Data Processing Addendum
Last updated: August 9, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) entered into by and between the Customer and FM Media, Inc., doing business as Levito (“Levito”), pursuant to which Customer has accessed Levito’s Service as defined in the Agreement. The purpose of this DPA is to reflect the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of Data Protection Legislation as defined below.
This DPA shall not replace or supersede any agreement or addendum relating to the processing of Personal Data negotiated by Customer and referenced in the Agreement, and any such individually negotiated agreement or addendum shall apply instead of this DPA.
In the course of providing the Service to Customer pursuant to the Agreement, Levito may process Personal Data on behalf of Customer. Levito agrees to comply with the following provisions with respect to any Personal Data submitted by or for Customer to the Service, or collected and processed by or for Customer through the Service.
Data processing terms
In this DPA, “Data Protection Legislation” means the General Data Protection Regulation (Regulation (EU) 2016/679), the UK GDPR and the Data Protection Act 2018, and all other applicable laws relating to the processing of Personal Data and privacy that may exist in any relevant jurisdiction.
“Data controller”, “data processor”, “data subject”, “Personal Data”, “processing” and “appropriate technical and organisational measures” shall be interpreted in accordance with applicable Data Protection Legislation.
The parties agree that Customer is the data controller and that Levito is its data processor in relation to Personal Data processed in the course of providing the Service. Customer shall comply at all times with Data Protection Legislation in respect of all Personal Data it provides to Levito pursuant to the Agreement.
The subject-matter of the data processing covered by this DPA is the Service ordered by Customer. The processing will be carried out until the term of Customer’s ordering of the Service ceases. Further details are set out in Annex 1.
In respect of Personal Data processed in the course of providing the Service, Levito:
- shall process the Personal Data only in accordance with documented instructions from Customer, as set out in this DPA, the Agreement, or as otherwise notified by Customer from time to time. If Levito is required to process the Personal Data for any other purpose provided by applicable law to which it is subject, Levito will inform Customer of that requirement before processing, unless that law prohibits it on important grounds of public interest;
- shall notify Customer without undue delay if, in Levito’s opinion, an instruction for the processing of Personal Data given by Customer infringes applicable Data Protection Legislation;
- shall implement and maintain appropriate technical and organisational measures designed to protect the Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, theft, alteration or disclosure. These measures are described in Annex 2, and include storing visitor IP addresses and email addresses only as one-way cryptographic hashes, so that neither value can be recovered from Levito’s systems;
- may hire other companies to provide limited services on its behalf, provided Levito complies with this clause. Any such subcontractors will be permitted to process Personal Data only to deliver the services Levito has retained them to provide, and shall be prohibited from using Personal Data for any other purpose. Levito remains responsible for its subcontractors' compliance with the obligations of this DPA. Any subcontractor to which Levito transfers Personal Data will have entered into a written agreement requiring it to abide by terms substantially similar to this DPA. Levito will inform Customer before engaging any new subcontractor to process Personal Data, and Customer may object;
- shall ensure that personnel authorised to process the Personal Data are subject to a duty of confidence;
- shall, taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests from data subjects exercising their rights. Customer acknowledges that because visitor IP addresses and email addresses are stored only as salted one-way hashes, Levito can identify records relating to an individual data subject only where Customer supplies the information required to derive the same hash;
- shall, taking into account the nature of the processing and the information available to it, assist Customer in meeting its obligations under Articles 32 to 36 of the GDPR;
- shall notify Customer without undue delay after becoming aware of a Personal Data breach, and provide Customer with a description of the breach together with periodic updates as further information becomes available. Levito shall investigate the breach and take reasonable steps to prevent or mitigate its effects;
- shall, at Customer’s choice, delete or return all Personal Data to Customer after the end of the provision of the Service, unless applicable law requires storage of the Personal Data; and
- shall make available to Customer all information necessary to demonstrate compliance with the obligations in this DPA, and allow for and contribute to audits conducted by Customer or an auditor mandated by Customer. Such an audit shall consist of the provision by Levito of written information, which may include questionnaires and information about security policies, and interviews with Levito personnel. For the avoidance of doubt, an audit does not include access to Levito’s systems, data hosting sites or infrastructure.
