to the Terms and Conditions
Recitals
WHEREAS:
A. Speedflow (“Processor”) operates the website https://speedflow.cc and provides website analysis and optimization services (“Services”) to its users (“Controller”), whereby the Services may require the Processor to process Personal Data on behalf of the Controller;
B. This Data Processing Addendum (“DPA” or “Addendum”) establishes the framework governing the rights and obligations of the Controller and the Processor in relation to the processing of Personal Data. The Parties will process Personal Data when performing their obligations under the Terms and Conditions (“Principal Agreement”), whereby the Controller may provide Personal Data to the Processor for processing in connection with the Services;
C. This Addendum sets out the additional terms, requirements, and conditions under which the Processor will process Personal Data in the provision of the Services in accordance with the Principal Agreement. This Addendum supplements the Principal Agreement and forms an integral part thereof;
D. This Addendum contains the mandatory clauses required by Article 28(3) of Regulation (EU) 2016/679 (General Data Protection Regulation - “GDPR”) for contracts between controllers and processors, as well as requirements under other applicable data protection legislation (collectively “Data Protection Laws”);
E. BETA/MVP NOTICE: As Speedflow is currently operating as a beta/MVP product without a formal corporate entity, this DPA reflects our current data processing practices. As our business evolves and we establish a formal legal entity, this DPA will be updated accordingly, and users will be notified of material changes. NOW, THEREFORE, the Parties agree as follows:
1. Definitions
In this Addendum, the following terms shall have the meanings set out below:
- (a) “Controller” means the natural or legal person who determines the purposes and means of processing Personal Data. In the context of Speedflow Services, the Controller is typically the user of the Services who submits website URLs for analysis;
- (b) “Processor” means Speedflow, which processes Personal Data on behalf of the Controller in accordance with the Controller’s instructions;
- (c) “Personal Data” means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR;
- (d) “Data Subject” means the identified or identifiable natural person to whom Personal Data relates;
- (e) “Processing” means any operation or set of operations performed on Personal Data, as defined in Article 4(2) GDPR;
- (f) “Sub-processor” means any processor engaged by the Processor who processes Personal Data on behalf of the Controller;
- (g) “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, as defined in Article 4(12) GDPR.
2. Scope and Purpose of Processing
2.1 Processor’s Obligations
The Processor undertakes to:
- (h) Process Personal Data only in accordance with the documented instructions of the Controller and in compliance with applicable Data Protection Laws;
- (i) Not process Personal Data for any purpose other than as specified in this Addendum (“Permitted Purpose”), unless required by applicable law;
- (j) Immediately inform the Controller if, in the Processor’s opinion, an instruction from the Controller infringes Data Protection Laws.
2.2 Purpose of Processing
The Processor processes Personal Data for the following purposes:
- (k) Providing the Services (website analysis and optimization recommendations) in accordance with the Principal Agreement;
- (l) User account creation, authentication, and management;
- (m)Processing subscription payments and managing billing;
- (n) Communicating with users regarding their account, subscription, and service updates;
- (o) Analyzing usage patterns to improve the Services (via analytics tools);
- (p) Ensuring security, preventing fraud, and maintaining system integrity.
2.3 Categories of Personal Data
The Processor processes the following categories of Personal Data:
- (q) Identity Data: Name (if provided via Google OAuth);
- (r) Contact Data: Email address;
- (s) Authentication Data: Password (stored in hashed form only, never in plain text), authentication tokens;
- (t) Usage Data: Website URLs submitted for analysis (processed in real-time, NOT stored), pages visited, features used, interaction data;
- (u) Technical Data: IP address, browser type, device information, cookies;
- (v) Payment Data: Transaction confirmations from Paddle (the Processor does NOT store payment card details or full billing information - this is handled by Paddle as Merchant of Record).
2.4 Categories of Data Subjects
The Processor processes Personal Data of the following categories of Data Subjects:
- (w) Registered users of Speedflow Services;
- (x) Website visitors (limited technical data via analytics).
2.5 Duration of Processing
The processing of Personal Data shall:
- (y) Commence upon account creation or first use of the Services;
- (z) Continue for the duration of the user’s active subscription or account;
- (aa) Be retained for a maximum of 5 years after account deletion for tax and legal compliance purposes, after which all Personal Data will be securely deleted.
