Legal

Data Processing Agreement

Last updated: August 22, 2026

This summary describes how Prynt processes personal data on your behalf. A signable DPA is available to any customer on request at [email protected].

Roles

You (the customer) are the data controller. Prynt is the data processor, processing device and network signals only to provide the identification and fraud-detection service you configure — never for our own purposes and never sold.

Scope of processing

  • Categories of data: pseudonymous device signals, a derived visitor ID, IP address (minimized per your configuration), and any linkedId/tag you send.
  • Purpose: visitor identification and bot/fraud risk scoring for your properties.
  • Duration: for the term of your subscription; deleted on account closure or request.

Security & sub-processors

Prynt encrypts secrets at rest, restricts access, and maintains an audit log. Our current sub-processor list (hosting, email, payments) is available on request and updated with notice.

The intelligence network

Where enabled, Prynt exchanges only one-way, salted signals of confirmed-bad entities — not raw personal data — to improve fraud detection across the network. This processing is governed by this DPA; contact us to review data-flow details and opt-out options for your compliance needs.

Your rights & assistance

Prynt honors GPC/Do-Not-Track, supports data export and right-to-erasure, and assists with data-subject requests and regulator inquiries under GDPR Art. 28 and LGPD.

This summary is informational; the executed DPA governs.