Data Processing Agreement (DPA)
Last updated: July 20, 2026
Preamble: read this first
AttribuLead is primarily self-hosted WordPress software. The plugin stores visitor, attribution, lead, and commerce data in the Customer’s own WordPress database on infrastructure selected and controlled by the Customer. That data is not routinely transmitted to AttribuLead.
This agreement distinguishes among three categories of data:
| Website Data | Support Data | Account Data | |
|---|---|---|---|
| Examples | Visitor UUIDs, attribution signals, lead email, name, company, form submissions, and purchase attribution stored by the plugin | Diagnostics, screenshots, exports, or other Website Data that the Customer deliberately sends to AttribuLead for support | Customer name, billing email, licence key, activated site URL, purchase records, and ordinary support correspondence |
| Where it lives | The Customer’s WordPress database on the Customer’s server | AttribuLead’s support systems for the limited duration needed to resolve the request | AttribuLead’s account, licensing, billing, website, and support systems |
| Primary legal role | The Customer is the controller; AttribuLead does not process this data | The Customer is the controller; AttribuLead acts as processor for the submitted material | AttribuLead ordinarily acts as an independent controller |
| Covered by this DPA? | No, unless the Customer deliberately sends it to AttribuLead | Yes | No; it is governed by AttribuLead’s Privacy Policy and applicable law |
AttribuLead personnel cannot access Customer Website Data unless the Customer deliberately exports, copies, uploads, or otherwise sends that data to AttribuLead as part of a support request.
This DPA therefore applies only when AttribuLead processes Personal Data on the Customer’s behalf, principally where the Customer deliberately supplies Website Data or other Personal Data for troubleshooting or support. It also records, for the Customer’s compliance file, why AttribuLead is not ordinarily a processor of Website Data.
1. Parties and scope
1.1 This Data Processing Agreement (“DPA“) forms part of the Terms of Service (the “Agreement“) between:
- AttribuLead, a sole proprietorship operating in British Columbia, Canada, through https://www.attribulead.com/ (“AttribuLead” or “Processor” when acting on the Customer’s behalf); and
- the Customer, the individual or organisation that has entered into the Agreement by purchasing or using AttribuLead (“Customer” or “Controller“).
1.2 Where this DPA is signed, the Customer’s legal name and details are completed in the signature block. Where it is incorporated by reference into the Agreement, “Customer” means the account holder identified in the Agreement.
1.3 This DPA applies only to Personal Data that AttribuLead processes on the Customer’s behalf. It is intended to satisfy applicable processor-contract requirements under Article 28 of the EU GDPR, the UK GDPR, and comparable requirements under applicable privacy law.
1.4 AttribuLead is established in British Columbia, Canada. Depending on the circumstances, applicable Canadian privacy law may include British Columbia’s Personal Information Protection Act (“BC PIPA“) and the federal Personal Information Protection and Electronic Documents Act (“PIPEDA“), including for interprovincial or international commercial data flows.
1.5 AttribuLead ordinarily acts as an independent controller for Account Data used to administer customer relationships, licensing, billing, fraud prevention, legal compliance, product communications, and AttribuLead’s own website analytics. Those activities are governed by the Privacy Policy, not this DPA.
2. Website Data: AttribuLead is not ordinarily a processor
2.1 The AttribuLead plugin is self-hosted software installed on infrastructure selected and controlled by the Customer. Data collected by the plugin about the Customer’s website visitors, leads, customers, and attributed purchases (“Website Data“) is written to and remains within the Customer’s own WordPress database, subject to any integrations independently configured by the Customer.
2.2 Except where the Customer deliberately submits Website Data to AttribuLead for support, AttribuLead does not receive, access, store, retrieve, or otherwise process Website Data.
2.3 For licence validation and software delivery, the plugin may transmit limited licensing information such as the licence key, product identifier, plugin version, and activated site URL. This information is Account Data and does not include the visitor, lead, form, journey, or purchase records stored in the Customer’s WordPress database.
