Data Processing Agreement

Last updated: August 2026

This Data Processing Agreement (“DPA”) forms part of the contract between you (the “Customer”, acting as data controller) and Enderway (“we”, “Processor”) when we host your website and quote engine and process personal data on your documented instructions. It reflects Regulation (EU) 2016/679 (“GDPR”), the UK GDPR where applicable, and Portuguese Law 58/2019. This is counsel-lite documentation — not formal legal advice. Enterprise customers may request a countersigned version.

1. Subject matter, duration, and roles

We process personal data submitted through your Enderway site (quote requests, contact details, optional photos, and related metadata) solely to provide, secure, and support the platform you subscribed to.

Processing continues for the term of your subscription and a reasonable wind-down period afterwards, unless you or we delete data sooner or law requires longer retention.

For visitor leads on your site you are the controller; Enderway is the processor. For enderway.com walkthrough requests, billing, and platform administration, Enderway is an independent controller — see our Privacy Policy.

2. Nature and purpose of processing

Activities include: receiving and storing lead submissions; delivering notifications (email, SMS, WhatsApp where configured); hosting media; fraud/abuse protection; error monitoring; and providing export and deletion tools in your workspace.

We do not sell lead data, use it for our own unrelated marketing, or train public AI models on identifiable lead content.

3. Categories of data and data subjects

Data subjects: visitors and prospects who interact with your quote engine or contact flows.

Categories may include: identity and contact data (name, phone, email); job/quote answers; estimates; optional photos; technical metadata (timestamps, locale, source channel); and notification delivery logs.

4. Customer instructions and compliance

You instruct us through your use of the product, workspace settings, and documented support requests. You are responsible for a lawful basis, transparent notices on your site, and accurate service descriptions.

You will not instruct us to process special categories of data unless strictly necessary, lawful, and agreed in writing.

5. Processor obligations

We process personal data only on documented instructions, ensure confidentiality of personnel with access, implement appropriate technical and organisational measures (encryption in transit, access control, audit logging, least-privilege admin access), and assist with data subject requests where feasible via workspace tools or support.

You may export leads to CSV and permanently delete them from the CRM without SQL or engineering access. Deletion removes database records and associated media where stored on our systems.

We notify you without undue delay after becoming aware of a personal data breach affecting your tenant, and cooperate on regulatory notifications where required.

6. Sub-processors and changes

You authorise us to use the sub-processors listed in Annex A. We impose data protection terms on each sub-processor and remain responsible for their performance.

We will publish material changes to Annex A at least 30 days before they take effect and notify account holders by email or in-product notice. You may object on reasonable grounds relating to data protection; if unresolved, you may terminate the affected service.

7. International transfers

Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK IDTA/Addendum, or an adequacy decision, as offered by the relevant sub-processor.

You may request further transfer information by contacting hello@enderway.com.

8. Return and deletion

On termination, you may export remaining leads before closure. Unless law requires retention, we delete or anonymise Customer personal data within 90 days of termination, including backups on rolling schedules.

Aggregated, non-identifying analytics may be retained.

9. Audits and liability

Upon reasonable written request, we provide information necessary to demonstrate compliance and allow audits no more than once per year with 30 days’ notice, subject to confidentiality and security constraints.

Liability for processing is capped as in your main service agreement. Nothing limits liability where prohibited by GDPR or mandatory law.

10. Governing law

This DPA is governed by the laws of Portugal and the courts of Lisbon, without prejudice to mandatory consumer or data-protection rights in your country of establishment.

If this DPA conflicts with mandatory GDPR processor terms, the mandatory terms prevail.

Annex A — Authorised sub-processors

The following sub-processors support delivery of the Enderway platform. Typical locations refer to standard product regions; your project may be pinned to the EU where configurable.

Sub-processorProcessing activityTypical locationTransfers
Supabase, Inc.PostgreSQL database, authentication, row-level securityEU (Frankfurt) or US, per projectSCCs / DPA
Vercel Inc.Application hosting, serverless functions, edge routingGlobal (EU regions available)SCCs / DPA
Cloudflare, Inc. (R2)Object storage for site media and lead photosGlobalSCCs / DPA
Cloudflare, Inc. (Turnstile)Bot protection on formsGlobalTurnstile privacy addendum
Twilio Inc.SMS delivery and phone verification (where enabled)US / EUSCCs / DPA
Stripe, Inc.Subscription billing and payment processingEU / USSCCs / DPA
Google LLC (Gemini API)Optional AI-assisted content tooling in admin pipelinesUS / EU (where offered)Google Cloud DPA / SCCs
Functional Software, Inc. (Sentry)Error and performance monitoring (scrubbed of secrets)US / EUSCCs / DPA
Upstash, Inc.Redis rate limiting and abuse protectionEU / USSCCs / DPA

Privacy and DPA questions: hello@enderway.com

We may update Annex A and this DPA. Material changes will be announced on this page and, where appropriate, by email to active customers.