Skip to content
Nvektor
  • Why it breaks
  • How it works
  • Architecture
  • Comparison
  • Pricing
LOG IN
GET STARTED

Legal

Data Processing Addendum

Last updated: 27 July 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Wahecos Commerce Digital, LLC (“nVektor”, “we”, “us”, or “our”) and the customer agreeing to use the nVektor Service (“Customer”, “you”, or “your”).

This DPA applies where nVektor processes Personal Data on behalf of Customer in connection with the nVektor Service.

1. Definitions

Agreement means the nVektor Terms of Service, order form, subscription agreement, master services agreement, or other agreement governing Customer’s use of the nVektor Service.

Applicable Data Protection Laws means all privacy, data protection, electronic communications, cookie, tracking, and consumer privacy laws applicable to the processing of Personal Data under the Agreement, including where applicable, the GDPR, UK GDPR, Data Protection Act 2018, PECR, CCPA/CPRA, and similar laws.

Customer Data means data submitted to, collected through, generated by, or processed by the nVektor Service on behalf of Customer, including End User Data, event data, attribution data, order data, configuration data, and related technical data.

End User means an individual who visits, browses, interacts with, or purchases from a Customer website, store, checkout, or other digital property.

End User Data means Customer Data relating to an End User, which may include online identifiers, cookie identifiers, device and browser information, IP address, user agent, event data, order and transaction data, hashed contact identifiers where provided, referral data, click identifiers, attribution data, and similar information made available through Customer’s website, ecommerce platform, or configuration.

Personal Data means any Customer Data that is personal data, personal information, personally identifiable information, or similar regulated information under Applicable Data Protection Laws.

Personal Information has the meaning given to that term under the CCPA/CPRA.

Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed by nVektor on behalf of Customer.

Service or nVektor Service means nVektor’s tracking, attribution, event processing, reporting, debugging, delivery, dashboard, API, and related services.

Subprocessor means a third party engaged by nVektor to process Personal Data on behalf of Customer in connection with the Service.

Terms such as “controller”, “processor”, “business”, “service provider”, “contractor”, “consumer”, “data subject”, “sale”, “share”, and “processing” have the meanings given to them under Applicable Data Protection Laws.

2. Roles of the Parties

As between Customer and nVektor, Customer determines the purposes and means of processing Customer Data.

Customer acts as the controller, business, or equivalent role with respect to End User Data.

nVektor acts as the processor, service provider, contractor, or equivalent role with respect to End User Data processed on behalf of Customer.

nVektor does not control Customer’s website, store, cookie banner, consent tool, privacy policy, advertising account, ecommerce platform, or relationship with End Users.

3. Customer Instructions

Customer instructs nVektor to process Personal Data as necessary to provide, secure, support, maintain, and improve the Service in accordance with the Agreement, this DPA, Customer’s configuration of the Service, and Customer’s written instructions.

Customer’s instructions include processing Personal Data to:

  1. receive, validate, enrich, and process events from Customer websites and stores;
  2. support attribution, event matching, conversion tracking, reporting, and debugging;
  3. process visitor, session, customer, order, event, and attribution records;
  4. transmit events or derived events to Customer-selected destinations;
  5. provide dashboards, logs, health checks, delivery records, match-quality reporting, and support;
  6. secure, monitor, maintain, and improve the Service;
  7. comply with legal obligations and enforce the Agreement.

nVektor will process Personal Data only on Customer’s documented instructions unless required to do otherwise by applicable law. If nVektor is required by law to process Personal Data other than on Customer’s instructions, nVektor will notify Customer unless legally prohibited from doing so.

nVektor will inform Customer if, in nVektor’s reasonable opinion, a Customer instruction infringes Applicable Data Protection Laws.

4. Customer Responsibilities

Customer is responsible for the lawfulness of Customer’s collection, use, disclosure, and processing of Customer Data.

