Draft — pending legal review. This document describes how we intend to operate and has not yet been reviewed by counsel. Ask us at hello@pejd.com before relying on it.
Data Processing Agreement
Last updated 16 September 2026
This agreement applies between you (the controller) and Moen & Co AS, Norway (the processor) whenever we process personal data on your behalf through Pejd. It forms part of the terms of service and is entered into automatically when you create an account. It implements Article 28 of the GDPR.
1. Subject matter and duration
We process personal data only to provide Pejd, for as long as your account exists and for up to 30 days afterwards.
2. Nature and purpose
Storing and retrieving your account and workspace data; fetching and analysing the public storefronts you submit; generating advertising creative and copy; publishing approved ads, paused, to the Meta ad account you connect; and providing support.
3. Categories of data and data subjects
- Data subjects: your team members who use the service, and any individuals whose personal data appears in content you submit.
- Data: names and email addresses of your users, workspace and usage records, the content of the storefronts you point us at, and the ad content generated from it.
- No special categories. Do not put health, biometric, political or similarly sensitive data into the service.
4. Our obligations
- Process personal data only on your documented instructions — using the service is the instruction — unless EU or member-state law requires otherwise, in which case we tell you first where we may.
- Bind everyone with access to confidentiality.
- Implement appropriate technical and organisational measures (clause 6).
- Help you respond to data subject requests and to meet your obligations under Articles 32–36.
- On termination, delete your personal data or return it at your choice, except where law requires retention.
- Make available the information needed to demonstrate compliance and allow audits, on reasonable notice and no more than once a year unless an authority requires otherwise.
5. Subprocessors
You give general authorisation for the subprocessors below. We will give at least 30 days’ notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected part of the service.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | EU (eu-west-1, Ireland) |
| Vercel | Application hosting and delivery | EU region for compute; global edge network |
| Trigger.dev | Background jobs that run the analysis and generation pipelines | EU/US |
| Google (Gemini API) | Brand extraction and ad copy generation | US |
| fal.ai | Image generation and reframing | US |
| Firecrawl | Rendering storefronts that require JavaScript | US |
| PostHog | Product analytics | EU (Frankfurt) |
| Stripe | Payments, invoicing and tax | EU/US |
| Meta Platforms | Publishing ads to your own Meta ad account, at your instruction | EU/US |
Transfers outside the EEA rely on the EU Standard Contractual Clauses together with the transfer risk assessments each provider publishes.
6. Security measures
- Encryption in transit (TLS) and at rest.
- No direct database access from the browser: every read and write goes through server-side code with authorisation checked in one place.
- Row level security enabled on every table as a second line of defence.
- Private storage buckets, served only through short-lived signed links.
- Third-party access tokens encrypted with a separate key before storage.
- Least-privilege access for staff, and access logging.
- Managed EU-region infrastructure with automated backups.
7. Personal data breach
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need for your own Article 33 notification.
8. Liability
The liability provisions of the terms of service apply to this agreement.
Need this signed on your own paper, or a copy with your company details? Write to privacy@pejd.com.