Data Processing Agreement
Last updated: 3 September 2026
This Data Processing Agreement ("DPA") describes how Lirova processes personal data on your behalf when you use the service. It forms part of our Terms of Service.
Who we are
Lirova is operated by Lirova, LLC, a limited liability company organised under the laws of the State of Delaware, United States, with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, USA.
In this DPA, "Lirova", "we", "us" and "our" refer to that entity, which acts as the data processor under this agreement.
Roles of the parties
For personal data of your customers processed through Lirova, you act as the data controller and Lirova acts as the data processor.
Scope of processing
We process personal data only to provide the recovery service: classifying failed payments, scheduling retries, and sending the dunning communications you have enabled.
Subprocessors
We use a small set of service providers to run Lirova. Each one processes only what its own job needs, under a written agreement holding it to data-protection obligations no weaker than ours under this DPA.
- Zomro
- Virtual private server. Runs the API, including the retry scheduler and the messaging workers.
- Vercel
- Hosts the dashboard and the public site.
- Supabase
- Managed PostgreSQL. Stores your account, your recovery cases and our fee records.
- Upstash
- Managed Redis. Holds the retry and message queue: case identifiers and scheduling data, no card data.
- Resend
- Email delivery. Sends the payment-update emails that reach your customers.
- PostHog
- Product analytics and error tracking. Records how the dashboard and the public site are used, and receives crash reports: stack traces and request context.
- Telegram
- Support chat. A conversation you start in the support widget is mirrored to our team there.
Stripe is not on this list. It is your payment processor: we reach your account through Stripe under Stripe's own terms, not as a provider we engaged to process on your behalf.
SMS and WhatsApp recovery is not switched on, so no SMS or WhatsApp provider processes anything today. Its provider will be named here before that channel goes live, and the same rule holds generally: a new subprocessor appears on this page before it starts processing.
Security measures
We apply technical and organisational measures appropriate to the risk, including access controls and encryption in transit. We do not store full card numbers.
International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards as required by applicable law.
Data subject requests
Taking into account the nature of the processing, we assist you in responding to requests from data subjects exercising their rights.
Return and deletion
On termination we return or delete the personal data we process on your behalf within 30 days, except where law requires us to keep it. Termination means you revoke Lirova's access in your Stripe dashboard, or ask us to close the account; the revoke stops all processing at once and deletion follows inside that window.
We keep beyond it only our own billing records — the fee amounts, the invoice references and the dates — for seven years, as tax law requires.
The 30 days are a contractual commitment we execute, not an automated retention job: nothing deletes on a timer today. Ask at legal@lirova.app and we run it and confirm completion in writing.
Audit
On reasonable request, we make available the information necessary to demonstrate compliance with this DPA.
Contact
Questions about this agreement, and data protection enquiries generally, can be sent to legal@lirova.app.
Lirova, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, USA.