Data Processing Agreement

Data processing agreement.

This DPA governs Overlay's processing of personal data on behalf of the merchants who use it. It is designed to satisfy GDPR Article 28, the UK GDPR, and the California, Colorado, Virginia, Connecticut, and Utah state privacy laws. Print, sign, and email it back — or accept it electronically in the dashboard.

Effective · 2026-09-28 Last updated · 2026-09-28 Version · 1.0
Request a countersigned copy

1Preamble #

This Data Processing Agreement ("DPA") supplements the Terms of Service between Overlay ("Overlay", "Processor") and the merchant identified in the signature block ("Customer", "Controller"). It applies whenever Overlay processes Personal Data on the Customer's behalf.

If there is a conflict between the Terms of Service and this DPA on any matter concerning Personal Data, this DPA controls.

2Definitions #

Capitalized terms have the meaning given in the Terms of Service or, if not defined there, the meaning given by GDPR Article 4. For clarity:

Personal Data
any information relating to an identified or identifiable natural person that Overlay processes on behalf of the Customer under the Terms.
Data Subject
a natural person to whom Personal Data relates (typically, one of the Customer's own customers or staff).
Processing
any operation performed on Personal Data — collection, storage, retrieval, transmission, deletion, and similar.
Sub-processor
a third party engaged by Overlay to process Personal Data on the Customer's behalf.
Personal Data Breach
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
SCCs
the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 for the transfer of Personal Data to third countries.
Applicable Law
GDPR, UK GDPR, the Swiss Federal Act on Data Protection, and US state privacy laws applicable to the Customer's business.

3Roles of the parties #

The Customer is the Controller of the Personal Data it uploads or directs Overlay to process. Overlay is the Processor. Where a Sub-processor is engaged, that Sub-processor acts as a further processor.

Each party is independently responsible for its own compliance with Applicable Law. The Customer is responsible for the lawfulness of the instructions it gives Overlay, including having a legal basis for processing and, where required, having obtained the necessary consents from Data Subjects.

4Scope of processing #

Overlay processes Personal Data only:

  1. To provide the service described in the Terms of Service;
  2. In accordance with the Customer's documented instructions (which are given by the Customer's use of the service and the settings the Customer configures);
  3. As required by law (with notice to the Customer where lawful).

The subject matter, duration, nature, purpose of processing, categories of Personal Data, and categories of Data Subjects are set out in Appendix A.

Overlay will inform the Customer if, in its opinion, an instruction infringes Applicable Law.

5Processor obligations #

  • Confidentiality. Overlay ensures that persons authorized to process Personal Data have committed to confidentiality obligations, whether contractual or statutory.
  • Cooperation. Overlay will assist the Customer, at the Customer's expense for anything beyond what is included in the standard service, in complying with the Customer's obligations under Applicable Law — including responses to Data Subject requests, data-protection impact assessments, and consultations with a supervisory authority.
  • Records. Overlay maintains a written record of processing activities carried out on behalf of Controllers as required by GDPR Article 30(2), and will make it available to the Customer on request.
  • No selling. Overlay does not sell or share Personal Data. Overlay does not process Personal Data for purposes outside the direct provision of the service.

6Sub-processors #

The Customer authorizes Overlay to engage the Sub-processors listed in Appendix B. Overlay will:

  • Impose written obligations on each Sub-processor that are no less protective than those in this DPA.
  • Remain fully liable to the Customer for the acts and omissions of its Sub-processors.
  • Give at least 30 days' notice by email to the account contact of any change to the Sub-processor list. The Customer may object in writing within that period on reasonable data-protection grounds. If the parties cannot reach a mutually acceptable solution, the Customer may terminate the service on written notice; Overlay will refund any prepaid unused fees.

7Security measures #

Overlay implements appropriate technical and organizational measures to protect Personal Data against a Personal Data Breach. A description of those measures is set out in Appendix C and on the Security page. Because security practices evolve, Overlay may update its measures provided that the level of protection is not materially decreased.

8Personal Data Breach #

Overlay will notify the Customer by email to the account contact without undue delay, and in any event within 48 hours of becoming aware of a confirmed Personal Data Breach affecting Personal Data processed on the Customer's behalf. The notification will include:

  • The nature of the breach, including the categories and approximate number of Data Subjects and records affected;
  • The likely consequences of the breach;
  • The measures Overlay has taken or proposes to take to address the breach and mitigate its effects;
  • The contact point for further information.

