Data Processing Agreement
Service: SalesCentral (sales-central.org) Provider / Processor: SalesCentral, Republic of Armenia Last updated: 30 June 2026
This DPA is incorporated into and forms part of the Terms of Service (the "Agreement") between SalesCentral (the "Processor") and the Developer (the "Controller", "you"). It governs Processor's processing of personal data on Controller's behalf. If there is a conflict on data-protection matters, this DPA prevails over the rest of the Agreement.
In this DPA, "Data Protection Law" means all laws applicable to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the Republic of Armenia Law on the Protection of Personal Data (No. HO-49-N), and the California Consumer Privacy Act as amended (CCPA/CPRA); and "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in the GDPR.
1. Roles
- For End-User personal data submitted through the service, you are the Controller and SalesCentral is the Processor. Under the CCPA/CPRA, SalesCentral acts as a service provider.
- SalesCentral may act as an independent controller for limited data it processes for its own purposes — for example operator-account data, billing, and security/audit logging — as described in the Privacy Policy. This DPA governs only the processing where SalesCentral is your Processor.
2. Scope and instructions
- SalesCentral will process End-User personal data only on your documented instructions, including those set out in this DPA and the Agreement and as given through your configuration and use of the service, unless required to act by applicable law (in which case it will inform you unless legally prohibited).
- Your use of the service is your instruction to process Customer Data to provide, secure, maintain, and support the service.
- SalesCentral will inform you if, in its opinion, an instruction infringes Data Protection Law.
- SalesCentral will not sell or share (as defined by CCPA/CPRA) End-User personal data, and will not retain, use, or disclose it for any purpose other than performing the service or as permitted by Data Protection Law.
3. Details of processing
The subject matter, duration, nature and purpose of processing, the categories of data subjects, and the categories of personal data are set out in Annex A.
4. Confidentiality
SalesCentral ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and access it only as needed to perform their duties.
5. Security
SalesCentral implements appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs of implementation, and the risk to data subjects, as described in Annex B (consistent with GDPR Article 32).
6. Sub-processing
- You give SalesCentral general authorisation to engage sub-processors to process personal data. The current sub-processors are listed at Subprocessors.
- SalesCentral imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.
- SalesCentral will give you reasonable prior notice of any intended addition or replacement of a sub-processor (for example by updating the Subprocessors page and/or notifying you), giving you the opportunity to object on reasonable data-protection grounds. We will give at least 30 days' notice (by updating the Subprocessors page and/or emailing your account contact). If you object on reasonable grounds within that period, we will work with you in good faith to address it; if we cannot, you may terminate the affected part of the service.
7. Assistance to the Controller
Taking into account the nature of the processing, SalesCentral will:
- assist you, by appropriate technical and organisational measures and insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection); the service's admin panel and APIs let you access, export, correct, and delete End-User data directly;
- assist you in ensuring compliance with your obligations on security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities (GDPR Articles 32–36).
8. Personal data breaches
SalesCentral will notify you without undue delay after becoming aware of a personal data breach affecting End-User personal data, and will provide the information reasonably available to help you meet your own notification obligations, and reasonable cooperation to investigate and remediate. Notices go to your account contact; report suspected incidents to [email protected].
9. Return and deletion
On termination or expiry of the Agreement, or earlier on your written request, SalesCentral will, at your choice, delete or return End-User personal data and delete existing copies, unless retention is required by law. The service supports export via the admin panel and API, and uses soft-deletion followed by purging. Export remains available for 30 days after termination; we then delete End-User personal data within 90 days and purge it from backups within a further 35 days.
10. Audits
SalesCentral will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, security, frequency, and notice conditions. SalesCentral may satisfy audit requests by providing relevant documentation or third-party reports where available.
11. International transfers
SalesCentral processes data in the Republic of Armenia and uses sub-processors located in other countries, including the United States. Where this DPA covers transfers of EU/EEA, UK, or Swiss personal data to a country without an adequacy decision, the parties agree that:
- the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor, and Module Three for onward transfers) are incorporated by reference and completed by the information in the Annexes;
- the UK International Data Transfer Addendum (or IDTA) applies to UK personal data; and
- SalesCentral will assist with any transfer-impact assessment reasonably required.
Armenia is a party to Council of Europe Convention 108/108+ and recognises EU/EEA states as providing adequate protection.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
13. Term
This DPA takes effect when you accept the Agreement and continues until SalesCentral has ceased all processing of End-User personal data on your behalf.
Annex A — Details of processing
- Subject matter: provision of the SalesCentral backend service to the Controller.
- Duration: the term of the Agreement, plus any return/deletion period.
- Nature and purpose: verifying Apple in-app purchase receipts and notifications; maintaining premium, entitlement, and credit state; delivering push notifications the Controller triggers; providing analytics, paywall, experiment, and configuration features; and securing and supporting the service.
- Categories of data subjects: the Controller's End Users (users of the Controller's iOS Apps).
- Categories of personal data:
- online and device identifiers (service-generated user IDs, client-generated IDs, IDFV, IDFA where ATT-authorised, push tokens, Apple transaction IDs);
- device and technical data (model, OS, screen, memory, app version, SDK version, storefront);
- locale data (language, region, time zone, currency);
- approximate location derived from IP address (country, and where available region/city), and connection/carrier data;
- marketing/attribution data (ATT status, attribution source, campaign, UTM parameters);
- usage and engagement data (sessions, custom events and properties, experiment assignments);
- commerce data (purchases, subscriptions, credits, refunds, lifetime totals);
- any contact or profile data the Controller chooses to send as user properties (which may include name or email if the Controller sends them).
- Special categories of personal data: none requested or required; the Controller must not submit special-category data through the service.
- Frequency: continuous, for the duration of the Agreement.
Annex B — Technical and organisational measures
SalesCentral maintains measures including, as applicable to its current deployment:
- Encryption in transit: TLS for traffic to the service (terminated at the CDN edge).
- Access control: authenticated admin access with role-based permissions; per-App API keys and per-endpoint tokens that scope each App's access to its own data; separated signing secrets for end-user and admin tokens; hashed operator passwords.
- Network isolation: the database is not exposed to the public network; only the reverse proxy is reachable externally.
- Integrity controls: idempotency and deduplication on purchase and notification processing; signature verification of Apple notifications; soft-deletion followed by purge for deletions.
- Logging and monitoring: request and audit logging, retained for up to 90 days, with access limited to authorised personnel.
- Data-at-rest protection: personal data and uploaded Apple credentials are held in the database on access-controlled, network-isolated servers reachable only by the application service, with access limited to authorised personnel on a least-privilege basis.
- Resilience: regular database backups and documented recovery procedures to restore the service after a failure.
- Organisational: confidentiality obligations on personnel, least-privilege access, and a vulnerability-reporting channel (
[email protected]).
Annex C — Sub-processors
The list of authorised sub-processors is maintained at Subprocessors and incorporated here by reference.