Effective Date: 29 October 2025
Last Updated: 26 July 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Service between VALUESHIPS Sp. z o.o., with its registered office at ul. Wielka 67, 53-340 Wrocław, Poland, registered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for Wroclaw-Fabryczna in Wroclaw, VI Commercial Division of the National Court Register, under number KRS 0000870565, tax identification number NIP PL8943161057, statistical number REGON 387572179, operating the Revenue Plumber service (the "Processor", "we" or "us"), and the customer accepting those Terms (the "Controller", "you"), together the "Parties".
By accepting the Terms of Service you accept this DPA. Where the Parties have entered into a separately executed data processing agreement, that agreement prevails over this DPA to the extent of any inconsistency.
1.1. Under this DPA we process personal data provided by you, or by third-party systems you connect, for the purpose of providing the Revenue Plumber service (the "Service").
1.2. This DPA is made to satisfy Article 28 of Regulation (EU) 2016/679 ("GDPR"). Terms used here have the meaning given to them in the GDPR unless defined otherwise.
1.3. In respect of personal data processed under this DPA you are the controller within the meaning of Art. 4(7) GDPR and we are the processor within the meaning of Art. 28 GDPR. You alone determine the purposes and means of the processing.
1.4. Where you are yourself a processor acting on behalf of a third-party controller, you warrant that you are authorised to engage us as a sub-processor, and this DPA applies to us as sub-processor with references to "controller" construed accordingly.
1.5. The subject matter, nature and purpose of the processing, the duration, the categories of personal data and the categories of data subjects are set out in Schedule 1.
1.6. You represent and warrant that you have a lawful basis under Art. 6 GDPR for the processing you instruct us to carry out, that you have obtained any consents required from data subjects, and that you have provided any information required under Art. 13 and 14 GDPR. You are responsible for the lawfulness of your instructions.
1.7. We do not use personal data processed on your behalf to train, fine-tune or otherwise develop machine learning models, whether our own or those of any sub-processor. Where AI features are provided through a sub-processor, we contract on terms that exclude the use of your data for model training.
1.8. We may create aggregated statistical information derived from the processing, for the purposes of operating, securing and improving the Service and of publishing industry benchmarks. Such information is irreversibly anonymised before use, contains no identifier of you, of your end customers or of any individual, and cannot by reasonable means be attributed to you or to any data subject. Once anonymised it is no longer personal data and its use falls outside this DPA. We will not publish or disclose aggregated information in a form that permits you or your end customers to be identified, including by inference from small sample sizes.
2.1. You grant us general authorisation to engage sub-processors. The sub-processors engaged as at the date you accept this DPA are listed in Schedule 2 and are approved by you on acceptance.
2.2. We will notify you at least fourteen (14) days in advance of the addition or replacement of a sub-processor, by email to the address associated with your account. If you do not object within fourteen (14) days of notification, the sub-processor is deemed approved.
2.3. If you object on reasonable data protection grounds and we nonetheless proceed with engaging that sub-processor, you may terminate this DPA and the Service by written notice within thirty (30) days of our notification, without penalty and with a pro-rata refund of prepaid fees. You will not object unreasonably.
2.4. We will enter into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each sub-processor's obligations.
2.5. Where you connect a third-party application or service through the Service interface, that act constitutes both your documented instruction to transfer personal data to and receive personal data from that system, and your authorisation of the provider of that system for the purposes of this Section 2. You may withdraw that instruction and authorisation at any time by disconnecting the integration. Section 2.2 does not apply to providers authorised in this way, because the authorisation arises from your own configuration rather than from our engagement of the provider.
2.6. In respect of any sub-processor established outside the European Economic Area, you authorise us to conclude standard contractual clauses adopted by the European Commission with that sub-processor in your name and on your behalf, and to accept on your behalf standard contractual clauses incorporated into that sub-processor's terms.
2.7. The current list of sub-processors is maintained in Schedule 2 to this DPA. Schedule 2 is updated whenever a sub-processor is added, replaced or removed.
3.1. We process personal data only on your documented instructions, including in relation to transfers of personal data to a third country or an international organisation.
3.2. This DPA, together with its Schedules, the Terms of Service and your configuration of the Service, constitutes your documented instructions.
3.3. Your instructions may be updated, including through your configuration of the Service.
3.4. We take steps to ensure that any natural person acting under our authority who has access to personal data processes it only on your instructions, unless required to do otherwise by applicable law.
