Data Processing Addendum
Roles of the parties
Under the GDPR (Article 28) and the CCPA, the business that publishes on Onomaco is the controller of its customers’ personal data. Onomaco acts as a processor, handling that data only on the controller’s documented instructions and for the purpose of providing the service.
Processor commitments
- Process personal data only on the controller’s instructions.
- Impose confidentiality on personnel with access to the data.
- Apply appropriate technical and organizational security measures.
- Assist with data-subject requests and breach notification.
- Delete or return personal data at the end of the engagement.
Processing on the controller’s instructions includes server-side conversion attribution: Onomaco derives daily-rotating visitor identifiers from IP address and user-agent, captures ad click identifiers (fbclid, gclid, and similar) from inbound links, and attaches both to orders for the conversion reports sent to the controller’s ad platforms.
Sub-processors
Onomaco engages the following sub-processors to deliver the service. Controllers are notified of material changes before a new sub-processor begins processing.
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe | Payment processing and checkout | US / EU |
| Resend | Transactional and marketing email delivery | US |
| Vercel | Application hosting, edge delivery, analytics | Global |
| Neon (PostgreSQL) | Primary application database | US / EU |
| Sentry | Error monitoring and diagnostics | US / EU |
| Amazon Web Services (S3) | File and media object storage | US / EU |
| Calendar/Drive integrations and workspace APIs | Global | |
| Upstash (Redis) | Rate limiting and ephemeral caching | Global |
Requesting the signed DPA
To execute a countersigned copy of this addendum, email privacy@onomaco.com.