Sub-processors
As at the date of this DPA, Levito engages no sub-processor to process Personal Data relating to Customer’s visitors. Visitor data is sent directly to Levito’s own servers and is processed there.
For completeness, two third parties are involved in delivering the Service and neither receives Personal Data relating to Customer’s visitors:
- A content delivery network distributes the Levito script and other static files. It delivers files to browsers and receives no measurement data; visitor impressions and conversions are sent to Levito’s own servers on a separate address and never pass through it.
- A large language model provider generates the alternative versions of Customer’s page copy. What is sent to it is the content of Customer’s page and the business context Customer has supplied. Visitor identifiers, the hashed values described in Annex 1, and any other visitor data are not sent to it. Customer should not place Personal Data in its page copy or in the business context it supplies if it does not wish that content to be processed in this way.
If Levito engages a sub-processor in the future, the clause above governs it and Levito will inform Customer beforehand.
International transfers
Levito is established in the United States and processes Personal Data there.
In this section, “EU SCCs” means the Standard Contractual Clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
European Economic Area
Where Customer is established in the European Economic Area, or is otherwise subject to the GDPR, and the transfer of Personal Data to Levito requires a transfer mechanism under Article 46 of the GDPR, the EU SCCs are hereby incorporated into and form part of this DPA by reference, and apply to that transfer. Customer is the data exporter and Levito is the data importer. The parties agree the following:
- Module. Module Two (controller to processor) applies. The other modules do not.
- Clause 7 (docking clause). Does not apply.
- Clause 9 (use of sub-processors). Option 2, general written authorisation, applies. The time period for prior notice of sub-processor changes is thirty (30) days, consistent with the Sub-processors section above.
- Clause 11 (redress). The optional paragraph permitting data subjects to lodge a complaint with an independent dispute resolution body does not apply.
- Clause 17 (governing law). The EU SCCs are governed by the law of Ireland.
- Clause 18 (choice of forum and jurisdiction). Disputes arising from the EU SCCs shall be resolved by the courts of Ireland.
- Annex I.A (list of parties). Customer is the data exporter and controller, with the identity and contact details in Customer’s account. FM Media, Inc., doing business as Levito, is the data importer and processor; its contact point for data protection is help@levito.com. The activity relevant to the transfer is the provision of the Service.
- Annex I.B (description of the transfer). The categories of data subject, the categories of personal data, the frequency of the transfer, the nature and purpose of the processing, and the retention period are as set out in Annex 1 of this DPA. No special categories of personal data are transferred.
- Annex I.C (competent supervisory authority). The supervisory authority of the Member State in which the data exporter is established. Where the data exporter is not established in the European Economic Area, the competent authority is that of the Member State in which the exporter’s representative is established or, where Clause 13 so provides, the Irish Data Protection Commission.
- Annex II (technical and organisational measures). As set out in Annex 2 of this DPA.
- Annex III (list of sub-processors). None, as stated in the Sub-processors section above.
United Kingdom
Where the transfer is subject to the UK GDPR, the UK Addendum is hereby incorporated into and forms part of this DPA by reference and applies to that transfer, together with the EU SCCs as modified by it. Tables 1 to 3 of the UK Addendum are populated by the corresponding information in the section above and in Annex 1 and Annex 2 of this DPA. For Table 4, the party who may end the UK Addendum as set out in its Section 19 is the data importer.
Switzerland
Where the transfer is subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with the following adaptations: references to the GDPR are to be understood as references to the Swiss Federal Act on Data Protection; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to a Member State are to be read as including Switzerland; and data subjects in Switzerland may enforce their rights in Switzerland.
Precedence
In the event of any conflict between the EU SCCs or the UK Addendum and any other term of this DPA or of the Agreement, the EU SCCs or the UK Addendum shall prevail in respect of the transfer to which they apply. If at any time the transfer mechanism relied on above is invalidated, or is replaced by a successor mechanism, the parties shall in good faith adopt the successor mechanism or an alternative lawful transfer mechanism without undue delay.
CCPA service provider statement
For the purposes of the California Consumer Privacy Act (“CCPA”), Levito acts as a “service provider” with respect to personal information processed on behalf of Customer, and Customer is the “business”.
