Data processing agreement
Version of September 20, 2026
This is an English translation of the French original, provided for convenience. If the two differ, the French version prevails. Read the French original.
When you use Oriva, you remain responsible for your visitors' data and Oriva processes it on your behalf, following your instructions. This agreement sets out what Oriva does, how it protects this data, who helps it do so and what happens if something goes wrong. It is part of the terms: by creating an account, you accept it.
The processing
1. Roles and purpose
For your visitors' data, you are the data controller (responsable de traitement) and Oriva is your processor (sous-traitant) within the meaning of article 28 of the GDPR. Oriva processes this data only to provide you with the service described in the terms: collecting the events of your sites, recording them, linking them to a click, sending them to the destinations you have configured and presenting them to you.
For the data of your own Oriva account (sign-in email, billing), Oriva is the data controller. This document does not cover it: it is described in the privacy policy.
2. Nature of the processing
| Item | Detail |
|---|---|
| Purpose | Measure the conversions of your site and pass them on to the platforms you choose, with proof of delivery. |
| Operations | Reception, deduplication, hashing, recording, linking to a click, sending to destinations, display, deletion. |
| Data subjects | The visitors and customers of your sites. |
| Data processed | First-party visitor identifier, IP address, browser, advertising click identifiers (Meta, TikTok, Google, OpenAI) and UTM parameters, hashed fingerprints of email, phone, name, postal code and customer identifier, page address, amount, currency and order reference, state of advertising consent. |
| Duration | The length of your subscription, then the deletion described in article 10. |
When a visitor refuses advertising consent, Oriva keeps no visitor identifier, no IP address, no browser, no fingerprint of email or phone, nor the full page address, and sends nothing to the advertising platforms. Only the amount, the currency and the order reference remain, as an aggregate measure. The detail is on the GDPR page.
3. Your instructions
Oriva processes the data only on your documented instruction: the terms, your configuration (domains, destinations, consent passed on by your site) and your written requests. It uses this data for no other purpose, in particular not on its own behalf nor on behalf of another customer. If Oriva considers that an instruction infringes the GDPR, it tells you.
Two technical uses are necessary to the service and are not uses on its own behalf: rate limiting by IP address, which protects the collection API against abusive sendings, and the logging of deliveries.
4. Confidentiality
The people who can access your visitors' data are bound by confidentiality. Today, that is the Oriva team.
5. Security
Oriva implements the measures described in annex 1. None of them is a certification: Oriva claims no security certification.
Sub-processors and transfers
6. Sub-processors
You authorize Oriva to use the sub-processors (sous-traitants ultérieurs) listed in annex 2. Oriva commits to:
- imposing on each of them data protection obligations equivalent to those of this agreement;
- informing you by email at least 30 days before adding or replacing a sub-processor, as soon as it is itself informed by that sub-processor (Oriva subscribes to each one's change notifications);
- letting you object. If the objection is reasoned and no solution is found, you may cancel without penalty before the change takes effect.
Oriva remains liable to you for the performance of its sub-processors' obligations.
The platforms to which you send data are not Oriva's sub-processors. When you configure a destination (Meta, TikTok, Google Ads, OpenAI, affiliate network), Oriva sends the data there on your instruction. What the platform then does with it falls under its own terms and your relationship with it, not Oriva's.
7. Transfers outside the European Union
What is stored is stored in the European Union: the database in Frankfurt (Supabase) and the cache and queue in Europe (Upstash). The application code runs in Frankfurt (Vercel).
Vercel is a US company and its platform (logs, backups, operating tools) is not limited to the European Union. Oriva limits what passes through it (emails, phone numbers and names are hashed before any recording, and the logs contain none), but cannot state that no data leaves the EU. For transfers outside the EU, the sub-processors rely on the standard contractual clauses of the European Commission (Vercel, Supabase) or on the EU-US data protection framework (Upstash), which provides the standard clauses as a fallback. The sendings to Meta, TikTok, Google and OpenAI that you configure are not Oriva's transfers but yours.
Your rights and what happens if things go wrong
8. Help with data subjects' rights
Oriva helps you, as far as possible, to answer your visitors' requests:
- Erasure. From your domain's page, the “Personal data” section deletes everything Oriva holds on a person (visitor identifier, visits, events, conversions, deliveries), found by visitor identifier, hashed email or IP address. Permanent.
