Data Processing Agreement

Last updated: July 31, 2026

This Data Processing Agreement (“DPA”) is entered into between the business that has created a Peleka account and connected a store or otherwise submitted personal data to the Service (“Customer”, “Controller”) and Peleka LLC, a Wyoming limited liability company (“Peleka”, “Processor”), and forms part of, and is incorporated by reference into, the Peleka Terms of Service (the “Agreement”). By using the Service, Customer agrees to the terms of this DPA. Capitalized terms not defined here have the meaning given in the Agreement.

1. Definitions

  • “Data Protection Laws”means all applicable laws relating to the processing of Personal Data, including, where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
  • “Personal Data”, “Processing”, “Data Subject”, “Controller”, and “Processor” have the meanings given in the GDPR, and this DPA applies those meanings regardless of which Data Protection Law governs a given Data Subject.
  • “Customer Personal Data”means Personal Data that Peleka Processes on Customer’s behalf in the course of providing the Service, as further described in Sections 4 through 6 below.
  • “Sub-processor”means any third party engaged by Peleka to Process Customer Personal Data on Peleka’s behalf.

2. Roles of the Parties

Customer is the Controller of Customer Personal Data. Peleka is a Processor acting only on Customer’s documented instructions, as set out in this DPA and the Agreement, except where otherwise required by law.

3. Subject Matter and Duration

Peleka Processes Customer Personal Data for the duration of the Agreement, and thereafter only to the extent and for as long as required to comply with Section 12 (Retention and Deletion) or applicable law.

4. Nature and Purpose of Processing

Peleka Processes Customer Personal Data to provide the Service Customer has signed up for: importing and storing contact records (including those synced from a connected Shopify or WooCommerce store), building audience segments, sending marketing emails and automations on Customer’s behalf, tracking engagement (opens, clicks, unsubscribes), processing double opt-in confirmations, and related account/billing administration.

5. Categories of Data Subjects

  • End customers and website/store visitors of the Customer (contacts, subscribers, e-commerce customers).
  • Customer’s own personnel who access the Service (workspace users/team members).

6. Categories of Personal Data

Depending on how Customer uses the Service, Customer Personal Data may include:

  • Contact/subscriber data: email address, first and last name, phone number, custom fields Customer chooses to collect, subscription/consent status, engagement history (opens, clicks, unsubscribes).
  • E-commerce integration data (Shopify/WooCommerce, only if Customer connects a store): customer email/name/phone and marketing-consent status; order identifiers, order totals, and line-item titles; abandoned-checkout email and cart contents. Peleka does not receive full payment card data.
  • Team/account data: names and email addresses of Customer’s own users who log into the Service.

Where Customer connects an e-commerce store, Peleka correlates contact/subscriber engagement history with e-commerce integration data (order records) to provide revenue attribution reporting.

Peleka does not intentionally process special categories of Personal Data (as defined in GDPR Art. 9) and Customer agrees not to submit such data to the Service.

7. Processor Obligations

Peleka shall:

  • Process only on instructions.Process Customer Personal Data only on Customer’s documented instructions (including this DPA and Customer’s configuration of the Service), unless required to do otherwise by law, in which case Peleka will inform Customer before Processing, unless legally prohibited from doing so.
  • Confidentiality. Ensure that personnel authorized to Process Customer Personal Data are subject to a duty of confidentiality.
  • Security.Implement the technical and organizational security measures described below in “ Security Measures”.
  • Sub-processors. Engage Sub-processors only as permitted under Section 8.
  • Assistance with Data Subject rights. Taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, in responding to requests from Data Subjects to exercise their rights under Data Protection Laws. In practice:
    • Customer can self-serve deletion of an individual contact’s Personal Data at any time from the Service, which purges identifying fields immediately.
    • Where Peleka is integrated with Customer’s Shopify store, Peleka implements Shopify’s mandatory compliance webhooks: customers/redact(automated erasure/anonymization of the affected contact’s Personal Data) and shop/redact (data cleanup after app uninstall).
    • For customers/data_request(a Data Subject requesting a copy of their data), Peleka acknowledges the request and provides the underlying data to Customer for delivery to the Data Subject within the 30-day window Shopify’s program requires.
  • Data Protection Impact Assessments.Provide reasonably requested information to assist Customer with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and relating to Peleka’s Processing.
  • Breach notification. Notify Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a Personal Data breach affecting Customer Personal Data, and provide the information reasonably necessary for Customer to meet its own breach-notification obligations.
  • Deletion or return.At Customer’s election, delete or return all Customer Personal Data at the end of the provision of Service, except to the extent Peleka is required by law to retain some or all of it, or as described in 12.
  • Audits. Make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable notice, confidentiality, and no more than once per 12-month period absent a reasonable belief of non-compliance.

