Purpose
This DPA explains how Kepixel AI processes customer data while providing server-side tracking, Conversion API delivery, destination setup, reporting, support, and security.
Roles of the Parties
For customer event data, the customer is typically the controller and Kepixel AI acts as processor according to the customer's instructions unless otherwise agreed in writing.
Types of Data Processed
Data may include account data, workspace settings, sources, destination settings, event names, timestamps, URLs, order IDs, order values, currencies, click IDs, hashed identifiers, and session data.
Categories of Data Subjects
Data subjects may include website visitors, customers, purchasers, leads, app users, and members of the customer's team using the KePixel dashboard.
Processing Instructions
KePixel processes data based on the customer's configuration, including selected sources, destinations, event mapping, deduplication, and retention settings.
Confidentiality
Only authorized people and systems may access data where needed for operations, support, or security, subject to appropriate confidentiality obligations.
Security Measures
Measures may include access controls, operational logs, permission separation, protection of keys and tokens, and cloud security practices.
Subprocessors
We may use hosting, database, cloud function, email, billing, analytics, and advertising providers to deliver the service. Categories are listed on the Subprocessors page.
International Transfers
Data may be processed in different countries depending on infrastructure providers and enabled destinations. Customers are responsible for evaluating transfer requirements applicable to their business.
Data Subject Requests
KePixel helps customers handle valid requests related to data processed on their behalf, subject to technical and legal feasibility.
Data Breach Notification
If we identify a security incident affecting customer data, we aim to notify the customer within a reasonable time and provide available information to support investigation and remediation.
Return or Deletion of Data
After termination or upon a valid request, certain data may be deleted or reduced subject to system limitations, retention requirements, logs, and legal obligations.
Audit Rights
We may provide reasonable information about security and processing practices. Additional reviews may be agreed for enterprise customers by contract.
Term and Termination
Processing continues while the customer uses the service. Some logs may be retained for a limited period for security, billing, support, or compliance.