Data Processing Agreement
Last updated: September 1, 2026
1. Scope and how this applies
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Gaviro Tecnologia LTDA (CNPJ 54.585.383/0001-36), trading as Retain ("Processor", "we", "us"). It takes effect when you accept the Terms, and no separate signature is required. If you need a countersigned copy for your records, write to [email protected].
It applies wherever we process personal data on your behalf and that processing is subject to the EU General Data Protection Regulation, the UK GDPR, the Swiss FADP, or the Brazilian LGPD. Terms such as "personal data", "controller", "processor", "processing", and "data subject" carry the meaning given to them in those laws.
2. Roles of the parties
You are the controller of the data you send us about your users ("Customer Personal Data"), and we are your processor for it. You decide what to send, why, and for how long we keep it. We process it only to provide the service.
We are a separate and independent controller for the account data of the people on your team who use Retain, such as their names, email addresses, and login sessions. That processing is governed by our Privacy Policy, not by this DPA.
3. Our obligations as processor
- We process Customer Personal Data only on your documented instructions. Your use of the service, together with the Terms and this DPA, constitutes those instructions. If we are required by law to process it otherwise, we will tell you first unless the law forbids it.
- Everyone we authorise to access Customer Personal Data is bound by a duty of confidentiality.
- We maintain the technical and organisational measures set out in Annex C.
- We assist you, taking into account the nature of the processing and the information available to us, with your obligations on security, breach notification, and data protection impact assessments.
- We do not sell Customer Personal Data, and we do not use it for advertising, for profiling on behalf of anyone but you, or to train machine learning models.
4. Your obligations as controller
You are responsible for the lawfulness of the data you send us. In particular, you confirm that you have a lawful basis to collect Customer Personal Data and disclose it to us, that your own privacy notices tell your users about this processing, and that your instructions to us do not put us in breach of applicable law.
You must not send us special categories of personal data, data relating to criminal convictions, or data about children. The event and trait fields of our ingestion API accept free-form values, so this is a limit you enforce at the point you send data, not one we can enforce on receipt.
5. Subprocessors
You give us general authorisation to engage the subprocessors listed in Annex B. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain liable to you for their performance.
When we intend to add or replace a subprocessor, we will update Annex B and announce the change by email or in the dashboard at least 30 days before it takes effect. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will work with you on an alternative. If none is workable, you may terminate the affected part of the service and receive a pro rata refund of any prepaid fees.
Third-party services that you connect to your workspace, such as your Polar account, your PostHog project, or a Slack or Discord channel, are not our subprocessors. We act on them under your instructions, using credentials you supply, and your relationship with those providers is governed by their own terms.
6. International transfers
We are established in Brazil and our infrastructure is hosted in the United States, so Customer Personal Data is transferred out of the EEA, the UK, and Switzerland when you use the service.
Where the EU GDPR applies, those transfers are governed by the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, Module Two (controller to processor), which are incorporated into this DPA by reference, with us as data importer and you as data exporter. Annex A supplies the details of processing they require, Annex B the subprocessors, and Annex C the security measures. Where the UK GDPR applies, the UK International Data Transfer Addendum applies to those Clauses. Where the LGPD applies, we will enter into the standard contractual clauses approved by the ANPD on request.
7. Data subject requests
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, and objection.
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will tell them to contact you and, where we can identify you, let you know it happened.
8. Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay. The notification will describe what we know at the time: the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will send what we have and follow up as the picture becomes clear.
Notifying you is not an acknowledgement of fault. Reporting the breach to a supervisory authority or to affected data subjects, where the law requires it, is your responsibility as controller, and we will give you the information you reasonably need to do it.
9. Audits
On request, and no more than once in any 12 month period unless a supervisory authority or a breach requires otherwise, we will make available the information necessary to demonstrate compliance with this DPA. In the first instance this is satisfied by our written responses to a reasonable security questionnaire and by the documentation we can supply about our measures.
