Data Processing Agreement (DPA)
Last Updated: July 2026
1. Introduction & Scope
This Data Processing Agreement ("DPA") governs the processing of personal data by Nativine ("Processor") on behalf of the customer ("Controller") in connection with the services provided under the Terms of Use.
This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR) and other applicable privacy regulations.
2. Roles and Responsibilities
2.1. Controller: The Customer is the Data Controller, determines the purposes and means of processing, and warrants that it has all necessary consents and rights to process the data.
2.2. Processor: Nativine acts as the Data Processor and shall process personal data only on documented instructions from the Controller, including with respect to transfers of personal data to a third country.
3. Details of Processing
3.1. Subject Matter: Provision of web-to-app conversion services, push notifications, and app build configurations.
3.2. Duration of Processing: For the duration of the active subscription or until the Controller requests deletion of their account/app configurations.
3.3. Categories of Data Subjects: Users of the Controller's mobile applications, and the Controller's administrative accounts.
3.4. Types of Personal Data: Website URLs, app metadata (icons, splash screens), device identifiers (for push notifications), configuration settings, and contact information (email addresses).
4. Technical and Organizational Security Measures
Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit using HTTPS/TLS.
- Robust access control and authentication procedures for administrative services.
- Self-healing database session security and OTP passwordless authentication options.
- Prompt security vulnerability patching and regular server maintenance.
5. Sub-processors
Controller authorizes Processor to engage sub-processors (such as cloud hosting providers and push notification gateways) to perform specific processing activities. Processor remains fully liable to Controller for the performance of the sub-processors' obligations.
6. Data Subject Rights
Processor shall assist Controller, through appropriate technical and organizational measures, to fulfill Controller's obligation to respond to requests from data subjects exercising their rights (such as access, rectification, or erasure of their personal data).
7. Deletion and Return of Data
Upon termination of the service or request by the Controller, Processor shall permanently delete all personal data and existing copies associated with the Controller's account, unless applicable laws require storage of the personal data.
8. Contact Information
For any privacy or data processing inquiries under this DPA, please contact us at [email protected].
