@cxformula.com.

1. Definitions

"Data Protection Law" means all laws that apply to the processing, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended ("CCPA"). "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data that CXFormula processes for the Customer through RAVE™. "Sub-processor" means a third party CXFormula engages to process Customer Personal Data.

2. Roles and scope

  • The Customer is the Controller (or, for an agency acting for its clients, a Processor instructing CXFormula as its Sub-processor).
  • CXFormula is the Processor, and under the CCPA a "service provider".
  • Details of the processing (subject matter, duration, nature, purpose, data and data subjects) are in Annex 1.
  • This DPA does not cover data CXFormula controls about its own customers and users (account, billing, support), which is described in Part A of the Privacy Policy.

3. Customer obligations

The Customer:

  • is responsible for having a lawful basis, and any consent required (including for storage on visitors' devices), for the processing;
  • keeps a privacy notice on each site where RAVE™ runs that describes RAVE™ (a suggested paragraph is on the Cookie Notice);
  • only sends RAVE™ real activity and the fields RAVE™ needs, and no special-category or children's data;
  • is responsible for the accuracy of its instructions and for its settings (name display, lookback window, form capture, sources).

4. CXFormula obligations (GDPR Article 28(3))

  • Instructions. CXFormula processes Customer Personal Data only on the Customer's documented instructions, which are this DPA, the Terms, and the Customer's settings and use of RAVE™, unless the law requires otherwise (in which case CXFormula will tell the Customer first, unless the law forbids it). CXFormula will tell the Customer if it believes an instruction breaks Data Protection Law.
  • Confidentiality. Everyone at CXFormula who can access Customer Personal Data is bound by confidentiality and accesses it only as needed to provide and support the Service.
  • Security. CXFormula maintains the technical and organizational measures in Annex 2.
  • Sub-processors. CXFormula engages Sub-processors only as described in section 5.
  • Data subject requests. CXFormula offers self-service tools (the public delete my data page and POST /api/v1/data-deletion) and will otherwise help the Customer respond to requests to access, correct, delete, restrict or port data. If a Data Subject contacts CXFormula about the Customer's processing, CXFormula will forward the request to the Customer without undue delay, except that requests made through the public deletion page are carried out directly once the requester confirms control of the email address.
  • Assistance. CXFormula will reasonably help the Customer with security, breach notification, data protection impact assessments and consultations with authorities, taking into account the information available to it.
  • Breach notification. CXFormula will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information the Customer reasonably needs to meet its own obligations, and will take reasonable steps to contain it.
  • Deletion or return. At the end of the Service, the Customer may export its data within 30 days; CXFormula then deletes Customer Personal Data within 90 days, unless the law requires it to be kept. Backups roll off on the database provider's schedule and remain protected until then.
  • Audits. CXFormula will make available the information reasonably needed to show compliance with this DPA and answer reasonable security questionnaires. If that is not enough, or an authority requires it, the Customer may audit once a year on 30 days' notice, during business hours, at its own cost, under confidentiality, and without access to other customers' data.

5. Sub-processors

The Customer gives general authorization for CXFormula to use the Sub-processors listed below. CXFormula imposes data protection obligations on each that are no less protective than this DPA, and remains responsible for their performance.

Changes: CXFormula will update the list on this page and email account owners at least 30 days before a new Sub-processor starts processing Customer Personal Data (sooner only in an emergency affecting the Service, with notice as soon as possible). The Customer may object on reasonable data protection grounds within that period by emailing support@cxformula.com. The parties will discuss a solution in good faith; if none is found, the Customer's only remedy is to cancel the Service effective at the end of the current paid period. No refunds or credits apply.

Sub-processorPurposeDataLocation
Supabase, Inc.Database, authentication and file storageAll customer data and end-visitor data RAVE™ storesUnited States (AWS us-east-2, Ohio)
Vercel, Inc.Application hosting, serverless functions, IP-based location lookupRequests to RAVE™, including IP addresses in transit and in short-lived logsUnited States (global edge network)
Cloudflare, Inc.DNS and content deliveryRequests to RAVE™ domains, including IP addresses in transitGlobal network
Stripe, Inc.Subscription billing and paymentsBilling contact, payment method and invoice data of RAVE™ customersUnited States
Anthropic, PBCRAVE™ AI coach (only when a user asks the coach for suggestions)Campaign settings, card text and aggregated analytics; no end-visitor names or emailsUnited States
Resend, Inc.Transactional email (once enabled)Recipient email address and message content for account noticesUnited States

6. International transfers

Customer Personal Data is stored and processed in the United States. To the extent a transfer of Personal Data from the EEA, the UK or Switzerland to CXFormula is not covered by an adequacy decision (such as the EU-U.S. Data Privacy Framework, where the recipient is certified), the parties agree that the Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914 are incorporated by reference: Module Two (controller to processor), or Module Three (processor to processor) where the Customer is itself a processor. For those clauses: Clause 7 (docking) applies; Clause 9 option 2 (general authorization, with the notice period in section 5) applies; the optional language in Clause 11 does not apply; Clauses 17 and 18 are governed by and resolved in the courts of Ireland; and Annexes I and II are Annex 1 and Annex 2 of this DPA. For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies, and for Swiss transfers the clauses apply with references read as the Swiss FADP and the Swiss FDPIC. CXFormula ensures that onward transfers to Sub-processors are covered by equivalent safeguards.

