Data Processing Agreement

Last updated: May 18, 2026

This Data Processing Agreement ("DPA") is incorporated into and forms part of the Pierview Terms of Service between Pierview, Inc. ("Pierview", "Processor") and the customer entity that has agreed to those terms ("Customer", "Controller"). This DPA applies where and to the extent that Pierview processes Personal Data on behalf of Customer in connection with the Pierview platform and services.

1. Roles and Processing Instructions

The parties acknowledge that Customer is the Controller and Pierview is the Processor with respect to Personal Data processed under the Agreement. Pierview shall process Personal Data only on documented instructions from Customer, including as set forth in this DPA and the Agreement, unless required to do so by applicable law.

If Pierview is required by law to process Personal Data for a purpose other than those set forth in this DPA, Pierview shall inform Customer of that requirement before processing unless prohibited by law.

Permitted Purposes

Pierview is authorized to process Personal Data solely for the following purposes:

  • Providing and maintaining the Pierview analytics platform and services
  • Detecting and reporting AI agent visits to Customer's website
  • Processing website visitor analytics data collected via Customer's installed tracking script
  • Integrating with third-party services authorized by Customer (e.g., Google Search Console, Vercel)
  • Providing customer support and responding to Customer requests
  • Complying with legal obligations

2. Confidentiality of Processing

Pierview shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Pierview shall ensure that access to Personal Data is limited to those personnel who require access for the purposes set out in this DPA.

3. Security Measures

Pierview shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Pierview will encrypt Customer Personal Data in accordance with industry accepted standards, strong encryption techniques, and current security protocols
  • Role-based access controls limiting data access to authorized personnel only
  • Regular security reviews, vulnerability assessments, and updates
  • Logical isolation of Customer data
  • Access logging and monitoring for systems handling Personal Data

Security Incident Notification

In the event of a Personal Data breach, Pierview shall notify Customer without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. The notification shall include: (a) the nature of the breach; (b) the categories and approximate number of Data Subjects and records concerned; (c) likely consequences of the breach; and (d) measures taken or proposed to address the breach.

4. California Consumer Privacy Act (CCPA)

To the extent the CCPA applies, Pierview is a "service provider" as defined by the CCPA. Pierview shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than providing the services specified in the Agreement; (c) retain, use, or disclose Personal Data outside of the direct business relationship with Customer; or (d) combine Personal Data received from Customer with Personal Data received from other sources, except as permitted by the CCPA. Pierview certifies that it understands and will comply with these restrictions.

5. Subprocessors

Customer grants Pierview a general written authorization to engage Subprocessors. Pierview shall inform Customer of any intended changes to its list of Subprocessors by providing at least 30 days' prior notice, giving Customer the opportunity to object. Pierview shall impose data protection obligations on each Subprocessor equivalent to those in this DPA.

Current Subprocessors:

SubprocessorPurposeLocation
ClerkAuthentication and user identity managementUnited States
StripePayment processingUnited States
NeonPostgreSQL database hostingUnited States
VercelApplication hosting and edge infrastructureUnited States
OpenAIAI model provider for visibility analysisUnited States
AnthropicAI model provider for visibility analysisUnited States
GoogleAI model provider and Search Console integrationUnited States

6. Data Subject Rights

Pierview shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise any rights under applicable Data Protection Laws. Pierview shall not respond to Data Subject requests directly unless authorized by Customer or required by law. Pierview shall provide Customer with reasonable assistance to fulfill its obligations to respond to Data Subject requests, including requests for access, rectification, erasure, restriction, portability, and objection.

7. Assistance to Customer

Taking into account the nature of processing and information available to Pierview, Pierview shall provide reasonable assistance to Customer in ensuring compliance with Customer's obligations under applicable Data Protection Laws, including with respect to:

  • Data protection impact assessments
  • Prior consultation with supervisory authorities
  • Security of processing
  • Notification of Personal Data breaches

8. Audits and Inspections

Upon Customer's reasonable written request, Pierview will permit Customer, at Customer's expense, to audit Pierview's applicable controls and compliance with this DPA (an "Audit"), provided such Audit is: (a) conducted by Customer or a third-party auditor designated by Customer that has executed an appropriate non-disclosure agreement with Pierview; (b) Customer and Pierview mutually agree on reasonable details of the Audit, including the start date, scope and duration of, and security and confidentiality controls applicable to, such Audit; and (c) a similar Audit has not already been conducted less than twelve (12) months prior, unless it is required by a supervisory authority or other regulatory authority responsible for the enforcement of applicable Data Protection Laws. Customer will pay all costs and expenses incurred by Pierview in connection with any such Audit. Customer may use the results of an Audit only for the purposes of meeting Customer's regulatory audit requirements and confirming compliance with the requirements of this DPA.

9. Deletion and Return of Data

Upon termination of the Agreement or upon Customer's written request, Pierview shall delete or return all Personal Data processed on Customer's behalf, and delete existing copies, unless applicable law requires storage of the Personal Data. Pierview shall certify in writing to Customer upon request that it has complied with this obligation.

Contact

Questions regarding this Data Processing Agreement should be directed to support@pierview.ai.