Acuerdo de procesamiento de datos
Última actualización: 23 de agosto de 2026
Idioma de este documento
Este documento se proporciona en inglés y la versión en inglés es la vinculante. Preguntas: hello@engagenudge.com.
What this is
This Data Processing Agreement (DPA) forms part of the agreement between the customer (the controller) and Hyperity, the Swedish company operating EngageNudge (the processor), as required by Article 28 GDPR. Your workspace accepts it in the dashboard, during onboarding or under Settings, and the acceptance timestamp is recorded on your account.
Subject matter and duration
The processing covers the personal data of the customer's web push subscribers, for the purpose of operating the EngageNudge service for the customer. It lasts as long as the customer account exists.
Nature and purpose
Storing push subscriptions in encrypted form, deciding and sending notifications on the customer's instruction, measuring engagement, and protecting the audience through frequency limits, quiet hours, and holdouts.
Data and data subjects
Data subjects are subscribers to the customer's site. The data is the push endpoint and its browser keys, topic choices and preferences, engagement events, and a coarse location derived at ingestion. The service is not designed for special categories of personal data, and the customer agrees not to direct such data through it.
Instructions
We process personal data only on the customer's documented instructions: the settings, dashboard actions, and API calls of the workspace. If an instruction would in our view violate data protection law, we tell the customer instead of executing it.
Confidentiality
Persons authorized to process the data are bound by confidentiality obligations.
Security measures
Encryption in transit everywhere; field-level encryption of push endpoints and signing keys with keys derived per customer; strict tenant scoping on every query; redaction of personal data in logs; access controls and rate limits on all interfaces. The Security page at /security describes the current measures.
Subprocessors
The customer gives general authorization for the subprocessors listed at /subprocessors. We impose the same data protection obligations on them, remain responsible for their performance, and give notice before adding or replacing one, so the customer can object.
Assistance
We assist the customer in answering data subject requests, and with the customer's obligations on security, breach notification, and impact assessments, taking into account the nature of the processing.
Personal data breaches
We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information the customer needs for their own notification duties.
Deletion and return
Account owners can export their data from the dashboard at any time. Unsubscribed records are hard-deleted when they occur. On termination, the customer schedules deletion of the workspace; after the cooldown, the data is deleted.
Audits
We make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the customer or an auditor the customer mandates, within reasonable notice and scope.
International transfers
Processing is EU-first. Where a subprocessor processes personal data outside the EEA, the transfer relies on an adequacy decision or standard contractual clauses. Locations are noted on the subprocessor page.
Version
This page is the current version of the DPA. The English version governs. Material changes are announced to account owners by email before they take effect. Questions: hello@engagenudge.com.
