Data processing agreement

Version of September 20, 2026

This is an English translation of the French original, provided for convenience. If the two differ, the French version prevails. Read the French original.

When you use Oriva, you remain responsible for your visitors' data and Oriva processes it on your behalf, following your instructions. This agreement sets out what Oriva does, how it protects this data, who helps it do so and what happens if something goes wrong. It is part of the terms: by creating an account, you accept it.

The processing

1. Roles and purpose

For your visitors' data, you are the data controller (responsable de traitement) and Oriva is your processor (sous-traitant) within the meaning of article 28 of the GDPR. Oriva processes this data only to provide you with the service described in the terms: collecting the events of your sites, recording them, linking them to a click, sending them to the destinations you have configured and presenting them to you.

For the data of your own Oriva account (sign-in email, billing), Oriva is the data controller. This document does not cover it: it is described in the privacy policy.

2. Nature of the processing

ItemDetail
PurposeMeasure the conversions of your site and pass them on to the platforms you choose, with proof of delivery.
OperationsReception, deduplication, hashing, recording, linking to a click, sending to destinations, display, deletion.
Data subjectsThe visitors and customers of your sites.
Data processedFirst-party visitor identifier, IP address, browser, advertising click identifiers (Meta, TikTok, Google, OpenAI) and UTM parameters, hashed fingerprints of email, phone, name, postal code and customer identifier, page address, amount, currency and order reference, state of advertising consent.
DurationThe length of your subscription, then the deletion described in article 10.

When a visitor refuses advertising consent, Oriva keeps no visitor identifier, no IP address, no browser, no fingerprint of email or phone, nor the full page address, and sends nothing to the advertising platforms. Only the amount, the currency and the order reference remain, as an aggregate measure. The detail is on the GDPR page.

3. Your instructions

Oriva processes the data only on your documented instruction: the terms, your configuration (domains, destinations, consent passed on by your site) and your written requests. It uses this data for no other purpose, in particular not on its own behalf nor on behalf of another customer. If Oriva considers that an instruction infringes the GDPR, it tells you.

Two technical uses are necessary to the service and are not uses on its own behalf: rate limiting by IP address, which protects the collection API against abusive sendings, and the logging of deliveries.

4. Confidentiality

The people who can access your visitors' data are bound by confidentiality. Today, that is the Oriva team.

5. Security

Oriva implements the measures described in annex 1. None of them is a certification: Oriva claims no security certification.

Sub-processors and transfers

6. Sub-processors

You authorize Oriva to use the sub-processors (sous-traitants ultérieurs) listed in annex 2. Oriva commits to:

  • imposing on each of them data protection obligations equivalent to those of this agreement;
  • informing you by email at least 30 days before adding or replacing a sub-processor, as soon as it is itself informed by that sub-processor (Oriva subscribes to each one's change notifications);
  • letting you object. If the objection is reasoned and no solution is found, you may cancel without penalty before the change takes effect.

Oriva remains liable to you for the performance of its sub-processors' obligations.

The platforms to which you send data are not Oriva's sub-processors. When you configure a destination (Meta, TikTok, Google Ads, OpenAI, affiliate network), Oriva sends the data there on your instruction. What the platform then does with it falls under its own terms and your relationship with it, not Oriva's.

7. Transfers outside the European Union

What is stored is stored in the European Union: the database in Frankfurt (Supabase) and the cache and queue in Europe (Upstash). The application code runs in Frankfurt (Vercel).

Vercel is a US company and its platform (logs, backups, operating tools) is not limited to the European Union. Oriva limits what passes through it (emails, phone numbers and names are hashed before any recording, and the logs contain none), but cannot state that no data leaves the EU. For transfers outside the EU, the sub-processors rely on the standard contractual clauses of the European Commission (Vercel, Supabase) or on the EU-US data protection framework (Upstash), which provides the standard clauses as a fallback. The sendings to Meta, TikTok, Google and OpenAI that you configure are not Oriva's transfers but yours.

