Data Processing Addendum (DPA)
Version: 2.0.0 Effective Date: July 19, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Merchant ("Controller") and Matteo De Giuseppe, operating the SetRoasFlow platform ("Processor" or "SetRoasFlow").
This DPA applies whenever SetRoasFlow processes Personal Data on behalf of the Merchant in connection with the Services.
Where applicable, this DPA is intended to satisfy the requirements of applicable data protection laws, including the General Data Protection Regulation ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection ("FADP") and applicable U.S. privacy laws.
1. Purpose
The purpose of this DPA is to define the responsibilities of the parties regarding the processing of Personal Data carried out through the SetRoasFlow platform.
This DPA applies exclusively to Merchant Customer Data processed by SetRoasFlow on behalf of the Merchant.
It does not apply to Personal Data processed by SetRoasFlow as an independent Controller, including information relating to:
- Merchant accounts;
- billing;
- customer support;
- website visitors;
- platform security;
- legal compliance.
Such processing is governed by the SetRoasFlow Privacy Policy.
2. Definitions
Unless otherwise defined in this DPA, capitalized terms have the meaning given in the Terms of Service.
For purposes of this DPA:
Controller means the Merchant determining the purposes and means of processing Merchant Customer Data.
Processor means SetRoasFlow, processing Merchant Customer Data solely on behalf of the Controller.
Merchant Customer Data means Personal Data transmitted to SetRoasFlow through Connected Properties using supported Collection Methods.
Processing means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion or destruction.
3. Subject Matter
SetRoasFlow provides a privacy-first Customer Data Platform that processes Merchant Customer Data for purposes including:
- server-side event processing;
- customer identity resolution;
- Customer Profile generation;
- audience segmentation;
- conversion routing;
- analytics;
- synchronization with Merchant-selected Destinations.
Processing is performed solely for the benefit of the Merchant and according to the Merchant's documented instructions.
4. Duration
This DPA remains in effect for as long as SetRoasFlow processes Merchant Customer Data on behalf of the Merchant.
Upon termination of the Services, Personal Data will be handled in accordance with the Terms of Service, this DPA and the Data Retention Policy.
5. Nature and Purpose of Processing
Depending on the Merchant's configuration, SetRoasFlow may perform activities including:
- receiving events;
- validating requests;
- storing customer identifiers;
- generating Customer Profiles;
- calculating customer metrics;
- building Merchant-defined audiences;
- routing conversions;
- synchronizing data with Merchant-selected Destinations;
- maintaining operational logs;
- securing the platform.
SetRoasFlow does not determine the commercial purposes for which Merchant Customer Data is processed.
Those purposes are determined exclusively by the Merchant.
6. Categories of Personal Data
Depending on the Merchant's implementation, Personal Data processed may include:
- customer identifiers;
- email addresses;
- telephone numbers;
- browser identifiers;
- device identifiers;
- IP addresses;
- order information;
- transaction values;
- product information;
- attribution identifiers;
- consent signals;
- technical metadata.
The Merchant remains responsible for determining which categories of Personal Data are transmitted to SetRoasFlow.
7. Categories of Data Subjects
Data Subjects may include:
- customers;
- prospective customers;
- website visitors;
- purchasers;
- newsletter subscribers;
- users of Connected Properties.
The exact categories depend on the Merchant's implementation of the Services.
8. Controller Responsibilities
The Merchant represents and warrants that it:
- has an appropriate legal basis for processing Personal Data;
- has provided required privacy notices;
- has obtained consent where required;
- has authority to instruct SetRoasFlow;
- complies with applicable privacy laws.
The Merchant is solely responsible for determining:
- why Personal Data is processed;
- which Destinations receive Personal Data;
- which Collection Methods are enabled;
- retention requirements applicable to its business.
SetRoasFlow is not responsible for the Merchant's compliance with laws applicable to its own business.
9. Processor Obligations
SetRoasFlow shall process Merchant Customer Data only:
- on documented instructions from the Merchant;
- for the purposes described in the Terms of Service and this DPA;
- as required by applicable law.
If SetRoasFlow is required by law to process Personal Data beyond the Merchant's instructions, SetRoasFlow will notify the Merchant before such processing unless prohibited by law.
SetRoasFlow will not:
- sell Merchant Customer Data;
- use Merchant Customer Data for its own advertising purposes;
- determine independent commercial purposes for processing Merchant Customer Data;
- disclose Merchant Customer Data except as permitted by this DPA or required by law.
10. Personnel and Confidentiality
SetRoasFlow ensures that any person authorized to process Merchant Customer Data:
- is bound by appropriate confidentiality obligations;
- receives access only where necessary to perform assigned duties;
- processes Personal Data solely for authorized purposes.
Access to production systems is limited according to the principle of least privilege.
11. Security Measures
SetRoasFlow implements technical and organizational measures designed to protect Merchant Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorized access.
Depending on the Services used, these measures may include:
- encrypted communications using TLS;
- secure cloud infrastructure;
- role-based access controls;
- authentication and authorization mechanisms;
- webhook signature verification;
- cryptographic hashing of supported identifiers before transmission to compatible Destinations;
- infrastructure monitoring;
- audit logging;
- secret management;
- vulnerability management;
- disaster recovery procedures.
Security measures may evolve over time provided that the overall level of protection is not materially reduced.
