← All legal documents

Noetis — Data Processing Agreement

Version 2.0 · Effective date: to be announced upon release · Last updated: to be announced upon release

This Data Processing Agreement ("DPA") forms part of the agreement between Final Frame trading as Noetis ("Noetis", "Processor") and Customer ("Customer", "Controller") concerning the Service.

It is intended to satisfy Article 28 GDPR.

Where Customer acts as processor for another controller, Noetis acts as Customer's subprocessor and references to Controller instructions include instructions Customer is lawfully authorised to give.

1. Roles

Legal roles depend on the actual processing, not on contractual labels alone.

For Customer Personal Data processed through Customer's use of the Service:

Customer determines the purposes and essential means of processing and acts as Controller, unless Customer itself acts as Processor.

Noetis acts as Processor and processes Customer Personal Data on Customer's documented instructions.

Noetis separately acts as Controller for its own account administration, billing, fraud prevention, security administration, legal compliance and other processing described in its Privacy Policy.

Nothing in this DPA artificially determines a role where applicable law determines otherwise.

2. Instructions

Noetis shall process Customer Personal Data only:

  • to provide the Service;
  • in accordance with this DPA;
  • in accordance with the Terms;
  • pursuant to Customer's configuration and feature choices;
  • pursuant to Customer's API or technical instructions; and
  • where required by Union or Member State law.

Enabling a feature, data source, Visitor Intelligence, consent category, experiment, Autonomous Mode, Optimisation Boundary or publication rule constitutes a documented instruction to the extent it causes processing on Customer's behalf.

If Noetis believes an instruction infringes applicable data-protection law, Noetis shall inform Customer and may suspend the affected processing pending clarification or modification.

3. Subject matter and duration

The subject matter is the provision of Noetis's website intelligence, optimisation, personalisation, experimentation and growth functionality.

Processing continues for the Subscription term and any limited period necessary for return, deletion, backup expiry, security, dispute handling or mandatory retention.

4. Nature and purposes

Depending on Customer configuration, processing may include:

  • website hosting;
  • collection of behavioural events;
  • analytics;
  • heatmaps;
  • session recordings;
  • section visibility measurement;
  • click and interaction measurement;
  • scroll and dwell-time measurement;
  • Visitor Identifier creation and storage;
  • cross-session recognition where lawfully enabled;
  • aggregation of behavioural histories;
  • creation and updating of Visitor Profiles;
  • inference of interests and preferences;
  • inference of behavioural or commercial intent signals;
  • behavioural segmentation;
  • persona hypotheses;
  • confidence scoring;
  • experimentation;
  • cohort and control-group assignment;
  • automated content selection;
  • Personalisation;
  • rendering and exposure measurement;
  • conversion and interaction measurement;
  • causal or statistical experimentation;
  • AI generation and evaluation;
  • Growth Engine operation;
  • autonomous optimisation;
  • storage;
  • support;
  • security;
  • deletion and export.

5. Categories of Personal Data

Depending on Customer configuration:

Identifiers

  • pseudonymous Visitor Identifier;
  • session identifier;
  • IP address;
  • online identifiers;
  • device/browser identifiers where applicable;
  • consent and preference state.

Behavioural Data

  • page and URL visits;
  • timestamps;
  • navigation sequence;
  • click events;
  • CTA interactions;
  • section visibility;
  • scroll depth;
  • dwell time;
  • repeat visits;
  • referral and attribution information;
  • experiment interactions;
  • form interaction metadata.

Derived Data

  • inferred interests;
  • inferred preferences;
  • behavioural segments;
  • persona hypotheses;
  • inferred intent;
  • engagement indicators;
  • confidence or probability scores.

Derived Data represents probabilistic inference and does not necessarily represent fact.

Decision and Experiment Data

  • eligibility;
  • experiment/cohort assignment;
  • selected treatment;
  • reason or signals associated with selection;
  • render status;
  • viewability;
  • interaction;
  • conversion;
  • experiment outcome.

Customer-provided information

Personal Data contained in Customer content, integrations or data sources connected by Customer.

6. Data subjects

Data subjects may include:

  • Visitors and End Users of Customer Properties;
  • Customer leads and customers where Customer lawfully connects such information;
  • Customer personnel and authorised Platform users.

7. Sensitive data restrictions

The Service is not intended to process or infer special categories under Article 9 GDPR or criminal-conviction data under Article 10 for Visitor Intelligence or Personalisation, whether directly or through deliberate indirect proxies.

Customer shall not instruct Noetis to infer or target Visitors using such information unless specifically agreed in writing.

Noetis may implement technical safeguards designed to prevent sensitive inference.

If potentially sensitive information is inadvertently collected, Noetis may suppress, delete, quarantine or otherwise prevent its use for profiling or Personalisation.

