🚧 Onboardics is in private beta while we finish privacy, billing, and reliability hardening.

This Data Processing Agreement ("DPA") forms part of the agreement governing a customer's use of Onboardics (the "Agreement") when Onboardics processes Customer Personal Data on that customer's behalf. It applies from the date the customer accepts an Agreement that incorporates this DPA. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.

This DPA is intended to document the parties' processor and service-provider relationship. It is not a certification that either party complies with every law in every jurisdiction.

1. Parties, Roles, and Definitions

The customer identified in the Agreement is "Customer." Onboardics LLC, a Delaware limited liability company with its registered address at 8 The Green, Suite B, Dover, DE 19901, is "Onboardics." "Customer Personal Data" means personal data, personal information, or similar protected information that Onboardics processes on Customer's behalf through the service.

Customer is the controller or business and determines why and how Customer Personal Data is processed. If Customer processes Customer Personal Data for another controller or business, Customer is the processor or service provider and confirms it is authorized to instruct Onboardics. Onboardics is the processor, subprocessor, service provider, or contractor, as applicable. "Data Protection Laws" means privacy and data-protection laws applicable to that processing, including the GDPR and CCPA where they apply.

This DPA does not govern personal data for which Onboardics independently determines the purposes and means, such as its own website marketing, business-contact, billing, fraud-prevention, and legal-compliance records. Those activities are described in the Onboardics Privacy Policy.

2. Processing Details

Subject matterOperating, securing, supporting, and winding down the Onboardics analytics, dashboard, customer-configured messaging, integration, and support services.
DurationThe term of the Agreement and the deletion period in Section 6, unless law requires longer retention.
Nature of processingCollection when enabled, receipt, transmission, storage, organization, retrieval, analysis, display, export, restriction, and deletion.
PurposesProviding Customer-requested analytics and features; authenticating authorized users; delivering configured communications and integrations; customer support; service security, monitoring, troubleshooting, and deletion.
Data subjectsCustomer's website or application visitors and end users; Customer's authorized account users and team members; and recipients of Customer-configured communications.

Behavioral and technical data

When analytics collection is enabled, the tracking snippet can process:

Customer-provided identity, account, and configuration data

Collection limitations

The snippet does not automatically read form-field values, create DOM snapshots, record video, or generate a device fingerprint. It does not set browser cookies, but it uses localStorage and sessionStorage. The Onboardics events table has no IP-address field, although hosting, authentication, and security providers may process ordinary connection and request metadata. Customer-supplied custom properties, visible page text, URLs, and error strings can contain personal data; Customer must configure the service accordingly.

The service is not designed for special-category or sensitive personal data, payment-card data, account passwords, private messages, precise geolocation, or children's data. Customer must not submit those data unless the parties first agree in writing on appropriate instructions and safeguards.

3. Customer Instructions and Responsibilities

Customer instructs Onboardics to process Customer Personal Data only as necessary to provide the service under the Agreement, through Customer's documented configuration and use of the service, and through additional lawful written instructions accepted by Onboardics.

Customer discloses Customer Personal Data to Onboardics only for the limited and specified business purposes described in Section 2.

Customer is responsible for the lawfulness, accuracy, and minimization of Customer Personal Data and for providing required notices and obtaining any required consent before enabling collection. This includes compliance with applicable consent, electronic-communications, recording, interception, employment, and children's-privacy laws. Customer is also responsible for configuring consent controls, masking or excluding sensitive surfaces, and governing destinations it configures, such as Slack or custom webhooks.

Customer will not instruct Onboardics to process data unlawfully. Onboardics will promptly inform Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Laws, unless law prohibits that notice.

4. Onboardics Obligations

Onboardics will process Customer Personal Data only on documented instructions from Customer, including for transfers, unless applicable law requires otherwise. If law requires processing beyond those instructions, Onboardics will notify Customer before processing unless legally prohibited.

5. Current Wind-Down and AI Status

Service status as of July 12, 2026: Onboardics v1 is in wind-down. New account registration is disabled. The published v1 snippet is an inert compatibility stub that performs no analytics collection, network requests, browser storage, event registration, or page rendering. The public event, flow, badge, and snippet-error routes on the production service at onboardics.com return inert responses at an application boundary before their legacy handlers perform authentication, database access, rate limiting, or error reporting. Event responses also instruct historical snippets to stop. Reactivation through the customer and administrative controls is locked while this boundary is active. Previously cached or self-hosted historical snippets cannot be remotely erased and may still execute browser-local code until the site operator replaces or disables them; the production server boundary prevents those copies from entering the legacy application handlers. This status does not itself delete previously stored data.

New Anthropic processing is suspended. Direct application calls to Anthropic are blocked before the relevant handler reads Customer Personal Data or makes an outbound request, subject to authentication occurring first on the authenticated scheduled route. An automated source check covers the current direct Anthropic call sites. Previously generated output and frozen briefing snapshots may remain stored or displayable in Onboardics; they have not all been purged. Before the suspension, AI features could process pseudonymous session-level analytics and Customer-supplied identity or account fields, including name, email, user ID, or plan where supplied by Customer; processing was not limited to aggregate funnel metrics.

Onboardics will provide the subprocessor notice described in Section 7 and update this processing description before re-enabling Anthropic processing.