2.4 The plugin does not transmit Website Data to AttribuLead for telemetry, product analytics, advertising, or reporting.
2.5 The plugin’s default Lead Intelligence setting is Store Email + Name + Company. The Customer is responsible for establishing an appropriate lawful basis, providing any required notice, configuring the plugin’s consent and tracking settings, selecting appropriate retention periods, and responding to requests relating to Website Data.
2.6 The plugin provides functionality intended to help the Customer manage Website Data, including configurable retention, search, anonymisation, deletion, and integration with WordPress personal-data export and erasure tools.
2.7 Where the Customer configures the plugin to synchronise data to a CRM, commerce platform, webhook endpoint, or other third-party service, the transmission occurs from the Customer’s WordPress environment to the service selected by the Customer, using the Customer’s account or credentials. Unless expressly stated otherwise, that provider is the Customer’s own processor or controller and is not an AttribuLead subprocessor.
2.8 The Customer may inspect the distributed GPL source code and AttribuLead’s published Security & Privacy documentation to verify the plugin’s documented outbound communications.
2.9 Accordingly, Article 28 processor obligations do not ordinarily arise in relation to Website Data that remains solely within the Customer’s environment.
3. Support Data: AttribuLead as processor
3.1 Subject matter and duration
AttribuLead may process Personal Data on the Customer’s behalf when the Customer deliberately provides diagnostics, screenshots, exports, database extracts, or other materials for troubleshooting, implementation assistance, or customer support (“Support Data“). Processing continues only for the period reasonably necessary to resolve the support request and for the limited retention period set out in section 9.
3.2 Nature and purpose
The nature of processing may include receiving, viewing, storing, organising, retrieving, analysing, redacting, and deleting Support Data solely to investigate and resolve the Customer’s request, maintain security, or comply with documented instructions and applicable law.
3.3 Types of Personal Data
Depending on what the Customer chooses to submit, Support Data may include:
- Names, business email addresses, company names, and other contact details;
- Visitor or lead identifiers and attribution signals;
- Form-submission details;
- Site URLs, configuration data, diagnostic logs, screenshots, and database excerpts;
- Support correspondence and attachments; and
- Other Personal Data deliberately included by the Customer.
3.4 Categories of data subject
Data subjects may include the Customer’s employees, contractors, authorised users, website visitors, leads, prospects, customers, and other individuals whose information the Customer deliberately includes in a support request.
3.5 Restricted data
AttribuLead does not require or request special-category data, criminal-offence data, government identification numbers, payment-card data, medical information, passwords, authentication secrets, or other highly sensitive data. The Customer must not submit such data unless AttribuLead has expressly agreed in writing that it is necessary and appropriate safeguards have been established.
Support-data minimisation. Customers should avoid including production Personal Data wherever possible and should redact or replace it with test data before submission. AttribuLead may ask the Customer to remove unnecessary data or may delete an attachment that is not required to resolve the request.
4. Processor obligations
When processing Support Data on the Customer’s behalf, AttribuLead shall:
(a) Documented instructions. Process Support Data only on documented instructions from the Customer, including the Agreement, this DPA, the support request, and the Customer’s use of the support service, unless processing is required by law. Where legally permitted, AttribuLead will inform the Customer before processing required by law.
(b) Confidentiality. Ensure that each person authorised to process Support Data is subject to an appropriate duty of confidentiality.
(c) Security. Implement the technical and organisational measures described in Annex II.
(d) Subprocessors. Engage subprocessors for Support Data only in accordance with section 5.
(e) Data-subject requests. Taking into account the nature of processing, assist the Customer with appropriate technical and organisational measures, insofar as reasonably possible, in responding to requests concerning Support Data. AttribuLead will redirect requests concerning Website Data held only by the Customer because AttribuLead cannot fulfil such requests itself.
(f) Compliance assistance. Taking into account the nature of processing and information available to AttribuLead, provide reasonable assistance regarding security, breach response, data-protection impact assessments, and prior consultation obligations applicable to Support Data.