Customer is responsible for:

  • determining lawful purposes;
  • establishing an applicable lawful basis;
  • providing required privacy information;
  • determining whether consent is required;
  • obtaining and recording valid consent where required;
  • configuring its CMP or consent mechanism correctly;
  • transmitting accurate consent states to Noetis;
  • honouring withdrawals and objections; and
  • ensuring Customer's instructions are lawful.

Noetis shall provide functionality reasonably designed to respect supported consent states.

For processing configured as consent-dependent, only a supported affirmative consent state constitutes an instruction to activate that processing. An unknown, missing, malformed, rejected or withdrawn consent state does not count as consent.

A technical consent state received or stored by Noetis is distinct from legal evidence of consent. Noetis may receive and store a consent state without becoming the authoritative consent-evidence repository. Customer remains responsible for obtaining consent and for maintaining, or ensuring the availability of, evidence of consent where required.

Noetis may rely on consent and preference signals transmitted by Customer unless Noetis has reason to know they are invalid.

9. Withdrawal and profile suppression

Where Noetis receives a supported withdrawal, opt-out, objection or deletion instruction from Customer for consent-dependent Visitor Intelligence, then for the relevant identifier:

  • further processing based on the withdrawn consent shall cease;
  • consent-dependent cross-session recognition shall cease;
  • profile enrichment and profile updating shall cease;
  • consent-dependent inference shall cease;
  • consent-dependent Personalisation, including use of the profile for consent-dependent treatment selection, shall cease;
  • consent-dependent onward processing shall cease; and
  • background processes shall not silently reactivate the withdrawn processing.

Where a Visitor Profile or associated Personal Data exists solely because of the withdrawn consent and no independent lawful retention ground applies, it shall enter the applicable deletion lifecycle in accordance with Customer's instruction and the retention architecture.

Suppression data may be retained only where necessary to enforce the withdrawal, objection or deletion, or where another lawful retention obligation applies, and shall not be used for profiling or Personalisation.

Historical behavioural data shall not be used to silently reconstruct the withdrawn consent-dependent Visitor Profile. A return visit to the website does not by itself reactivate the withdrawn purpose. Where consent is legally required, a new valid affirmative consent state is required before the withdrawn processing may resume.

Withdrawal does not affect the lawfulness of processing performed before withdrawal.

Customer is responsible for ensuring that withdrawal signals reach Noetis correctly.

10. Article 22 and significant decisions

The Service is not intended for solely automated decisions producing legal effects or similarly significant effects concerning individuals.

Customer shall not instruct Noetis to perform such processing unless separately agreed and all Article 22 and other applicable requirements have been satisfied.

11. Confidentiality

Persons authorised by Noetis to process Customer Personal Data shall be subject to confidentiality obligations.

Access shall be limited according to role and legitimate operational need.

12. Security

Noetis shall implement appropriate technical and organisational measures under Article 32 GDPR, taking into account:

  • state of the art;
  • implementation costs;
  • nature and scope of processing;
  • context and purposes;
  • likelihood and severity of risks.

Current measures are described in Annex II and the Security & Compliance Addendum.

Noetis may update controls provided the overall level of protection is not materially reduced.

13. Personal Data Breach

Noetis shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Noetis shall provide information reasonably available to it concerning:

  • nature of the breach;
  • categories of affected data;
  • likely consequences;
  • measures taken or proposed; and
  • contact information.

Information may be supplied in phases.

Notification does not constitute an admission of fault or liability.

Customer remains responsible for determining its own notification obligations as Controller.

14. Data-subject requests

Taking into account the nature of processing, Noetis shall reasonably assist Customer in responding to applicable data-subject rights.

Where Noetis directly receives a request concerning Customer Personal Data, Noetis shall ordinarily refer the requester to Customer unless prohibited by law.

Noetis shall not independently respond substantively on Customer's behalf unless instructed or legally required.

15. DPIAs and regulatory assistance

Taking into account the nature of processing and information available to Noetis, Noetis shall reasonably assist Customer with Articles 32–36 GDPR.

Customer remains responsible for determining whether a DPIA, legitimate-interest assessment, consent assessment or prior consultation is required.

16. Subprocessors

Customer grants Noetis general written authorisation to engage subprocessors.

Noetis shall:

  • impose appropriate Article 28 obligations on subprocessors;
  • remain responsible to Customer for performance of applicable processor obligations by its subprocessors as required by GDPR;
  • maintain a current subprocessor list; and
  • provide at least 30 days' notice of a new or replacement subprocessor where reasonably practicable.

Customer may object during that period on reasonable and documented data-protection grounds.

The parties shall attempt to resolve the objection.

If no reasonable solution exists, Customer may terminate only the affected Service without penalty, and Noetis shall refund prepaid fees attributable to the unused affected Service period.

