Data processing addendum Version 0.3 — effective 2026-09-02, last updated 2026-09-02 Draft — pending legal review Article 28 terms for the personal data Popfinch processes on your instructions: what, for how long, by whom, and what happens when you leave. Who is who You are the controller of the personal data your widgets collect: you decide which of your visitors are asked for an email address, what they are told, and what happens to the answer. Vielendark is the processor, acting on your instructions. Vielendark is separately the controller of the data about you — your account, your billing details, your support messages and the operational logs of the service. That processing is described in the privacy notice, not here. This addendum forms part of the terms of service. Where they conflict about personal data processed on your behalf, this one wins. Subject matter, duration, nature and purpose Subject matter: hosting and delivering the widgets you configure, receiving what visitors submit to them, storing it, and forwarding it where you have told us to. Duration: for as long as your account exists, plus any retention period you set on a project and the backup window described below. Nature and purpose: collection, storage, retrieval, transmission to services you nominate, deletion. No profiling, no automated decision-making about a visitor, no use of the data for our own purposes. Data subjects and categories Data subjects: visitors to the websites on which you install Popfinch. - What your form asks for. Typically an email address; often a name; sometimes a phone number or an answer to a question. The fields are yours to define, so the categories are ultimately yours to control. - The page the submission came from, and the referrer. - The browser's user agent string and the language it advertises. - An identifier for that visit, which lives in the tab and not beyond it. - Which variant of an A/B test was shown. - The wording of your consent line exactly as that visitor saw it, and the time. Popfinch does not ask for special category data and does not want any. If your form collects it, that is your decision and your lawful basis, and you should tell us so the arrangement can be looked at properly. Counting is separate from collecting. Views, clicks, closes and steps are added to a counter per widget and day. No row identifies a visitor, and the counters can be switched off for a project entirely. Documented instructions We process this data only on your documented instructions. Your instructions are: this addendum, the terms, and the configuration you set in the product — which widget asks what, which project keeps data for how long, which integration receives a lead, whether statistics are counted at all. If we believe an instruction breaks data protection law, we will tell you and may pause that instruction until it is resolved. We will not simply carry it out and leave you to find out later. Confidentiality Everyone with access to this data is bound to confidentiality. Today that is the operator; any future staff or contractor is bound before being given access, not after. Security measures The technical and organisational measures are described in the security overview, which is part of this addendum by reference and is kept current as the product changes. In summary: row-level security on every table so one account cannot read another's rows even with a hand-written query; integration credentials encrypted at rest with AES-256-GCM and never shown again; TLS in transit; a site key bound to the domains you list; and no service-role database key held by the application at all. Subprocessors You give general authorisation for the subprocessors listed below and in the subprocessor list, which is the same set of facts published on its own page. Who | What for | What reaches them | Where | Transfer basis Vercel Inc. | Hosts the dashboard, the API and the script that serves your widgets. | Request metadata. Lead contents pass through in transit and are not stored there. | Functions run in Dublin. The edge cache serves the script from wherever the visitor is, which can be outside the EEA. | Standard contractual clauses. Supabase Inc. | Database, authentication and image storage. | Accounts, widgets, leads, statistics. | Ireland (eu-west-1). | Standard contractual clauses for the vendor's own access. Anthropic PBC | The AI designer, only when somebody uses it. | The instruction typed into the panel, a summary of the widget, and a screenshot if one is attached. No leads. | United States. | Standard contractual clauses. Google Ireland Ltd. | Sends operational email — a failed delivery, a widget gone quiet. | The account holder's own address and the text of the notice. | European Union. | Not applicable within the EEA. Stripe Payments Europe Ltd. | Takes payment for a plan. | The account's billing identity and what the card holder types on Stripe's own page. No visitor data of any kind. | Ireland, with group processing in the United States. | Standard contractual clauses. You are told before a subprocessor is added or replaced, with enough notice to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may end the agreement for the affected part without penalty. Only if you switch them on - Ecomail — receives leads when you enable it for a widget. Your account and your contract with them; Popfinch forwards on your instruction. - Your own endpoint — receives leads by webhook wherever you point it. Popfinch signs the request so you can verify it came from us. Those two are recipients you nominate rather than subprocessors we chose. Once a lead has arrived there, what happens to it is governed by your arrangement with that service. International transfers Data is not guaranteed to stay inside the European Economic Area, and no document of ours will claim it does. The database is in Ireland and the application's functions run in Dublin, but the content delivery network that serves the widget script answers from wherever the visitor is, and the AI designer sends its input to the United States when it is used. Transfers outside the EEA rely on the European Commission's standard contractual clauses with the vendor concerned. [To be settled] Owner verification outstanding: the contracting entity, plan and executed data processing agreement for each vendor above, and whether the Anthropic account is on terms that exclude training and limit retention. The repository can show which services are used; it cannot show which agreement was signed. Helping with data subject requests Requests come to you, because you are the controller and the visitor dealt with your website. The product gives you what you need to answer one: leads are searchable and exportable as CSV, and any lead can be deleted individually. There is nowhere else a visitor's submission lives, so deleting it there is the whole of the erasure. If a visitor contacts us directly we will not answer on your behalf. We will tell them to contact you, and tell you that they tried. Personal data breaches You are told without undue delay, and in any event within 72 hours of us becoming aware of a breach affecting personal data we process for you. The notice says what is known at the time, what is affected, what is being done, and what you may need to do. A later notice follows when more is known rather than a first one being delayed until everything is. We assist you with impact assessments and with the supervisory authority to the extent the information is ours to give. Return and deletion You can export at any time while the account exists, and export is not conditional on anything being paid or agreed. On termination, the export and termination policy applies: what you can take, in what format, and by when. Deleted data goes from the live database immediately. It can still exist in a database backup until that backup expires, and the current configuration keeps daily backups for seven days. No document of ours will promise erasure everywhere at once, because backups do not work that way. Audit and information You may ask for the information needed to show that this addendum is being complied with, and we will give what we have: the security overview, the subprocessor list, the measured figures behind them, and answers to specific questions. An on-site audit of a one-person operator running on other people's infrastructure is mostly an audit of those vendors, and their own certifications and reports are the honest answer to that. We will not claim a certification we do not hold. --- Operator: Vielendark s. r. o., Cyprichova 2477/24, 831 53 Bratislava - mestská časť Rača, Slovakia. Registration number 55121250, tax number 2121872962, VAT number SK2121872962, registered in the Commercial Register of the Municipal Court Bratislava III, Section Sro, Insert No. 167007/B. Contact: hello@popfinch.com. Privacy: privacy@popfinch.com. Security: security@popfinch.com. Abuse: abuse@popfinch.com. Owner verification outstanding: these register details have not yet been checked against a current extract from the Commercial Register.