Data Processing Addendum
How Coeff IQ processes personal data as a processor on behalf of customers, and how to request an executable DPA.
Last updated: September 8, 2026
This page is informational.
It summarizes how Coefficients Co Ltd processes personal data on behalf of customers when providing Coeff IQ. A Data Processing Addendum ("DPA") becomes binding only when it is separately executed by Coefficients Co Ltd and the customer, or expressly incorporated into a signed agreement. Viewing this page does not put a DPA in place. Eligible customers can request an executable DPA at legal@coeffiq.com or privacy@coeffiq.com.
Roles of the Parties
For personal data contained in the data a customer connects to or generates within a workspace ("Customer Personal Data"), the customer is the controller (or processor acting for its own customers) and Coefficients Co Ltd is the processor (or, under some laws, the service provider). Coefficients Co Ltd processes Customer Personal Data only to provide, secure, and support the Service, and on the customer's documented instructions. For the account, billing, and website data Coefficients Co Ltd handles for its own purposes, Coefficients Co Ltd is the controller and the Privacy Policy applies.
Details of Processing
- Subject matter and purpose: provision of the Coeff IQ analytics platform — retrieving, storing, organizing, analyzing, and displaying connected data, and generating reports and exports at the customer's request.
- Duration: for the term of the customer's subscription, plus the deletion periods described in Return and Deletion of Data.
- Nature of processing: collection, storage, structuring, analysis, retrieval, transmission to subprocessors, and deletion, by automated means.
- Categories of data subjects: the customer's personnel and authorized users, its own clients and their personnel, and individuals represented in the aggregated analytics the customer connects (for example, website visitors, ad audiences, and social followers), as determined by the customer.
- Categories of personal data: account and contact details of users; and, within Customer Data, primarily aggregated and statistical metrics. It is not designed for, and customers are instructed not to submit, special categories of personal data or government identifiers.
Customer Instructions
Coefficients Co Ltd processes Customer Personal Data only on the customer's documented instructions, including as set out in the Terms of Service, this summary, an executed DPA, and the customer's configuration and use of the Service. Coefficients Co Ltd will inform the customer if it believes an instruction infringes applicable data-protection law, and may suspend processing that would place it in violation of law.
Confidentiality of Personnel
Coefficients Co Ltd ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and are granted access on a need-to-know basis under least-privilege controls.
Technical and Organizational Measures
Coefficients Co Ltd maintains measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and AES-256 encryption of stored integration credentials.
- Multi-tenant isolation enforced at both the application layer and the database layer (PostgreSQL row-level security), with least-privilege runtime database roles.
- Role-based access control within the Service and for administrative access to production systems.
- Hashed password storage, rate limiting, and failed-login lockout.
- Logging of significant account activity and production access, with redaction of sensitive values.
- Encrypted, access-restricted backups used only for disaster recovery and security purposes.
Coefficients Co Ltd does not currently hold a third-party security certification such as SOC 2 or ISO 27001 and does not claim one. Measures may evolve, provided the level of protection is not materially reduced.
Subprocessors
Coefficients Co Ltd engages the subprocessors listed in the Privacy Policy (currently Cloudflare, Neon, Upstash, Paddle, and Amazon Web Services) to help provide the Service. Each is engaged under a written contract requiring data-protection and security obligations no less protective than those Coefficients Co Ltd undertakes.
Coefficients Co Ltd will make the current subprocessor list available and, before adding or replacing a subprocessor that processes Customer Personal Data, will provide notice (for example, by updating the Privacy Policy and, for customers who request it, by email) so the customer has an opportunity to object on reasonable data-protection grounds. The third-party platforms a customer independently authorizes as data sources are not Coefficients Co Ltd subprocessors.
Assistance with Data Subject Requests
Taking into account the nature of the processing, Coefficients Co Ltd provides the customer with the tools in the Service and reasonable additional assistance to help the customer respond to requests from data subjects to exercise their rights (such as access, correction, deletion, restriction, objection, and portability). IfCoefficients Co Ltd receives such a request directly from a data subject relating to a customer's Customer Personal Data, it will refer the request to the customer.
Security Incidents
Coefficients Co Ltd will notify the affected customer without undue delay after becoming aware of a personal-data breach affecting that customer's Customer Personal Data, and will provide the information reasonably available to help the customer meet its own notification obligations, along with the measures Coefficients Co Ltd has taken or proposes to take. An executed DPA sets out any specific timeframe and process.
Audits and Compliance Assistance
Coefficients Co Ltd will make available information reasonably necessary to demonstrate compliance with its processor obligations and will assist the customer, at the customer's reasonable request and expense, with data-protection impact assessments and prior consultations. The scope, frequency, and process for any audit or inspection are defined in an executed DPA, subject to confidentiality and to protecting other customers' data and the security of the Service.
Return and Deletion of Data
On termination of the subscription, or on the customer's earlier verified request, Coefficients Co Ltd deletes or irreversibly anonymizes active Customer Personal Data and provider-derived data within 30 days, and removes it from disaster-recovery backups within a further 30 days as those backups expire on their ordinary schedule. Stored OAuth credentials and API keys are revoked or deleted as soon as a deletion request is validated. Coefficients Co Ltd may retain data where required by law, and such data remains subject to this summary's confidentiality and security commitments. See the Privacy Policy and Data Deletion page.
International Transfers
Coefficients Co Ltd is based in the Philippines and hosts persistent platform data primarily in Singapore, with subprocessors that operate in other regions (see the Privacy Policy). Where a transfer of Customer Personal Data requires a safeguard under applicable law, Coefficients Co Ltd relies on an appropriate mechanism, which may include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated through Coefficients Co Ltd's agreements with its subprocessors, together with supplementary measures where needed.
Requesting an Executable DPA
Eligible customers and prospective customers can request a DPA for signature by emailing legal@coeffiq.com or privacy@coeffiq.com, including the contracting entity name and the plan or agreement it relates to. Until a DPA is executed or expressly incorporated into a signed agreement, this page is a description of Coefficients Co Ltd's practices and not a contract.
