UserVane
Home Sign in

Home · Data Processing Agreement

Last updated: 2026-07-25

Data Processing Agreement

These Data Processing terms (the "DPA") form part of the agreement between O'Shea & Sons, LLC ("Processor", "UserVane", "we", "us") and the customer that uses UserVane ("Controller", "Customer", "you"). This DPA is the operative processor terms that apply to all customers of the Service unless a separately signed DPA expressly replaces it.

Together with the Terms of Service and Privacy Policy, this DPA governs processing of Customer Personal Data. Capitalized terms not defined here have the meaning in the Terms.

1. Roles

  • Customer is the Controller of Customer Personal Data (end-user feedback and related identifiers collected through UserVane).
  • UserVane is the Processor that processes Customer Personal Data only to provide the Service and as instructed by Customer through the Service configuration, APIs, and documented features.

Each party will comply with data protection laws applicable to its role.

2. Processing details

  • Subject matter: hosting and operation of in-product, link, and imported microsurveys and related dashboard/API features.
  • Duration: for the term of Customer's use of the Service, and until deletion or return as described below.
  • Nature and purpose: store, score, display, export, and erase survey feedback so Customer can measure experience (NPS, CSAT, CES, PMF, and related feedback).
  • Data subjects: Customer's end users and survey respondents (and, where imported, historical respondents from systems such as Delighted).
  • Categories of data: survey ratings; free-text comments (which may include personal data); respondent identifiers (including hashed imp_ ids for imports; raw respondent emails are not stored for imported rows); customer-provided metadata/traits; technical logs needed to operate the Service.
  • Special categories: the Service is not designed for special-category data. Customer must not instruct processing of special-category data unless lawful and necessary, and Customer remains responsible for that decision.

3. Customer instructions

Processor will process Customer Personal Data only on documented instructions from Customer, including via the Service UI and APIs, and as required by law (in which case Processor will inform Customer unless legally prohibited). Customer is responsible for the lawfulness of its instructions and for notices/consents to data subjects.

4. Confidentiality

Processor ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.

5. Security measures

Processor implements reasonable technical and organizational measures appropriate to the nature of the Service, including: edge hosting on Cloudflare Workers with D1 and KV; authenticated dashboard access via WorkOS; secret-key gated privacy APIs; origin allowlisting for the widget where configured; show-token integrity for in-product submission; and access limited to operating the product. No security measure is perfect; Processor does not claim certifications or encryption guarantees beyond what is actually implemented.

6. Subprocessors

Customer authorizes Processor to use the following subprocessors (complete current list):

  • Cloudflare - hosting and infrastructure (Workers, D1, KV, DNS/CDN)
  • WorkOS - dashboard authentication
  • Stripe - payment processing (primarily account/billing data; may process limited metadata tied to the subscription)

Processor will impose data-protection obligations on subprocessors no less protective than this DPA. Processor remains responsible for subprocessors' performance. Processor will update this page (or otherwise notify Customer) when the subprocessor list changes. Customer may object to a new subprocessor on reasonable data-protection grounds within thirty (30) days of notice; if the parties cannot resolve the objection, Customer may stop using the affected Service or terminate the subscription for the affected portion as its sole remedy.

7. International transfers

Where Customer Personal Data is transferred internationally, Processor relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms provided via subprocessors as applicable, together with any supplementary measures those providers document.

8. Assistance with data-subject rights

Taking into account the nature of processing, Processor assists Customer in responding to data-subject requests by providing built product capabilities:

  • GET /v1/privacy/export - export responses for a respondent or survey filter
  • DELETE /v1/privacy/erase - erase responses (including erase by email for imported rows, hashed server-side to imp_ ids)

Customer remains responsible for verifying the requestor and responding to the data subject. Processor will provide reasonable additional assistance where the product tools are insufficient, via hello@uservane.com.

9. Breach notification

Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.

10. Return and deletion

Upon termination of the Service or on Customer's written request, Processor will delete or return Customer Personal Data in accordance with product tools (export/erase/account purge) and operational practice, except where retention is required by law. Customer should export data before closing the account if a copy is needed. As stated in the Privacy Policy, there is no automated TTL job that deletes responses on a fixed schedule today.

11. Audits

Upon reasonable written request, and no more than once per twelve (12) months (unless a regulator or confirmed breach requires more), Processor will provide information reasonably necessary to demonstrate compliance with this DPA (for example up-to-date subprocessor list and high-level security description). On-site audits are not offered by default for a small multi-tenant SaaS; the parties will discuss good-faith alternatives if required by law.

12. No LLM processing

Processor does not use large language models or generative AI to process Customer Personal Data, survey content, or free-text feedback. This is a current product and house policy commitment.

13. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where prohibited by applicable data-protection law.

14. Order of precedence

If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls for that subject. A separately signed DPA between the parties controls over this page if it expressly says so.

15. Contact

O'Shea & Sons, LLC
Email: hello@uservane.com
Website: https://uservane.com/

Terms · Privacy · DPA · Refunds · Home

O'Shea & Sons, LLC · hello@uservane.com