Preamble
This Data Processing Agreement (“DPA”) is entered into between:
- Controller: The Customer as identified in the EULA (“Customer”, “Controller”);
- Processor: Ipportunities B.V., KvK [PLACEHOLDER], with registered office at [PLACEHOLDER] (“Ipportunities”, “Processor”).
This DPA supplements the EULA and the Privacy Policy, and governs the processing of personal data by Ipportunities on behalf of the Customer in connection with the License Server.
1. Scope and Purpose
1.1 Narrow Scope
This DPA covers only the personal data processed through the License Server operated by Ipportunities. It does NOT cover:
- Chat messages, visitor data, or website content processed by the plugin on the Customer’s server (the Customer is the sole controller for such data);
- Payment data processed by Freemius (Freemius is an independent controller);
- Data transmitted by the Customer to Third-Party AI Providers (the Customer controls these transfers directly).
1.2 Purpose of Processing
Ipportunities processes personal data on behalf of the Customer solely for:
- License key validation;
- Domain activation and deactivation;
- License lifecycle management (creation, expiration, cancellation, renewal via Freemius webhooks);
- Security monitoring and abuse prevention.
2. Data Categories
2.1 Personal Data Processed
| Category | Data Elements | Source |
|---|---|---|
| Customer identity | Name, email address | Freemius (at purchase) |
| License data | License key, license type, order ID, status, expiry date | Freemius webhooks, activation API |
| Domain data | Domain name, activation date, last validation date, plugin version | Plugin validation requests |
| Network data | IP address | Automatically collected during API calls |
| API logs | Timestamp, action, result, error messages | Automatically generated |
2.2 Data Subjects
- Customers: Individuals who purchase or use the Software.
- Customer representatives: Individuals acting on behalf of a Customer organization.
2.3 No Special Categories
Ipportunities does not process special categories of personal data (Art. 9 GDPR) or criminal conviction data (Art. 10 GDPR) through the License Server.
3. Processor Obligations
3.1 Processing Instructions
Ipportunities shall process personal data only on documented instructions from the Controller, unless required by Union or Member State law. The instructions are as documented in:
- This DPA;
- The EULA;
- The License Server API specification.
3.2 Confidentiality
Ipportunities ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 Security Measures
Ipportunities implements the following technical and organizational measures:
Technical Measures
| Measure | Implementation |
|---|---|
| Cryptographic signing | All validation responses are signed using HMAC-SHA256 with a configurable signing key (default: inqyra_license_signature_key_v1, overridable via INQYRA_LICENSE_SIGNING_KEY). |
| Rate limiting | License Server API: 30 requests/minute, 300 requests/hour per IP address. |
| Input validation | All API parameters are validated and sanitized before database queries. Parameterized queries prevent SQL injection. |
| Transport encryption | All API communication over HTTPS (TLS 1.2+). |
| Access control | License Server admin dashboard restricted to authorized WordPress administrators. |
| Webhook verification | Freemius webhooks verified using HMAC-SHA256 signature validation. |
| Minimal data storage | IP addresses stored in logs only; purged after 90 days. |
Organizational Measures
| Measure | Description |
|---|---|
| Access limitation | Access to License Server data limited to Ipportunities personnel who require it. |
| Incident response | Documented breach notification procedure (see Section 6). |
| Regular review | Security measures reviewed and updated as needed. |
3.4 Assistance to Controller
Ipportunities shall assist the Controller, insofar as possible, in fulfilling the Controller’s obligations regarding:
- Data subject rights requests (Art. 15–22 GDPR);
- Data protection impact assessments (Art. 35 GDPR);
- Prior consultation with supervisory authorities (Art. 36 GDPR).
4. Sub-processors
4.1 Authorized Sub-processors
The Controller grants general authorization for Ipportunities to engage sub-processors, subject to the conditions in this Section.
| Sub-processor | Processing Activity | Location |
|---|---|---|
| Freemius Inc. | Payment processing, license event webhooks, customer identity management | USA/EU |
| [PLACEHOLDER Hosting Provider] | License Server infrastructure hosting | [PLACEHOLDER] |
4.2 Sub-processor Changes
Ipportunities shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days before the change, giving the Controller the opportunity to object.