12. Assistance to the Controller
Taking into account the nature of the processing and the information available to SetRoasFlow, SetRoasFlow will provide reasonable assistance to the Merchant in fulfilling obligations relating to:
- data subject requests;
- security obligations;
- breach notifications;
- privacy impact assessments where applicable;
- consultations with supervisory authorities where legally required.
Such assistance may be subject to reasonable administrative costs where permitted by applicable law or contract.
13. Personal Data Breaches
If SetRoasFlow becomes aware of a confirmed Personal Data Breach affecting Merchant Customer Data, SetRoasFlow will, without undue delay:
- notify the affected Merchant;
- provide available information regarding the nature of the incident;
- describe the categories of data involved where known;
- communicate measures taken to mitigate the incident;
- provide additional relevant information as it becomes available.
SetRoasFlow does not undertake to notify individual data subjects directly unless required by applicable law.
14. Subprocessors
The Merchant authorizes SetRoasFlow to engage subprocessors necessary for providing the Services.
Current subprocessors are identified in the Subprocessors List published by SetRoasFlow.
SetRoasFlow will ensure that each subprocessor is subject to contractual obligations providing an appropriate level of protection for Personal Data.
SetRoasFlow remains responsible for the performance of its subprocessors to the extent required by applicable law.
15. Merchant-selected Destinations
The Merchant acknowledges that Destinations configured within the Services are selected solely by the Merchant.
Where SetRoasFlow transmits Merchant Customer Data to a Destination configured by the Merchant, such transmission is performed according to the Merchant's documented instructions.
The Merchant remains responsible for:
- selecting appropriate Destinations;
- determining the legal basis for such disclosures;
- ensuring that use of each Destination complies with applicable law;
- reviewing the privacy practices of each Destination.
Merchant-selected Destinations are distinct from SetRoasFlow's infrastructure subprocessors.
16. International Transfers
Merchant Customer Data may be processed in jurisdictions outside the country in which it originated.
Where required by applicable law, SetRoasFlow will implement appropriate safeguards intended to protect Personal Data during international transfers.
Where Personal Data is transmitted to Merchant-selected Destinations, the Merchant remains responsible for determining whether such transfers comply with applicable law.
17. Data Subject Requests
Where SetRoasFlow receives a request relating to Merchant Customer Data directly from a data subject, SetRoasFlow will, where appropriate:
- promptly inform the Merchant;
- refrain from responding directly except where legally required;
- provide reasonable assistance to enable the Merchant to respond.
Nothing in this section limits SetRoasFlow's ability to respond where required by applicable law.
18. Return and Deletion of Personal Data
Upon termination of the Services, and subject to applicable law, SetRoasFlow will delete or anonymize Merchant Customer Data within a commercially reasonable period, unless:
- the Merchant requests continued retention where supported by the Services;
- retention is required by applicable law;
- retention is necessary to establish, exercise or defend legal claims;
- temporary retention is required for disaster recovery or backup restoration procedures.
Backups containing Merchant Customer Data will be overwritten or securely deleted in accordance with SetRoasFlow's Data Retention Policy.
19. Audits and Information Requests
Recognizing the cloud-native and multi-tenant nature of the Services, SetRoasFlow will make available reasonable information demonstrating compliance with this DPA.
Where reasonably necessary and proportionate, the Merchant may request additional information regarding SetRoasFlow's security and privacy practices.
Physical inspections of production infrastructure are not permitted unless:
- required by applicable law;
- mutually agreed in writing;
- strictly necessary to verify compliance.
Nothing in this section requires SetRoasFlow to disclose:
- trade secrets;
- source code;
- security credentials;
- confidential information relating to other customers;
- information that would compromise platform security.
20. California Privacy Addendum
To the extent applicable under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), SetRoasFlow acts as a Service Provider with respect to Merchant Customer Data processed on behalf of the Merchant.
SetRoasFlow:
- processes Personal Information solely for the business purposes specified by the Merchant;
- does not sell Personal Information received from the Merchant;
- does not share Personal Information for cross-context behavioral advertising except as instructed by the Merchant through configured Destinations;
- does not retain, use or disclose Personal Information outside the direct business relationship with the Merchant except as permitted by applicable law.
Nothing in this section limits processing expressly permitted under the CCPA/CPRA.
21. Limitation of Liability
The liability of each party arising under this DPA shall be subject to the limitations of liability contained in the Terms of Service, except where applicable law provides otherwise.
Nothing in this DPA limits liability that cannot legally be limited under applicable law.
22. Order of Precedence
In the event of any conflict between:
- this DPA;
- the Terms of Service;
- another agreement between the parties,
this DPA shall prevail solely with respect to the processing of Merchant Customer Data.
23. Amendments
SetRoasFlow may update this DPA where reasonably necessary to:
- reflect changes in applicable law;
- reflect new platform functionality;
- reflect changes to subprocessors;
- improve clarity;
- address regulatory guidance.
Material changes will become effective after reasonable notice to Merchants, unless immediate changes are required by law.
24. Contact
Questions regarding this Data Processing Addendum may be directed to:
Operator
Matteo De Giuseppe
Italy
Version History
| Version | Date | Description |
|---|---|---|
| 2.0.0 | July 19, 2026 | Complete rewrite reflecting SetRoasFlow as a privacy-first Customer Data Platform supporting multiple collection methods and merchant-selected destinations. |
End of Data Processing Addendum