Levito shall not:
- sell or share personal information, as those terms are defined under the CCPA;
- retain, use or disclose personal information for any purpose other than performing the services specified in the Agreement, including retaining, using or disclosing it for a commercial purpose other than performing those services;
- retain, use or disclose personal information outside the direct business relationship between Levito and Customer; or
- combine personal information received from Customer with personal information received from, or on behalf of, any other person, except as permitted under the CCPA.
Levito certifies that it understands the restrictions above and will comply with them. Levito will notify Customer if it determines that it can no longer meet its obligations as a service provider under the CCPA.
Annex 1 - Details of the data processing
Levito processes information in order to provide the Service pursuant to the Agreement. Levito processes information sent by Customer’s end users, identified through Customer’s implementation of the Service.
Types of personal data
For each visitor to a page on which the Service is active, Levito may store:
- A pseudonymous visitor identifier generated by the Service. It is a random value and is not derived from any personal identifier.
- Which version of the tested page the visitor was shown.
- Whether the request came from a mobile device.
- Whether the request was identified as automated traffic.
- The address (URL) of the page.
- Where a goal was completed, an identifier for the page element involved.
- The date and time of the impression or conversion.
- A keyed one-way hash of the visitor’s IP address. The IP address is combined with Customer’s site identifier and passed through HMAC-SHA256 using a secret held by Levito; only a short prefix of the digest is stored. The IP address itself is not stored.
- A salted one-way hash of the visitor’s email address, where Customer’s configuration supplies one for attribution purposes. The normalised address is hashed with SHA-256 using a salt unique to Customer’s site, so the same address yields a different value on each site. The address itself is not stored.
Raw IP addresses and browser user-agent strings are used transiently to derive the values above and are not retained.
Categories of data subjects
Visitors to Customer’s websites on which the Service is active.
Processing activities
The provision of the Service by Levito to Customer, comprising: serving one of several versions of Customer’s page copy to each visitor; recording which version was served; recording whether the visitor subsequently completed a goal Customer has configured; attributing that completion to the version served; excluding automated traffic from those measurements; and reporting the results to Customer.
Duration and retention
Processing is carried out for as long as Customer’s ordering of the Service continues. Within that period:
- the hashed IP value is erased thirty days after the record it belongs to was created;
- the hashed email values used to attribute conversions, and the records of the requests that supplied them, are deleted after thirteen months;
- impression and conversion records are retained while Customer keeps them, and are deleted when Customer deletes the test they belong to; and
- all of the above are deleted when Customer’s account is closed.
On termination, Levito shall delete or return the Personal Data at Customer’s choice, as set out above.
Annex 2 - Technical and organisational measures
Levito applies the following measures to Personal Data processed under this DPA:
- Data minimisation by design. The two directly identifying values the Service encounters, the visitor’s IP address and, where supplied, their email address, are never written to Levito’s database. Each is reduced to a one-way cryptographic hash at the point of ingestion and the original value is discarded. Browser user-agent strings are used to classify the request and are not stored.
- Separation between customers. The email hash is salted with a value unique to each site, so the same address produces a different value on every site. Hashes cannot be correlated across customers, or against a list obtained elsewhere.
- Encryption in transit. All connections to the Service, including the collection endpoint, are served over TLS.
- Access control. Personal Data is held behind secured networks and is accessible only to personnel who need it to operate the Service. Access to a customer account by Levito staff is displayed to the customer while it is in progress. Authenticated sessions are bound to the browser that created them and expire.
- Confidentiality. Personnel authorised to process Personal Data are subject to a duty of confidence.
- Retention limits. The retention periods in Annex 1 are enforced automatically by scheduled deletion, not by manual process.
- Abuse and automated-traffic controls. Automated traffic is identified and excluded from measurement, and account creation and sign-in are rate limited.
- Deletion on request. Customer can delete individual sites, pages, goals and tests from within the Service, which deletes the associated records, and closing the account deletes all of them.
Notices
Any notice under this DPA must be sent to FM Media, Inc. d/b/a Levito, 21750 Hardy Oak Blvd Ste 104, San Antonio, TX 78258-4946, USA, or to help@levito.com.
We only get paid if you do.
Free to start. Pay on results.