- Access. Oriva has no automatic export. Write to contact@orivaforge.com: the request is handled by hand, within a reasonable time.
- Other rights (rectification, objection, restriction): Oriva answers you within 15 days and applies what you ask.
Oriva cannot delete what has already gone to Meta, TikTok, Google or OpenAI. If a person writes directly to Oriva, Oriva passes the request on to you without answering it itself.
9. Personal data breach
If Oriva finds a security breach affecting your visitors' data, it informs you by email, at your account's address, within 48 hours after becoming aware of it. When the breach occurs at one of its sub-processors, this period runs from the moment that sub-processor reported it to Oriva.
The notification describes, as far as known: the nature of the breach, the data and the approximate number of people concerned, the likely consequences and the measures taken or proposed. Oriva then completes the information as it goes. Notifying the supervisory authority and the people concerned remains your responsibility, as data controller.
10. Duration, end of contract, deletion and return
This agreement lasts as long as you use Oriva.
- Deletion. Deleting your account deletes your domains, your events, your conversions, your deliveries and your keys. Oriva also cancels your Stripe subscription.
- Without deleting your account, the history kept continues to be purged automatically according to your plan's duration (30 days on trial and Starter, 13 months for Pro and Agency). The IP address and the browser are purged at 90 days. Your account and your domains remain until you delete them.
- Return. On written request before deletion, Oriva provides your tracking data in a structured, machine-readable format, within a reasonable time.
- Copies. The database provider's backups expire according to its own policy.
11. Documentation and audit
Oriva makes available to you the information needed to demonstrate compliance with this agreement: this page, the GDPR page, the list of sub-processors and, on request, a completed security questionnaire. If a proven breach justifies it, you may have an audit carried out, at your own expense, with 30 days' notice and under conditions that do not disrupt the service for other customers.
12. Liability and governing law
Oriva's liability under this agreement follows the limits of article 18 of the terms, subject to what the law forbids limiting. This agreement is governed by French law; the competent court is the one indicated in article 20 of the terms. In case of contradiction on data protection, this agreement prevails over the rest of the terms.
Annexes
Annex 1. Security measures
| Measure | Detail |
|---|---|
| Hashing before writing | Email, phone, first name, last name, postal code, customer identifier: normalized then hashed (SHA-256). Never stored in plain text, never in logs. |
| IP and browser | Kept 90 days at most, for the IP and the browser of each event and visit. The visit's IP is recorded only as a fingerprint salted with a secret key. The delivery log does not keep them. |
| Secrets | Platform tokens encrypted (AES-256). Secret keys sk_ hashed (argon2id) and shown only once. Public keys pk_ write-only. |
| Partitioning | Row-level security enabled on customer tables, and an explicit filter on the workspace in every query of the application. |
| Access control | Administrator access limited to the members of the workspace; membership checked on every action. |
| Network and API | Signed requests between internal services, rate limits per IP and per key, content security policy on the customer area. |
| Resilience | If the database is unavailable, events are queued then replayed. Failed sendings to a platform are retried on a progressive schedule. |
| Logs | Structured, with no personal data in plain text. |
Secret keys are written sk_ and public keys pk_.
Annex 2. Sub-processors
| Sub-processor | Role | Storage and processing | Transfer framework | Visitor data |
|---|---|---|---|---|
| Vercel Inc. (United States) | Running the application and the collection API | Code run in Frankfurt. Platform (logs, backups) not limited to the EU. | 2021 standard contractual clauses | Yes, in transit and in runtime logs, with no personal data in plain text |
| Supabase | Database | Frankfurt (Germany) | Standard contractual clauses | Yes, storage |
| Upstash | Cache, delivery queue, backup buffer | Europe | EU-US framework, standard clauses as a fallback | Yes, transient (deduplication, buffer, delivery queue) |
Stripe (payment) and Google (sign-in) process only your account's data, not your visitors': they are described in the privacy policy.
A question about this agreement: contact@orivaforge.com. Version of September 20, 2026. Previous versions are kept and provided on request.