FeaturesPricingHow It WorksSupportDocumentationBlog Download

Preamble

This Data Processing Agreement (“DPA”) is entered into between:

  • Controller: The Customer as identified in the EULA (“Customer”, “Controller”);
  • Processor: Ipportunities B.V., KvK [PLACEHOLDER], with registered office at [PLACEHOLDER] (“Ipportunities”, “Processor”).

This DPA supplements the EULA and the Privacy Policy, and governs the processing of personal data by Ipportunities on behalf of the Customer in connection with the License Server.

1. Scope and Purpose

1.1 Narrow Scope

This DPA covers only the personal data processed through the License Server operated by Ipportunities. It does NOT cover:

  • Chat messages, visitor data, or website content processed by the plugin on the Customer’s server (the Customer is the sole controller for such data);
  • Payment data processed by Freemius (Freemius is an independent controller);
  • Data transmitted by the Customer to Third-Party AI Providers (the Customer controls these transfers directly).

1.2 Purpose of Processing

Ipportunities processes personal data on behalf of the Customer solely for:

  • License key validation;
  • Domain activation and deactivation;
  • License lifecycle management (creation, expiration, cancellation, renewal via Freemius webhooks);
  • Security monitoring and abuse prevention.

2. Data Categories

2.1 Personal Data Processed

Category Data Elements Source
Customer identity Name, email address Freemius (at purchase)
License data License key, license type, order ID, status, expiry date Freemius webhooks, activation API
Domain data Domain name, activation date, last validation date, plugin version Plugin validation requests
Network data IP address Automatically collected during API calls
API logs Timestamp, action, result, error messages Automatically generated

2.2 Data Subjects

  • Customers: Individuals who purchase or use the Software.
  • Customer representatives: Individuals acting on behalf of a Customer organization.

2.3 No Special Categories

Ipportunities does not process special categories of personal data (Art. 9 GDPR) or criminal conviction data (Art. 10 GDPR) through the License Server.

3. Processor Obligations

3.1 Processing Instructions

Ipportunities shall process personal data only on documented instructions from the Controller, unless required by Union or Member State law. The instructions are as documented in:

  • This DPA;
  • The EULA;
  • The License Server API specification.

3.2 Confidentiality

Ipportunities ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3 Security Measures

Ipportunities implements the following technical and organizational measures:

Technical Measures

Measure Implementation
Cryptographic signing All validation responses are signed using HMAC-SHA256 with a configurable signing key (default: inqyra_license_signature_key_v1, overridable via INQYRA_LICENSE_SIGNING_KEY).
Rate limiting License Server API: 30 requests/minute, 300 requests/hour per IP address.
Input validation All API parameters are validated and sanitized before database queries. Parameterized queries prevent SQL injection.
Transport encryption All API communication over HTTPS (TLS 1.2+).
Access control License Server admin dashboard restricted to authorized WordPress administrators.
Webhook verification Freemius webhooks verified using HMAC-SHA256 signature validation.
Minimal data storage IP addresses stored in logs only; purged after 90 days.

Organizational Measures

Measure Description
Access limitation Access to License Server data limited to Ipportunities personnel who require it.
Incident response Documented breach notification procedure (see Section 6).
Regular review Security measures reviewed and updated as needed.

3.4 Assistance to Controller

Ipportunities shall assist the Controller, insofar as possible, in fulfilling the Controller’s obligations regarding:

  • Data subject rights requests (Art. 15–22 GDPR);
  • Data protection impact assessments (Art. 35 GDPR);
  • Prior consultation with supervisory authorities (Art. 36 GDPR).

4. Sub-processors

4.1 Authorized Sub-processors

The Controller grants general authorization for Ipportunities to engage sub-processors, subject to the conditions in this Section.

Sub-processor Processing Activity Location
Freemius Inc. Payment processing, license event webhooks, customer identity management USA/EU
[PLACEHOLDER Hosting Provider] License Server infrastructure hosting [PLACEHOLDER]

4.2 Sub-processor Changes

Ipportunities shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days before the change, giving the Controller the opportunity to object.

