← Back to home
The Front Desk · Legal

Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between EasyFunnel (“Processor”) and the customer (“Controller”) and applies whenever EasyFunnel processes personal data on the Controller's behalf. It is accepted by using the service. A countersigned copy is available on request at privacy@easyfunnel.co.

1. Definitions

“Controller”, “Processor”, “Sub-processor”, “Personal Data”, “Processing”, and “Data Subject” have the meanings given in the EU General Data Protection Regulation (GDPR), Article 4, and equivalent applicable data-protection law.

2. Roles of the parties

The Controller is the customer; EasyFunnel is the Processor and processes Personal Data only on the Controller's documented instructions. For a Controller's website visitors — including visitors who chat with or call the agent — the Controller is the controller of that visitor data.

3. Details of processing

  • Subject matter & duration: for the term of the Controller's subscription and any retention period below.
  • Nature & purpose: providing analytics, an AI chat agent, and — where enabled — voice conversations and call recording.
  • Types of Personal Data: online identifiers and session data; message text; and, for voice, audio recordings and transcripts; email addresses a visitor provides; approximate network/organization and coarse location derived from IP address, and the raw IP address itself — encrypted at rest and retained for up to 30 days to enable on-demand visitor reveal, then permanently deleted (a salted hash of the IP is retained thereafter).
  • Visitor reveal (opt-in): for Controllers who enable person-level visitor reveal, resolved visitor identity — name, business email, and professional profile — obtained via a sub-processor. Person reveal is off by default, requires the Controller to opt in per project, and is blocked for visitors on EU/EEA/UK IP addresses. The Controller is the controller of any personal data resolved through visitor reveal and is responsible for its lawful collection and use.
  • Categories of Data Subjects: the Controller's website visitors and end users.

4. Processor obligations

  • Process Personal Data only on the Controller's documented instructions.
  • Ensure persons authorized to process are bound by confidentiality.
  • Implement appropriate technical and organizational security measures — row-level security, encryption in transit (HTTPS), a private storage bucket with signed-URL access for call audio, and access controls.
  • Assist the Controller in responding to Data Subject requests.
  • Notify the Controller without undue delay after becoming aware of a personal-data breach.

5. Sub-processors

The Controller authorizes EasyFunnel to engage the sub-processors listed at easyfunnel.co/subprocessors. EasyFunnel imposes data-protection obligations on each sub-processor no less protective than this DPA and will update the list before adding or replacing a sub-processor that handles Personal Data. The Controller may object on reasonable data-protection grounds by contacting privacy@easyfunnel.co.

6. International transfers

Where Personal Data is transferred outside its region of origin, EasyFunnel relies on an applicable transfer mechanism (such as the EU Standard Contractual Clauses) with the relevant sub-processor.

7. Retention & deletion

Audio recordings are deleted 90 days after the call. Raw visitor IP addresses are encrypted at rest and retained for up to 30 days solely to enable on-demand visitor reveal, then permanently deleted; a salted hash of the IP is retained thereafter to derive network/organization and coarse-location data. The derived approximate network/organization and coarse location, the salted IP hash, resolved visitor-reveal data (where a Controller has opted in), transcripts, and other Personal Data are retained for the term of the subscription and deleted when the project or account is deleted, as described in the Terms and Privacy Policy. On request, EasyFunnel will return or delete Personal Data.

8. Audit

EasyFunnel will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audit requests, subject to confidentiality.

9. Acceptance

This DPA is accepted by the Controller's authorized use of the service. For a signed counterpart, contact privacy@easyfunnel.co.