Skip to content
Twinpage

Data Processing Agreement

Effective 1 October 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you, the customer, and Ziad Antar, trading as Twinpage, United Arab Emirates ("we", "us"). It applies whenever we process personal data for you under the GDPR, the UK GDPR or similar laws. You accept it when you accept the Terms; you don't need to sign anything.

Roles

For data about visitors to your website that the Twinpage snippet handles, you are the controller and we are your processor. For your own account, billing and our website, we are the controller, as described in our Privacy Policy; this DPA does not cover that data.

What we process and why

  • Purpose: running your A/B tests and showing you their results.
  • Data subjects: visitors to the websites where you install the snippet.
  • Personal data: the experiment, version and metric a visitor's browser reports with each view or conversion, which we keep only as counts; and, in our hosting provider's request logs, the visitor's IP address, browser details, the address requested and the time. The random visitor ID and the visitor profile the snippet keeps stay in the visitor's browser and are not sent to us (see Snippet privacy and consent).
  • Special categories of data: none. You must not use Twinpage to process them.
  • Duration: while your account exists, and until the data is deleted as described below.

What custom JavaScript you add does on your site is your own processing, not ours, and is outside this DPA.

Our obligations

  • We process the data only on your documented instructions (the Terms, this DPA and how you set up the Service), including for transfers, unless the law requires otherwise; in that case we tell you first, unless the law forbids it. If we think an instruction breaks data protection law, we tell you immediately.
  • Everyone we allow to process the data is bound to keep it confidential.
  • We take the security measures described below.
  • We use sub-processors only as described below.
  • We help you, as far as we reasonably can, to answer requests from visitors who use their data protection rights.
  • We help you meet your duties on security, breach notification, data protection impact assessments and consulting a supervisory authority, taking into account what we process and the information we have. If we become aware of a personal data breach affecting your data, we tell you without undue delay.
  • When your account ends, we delete the data as described below.
  • We give you the information you need to show that we meet this DPA, and allow and contribute to reasonable audits, including inspections, by you or an auditor you choose, on reasonable notice.

Security

  • All traffic to our servers is encrypted in transit (HTTPS).
  • Every database query for your dashboard is limited to your account, and our database's public interfaces give signed-in users read access only to their own account's rows.
  • In browsers, the snippet's configuration, heartbeat and event endpoints answer only pages on your project's domain and its subdomains (and our own app); event intake is also rate-limited per project.
  • We keep only counts of views and conversions, never a record of individual visitors, and we do not store visitors' IP addresses or browser details in our database.
  • Custom JavaScript is off unless you turn it on for a project, and we can turn it off for any project or for the whole Service.

Sub-processors

You authorise us to use these sub-processors for the data this DPA covers:

  • Supabase: our database. Our production database is in the EU (Frankfurt, Germany).
  • Vercel: hosting of our servers in the EU (Frankfurt) region, and their request logs.

We will email you at least 30 days before we add or replace a sub-processor for this data. If you object on reasonable data protection grounds, you can cancel before the change applies; your plan then runs to the end of the period you have paid for, and within 14 days of a charge the Refund Policy applies. We give each sub-processor data protection obligations that are at least as protective as this DPA, and we remain responsible to you for them.

Transfers

Twinpage is operated from the United Arab Emirates, and our sub-processors may access data from outside the EU or the UK. Where data is transferred out of the EU, the standard contractual clauses adopted by the European Commission (Decision 2021/914), Module 2 (controller to processor), are incorporated into this DPA by reference, with you as the data exporter and us as the data importer. For transfers out of the UK, the UK International Data Transfer Addendum to those clauses is incorporated too. The parties and roles, the data and purposes, and the security measures the clauses describe are those in this DPA. If the clauses and this DPA conflict, the clauses win.

For the clauses: the optional docking clause applies; general written authorisation applies to sub-processors, with the 30 days' notice above; the clauses are governed by the law of Ireland and disputes go to its courts; the competent supervisory authority is the one the clauses' own rules name for an importer outside the EU; the list of sub-processors above is the sub-processor annex. For the UK Addendum, the tables are filled in with the same details, and either party may end it as the Addendum allows.

Deletion and return

Deleting an experiment deletes its results, and deleting your account deletes the results of all your experiments. If your account ends in another way, we delete the data within 30 days unless the law requires us to keep it. Our providers' request logs and backups clear on their own schedules. Before your account ends you can note your results from the dashboard (there is no export yet), or ask us for a copy.

Contact

Ziad Antar, trading as Twinpage, United Arab Emirates, hello@twinpage.app.