4.3 Sub-processor Agreements
Ipportunities shall impose the same data protection obligations as set out in this DPA on each sub-processor by way of a contract. Ipportunities remains fully liable to the Controller for the performance of the sub-processor’s obligations.
5. International Transfers
5.1 License Server
The License Server is hosted in [PLACEHOLDER]. Processing takes place within [PLACEHOLDER].
5.2 Freemius
Freemius may process data outside the EEA, including in the United States. Transfers are governed by [PLACEHOLDER: appropriate transfer mechanism — e.g., Standard Contractual Clauses (SCC), EU-US Data Privacy Framework].
5.3 Transfer Safeguards
Any transfer of personal data to a third country or international organization shall only occur subject to appropriate safeguards in accordance with Chapter V of the GDPR.
6. Data Breach Notification
6.1 Notification to Controller
Ipportunities shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting data processed under this DPA.
6.2 Notification Content
The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records affected;
- The name and contact details of the data protection point of contact;
- A description of the likely consequences of the breach;
- A description of the measures taken or proposed to be taken to address the breach and mitigate its effects.
6.3 Cooperation
Ipportunities shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
7. Audit Rights
7.1 Audit
The Controller has the right to conduct audits, including inspections, to verify Ipportunities’ compliance with this DPA. Audits shall be conducted:
- With at least 30 days written notice;
- During normal business hours;
- In a manner that minimizes disruption to Ipportunities’ operations;
- At the Controller’s expense.
7.2 Audit Reports
Ipportunities may satisfy audit requests by providing relevant certifications, audit reports, or third-party assessments, where available. The Controller agrees to accept such documentation as an alternative to on-site audits where reasonable.
7.3 Confidentiality
Audit findings shall be treated as confidential by both parties.
8. Data Retention and Deletion
8.1 Retention Schedule
| Data | Retention Period | Deletion Method |
|---|---|---|
| API logs (IP, action, result, errors) | 90 days | Automated daily cron purge |
| License records (key, type, status, customer data) | Duration of contract + 7 years | Manual deletion upon request, subject to fiscal retention |
| Domain activation records | Until deactivation or license expiry | Automated upon deactivation; manual cleanup upon expiry |
8.2 End of Contract
Upon termination of the EULA, Ipportunities shall:
- Delete or anonymize personal data within 30 days, unless retention is required by law;
- Provide the Controller with a copy of their data upon request, made before termination;
- Confirm deletion in writing upon request.
8.3 Legal Retention
Where Ipportunities is required by applicable law (e.g., Dutch fiscal retention requirements) to retain personal data beyond the contract period, Ipportunities shall:
- Inform the Controller of the legal requirement;
- Limit processing to the purpose required by law;
- Delete the data at the end of the legally required retention period.
9. GDPR Article 28(3) Compliance Checklist
This DPA addresses the requirements of GDPR Article 28(3):
| Requirement | DPA Reference |
|---|---|
| (a) Process only on documented instructions | Section 3.1 |
| (b) Confidentiality obligations | Section 3.2 |
| (c) Security measures (Art. 32) | Section 3.3 |
| (d) Sub-processor conditions | Section 4 |
| (e) Assist with data subject rights | Section 3.4 |
| (f) Assist with security obligations (Art. 32–36) | Sections 3.3, 3.4, 6 |
| (g) Deletion or return at end of service | Section 8.2 |
| (h) Audit rights | Section 7 |
10. Liability
Liability under this DPA is governed by and subject to the limitation of liability provisions in the EULA (Section 11).
11. Term and Termination
11.1 Term
This DPA enters into force upon the Customer’s acceptance of the EULA and remains in effect for the duration of the license agreement.
11.2 Survival
Sections 6, 7, 8, and 10 survive termination of this DPA.
12. Governing Law
This DPA is governed by the laws of the Netherlands. Any disputes arising from this DPA shall be submitted to the competent courts in [PLACEHOLDER], the Netherlands.
13. Contact
For questions about this DPA or to exercise audit rights:
Ipportunities B.V.
Email: [PLACEHOLDER]
Address: [PLACEHOLDER]
Related documents: EULA · Privacy Policy · AI Disclaimer · Support Policy