dropify.dev
Pricing Log in Get started

Legal

Data Processing Addendum

Effective date: 2026-06-16 — Last updated: 2026-06-16

This DPA is incorporated by reference into the Dropify Terms of Service. It applies automatically to all customers whose use of the service involves the processing of personal data of EU or UK data subjects (GDPR / UK GDPR). No separate signature is required unless you request a countersigned copy.

1. Definitions

Terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679). “Agreement” means the Dropify Terms of Service. “Services” means the queue admission and Drop Room waiting-room products described therein.

2. Roles

Controller: the Customer (Tenant) — the party who determines the purposes and means of processing personal data of their end-users (“visitors”).

Processor: Dropify [legal entity TBD at incorporation] — processes personal data only on the Controller’s behalf and as described in this DPA.

3. Subject matter and nature of processing

Subject matter Fair queue admission, bot-challenge verification, and prevention of queue-position fraud for high-demand e-commerce drop events.
Nature Collection, storage, analysis, and automated decision-making based on visitor request data.
Purpose Enforcement of the Controller’s Drop Room queue configuration; forensic audit logging; metered billing.
Categories of data subjects Visitors to the Controller’s website or store.
Categories of personal data IP address, country, ASN (autonomous system number), HTTP endpoint, block/queue reason, and optionally ESTF (edge TLS fingerprint, Enterprise only).
Duration For the term of the Agreement. Forensic records are purged on a rolling 2,000-row-per-tenant basis; see Privacy Policy §3.

4. Processor obligations

Dropify shall:

  • Process personal data only on documented instructions from the Controller (i.e. the Controller’s configuration of Drop Room queue rules). If we are required by law to process data differently we will inform the Controller unless prohibited.
  • Ensure that persons authorised to process personal data are under confidentiality obligations.
  • Implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest (Cloudflare D1 encryption), access controls (adapter keys, admin bearer tokens), and secret-rotation procedures (see docs/runbook.md).
  • Assist the Controller in responding to data-subject rights requests. For visitor data, the Controller may direct us to provide or delete specific records (IP-based lookup) via privacy@dropify.dev.
  • Notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting visitor data. **[cutover — monitoring not yet live]**
  • Delete or return all personal data at the end of the Agreement (Controller may trigger immediate deletion via the GDPR delete endpoint).
  • Make available all information necessary to demonstrate compliance and allow for audits on reasonable notice.

5. Sub-processors

The Controller authorises the use of the following sub-processors. We will provide 30 days’ notice before adding new sub-processors that touch visitor personal data.

Sub-processorPurposeLocation
Cloudflare, Inc. Infrastructure: Workers (brain compute), D1 (audit log storage), Durable Objects (queue state), Turnstile (bot challenge). Global — EU–US DPF certified; Cloudflare DPA applies.
Stripe, Inc. Payment processing and subscription management (does not process visitor personal data — only Controller billing data). USA — EU–US DPF / SCCs.

6. International transfers

Personal data of EU/EEA data subjects may be transferred to Cloudflare infrastructure outside the EEA. Such transfers rely on:

  • Cloudflare’s EU–US Data Privacy Framework certification (for US-bound transfers).
  • Cloudflare’s Standard Contractual Clauses (SCCs) for other non-EEA transfers.

Copies of the relevant transfer mechanisms are available from Cloudflare at cloudflare.com/privacypolicy.

7. Governing law

This DPA is governed by the same law as the Agreement (§12 of the Terms of Service). If any provision conflicts with the GDPR, the GDPR prevails.

8. Contact

Data protection inquiries: privacy@dropify.dev

Privacy Policy Terms of Service Security & Disclosure
dropify.dev
Privacy Terms DPA Contact