(g) Deletion or return. At the Customer’s choice, delete or return Support Data at the end of the relevant support engagement, except where retention is required by law or reasonably necessary to establish, exercise, or defend legal claims.
(h) Demonstrating compliance. Make available information reasonably necessary to demonstrate compliance with applicable processor obligations and permit audits in accordance with section 8.
(i) Unlawful instructions. Inform the Customer if, in AttribuLead’s reasonable opinion, an instruction infringes applicable Data Protection Law.
(j) No sale or unrelated use. Not sell, rent, or use Support Data for advertising, profiling, data brokerage, or any purpose unrelated to providing the requested support, maintaining security, or complying with law.
5. Subprocessors
5.1 General authorisation. The Customer grants AttribuLead general written authorisation to engage subprocessors for processing covered by this DPA, subject to this section.
5.2 Current list. The current list of subprocessors and relevant service providers is published at attribulead.com/legal/subprocessors/ and forms part of this DPA.
5.3 Relevant Support Data subprocessors. At the date of this DPA, the principal providers that may process Support Data are:
| Subprocessor | Purpose | Data processed | Primary processing location | Transfer safeguard |
|---|---|---|---|---|
| KnownHost | Hosting attribulead.com and supporting account, licensing, and web systems | Support Data deliberately uploaded to AttribuLead-hosted systems; account identifiers; site URLs; server and security logs, which may include IP addresses | United States | Contractual safeguards, including Standard Contractual Clauses where required |
| Help Scout | Receiving, organising, and responding to support requests | Name, email address, support correspondence, attachments, diagnostics, and any other information deliberately included in a support request | United States | Help Scout’s Data Processing Amendment and Standard Contractual Clauses or another valid transfer mechanism where applicable |
5.4 Other service providers. Stripe, Google Analytics, and Umami may process Account Data or data relating to visits to AttribuLead’s own website. Because AttribuLead ordinarily determines the purposes and means of those activities as a controller, those providers are described in the Privacy Policy and public service-provider list rather than treated as subprocessors of Customer Website Data under this DPA.
5.5 No routine access to Website Data. No AttribuLead subprocessor receives Website Data merely because a Customer installs or operates the plugin. A subprocessor receives such data only where the Customer deliberately submits it to AttribuLead or where a separate service expressly states otherwise.
5.6 Changes. AttribuLead will provide at least 30 days’ notice before appointing a new subprocessor that will materially process Support Data or replacing an existing one. Notice may be provided by email, account notice, or an update mechanism offered on the subprocessor page.
5.7 Objections. The Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable resolution is available, the Customer may discontinue the affected support service or terminate the affected paid Service and receive any refund required by the Agreement or applicable law.
5.8 Flow-down and responsibility. AttribuLead will impose data-protection obligations on each subprocessor that are appropriate to the processing and no less protective in substance than the relevant obligations in this DPA. AttribuLead remains responsible for the subprocessor’s processing to the extent required by applicable law.
6. International transfers
6.1 AttribuLead is established in British Columbia, Canada.
6.2 Canada adequacy. Where applicable, transfers from the European Economic Area to AttribuLead may rely on the European Commission’s adequacy decision for Canadian commercial organisations subject to PIPEDA.
6.3 Alternative transfer mechanism. Where an adequacy decision does not apply or is unavailable, the parties agree that the EU Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), are incorporated by reference and completed as described in Annex III.
6.4 UK transfers. Where required for a restricted transfer under the UK GDPR, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses is incorporated by reference and completed consistently with Annex III.
6.5 Swiss transfers. For transfers subject to Swiss data-protection law, references in the incorporated safeguards will be interpreted and adapted as necessary to apply to Switzerland and the competent Swiss authority.
6.6 Onward transfers. Where AttribuLead transfers Support Data to a subprocessor in a country not covered by an applicable adequacy decision, AttribuLead will use a legally recognised transfer mechanism, such as applicable Standard Contractual Clauses, an approved data-transfer framework, or another safeguard permitted by law.
