Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service at roi.me/terms (or other written agreement) between Nead, LLC, doing business as ROI.me ("Processor", "ROI.me" or "we"), and the customer ("Customer"). It applies whenever ROI.me processes Customer Personal Data on the Customer's behalf. It takes effect when the Customer accepts the Terms; no separate signature is needed. Customers who want a countersigned copy can request one at [email protected].

Last updated September 28, 2026

1. Definitions

  • "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
  • "Customer Personal Data" means personal data within Customer Data (as defined in the Terms) that ROI.me processes on the Customer's behalf.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • "Sub-processor" means a third party engaged by ROI.me that processes Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • Terms such as "controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR; "business", "service provider" and "sell" have the meanings given in the CCPA.

2. Roles and scope

The Customer is the controller (or, where it acts for its own clients, a processor) of Customer Personal Data, and ROI.me is its processor (or sub-processor). Annex 1 describes the processing. ROI.me is an independent controller only for the account, billing and usage information it processes to run its business, as described in its Privacy Policy at roi.me/privacy.

3. Customer instructions

  • ROI.me will process Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA and the Customer's configuration and use of the Service (including connecting advertising networks and other services, and syncing audiences to them) are the Customer's complete instructions. Additional instructions require written agreement.
  • ROI.me will tell the Customer if it believes an instruction infringes Data Protection Laws, unless the law prohibits that.
  • The Customer is responsible for the lawfulness of the processing it instructs, including providing notices and obtaining any consents required from its website visitors and customers (for example, for cookies and advertising), and for the accuracy of the data it provides.

4. Processor obligations

  • Confidentiality. Personnel authorized to process Customer Personal Data are bound by confidentiality obligations, and access is limited to those who need it.
  • Security. ROI.me implements and maintains the technical and organizational measures in Annex 2, and may update them provided the overall level of protection is not reduced.
  • No other use. ROI.me will not sell or share Customer Personal Data, use it for its own purposes (including training AI models), or combine it with personal data from other customers or sources, except as permitted by Data Protection Laws for a service provider.
  • Assistance. Taking into account the nature of the processing, ROI.me will assist the Customer with data protection impact assessments and prior consultations with authorities, to the extent the Customer cannot do so using the Service.

5. Data subject requests

The Service lets the Customer access, export, correct and erase Customer Personal Data, including erasing all data about a person by email address (in the organization settings, under Privacy requests) or from a visitor's page. Erasure removes the person's profile, identifiers, audience memberships, matching CRM records and website activity. If ROI.me receives a request directly from a data subject about Customer Personal Data, it will refer the data subject to the Customer (without responding itself, unless required by law) and give reasonable help where the Customer cannot fulfil the request through the Service.

6. Sub-processors

  • The Customer gives general authorization for ROI.me to engage Sub-processors. The current list, with each Sub-processor's purpose and location, is at roi.me/subprocessors and forms Annex 3.
  • ROI.me will give at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by updating that page and notifying account owners by email or in the application.
  • The Customer may object on reasonable data protection grounds within that notice period by writing to [email protected]. The parties will discuss the concern in good faith. If ROI.me cannot reasonably accommodate it, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the remaining term.
  • ROI.me imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for its Sub-processors' performance.
  • Advertising networks, CRMs and other services the Customer chooses to connect are not Sub-processors: the Customer instructs ROI.me to send data to them, and their processing is governed by the Customer's own agreements with them.

7. Security incidents

ROI.me will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. ROI.me will provide further information as it becomes available, take reasonable steps to contain and remedy the incident, and assist the Customer with its own notification obligations. Notification is not an acknowledgment of fault.

8. Return and deletion

During the subscription, the Customer can export and delete Customer Personal Data using the Service. When the Customer deletes its organization or the Agreement ends, ROI.me will delete Customer Personal Data within 30 days, unless the law requires it to be kept. Residual copies in backups are deleted as backups expire on their rolling schedule (no more than 12 months) and remain protected by this DPA until then.

9. Audits

ROI.me will make available the information reasonably necessary to demonstrate compliance with this DPA, including by answering reasonable security questionnaires and providing summaries of its security measures. If that information is not sufficient to satisfy an obligation under Data Protection Laws or a regulator's request, the Customer may, at its own cost and no more than once a year (unless following a Security Incident or regulator request), conduct an audit on at least 30 days' notice, during business hours, in a way that does not disrupt the Service or compromise other customers' data or ROI.me's confidential information. Auditors must be bound by confidentiality.

