Data Processing Agreement

This agreement governs the processing of personal data that GoCohort carries out on behalf of its customers pursuant to Art. 28 GDPR. It supplements the Terms of Service and applies in addition to them.

1. Scope, Roles and Subject Matter

1.1

This Data Processing Agreement ("DPA") is concluded between you (the "Customer") and GoCohort GmbH ("GoCohort", "we") and supplements the Terms of Service available at /terms.

1.2

It applies where GoCohort processes personal data on behalf of the Customer, in particular personal data of visitors and end users of the funnel pages the Customer creates, publishes and hosts through the platform.

1.3

The Customer is the controller within the meaning of Art. 4 No. 7 GDPR and determines the purposes and means of the processing. GoCohort is a processor within the meaning of Art. 4 No. 8 GDPR and processes such data exclusively on behalf of the Customer.

1.4

This DPA does not apply where GoCohort processes personal data of the Customer's own account users for its own purposes, such as account administration, billing and product analytics. For that processing GoCohort is itself the controller and its privacy notice applies.

1.5

The subject matter, nature, purpose and duration of the processing, the categories of personal data and the categories of data subjects are set out in Annex 1.

2. Duration

2.1

This DPA takes effect when the Customer first uses a feature that causes GoCohort to process personal data on the Customer's behalf, and remains in force for as long as the Terms of Service are in force or such processing continues.

2.2

Either party may terminate this DPA only together with the Terms of Service. Provisions that by their nature are intended to survive termination, in particular Sections 4, 9 and 12, remain in force.

3. Instructions of the Controller

3.1

GoCohort processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which GoCohort is subject. In that case GoCohort informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

3.2

The Customer's configuration of the platform constitutes documented instructions. This includes in particular the fields collected by a funnel's lead form, the enabling of the AI chat assistant, the tracking and pixel integrations activated for a funnel page, the lead delivery destinations configured by the Customer, and the retention settings selected.

3.3

Additional or deviating instructions must be given in text form to hey@gocohort.com. GoCohort may charge for the implementation of instructions that go beyond the functionality of the platform.

3.4

GoCohort informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. GoCohort may suspend the execution of such an instruction until it is confirmed or amended by the Customer.

3.5

The Customer is responsible for the lawfulness of the processing, in particular for establishing a legal basis under Art. 6 GDPR, for obtaining and documenting any required consent from visitors of its funnel pages, and for meeting the information obligations under Art. 13 and 14 GDPR by providing its own imprint and privacy notice.

4. Confidentiality

4.1

GoCohort ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.2

This obligation continues to apply after the termination of the respective employment or contractual relationship and after the end of this DPA.

4.3

Access to personal data processed on behalf of the Customer is limited to those personnel who require such access to provide, maintain or support the platform.

5. Technical and Organisational Measures

5.1

GoCohort implements appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures in force at the time of conclusion of this DPA are described in Annex 2.

5.2

GoCohort may adapt the measures over time, provided that the agreed level of protection is not reduced. Material changes are documented in Annex 2.

5.3

On request, GoCohort provides the Customer with more detailed information about the implemented measures, subject to appropriate confidentiality obligations.

5.4

The Customer has reviewed the measures described in Annex 2 and considers them appropriate for the personal data it entrusts to GoCohort. The Customer is responsible for assessing whether these measures are appropriate for any special categories of personal data pursuant to Art. 9 GDPR that the Customer chooses to collect through custom lead form fields or the chat assistant.

6. Sub-processors

6.1

The Customer grants GoCohort general written authorisation within the meaning of Art. 28(2) GDPR to engage sub-processors. The sub-processors engaged at the time of conclusion of this DPA are listed in Annex 3.

6.2

GoCohort imposes on each sub-processor, by way of a contract, data protection obligations that are no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of the sub-processor's obligations.

6.3

GoCohort informs the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the address associated with the Customer's account or by an in-product notice.

6.4

The Customer may object to such a change on reasonable data protection grounds within 30 days of being informed. If the parties cannot reach an amicable solution, the Customer may terminate the affected services with effect from the date the change takes effect, without incurring an early termination fee for those services.

6.5

Providers that the Customer itself configures as a destination for its data, such as CRM systems, webhook endpoints and advertising pixels, are not sub-processors of GoCohort to the extent that GoCohort transmits personal data to them solely on the Customer's documented instruction and does not process the data for its own purposes. The Customer is responsible for its relationship with those providers, including any required processing agreement with them.

7. Assistance with Data Subject Rights

7.1

Taking into account the nature of the processing, GoCohort assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR.

7.2

The platform enables the Customer to view, export, correct and delete the leads and chat records associated with its funnel pages directly, which the Customer uses as the primary means of responding to such requests.

7.3

If a data subject contacts GoCohort directly regarding data processed on behalf of the Customer, GoCohort forwards that request to the Customer without undue delay and does not respond to it substantively itself.

