Skip to main content
Version v1.1 · 10 Aug 2026. This Data Processing Addendum forms part of the migration agreement between Recurr Pty Ltd (ABN 31 693 957 809, “Recurr”) and the customer named in that agreement. It applies whenever Recurr processes personal data of your subscribers on your behalf. It is set out in full inside the agreement itself rather than linked from it, so what you sign is the whole instrument and neither of us has to rely on a page that can change afterwards. This copy is published so you can read it before you sign — it is kept identical to the signed text by an automated check. A countersigned copy is available on request.
Questions about any of it — matt@recurr.dev.

Roles

You are the controller of your subscribers’ personal data. Recurr is your processor. Your own Stripe account holds and processes payment credentials under your direct agreement with Stripe — full card data never passes through or rests on Recurr systems.

What we process, and why

  • Data subjects: your app’s subscribers.
  • Data categories: subscriber identifiers and contact data (email address, name where provided), subscription state (plan, status, tenure, store-vs-web billing status, cohort assignment), payment metadata (amounts, currency, timestamps, outcome — never card numbers), and migration and support workflow status and motion outcomes.
  • Purposes: operating your migration program and the Oikos platform — migration communications, checkout and billing surfaces, payment recovery, cancellation and win-back motions, statements and reporting. Also producing the anonymous record described below, which is an act of stripping data rather than of using it.
  • Duration: the term of the migration agreement.

How we process

  • On your instructions only. The agreement, your configuration in the platform, and your written instructions are the complete set of processing instructions. We process for no other purpose.
  • The anonymous record. We keep a record of what happens across the programs we run, and it is what our decisioning learns from. It is a separate store holding no identifiers and no key back to your systems or ours — nothing in it can be traced to a subscriber, to you, or to any other customer, by us or by anyone else. Because it identifies no one it is not personal data, and it is not governed by this addendum. Producing it is a one-way step: personal data goes in, and what comes out cannot be turned back into it.
  • No sale, no advertising, and your subscribers’ data never trains anyone else’s model. Subscriber personal data is never sold, never used for advertising, and never sent to a third party to train their AI models. Where our decisioning learns from personal data, it learns from what happens in your account in order to serve your account, and never to serve another customer’s.
  • Confidentiality. Access is limited to personnel who need it to deliver the service, under confidentiality obligations.
  • Security. Technical and organisational measures include encryption in transit and at rest, access controls, and audit logging. We review these measures regularly.
  • Analytics hygiene. Product analytics run on opaque identifiers — never subscriber email addresses or names.

Sub-processors

We use the following sub-processors to deliver the service: Supabase (application database and authentication), Vercel (application hosting), Stripe (payment processing, on your own account), Resend (transactional and campaign email delivery), PostHog (product analytics, opaque identifiers only), and Sentry (error monitoring, no subscriber personal data in events). We will notify you at least 14 days before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, we will work with you to resolve the objection, and you may end the engagement per the agreement’s exit terms if we cannot.

International transfers

Recurr is an Australian company subject to the Privacy Act 1988 (Cth). Where subscriber data of EU/UK data subjects is processed, transfers rely on the applicable standard contractual clauses or an equivalent lawful mechanism, and this addendum is read to include the obligations those clauses require of a processor.

Your rights and our assistance

  • Data subject requests. We assist with access, correction, deletion, and portability requests relating to subscriber data we process, within 10 business days of your request.
  • Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your subscriber data — targeting 72 hours — with the information you need for your own notification obligations.
  • Audit. Once per year, on 30 days’ notice, we will answer reasonable written security questionnaires and provide summaries of relevant assessments. On-site or technical audits are available where legally required, at shared cost.

Return and deletion

At the end of the engagement, on your instruction we return subscriber data we hold in a portable format and then delete it from our live systems within 14 days, except where retention is legally required. Managed backups are not deleted on demand: data in them ages out on our provider’s schedule, and if a restore inside that window returns deleted data, the deletion is re-applied. Your Stripe account — and everything in it — was always yours and simply remains with you.

Precedence

If this addendum conflicts with the migration agreement on the subject of personal data, this addendum prevails. It is governed by the same law as the agreement — Victoria, Australia.