This Data Processing Agreement (“DPA”) forms part of the agreement between Margin Levers (“Processor”) and the customer (“Controller”) for the provision of customer profitability analysis services. This DPA sets out the terms under which Margin Levers processes personal data on behalf of the Controller.
1. Definitions
- Controller: The customer who determines the purposes and means of processing personal data by using Margin Levers services.
- Processor: Margin Levers, which processes personal data on behalf of the Controller to provide the services.
- Data Subject: An identified or identifiable natural person whose personal data is processed.
- Personal Data: Any information relating to a Data Subject that is processed through the services.
- Sub-Processor: A third party engaged by Margin Levers to process personal data on behalf of the Controller.
2. Scope and Purpose
Margin Levers processes personal data solely as a Processor acting on behalf of the Controller. The purpose of processing is to provide customer profitability analysis services, including data ingestion, profitability analysis, AI-powered insights generation, benchmarking, and report generation. Processing is performed only in accordance with the Controller's documented instructions as embodied in their use of the service.
3. Categories of Data Processed
The following categories of data may be processed through the services:
- Financial data:Revenue, cost, and profit margin figures associated with the Controller's customers
- Customer identifiers: Customer names or identifiers as provided by the Controller (optionally client-side hashed before transmission)
- Account data:Email address and subscription status of the Controller's account
- Usage data: Feature interactions and anonymized analytics events
4. Sub-Processors
The Controller authorizes the use of the following sub-processors. We will notify you of any changes to this list via email at least 30 days before engaging a new sub-processor.
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database and authentication | Account data, analysis results | US (AWS us-east-1) |
| Vercel | Application hosting | Request logs, IP addresses | US |
| Anthropic (via OpenRouter) | AI-powered analysis | Analysis prompts, financial data | US |
| Stripe | Payment processing | Billing information, subscription data | US |
| Postmark | Transactional email | Email addresses, notification content | US |
| PostHog | Product analytics | Anonymized usage events | US |
| Cloudflare | Bot protection (Turnstile), DNS routing, scheduled tasks | Request routing metadata | Global — DPA available |
| HubSpot | CRM integration (OAuth tokens stored encrypted) | Contact and account data | US — DPA available |
| Xero | Accounting integration (OAuth tokens stored encrypted) | Financial account metadata | US/AU — DPA available |
| QuickBooks (Intuit) | Accounting integration (OAuth tokens stored encrypted) | Financial account metadata | US — DPA available |
| Ahrefs | Analytics beacon for referral tracking | Referral and traffic metadata | US/EU — Privacy policy |
5. Security Measures
Margin Levers implements appropriate technical and organizational measures to protect personal data, including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Row-level security (RLS) policies ensuring strict data isolation between customers
- Comprehensive audit logging of data access and modifications
- Session-based authentication with configurable session duration via Supabase Auth
For full details of our security practices, see our Security page.
6. Data Subject Rights
Margin Levers assists the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection law, including the right of access, rectification, erasure, and data portability. The Processor will respond to such assistance requests within 30 days.
7. Data Breach Notification
In the event of a confirmed personal data breach, Margin Levers will notify the Controller without undue delay and in any event within 72 hours. The notification will include:
- The nature of the personal data breach
- The categories and approximate number of Data Subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
8. Data Retention and Deletion
Personal data is retained for the duration of the Controller's subscription. Upon termination of the subscription agreement, all identifying personal data will be anonymized or deleted within 30 days. Account profile information (name and email) may be retained to facilitate account recovery or re-subscription. Anonymized benchmark contributions and aggregate metrics that cannot be linked back to the Controller or any Data Subject are retained indefinitely to support industry benchmarking research.
9. Cross-Border Transfers
All primary data processing occurs in the United States. Standard Contractual Clauses (SCCs) are incorporated by reference into this Data Processing Agreement and apply to all transfers of personal data from the EEA/UK to the United States. Copies are available upon request at [email protected]. Where applicable, Margin Levers relies on sub-processors certified under the EU-US Data Privacy Framework (DPF).
10. Term and Termination
This DPA is effective for the duration of the subscription agreement between the Controller and Margin Levers. Upon termination of the subscription, this DPA terminates automatically, except that Section 8 (Data Retention and Deletion) survives termination and continues to apply until all personal data has been deleted.
11. Contact
For data protection inquiries or to exercise any rights under this DPA, please contact us at:
- Email: [email protected]
- Website: marginlevers.com