6. Retention, Return, and Deletion

Automated behavioral-event retention

PlanEvent-row retention
Free30 days
Diagnose30 days
Deploy90 days
ScaleNo automatic age-based deletion while the account remains active
BusinessNo automatic age-based deletion while the account remains active

The table applies only to rows in the events table. A daily automated job deletes event rows older than the applicable plan window. It does not currently apply an age-based deletion schedule to project configuration, account records, email-delivery metadata, cached AI output, or frozen briefing-share snapshots.

Customer may request a machine-readable return of Customer Personal Data before deletion, where technically feasible, or may submit a verified deletion or restriction instruction to tyler@onboardics.com. Onboardics will verify and fulfill those requests manually within 30 days unless law requires retention or the parties agree to a different period. A complete project export and account deletion are not presently self-service.

At the end of the service, Onboardics will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies within 30 days, except data that applicable law requires Onboardics to retain. Any Customer Personal Data remaining in routine backups will remain protected and will be deleted through the applicable backup lifecycle.

7. Subprocessors and Customer-Directed Destinations

SubprocessorPurposePrimary location
Supabase (AWS infrastructure)Database, authentication, and backend platform servicesUnited States
Vercel Inc.Application hosting, serverless functions, logs, and scheduled jobsUnited States and global edge network
Functional Software, Inc. (Sentry)Dashboard and API error monitoring and performance tracing, plus historical installed-snippet error monitoring; new v1 snippet-error reports are currently blocked. Diagnostic data can include account ID or email, project ID, redacted URL, user agent, and error contextUnited States
Google LLCGoogle OAuth authentication for authorized account usersUnited States and global infrastructure
Resend, Inc.Account and transactional email deliveryUnited States
Anthropic, PBCInactive for new processing as of July 12, 2026. Historical AI analysis as described in Section 5; direct Anthropic calls are currently blocked.United States

Stripe, Brevo, Google Analytics, and Termly support Onboardics's own billing, waitlist, marketing site, or consent-management activity. Onboardics does not use them to process Customer behavioral-event data on Customer's behalf.

Customer gives Onboardics general written authorization to use the subprocessors above. Onboardics will impose data-protection obligations on each active subprocessor that are no less protective than the relevant obligations in this DPA. Onboardics remains responsible for each subprocessor's performance to the extent required by applicable law.

Onboardics will provide at least 30 days' advance notice before a new or replacement subprocessor processes Customer Personal Data, or before reactivating Anthropic. If that notice period cannot be provided, Onboardics will obtain Customer's specific written authorization before the subprocessor processes Customer Personal Data. Customer may object on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, Customer may terminate the affected service.

Customer may configure destinations such as Slack or custom webhooks. Onboardics sends data to those destinations only on Customer's instructions. Customer is responsible for authorizing and governing those destination providers.

8. Security Measures

No system is completely secure. These measures describe current controls and do not state that Onboardics holds a particular security certification.

9. Data Subject Requests and Compliance Assistance

Customer is primarily responsible for responding to data subjects and regulators. Taking into account the nature of processing, Onboardics will provide reasonable assistance with access, correction, deletion, restriction, objection, and portability requests, including by using available technical and organizational measures.

The dashboard displays recent event rows and can export the currently loaded filtered rows as CSV. A complete project export is not presently self-service. Customer may request a complete machine-readable export, deletion, or restriction at tyler@onboardics.com. Onboardics will verify the request, search the relevant event, cache, configuration, communication, and sharing stores, and respond within 30 days unless applicable law requires a shorter period.

If Onboardics receives a request directly from a data subject concerning Customer Personal Data, Onboardics will notify Customer and will not respond except on Customer's instructions or as required by law. Onboardics will also provide reasonable information and assistance for Customer's security obligations, data-protection impact assessments, prior consultations, and regulatory inquiries under applicable Data Protection Laws.

10. Personal Data Breaches

Onboardics will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and data subjects, likely consequences, mitigation taken or proposed, and a contact for follow-up. Onboardics will reasonably cooperate with Customer's investigation, remediation, and legally required notifications.

11. International Transfers

Onboardics and the subprocessors listed above primarily process data in the United States. Customer authorizes those transfers only where a lawful transfer mechanism applies.

This public DPA does not by itself complete a GDPR Chapter V transfer mechanism. Before Customer submits data requiring safeguards for a transfer from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, the parties must execute the applicable Standard Contractual Clauses and completed annexes, transfer addendum, or another valid mechanism. Customer must contact tyler@onboardics.com and must not enable the affected processing until that mechanism is in place.

12. Information and Audits

Onboardics will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to audits or inspections by Customer or an independent auditor bound by confidentiality. Audits must be reasonable in scope, scheduled with reasonable advance notice, avoid disruption and exposure of other customers' data, and ordinarily occur no more than once per year unless a regulator, personal data breach, or credible evidence of material noncompliance requires otherwise.

Onboardics may satisfy a request with current policies, system descriptions, or independent reports where those materials provide the requested assurance. Customer bears its audit costs unless an audit identifies material noncompliance by Onboardics.

13. Contact

For questions, instructions, export or deletion requests, subprocessor objections, or notices under this DPA:

Tyler Allen, Founder
Onboardics LLC
8 The Green, Suite B, Dover, DE 19901
Email: tyler@onboardics.com
Website: onboardics.com