Data Processing Agreement
Last updated: August 22, 2026
This summary describes how Prynt processes personal data on your behalf. A signable DPA is available to any customer on request at [email protected].
Roles
You (the customer) are the data controller. Prynt is the data processor, processing device and network signals only to provide the identification and fraud-detection service you configure — never for our own purposes and never sold.
Scope of processing
- Categories of data: pseudonymous device signals, a derived visitor ID, IP address (minimized per your configuration), and any linkedId/tag you send.
- Purpose: visitor identification and bot/fraud risk scoring for your properties.
- Duration: for the term of your subscription; deleted on account closure or request.
Security & sub-processors
Prynt encrypts secrets at rest, restricts access, and maintains an audit log. Our current sub-processor list (hosting, email, payments) is available on request and updated with notice.
The intelligence network
Where enabled, Prynt exchanges only one-way, salted signals of confirmed-bad entities — not raw personal data — to improve fraud detection across the network. This processing is governed by this DPA; contact us to review data-flow details and opt-out options for your compliance needs.
Your rights & assistance
Prynt honors GPC/Do-Not-Track, supports data export and right-to-erasure, and assists with data-subject requests and regulator inquiries under GDPR Art. 28 and LGPD.
This summary is informational; the executed DPA governs.