src/lib/legal.ts to remove this banner.The processor terms that apply when ChurnLens handles personal data on your behalf. These form part of our Terms of Service.
Last updated: [EFFECTIVE DATE]
This Agreement applies where [LEGAL ENTITY NAME] ("Processor") processes personal data on behalf of a customer ("Controller") in providing ChurnLens. It is incorporated into and governed by our Terms of Service, and takes effect when you begin using the service. No signature is required, but we will countersign a copy on request to privacy@churnlens.com.
You are the Controller of your former customers' personal data. You decide that surveys are sent and what they ask. We are your Processor and act only on your instructions. Please read this document rather than assuming its contents — it allocates real obligations to you.
Where the personal data concerned is subject to South Africa's Protection of Personal Information Act (POPIA), this Agreement is also the written contract that POPIA section 21 requires between a "responsible party" and an "operator" before the latter may process personal data on the former's behalf. Throughout this document, "Controller" and "responsible party" are used interchangeably, as are "Processor" and "operator" — the same allocation of responsibility, under two different statutes.
We process personal data only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we will tell you before processing, unless that law prohibits it. Your instructions are given through your configuration and use of the service, and through this Agreement and the Terms.
We will tell you if, in our opinion, an instruction infringes applicable data protection law.
We ensure that anyone authorised to process personal data is bound by an appropriate duty of confidentiality, and that access is limited to those who need it to provide or support the service.
Taking account of the risk, we implement measures including:
We may update these measures provided the level of protection is not materially reduced.
You give general authorisation for us to engage the sub-processors listed below. Each is bound by written terms offering protection materially equivalent to this Agreement, and we remain fully liable to you for their performance.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Railway | Application hosting and PostgreSQL database | All data stored by the Service | United States |
| Resend | Transactional email delivery | Recipient email addresses and names, email content | United States |
| OpenAI | Clustering free-text survey answers into themes (GPT-4o-mini) | Free-text survey answers and the selected cancellation reason | United States |
We will give at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate the affected service and receive a pro-rata refund of any prepaid fees.
Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests to exercise rights of access, rectification, erasure, restriction, portability and objection.
If we receive such a request directly from one of your customers, we will not respond to it substantively ourselves. We will refer them to you and forward the request without undue delay. The one exception is unsubscribe requests, which we action immediately on your behalf, as they are also a legal requirement of the email itself.
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, and provide the information reasonably available to help you meet your own notification obligations.
We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, so far as they relate to our processing and taking account of the information available to us.
On termination of your account, we will delete all personal data processed on your behalf within 30 days, unless retention is required by law. Before then you may request a copy in a commonly used machine-readable format.
This is not aspirational: requesting account deletion from Settings triggers our account-deletion endpoint, which disconnects Stripe and stops surveys immediately and records the request; a daily purge job then permanently erases the account and its data once 30 days have passed. The same purge job independently enforces the survey-response retention period described in our Privacy Policy (section 8), so responses are deleted on a schedule regardless of whether or when you close your account.
Opt-out records are the sole exception: we retain the minimum needed — the account identifier and the email address that opted out — for as long as your account with us exists, so that the suppression continues to be honoured while it can still apply. Once your account is closed, the corresponding opt-out records are deleted along with it by the same daily job: retaining them any longer serves no purpose once you can no longer instruct us to survey that customer again.
We will make available the information reasonably necessary to demonstrate compliance with this Agreement and, on reasonable written notice and no more than once in any 12-month period, allow for and contribute to an audit conducted by you or an independent auditor you appoint, subject to confidentiality and to not unreasonably disrupting our operations. Where available, current third-party certifications or reports may be provided to satisfy this obligation.
Where we transfer personal data of individuals in the UK or European Economic Area outside those territories, the transfer is made under the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, as incorporated into our agreements with each sub-processor.
Where the data transferred is instead subject to POPIA, the transfer relies on section 72(1)(a): each sub-processor listed in section 6 is bound by a written agreement requiring it to provide a level of protection materially equivalent to POPIA's own requirements.
In the event of a conflict between this Agreement and the Terms of Service in relation to the processing of personal data, this Agreement prevails.
Questions about this document? privacy@churnlens.com