Harvv
How it worksWhat we findCase studiesGuidesFree auditPricing
Sign in Start free
How it worksWhat we findCase studiesGuidesFree auditPricingSign in

Harvv legal

Data Processing Addendum

Last updated: October 5, 2026

Effective October 5, 2026. Incorporated into the Terms of Service for every plan.

This Data Processing Addendum ("DPA") forms part of the Harvv Terms of Service (the "Terms") between Harvv, Inc., a Delaware corporation with its principal office at 101 Valley View Trail, Double Oak, Texas 75077 ("Harvv" or "Processor") and the customer that accepted the Terms ("Customer" or "Controller"). It applies whenever Harvv processes Personal Data on Customer's behalf through the Service. Capitalized terms not defined here have the meaning in the Terms.

1. Definitions. "Data Protection Laws" means all laws applying to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR and Data Protection Act 2018, the CCPA/CPRA, and other U.S. state privacy laws. "Personal Data" means information relating to an identified or identifiable natural person that Harvv processes on Customer's behalf. "Visitor Data" means the behavioral telemetry collected by the Harvv pixel from Customer's sites, as described in the Privacy Policy, Section 1.3. "Sub-processor" means a third party engaged by Harvv to process Personal Data. "Standard Contractual Clauses" or "SCCs" means the clauses approved by European Commission Decision 2021/914, Module Two (controller to processor), and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.

2. Roles. For Visitor Data, Customer is the controller (and, under the CCPA, the business) and Harvv is the processor (and service provider). For Customer's own account information (name, email, company, billing), Harvv is an independent controller, as described in the Privacy Policy. Harvv's processing of Visitor Data under this DPA is limited to the purposes in Annex 1.

3. Processor obligations. Harvv shall: (a) process Visitor Data only on Customer's documented instructions, which are the Terms, this DPA, and Customer's configuration of the Service, unless required otherwise by law, in which case Harvv will inform Customer unless prohibited; (b) not sell or share Visitor Data, nor retain, use, or disclose it for any purpose other than providing and securing the Service, or combine it with personal information from other sources, except as Data Protection Laws permit for service providers; (c) ensure persons authorized to process Visitor Data are bound by confidentiality; (d) implement the technical and organizational measures in Annex 2; (e) assist Customer, by appropriate technical measures and insofar as possible, in responding to data subject requests, which Customer handles directly with its visitors; (f) assist Customer with security, breach notification, and data protection impact assessments relating to the Service, taking into account the information available to Harvv; (g) delete or return Visitor Data at the end of the Service as set out in Section 7; (h) make available information necessary to demonstrate compliance and allow for audits under Section 9; and (i) notify Customer if it determines it can no longer meet its obligations under Data Protection Laws, upon which Customer may take reasonable steps to stop and remediate unauthorized use.

4. Customer obligations. Customer is responsible for the lawfulness of the collection of Visitor Data on its sites, including disclosing the use of analytics in its own privacy policy, deploying a consent mechanism where the laws applying to its visitors require one, and configuring consent-aware mode where appropriate, as described in the Terms, Section 7. Customer's instructions shall comply with Data Protection Laws.

5. Sub-processors. Customer authorizes the Sub-processors in Annex 3. Harvv shall impose data protection obligations on each Sub-processor no less protective than this DPA and remains liable for their performance. Harvv will post changes to Annex 3 at harvv.com/trust and give Customer at least 30 days' notice of any new Sub-processor by email to the account owner. Customer may object in writing on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected site or account with a pro-rata refund of prepaid fees.

6. Security incidents. Harvv shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Visitor Data in Harvv's systems. The notice will describe the nature of the incident, the likely consequences, and the measures taken or proposed. Harvv will not identify Customer to third parties in connection with an incident without Customer's consent, except as required by law.

7. Retention and deletion. Raw event-level Visitor Data is kept in the live database for approximately 30 days, then in a compressed archive for 13 months by default and never more than 24 months; Customer may shorten the archive window per site. Aggregates, detected issues, and reports are kept for the life of the account. When Customer deletes a site or closes its account, raw events (live and archived), sessions, and reports are deleted or returned within 90 days, the first 30 days being a recovery window; thereafter deletion is permanent and includes the archive. Routine deletion is suspended only under a documented legal hold. Database backups are overwritten on a 30-day rotation.

8. International transfers. Harvv processes Visitor Data in the United States. Where Visitor Data is transferred from the EEA, the SCCs (Module Two) are incorporated by reference, with Customer as data exporter and Harvv as data importer, Clause 7 (docking) included, Clause 9(a) Option 2 (general authorization, 30 days), Clause 11 optional language omitted, Clause 13 and the governing-law and forum clauses completed with the Member State of the Customer's establishment (or Ireland if none), and Annexes I and II completed by Annexes 1 and 2 of this DPA. Where Visitor Data is transferred from the United Kingdom, the UK Addendum is incorporated with the same selections, Part 1 Tables completed by the information in this DPA, and either party may end the UK Addendum as set out in its Section 19. Where Visitor Data is transferred from Switzerland, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner.

9. Audits. On written request no more than once per year (or following a security incident), Harvv will provide its then-current security documentation, completed security questionnaires, and any third-party audit reports it holds. Where these are insufficient to demonstrate compliance, Customer may conduct, at its expense and on 30 days' notice, a remote audit by an independent auditor bound by confidentiality, limited to the systems processing Visitor Data and not more than two business days.