6.7 Customer-directed transfers. Transfers performed directly by the Customer’s WordPress site to the Customer’s selected hosting provider, CRM, commerce platform, webhook destination, or other integration are controlled by the Customer and are not transfers by AttribuLead.
7. Personal data breach
7.1 AttribuLead will notify the Customer without undue delay and, where reasonably practicable, within 48 hours after becoming aware of a Personal Data Breach affecting Support Data processed under this DPA.
7.2 The notification will describe, to the extent known at the time:
- the nature of the breach;
- the categories and approximate number of affected data subjects and records;
- the likely consequences;
- the measures taken or proposed to address and mitigate the breach; and
- a contact point for further information.
7.3 AttribuLead may provide information in phases as it becomes available and will cooperate reasonably with the Customer’s investigation and response.
7.4 Website Data incidents. A breach confined to the Customer’s WordPress site, database, hosting environment, CRM, or other Customer-controlled integration is the Customer’s incident to assess and report. AttribuLead does not monitor or have visibility into those systems. On request, AttribuLead may provide reasonable product information to assist the Customer.
8. Audit and compliance information
8.1 AttribuLead will make available information reasonably necessary to demonstrate compliance with this DPA. This may include the DPA, Privacy Policy, Security & Privacy documentation, subprocessor list, responses to a reasonable security questionnaire, and other relevant written materials.
8.2 The Customer may conduct an audit of processing covered by this DPA on at least 30 days’ written notice, no more than once in any 12-month period, unless a more frequent audit is required by a supervisory authority or reasonably justified by a confirmed breach affecting the Customer’s Support Data.
8.3 Audits must be proportionate, conducted during normal business hours, avoid access to information relating to other customers, preserve confidentiality and security, and not unreasonably disrupt AttribuLead’s operations.
8.4 The parties agree that review of current documentation and responses to a reasonable questionnaire will ordinarily be the first method used to satisfy audit requirements. An on-site or third-party audit may be considered where the documentation is materially insufficient and the Customer has reasonable grounds for further verification.
8.5 The Customer bears its audit costs. AttribuLead may charge reasonable fees for assistance that is unusually extensive or repetitive, unless the audit identifies a material breach of this DPA by AttribuLead.
8.6 An audit of AttribuLead is not a meaningful method of auditing Website Data that has never been supplied to AttribuLead. The Customer may inspect the plugin’s source code and its own infrastructure to verify the data flows described in section 2.
9. Retention and deletion
9.1 Support Data. AttribuLead will delete Support Data within 90 days after the related support request is closed or no longer reasonably active, unless:
- the Customer requests earlier deletion;
- a shorter period is agreed;
- the material is reasonably necessary to address an ongoing security or legal matter; or
- retention is required by law.
9.2 Account Data. Account Data is retained under the periods described in the Privacy Policy. Following termination, AttribuLead will delete or anonymise Account Data that is no longer required within 90 days, subject to legal, tax, accounting, fraud-prevention, dispute-resolution, and backup-retention requirements.
9.3 Financial records. Purchase, invoice, tax, and accounting records may be retained for at least 7 years where required for Canadian tax and business-record obligations.
9.4 Backups. Data deleted from active systems may remain temporarily in secure backups until overwritten through the ordinary backup cycle. Backups are retained for up to 90 days and are not restored except for disaster recovery, security, or continuity purposes.
9.5 Website Data. AttribuLead takes no deletion action for Website Data that remains solely in the Customer’s environment. The Customer controls that data through the plugin’s retention settings, deletion tools, WordPress tools, database administration, and any applicable uninstall options.
