Data Processing Agreement (DPA)
Effective Date: October 3, 2026
On This Page
This Data Processing Agreement ("DPA") governs the processing of personal data by Periscopify AS ("Data Processor") on behalf of the customer ("Data Controller") in connection with the provision of the Peri Monitor SaaS platform under the Periscopify Terms and Conditions. This DPA complies with Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR).
1. Scope, Purpose, and Categories of Data
- Purpose: The Processor processes personal data solely to provide, operate, and maintain the Peri Monitor AI Visibility and GEO intelligence platform as instructed by the Controller.
- Subject Matter: Monitoring, measuring, and reporting brand and domain visibility across artificial intelligence platforms and search surfaces.
- Categories of Data Subjects: Authorized employees, contractors, consultants, and advisors designated by the Controller.
- Types of Personal Data:
- Account Identifiers: Name, professional email address, role, profile picture.
- Authentication & Access: IP addresses, login timestamps, cryptographic session tokens, user permission levels (Admin, Editor, Reader).
- Interaction Data: User audit logs, system feedback, and support inquiries submitted through the platform.
- Special Categories of Data: No sensitive personal data (as defined in GDPR Article 9) is processed or intended to be processed within the service.
2. Location of Data Processing & Hosting
All customer relational data, prompt records, measurement logs, and user credentials are systematically stored and processed within the European Economic Area (EEA).
- Primary Database Hosting: Amazon Web Services (AWS) in Dublin, Ireland (Region:
eu-west-1), provisioned and managed via Supabase Cloud (aws-1-eu-west-1.pooler.supabase.com). Data does not leave the EU/EEA.
3. Obligations of the Data Processor
Periscopify AS undertakes to:
- Process personal data solely on documented instructions from the Controller, including with regard to transfers of personal data outside the EEA, unless required by applicable European or Norwegian law.
- Ensure that all personnel authorized to process personal data have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement robust technical and organizational security measures pursuant to GDPR Article 32, including PostgreSQL Row Level Security (RLS) data isolation, end-to-end transport encryption (TLS 1.3), AES-256 encryption at rest, and cryptographic hashing of API credentials.
- Promptly notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of any accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to personal data (Personal Data Breach).
- Assist the Controller by appropriate technical measures in fulfilling obligations to respond to data subjects exercising their GDPR rights (access, rectification, erasure, data portability).
- Upon termination of the service, delete or return all personal data to the Controller, unless mandatory Norwegian or EU statutory retention rules require storage.
4. Authorized Sub-processors
The Controller grants general written authorization to Periscopify AS to engage the following trusted sub-processors:
| Sub-processor | Purpose | Processing Location | Data Handled |
|---|---|---|---|
| Supabase Cloud / AWS | Managed PostgreSQL Database, Auth & Edge Infrastructure | Dublin, Ireland (EU / eu-west-1) | User accounts, workspace configurations, audit logs |
| Brevo (Sendinblue SAS) | Transactional emails, system notifications and support dispatches | France / Germany (EU) | Recipient email address, name and message content |
| Stripe Payments Europe Ltd. | Subscription billing, checkout, and invoicing | Dublin, Ireland (EU) | Billing contact details, corporate address, payment tokens |
| DataForSEO | Aggregation of public AI model answers & SERP data | EU / US (Standard Contractual Clauses) | Search terms, public domain targets (No personal data) |
Periscopify AS shall impose data protection obligations on any sub-processor no less protective than those set out in this DPA.
5. Audit Rights & Inquiries
The Controller has the right to verify compliance with this DPA. Upon written request, Periscopify AS shall provide reasonable compliance documentation, summary audit logs, or third-party certifications. Inquiries regarding data processing may be directed to: hello@periscopify.com.