8. Assistance with Security, Breach Notification and Impact Assessments

8.1

GoCohort assists the Customer in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to GoCohort.

8.2

GoCohort notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.

8.3

The notification pursuant to Art. 33(1) GDPR to the competent supervisory authority and, where required, the communication to data subjects pursuant to Art. 34 GDPR are the responsibility of the Customer as controller.

8.4

On request, GoCohort provides the Customer with the information reasonably required for a data protection impact assessment pursuant to Art. 35 GDPR and for prior consultation pursuant to Art. 36 GDPR.

9. Deletion and Return of Data

9.1

On termination of the provision of services relating to processing, GoCohort deletes the personal data processed on behalf of the Customer without undue delay, unless Union or Member State law requires continued storage.

9.2

The Customer is able to export its leads and chat records through the platform at any time during the term and thereby effects the return of the data itself. The Customer must complete any export it requires before termination takes effect; after termination the data is no longer available.

9.3

Files uploaded by visitors during a chat session are deleted automatically after three weeks, independently of the term of this DPA.

9.4

Backups are retained for the duration of the applicable backup cycle and are deleted in accordance with that cycle. Until deletion, the data in backups remains subject to this DPA.

9.5

On request, GoCohort confirms the deletion in text form.

10. Audits and Information

10.1

GoCohort makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

10.2

Audits are announced with reasonable notice of at least four weeks, take place during normal business hours, must not disproportionately disrupt operations, and are limited to one audit per calendar year. The notice period and the annual limit do not apply where there is an actual or reasonably suspected personal data breach affecting personal data processed on behalf of the Customer, a material compliance issue under this DPA, or where an audit is required by a competent supervisory authority.

10.3

The auditor must not be a competitor of GoCohort and must be bound to confidentiality. GoCohort may require the auditor to sign a confidentiality agreement before granting access.

10.4

GoCohort may satisfy the audit obligation by providing current certifications, audit reports or reports of independent third parties, insofar as these are suitable to demonstrate compliance.

11. International Transfers

11.1

Personal data processed on behalf of the Customer is processed within the European Union wherever the relevant service permits. Where a sub-processor listed in Annex 3 processes personal data outside the European Economic Area, the transfer takes place on the basis of an adequacy decision pursuant to Art. 45 GDPR or on the basis of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, supplemented where necessary by additional safeguards.

11.2

The legal basis relied on for each sub-processor established outside the European Economic Area is stated in Annex 3.

11.3

GoCohort does not transfer personal data processed on behalf of the Customer to a third country on its own initiative without a valid transfer mechanism.

12. Liability, Precedence and Amendments

12.1

The liability provisions of the Terms of Service apply to this DPA, without prejudice to Art. 82 GDPR.

12.2

Where the Terms of Service and this DPA conflict in respect of the processing of personal data on behalf of the Customer, this DPA prevails.

12.3

GoCohort may amend this DPA where necessary to reflect changes in the law, in the decisions of supervisory authorities or in the functionality of the platform. Material amendments are notified to the Customer at least 30 days before they take effect.

12.4

Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions remains unaffected.

12.5

This DPA is governed by German law. The place of jurisdiction is Stuttgart, Germany, insofar as the Customer is a merchant, a legal person under public law or a special fund under public law.

Annex 1 — Description of the Processing

This annex describes the processing carried out by GoCohort on behalf of the Customer in connection with the funnel pages the Customer publishes and hosts through the platform.

Categories of data subjects

  • Visitors of the funnel pages published by the Customer
  • Persons who submit a lead form or interact with the chat assistant on those pages (leads)

Categories of personal data

  • Contact data submitted through a lead form: name, email address, telephone number
  • Any further data the Customer chooses to collect through custom lead form fields, the content of which is determined solely by the Customer
  • The full content of the conversation a visitor conducts with the chat assistant, including any free text the visitor enters
  • Files a visitor uploads during a chat session, such as images, PDF documents and text or tabular files, including any personal data contained in them
  • Campaign attribution parameters contained in the URL through which the visitor arrived, including UTM parameters and advertising click identifiers such as fbclid and gclid
  • The visitor's IP address, processed transiently for rate limiting and abuse prevention and not stored together with the lead record
  • Online identifiers set by tracking technologies the Customer activates for its funnel page

Nature and purpose of the processing

  • Hosting and delivery of the funnel page requested by the visitor
  • Operation of the AI chat assistant, including generating responses to visitor messages and, where the visitor requests it, web search
  • Collection, validation and storage of lead submissions
  • Transmission of lead data to the destinations the Customer has configured, such as email notifications, webhooks and CRM systems
  • Rate limiting and abuse prevention
  • Error monitoring and quality assurance of the chat assistant