4.3 Sub-processor Agreements

Ipportunities shall impose the same data protection obligations as set out in this DPA on each sub-processor by way of a contract. Ipportunities remains fully liable to the Controller for the performance of the sub-processor’s obligations.

5. International Transfers

5.1 License Server

The License Server is hosted in [PLACEHOLDER]. Processing takes place within [PLACEHOLDER].

5.2 Freemius

Freemius may process data outside the EEA, including in the United States. Transfers are governed by [PLACEHOLDER: appropriate transfer mechanism — e.g., Standard Contractual Clauses (SCC), EU-US Data Privacy Framework].

5.3 Transfer Safeguards

Any transfer of personal data to a third country or international organization shall only occur subject to appropriate safeguards in accordance with Chapter V of the GDPR.

6. Data Breach Notification

6.1 Notification to Controller

Ipportunities shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting data processed under this DPA.

6.2 Notification Content

The notification shall include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and records affected;
  • The name and contact details of the data protection point of contact;
  • A description of the likely consequences of the breach;
  • A description of the measures taken or proposed to be taken to address the breach and mitigate its effects.

6.3 Cooperation

Ipportunities shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

7. Audit Rights

7.1 Audit

The Controller has the right to conduct audits, including inspections, to verify Ipportunities’ compliance with this DPA. Audits shall be conducted:

  • With at least 30 days written notice;
  • During normal business hours;
  • In a manner that minimizes disruption to Ipportunities’ operations;
  • At the Controller’s expense.

7.2 Audit Reports

Ipportunities may satisfy audit requests by providing relevant certifications, audit reports, or third-party assessments, where available. The Controller agrees to accept such documentation as an alternative to on-site audits where reasonable.

7.3 Confidentiality

Audit findings shall be treated as confidential by both parties.

8. Data Retention and Deletion

8.1 Retention Schedule

Data Retention Period Deletion Method
API logs (IP, action, result, errors) 90 days Automated daily cron purge
License records (key, type, status, customer data) Duration of contract + 7 years Manual deletion upon request, subject to fiscal retention
Domain activation records Until deactivation or license expiry Automated upon deactivation; manual cleanup upon expiry

8.2 End of Contract

Upon termination of the EULA, Ipportunities shall:

  • Delete or anonymize personal data within 30 days, unless retention is required by law;
  • Provide the Controller with a copy of their data upon request, made before termination;
  • Confirm deletion in writing upon request.

8.3 Legal Retention

Where Ipportunities is required by applicable law (e.g., Dutch fiscal retention requirements) to retain personal data beyond the contract period, Ipportunities shall:

  • Inform the Controller of the legal requirement;
  • Limit processing to the purpose required by law;
  • Delete the data at the end of the legally required retention period.

9. GDPR Article 28(3) Compliance Checklist

This DPA addresses the requirements of GDPR Article 28(3):

Requirement DPA Reference
(a) Process only on documented instructions Section 3.1
(b) Confidentiality obligations Section 3.2
(c) Security measures (Art. 32) Section 3.3
(d) Sub-processor conditions Section 4
(e) Assist with data subject rights Section 3.4
(f) Assist with security obligations (Art. 32–36) Sections 3.3, 3.4, 6
(g) Deletion or return at end of service Section 8.2
(h) Audit rights Section 7

10. Liability

Liability under this DPA is governed by and subject to the limitation of liability provisions in the EULA (Section 11).

11. Term and Termination

11.1 Term

This DPA enters into force upon the Customer’s acceptance of the EULA and remains in effect for the duration of the license agreement.

11.2 Survival

Sections 6, 7, 8, and 10 survive termination of this DPA.

12. Governing Law

This DPA is governed by the laws of the Netherlands. Any disputes arising from this DPA shall be submitted to the competent courts in [PLACEHOLDER], the Netherlands.

13. Contact

For questions about this DPA or to exercise audit rights:

Ipportunities B.V.

Email: [PLACEHOLDER]

Address: [PLACEHOLDER]


Related documents: EULA · Privacy Policy · AI Disclaimer · Support Policy