3.5. We will inform you without undue delay if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. We may suspend performance of the instruction until it is confirmed or withdrawn.
3.6. Where personal data is transferred outside the European Economic Area, the transfer is made on the basis of an adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the recipient is certified under it, or on the basis of standard contractual clauses. The transfer mechanism applicable to each sub-processor is stated in Schedule 2.
4.1. We will not disclose personal data processed on your behalf to any third party except as permitted by this DPA, on your instructions, or where required by applicable law. Where disclosure is required by law, we will inform you in advance unless prohibited from doing so.
4.2. We ensure that persons authorised to process personal data on our behalf are bound by an obligation of confidentiality, whether contractual or statutory.
4.3. The obligations in this Section 4 survive the expiry or termination of this DPA without limitation in time.
5.1. We implement appropriate technical and organisational measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures in place as at the date of this DPA are described in Schedule 1.
5.2. We may update those measures, provided that no update reduces the overall level of security.
6.1. We assist you, by appropriate technical and organisational measures and insofar as commercially reasonable, in responding to requests from data subjects exercising their rights under Chapter III GDPR.
6.2. Where we receive a request directly from a data subject in relation to personal data processed on your behalf, we will not respond to it substantively, and will forward it to you without undue delay, unless applicable law requires otherwise.
6.3. The Service provides functionality allowing you to access, correct, export and delete personal data processed on your behalf. Where a request can be satisfied through that functionality, our assistance under Section 6.1 consists of making that functionality available.
7.1. We will notify you of any personal data breach affecting personal data processed on your behalf without undue delay, and in any event within forty-eight (48) hours of becoming aware of it.
7.2. The notification will describe, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not available at once, we will provide it in phases without undue delay.
7.3. We assist you, insofar as commercially reasonable and taking into account the nature of the processing and the information available to us, in complying with your obligations under Art. 32 to 36 GDPR, including data protection impact assessments and prior consultation with the supervisory authority.
7.4. Notification under this Section is not an acknowledgement of fault or liability.
8.1. On expiry or termination of the Service, we will, at your choice, delete or return all personal data processed on your behalf, and delete existing copies, within thirty (30) days of the date of expiry or termination.
8.2. You may exercise the choice under Section 8.1 by written notice before the end of that period. If you do not, we will delete the data.
8.3. Where copies of personal data exist in platform-level storage snapshots maintained by our hosting provider, they are deleted in accordance with that provider's retention cycle and in any event within thirty (30) days of termination.
8.4. Section 8.1 does not apply to personal data we are required to retain by applicable law, which we will retain only for as long as that requirement applies and only for that purpose.
8.5. We will confirm deletion in writing at your request.
9.1. We make available to you the information reasonably necessary to demonstrate compliance with our obligations under this DPA.
9.2. We allow for and contribute to audits, including inspections, conducted by you or an auditor appointed by you, subject to: at least thirty (30) days' prior written notice; no more than one audit in any twelve (12) month period, except where required by a supervisory authority or following a personal data breach; conduct during normal business hours in a manner that does not unreasonably disrupt our operations; and the auditor being bound by confidentiality obligations.
9.3. We may satisfy our obligations under this Section by providing documentation of our technical and organisational measures, responses to a security questionnaire, or a report from an independent third party, where that reasonably addresses the scope of the proposed audit.
9.4. Where an audit exceeds the scope described in Section 9.2, we may charge our reasonable costs of supporting it, notified to you in advance.
10.1. Each Party is responsible for compliance with the obligations applicable to it in its respective role under the GDPR.
10.2. You are responsible for the lawfulness of the instructions, requests and configuration you issue to us, and for the accuracy of the personal data you provide or make available to us.
10.3. We remain liable to you for the acts and omissions of our sub-processors as for our own.
10.4. Each Party will notify the other without undue delay of any administrative or court proceedings, supervisory authority inspection, or decision concerning the processing of personal data under this DPA, and the Parties will cooperate in responding to any claim brought by a data subject or third party.
10.5. Nothing in this DPA or in the Terms of Service limits or excludes either Party's liability under Art. 82 GDPR towards a data subject, or any liability that cannot be limited or excluded under applicable law.
11.1. This DPA takes effect on the date you accept the Terms of Service and remains in force for as long as we process personal data on your behalf.
11.2. Provisions which by their nature are intended to survive, including Sections 4, 8 and 10, survive termination.
11.3. Either Party may terminate this DPA with immediate effect in the event of a material breach of it by the other Party which is not remedied within thirty (30) days of written notice.