Duration of the processing

  • For the duration of the Terms of Service, subject to Section 9 of this DPA
  • Files uploaded by visitors during a chat session are deleted automatically after three weeks
  • The visitor's IP address is retained only for the duration of the applicable rate limiting window

Cookies and tracking technologies on funnel pages

  • Set or loaded without prior consent of the visitor: a first-party cookie with a lifetime of one day that links the visitor to their chat session; product analytics of the hosting provider; and, where a Google Tag Manager container is configured for the Customer's account, the Google Tag Manager container script.
  • Loaded only after the visitor accepts the cookie banner: Meta Pixel, TikTok Pixel, LinkedIn Insight Tag and the Google Ads tag, in each case only where the Customer has activated the respective integration.
  • Where a server-side tagging container is used, the visitor's IP address and user agent are transmitted to Meta together with the corresponding pixel identifiers. No name, email address or telephone number is transmitted to advertising providers by the platform.
  • The Customer is responsible for assessing which of these technologies require prior consent under § 25 TDDDG and Art. 6 GDPR, for configuring its funnel page accordingly, and for describing them in its own privacy notice. GoCohort draws the Customer's attention to the fact that not all of the technologies listed above are gated behind the cookie banner.

Annex 2 — Technical and Organisational Measures (Art. 32 GDPR)

The following measures are in place at the time of publication of this agreement. On request, GoCohort provides customers with more detailed information about the implemented measures, subject to appropriate confidentiality obligations.

Confidentiality and access control

  • Access to personal data processed on behalf of the Customer is restricted to authorised personnel and systems on a need-to-know basis.
  • Automated submission of lead data to the platform requires authentication.
  • Administrative access to production systems is individually assigned, limited to personnel who require it and protected by multi-factor authentication.
  • Credentials for integrations configured by the Customer are stored separately from application data with restricted access.

Encryption

  • All connections between visitors, the platform and its sub-processors are encrypted in transit using TLS.
  • Personal data is encrypted at rest by the underlying infrastructure providers.

Separation of processing

  • Customer data is logically separated between customer environments, and access controls are designed to prevent unauthorised cross-customer access.
  • Development and production environments are appropriately separated.

Integrity and change management

  • Inbound lead submissions are validated before storage.
  • Rate limits are applied to the lead intake and chat functionality to protect against abuse.
  • Changes to the platform are subject to version control and review before controlled deployment, and deployments can be rolled back to a previous version.

Availability and resilience

  • The platform runs on managed infrastructure with automated backups and point-in-time recovery appropriate to the nature and risks of the processing.
  • Measures for detecting, investigating and responding to security events, including server-side error monitoring and alerting, are in place.

Data deletion

  • Personal data is deleted in accordance with Section 9 of this DPA and the retention periods described in Annex 1.

Known limitations

  • Files uploaded by a visitor during a chat session are made available through access links that do not require further authentication; anyone in possession of such a link can retrieve the file until it is deleted automatically after three weeks. The Customer should take this into account when deciding whether to enable file uploads and when instructing visitors what to upload.
  • The content of chat conversations is transmitted to the providers listed in Annex 3 for the purpose of generating responses and for quality monitoring of the assistant.

Annex 3 — Sub-processors

The following sub-processors are engaged in the processing of personal data on behalf of the Customer. Providers that process personal data only of GoCohort's own account users, such as payment and billing providers, are not listed here.

ProviderPurposePersonal dataLocation and transfer basis
Vercel Inc.Hosting and delivery of the funnel pages and of the platform API, product analytics of page viewsAll request content, IP address, user agentUSA — EU-U.S. Data Privacy Framework and Standard Contractual Clauses
Supabase, Inc.Database and object storageLead records, chat transcripts, files uploaded by visitorsHosting in the European Union (Frankfurt, Germany); remote access from the USA under Standard Contractual Clauses
OpenAI Ireland LtdGeneration of chat assistant responses and, where requested by the visitor, web searchChat conversation content, files uploaded by visitorsIreland; onward transfer to OpenAI affiliates in the USA under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework
PostHog (EU Cloud)Quality monitoring of the chat assistantFull chat prompts and generated responses, token usageEuropean Union — no third country transfer
Upstash, Inc.Rate limiting and abuse preventionIP address, transientlyUSA — EU-U.S. Data Privacy Framework and Standard Contractual Clauses
Resend (Plus Five Five, Inc.)Delivery of lead notification emails to the CustomerName, email address, telephone number and custom fields of the leadUSA — EU-U.S. Data Privacy Framework and Standard Contractual Clauses
Google Ireland LimitedTag management and analytics on funnel pages, where a container is configuredIP address, user agent, page URL, online identifiersIreland; onward transfer to Google LLC in the USA under the EU-U.S. Data Privacy Framework
Sentry (Functional Software, Inc.)Server-side error monitoringIncidental personal data contained in error contextUSA — EU-U.S. Data Privacy Framework and Standard Contractual Clauses

Last updated: August 10, 2026