3. Security of Processing
3.1 Technical and Organizational Measures Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, the Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- (bb) Encryption: All data transmitted between users and Speedflow servers is encrypted using TLS (Transport Layer Security). Passwords are hashed using industry-standard algorithms (bcrypt via Supabase);
- (cc) Access Control: Access to systems containing Personal Data is restricted to authorized personnel only. Role-based access controls are implemented through Supabase;
- (dd) Authentication: Two-factor authentication (2FA) is used where available for accessing critical systems and accounts;
- (ee) Infrastructure Security: Personal Data is stored on enterprise-grade cloud infrastructure (Supabase EU servers, Vercel) with SOC 2 Type II compliance and regular security audits;
- (ff) Monitoring and Logging: System access and data processing activities are logged and monitored for suspicious activity;
- (gg) Regular Security Updates: Software and systems are regularly updated to address security vulnerabilities.
3.2 Beta/MVP Security Notice As Speedflow is in beta/MVP stage, security measures are continually being enhanced and refined. Users will be notified of significant security improvements or changes to data processing practices.
3.3 Risk Assessment The Processor regularly assesses risks to Personal Data and adjusts security measures accordingly, taking into account the risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
4. Processor Personnel and Confidentiality
4.1 The Processor ensures that all persons authorized to process Personal Data (including employees, contractors, and authorized personnel) are subject to confidentiality obligations, either by contract or by professional duty;
4.2 Access to Personal Data is limited strictly to individuals who need such access to perform services under the Principal Agreement;
4.3 Upon request, the Processor will provide reasonable evidence that authorized personnel have received appropriate training on data protection and are bound by confidentiality obligations.
5. Sub-Processors
5.1 General Authorization The Controller provides general authorization for the Processor to engage sub-processors to assist in providing the Services, provided that:
- (hh) The Processor maintains a current list of sub-processors (as specified in Section 5.3);
- (ii) The Processor notifies the Controller of any intended changes (addition or replacement of sub-processors) at least 30 days in advance;
- (jj) The Controller may object to the engagement of a new sub-processor on reasonable data protection grounds by notifying the Processor within 30 days.
5.2 Sub-processor Obligations The Processor ensures that:
- (kk) All sub-processors are bound by written agreements imposing data protection obligations equivalent to those in this Addendum;
- (ll) The Processor remains fully liable to the Controller for the performance of any sub-processor’s obligations.
5.3 Current Sub-processors The Processor currently engages the following sub-processors:
- (mm) Supabase (EU servers) - Authentication, database hosting, and backend infrastructure. Stores user credentials and account data securely. More info: https://supabase.com/privacy
- (nn) Paddle.com (UK/USA) - Payment processing and subscription management (Merchant of Record). Handles all payment data and billing information. More info: https://www.paddle.com/legal/privacy
- (oo) Vercel / GitHub (USA) - Website hosting and deployment infrastructure. More info: https://vercel.com/legal/privacy-policy
- (pp) Google LLC (USA) - Google Analytics for website traffic analysis. More info: https://policies.google.com/privacy
- (qq) Posthog (USA) - Product analytics and user behavior tracking. More info: https://posthog.com/privacy
- (rr) Hotjar (Malta) - User behavior analytics, heatmaps, and session recordings. More info: https://www.hotjar.com/legal/policies/privacy/
6. Assistance with Data Subject Rights
6.1 The Processor shall, taking into account the nature of processing, assist the Controller by implementing appropriate technical and organizational measures to fulfill the Controller’s obligation to respond to requests from Data Subjects exercising their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, data portability, and objection);
6.2 If the Processor receives a request directly from a Data Subject to exercise their rights, the Processor shall:
- (ss) Promptly notify the Controller and provide full details of the request;
- (tt) Not respond to the request except on documented instructions from the Controller or as required by applicable law.
7. Personal Data Breach Notification
7.1 Notification Obligation The Processor shall notify the Controller without undue delay, and in any event within 72 hours, upon becoming aware of a Personal Data Breach affecting Personal Data processed under this Addendum. The notification shall include, to the extent possible:
- (uu) A description of the nature of the breach, including the categories and approximate number of Data Subjects and Personal Data records affected;
- (vv) The likely consequences of the breach;
- (ww) Measures taken or proposed to address the breach and mitigate its potential adverse effects.
