Data Processing Agreement — Cover Page

Last updated: August 24, 2026

This Cover Page incorporates by reference the Bonterms Data Protection Addendum, Version 2.0 ("DPA"). Together they form our data processing agreement with you.

We use a standard form rather than a bespoke one on purpose. A DPA your counsel already recognises is faster to review and faster to sign than one we wrote ourselves, and there is nothing in ours that would benefit from being unusual.

Where the actual terms are. The DPA's operative text lives at bonterms.com/standard/dpa-v2. We incorporate it unmodified — the whole value of a standard form is that it is the same document everywhere, so we have not edited it and you should not have to diff it. This page supplies only the details the DPA leaves to the parties.


1. The parties

Provider MajesticPenguin LLC, 1522 Western Ave STE 80544, Seattle, WA 98101, USA
Customer The entity that signs this Cover Page

Provider is the Processor. Customer is the Controller. This reflects §7 of our Privacy Policy: you decide what event data to send and why, and we act on your instructions.


2. Key Terms

Field Value
Main Agreement The Postcone Terms of Service
DPA Effective Date The date the Customer signs this Cover Page
Sub-processor List postcone.com/subprocessors
Designated EU Governing Law The law of Ireland
Designated EU Member State Ireland
Additional Terms None. The DPA is incorporated unmodified.

Ireland is a conventional designation for the EU Standard Contractual Clauses and is not a statement about where data is processed — Section 4 describes that. We will agree to a different member state on request where a customer has a reason to prefer one.


3. Subject matter and details of processing

Subject matter Provision of the Postcone event analytics service
Duration The term of the Main Agreement, plus the deletion period in Terms §8.4
Nature and purpose Receiving, storing, indexing and querying event data on Customer's instructions; generating schema and data view suggestions from it
Categories of data subject Customer's own end users, and Customer's personnel who use the Service
Types of personal data Whatever Customer chooses to send as event data — typically identifiers, event attributes, and device or request metadata. Provider does not select it
Sensitive data None. Terms §4.5 prohibits sending health, payment card, government identifier, precise geolocation, biometric and children's data unless separately agreed in writing
Frequency Continuous, as Customer sends data
Retention Controlled by Customer. After termination, available for export for 30 days, then deleted

Automated analysis. The Service analyses table schemas automatically and sends a column's name, summary statistics and a small number of example values to our model provider. Those example values come from Customer Data and may therefore contain personal data. The provider does not train on them. Terms §5 sets this out in full, and §5.4 explains how to switch it off.


4. Transfers

Provider is established in the United States and processes data there and, for object storage, in Cloudflare's automatically-selected locations. Where Customer is subject to the GDPR, transfers rely on the EU Standard Contractual Clauses (Module 2, controller to processor) as incorporated by the DPA, with the UK International Data Transfer Addendum and the Swiss adaptations applying where relevant.

The current list of sub-processors and their locations is at postcone.com/subprocessors. We give at least 14 days' notice before adding a sub-processor that handles Customer Data.


5. Security measures

Encryption in transit and at rest. Scoped API keys the Customer can revoke. Access limited to staff who need it. Passwords hashed and salted. Vulnerability reports to security@postcone.com.

These are the measures described in the Security section of our Privacy Policy, and that section is the current statement of them.


6. Signing it

Write to privacy@postcone.com and we will send this Cover Page for signature. It is not binding until both parties sign — publishing it here tells you what we will agree to, it does not conclude the agreement.


The Bonterms Data Protection Addendum, Version 2.0 is © Bonterms and made available under CC BY 4.0. This Cover Page is Postcone's own and incorporates that form unmodified. Bonterms does not endorse Postcone.