This Data Processing Agreement ("DPA") forms part of the agreement governing a customer's use of Onboardics (the "Agreement") when Onboardics processes Customer Personal Data on that customer's behalf. It applies from the date the customer accepts an Agreement that incorporates this DPA. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.
This DPA is intended to document the parties' processor and service-provider relationship. It is not a certification that either party complies with every law in every jurisdiction.
1. Parties, Roles, and Definitions
The customer identified in the Agreement is "Customer." Onboardics LLC, a Delaware limited liability company with its registered address at 8 The Green, Suite B, Dover, DE 19901, is "Onboardics." "Customer Personal Data" means personal data, personal information, or similar protected information that Onboardics processes on Customer's behalf through the service.
Customer is the controller or business and determines why and how Customer Personal Data is processed. If Customer processes Customer Personal Data for another controller or business, Customer is the processor or service provider and confirms it is authorized to instruct Onboardics. Onboardics is the processor, subprocessor, service provider, or contractor, as applicable. "Data Protection Laws" means privacy and data-protection laws applicable to that processing, including the GDPR and CCPA where they apply.
This DPA does not govern personal data for which Onboardics independently determines the purposes and means, such as its own website marketing, business-contact, billing, fraud-prevention, and legal-compliance records. Those activities are described in the Onboardics Privacy Policy.
2. Processing Details
| Subject matter | Operating, securing, supporting, and winding down the Onboardics analytics, dashboard, customer-configured messaging, integration, and support services. |
|---|---|
| Duration | The term of the Agreement and the deletion period in Section 6, unless law requires longer retention. |
| Nature of processing | Collection when enabled, receipt, transmission, storage, organization, retrieval, analysis, display, export, restriction, and deletion. |
| Purposes | Providing Customer-requested analytics and features; authenticating authorized users; delivering configured communications and integrations; customer support; service security, monitoring, troubleshooting, and deletion. |
| Data subjects | Customer's website or application visitors and end users; Customer's authorized account users and team members; and recipients of Customer-configured communications. |
Behavioral and technical data
When analytics collection is enabled, the tracking snippet can process:
- Page URL and path, page title, referrer and first-touch referrer, selected campaign parameters, event type, and timestamp
- Pseudonymous session and user UUIDs stored in localStorage or sessionStorage
- Click coordinates, element selectors and descriptors, limited visible click text, rage-click frequency, and flow interactions
- Form focus, blur, and submit interactions and form or field names and identifiers, but not automatically captured form-field values
- Time-on-page, scroll-depth, visibility, idle, session, viewport, browser, device-category, and detected-framework data
- Customer-defined event names and properties sent through the tracking API
- Limited snippet-error telemetry, including snippet version, redacted URL, browser user agent, error message or stack, project identifier, and diagnostic context
Customer-provided identity, account, and configuration data
- Email address, Customer-defined user ID, display name, plan or tier, signup date, and any custom properties Customer sends through
identify()ortrack() - Authorized account user name, email, authentication identifier, project membership, service configuration, and support or delivery metadata
- Project, funnel, segment, milestone, flow, messaging, integration, and sharing configuration supplied by Customer
Collection limitations
The snippet does not automatically read form-field values, create DOM snapshots, record video, or generate a device fingerprint. It does not set browser cookies, but it uses localStorage and sessionStorage. The Onboardics events table has no IP-address field, although hosting, authentication, and security providers may process ordinary connection and request metadata. Customer-supplied custom properties, visible page text, URLs, and error strings can contain personal data; Customer must configure the service accordingly.
The service is not designed for special-category or sensitive personal data, payment-card data, account passwords, private messages, precise geolocation, or children's data. Customer must not submit those data unless the parties first agree in writing on appropriate instructions and safeguards.
3. Customer Instructions and Responsibilities
Customer instructs Onboardics to process Customer Personal Data only as necessary to provide the service under the Agreement, through Customer's documented configuration and use of the service, and through additional lawful written instructions accepted by Onboardics.
Customer discloses Customer Personal Data to Onboardics only for the limited and specified business purposes described in Section 2.
Customer is responsible for the lawfulness, accuracy, and minimization of Customer Personal Data and for providing required notices and obtaining any required consent before enabling collection. This includes compliance with applicable consent, electronic-communications, recording, interception, employment, and children's-privacy laws. Customer is also responsible for configuring consent controls, masking or excluding sensitive surfaces, and governing destinations it configures, such as Slack or custom webhooks.
