Data Processing Agreement
Last updated: June 2026
This Data Processing Agreement ("DPA") is entered into between FunnelRover, operated by AMCherif ("Processor"), and the organization subscribing to the FunnelRover platform ("Controller"), collectively "the Parties."
This DPA forms part of the agreement between the Parties and supplements the Terms of Use and Terms of Sale. It governs the processing of personal data carried out by FunnelRover on behalf of the Controller in connection with the provision of the Platform.
1. Definitions
- Personal Data: any information relating to an identified or identifiable natural person, as defined under the GDPR and applicable local law
- Processing: any operation performed on personal data (collection, storage, use, transmission, deletion)
- Controller: the organization that determines the purposes and means of processing personal data
- Processor: FunnelRover, which processes personal data on behalf of the Controller
2. Subject Matter and Duration
FunnelRover processes personal data on behalf of the Controller solely to provide the services described in the Terms of Use: contact management, field visit tracking, training, retail audits, lead capture, consumer campaigns, and analytics.
This DPA is effective for the duration of the subscription and terminates automatically upon expiration or cancellation. Upon termination, FunnelRover will delete or return all personal data as described in Section 9.
3. Nature and Purpose of Processing
FunnelRover processes personal data as instructed by the Controller, for the following purposes:
- Storing and managing professional contacts (healthcare professionals, distributors, consumers, prospects)
- Recording field visit reports and interaction history
- Managing training enrollments and certifications
- Processing consumer campaign codes, draws, and loyalty points
- Capturing leads via landing pages
- Generating analytics and KPI reports
FunnelRover does not use the Controller's personal data for any purpose other than providing the Platform services.
4. Categories of Personal Data
- Professional contacts: name, employer, job title, email, phone, territory, specialty
- Field users: name, email, job title, role, login history
- Consumers: first name, phone number (WhatsApp), email, city, opt-in consents
- Interaction data: visit reports, attendance records, quiz results, campaign participation
- Consent records: opt-in timestamps, channel, source landing page
5. Categories of Data Subjects
- Employees and field representatives of the Controller
- Professional contacts (healthcare professionals, pharmacists, distributors, retailers) managed by the Controller
- Consumers participating in the Controller's campaigns
6. Obligations of FunnelRover as Processor
FunnelRover undertakes to:
- Process personal data only on documented instructions from the Controller
- Ensure that authorized personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Privacy Policy, Section 7)
- Assist the Controller in responding to data subject rights requests
- Notify the Controller without undue delay (and within 72 hours where feasible) of any personal data breach
- Delete or return all personal data upon termination of the DPA
- Provide all necessary information to demonstrate compliance and cooperate with audits
7. Obligations of the Controller
The Controller undertakes to:
- Ensure it has a valid legal basis for processing personal data before uploading it to the Platform
- Provide data subjects with appropriate privacy notices as required by applicable law
- Ensure that data uploaded to the Platform is accurate and relevant
- Notify FunnelRover of any changes to instructions that may affect processing
- Cooperate with FunnelRover in the event of a data subject rights request or data breach
8. Sub-processors
FunnelRover uses the following authorized sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Infrastructure — Cloud SQL, Cloud Run, Cloud Storage | EU / US (SCCs apply) |
| Anthropic | AI processing (Claude API) | US (SCCs apply) |
| Google Vertex AI | AI vision processing | EU / US (SCCs apply) |
| Flutterwave | Payment processing | Africa / UK |
| Stripe | Payment processing | US / EU |
| Twilio | WhatsApp Business API | US (SCCs apply) |
| Meta (WhatsApp Cloud API) | WhatsApp messaging | US (SCCs apply) |
FunnelRover will notify the Controller of any intended changes to this list with at least 30 days' notice. The Controller may object to such changes in writing within 15 days.
9. Data Return and Deletion
Upon expiration or termination of the subscription, FunnelRover will:
- Allow the Controller to export its data for 30 days following termination
- Permanently delete all personal data from active systems after this 30-day window
- Delete backup copies within 90 days of termination
Upon written request, FunnelRover will provide a written confirmation of deletion.
10. International Transfers
Where personal data is transferred outside the country of origin, FunnelRover ensures that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission where applicable, and data processing agreements with each sub-processor covering international transfers.
11. Audits
The Controller may, upon 30 days' written notice and no more than once per calendar year, conduct an audit of FunnelRover's data processing activities or designate a qualified third party to do so. Audits must be conducted during normal business hours and must not unreasonably disrupt operations. FunnelRover may satisfy this obligation by providing a recent third-party audit report covering the relevant controls.
12. Governing Law and Liability
This DPA is governed by the same law as the Terms of Use. The Parties' liability under this DPA is subject to the limitations set out in the Terms of Use.
13. Contact
For data protection inquiries and DPA-related matters, contact us at privacy@funnelrover.com or via our contact page. To request acceptance of this DPA or obtain a signed copy, contact us at the above address.