Overlay's notification is not an acknowledgment of fault or liability. The Customer remains responsible for any notifications to supervisory authorities and Data Subjects that are required of it as Controller.

9Data subject requests #

The Customer's dashboard includes self-serve tools to export, correct, and delete customer records. Overlay will assist with a Data Subject request that cannot be handled through those tools, at no additional cost for reasonable volumes.

If a Data Subject contacts Overlay directly with a request concerning data processed for a specific Customer, Overlay will forward the request to that Customer without acting on it, unless the request concerns Overlay's own processing (for example, an inquiry about how a merchant's marketing email reached that recipient).

10International transfers #

Overlay processes and stores Personal Data in the United States. Where the Customer is established in the European Economic Area, the United Kingdom, or Switzerland, transfers of Personal Data to Overlay and its US-based Sub-processors are governed by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2 or 3 as applicable), which are incorporated into this DPA by reference and completed as follows:

  • Clause 7 (docking clause): applies.
  • Clause 9 (sub-processor authorization): Option 2, general written authorization with 30-day notice.
  • Clause 11 (redress): the optional independent dispute-resolution language is omitted.
  • Clause 17 (governing law): Republic of Ireland.
  • Clause 18 (choice of forum): courts of Ireland.
  • Annex I.A (parties): Customer as data exporter (Controller); Overlay as data importer (Processor).
  • Annex I.B (transfer details): as described in Appendix A.
  • Annex II (technical and organizational measures): as described in Appendix C.
  • Annex III (sub-processors): as listed in Appendix B.

For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the SCCs. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss FADP; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.

11Audits #

Overlay will make available to the Customer, on written request, information reasonably necessary to demonstrate compliance with this DPA — including the current security summary in Security, sub-processor list, and any third-party audit reports Overlay obtains in the future.

The Customer may, at its expense and no more than once per 12-month period (except after a Personal Data Breach or when required by a supervisory authority), audit Overlay's compliance with this DPA. Audits must be conducted:

  • With at least 30 days' written notice;
  • During normal business hours;
  • Without disruption to Overlay's operations or those of its other customers;
  • By the Customer or an independent auditor bound by written confidentiality obligations;
  • Subject to reasonable safety and security procedures.

An audit does not extend to Overlay's Sub-processors' facilities or systems; for those, Overlay will use reasonable efforts to obtain the Customer information it needs from the relevant Sub-processor.

12Return & deletion #

Within 30 days of termination of the Terms of Service, or on the Customer's earlier written request, Overlay will delete all Personal Data processed on the Customer's behalf, except to the extent that:

  • Applicable law requires retention (in which case Overlay isolates and secures the retained data);
  • Personal Data has been anonymized and cannot be re-identified;
  • Personal Data is contained in routine backups that have not yet rolled off (they roll off within 7 days per Security §7).

The Customer may request an export of Personal Data in a structured, commonly used, machine-readable format at any time before deletion.

13CCPA & US state privacy laws #

Where the California Consumer Privacy Act ("CCPA"), Colorado Privacy Act, Virginia Consumer Data Protection Act, Connecticut Data Privacy Act, or Utah Consumer Privacy Act applies to the Customer, Overlay acts as a service provider or processor (as those terms are used in the applicable statute). Overlay will:

  • Process Personal Information only for the "business purposes" of providing the service and only as described in this DPA;
  • Not sell or share Personal Information;
  • Not retain, use, or disclose Personal Information outside the direct business relationship between Overlay and the Customer;
  • Not combine Personal Information received from the Customer with Personal Information received from any other source, except as expressly permitted by the applicable statute;
  • Assist the Customer in responding to consumer rights requests to the extent reasonably practicable;
  • Notify the Customer if Overlay determines that it can no longer meet its obligations under the applicable statute.

The Customer certifies that it understands and will comply with its own obligations under the applicable statute.

14Term & liability #

This DPA takes effect on the Effective Date and continues for the duration of the Terms of Service and for as long as Overlay retains any Personal Data on the Customer's behalf. Sections that by their nature survive termination (audit, return and deletion, liability) survive.

The liability of each party under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA is intended to exclude or limit liability that cannot be excluded or limited under Applicable Law.