Customer will not instruct Onboardics to process data unlawfully. Onboardics will promptly inform Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Laws, unless law prohibits that notice.
4. Onboardics Obligations
Onboardics will process Customer Personal Data only on documented instructions from Customer, including for transfers, unless applicable law requires otherwise. If law requires processing beyond those instructions, Onboardics will notify Customer before processing unless legally prohibited.
- Personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
- Onboardics will implement and maintain the security measures in Section 8.
- Onboardics will provide the assistance described in Sections 9 and 10, taking into account the nature of the processing and information available to Onboardics.
- Onboardics will not sell or share Customer Personal Data; retain, use, or disclose it outside the specific purposes in this DPA or the direct business relationship; combine it across customers or with data collected from Onboardics's own consumer interactions except as permitted by law; or use it for unrelated commercial purposes.
- Onboardics will provide the same level of privacy protection required of a service provider or contractor under the CCPA where applicable.
- Onboardics certifies that it understands the CCPA restrictions stated in this DPA and will comply with them where the CCPA applies.
- If Onboardics determines it can no longer meet its obligations under applicable Data Protection Laws, it will notify Customer. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
5. Current Wind-Down and AI Status
Service status as of July 12, 2026: Onboardics v1 is in wind-down. New account registration is disabled. The published v1 snippet is an inert compatibility stub that performs no analytics collection, network requests, browser storage, event registration, or page rendering. The public event, flow, badge, and snippet-error routes on the production service at onboardics.com return inert responses at an application boundary before their legacy handlers perform authentication, database access, rate limiting, or error reporting. Event responses also instruct historical snippets to stop. Reactivation through the customer and administrative controls is locked while this boundary is active. Previously cached or self-hosted historical snippets cannot be remotely erased and may still execute browser-local code until the site operator replaces or disables them; the production server boundary prevents those copies from entering the legacy application handlers. This status does not itself delete previously stored data.
New Anthropic processing is suspended. Direct application calls to Anthropic are blocked before the relevant handler reads Customer Personal Data or makes an outbound request, subject to authentication occurring first on the authenticated scheduled route. An automated source check covers the current direct Anthropic call sites. Previously generated output and frozen briefing snapshots may remain stored or displayable in Onboardics; they have not all been purged. Before the suspension, AI features could process pseudonymous session-level analytics and Customer-supplied identity or account fields, including name, email, user ID, or plan where supplied by Customer; processing was not limited to aggregate funnel metrics.
Onboardics will provide the subprocessor notice described in Section 7 and update this processing description before re-enabling Anthropic processing.
6. Retention, Return, and Deletion
Automated behavioral-event retention
| Plan | Event-row retention |
|---|---|
| Free | 30 days |
| Diagnose | 30 days |
| Deploy | 90 days |
| Scale | No automatic age-based deletion while the account remains active |
| Business | No automatic age-based deletion while the account remains active |
The table applies only to rows in the events table. A daily automated job deletes event rows older than the applicable plan window. It does not currently apply an age-based deletion schedule to project configuration, account records, email-delivery metadata, cached AI output, or frozen briefing-share snapshots.
Customer may request a machine-readable return of Customer Personal Data before deletion, where technically feasible, or may submit a verified deletion or restriction instruction to tyler@onboardics.com. Onboardics will verify and fulfill those requests manually within 30 days unless law requires retention or the parties agree to a different period. A complete project export and account deletion are not presently self-service.
At the end of the service, Onboardics will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies within 30 days, except data that applicable law requires Onboardics to retain. Any Customer Personal Data remaining in routine backups will remain protected and will be deleted through the applicable backup lifecycle.
7. Subprocessors and Customer-Directed Destinations
| Subprocessor | Purpose | Primary location |
|---|---|---|
| Supabase (AWS infrastructure) | Database, authentication, and backend platform services | United States |
| Vercel Inc. | Application hosting, serverless functions, logs, and scheduled jobs | United States and global edge network |
| Functional Software, Inc. (Sentry) | Dashboard and API error monitoring and performance tracing, plus historical installed-snippet error monitoring; new v1 snippet-error reports are currently blocked. Diagnostic data can include account ID or email, project ID, redacted URL, user agent, and error context | United States |
| Google LLC | Google OAuth authentication for authorized account users | United States and global infrastructure |
| Resend, Inc. | Account and transactional email delivery | United States |
| Anthropic, PBC | Inactive for new processing as of July 12, 2026. Historical AI analysis as described in Section 5; direct Anthropic calls are currently blocked. | United States |
Stripe, Brevo, Google Analytics, and Termly support Onboardics's own billing, waitlist, marketing site, or consent-management activity. Onboardics does not use them to process Customer behavioral-event data on Customer's behalf.