Customer represents and warrants that:

  1. Customer has provided all required notices to End Users;
  2. Customer has obtained all required consents and permissions;
  3. Customer has a lawful basis for collecting and processing End User Data;
  4. Customer’s privacy policy, cookie notice, terms, consent flows, and disclosures accurately describe Customer’s use of analytics, attribution, advertising, tracking, service providers, and data processing partners;
  5. Customer’s use of the Service complies with Applicable Data Protection Laws;
  6. Customer’s use of the Service complies with applicable ecommerce platform and advertising platform terms;
  7. Customer will not send prohibited, sensitive, or unnecessary Personal Data to nVektor unless expressly agreed in writing;
  8. Customer will honour End User choices, opt-outs, access requests, deletion requests, and other privacy rights.

Customer is solely responsible for configuring the Service lawfully, including determining which events, identifiers, destinations, and integrations are enabled.

5. nVektor Responsibilities

nVektor will:

  1. process Personal Data only as described in the Agreement, this DPA, Customer’s configuration, and Customer’s documented instructions;
  2. ensure that personnel authorised to process Personal Data are bound by confidentiality obligations;
  3. implement reasonable technical and organisational measures designed to protect Personal Data;
  4. assist Customer with privacy requests where required by Applicable Data Protection Laws, taking into account the nature of the processing and the functionality of the Service;
  5. assist Customer with security, breach notification, and data protection impact assessment obligations where required by Applicable Data Protection Laws;
  6. maintain appropriate records of processing where required by law;
  7. use Subprocessors only in accordance with this DPA;
  8. delete or return Personal Data in accordance with this DPA and the Agreement.

6. CCPA / CPRA Service Provider Terms

Where CCPA/CPRA applies, Customer discloses Personal Information to nVektor only for the limited and specified business purposes described in the Agreement and this DPA.

nVektor will not retain, use, or disclose Personal Information except:

  1. to provide the Service to Customer;
  2. for the business purposes described in this DPA;
  3. to retain and use permitted Subprocessors;
  4. to detect, prevent, or investigate security incidents, fraud, abuse, or unlawful activity;
  5. to improve the quality, reliability, and security of the Service, provided nVektor does not use Customer’s Personal Information to provide services to another customer;
  6. as otherwise permitted by CCPA/CPRA.

nVektor will not sell or share Personal Information as those terms are defined by CCPA/CPRA.

nVektor will not retain, use, or disclose Personal Information outside the direct business relationship between nVektor and Customer except as permitted by CCPA/CPRA.

nVektor will not combine Personal Information received from Customer with Personal Information received from another customer or collected from nVektor’s own interaction with an End User, except as permitted by CCPA/CPRA.

nVektor will notify Customer if nVektor determines that it can no longer meet its obligations under CCPA/CPRA.

Customer has the right to take reasonable and appropriate steps to ensure that nVektor processes Personal Information consistently with Customer’s obligations under CCPA/CPRA.

7. Security Measures

nVektor will implement reasonable technical and organisational measures designed to protect Personal Data against unauthorised access, disclosure, alteration, loss, or destruction.

These measures may include, as appropriate:

  1. access controls;
  2. authentication controls;
  3. least-privilege access practices;
  4. encryption in transit where supported;
  5. secret management practices;
  6. logging and monitoring;
  7. backup and recovery controls;
  8. vulnerability management;
  9. personnel confidentiality obligations;
  10. incident response procedures;
  11. separation of customer environments or logical tenant isolation where applicable.

Customer acknowledges that no online service, storage system, or transmission method can be guaranteed to be completely secure.

Customer remains responsible for securely configuring Customer’s own website, store, advertising accounts, ecommerce platform, consent tools, API keys, credentials, and integrations.

8. Security Incidents

nVektor will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data processed by nVektor on behalf of Customer.

The notification will include information reasonably available to nVektor, which may include:

  1. the nature of the Security Incident;
  2. the categories of Personal Data affected;
  3. the approximate number of affected records, where known;
  4. steps taken or planned to mitigate the Security Incident;
  5. information reasonably needed by Customer to meet its own legal obligations.

nVektor’s notification of a Security Incident is not an admission of fault or liability.

Customer is responsible for determining whether the Security Incident triggers any notification obligations to regulators, End Users, or other parties.

9. End User Requests

Customer is responsible for receiving and responding to End User privacy requests.

Where required by Applicable Data Protection Laws, nVektor will reasonably assist Customer in responding to End User requests relating to Personal Data processed by nVektor on Customer’s behalf.