17. International transfers

Where Customer Personal Data is transferred outside the EEA and an adequacy decision does not provide the relevant transfer mechanism, the parties shall use an applicable lawful transfer mechanism.

Where required, Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses are incorporated:

  • Module Two for controller-to-processor transfers;
  • Module Three where Customer is a processor;
  • Clause 7 docking applies;
  • Clause 9 Option 2 applies;
  • the Netherlands is the governing Member State where permitted;
  • competent Dutch courts apply where permitted.

Where an applicable recipient validly participates in the EU-US Data Privacy Framework and that mechanism may lawfully be relied upon, it may be used.

The transfer mechanism actually used for each relevant processing flow is identified in Noetis's operational transfer records as they are verified and maintained.

18. Audits

Noetis shall make available information reasonably necessary to demonstrate compliance with Article 28.

Noetis may first satisfy audit requests through:

  • security documentation;
  • questionnaires;
  • certifications or attestations where available;
  • penetration-test summaries where available;
  • independent audit materials.

Where those materials are reasonably insufficient, Customer may request an audit by itself or an independent auditor subject to confidentiality.

Unless required by a supervisory authority or following a material Personal Data Breach attributable to Noetis, ordinary audits are limited to once per twelve months, on reasonable prior notice and without unreasonable disruption.

Audits must not compromise other customers' confidentiality or security.

19. Return and deletion

Upon termination, Noetis shall, at Customer's choice and subject to available functionality, return or delete Customer Personal Data except where retention is legally required.

The deletion architecture recognises, where applicable, the different data classes involved, including raw behavioural events, Visitor Profiles, Derived Data, session information, experiment assignments, Personalisation Records, session recordings, AI-related Customer Personal Data, operational copies and backups.

Deletion of a consent-dependent Visitor Profile is not complete if production systems automatically reconstruct substantially the same profile from retained historical Personal Data without an applicable lawful basis.

Customer should export Customer Data before termination.

Residual copies contained in ordinary backups may remain until expiry of the applicable backup cycle, provided they remain protected and are not used for normal production processing and are not restored except for legitimate disaster-recovery purposes. If a backup is restored for disaster recovery, applicable deletion and suppression states shall be reapplied where technically and legally required.

20. Cross-customer separation

Noetis shall not use pseudonymous or identifiable Visitor Profiles from one Customer to identify, advertise to or behaviourally target the same individual for an unrelated Customer.

Pseudonymised data is not treated as anonymous merely because direct identifiers are absent.

This does not prohibit use of genuinely aggregated or de-identified information that is no longer Personal Data.

21. Liability

Liability between the parties under this DPA is governed by the liability framework in the Terms except where mandatory data-protection law requires otherwise.

Nothing limits rights a data subject may have under Article 82 GDPR.


Annex I — Processing Details

Controller: Customer.

Processor: Final Frame trading as Noetis.

Subject matter: provision of the Service.

Duration: Subscription plus applicable wind-down, retention and backup periods.

Frequency: continuous or as configured by Customer.

Purpose: website intelligence, analytics, experimentation, Personalisation, optimisation, Growth Engine functionality, security, support and related Service operation.

Categories of data subjects: Customer website Visitors, End Users, leads/customers where connected by Customer, and Customer personnel where relevant.

Categories of Personal Data: as described in Sections 5–6.


Annex II — TOMs

Noetis maintains measures appropriate to the risk, including as applicable:

  • encryption in transit;
  • encryption at rest provided by relevant infrastructure;
  • additional application-level encryption for designated sensitive fields;
  • access control;
  • least privilege;
  • authentication controls;
  • tenant isolation;
  • logging and monitoring;
  • rate limiting;
  • backup and recovery;
  • incident response;
  • secure development practices;
  • vulnerability management;
  • data-retention controls;
  • secrets management;
  • change management.

Detailed implementation is described in the Security & Compliance Addendum and may evolve as security practices and infrastructure change.


Annex III — Subprocessors

Noetis maintains its authoritative current subprocessor register at its designated legal/compliance location. Verification of the production inventory is ongoing; the register is not represented as exhaustive until that verification is complete.

At the date of this DPA, subprocessors may include providers used for:

  • hosting/CDN/compute;
  • database/authentication/storage;
  • AI model inference;
  • payment processing;
  • transactional email;
  • Customer-authorised analytics/search integrations;
  • security/monitoring infrastructure.

The current identity, processing purpose, location and transfer mechanism of each applicable subprocessor shall be made available to Customer.

Noetis additionally maintains, or is completing verification of, the following operational compliance registers: a retention schedule, a cookie and storage register, the subprocessor register, and an international transfer register. Entries are recorded only once verified against production; unverified values are marked as verification pending rather than guessed.

Privacy contact: chris@noetis.nl


Contact: chris@noetis.nl