Skip to content
dropify.dev
Pricing Writing Log in Get started

Legal

Data Processing Agreement

How dropify processes personal data on your behalf when your shoppers pass through a queue, under article 28 of the GDPR.

Effective 2026-07-25 · Last updated 2026-07-25

Documents

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • Security & disclosure

Scope

This Data Processing Agreement (“DPA”) forms part of the dropify Terms of Service (the “Agreement”) and applies whenever we process personal data on your behalf. It applies automatically; no separate signature is needed. If you require a countersigned copy for your own records, write to privacy@dropify.dev and we will provide one.

Terms not defined here have the meaning given to them in the General Data Protection Regulation (EU) 2016/679 (“GDPR”). Where the UK GDPR applies instead, references to the GDPR should be read accordingly.

Roles

You are the controller: your shoppers are your visitors, and you decide that a queue should stand between them and your store, and on what terms.

We are the processor: we operate that queue on your instructions and process personal data only for that purpose. In respect of your own account data — the details of the people who administer your account — we are the controller, and our Privacy Policy governs instead.

What we process

Subject matter
Operating a fair waiting room for your product releases: admitting shoppers in the order your configuration determines, issuing admission passes, and distinguishing shoppers from automated traffic.
Nature of the processing
Collection, short-term storage, and automated evaluation of requests in order to decide whether and when a visitor is admitted.
Purpose
Enforcing the queue you have configured, preventing queue-position fraud and bot abuse, and giving you a record of what happened during a drop.
Data subjects
Visitors to your website or store.
Categories of data
Network identifiers (the visitor's IP address, and the country and network operator derived from it), the address requested, the queue decision taken and the reason for it, and timestamps. On Enterprise plans, a technical fingerprint of the connection used to detect automated traffic. We do not process names, contact details, payment details or any special category of personal data on your behalf.
Duration
For as long as the Agreement is in force. Records of individual queue decisions are held in a rolling window of the most recent activity per customer and are overwritten as newer activity replaces them; aggregate counts, which contain no network identifiers, are kept for the life of your account.

Your instructions

We process personal data only on your documented instructions. Your configuration of the Service — the drops you run and the rules you set — together with the Agreement and this DPA constitute those instructions in full.

If we are required by EU or member-state law to process personal data otherwise, we will tell you before doing so unless that law forbids it. If we believe an instruction breaches data protection law, we will tell you and may suspend that instruction until it is resolved.

Confidentiality

Access to personal data processed under this DPA is limited to personnel who need it to operate or support the Service. They are bound by a duty of confidentiality that survives the end of their engagement, and they are trained in their obligations.

Security

We implement technical and organisational measures appropriate to the risk, as required by article 32 GDPR. These include:

  • encryption of personal data in transit and at rest;
  • access on a least-privilege basis, restricted to named individuals, with authentication required for every administrative action;
  • logical separation of each customer's data, so that one customer's configuration or records are not reachable from another's;
  • management of credentials and signing material in a dedicated secret store, with defined procedures for rotating them, including after any suspected exposure;
  • collecting the minimum data needed to decide a queue position, and holding it no longer than that decision and its audit require;
  • periodic review of these measures, and of the access granted under them, as the Service changes.

We do not currently hold a SOC 2, ISO 27001 or comparable certification. Our security and disclosure page states our position and is updated if that changes.

Sub-processors

You give us general authorisation to engage sub-processors. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to you for their performance.

Cloudflare, Inc.
Provides the infrastructure the Service runs on: compute, storage and bot detection. Processes visitor data. Operates globally; certified under the EU–US Data Privacy Framework and offering Standard Contractual Clauses for other transfers.

That is the whole list. We invoice you directly and use no third-party payment processor, so no sub-processor receives your billing data.

We will give you at least 30 days' notice by email before adding or replacing a sub-processor that processes visitor personal data. If you reasonably object on data protection grounds within that period, and we cannot offer an alternative, you may terminate the affected part of the Service without penalty.

International transfers

Personal data may be processed outside the European Economic Area by the sub-processor named above. Those transfers rely on that sub-processor's certification under the EU–US Data Privacy Framework and, where the Framework does not apply, on the European Commission's Standard Contractual Clauses together with a transfer impact assessment. Copies of the relevant mechanisms are available on request.

Assisting you

Taking into account the nature of the processing, we will assist you:

  • in responding to requests from data subjects exercising their rights. If a visitor contacts us directly, we will not respond substantively but will refer them to you and let you know;
  • in meeting your obligations on security, breach notification, data protection impact assessments and prior consultation, by providing the information we hold.

Where assistance goes materially beyond the ordinary and requires significant engineering effort, we may charge a reasonable fee, agreed with you in advance.

Personal data breaches

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the full picture is not yet available, we will provide it in stages without further undue delay.

Notifying supervisory authorities and data subjects is your responsibility as controller; we will give you the information you need to do it.

Deletion and return

On termination of the Agreement we delete personal data processed on your behalf within 30 days, unless EU or member-state law requires us to keep it. You may ask us to delete it sooner, or to return it, at any time.

Audits

We will make available the information necessary to demonstrate compliance with article 28 GDPR, and will allow and contribute to audits carried out by you or an auditor you appoint. Audits take place at most once a year, on 30 days' notice, during business hours, without disrupting the Service, and subject to confidentiality. Where an independent report or certification would answer your questions, we may offer that instead.

Governing law

This DPA is governed by Dutch law and disputes are subject to the same forum as the Agreement. Where any provision of this DPA conflicts with the GDPR, the GDPR prevails; where it conflicts with the Agreement on a data protection matter, this DPA prevails.

Contact

Data protection questions and requests: privacy@dropify.dev

dropify.dev

A fair line for every drop, enforced by your own store.

Product

  • Pricing
  • Support
  • Writing

Account

  • Log in
  • Sign up

Legal

  • Terms
  • Privacy
  • DPA
  • Security

© 2026 dropify.dev