8. Sub-processors

Customer authorizes Peleka to engage Sub-processors to Process Customer Personal Data in order to provide the Service. Peleka will:

  • enter into a written agreement with each Sub-processor imposing data protection obligations materially equivalent to those in this DPA, and remain responsible for that Sub-processor’s compliance;
  • provide Customer, on written request to [email protected], with the current list of Sub-processors engaged to Process Customer Personal Data; and
  • give Customer at least 14 days’ advance notice by email of any new Sub-processor (or replacement), giving Customer the opportunity to object on reasonable data-protection grounds. If Customer objects, the parties will work in good faith to resolve the objection; if no resolution is reached, Customer may terminate the Agreement with respect to the affected part of the Service.

9. International Data Transfers

Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to a country not deemed to provide an adequate level of data protection (including the United States), such transfers are made subject to the European Commission’s Standard Contractual Clauses (Controller-to-Processor, Module Two) and, for UK transfers, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs, incorporated into this DPA by reference, or another valid transfer mechanism under applicable Data Protection Laws.

10. CCPA

To the extent Customer Personal Data includes Personal Information of California residents subject to the CCPA, Peleka acts as a “service provider” (not a “third party”) as those terms are defined under the CCPA, and shall not sell or share Customer Personal Data, or retain, use, or disclose it for any purpose other than providing the Service, as further restricted by the CCPA.

11. Liability

Each party’s liability arising out of or related to this DPA is subject to the limitation of liability set out in the Agreement. Nothing in this section is intended to restrict the rights of Data Subjects under Data Protection Laws.

12. Retention and Deletion

Customer controls the retention period for contact data via the Service’s workspace settings (a configurable retention window of 90, 180, 365, or 730 days, or disabled entirely, defaulting to 365 days). Where enabled, Peleka automatically purges Personal Data of contacts who are unsubscribed, bounced, or complained and have been inactive beyond that window. Customer may also erase an individual contact’s data at any time via the Service (see Section 7). Upon termination of the Agreement, Peleka will delete remaining Customer Personal Data in accordance with Section 7.

13. Term

This DPA remains in effect for as long as Peleka Processes Customer Personal Data on Customer’s behalf under the Agreement.

14. Governing Law

This DPA is governed by the laws of the State of Wyoming, without regard to conflict-of-law principles.

15. Privacy Contact

For Data Subject requests, regulator inquiries, or any question about this DPA, contact us at [email protected].

Security Measures

  • Encryption in transit: all connections to the Service and between Service components use TLS/HTTPS.
  • Encryption at rest: sender domain signing keys (DKIM private keys) are encrypted using AES-256-GCM before storage, and the primary database is encrypted at rest at the hosting-provider level.
  • Access control: role-based access within each Customer workspace (viewer/member/editor/admin/owner), enforced server-side on every request; workspace membership is re-verified on each request rather than trusted from a cached token.
  • Tenant isolation: all Customer data is scoped by workspace at the database query level; cross-tenant access is enforced in application logic on every read and write.
  • Session security: authentication cookies are httpOnly and scoped SameSite=strict; passwords are hashed with bcrypt; password changes and resets invalidate all other active sessions.
  • Rate limiting & abuse prevention: API endpoints are rate-limited; suppression lists are enforced before any marketing send to prevent emailing unsubscribed, bounced, or complained recipients.
  • Webhook authenticity: inbound webhooks (Shopify, WooCommerce, Stripe, AWS SNS) are verified via HMAC/signature checks before being trusted.
  • Retention controls: configurable, enforced data-retention windows (see Section 12).
  • Vulnerability management: dependencies are reviewed manually; automated dependency scanning is planned.
  • Sub-processor oversight: Sub-processors are contractually bound to data-protection obligations at least as protective as this DPA.