12.1. This DPA is governed by the laws of the Republic of Poland.
12.2. Disputes arising out of or in connection with this DPA are subject to the exclusive jurisdiction of the court having jurisdiction over the registered office of the Processor.
13.1. If any provision of this DPA is or becomes invalid or unenforceable, the remaining provisions remain in force and the invalid provision is replaced by a valid provision achieving as closely as possible the same commercial effect.
13.2. In the event of a conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails.
13.3. Neither Party may assign its rights or obligations under this DPA without the other Party's prior written consent, except to an affiliate or in connection with a merger, acquisition or sale of all or substantially all of its assets.
13.4. We may amend this DPA where required to reflect a change in applicable law, guidance from a supervisory authority, or a change in the Service. We will notify you of any material amendment at least thirty (30) days in advance, and Section 2.3 applies by analogy to your right to object.
13.5. This DPA is concluded in electronic form in accordance with Art. 28(9) GDPR. Your acceptance of the Terms of Service constitutes conclusion of this DPA in writing for that purpose.
13.6. The Schedules form an integral part of this DPA.
Subject matter: provision of the Revenue Plumber service, comprising ingestion of subscription, billing, CRM and product usage data, computation of retention and churn analytics, generation of insights and content through AI features, and delivery of notifications and customer communications.
Nature of the processing: collection, structuring, storage, retrieval, analysis, use, disclosure by transmission to systems connected by the Controller, and erasure.
Purpose: performing the Service in accordance with the Terms of Service and the Controller's configuration and instructions.
Duration: for the term of the Controller's subscription to the Service, and thereafter until deletion or return in accordance with Section 8.
Categories of personal data:
Categories of data subjects:
Technical and organisational measures:
The table below lists the third parties involved in processing personal data where Revenue Plumber acts as a data processor on behalf of a customer under a Data Processing Agreement. Service providers we engage as a controller of our own data, for example for our website, billing, invoicing and internal analytics, are listed in our Privacy Policy instead.
| No. | Details of the entity (sub-processor) | Place of processing | Scope and purpose of processing | Start date of sub-processing |
|---|---|---|---|---|
| 1. | Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland | EU Ireland / USA | Billing data integration | From the date of acceptance of the Terms of Service |
| 2. | Chargebee Inc., 909 Rose Avenue, Suite 610, North Bethesda, MD 20852, USA | EU Germany | Billing data integration | From the date of acceptance of the Terms of Service |
| 3. | HubSpot Ireland Limited, HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, D02 CR67, Ireland (CRO 515723) | USA / EU Germany | CRM integration | From the date of acceptance of the Terms of Service |
| 4. | SFDC Ireland Limited, Salesforce Tower, North Dock, Dublin 1, D01 W2Y3, Ireland (CRO 394272) | EU Ireland | CRM integration | From the date of acceptance of the Terms of Service |
| 5. | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (CRO 368047) | USA / EU Ireland | Sending email to end customers via Gmail | From the date of acceptance of the Terms of Service |
| 6. | Slack Technologies Limited, Salesforce Tower, 60 R801, North Dock, Dublin 1, D01 W2Y3, Ireland (CRO 558379) | USA / EU Ireland | Delivering notifications to the customer's workspace | From the date of acceptance of the Terms of Service |
| 7. | Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, Ireland (CRO 760497) | USA | AI features: AI agent, data analysis and content generation | From the date of acceptance of the Terms of Service |
| 8. | Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA | EU Netherlands | Hosting of application infrastructure and databases | From the date of acceptance of the Terms of Service |
| 9. | PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA | EU Germany | Product and behavioural analytics | From the date of acceptance of the Terms of Service |
Entries 1 to 6 are integrations that the Controller connects through the Service interface. As set out in Section 2.5, those providers are authorised by the Controller's own act of connecting the integration, and the region in which each of them processes data is determined by the Controller's account configuration. Entries 7 to 9 are engaged by Revenue Plumber on its own account.
Where a provider is listed as processing data in the European Economic Area but has personnel outside it, remote administrative access by that personnel constitutes a transfer, covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses under the relevant provider's data processing agreement.
Transfer mechanism applicable to all providers listed above: Standard contractual clauses (Commission Implementing Decision (EU) 2021/914) as incorporated into the provider's data processing agreement. Where the provider is certified under the EU-US Data Privacy Framework, that adequacy decision applies in addition.
Have any questionss?
Contact Support