10. CCPA/CPRA terms. Harvv is a service provider to Customer. Harvv certifies that it understands and will comply with the restrictions in Section 3(b). Harvv does not receive Visitor Data as consideration for any service and will not sell or share it. Customer may take reasonable and appropriate steps to ensure Harvv uses Visitor Data consistently with Customer's obligations.

11. Liability; precedence; term. Each party's liability under this DPA is subject to the limitation of liability in the Terms, except where Data Protection Laws or the SCCs do not permit limitation. In case of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms. This DPA lasts as long as Harvv processes Visitor Data for Customer.

12. Contact. Harvv, Inc., Attn: Privacy, 101 Valley View Trail, Double Oak, TX 75077, USA · privacy@harvv.com.

ANNEX 1 — DESCRIPTION OF PROCESSING

ItemDescription
Subject matterBehavioral analytics for Customer's websites via the Harvv pixel.
Nature and purposeCollection of structured behavioral telemetry; detection of user-experience issues; generation of findings, fix recommendations, dashboards, reports, and AI-assisted answers to Customer's questions about its sites.
Categories of data subjectsVisitors to Customer's websites.
Categories of Personal DataPseudonymous visitor identifier (first-party cookie _pxv on Customer's domain, or in-memory identifier where consent is denied); click targets and coordinates; scroll kinematics; hover durations; visible time on page; page URL path (no query string); device type and connection speed; JavaScript error messages; HTTP response status codes; performance timings and structural LCP selectors; page metadata audit values; conversion outcomes (order id, value, currency, payment method category); country code derived transiently from IP. IP addresses are not stored in analytics records.
Data not collected by designKeystrokes, form values, clipboard or selected text, DOM content, page text, screenshots, session replay, raw IP addresses, names, email addresses, or other direct identifiers of visitors.
Special categoriesNone intended. Customer shall not configure the Service to collect them.
FrequencyContinuous while the pixel is installed.
DurationPer Section 7.

ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES

  • Encryption in transit (TLS) for all pixel, dashboard, API, and third-party calls; encryption at rest for the database and backups; OAuth tokens stored encrypted.
  • Pseudonymization by design: no direct identifiers in telemetry; IP processed transiently and hashed where logged; defense-in-depth scrubbing of email, phone, and card-shaped strings from any shipped text.
  • Consent-aware capture honoring Shopify Customer Privacy API, Google Consent Mode, and Global Privacy Control signals.
  • Access control: role-based access with least privilege; separate database roles for runtime, backup, read-only gates, and replication; JWT authentication with expiring tokens; rate limiting on all endpoints; password hashing (bcrypt, cost 12).
  • Row-level tenant isolation in the database; one customer's data never exposed to another in identifiable form.
  • Logging and monitoring: security audit log retained 7 years; automated invariant checks on ingest and data integrity; alerting on anomalies.
  • Backups: nightly encrypted database backups with 30-day rotation; event archive with enforced per-site expiry; disaster-recovery replica in a second region.
  • Retention and deletion enforced by scheduled jobs; legal-hold switch documented.
  • Vendor management: Sub-processors bound by written terms; AI model provider under commercial terms that prohibit training on Customer data.
  • Incident response: documented runbooks; 72-hour customer notification commitment.

ANNEX 3 — SUB-PROCESSORS (as of October 5, 2026)

Sub-processorPurposeDataLocation
Railway Corp.Application hosting, primary database, cacheAll Visitor DataUnited States
Amazon Web Services, Inc.Encrypted backups, event archive, analytical replica, alertingAll Visitor DataUnited States
Cloudflare, Inc.Edge network, ingest spillover during outages, email routingVisitor Data in transit; transient spillover bufferUnited States / global edge
Anthropic, PBCAI-generated findings, fixes, and answers to Customer's questionsAggregated behavioral figures and findings; no visitor identifiers; not used for model trainingUnited States
Stripe, Inc.BillingCustomer account and payment data (controller data, not Visitor Data)United States
Resend, Inc.Transactional and digest email to CustomerCustomer account email; aggregated findings in digestsUnited States
Apollo.ioProfessional-profile enrichment of Customer's accountCustomer's name and email (controller data, not Visitor Data)United States
Slack Technologies, LLC; ClickUp, Inc.Only if Customer connects the integration: delivery of findings into Customer's workspaceAggregated findings; no visitor identifiersUnited States
Google LLC; Meta Platforms, Inc.; Microsoft CorporationOnly if Customer connects the integration or signs in with that provider: read-only retrieval of Customer's own analytics, ads, or identity dataData flows from the provider to Harvv; no Visitor Data is sent to the providerUnited States

Not Sub-processors (no Visitor Data is sent): MaxMind (country database runs locally), DataForSEO, Serper, SerpApi (receive only Customer's domain or keywords), GitHub (code hosting), Toast and QisstPay (integrations receiving no Visitor Data).

Harvv

The behavioral pixel for sites you ship to real users. Harvv finds what is broken, explains it in plain English, and hands the answer to your AI.

Product

How it works What we find Pricing For agencies Docs Audit your site

Learn

Case studies Guides Harvv vs Clarity Harvv vs Cloudflare Clarity & privacy

Company

Contact Trust & security Privacy Terms DPA
© 2026 Harvv, Inc. Zero PII. Every number on this site is measured, not modelled.