Your rights and what happens if things go wrong

8. Help with data subjects' rights

Oriva helps you, as far as possible, to answer your visitors' requests:

  • Erasure. From your domain's page, the “Personal data” section deletes everything Oriva holds on a person (visitor identifier, visits, events, conversions, deliveries), found by visitor identifier, hashed email or IP address. Permanent.
  • Access. Oriva has no automatic export. Write to contact@orivaforge.com: the request is handled by hand, within a reasonable time.
  • Other rights (rectification, objection, restriction): Oriva answers you within 15 days and applies what you ask.

Oriva cannot delete what has already gone to Meta, TikTok, Google or OpenAI. If a person writes directly to Oriva, Oriva passes the request on to you without answering it itself.

9. Personal data breach

If Oriva finds a security breach affecting your visitors' data, it informs you by email, at your account's address, within 48 hours after becoming aware of it. When the breach occurs at one of its sub-processors, this period runs from the moment that sub-processor reported it to Oriva.

The notification describes, as far as known: the nature of the breach, the data and the approximate number of people concerned, the likely consequences and the measures taken or proposed. Oriva then completes the information as it goes. Notifying the supervisory authority and the people concerned remains your responsibility, as data controller.

10. Duration, end of contract, deletion and return

This agreement lasts as long as you use Oriva.

  • Deletion. Deleting your account deletes your domains, your events, your conversions, your deliveries and your keys. Oriva also cancels your Stripe subscription.
  • Without deleting your account, the history kept continues to be purged automatically according to your plan's duration (30 days on trial and Starter, 13 months for Pro and Agency). The IP address and the browser are purged at 90 days. Your account and your domains remain until you delete them.
  • Return. On written request before deletion, Oriva provides your tracking data in a structured, machine-readable format, within a reasonable time.
  • Copies. The database provider's backups expire according to its own policy.

11. Documentation and audit

Oriva makes available to you the information needed to demonstrate compliance with this agreement: this page, the GDPR page, the list of sub-processors and, on request, a completed security questionnaire. If a proven breach justifies it, you may have an audit carried out, at your own expense, with 30 days' notice and under conditions that do not disrupt the service for other customers.

12. Liability and governing law

Oriva's liability under this agreement follows the limits of article 18 of the terms, subject to what the law forbids limiting. This agreement is governed by French law; the competent court is the one indicated in article 20 of the terms. In case of contradiction on data protection, this agreement prevails over the rest of the terms.

Annexes

Annex 1. Security measures

MeasureDetail
Hashing before writingEmail, phone, first name, last name, postal code, customer identifier: normalized then hashed (SHA-256). Never stored in plain text, never in logs.
IP and browserKept 90 days at most, for the IP and the browser of each event and visit. The visit's IP is recorded only as a fingerprint salted with a secret key. The delivery log does not keep them.
SecretsPlatform tokens encrypted (AES-256). Secret keys sk_ hashed (argon2id) and shown only once. Public keys pk_ write-only.
PartitioningRow-level security enabled on customer tables, and an explicit filter on the workspace in every query of the application.
Access controlAdministrator access limited to the members of the workspace; membership checked on every action.
Network and APISigned requests between internal services, rate limits per IP and per key, content security policy on the customer area.
ResilienceIf the database is unavailable, events are queued then replayed. Failed sendings to a platform are retried on a progressive schedule.
LogsStructured, with no personal data in plain text.

Secret keys are written sk_ and public keys pk_.

Annex 2. Sub-processors

Sub-processorRoleStorage and processingTransfer frameworkVisitor data
Vercel Inc. (United States)Running the application and the collection APICode run in Frankfurt. Platform (logs, backups) not limited to the EU.2021 standard contractual clausesYes, in transit and in runtime logs, with no personal data in plain text
SupabaseDatabaseFrankfurt (Germany)Standard contractual clausesYes, storage
UpstashCache, delivery queue, backup bufferEuropeEU-US framework, standard clauses as a fallbackYes, transient (deduplication, buffer, delivery queue)

Stripe (payment) and Google (sign-in) process only your account's data, not your visitors': they are described in the privacy policy.

A question about this agreement: contact@orivaforge.com. Version of September 20, 2026. Previous versions are kept and provided on request.