Legal

Data Processing

The terms under which Numal processes data on your behalf, including the subprocessor list, the security measures we actually run, and how a breach would reach you.

Last updated September 14, 2026

What this is

This page is the data processing agreement between Numal, Inc. and the account holder. It applies automatically when you use Numal and forms part of the Terms of Service, so most customers don't need to sign anything separately.

If your procurement team needs a countersigned copy on your own paper, write to privacy@numal.ai and we'll sign one. We won't charge for it and we won't make you buy a higher plan to get it.

Who is the controller, who is the processor

Getting this wrong is the usual reason a DPA is useless, so plainly:

DataControllerProcessor
Transaction records from the POSThe business owner, and the agency where it decides how they're usedNumal
Post and public engagement dataThe account holderNumal
Numal account and billing dataNumal—
Website analyticsNumal—

Where we act as processor, we process only on documented instructions from you — using the product is the instruction — and we will tell you if an instruction appears to breach data protection law rather than quietly carrying it out.

Scope, nature and duration

  • Subject matter: matching social posts to settled sales, and producing reports from the result.
  • Duration: for as long as the account is open, plus the retention windows set out in the Privacy Policy.
  • Categories of data subject: account users at the agency, and named contacts at the connected business. Not the business's customers — we don't receive data that identifies them.
  • Categories of personal data: names, work emails, roles, login and audit records. Transaction amounts and timestamps are business records rather than personal data in most cases, but we treat them with the same care.
  • Special categories: none. Don't send us any.

Subprocessors

You give general authorization for the subprocessors below. Each is bound by terms no weaker than these, and we remain liable to you for what they do.

SubprocessorFunctionLocation
Amazon Web Services, Inc.Hosting, storage, databaseUS — us-west-2
Stripe, Inc.Payment processing, invoicingUnited States
Wildbit, LLC (Postmark)Transactional emailUnited States
Cloudflare, Inc.CDN, DNS, DDoS protectionGlobal edge
Google LLCWebsite analytics on numal.ai, where the visitor has not turned it offUnited States
Microsoft CorporationWebsite analytics and visit replay on numal.ai, where the visitor has not turned it offUnited States
Anthropic, PBCReport summary drafting, where the account has it enabledUnited States

We'll give 30 days' notice by email before adding or replacing one. If you have a reasonable, specific objection on data protection grounds, tell us within those 30 days and we'll either propose a workaround or let you terminate the affected part of the service with a pro-rata refund.

Security measures

The technical and organizational measures required by Article 32, in the form we actually operate them:

  • Encryption — TLS 1.2+ in transit, AES-256 at rest, including backups.
  • Access control — least privilege, hardware-key two-factor for all production access, quarterly review, revocation on the day someone leaves.
  • Segregation — each account's data is logically separated and queries are scoped at the application layer; production data is never copied to development environments.
  • Scope minimization — point-of-sale connections are read-only, and request only the narrowest scope each provider offers.
  • Resilience — daily encrypted backups with a 30-day window, restore-tested quarterly.
  • Logging — administrative access and data exports are logged and retained for 12 months.
  • People — background checks where lawful, confidentiality obligations that survive employment, annual security training.

International transfers

Numal is hosted in the United States. If you're in the EEA, the UK or Switzerland, your data will be transferred there.

That transfer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), module two, controller to processor, incorporated into this agreement by reference — together with the UK Addendum issued by the ICO where the UK GDPR applies. We've carried out a transfer impact assessment and will share it on request.

If a decision or law makes that basis invalid, we'll adopt a valid alternative or, failing that, let you terminate without penalty and refund what's unused.

Breach notification

If we become aware of a personal data breach affecting your data, we'll notify you without undue delay and in any case within 72 hours. The notice will say what happened, which data and roughly how many records are affected, what the likely consequences are, and what we're doing — including what we don't yet know.

We'll help you meet your own notification duties, and we won't ask you to keep the incident confidential as a condition of being told about it.

Data subject requests and audits

If a data subject contacts us directly about data we process on your behalf, we'll point them to you rather than answering for you — unless they're the business owner asking about access to their own point of sale, where we'll act immediately and tell you afterward.

The product has export and deletion built in, so most access, correction and erasure requests you receive can be answered without involving us. Where they can't, we'll help within 10 business days.

You may audit our compliance once in any twelve-month period, or more often if a regulator requires it. In the first instance we'll answer a written questionnaire and share our current security documentation; if that doesn't settle it, we'll accommodate an on-site or remote audit on 30 days' notice, during business hours, under confidentiality, at your cost unless the audit finds a material breach.

Return and deletion

At any point during the agreement you can export everything yourself, in CSV and PDF, without asking.

When the agreement ends we delete personal data within 90 days, including from backups as they cycle out on their 30-day rotation. We'll confirm deletion in writing if you ask. The only exception is what we're legally required to keep — billing records for tax — which stays isolated and is used for nothing else.

Contact

Data protection inquiries, DPA signature requests, transfer impact assessments and audit questionnaires: privacy@numal.ai.

Numal, Inc., Los Angeles, California, United States.

We don't currently have an Article 27 representative in the EU or UK because we don't yet meet the threshold that requires one. If that changes, this page changes first.