Data Processing Addendum
Effective date: 11 August 2026
Last updated: 11 August 2026
This Data Processing Addendum (“DPA”) forms part of the PopupForge Terms of Service between the customer (“Controller”) and Lungu Andrei-Leonard PFA, trading as PopupForge (“Processor”), when PopupForge processes personal data in lead submissions on the customer's behalf.
1. Processing details
Subject and duration: providing lead collection, storage, analytics, notifications, exports and customer-configured integrations for the term of the customer account.
Data subjects: visitors, prospects, customers and other people who interact with the Controller's website or modal.
Data: contact details, form responses, page/referrer information, IP address, browser metadata and any other data the Controller chooses to collect. Customers must not collect special-category or highly sensitive data unless expressly agreed in writing.
2. Processor obligations
- Process personal data only on documented instructions from the Controller, including the Terms and product configuration.
- Ensure authorised personnel are bound by confidentiality obligations.
- Maintain appropriate technical and organisational security measures.
- Assist with data-subject requests, security incidents, impact assessments and regulator consultations where reasonably required.
- Delete or return personal data after termination, subject to legal obligations and limited backup retention.
3. Security measures
Measures include encrypted transport, access-controlled cloud infrastructure, server-side authorisation, signed sessions, input validation, rate limiting, anti-spam controls, logging and monitoring, backups provided by infrastructure vendors and procedures for vulnerability remediation and incident response.
4. Sub-processors
The Controller authorises sub-processors used for cloud hosting and databases, authentication, payments, transactional email, abuse prevention, AI generation, monitoring and support. PopupForge remains responsible for appropriate data-protection terms with sub-processors and will provide notice of material changes through the service or account email.
- Vercel: application hosting, serverless execution and delivery.
- Google Cloud / Firebase: database storage, authentication infrastructure and related cloud services.
- Google Gemini: AI generation when the customer uses the AI modal generator.
- Stripe: subscriptions, billing and payment processing.
- Resend: transactional email and customer-configured lead notifications.
- Upstash: distributed rate limiting and abuse prevention.
- Sentry: error monitoring and diagnostics.
- Cloudflare: Turnstile anti-bot verification when enabled by the customer.
5. International transfers
Where personal data is transferred outside the EEA, UK or Switzerland, the parties rely on an applicable adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum or another lawful transfer mechanism. The Controller authorises PopupForge to complete those clauses on its behalf where required.
6. Incidents and audits
PopupForge will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data and will provide information reasonably available to support required notifications. PopupForge will make relevant compliance information available and permit a reasonable audit where written documentation is insufficient, subject to confidentiality, security and cost controls.
7. Instructions and contact
The Controller must configure PopupForge lawfully, collect only necessary data and respond to data subjects. Additional instructions require written agreement and may incur reasonable costs. DPA questions can be sent to privacy@getpopupforge.com.
The Processor's registered office, registration number and tax identification code must be completed before relying on this DPA with customers.