10. Controller obligations
The Customer shall:
- comply with applicable Data Protection Law in its collection and use of Website Data and Support Data;
- have a valid lawful basis and provide any required privacy notices;
- submit only Personal Data that is relevant and reasonably necessary for support;
- avoid submitting restricted or highly sensitive data;
- ensure that its instructions are lawful;
- configure consent, Lead Intelligence, integrations, and retention settings appropriately for its circumstances; and
- maintain appropriate security for its WordPress site, hosting, administrator accounts, databases, and third-party integrations.
11. Liability
The liability of each party arising from or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent such limitation is prohibited by applicable law or conflicts with incorporated Standard Contractual Clauses.
12. Order of precedence
In the event of a conflict relating to processing covered by this DPA, the order of precedence is:
- any incorporated Standard Contractual Clauses or mandatory transfer addendum;
- this DPA;
- the Agreement; and
- other incorporated policies.
13. Term and amendment
13.1 This DPA takes effect when the Agreement takes effect or when AttribuLead first processes Personal Data on the Customer’s behalf, whichever occurs first.
13.2 It continues until AttribuLead ceases all processing covered by this DPA.
13.3 AttribuLead may update this DPA where reasonably necessary to reflect legal, regulatory, security, or service changes. Material changes will be communicated through an appropriate notice mechanism. Changes will not materially reduce the protection of Support Data during an active paid term without a valid legal or operational reason.
14. Contact
Questions concerning this DPA or AttribuLead’s privacy practices may be sent to:
AttribuLead Privacy Contact
British Columbia, Canada
Email: privacy@attribulead.com
Signatures
This DPA may be accepted electronically, incorporated into the Agreement by reference, or signed below.
| AttribuLead A sole proprietorship operating in British Columbia, Canada Name: ____________________________________ Title: Proprietor Date: _____________________________________ Signature: _________________________________ |
Customer
Legal name: ________________________________ Name: ____________________________________ Title: _____________________________________ Date: _____________________________________ Signature: _________________________________ |
Annex I — Description of processing
A. List of parties
Data exporter / Controller: The Customer identified in the Agreement or signature block.
Data importer / Processor: AttribuLead, a sole proprietorship operating in British Columbia, Canada; website: https://www.attribulead.com/; privacy contact: privacy@attribulead.com.
B. Description of transfer and processing
| Item | Detail |
|---|---|
| Categories of data subject | The Customer’s employees, contractors, authorised users, website visitors, leads, prospects, customers, and other individuals whose data the Customer deliberately supplies for support |
| Categories of Personal Data | Names; contact information; company information; visitor or lead identifiers; attribution information; form data; site URLs; configuration data; diagnostic logs; screenshots; database excerpts; support correspondence; and attachments submitted by the Customer |
| Sensitive or special-category data | Not required or authorised as part of the ordinary service. The Customer must not submit such data unless expressly agreed in writing and legally permitted. |
| Frequency | Occasional, when the Customer deliberately submits Personal Data for support |
| Nature of processing | Receipt, storage, review, organisation, retrieval, analysis, redaction, communication, and deletion for support and security purposes |
| Purpose | Investigating and resolving support, implementation, compatibility, security, or troubleshooting requests |
| Duration and retention | For the period necessary to resolve the request, followed by deletion within 90 days, subject to section 9 |
| Subprocessors | As described in section 5 and at /legal/subprocessors/ |
C. Competent supervisory authority
Where the EU Standard Contractual Clauses apply, the competent supervisory authority will be determined in accordance with Clause 13 of those clauses. Where the Customer is established in the EEA, this will ordinarily be the supervisory authority of the Customer’s EEA establishment. Where the Customer is not established in the EEA but is subject to the EU GDPR, the authority will be determined under the applicable GDPR rules.
Annex II — Technical and organisational measures
The following measures apply to systems used by AttribuLead to process Account Data and Support Data, as relevant to the service and risk:
Access control
- Access to production, hosting, licensing, and support systems is limited to persons who require it for their role.
- Administrative accounts use unique credentials and multi-factor authentication where supported.
- Shared administrator credentials are avoided.
- Access is reviewed when responsibilities change or access is no longer required.
- Help Scout access is limited to authorised support personnel.