Where that is genuinely insufficient for your compliance obligations, we will discuss further steps in good faith. Any audit must be requested at least 30 days in advance, must not disrupt the service or compromise the confidentiality of our other customers, and is at your cost.
10. Deletion and return
When the Terms end, or when you ask us in writing, we delete Customer Personal Data within 30 days, except where the law requires us to keep it. If you ask before deletion, we will provide a copy of the data first. We will confirm the deletion in writing on request. Deletion requests are handled by our team rather than by a button in the product.
11. Liability
Each party's liability under this DPA is subject to the exclusions and limitations in the Terms of Service.
12. Term, changes, and governing law
This DPA runs for as long as we process Customer Personal Data for you. We may update it as the service and the law evolve, and material changes will be announced by email or in the dashboard at least 30 days before they take effect. Where this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. It is governed by the law and jurisdiction stated in the Terms, except where the Standard Contractual Clauses require otherwise, in which case they govern on that point.
Annex A. Details of processing
- Subject matter: our provision of the Retain churn prevention and customer analytics service.
- Duration: the term of the Terms of Service, plus the deletion window in Section 10.
- Nature and purpose: receiving, storing, and analysing product usage and subscription data in order to compute customer health scores, churn risk levels, activation signals, and retention metrics; raising alerts; and generating draft re-engagement emails at your request.
- Types of personal data: user identifiers assigned by you, email addresses, names, avatar URLs, and any custom traits you choose to send; records of product events with their timestamps and properties; and subscription and revenue metadata imported from the payment providers you connect, which for Stripe includes the name and email address recorded against a customer.
- Categories of data subjects: the users of your product, and the people associated with the business accounts you monitor.
- Special categories: none. Sending them is prohibited by Section 4.
- Frequency: continuous, for as long as your integrations are connected.
Annex B. Subprocessors
These providers process Customer Personal Data on our behalf:
- Hetzner, application hosting, United States
- Neon, database hosting on AWS us-east-1, United States
- Vercel, frontend hosting
- Cloudflare, network, CDN, and security
- OpenAI, generation of draft re-engagement emails and cohort notes, United States
- Resend, delivery of the email alerts you configure
- Sentry, error monitoring
Stripe acts as our own payment processor for your subscription to Retain, which is account data rather than Customer Personal Data. PostHog, Meta, and Firecrawl are listed in our Privacy Policy but do not receive Customer Personal Data: PostHog measures our own marketing site, Meta measures our advertising on those same public, sign-up, and onboarding pages plus the single conversion recorded when you return from Stripe, and Firecrawl reads only the public website you give us at onboarding. The Meta pixel is not loaded anywhere else in the dashboard, so it never sees your accounts, customers, or events.
Annex C. Technical and organisational measures
These are the measures in place today. We describe what we actually do, so this annex is deliberately narrower than the ones you may have seen from larger vendors.
- Encryption in transit: all traffic to the application and the API is served over TLS.
- Encryption at rest: data stored in our managed database is encrypted at rest by the database provider.
- Authentication: passwords are stored hashed with bcrypt, and Google sign-in is available as an alternative. Accepting an invitation to an organisation requires a verified email address.
- Tenant isolation: every dashboard request is scoped to a single organisation, so one workspace cannot read another. Access within a workspace is governed by two roles, administrator and team member.
- Key management: ingestion write keys can be rotated at any time from the dashboard. API keys issued to AI agents are stored only as a SHA-256 hash, are displayed once at creation, and can be revoked.
- Integrity of ingestion: payment provider webhooks are verified by signature, and authentication endpoints are rate limited.
- Operational access: access to production systems is restricted to authorised personnel and authenticated. Credentials are stripped from error reports before they are sent to our monitoring provider.
- Certifications: we do not currently hold SOC 2 or ISO 27001 certification, and we do not claim measures we have not implemented.
Contact
Questions about this DPA, requests for a countersigned copy, or security questionnaires: [email protected].