AAppendix A — Categories of data #

Subject matter

The provision of the Overlay service — storefront, marketing, subscription clubs, waitlist, analytics — to the Customer.

Duration

The duration of the Terms of Service, plus up to 30 days for deletion and up to 7 days for backup rollover.

Nature and purpose of processing

Hosting, transmission, storage, retrieval, analysis, and deletion of Personal Data to deliver the service.

Categories of Data Subjects

  • The Customer's own customers (retail shoppers, subscribers, waitlist entrants).
  • The Customer's staff and administrators (with dashboard access).
  • Recipients of marketing communications sent by the Customer through Overlay.

Categories of Personal Data

  • Identity: name, business name, staff role.
  • Contact: email address, phone number, mailing address.
  • Transactional: order records, purchase history, subscription status, waitlist entries.
  • Marketing engagement: opens, clicks, unsubscribes, suppression list membership.
  • Authentication metadata (session tokens, IP address at login for security).

No Special Categories of Personal Data (GDPR Article 9) are intentionally processed. Card numbers and government identifiers are not stored by Overlay.

Frequency and duration of transfer

Continuous, for the duration of the Terms of Service.

BAppendix B — Sub-processors #

The current list of Sub-processors engaged by Overlay to process Personal Data. Overlay-operator infrastructure is listed first; Customer-selected connections are marked as such.

Sub-processorPurposeLocation
Render Services, Inc.Application hosting, disk backups, TLS terminationUnited States
Amazon Web Services, Inc. (SES)Transactional and marketing email deliveryUnited States (US-East)
Stripe, Inc.Overlay subscription billingUnited States
Anthropic, PBCAI text generation for merchant-authored contentUnited States
Functional Software, Inc. (Sentry)Server error reporting (headers redacted)United States
Block, Inc. (Square) — Customer-selectedPOS, catalog, inventory, hosted checkoutUnited States
Shopify, Inc. — Customer-selectedPOS, catalog, checkoutCanada / United States
Automattic (WooCommerce) — Customer-selectedPOS, catalog, checkoutUnited States
EasyPost, Inc. — Customer-selectedShipping labels for orders that shipUnited States
DoorDash, Inc. (Drive) — Customer-selectedLocal delivery for orders that deliverUnited States

The latest version of this list is maintained at overlaypos.com/security. Changes are announced by email 30 days before they take effect.

CAppendix C — Security measures #

Overlay implements the following technical and organizational measures. A fuller, plain-language description — including the current roadmap and known limitations — is maintained on the Security page and is incorporated here by reference.

  • Encryption in transit — TLS 1.2 or higher on all customer-facing endpoints; HSTS enabled.
  • Encryption at rest — provider-level disk encryption on all application storage.
  • Isolation — every tenant's data is namespaced and accessed only through the tenant-resolving abstraction; cross-tenant reads are prevented at code review.
  • Access controls — layered session tokens, per-tenant admin keys, and a single operator master key; passwords hashed with bcrypt.
  • Change control — every production push runs npm audit at HIGH+, syntax checks, and the test suite; sensitive changes stage through staging.overlaypos.com.
  • Mass-send guardrails — preflight and duplicate-send guards are mandatory on any campaign that reaches more than one recipient.
  • Logging — structured logs retained 30 days with sensitive headers redacted; Sentry available on opt-in.
  • Backups — daily snapshots retained 7 days.
  • Personnel — access to production systems is limited to Overlay's operator; contractors sign confidentiality agreements before access.
  • Incident response — 48-hour breach notification target; 14-day fix target for HIGH/CRITICAL.

Overlay does not currently hold SOC 2, ISO 27001, or PCI DSS attestations. Payment card data does not enter Overlay systems.

✓Signatures #

The parties agree to this DPA as of the date last signed below. Electronic acceptance in the Overlay dashboard has the same legal effect as a handwritten signature.

Signed as of the Effective Date
Print and sign, or email a scanned copy to team@overlaypos.com with the subject "DPA countersignature request". Overlay will countersign and return within five business days.

Processor

Overlay
Signature
Name
Title
Date

Controller

Customer
(as identified in the Overlay account)
Signature
Name
Title
Date
Prefer electronic acceptance? The current signed-in merchant contact can accept this DPA in the Overlay dashboard under Settings → Legal → Data Processing Agreement. Acceptance is time-stamped, logged, and binding.