Data Processing Agreement

Last updated: September 1, 2026

1. Scope and how this applies

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Gaviro Tecnologia LTDA (CNPJ 54.585.383/0001-36), trading as Retain ("Processor", "we", "us"). It takes effect when you accept the Terms, and no separate signature is required. If you need a countersigned copy for your records, write to [email protected].

It applies wherever we process personal data on your behalf and that processing is subject to the EU General Data Protection Regulation, the UK GDPR, the Swiss FADP, or the Brazilian LGPD. Terms such as "personal data", "controller", "processor", "processing", and "data subject" carry the meaning given to them in those laws.

2. Roles of the parties

You are the controller of the data you send us about your users ("Customer Personal Data"), and we are your processor for it. You decide what to send, why, and for how long we keep it. We process it only to provide the service.

We are a separate and independent controller for the account data of the people on your team who use Retain, such as their names, email addresses, and login sessions. That processing is governed by our Privacy Policy, not by this DPA.

3. Our obligations as processor

4. Your obligations as controller

You are responsible for the lawfulness of the data you send us. In particular, you confirm that you have a lawful basis to collect Customer Personal Data and disclose it to us, that your own privacy notices tell your users about this processing, and that your instructions to us do not put us in breach of applicable law.

You must not send us special categories of personal data, data relating to criminal convictions, or data about children. The event and trait fields of our ingestion API accept free-form values, so this is a limit you enforce at the point you send data, not one we can enforce on receipt.

5. Subprocessors

You give us general authorisation to engage the subprocessors listed in Annex B. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain liable to you for their performance.

When we intend to add or replace a subprocessor, we will update Annex B and announce the change by email or in the dashboard at least 30 days before it takes effect. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will work with you on an alternative. If none is workable, you may terminate the affected part of the service and receive a pro rata refund of any prepaid fees.

Third-party services that you connect to your workspace, such as your Polar account, your PostHog project, or a Slack or Discord channel, are not our subprocessors. We act on them under your instructions, using credentials you supply, and your relationship with those providers is governed by their own terms.

6. International transfers

We are established in Brazil and our infrastructure is hosted in the United States, so Customer Personal Data is transferred out of the EEA, the UK, and Switzerland when you use the service.

Where the EU GDPR applies, those transfers are governed by the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, Module Two (controller to processor), which are incorporated into this DPA by reference, with us as data importer and you as data exporter. Annex A supplies the details of processing they require, Annex B the subprocessors, and Annex C the security measures. Where the UK GDPR applies, the UK International Data Transfer Addendum applies to those Clauses. Where the LGPD applies, we will enter into the standard contractual clauses approved by the ANPD on request.

7. Data subject requests

Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, and objection.

If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will tell them to contact you and, where we can identify you, let you know it happened.

8. Personal data breach

If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay. The notification will describe what we know at the time: the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will send what we have and follow up as the picture becomes clear.

Notifying you is not an acknowledgement of fault. Reporting the breach to a supervisory authority or to affected data subjects, where the law requires it, is your responsibility as controller, and we will give you the information you reasonably need to do it.

9. Audits

On request, and no more than once in any 12 month period unless a supervisory authority or a breach requires otherwise, we will make available the information necessary to demonstrate compliance with this DPA. In the first instance this is satisfied by our written responses to a reasonable security questionnaire and by the documentation we can supply about our measures.

Where that is genuinely insufficient for your compliance obligations, we will discuss further steps in good faith. Any audit must be requested at least 30 days in advance, must not disrupt the service or compromise the confidentiality of our other customers, and is at your cost.

10. Deletion and return

When the Terms end, or when you ask us in writing, we delete Customer Personal Data within 30 days, except where the law requires us to keep it. If you ask before deletion, we will provide a copy of the data first. We will confirm the deletion in writing on request. Deletion requests are handled by our team rather than by a button in the product.

11. Liability

Each party's liability under this DPA is subject to the exclusions and limitations in the Terms of Service.

12. Term, changes, and governing law

This DPA runs for as long as we process Customer Personal Data for you. We may update it as the service and the law evolve, and material changes will be announced by email or in the dashboard at least 30 days before they take effect. Where this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. It is governed by the law and jurisdiction stated in the Terms, except where the Standard Contractual Clauses require otherwise, in which case they govern on that point.

Annex A. Details of processing

Annex B. Subprocessors

These providers process Customer Personal Data on our behalf:

Stripe acts as our own payment processor for your subscription to Retain, which is account data rather than Customer Personal Data. PostHog, Meta, and Firecrawl are listed in our Privacy Policy but do not receive Customer Personal Data: PostHog measures our own marketing site, Meta measures our advertising on those same public, sign-up, and onboarding pages plus the single conversion recorded when you return from Stripe, and Firecrawl reads only the public website you give us at onboarding. The Meta pixel is not loaded anywhere else in the dashboard, so it never sees your accounts, customers, or events.

Annex C. Technical and organisational measures

These are the measures in place today. We describe what we actually do, so this annex is deliberately narrower than the ones you may have seen from larger vendors.

Contact

Questions about this DPA, requests for a countersigned copy, or security questionnaires: [email protected].

Command palette

Search customers, alerts, events, pages and docs