7.2 Cooperation The Processor shall cooperate with the Controller and take reasonable steps to assist in:
- (xx) Investigating the breach;
- (yy) Mitigating potential harm;
- (zz) Fulfilling the Controller’s obligations to notify supervisory authorities and/or affected Data Subjects.
7.3 Documentation The Processor shall document all Personal Data Breaches, including the facts, effects, and remedial actions taken, and make this documentation available to the Controller upon request.
8. Data Protection Impact Assessment and Consultation
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with supervisory authorities that the Controller reasonably considers necessary under Articles 35 and 36 GDPR or equivalent provisions of other Data Protection Laws, solely in relation to processing of Personal Data under this Addendum.
9. Deletion or Return of Personal Data
9.1 Upon Termination Upon termination or expiration of the Principal Agreement, or upon the Controller’s written request, the Processor shall, at the Controller’s choice: (aaa) Delete all Personal Data processed under this Addendum within 30 days; or (bbb) Return all Personal Data to the Controller in a commonly used, machine-readable format.
9.2 Exceptions The obligation to delete or return Personal Data does not apply to the extent the Processor is required by applicable law to retain some or all of the Personal Data (e.g., for tax compliance purposes - up to 5 years). In such cases, the Processor shall: (ccc) Continue to protect the Personal Data in accordance with this Addendum; (ddd) Only process such Personal Data to the extent and for such period as required by law.
9.3 Certification Upon request, the Processor shall provide written certification that it has complied with its obligations under this Section 9.
10. Audit Rights
10.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with this Addendum and Data Protection Laws;
10.2 The Processor shall allow for and contribute to audits, including inspections, by the Controller or an independent auditor mandated by the Controller, upon reasonable notice and during normal business hours, provided that: (eee) Such audits shall not occur more than once per year unless there is a suspected breach; (fff) The auditor shall be bound by confidentiality obligations; (ggg) The Controller shall bear the costs of such audits unless a material breach is discovered.
11. International Data Transfers
11.1 General Prohibition The Processor shall not transfer Personal Data to countries outside the European Economic Area (“EEA”) without: (hhh) Prior written authorization from the Controller; and (iii) Implementing appropriate safeguards as required by Data Protection Laws.
11.2 Current Transfers The Controller acknowledges that the following sub-processors may process Personal Data outside the EEA: (jjj) Paddle (UK/USA) - Protected by Standard Contractual Clauses and compliance with UK GDPR; (kkk) Vercel, Google, Posthog (USA) - Protected by EU-US Data Privacy Framework certification and/or Standard Contractual Clauses.
11.3 Safeguards Where Personal Data is transferred outside the EEA, the Processor ensures that appropriate safeguards are in place, including but not limited to Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other legally recognized transfer mechanisms.
12. Final Provisions
12.1 Validity and Hierarchy This Addendum shall remain in effect for as long as the Principal Agreement is in force and the Processor processes Personal Data on behalf of the Controller. In the event of any conflict between this Addendum and the Principal Agreement, the provisions of this Addendum shall prevail with respect to data protection matters.
12.2 Amendments Any amendments to this Addendum must be in writing and agreed upon by both Parties. However, the Processor may update the list of sub-processors in accordance with Section 5.1.
12.3 Severability If any provision of this Addendum is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid provision shall be replaced with a valid provision that most closely reflects the intent of the original provision.
12.4 Governing Law and Jurisdiction This Addendum shall be governed by and construed in accordance with the laws of Poland. Any disputes arising from or in connection with this Addendum shall be subject to the exclusive jurisdiction of the courts of Poland.
12.5 Order of Precedence In the event of any conflict or inconsistency between: (lll) This Addendum and the Principal Agreement, this Addendum prevails; (mmm) This Addendum and Data Protection Laws, Data Protection Laws prevail. * * * This Data Processing Addendum is effective as of the date you agree to the Terms and Conditions. For questions regarding data processing, contact info@speedflow.cc