Encryption and transmission security
- TLS/HTTPS is used for connections to attribulead.com and supported service interfaces.
- Support and account systems use encryption at rest where provided by the applicable hosting or SaaS provider.
- Full payment-card details are handled by Stripe and are not stored in AttribuLead’s own systems.
- Customers are instructed not to include passwords, API secrets, payment-card data, or similarly sensitive material in support requests.
Availability, backup, and recovery
- Automated backups are maintained for relevant AttribuLead-hosted account and licensing systems.
- Backups are retained for up to 90 days.
- Restore procedures are documented and are tested periodically and following material infrastructure changes where appropriate.
- Backups are used for disaster recovery and business continuity, not for routine access to deleted data.
Logging and operational security
- Security, access, and server logs may be maintained to detect abuse, troubleshoot incidents, and protect systems.
- Software, WordPress components, and server components are updated as reasonably appropriate to address known security risks.
- Security incidents are investigated and documented in proportion to their severity.
- Providers are selected with regard to security, privacy, reliability, and contractual protections.
Data minimisation and retention
- Customers are instructed to redact Personal Data from support materials wherever possible.
- Support Data is used only for the relevant support or security purpose.
- Support Data is deleted under the retention periods in section 9.
- AttribuLead does not use Support Data for advertising, data brokerage, or unrelated analytics.
Organisational measures
- Persons with access to Personal Data are subject to confidentiality obligations.
- Privacy and security considerations are incorporated into product and service design.
- Subprocessors are subject to appropriate written data-protection and confidentiality obligations.
- Documented procedures are maintained for access requests, deletion requests, and incident response as appropriate to the scale of operations.
Product security measures
The following measures are features of the self-hosted plugin that help the Customer protect Website Data in the Customer’s own environment. They do not mean that AttribuLead remotely operates or accesses that environment:
- Capability-gated administrative screens using appropriate WordPress permissions.
- Nonce protection for state-changing administrative actions.
- Prepared database queries, input sanitisation, validation, and output escaping.
- Rate limiting and abuse controls on public-facing endpoints.
- No ordinary persistent storage of raw visitor IP addresses or browser user-agent strings in plugin reporting tables.
- No browser fingerprinting or cross-site identity graph.
- Bot and crawler filtering and duplicate-conversion controls.
- Configurable retention, scheduled purging, anonymisation, deletion, and WordPress export/erasure integration.
Credential security. CRM credentials entered into supported plugin settings are encrypted at rest using authenticated encryption and WordPress-derived or dedicated key material, subject to the plugin version and integration. The plugin is designed to fail closed rather than knowingly fall back to plaintext storage where required key material is unavailable.
Annex III — International transfer details
Where the EU Standard Contractual Clauses are required, they are completed as follows:
| SCC item | Selection or detail |
|---|---|
| Module | Module Two: Controller to Processor |
| Docking clause | Clause 7 applies |
| Subprocessor authorisation | Option 2, general written authorisation, with 30 days’ advance notice |
| Redress | Clause 11 optional language does not apply unless the parties expressly agree otherwise |
| Supervision | As described in Annex I.C and determined under Clause 13 |
| Governing law | The law of an EU Member State that permits third-party beneficiary rights under the SCCs, selected based on the Customer’s establishment or, where necessary, Ireland |
| Courts | The courts corresponding to the governing law selected above |
| Annex I parties and processing | The information in Annex I of this DPA |
| Annex II measures | The technical and organisational measures in Annex II of this DPA |
| Annex III subprocessors | The subprocessors identified in section 5 and on AttribuLead’s current subprocessor page |
For a UK restricted transfer, references and selections above apply together with the mandatory tables and provisions of the UK International Data Transfer Addendum, with AttribuLead as importer and the Customer as exporter.
This document is intended to describe AttribuLead’s actual product and support data flows. It should be reviewed by qualified legal counsel before being relied upon for a specific regulatory, contractual, or enterprise procurement requirement.