Customer gives Onboardics general written authorization to use the subprocessors above. Onboardics will impose data-protection obligations on each active subprocessor that are no less protective than the relevant obligations in this DPA. Onboardics remains responsible for each subprocessor's performance to the extent required by applicable law.
Onboardics will provide at least 30 days' advance notice before a new or replacement subprocessor processes Customer Personal Data, or before reactivating Anthropic. If that notice period cannot be provided, Onboardics will obtain Customer's specific written authorization before the subprocessor processes Customer Personal Data. Customer may object on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, Customer may terminate the affected service.
Customer may configure destinations such as Slack or custom webhooks. Onboardics sends data to those destinations only on Customer's instructions. Customer is responsible for authorizing and governing those destination providers.
8. Security Measures
- Application traffic is served over HTTPS by Vercel and Supabase.
- Direct browser database access is protected by Supabase Row Level Security, and authenticated dashboard endpoints apply project-role checks. Customer-authorized public share links and configured integration destinations use separate token or destination controls. Backend routes and scheduled jobs use server-side service-role access.
- Authenticated dashboard APIs validate Supabase sessions and project roles. Public v1 collection routes are currently blocked at the application handler boundary as described in Section 5.
- Onboardics-managed service-role and provider secrets are supplied to server functions through environment variables and are not intentionally embedded in client bundles; browser-safe public keys and monitoring DSNs are excluded.
- Configured browser protections include HSTS, Content Security Policy (including
frame-ancestors), X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. - Current account authentication uses Supabase magic links and Google OAuth. Onboardics does not directly collect account passwords.
- Automated build checks cover tenant-isolation patterns, the current direct Anthropic call boundary, the v1 collection boundary, and the inert published snippet. Monitoring and error reporting support detection and investigation.
No system is completely secure. These measures describe current controls and do not state that Onboardics holds a particular security certification.
9. Data Subject Requests and Compliance Assistance
Customer is primarily responsible for responding to data subjects and regulators. Taking into account the nature of processing, Onboardics will provide reasonable assistance with access, correction, deletion, restriction, objection, and portability requests, including by using available technical and organizational measures.
The dashboard displays recent event rows and can export the currently loaded filtered rows as CSV. A complete project export is not presently self-service. Customer may request a complete machine-readable export, deletion, or restriction at tyler@onboardics.com. Onboardics will verify the request, search the relevant event, cache, configuration, communication, and sharing stores, and respond within 30 days unless applicable law requires a shorter period.
If Onboardics receives a request directly from a data subject concerning Customer Personal Data, Onboardics will notify Customer and will not respond except on Customer's instructions or as required by law. Onboardics will also provide reasonable information and assistance for Customer's security obligations, data-protection impact assessments, prior consultations, and regulatory inquiries under applicable Data Protection Laws.
10. Personal Data Breaches
Onboardics will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and data subjects, likely consequences, mitigation taken or proposed, and a contact for follow-up. Onboardics will reasonably cooperate with Customer's investigation, remediation, and legally required notifications.
11. International Transfers
Onboardics and the subprocessors listed above primarily process data in the United States. Customer authorizes those transfers only where a lawful transfer mechanism applies.
This public DPA does not by itself complete a GDPR Chapter V transfer mechanism. Before Customer submits data requiring safeguards for a transfer from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, the parties must execute the applicable Standard Contractual Clauses and completed annexes, transfer addendum, or another valid mechanism. Customer must contact tyler@onboardics.com and must not enable the affected processing until that mechanism is in place.
12. Information and Audits
Onboardics will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to audits or inspections by Customer or an independent auditor bound by confidentiality. Audits must be reasonable in scope, scheduled with reasonable advance notice, avoid disruption and exposure of other customers' data, and ordinarily occur no more than once per year unless a regulator, personal data breach, or credible evidence of material noncompliance requires otherwise.
Onboardics may satisfy a request with current policies, system descriptions, or independent reports where those materials provide the requested assurance. Customer bears its audit costs unless an audit identifies material noncompliance by Onboardics.
13. Contact
For questions, instructions, export or deletion requests, subprocessor objections, or notices under this DPA:
Tyler Allen, Founder
Onboardics LLC
8 The Green, Suite B, Dover, DE 19901
Email: tyler@onboardics.com
Website: onboardics.com