Legal
The terms under which Numal processes data on your behalf, including the subprocessor list, the security measures we actually run, and how a breach would reach you.
Last updated September 14, 2026
This page is the data processing agreement between Numal, Inc. and the account holder. It applies automatically when you use Numal and forms part of the Terms of Service, so most customers don't need to sign anything separately.
If your procurement team needs a countersigned copy on your own paper, write to privacy@numal.ai and we'll sign one. We won't charge for it and we won't make you buy a higher plan to get it.
Getting this wrong is the usual reason a DPA is useless, so plainly:
| Data | Controller | Processor |
|---|---|---|
| Transaction records from the POS | The business owner, and the agency where it decides how they're used | Numal |
| Post and public engagement data | The account holder | Numal |
| Numal account and billing data | Numal | — |
| Website analytics | Numal | — |
Where we act as processor, we process only on documented instructions from you — using the product is the instruction — and we will tell you if an instruction appears to breach data protection law rather than quietly carrying it out.
You give general authorization for the subprocessors below. Each is bound by terms no weaker than these, and we remain liable to you for what they do.
| Subprocessor | Function | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, storage, database | US — us-west-2 |
| Stripe, Inc. | Payment processing, invoicing | United States |
| Wildbit, LLC (Postmark) | Transactional email | United States |
| Cloudflare, Inc. | CDN, DNS, DDoS protection | Global edge |
| Google LLC | Website analytics on numal.ai, where the visitor has not turned it off | United States |
| Microsoft Corporation | Website analytics and visit replay on numal.ai, where the visitor has not turned it off | United States |
| Anthropic, PBC | Report summary drafting, where the account has it enabled | United States |
We'll give 30 days' notice by email before adding or replacing one. If you have a reasonable, specific objection on data protection grounds, tell us within those 30 days and we'll either propose a workaround or let you terminate the affected part of the service with a pro-rata refund.
The technical and organizational measures required by Article 32, in the form we actually operate them:
Numal is hosted in the United States. If you're in the EEA, the UK or Switzerland, your data will be transferred there.
That transfer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), module two, controller to processor, incorporated into this agreement by reference — together with the UK Addendum issued by the ICO where the UK GDPR applies. We've carried out a transfer impact assessment and will share it on request.
If a decision or law makes that basis invalid, we'll adopt a valid alternative or, failing that, let you terminate without penalty and refund what's unused.
If we become aware of a personal data breach affecting your data, we'll notify you without undue delay and in any case within 72 hours. The notice will say what happened, which data and roughly how many records are affected, what the likely consequences are, and what we're doing — including what we don't yet know.
We'll help you meet your own notification duties, and we won't ask you to keep the incident confidential as a condition of being told about it.
If a data subject contacts us directly about data we process on your behalf, we'll point them to you rather than answering for you — unless they're the business owner asking about access to their own point of sale, where we'll act immediately and tell you afterward.
The product has export and deletion built in, so most access, correction and erasure requests you receive can be answered without involving us. Where they can't, we'll help within 10 business days.
You may audit our compliance once in any twelve-month period, or more often if a regulator requires it. In the first instance we'll answer a written questionnaire and share our current security documentation; if that doesn't settle it, we'll accommodate an on-site or remote audit on 30 days' notice, during business hours, under confidentiality, at your cost unless the audit finds a material breach.
At any point during the agreement you can export everything yourself, in CSV and PDF, without asking.
When the agreement ends we delete personal data within 90 days, including from backups as they cycle out on their 30-day rotation. We'll confirm deletion in writing if you ask. The only exception is what we're legally required to keep — billing records for tax — which stays isolated and is used for nothing else.
Data protection inquiries, DPA signature requests, transfer impact assessments and audit questionnaires: privacy@numal.ai.
Numal, Inc., Los Angeles, California, United States.
We don't currently have an Article 27 representative in the EU or UK because we don't yet meet the threshold that requires one. If that changes, this page changes first.
Numal sets two kinds of cookie and no others. There is no advertising network on this site, so there is nothing here to sell you.
Your choice is stored on this device and applies until you change it. Details are in the Privacy Policy.