Data Processing Addendum
Last updated: 6 August 2026
This Addendum forms part of the Terms of Service between ConvexFlow(“Processor”, “we”) and the customer accepting those Terms (“Controller”, “you”). It governs our processing of Lead Data only. Where it conflicts with the Terms, this Addendum prevails for Lead Data.
1. Definitions
Lead Data means personal data relating to visitors to pages you publish through FunnelForge A.I.— contact details submitted to an opt-in form, quiz answers and resulting segment, and traffic data such as UTM parameters. Data Protection Law means the EU GDPR, the UK GDPR, the Brazilian LGPD, and applicable US state privacy laws, each as amended.
2. Roles
You are the controller of Lead Data. We are the processor, and under US state privacy law a service provider. You determine the purposes and means; we process only on your documented instructions, of which the Terms and your use of the Service are the complete set. We will tell you if an instruction appears to infringe Data Protection Law.
3. Your responsibilities as controller
You are responsible for having a lawful basis to collect Lead Data, for the notice and consent presented on your published pages, for the accuracy of what you ask, and for responding to data-subject requests. This is a real obligation, not boilerplate: the Service lets you publish a form and a quiz, but it does not supply your privacy notice or verify that you are entitled to contact the people who complete them.
4. Our obligations
- Purpose limitation. We process Lead Data solely to provide the Service. We do not sell it, do not use it for our own marketing, do not combine it with data from other sources, and do not use it to train AI models.
- Confidentiality. Personnel with access are bound by confidentiality and access is least-privilege.
- Security. The measures in Annex II.
- Assistance. We will assist you, so far as reasonable, with data-subject requests, impact assessments and regulator enquiries. Requests we receive directly from a lead are forwarded to you, not actioned by us.
- Breach notification. We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal-data breach affecting Lead Data, with the information available to us at the time.
5. Sub-processors
You give general authorisation for the sub-processors listed at /subprocessors. We will give at least 30 days’ notice before adding or replacing one, during which you may object on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected part of the Service. Each sub-processor is bound by obligations no less protective than these, and we remain liable for their performance.
6. International transfers
Where Lead Data is transferred out of the EEA or the UK, the parties adopt the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), whose Annexes are completed by Annexes I and II below, and the UK International Data Transfer Addendum where the UK GDPR applies. Our database and file storage are hosted in Canada; other sub-processors process in the United States, as listed at /subprocessors.
7. Deletion and return
You may export or delete Lead Data at any time through the Service. On termination we will delete Lead Data within 30 days, except where retention is required by law. Published pages are immutable snapshots; deleting a funnel does not retroactively alter a snapshot already served, and unpublishing is the way to stop a page collecting further leads.
8. Audit
On reasonable written request, no more than once a year, we will provide the information necessary to demonstrate compliance with this Addendum, including a description of our technical and organisational measures. This obligation is satisfied by documentation; on-site audits are not offered.
9. Liability
Liability under this Addendum is subject to the limitations in the Terms, including the liability cap in §10, to the maximum extent permitted by applicable law. Nothing here limits a data subject’s rights against either party under Data Protection Law.
Annex I — Description of processing
- Subject matter: provision of FunnelForge A.I..
- Duration: the term of your account, plus the deletion window in §7.
- Nature and purpose: collecting, storing, segmenting and delivering to you the details of visitors who opt in on your published pages, and sending those visitors the lead magnet they requested.
- Categories of data subject: visitors to your published pages who submit a form or complete a quiz.
- Categories of personal data: email address; any additional form fields you configure; quiz answers and resulting segment; UTM parameters and visit analytics.
- Special categories: none requested by the Service. You must not configure a form field or quiz question that elicits special-category data(health, beliefs, biometrics and the like) without your own lawful basis and notice — the Service does not detect or prevent this.
Annex II — Technical and organisational measures
These describe controls the Service actually implements:
- Tenant isolation:row-level security on every table, so one customer’s leads are not reachable from another’s session.
- Privilege separation: the elevated service-role credential is confined to server-only modules and never reaches a browser bundle; column-level grants prevent self-promotion and credit minting regardless of application code.
- Encryption: in transit via TLS; at rest by the database provider.
- Input validation and output escaping at every boundary; a scheme allowlist on links; no raw HTML injection anywhere in the render path.
- Immutable publishing: a published page is a snapshot, so editing a funnel cannot silently change what a visitor sees or what a live form collects.
- Rate limiting and abuse controls on public endpoints.
- Access control: least-privilege administrative access; authentication managed by our identity provider.
These measures may be updated as the Service evolves, provided the level of protection is not reduced.