7. CCPA terms

As a service provider, CXFormula will not sell or share Customer Personal Data; retain, use or disclose it for any purpose other than providing the Service under the Terms (including outside the direct business relationship with the Customer); or combine it with personal information it receives from others, except as the CCPA allows. CXFormula will comply with the CCPA, provide the same level of protection it requires, and notify the Customer if it can no longer meet these obligations. The Customer may take reasonable steps to stop and remediate unauthorized use.

8. Liability and order of precedence

Each party's liability under this DPA is subject to the limits in the Terms, to the extent Data Protection Law allows. If this DPA conflicts with the Terms, this DPA wins for the processing of Customer Personal Data; the Standard Contractual Clauses win over both. This DPA is governed by the law that governs the Terms (New Jersey), except where the Standard Contractual Clauses or Data Protection Law require otherwise.

Annex 1 — Details of processing

  • Parties: data exporter is the Customer (contact: the account owner's email). Data importer is CXFormula LLC, 60 Whitney Road, Suite 13, Mahwah, NJ 07430, USA(contact: support@cxformula.com).
  • Subject matter and purpose: showing real activity notifications (RAVE™ Alert, RAVE™ Count, RAVE™ Live) on the Customer's websites; live visitor counts; measuring card impressions, clicks and conversions; A/B lift measurement; verifying imported activity; and support.
  • Nature of processing: collection (webhooks, API, pixel beacons, form capture, imports), hashing, storage, de-duplication, aggregation, display of limited fields to site visitors, analysis and deletion.
  • Data subjects: visitors, leads, customers and content viewers of the Customer's websites and funnels.
  • Categories of data: first name and last initial (a full last name is reduced to its first letter on arrival and never stored); email address, stored only as a SHA-256 hash; approximate location (city, region, country) from the source or derived from the IP address at the time of collection (the IP address is not stored); action type, offer or content name, funnel step and timestamp; profile image URL if the source sends one; random pseudonymous visitor ID, page paths, and card exposure, impression, hover, click and conversion events; A/B holdout assignment.
  • Special categories: none. The Customer must not send them.
  • Frequency: continuous, while the Service is in use.
  • Duration and retention: for the term of the Terms, then as in section 4 (deletion or return). Activity is shown only within each campaign's lookback window (30 days by default, set by the Customer), and the Customer can delete entries at any time.
  • Sub-processor transfers: as listed in section 5, for the purposes listed there.
  • Competent supervisory authority: as determined under Clause 13 of the Standard Contractual Clauses.

Annex 2 — Security measures

  • Encryption: HTTPS (TLS) for all traffic; encryption at rest for the database and backups by our hosting providers.
  • Data minimization: raw email addresses are hashed with SHA-256 on arrival and never stored; IP addresses are not stored; visitors are identified only by a random ID; last names are reduced to their initial on arrival and never stored; browsers receive at most first name, last initial and city/region; the pixel loads no third-party code and sets no cookies.
  • Access control: row-level security on every database table, scoped to the Customer's account and workspaces; role-based access (owner, admin, member) with per-workspace permissions; passwordless sign-in by emailed link; CXFormula staff access limited to platform administrators, with any ability to make changes in a customer account granted per account, time-limited and audit-logged.
  • Secrets: customer integration API keys encrypted with AES-256-GCM; public endpoints validate the site or campaign key before writing data; API keys are scoped to one workspace; signed imports use per-workspace HMAC secrets; server credentials kept in the hosting provider's encrypted environment settings.
  • Abuse protection: rate limits on public endpoints, input validation and size limits on every field accepted from browsers.
  • Integrity: automated tests for access rules and data handling run before changes ship; all changes are version-controlled.
  • Availability and resilience: managed hosting with automatic scaling; database backups by the database provider; the pixel is designed to fail silently so customer pages keep working if RAVE™ is unavailable.
  • Incident response: breaches are assessed, contained and notified as described in section 4.
  • Sub-processors: chosen for their security programs (for example SOC 2 reports) and bound by data protection terms.