Customer must provide sufficient information for nVektor to identify relevant records, such as email, hashed email, phone number, order identifier, visitor identifier, session identifier, event identifier, or other applicable identifier.

If nVektor receives a privacy request directly from an End User relating to Customer Data, nVektor may direct the End User to contact Customer, or may act on the request in accordance with Customer’s instructions.

10. Subprocessors

Customer provides general authorisation for nVektor to use Subprocessors to provide, secure, host, monitor, maintain, and support the Service.

nVektor will maintain an up-to-date list of Subprocessors used to process Personal Data on behalf of Customer. The current list is available upon written request to hello@nvektor.com.

nVektor will require each Subprocessor to process Personal Data only as necessary to provide services to nVektor and under confidentiality, security, and data protection obligations that provide an appropriate level of protection.

nVektor remains responsible to Customer for the performance of its Subprocessors’ data protection obligations to the extent required by Applicable Data Protection Laws.

nVektor will notify Customer of intended additions or replacements to its Subprocessors where required by Applicable Data Protection Laws and will provide Customer a reasonable opportunity to object on legitimate data protection grounds. If the parties cannot resolve the objection, Customer may stop using the affected Service feature or terminate the affected Service in accordance with the Agreement.

11. International Transfers

Customer authorises nVektor and its Subprocessors to process Personal Data in locations where nVektor or its Subprocessors operate.

Where Personal Data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country that has not been recognised as providing an adequate level of protection, the parties will use an appropriate transfer mechanism, such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.

Where an applicable transfer mechanism requires additional information or execution, the parties will complete and enter into the required transfer documentation.

12. Retention

nVektor retains Customer Data for the duration of Customer’s subscription and for as long as necessary to provide the Service, maintain historical attribution and reporting, support debugging and service reliability, comply with legal obligations, resolve disputes, enforce agreements, and follow Customer instructions.

Retention periods may vary depending on the type of data, Customer’s configuration, subscription plan, applicable laws, technical requirements, and whether the data remains necessary to provide the Service.

nVektor may retain structured records, including order records, session records, visitor records, attribution records, event delivery records, and reporting summaries, for as long as needed to provide historical reporting, attribution analysis, service support, and account history.

nVektor may retain raw event payloads, diagnostic logs, and other high-volume operational data for shorter periods, or may archive, delete, minimise, anonymise, or de-identify such data when it is no longer required for active debugging, validation, security, or service operation.

Aggregated or de-identified data may be retained where it no longer identifies Customer, Customer Users, or End Users.

13. Deletion or Return

Upon termination of the Agreement, or upon Customer’s written instruction, nVektor will delete or return Personal Data processed on behalf of Customer within 60 days, unless retention is required or permitted by applicable law.

nVektor may retain Personal Data where necessary to:

  1. comply with legal obligations;
  2. resolve disputes;
  3. enforce the Agreement;
  4. maintain security;
  5. prevent fraud, abuse, or unlawful activity;
  6. maintain backup or disaster recovery copies until overwritten or deleted in the ordinary backup lifecycle.

Backup and disaster recovery copies will be protected from active processing and deleted according to nVektor’s ordinary backup lifecycle, unless legally required to retain them.

14. Audits and Compliance Information

Upon Customer’s reasonable written request, nVektor will provide information reasonably necessary to demonstrate compliance with this DPA.

Customer may request an audit no more than once per calendar year, unless required by Applicable Data Protection Laws or following a confirmed Security Incident affecting Customer’s Personal Data.

Any audit must:

  1. be conducted during normal business hours;
  2. be subject to reasonable advance notice;
  3. not unreasonably disrupt nVektor’s business;
  4. protect the confidentiality and security of nVektor systems and other customers’ data;
  5. be conducted by Customer or an independent auditor bound by confidentiality.

nVektor may satisfy audit requests by providing security documentation, policies, summaries, certifications, or third-party audit materials where available.

15. Data Protection Impact Assessments

Taking into account the nature of the processing and information available to nVektor, nVektor will reasonably assist Customer with data protection impact assessments, prior consultations, and similar assessments required by Applicable Data Protection Laws.

Customer remains responsible for determining whether a data protection impact assessment or prior consultation is required.

