← All legal documents

Noetis — Data Processing Agreement (Art. 28 GDPR)

Version 1.0 · Effective date: 19 June 2026 · Last updated: 2026-06-19

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Final Frame ("Noetis", "Processor") and the customer ("Customer", "Controller") and governs Noetis's processing of personal data on Customer's behalf in connection with the Service. It is entered into pursuant to Article 28 GDPR. In case of conflict on data-protection matters, this DPA prevails over the Terms.

Capitalised terms not defined here have the meaning in the Terms or the GDPR ("personal data", "processing", "data subject", "controller", "processor", "supervisory authority", "personal data breach").

1. Roles and scope

1.1 For personal data processed on Customer's behalf through the Service ("Customer Personal Data", primarily End-User/visitor data and any personal data within Customer Data), Customer is the controller (or itself a processor for a third-party controller) and Noetis is the processor (or sub-processor).

1.2 Noetis processes Customer Personal Data only to provide the Service and only on Customer's documented instructions, including those in the Terms, this DPA, and Customer's configuration and use of the Service. Noetis will inform Customer if, in its opinion, an instruction infringes the GDPR, and may suspend processing of the affected instruction.

1.3 Where Noetis processes account/billing data of Customer's users as a controller, the Privacy Policy applies, not this DPA.

2. Details of processing — see Annex I

The subject-matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects are set out in Annex I.

3. Confidentiality

Noetis ensures that persons authorised to process Customer Personal Data are bound by confidentiality and process it only as instructed.

4. Security (Art. 32)

Noetis implements and maintains the technical and organisational measures ("TOMs") described in Annex II and in the Security & Compliance Addendum, appropriate to the risk. Noetis may update TOMs provided the level of protection is not materially reduced.

5. Sub-processors (Art. 28(2),(4))

5.1 Customer provides general written authorisation for Noetis to engage sub-processors. The current list is in Annex III.

5.2 Noetis will impose data-protection obligations on each sub-processor that are no less protective than this DPA, and remains liable to Customer for its sub-processors' performance of those obligations.

5.3 Change notice. Noetis will give Customer at least 30 days' prior notice (e.g. by email or in-product) before adding or replacing a sub-processor. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected part of the Service.

6. Assistance to the Controller

6.1 Data subject rights (Art. 28(3)(e)). Taking into account the nature of processing, Noetis will assist Customer by appropriate technical and organisational measures (including in-product export and deletion) to respond to data-subject requests. If Noetis receives such a request directly, it will, unless legally prohibited, refer the data subject to Customer.

6.2 Art. 32–36 assistance. Noetis will assist Customer, taking into account the nature of processing and information available to Noetis, with security, breach notification, data protection impact assessments (DPIAs) and prior consultation with supervisory authorities.

7. Personal data breach (Art. 33)

Noetis will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to enable Customer to meet its own notification obligations, and will update Customer as further information becomes available. Notification is not an acknowledgement of fault.

8. Deletion or return (Art. 28(3)(g))

On termination or expiry of the Service, Noetis will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, except to the extent storage is required by Union or Member-State law. Customer may export its data in-product before termination. Routine backups are deleted on their ordinary cycle.

9. Audits and inspections (Art. 28(3)(h))

9.1 Noetis will make available information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections.

9.2 Noetis may satisfy this primarily by providing its security documentation, the Security & Compliance Addendum, and (when available) third-party attestations (e.g. SOC 2 / penetration-test summaries).

9.3 Where an on-site audit is reasonably required, Customer may audit (itself or a mandated, independent auditor bound by confidentiality) once per 12 months (or after a breach), on at least 30 days' notice, during business hours, without unreasonably disrupting Noetis's operations, and not accessing other customers' data. Each party bears its own costs.

10. International transfers (Chapter V)

10.1 To the extent Noetis or its sub-processors process Customer Personal Data outside the EEA, the transfer is subject to appropriate safeguards, primarily the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, "SCCs"), which are hereby incorporated by reference and completed as follows:

  • Module: Module Two (controller → processor) where Customer is a controller;

Module Three (processor → processor) where Customer is itself a processor.

  • Clause 7 (docking): applies.
  • Clause 9 (sub-processors): Option 2 (general authorisation), with the 30-day

notice in §5.3.

  • Clause 11 (redress): the optional independent-dispute-resolution body does

not apply.

  • Clause 17 (governing law): the law of the Netherlands.
  • Clause 18 (forum): the courts of the Netherlands.
  • Annexes: Annexes I–III of this DPA populate Annexes I and II of the SCCs.

10.2 Where a sub-processor is certified under the EU–US Data Privacy Framework, that mechanism may apply in addition to or instead of the SCCs. Noetis applies supplementary measures (encryption in transit and at rest, access controls).

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (§10), except where mandatory law (including Art. 82 GDPR liability to data subjects) provides otherwise.

12. Term

This DPA takes effect on the Effective Date and remains in force for as long as Noetis processes Customer Personal Data, after which §8 (deletion/return) and surviving terms apply.


Annex I — Details of processing

  • Subject-matter: provision of the Noetis website-optimisation Service.
  • Duration: the term of the Subscription plus any wind-down/retention period.
  • Nature & purpose: hosting; collecting and analysing visitor behaviour

(analytics, heatmaps, funnels, session recordings); experimentation (A/B and multivariate testing); AI-generated content and recommendations; storage; and related support and security.

  • Types of personal data: online identifiers and device/browser data; IP

addresses; on-site behaviour and event data; content of form/interaction fields (with sensitive fields masked in recordings by default); and any personal data Customer includes in its content or connects via integrations. Customer must not submit special-category data unless agreed and lawfully justified.

  • Categories of data subjects: Customer's website visitors and End Users;

Customer's own personnel/users of the dashboard (as relevant).

  • Frequency: continuous, for the duration of the Service.

Annex II — Technical and organisational measures (summary)

Encryption in transit (TLS 1.2+) and at rest (AES-256); application-level encryption of sensitive fields (e.g. OAuth tokens, submitted PII); tenant isolation (database row-level security + application-layer ownership checks); role-based access control and least privilege; multi-factor authentication; append-only audit logging; rate limiting and platform WAF; secure SDLC with type/test gates and dependency scanning; backups; documented incident response, disaster recovery, key rotation and data retention. Full detail: Security & Compliance Addendum and the docs/ policy set.

Annex III — Authorised sub-processors

Sub-processorServiceProcessing locationSafeguard
Vercel Inc.Hosting / CDN / computeEU / USSCCs / DPF
SupabaseDatabase / auth / storageEU (configured)SCCs / DPA
OpenAIAI generationUSSCCs / no-training API terms
AnthropicAI generation (Claude)USSCCs / no-training API terms
StripePaymentsEU / USSCCs / DPF
ResendTransactional emailEU / USSCCs
Google (customer-authorised)Analytics / Search ConsoleEU / USSCCs / DPF

The authoritative, current list is maintained by Noetis and provided on request; changes are notified per §5.3.

Contact: chris@noetis.nl


Contact: chris@noetis.nl