Data Processing Agreement
Version 1.0. Last updated: 28.08.2026
Straycy OÜ
Registry code:
Registered in Estonia
Contact: hi@straycy.com
This Data Processing Agreement (“DPA”) forms part of the Straycy Terms of Service between Straycy OÜ (the “Processor”) and the customer identified in the account (the “Controller”). It applies where we process personal data on your behalf, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. How Straycy works, and why it matters here
Understanding where data physically sits is necessary to understand this DPA.
The plugin stores data on your own server. Attribution and lead data recorded by the Straycy WordPress plugin is written to the database of your own WordPress installation. It does not pass through or get stored on Straycy’s infrastructure. For that data you are the controller and we are not a processor, because we neither receive nor hold it.
Similarly, when the plugin sends a conversion to Meta, Google, Reddit or Snapchat, the request goes from your server directly to that platform. It does not route through us.
We process personal data on your behalf in three situations, and this DPA governs those:
| Situation | What we process |
|---|---|
| Your account | Name, email, profile image, licence key, subscription and billing records, and the URLs of sites you register |
| Support | Anything you send us in a support request, including logs, screenshots or exports you choose to share |
| Server-side conversion forwarding | Where you enable a feature that routes conversion events through Straycy’s infrastructure on your behalf. See section 4 |
Note that data about you as our customer, meaning your own name and email, is data for which we are the controller, not the processor. That processing is described in our Privacy Policy, not this DPA.
2. Subject matter, duration, nature and purpose
Subject matter. Processing of personal data necessary to provide the Straycy service.
Duration. For the term of your subscription, plus the retention periods in section 9.
Nature and purpose. Storing site registration data; receiving and, where applicable, forwarding conversion events to Advertising Platforms you have configured; and providing support.
2.1 Types of personal data
Depending on the features you enable:
- Site URLs and licence activation records
- Hashed identifiers: SHA-256 of email addresses and phone numbers
- Advertising click identifiers, such as GCLID and FBCLID
- Conversion metadata: timestamp, value, currency, order or transaction reference
- Consent status
- Anything contained in support requests you send us
2.2 Categories of data subjects
Visitors to and customers of your website, and your own personnel who use the portal.
3. Our obligations as processor
We will:
- Process personal data only on your documented instructions, including for transfers, unless required otherwise by EU or Member State law, in which case we will inform you before processing unless the law prohibits it. Your use of the Service and these agreements constitute your instructions.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement the technical and organisational measures described in section 7.
- Respect the conditions in section 5 for engaging sub-processors.
- Assist you, so far as reasonably possible, in responding to data subject requests under Chapter III GDPR.
- Assist you with data protection impact assessments and prior consultation under Articles 32 to 36, taking into account the information available to us.
- At your choice, delete or return personal data at the end of the service, and delete existing copies unless law requires retention.
- Make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in section 8.
- Inform you immediately if, in our opinion, an instruction infringes the GDPR or other data protection law.
4. Server-side conversion forwarding
Where you enable a feature that routes conversion events through Straycy’s infrastructure, rather than sending them directly from your server, we process those events as your processor, for the sole purpose of delivering them to the Advertising Platform you have designated.
We will not use those events for our own purposes, will not sell or share them, and will not use them to train models or build products other than to provide the Service to you.
4.1 Advertising Platforms are not our sub-processors
Meta, Google, Reddit, Snapchat and any other platform you connect determine their own purposes and means for the data they receive. They act as independent controllers in respect of that data, or in some configurations as joint controllers with you. Your relationship with them is governed by their own terms and data protection agreements, which you are responsible for accepting. We forward data only where you have configured and authorised it.
5. Sub-processors
You give general authorisation for us to engage sub-processors. Our current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting for the portal | EU region; US company |
| Neon Inc. | Database hosting | EU (Frankfurt, Germany); US company |
| [Payment provider] | Payment processing and invoicing | [To be completed] |
We impose data protection obligations on each sub-processor no less protective than those in this DPA, and remain fully liable to you for their performance.
We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period and we will work in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty for the remainder of the paid term.
6. International transfers
Our infrastructure is located in the European Union. Application hosting is configured to EU regions and the database is hosted in Frankfurt, Germany.
Some sub-processors are US-incorporated companies operating EU infrastructure. Where any transfer of personal data outside the EEA occurs, it will be covered by an appropriate safeguard under Chapter V GDPR: the EU Standard Contractual Clauses, an adequacy decision, or the EU-US Data Privacy Framework where applicable.
7. Security measures
We implement appropriate technical and organisational measures under Article 32, including:
- Encryption in transit: TLS on all connections to the portal and API
- Encryption at rest for database storage
- Identifier hashing: email addresses and phone numbers used for platform matching are hashed with SHA-256 before transmission. We do not transmit raw email addresses or phone numbers to Advertising Platforms
- IP addresses are not stored by the portal. Where an IP is used transiently for rate limiting, it is not written to persistent storage
- Access control: access to production systems is limited to personnel who require it, protected by multi-factor authentication
- Credential protection: third-party credentials such as OAuth refresh tokens are encrypted at rest and are never exposed to your WordPress installation or to end users
- Segregation: customer data is logically separated by account
- Backups with the durability guarantees of our database provider
- Change management: version-controlled code and reviewed changes
These measures may evolve. We will not materially reduce the overall level of security during your subscription.
8. Audits
On reasonable written request, no more than once per twelve months, unless required by a supervisory authority or following a personal data breach, we will provide information reasonably necessary to demonstrate compliance with this DPA.
Where an on-site audit is required, it will be at your expense, on at least 30 days’ notice, during business hours, subject to confidentiality, and conducted so as not to disrupt our operations.
9. Retention and deletion
| Data | Retention |
|---|---|
| Account and licence data | Subscription term plus 30 days, during which you may export it. Then deleted, except records we must keep for legal, tax or accounting purposes. |
| Conversion events processed through our infrastructure | Only as long as necessary to deliver them and support retry and diagnostics, and no longer than 90 days. |
| Support correspondence | Up to 24 months. |
| Data on your own WordPress installation | Controlled by you, subject to your own retention settings. We cannot delete it on your behalf. |
You may request deletion at any time by contacting hi@straycy.com.
10. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf.
The notification will describe, so far as we know it: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases without undue delay.
You remain responsible for notifying your supervisory authority and, where required, the affected data subjects.
11. Your obligations as controller
You warrant that:
- You have a valid legal basis for the processing you instruct us to carry out
- You have obtained any consent required from your website visitors, including under the ePrivacy Directive for cookies and similar technologies, before tracking occurs
- Your privacy notice accurately describes the processing, including the use of a service provider and the transfer of conversion data to Advertising Platforms
- Your instructions to us comply with data protection law
12. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted by the GDPR.
If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
13. Contact
Data protection queries:
Straycy OÜ
Registry code: [REGISTRY CODE]
Email: hi@straycy.com
Straycy OÜ has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR.