Data Processing Addendum

Effective October 9, 2026

This Data Processing Addendum (the "DPA") forms part of the Terms of Service (the "Terms") between Compiled Intelligence, Inc. ("RoutingCat", "we", "us") and the customer that accepts them ("you"). You accept it by accepting the Terms, and no signature is needed. Words defined in the Terms have the same meaning here.

1. Scope and roles

1.1 Definitions.

  • "Data Protection Law" means the laws that apply to the processing of personal data under the Terms, including the EU General Data Protection Regulation (the "GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act (the "CCPA").
  • "Customer Personal Data" means the personal data in Customer Data.
  • "Security Breach" means a breach of our security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorized disclosure of or access to, Customer Personal Data.
  • "Subprocessor" means a third party we engage to process Customer Personal Data.
  • "Controller", "processor", "personal data", "processing", "data subject", "service provider", "sell" and "share" have the meanings Data Protection Law gives them.

1.2 Roles.

  • You are the controller of Customer Personal Data, or a processor acting for your own client, and we process it on your behalf as your processor or subprocessor.
  • When we use Customer Personal Data to improve our products and services, including to train the models that serve all our customers (section 6.2 of the Terms), we decide why and how. For that use, where Data Protection Law treats us as a controller, we act as an independent controller, and our Privacy Policy describes it.
  • We are also the controller of the data we need to run our business, such as the sign-in and billing details of the people who use RoutingCat, under our Privacy Policy.

1.3 Details. Annex 1 describes the processing: its parties, nature, purposes and duration, and the categories of personal data and of data subjects.

2. Instructions

We process Customer Personal Data only on your documented instructions, unless the law requires otherwise, in which case we'll tell you first unless the law forbids it. Your instructions are the Terms, this DPA, and your use and configuration of the Service. Any other instruction needs our written agreement. We'll tell you if we believe an instruction breaches Data Protection Law.

3. Your responsibilities

You are responsible for the lawfulness of Customer Personal Data and of your instructions, including the privacy notices and any consent that section 5 of the Terms requires, and for ensuring that we may process Customer Personal Data as the Terms and this DPA describe.

4. Confidentiality

Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality.

5. Security

We maintain the technical and organizational measures summarized in Annex 2, appropriate to the risk. We may change them, as long as the overall level of protection doesn't decrease.

6. Subprocessors

6.1 Authorization. You authorize us to engage subprocessors. Annex 3 lists those we use and what they do.

6.2 Our duties. We bind each subprocessor to data protection terms that require at least the same level of protection as this DPA, and we remain responsible to you for its performance of them.

6.3 Changes. We'll tell you about a new subprocessor, by email to your account's owner or in the Service, at least 14 days before it starts processing Customer Personal Data. If you object on reasonable data protection grounds within that time, we'll discuss your concerns in good faith. If we can't resolve them, you may close your account, and we'll refund any fees you prepaid for the period after it closes. That is your only remedy.

7. International transfers

7.1 Where. We and our subprocessors process Customer Personal Data in the United States and in other countries where we or they operate.

7.2 From the European Economic Area. For transfers of Customer Personal Data from the European Economic Area to a country without an adequacy decision, the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the "SCCs") apply and form part of this DPA, with you as data exporter and us as data importer:

  • Module 2 (controller to processor) applies where you are a controller, Module 3 (processor to processor) where you are a processor, and Module 1 (controller to controller) to the uses for which we are an independent controller (section 1.2);
  • Clause 7 doesn't apply; in Clause 9(a), Option 2 applies, with the notice period of section 6.3; the option in Clause 11(a) doesn't apply; the competent supervisory authority is the one Clause 13 designates; and in Clauses 17 and 18, the law and the courts of Ireland apply;
  • Annex I to the SCCs is Annex 1 of this DPA, Annex II is Annex 2, and Annex III is Annex 3;
  • audits and the certification of deletion under the SCCs are carried out as sections 10 and 11 describe.

7.3 From the United Kingdom. For transfers from the United Kingdom, the SCCs apply as amended by the International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner, whose tables are completed with the information in section 7.2 and the Annexes.

7.4 From Switzerland. For transfers from Switzerland, the SCCs apply with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; references to the GDPR include the Swiss Federal Act on Data Protection; and "Member State" includes Switzerland, so that data subjects there can enforce their rights in Switzerland.

7.5 Precedence and signature. If the SCCs conflict with this DPA or the Terms, the SCCs prevail. Accepting the Terms counts as signing the SCCs and the UK Addendum.

8. Security Breaches

We'll notify you without undue delay after we become aware of a Security Breach. As information becomes available, we'll give you what you reasonably need to meet your own obligations: what happened, the categories of data and of data subjects concerned, its likely consequences, and the measures taken or proposed. We'll take reasonable steps to contain it and limit its effects. Notifying you is not an admission of fault. Unsuccessful attempts that don't compromise Customer Personal Data, such as scans, failed sign-ins or denial-of-service attacks, are not Security Breaches.

9. Requests and assistance

9.1 Requests from individuals. If a data subject asks us about Customer Personal Data, we refer them to you, or pass the request on to you when we can tell that it concerns your sites, and we don't otherwise answer it unless you instruct us or the law requires it. We answer requests about the uses for which we are an independent controller (section 1.2) ourselves.

9.2 Deletion. You can ask us to delete the data of one visitor or one of your users, or all of a site's data, as section 6.5 of the Terms describes. A visitor's id is the value of its rc_vid cookie.

9.3 Other assistance. Taking into account the nature of the processing and the information available to us, we'll give you reasonable assistance with other data subject requests, and with your security obligations, data protection impact assessments and consultations with supervisory authorities, where you can't get what you need from the Service, its documentation or this DPA. We may charge our reasonable costs for assistance that takes significant effort.

10. Information and audits

On written request, once a year at most or after a Security Breach, we'll give you the information reasonably needed to show that we meet this DPA, such as answers to a reasonable security questionnaire, and our subprocessors' security reports where they allow us to share them. If that information isn't enough, or a supervisory authority requires it, you may have an independent auditor, bound by confidentiality, audit our compliance with this DPA at your cost, with at least 30 days' notice, during business hours, without disrupting our operations or accessing other customers' data.

11. Deletion and return

When your account closes, we delete Customer Personal Data, after returning a copy if you asked for one, as section 6.5 of the Terms describes. We may keep what the law requires us to keep, protected by this DPA for as long as we keep it. On request, we'll confirm the deletion in writing.

12. US state privacy laws

Where the CCPA or a similar US state law applies, we act as your service provider or processor for Customer Personal Data, and:

  • we don't sell or share it;
  • we don't retain, use or disclose it for any purpose other than the business purposes in the Terms and this DPA, or outside our direct business relationship with you, except as that law permits, including to build or improve the quality of our services;
  • we don't combine it with personal data from other sources, except as that law permits;
  • we meet that law's obligations for service providers and processors, give Customer Personal Data the level of privacy protection it requires, and tell you if we can no longer meet those obligations;
  • you may take reasonable and appropriate steps, through section 10, to ensure that we use Customer Personal Data consistently with your obligations, and to stop and remediate any unauthorized use.

13. Liability and precedence

Our liability under this DPA, including under the SCCs, is subject to section 13 of the Terms, except where the SCCs or Data Protection Law don't allow it to be limited, such as toward data subjects. If this DPA conflicts with the rest of the Terms, this DPA prevails for the processing of Customer Personal Data. It applies for as long as we process Customer Personal Data.

Annex 1: The processing

Parties. The data exporter is you, the customer, as controller or processor; your contact is your account's owner. The data importer is Compiled Intelligence, Inc., 2810 N Church St, Ste 88797, Wilmington, DE 19802, USA, as processor, and as independent controller for the uses in section 1.2; its contact is privacy@routingcat.com.

Data subjects. Visitors to your sites; your users and customers whom you identify by your own account ids; and the people you add to your RoutingCat account.

Personal data, by category:

  • identifiers: the random visitor and visit ids that RoutingCat assigns, and the account ids you send;
  • request details, such as the time, the browser and its language, the page's address with identifiers removed, an approximate location that your host derives from the IP address, and the IP address's network prefix; the full address is used in memory only and never stored;
  • device and browser characteristics, such as the screen size and the time zone;
  • where visits came from, such as the referring site, the landing page, campaign tags and ad click identifiers, whose values are kept;
  • what each visitor was shown, including whether they were in the control group;
  • engagement, such as what was seen and for how long, clicks, scroll depth and page performance;
  • the events you send, such as sign-ups and purchases, with what you include in them, and the links you make between visitor ids and account ids;
  • the email addresses of the people you add to your account.

Sensitive data. None. Section 4 of the Terms forbids sending it.

Frequency. Continuous, while RoutingCat is installed on your sites.

Nature of the processing. Collection, recording, storage, analysis, model training, aggregation, retrieval, disclosure to you, and deletion.

Purposes. To route each visitor between your variants; to measure your outcomes, and the gain over a control group; to report results to you and your agents; to secure the Service, including by recognizing crawlers and abuse; to support you; and, as an independent controller (section 1.2), to improve RoutingCat's products and the models that serve all its customers.

Duration. For the term of the Terms, then until deletion under section 6.5 of the Terms.

Subprocessors. Those in Annex 3, for the purposes stated there, for as long as we use them.

Annex 2: Security measures

  • Encryption. Data travels over TLS, and our storage and database providers encrypt it at rest.
  • Minimization. A visitor's full IP address is used in memory to recognize crawlers, and only its network prefix is stored. The endpoint that collects data from your sites keeps no request logs. Form contents, request bodies, authorization headers and other cookies' contents are never stored. Page addresses are stored with identifiers removed, and without query values other than campaign tags and ad click identifiers.
  • Separation between customers. Each customer's data is kept by site, and the database enforces that separation on every transaction. Each part of the Service has its own database role, with only the access it needs.
  • Access. Only the RoutingCat staff who need it can reach production systems, with individual credentials. Servers accept administrative connections only with a key and from approved addresses. Secrets are kept out of code. Each key we issue to you is scoped to one site; the secret keys are also scoped to one environment and can be replaced, and the public key can only send data.
  • Accountability. Every change to a site is recorded with who made it, including changes made by RoutingCat's staff.
  • Infrastructure. The Service runs on the providers in Annex 3, which maintain their own security programs and certifications. RoutingCat holds no security certification of its own.
  • People. Everyone with access to Customer Personal Data is bound by confidentiality.

Annex 3: Subprocessors

  • Cloudflare, Inc.: runs RoutingCat's API, data collection, dashboard and documentation; queues and stores collected data, results and the files the SDK downloads; and provides DNS, email routing, content delivery and network protection.
  • DigitalOcean, LLC: hosts the server that processes collected data: analytics, model training, and building the files the SDK downloads.
  • Supabase, Inc.: hosts the database of accounts, sites, their configuration and the index of their results.
  • Clerk, Inc.: signs in the people who use RoutingCat, and sends the invitations to join an account.

Request access

Leave your details and we’ll get back to you.

Stack (optional)

By requesting access, you agree to our Privacy Policy.