Data Processing Agreement
Last updated: August 3, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between you (“Controller”, “you”) and Remote Leads OÜ (“Processor”, “we”, “us”), registry code 14487589, Väike-Paala tn 1, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia. It applies where we process personal data on your behalf, and satisfies Article 28 of Regulation (EU) 2016/679 (“GDPR”). By accepting the Terms you enter into this DPA; no separate signature is required.
1. Scope & Roles
This DPA governs Funnel Data only: personal data that funnel pages you publish through the Platform collect from your visitors, leads, and buyers. For that data you are the controller and we are your processor.
It does not govern your own account data, billing data, or the briefing content you submit about your business. For that data we are the controller and our Privacy Policy applies.
2. Our Obligations as Processor
We will:
- process Funnel Data only on your documented instructions — the Terms, this DPA, and your use of the Platform’s features constitute those instructions — including as regards transfers to a third country, unless we are required to do otherwise by EU or member-state law, in which case we will inform you before processing unless that law forbids it;
- ensure that everyone we authorise to process Funnel Data is bound by an appropriate duty of confidentiality;
- implement the technical and organisational measures described in Annex 3, as required by Article 32;
- respect the conditions in Section 3 for engaging sub-processors;
- assist you, by appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights;
- assist you in ensuring compliance with Articles 32 to 36 — security, breach notification, and data protection impact assessments — taking into account the nature of processing and the information available to us;
- at your choice, delete or return Funnel Data at the end of the service, as set out in Section 6; and
- make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as set out in Section 7.
We will tell you if, in our opinion, an instruction you give infringes the GDPR or other applicable data protection law.
3. Sub-Processors
You give us general authorisation to engage sub-processors. The current list is in Annex 2. Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, tell us at support@tribefunnels.com and we will work with you in good faith to find an alternative; if none is available, you may terminate the affected service and receive a refund of the unused prepaid portion.
4. International Transfers
Where a sub-processor processes Funnel Data outside the European Economic Area, the transfer is made under the European Commission’s Standard Contractual Clauses or another valid Article 46 mechanism, supported by supplementary measures and a documented transfer impact assessment. Annex 2 identifies the mechanism relied on for each provider.
Funnel Data is never sent to our AI providers. Annex 2 lists every sub-processor we use across the Platform, including the AI providers that generate marketing content from the account holder’s own briefing material. Those providers do not receive Funnel Data — no lead, buyer, or visitor record is included in a generation request. Where Annex 2 records that a provider offers no Article 46 safeguard, that provider is outside the scope of this DPA for that reason.
5. Personal Data Breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Funnel Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will help you meet your own notification duties under Articles 33 and 34. Notice to you is not an admission of fault.
6. Deletion & Return
You can export Funnel Data from the Platform at any time. On termination, we retain it for 30 days so you can retrieve it, then delete it. On written request within that window we will return it in a commonly used machine-readable format or delete it earlier. We may retain Funnel Data where EU or member-state law requires, for as long as that law requires, and the obligations in this DPA continue to apply to it while we hold it.
7. Audit & Information
On reasonable written request, and no more than once a year unless a supervisory authority requires otherwise or a breach has occurred, we will provide the information necessary to demonstrate compliance with Article 28. Where that is not sufficient, we will allow an audit by you or an independent auditor you appoint who is not a competitor of ours, subject to reasonable notice, confidentiality, and conduct that does not disrupt the Platform. You bear the cost of an audit unless it reveals material non-compliance.
8. Your Obligations as Controller
You are responsible for:
- having a valid legal basis for collecting personal data through your funnel pages, and for obtaining any consent required — including for any analytics or advertising pixels you add;
- providing your visitors with the privacy information required by Articles 13 and 14, including your own identity and contact details;
- the accuracy and lawfulness of the instructions you give us; and
- responding to data subject requests addressed to you as controller, with our assistance.
9. Liability & Precedence
The limitation of liability in the Terms applies to this DPA, except where the GDPR provides otherwise. If this DPA conflicts with the Terms in respect of Funnel Data, this DPA prevails. If it conflicts with the Standard Contractual Clauses, those Clauses prevail. This DPA is published in English and Ukrainian; the English version governs if the two differ.
A1. Annex 1 — Details of the Processing
- Subject matter: provision of the Tribe Funnels platform to you.
- Duration: for as long as your account is active, plus the 30-day retention window in Section 6.
- Nature and purpose: collecting, storing, and displaying leads and buyer records generated by your published funnel pages; delivering purchased products to your buyers on your behalf; showing you your own leads and sales.
- Types of personal data: email address, hashed IP address, browser user-agent, UTM campaign parameters, purchase records, and any additional fields you choose to collect on your funnel pages.
- Categories of data subjects: visitors to, leads from, and buyers through your published funnel pages.
- Special category data: none is requested by the Platform. Do not configure your pages to collect it.
A2. Annex 2 — Sub-Processors
- Supabase — Database and file storageLocation: EU region
- Vercel — Application hosting and content deliveryLocation: United States / global edge · Transfer mechanism: EU Standard Contractual Clauses
- Stripe — Payment processingLocation: Ireland / United States · Transfer mechanism: EU Standard Contractual Clauses
- Resend — Transactional and product-delivery emailLocation: United States · Transfer mechanism: EU Standard Contractual Clauses
- Self-managed automation server (n8n) — Workflow automation, operated by us on our own infrastructureLocation: EU
- OpenAI — AI generation of marketing materialsLocation: United States · Transfer mechanism: EU Standard Contractual Clauses
- Anthropic — AI generation of marketing materialsLocation: United States · Transfer mechanism: EU Standard Contractual Clauses
- Google — AI generation of marketing materialsLocation: United States / EU · Transfer mechanism: EU Standard Contractual Clauses
- DeepSeek — AI generation of marketing materialsLocation: People's Republic of China · Transfer mechanism: No adequacy decision and no Standard Contractual Clauses offered by this provider — see "Transfers to China" below
A3. Annex 3 — Technical & Organisational Measures
- encryption of data in transit using TLS;
- storage in access-controlled infrastructure with row-level security policies;
- passwords hashed with bcrypt; IP addresses stored only as salted hashes;
- access to production data limited to personnel who need it, under confidentiality obligations;
- rate limiting, bot protection, and IP/email blocklisting to limit abuse;
- automated backups of the production database, and a 30-day soft-delete window before permanent purge;
- audit logging of account activity and of consent events; and
- vendor review before a new sub-processor is engaged.
We keep these measures under review and may update them, provided the level of protection is not reduced.
A4. Contact
Data protection queries: support@tribefunnels.com, or write to Remote Leads OÜ, Väike-Paala tn 1, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia.