Acuerdo de procesamiento de datos

Última actualización: 23 de agosto de 2026

Idioma de este documento

Este documento se proporciona en inglés y la versión en inglés es la vinculante. Preguntas: hello@engagenudge.com.

What this is

This Data Processing Agreement (DPA) forms part of the agreement between the customer (the controller) and Hyperity, the Swedish company operating EngageNudge (the processor), as required by Article 28 GDPR. Your workspace accepts it in the dashboard, during onboarding or under Settings, and the acceptance timestamp is recorded on your account.

Subject matter and duration

The processing covers the personal data of the customer's web push subscribers, for the purpose of operating the EngageNudge service for the customer. It lasts as long as the customer account exists.

Nature and purpose

Storing push subscriptions in encrypted form, deciding and sending notifications on the customer's instruction, measuring engagement, and protecting the audience through frequency limits, quiet hours, and holdouts.

Data and data subjects

Data subjects are subscribers to the customer's site. The data is the push endpoint and its browser keys, topic choices and preferences, engagement events, and a coarse location derived at ingestion. The service is not designed for special categories of personal data, and the customer agrees not to direct such data through it.

Instructions

We process personal data only on the customer's documented instructions: the settings, dashboard actions, and API calls of the workspace. If an instruction would in our view violate data protection law, we tell the customer instead of executing it.

Confidentiality

Persons authorized to process the data are bound by confidentiality obligations.

Security measures

Encryption in transit everywhere; field-level encryption of push endpoints and signing keys with keys derived per customer; strict tenant scoping on every query; redaction of personal data in logs; access controls and rate limits on all interfaces. The Security page at /security describes the current measures.

Subprocessors

The customer gives general authorization for the subprocessors listed at /subprocessors. We impose the same data protection obligations on them, remain responsible for their performance, and give notice before adding or replacing one, so the customer can object.

Assistance

We assist the customer in answering data subject requests, and with the customer's obligations on security, breach notification, and impact assessments, taking into account the nature of the processing.

Personal data breaches

We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information the customer needs for their own notification duties.

Deletion and return

Account owners can export their data from the dashboard at any time. Unsubscribed records are hard-deleted when they occur. On termination, the customer schedules deletion of the workspace; after the cooldown, the data is deleted.

Audits

We make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the customer or an auditor the customer mandates, within reasonable notice and scope.

International transfers

Processing is EU-first. Where a subprocessor processes personal data outside the EEA, the transfer relies on an adequacy decision or standard contractual clauses. Locations are noted on the subprocessor page.

Version

This page is the current version of the DPA. The English version governs. Material changes are announced to account owners by email before they take effect. Questions: hello@engagenudge.com.

Sepa cuándo hacer un Nudge.

Sepa cuándo vale la pena enviar una notificación.

Ya sea que llegue a lectores, compradores, candidatos o shoppers, EngageNudge le ayuda a decidir quién merece un Nudge y a quién conviene dejar en paz.