Legal
Data Processing Addendum
This DPA is incorporated by reference into the Dropify Terms of Service. It applies automatically to all customers whose use of the service involves the processing of personal data of EU or UK data subjects (GDPR / UK GDPR). No separate signature is required unless you request a countersigned copy.
1. Definitions
Terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679). “Agreement” means the Dropify Terms of Service. “Services” means the queue admission and Drop Room waiting-room products described therein.
2. Roles
Controller: the Customer (Tenant) — the party who determines the purposes and means of processing personal data of their end-users (“visitors”).
Processor: Dropify [legal entity TBD at incorporation] — processes personal data only on the Controller’s behalf and as described in this DPA.
3. Subject matter and nature of processing
| Subject matter | Fair queue admission, bot-challenge verification, and prevention of queue-position fraud for high-demand e-commerce drop events. |
|---|---|
| Nature | Collection, storage, analysis, and automated decision-making based on visitor request data. |
| Purpose | Enforcement of the Controller’s Drop Room queue configuration; forensic audit logging; metered billing. |
| Categories of data subjects | Visitors to the Controller’s website or store. |
| Categories of personal data | IP address, country, ASN (autonomous system number), HTTP endpoint, block/queue reason, and optionally ESTF (edge TLS fingerprint, Enterprise only). |
| Duration | For the term of the Agreement. Forensic records are purged on a rolling 2,000-row-per-tenant basis; see Privacy Policy §3. |
4. Processor obligations
Dropify shall:
- Process personal data only on documented instructions from the Controller (i.e. the Controller’s configuration of Drop Room queue rules). If we are required by law to process data differently we will inform the Controller unless prohibited.
- Ensure that persons authorised to process personal data are under confidentiality obligations.
-
Implement technical and organisational measures appropriate to the risk,
including encryption in transit (TLS 1.2+) and at rest (Cloudflare D1
encryption), access controls (adapter keys, admin bearer tokens), and
secret-rotation procedures (see
docs/runbook.md). - Assist the Controller in responding to data-subject rights requests. For visitor data, the Controller may direct us to provide or delete specific records (IP-based lookup) via privacy@dropify.dev.
- Notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting visitor data. **[cutover — monitoring not yet live]**
- Delete or return all personal data at the end of the Agreement (Controller may trigger immediate deletion via the GDPR delete endpoint).
- Make available all information necessary to demonstrate compliance and allow for audits on reasonable notice.
5. Sub-processors
The Controller authorises the use of the following sub-processors. We will provide 30 days’ notice before adding new sub-processors that touch visitor personal data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Infrastructure: Workers (brain compute), D1 (audit log storage), Durable Objects (queue state), Turnstile (bot challenge). | Global — EU–US DPF certified; Cloudflare DPA applies. |
| Stripe, Inc. | Payment processing and subscription management (does not process visitor personal data — only Controller billing data). | USA — EU–US DPF / SCCs. |
6. International transfers
Personal data of EU/EEA data subjects may be transferred to Cloudflare infrastructure outside the EEA. Such transfers rely on:
- Cloudflare’s EU–US Data Privacy Framework certification (for US-bound transfers).
- Cloudflare’s Standard Contractual Clauses (SCCs) for other non-EEA transfers.
Copies of the relevant transfer mechanisms are available from Cloudflare at cloudflare.com/privacypolicy.
7. Governing law
This DPA is governed by the same law as the Agreement (§12 of the Terms of Service). If any provision conflicts with the GDPR, the GDPR prevails.
8. Contact
Data protection inquiries: privacy@dropify.dev