Loading...
Last Updated: November 25, 2025
This DPA forms part of the Terms & Conditions between Acquirely LLC and Customer.
This Data Processing Addendum ("DPA") is entered into by and between:
This DPA governs the Processing of Personal Data by Acquirely on behalf of the Customer in connection with Acquirely's Services, as required under:
"Personal Data"
Any information relating to an identified or identifiable natural person processed by Acquirely on behalf of Customer.
"Processing"
Any operation performed on Personal Data, including storage, transmission, retrieval, or deletion.
"Controller"
Customer — the entity determining purposes and means of Processing.
"Processor"
Acquirely — the entity processing Personal Data on behalf of the Customer.
"Sub-Processor"
A third-party service provider engaged by Acquirely to assist in providing the Service.
"Applicable Data Protection Laws"
GDPR, UK GDPR, CPRA, and other applicable U.S. privacy regulations.
Acquirely Processes Personal Data solely for:
Acquirely does not:
The parties acknowledge:
Acquirely will Process Personal Data only:
Acquirely will promptly notify Customer if an instruction violates applicable privacy law.
Customer agrees that Acquirely may use Sub-Processors, including:
| Sub-Processor | Purpose |
|---|---|
| Stripe | Billing |
| Vercel | Hosting & application delivery |
| Cloudflare | CDN & security |
| PostHog | Analytics |
| Supabase / Neon | Database backbone |
| AWS / Cloudflare R2 | Storage |
All Sub-Processors are subject to written data protection obligations equivalent to this DPA.
Acquirely will:
Acquirely implements industry-standard security, including:
Acquirely will maintain administrative, technical, and physical safeguards appropriate to industry standards.
Acquirely will assist Customer in handling:
Acquirely will not respond to requests from individuals without Customer's authorization.
If Acquirely becomes aware of a Personal Data Breach, Acquirely will:
A breach does not include unsuccessful attempts to compromise infrastructure (e.g., failed logins, port scans).
Upon termination of Customer's account:
Backup data will be securely overwritten in accordance with standard lifecycle policies.
Acquirely may Process data in the United States or other jurisdictions.
All international transfers will follow:
For California residents, Acquirely agrees:
Customer may request a summary of security audits or certifications.
Due to security reasons, on-site audits are not permitted, but Acquirely will provide:
Each party's liability under this DPA is subject to the exclusions and limitations in the Terms & Conditions.
This DPA remains in effect as long as Acquirely processes Personal Data on behalf of Customer.
For questions about this DPA: