Data Processing Agreement — Cover Page
Last updated: August 24, 2026
This Cover Page incorporates by reference the Bonterms Data Protection Addendum, Version 2.0 ("DPA"). Together they form our data processing agreement with you.
We use a standard form rather than a bespoke one on purpose. A DPA your counsel already recognises is faster to review and faster to sign than one we wrote ourselves, and there is nothing in ours that would benefit from being unusual.
Where the actual terms are. The DPA's operative text lives at bonterms.com/standard/dpa-v2. We incorporate it unmodified — the whole value of a standard form is that it is the same document everywhere, so we have not edited it and you should not have to diff it. This page supplies only the details the DPA leaves to the parties.
1. The parties
| Provider | MajesticPenguin LLC, 1522 Western Ave STE 80544, Seattle, WA 98101, USA |
| Customer | The entity that signs this Cover Page |
Provider is the Processor. Customer is the Controller. This reflects §7 of our Privacy Policy: you decide what event data to send and why, and we act on your instructions.
2. Key Terms
| Field | Value |
|---|---|
| Main Agreement | The Postcone Terms of Service |
| DPA Effective Date | The date the Customer signs this Cover Page |
| Sub-processor List | postcone.com/subprocessors |
| Designated EU Governing Law | The law of Ireland |
| Designated EU Member State | Ireland |
| Additional Terms | None. The DPA is incorporated unmodified. |
Ireland is a conventional designation for the EU Standard Contractual Clauses and is not a statement about where data is processed — Section 4 describes that. We will agree to a different member state on request where a customer has a reason to prefer one.
3. Subject matter and details of processing
| Subject matter | Provision of the Postcone event analytics service |
| Duration | The term of the Main Agreement, plus the deletion period in Terms §8.4 |
| Nature and purpose | Receiving, storing, indexing and querying event data on Customer's instructions; generating schema and data view suggestions from it |
| Categories of data subject | Customer's own end users, and Customer's personnel who use the Service |
| Types of personal data | Whatever Customer chooses to send as event data — typically identifiers, event attributes, and device or request metadata. Provider does not select it |
| Sensitive data | None. Terms §4.5 prohibits sending health, payment card, government identifier, precise geolocation, biometric and children's data unless separately agreed in writing |
| Frequency | Continuous, as Customer sends data |
| Retention | Controlled by Customer. After termination, available for export for 30 days, then deleted |
Automated analysis. The Service analyses table schemas automatically and sends a column's name, summary statistics and a small number of example values to our model provider. Those example values come from Customer Data and may therefore contain personal data. The provider does not train on them. Terms §5 sets this out in full, and §5.4 explains how to switch it off.
4. Transfers
Provider is established in the United States and processes data there and, for object storage, in Cloudflare's automatically-selected locations. Where Customer is subject to the GDPR, transfers rely on the EU Standard Contractual Clauses (Module 2, controller to processor) as incorporated by the DPA, with the UK International Data Transfer Addendum and the Swiss adaptations applying where relevant.
The current list of sub-processors and their locations is at postcone.com/subprocessors. We give at least 14 days' notice before adding a sub-processor that handles Customer Data.
5. Security measures
Encryption in transit and at rest. Scoped API keys the Customer can revoke. Access limited to staff who need it. Passwords hashed and salted. Vulnerability reports to security@postcone.com.
These are the measures described in the Security section of our Privacy Policy, and that section is the current statement of them.
6. Signing it
Write to privacy@postcone.com and we will send this Cover Page for signature. It is not binding until both parties sign — publishing it here tells you what we will agree to, it does not conclude the agreement.
The Bonterms Data Protection Addendum, Version 2.0 is © Bonterms and made available under CC BY 4.0. This Cover Page is Postcone's own and incorporates that form unmodified. Bonterms does not endorse Postcone.