16. Sensitive Data

Customer must not submit Sensitive Data to the Service unless expressly agreed in writing.

For purposes of this DPA, Sensitive Data includes government identifiers, payment card numbers, financial account credentials, health information, biometric information, precise geolocation, children’s data, special category data under GDPR, sensitive personal information under CCPA/CPRA, or similar regulated data.

Customer is responsible for ensuring that Customer’s website, store, ecommerce platform, custom events, and integrations do not send Sensitive Data to nVektor unless authorised.

17. Limitation of Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent prohibited by Applicable Data Protection Laws.

Nothing in this DPA limits either party’s liability where liability cannot be limited under applicable law.

18. Order of Precedence

If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls to the extent of the conflict.

If there is a conflict between this DPA and mandatory provisions of Applicable Data Protection Laws, Applicable Data Protection Laws control.

19. Processing Details

The subject matter, duration, nature, purpose, categories of Personal Data, and categories of data subjects are described in Schedule 1.

The technical and organisational measures are described in Schedule 2.


Schedule 1 – Processing Details

Subject Matter

nVektor processes Personal Data to provide tracking, attribution, event processing, reporting, debugging, delivery, dashboard, API, and related services to Customer.

Duration

nVektor processes Personal Data for the duration of the Agreement and as otherwise described in this DPA.

Nature of Processing

The processing may include collection, receipt, transmission, hosting, storage, validation, enrichment, matching, hashing, transformation, analysis, reporting, retrieval, deletion, archiving, and disclosure to Customer-selected destinations.

Purposes of Processing

The purposes of processing include:

  1. receiving and processing events from Customer websites and stores;
  2. identifying visitors, sessions, orders, and attribution signals;
  3. supporting conversion tracking and attribution reporting;
  4. sending events or derived events to Customer-selected platforms;
  5. providing dashboards, logs, debugging, service health, and support;
  6. securing, monitoring, maintaining, and improving the Service;
  7. complying with legal obligations and enforcing the Agreement.

Categories of Data Subjects

The categories of data subjects may include:

  1. End Users;
  2. Customer’s shoppers, visitors, buyers, leads, and prospects;
  3. Customer Users;
  4. Customer personnel and representatives.

Categories of Personal Data

The categories of Personal Data may include:

  1. online identifiers;
  2. cookie identifiers;
  3. visitor identifiers;
  4. session identifiers;
  5. advertising and click identifiers;
  6. IP address;
  7. user agent;
  8. device, browser, and operating system data;
  9. event data, such as page views, product views, cart events, checkout events, and purchases;
  10. order and transaction data;
  11. product and cart data;
  12. referral URLs;
  13. UTM parameters;
  14. attribution and channel data;
  15. hashed contact identifiers where provided, such as hashed email or hashed phone;
  16. Customer account and configuration data;
  17. diagnostic, log, and security data.

Sensitive Data

Sensitive Data is not required for the Service and must not be submitted unless expressly agreed in writing.

Processing Frequency

Processing occurs continuously or as events, integrations, configurations, support activity, and Service operations require.


Schedule 2 – Technical and Organisational Measures

nVektor will maintain reasonable technical and organisational measures designed to protect Personal Data, which may include:

  1. access controls based on role and need;
  2. authentication controls for internal systems;
  3. restricted production access;
  4. confidentiality obligations for personnel;
  5. encryption in transit where supported;
  6. secure handling of secrets and credentials;
  7. database access controls;
  8. logging and monitoring;
  9. backup and recovery practices;
  10. incident response procedures;
  11. vulnerability and dependency management;
  12. separation of customer data through logical access controls;
  13. secure development practices;
  14. review of Subprocessors used to provide the Service;
  15. deletion, archiving, or minimisation practices for data no longer required for active Service operation.

Attribution at the edge.

product

How It Works

Comparison

Architecture

Pricing

LEGAL

Data Protection And Compliance

Data Processing Addendum

Privacy Policy

Terms Of Service

Terms Of Use

Cookie Notice


© 2026 Nvektor. Wahecos Commerce Digital, LLC.


Built for Shopify, WooCommerce & custom checkouts

312 West 2nd Street
Casper, WY, USA