Last updated: 2026-07-25
These Data Processing terms (the "DPA") form part of the agreement between O'Shea & Sons, LLC ("Processor", "UserVane", "we", "us") and the customer that uses UserVane ("Controller", "Customer", "you"). This DPA is the operative processor terms that apply to all customers of the Service unless a separately signed DPA expressly replaces it.
Together with the Terms of Service and Privacy Policy, this DPA governs processing of Customer Personal Data. Capitalized terms not defined here have the meaning in the Terms.
Each party will comply with data protection laws applicable to its role.
imp_ ids for imports; raw respondent emails are not stored for imported rows); customer-provided metadata/traits; technical logs needed to operate the Service.Processor will process Customer Personal Data only on documented instructions from Customer, including via the Service UI and APIs, and as required by law (in which case Processor will inform Customer unless legally prohibited). Customer is responsible for the lawfulness of its instructions and for notices/consents to data subjects.
Processor ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
Processor implements reasonable technical and organizational measures appropriate to the nature of the Service, including: edge hosting on Cloudflare Workers with D1 and KV; authenticated dashboard access via WorkOS; secret-key gated privacy APIs; origin allowlisting for the widget where configured; show-token integrity for in-product submission; and access limited to operating the product. No security measure is perfect; Processor does not claim certifications or encryption guarantees beyond what is actually implemented.
Customer authorizes Processor to use the following subprocessors (complete current list):
Processor will impose data-protection obligations on subprocessors no less protective than this DPA. Processor remains responsible for subprocessors' performance. Processor will update this page (or otherwise notify Customer) when the subprocessor list changes. Customer may object to a new subprocessor on reasonable data-protection grounds within thirty (30) days of notice; if the parties cannot resolve the objection, Customer may stop using the affected Service or terminate the subscription for the affected portion as its sole remedy.
Where Customer Personal Data is transferred internationally, Processor relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms provided via subprocessors as applicable, together with any supplementary measures those providers document.
Taking into account the nature of processing, Processor assists Customer in responding to data-subject requests by providing built product capabilities:
GET /v1/privacy/export - export responses for a respondent or survey filterDELETE /v1/privacy/erase - erase responses (including erase by email for imported rows, hashed server-side to imp_ ids)Customer remains responsible for verifying the requestor and responding to the data subject. Processor will provide reasonable additional assistance where the product tools are insufficient, via hello@uservane.com.
Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.
Upon termination of the Service or on Customer's written request, Processor will delete or return Customer Personal Data in accordance with product tools (export/erase/account purge) and operational practice, except where retention is required by law. Customer should export data before closing the account if a copy is needed. As stated in the Privacy Policy, there is no automated TTL job that deletes responses on a fixed schedule today.
Upon reasonable written request, and no more than once per twelve (12) months (unless a regulator or confirmed breach requires more), Processor will provide information reasonably necessary to demonstrate compliance with this DPA (for example up-to-date subprocessor list and high-level security description). On-site audits are not offered by default for a small multi-tenant SaaS; the parties will discuss good-faith alternatives if required by law.
Processor does not use large language models or generative AI to process Customer Personal Data, survey content, or free-text feedback. This is a current product and house policy commitment.
Liability under this DPA is subject to the limitations in the Terms of Service, except where prohibited by applicable data-protection law.
If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls for that subject. A separately signed DPA between the parties controls over this page if it expressly says so.
O'Shea & Sons, LLC
Email: hello@uservane.com
Website: https://uservane.com/