10. International transfers

  • ROI.me and its Sub-processors process Customer Personal Data in the United States and the European Union.
  • EEA. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor. For the SCCs: the optional docking clause (Clause 7) applies; Clause 9 option 2 (general authorization) applies with the notice period in Section 6; the option in Clause 11 does not apply; Clause 17 option 1 applies, with the law of Ireland; the courts of Ireland are chosen under Clause 18(b); and Annexes I to III are completed by Annexes 1 to 3 of this DPA. The supervisory authority is that of the Customer's EU representative or establishment, as Clause 13 provides.
  • UK. For transfers subject to UK data protection law, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies, completed with the information in this DPA; either party may end it as permitted by its Section 19.
  • Switzerland. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
  • Where ROI.me is certified under the EU-US Data Privacy Framework or a successor mechanism, it may rely on that instead. If a transfer mechanism is invalidated, the parties will cooperate to put an alternative in place.

11. US state privacy laws

For Customer Personal Data subject to the CCPA or similar US state laws, ROI.me is a service provider (or processor). ROI.me will not sell or share it, will not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than performing the Service, will not combine it with personal information from other sources except as permitted by law, will comply with applicable obligations and provide the same level of privacy protection the law requires, and will notify the Customer if it can no longer meet its obligations. The Customer may take reasonable steps to stop and remediate unauthorized use. ROI.me certifies that it understands these restrictions.

12. Liability and general terms

Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow it. If this DPA conflicts with the Terms, this DPA controls for data protection matters; if it conflicts with the SCCs, the SCCs control. This DPA lasts as long as ROI.me processes Customer Personal Data.

13. Annex 1: Details of processing

ItemDescription
PartiesData exporter: the Customer, as identified in its account, acting as controller (or processor). Data importer: Nead, LLC (ROI.me), [email protected], acting as processor (or sub-processor).
Subject matterProviding the Service under the Agreement.
DurationThe term of the Agreement, plus up to 30 days for deletion (and backup expiry as described in Section 8).
Nature and purposeCollecting, storing, analyzing and transmitting data to provide website analytics, visitor intent and identity resolution from customer-provided identifiers, audience building and syncing to connected advertising networks, creative generation, campaign management, conversion measurement and attribution, reporting, ROI Agent answers, support and security.
Data subjectsVisitors to the Customer's websites; the Customer's leads, prospects and customers; and individuals appearing in content the Customer uploads.
Categories of personal dataPseudonymous visitor and session identifiers; website activity (pages, events, referrers, campaign parameters); device type, browser, operating system and approximate country; one-way hashes of email addresses and phone numbers; customer identifiers; CRM and commerce records (such as names, deal and order values and stages); advertising audience membership; and images, video or audio of people the Customer uploads.
Special categoriesNone. The Customer must not send special categories of personal data.
FrequencyContinuous, while the Customer uses the Service.
RetentionWebsite activity up to 25 months; other data for the term of the Agreement; deletion as in Section 8.

14. Annex 2: Technical and organizational measures

  • Encryption: TLS for data in transit; stored third-party credentials (OAuth tokens, integration secrets, webhook secrets) encrypted with AES-256-GCM using keys held outside the database and rotated through a keyring; API keys and session tokens stored only as hashes.
  • Access control: role-based permissions enforced in the service layer; API keys limited to scopes and to what their creator may do; staff access to customer accounts only through a time-limited, read-only, logged support session visible to the customer.
  • Customer isolation: every query is scoped to the customer's organization; automated tests check that internal identifiers never leave the service.
  • Spend safeguards: human approval with budget confirmation for launches; configurable autonomy levels with hard financial limits, daily caps and cooldowns; a platform-wide emergency stop; logging of every spend-affecting network call.
  • Data minimization: the ROI Pixel drops form contents and passwords, redacts values resembling card numbers and government identifiers, hashes emails, and does not store IP addresses with activity; advertising networks receive only hashed identifiers.
  • Application security: input validation on every boundary; protection against server-side request forgery, cross-site request forgery and clickjacking; a Content Security Policy; rate limiting; signed and verified webhooks; dependency auditing.
  • Logging and monitoring: an append-only audit log of security-relevant and spend-affecting actions, available to the Customer; health checks on every service.
  • Availability and recovery: daily encrypted database backups stored off-server, event data backups, versioned asset storage, and tested restores.
  • Secure development: code review, automated tests (including tests that block real network and ad calls), and separation of development and production environments.
  • Personnel: confidentiality obligations and least-privilege access for personnel.
  • Incident response: a documented process for containment, investigation and customer notification.

15. Annex 3: Sub-processors

The Sub-processors authorized under Section 6 are listed at roi.me/subprocessors.