Data Processing Addendum
Last Updated: 8/27/2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Nveal LLC ("Nveal", "Processor") and the customer ("Customer", "Controller") utilizing the Nveal session recording Service.
1. Definitions
- Data Controller: The entity which determines the purposes and means of the processing of Personal Data. In the context of the Nveal Service, the Customer is the Data Controller.
- Data Processor: The entity which processes Personal Data on behalf of the Controller. Nveal is the Data Processor.
- End-User Data: Any data relating to an identified or identifiable natural person visiting the Customer's web properties that is captured by the Nveal SDK.
2. Scope and Roles
This DPA applies when Nveal processes End-User Data on behalf of the Customer in the course of providing the Service. Nveal shall only process End-User Data in accordance with the documented instructions of the Customer (as specified in the Terms of Service and through the use of the Service). Nveal will not sell, retain, use, or disclose End-User Data for any purpose other than providing the Service.
3. Customer Obligations (Controller)
The Customer is solely responsible for:
- Ensuring that there is a lawful basis for processing the End-User Data via the Nveal Service.
- Providing necessary notices and obtaining necessary consents from End-Users regarding the use of session replay technology.
- Configuring the Nveal SDK (using masking and blocking features) to ensure that Highly Sensitive Information (e.g., credit card numbers, health data, passwords) is not transmitted to Nveal.
4. Nveal Obligations (Processor)
Security Measures
Nveal implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, protecting End-User Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure.
Subprocessors
The Customer authorizes Nveal to engage subprocessors to provide the Service. Currently, Nveal utilizes Amazon Web Services (AWS) for cloud hosting and data storage. Nveal ensures that all subprocessors are bound by written agreements that require them to provide at least the level of data protection required by this DPA.
5. Data Retention and Deletion
Nveal is programmed to automatically enforce data retention limits based on the Customer's subscription plan.
- End-User Data (session recordings) is actively retained for a maximum of 7, 14, or 30 days, depending on the active plan.
- Upon expiration of the applicable retention period, the End-User Data is permanently and irreversibly deleted from Nveal's production systems (AWS S3 and PostgreSQL).
- Nveal does not maintain long-term archival backups of expired End-User Data.
Upon termination of the Customer's account, Nveal will delete all remaining End-User Data in accordance with the standard retention cycle, or sooner upon written request from the Customer.
6. Subject Access Requests
Because Nveal processes data anonymously on behalf of the Customer, Nveal generally cannot identify specific End-Users. If Nveal receives a data subject request directly from an End-User, Nveal will direct the End-User to contact the Customer. Nveal will reasonably assist the Customer in fulfilling data subject requests (such as deletion requests) where technically feasible.
7. Contact
For privacy and data processing inquiries, contact [email protected].