GDPR & Data Processing Agreement

Effective date and last updated: 1 August 2026

Version: 2026-08-01

This Data Processing Agreement ("DPA") forms part of the ELVPro Terms of Service or other written agreement (the "Agreement") between:

(1) the yard, dismantler, recycler, used-parts business or other organisation that has contracted for ELVPro ("Customer", "Controller"); and

(2) SYNCDEV S.R.L., Romanian Trade Register no. J36/164/2014, CUI / fiscal identification code 33129339, registered office at Str. Fetițelor nr. 4, camera nr. 1, 820035 Tulcea, Tulcea, Romania ("SYNCDEV", "ELVPro", "Processor").

This DPA is intended to satisfy Article 28(3) and (4) of Regulation (EU) 2016/679 ("GDPR"). The parties may sign it electronically or accept it as part of the online Agreement.

1. Definitions and precedence

"Customer Personal Data" means personal data processed by SYNCDEV on behalf of Customer through ELVPro.

"Data Protection Law" means the GDPR, Romanian Law no. 190/2018, applicable rules implementing Directive 2002/58/EC, and any other data-protection law applicable to the processing.

"Data Subject", "personal data", "processing", "controller", "processor", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.

"Subprocessor" means another processor engaged by SYNCDEV to process Customer Personal Data.

If this DPA conflicts with the Agreement on protection of Customer Personal Data, this DPA prevails. If European Commission Standard Contractual Clauses used for an international transfer conflict with this DPA, those clauses prevail for that transfer.

2. Roles and scope

Customer determines the purposes and essential means of processing Customer Personal Data in its yard administration and public storefront. Customer is the controller and SYNCDEV is the processor.

SYNCDEV is a separate controller for its own prospect/customer relationship, SaaS-account administration, subscription billing, direct support relationship, security and legal compliance, as described in the ELVPro Privacy Policy. This DPA does not apply to that independent-controller processing.

The details of processing required by Article 28(3) GDPR are in Annex 1.

3. Customer instructions

SYNCDEV will process Customer Personal Data only:

  • to provide, secure, maintain and support the ELVPro service;
  • as configured or initiated by Customer and its authorised users through the service;
  • as described in the Agreement, this DPA and its Annexes;
  • to connect an integration expressly enabled by Customer; and
  • under other documented written instructions accepted by SYNCDEV.

The Agreement, this DPA, Customer's configuration and authorised use of a feature constitute documented instructions.

SYNCDEV will not sell Customer Personal Data, use it for its own advertising, or combine it with data from other yards to create a cross-yard customer marketplace.

If Union or Member State law requires processing outside Customer's instructions, SYNCDEV will inform Customer before processing unless the law prohibits that notice on important grounds of public interest.

SYNCDEV will inform Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law. SYNCDEV may suspend the affected processing while the parties clarify or amend the instruction.

4. Customer obligations

Customer warrants and undertakes that:

  • it has a valid lawful basis for each processing purpose and has provided all information required by Articles 13 and 14 GDPR;
  • its instructions comply with Data Protection Law;
  • it collects and uses only personal data that is adequate, relevant and necessary;
  • it has the rights and authority needed to upload, publish, disclose or instruct processing of the data and content;
  • it will not use ELVPro for unlawful discrimination or solely automated decisions prohibited by Article 22 GDPR;
  • it will not upload special-category data, criminal-offence data or children's data unless strictly necessary, expressly agreed with SYNCDEV, and supported by all required legal conditions and safeguards;
  • it configures retention, access permissions, cookies, marketing tags, communications and integrations lawfully;
  • it responds to Data Subjects and authorities as controller; and
  • its authorised users keep credentials and integration keys secure.

Customer is responsible for the accuracy, quality and legality of Customer Personal Data and the means by which it was obtained.

5. Confidentiality and personnel

SYNCDEV will ensure that persons authorized to process Customer Personal Data:

  • are subject to a contractual or statutory duty of confidentiality;
  • receive access only where needed for their duties;
  • receive appropriate privacy and security instructions; and
  • process the data only as permitted by this DPA.

Access by SYNCDEV support personnel must be limited, authorized and logged where the system supports logging. Support impersonation must be time-limited and used only for the authorized support purpose.

6. Security

Taking account of the state of the art, implementation costs, nature, scope, context and purposes of processing, and the risk to individuals, SYNCDEV will implement and maintain appropriate technical and organizational measures under Article 32 GDPR.

The baseline measures are described in Annex 2. SYNCDEV may update measures to address risk and technology, provided the overall protection is not materially reduced.

Customer acknowledges that security is a shared responsibility. Customer must configure roles and permissions appropriately, enable multi-factor authentication where required or available, secure endpoints and credentials, maintain authored-user lists and report suspected compromise promptly.

7. Personal data breaches

SYNCDEV will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification is not conditional on the breach being confirmed or on an investigation being completed. Where feasible, SYNCDEV will send an initial notice within 24 hours of becoming aware. That 24-hour period is an operational target inside the overriding duty to notify without undue delay and never postpones notification beyond it.

The notice will provide information available to SYNCDEV concerning:

  • the nature of the breach, affected data and approximate number/categories of Data Subjects and records;
  • likely consequences;
  • measures taken or proposed to contain and remedy it;
  • a contact point for follow-up; and
  • information reasonably needed for Customer's Articles 33 and 34 GDPR assessment.

Where the facts are not yet established, SYNCDEV will send a preliminary notice with the information then available instead of waiting for the investigation to conclude, and will supplement it in phases as further information becomes available. Notification is not an admission of fault or liability.

SYNCDEV will take reasonable steps to contain, investigate and remediate the breach and will cooperate with Customer. Customer remains responsible for deciding whether and how to notify a supervisory authority or Data Subjects, unless law assigns that duty directly to SYNCDEV.

8. Data Subject requests

Taking account of the nature of processing, SYNCDEV will provide reasonable technical and organisational assistance to help Customer respond to requests under Chapter III GDPR.

ELVPro includes functions for complete structured JSON export, rectification, restriction, consent history and erasure. Uploaded files are made available separately where applicable. Customer remains responsible for applying the correct legal exceptions and confirming its response to the Data Subject.

If SYNCDEV receives a request concerning Customer Personal Data directly from a Data Subject, it will not respond on the merits unless authorized by Customer or required by law. Where the requester and Customer can be identified, SYNCDEV will direct the requester to Customer or forward the request without undue delay.

9. Compliance assistance

Taking account of the nature of processing and information available to it, SYNCDEV will provide reasonable assistance with Customer's obligations under Articles 32 to 36 GDPR, including security, breach assessment, data protection impact assessments and prior consultation.

Assistance included in standard product features is covered by the subscription fee. Substantial bespoke work may be charged at the agreed professional-services rate, provided SYNCDEV gives advance notice and the charge does not prevent Customer from meeting a statutory obligation.

10. Subprocessors

Customer gives SYNCDEV general written authorisation to use the Subprocessors in the current Subprocessor Register.

Before a new Subprocessor begins processing Customer Personal Data, SYNCDEV will:

  • carry out a proportionate privacy/security assessment;
  • enter a written contract imposing data-protection obligations no less protective than the relevant obligations in this DPA;
  • update the register; and
  • give Customer at least 15 days' prior notice by email or an in-service notice, unless an urgent replacement is necessary to protect security, prevent service interruption or comply with law.

Customer may object during the notice period on reasonable and documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution, such as avoiding the affected feature. If no reasonable solution is available, either party may terminate only the affected optional feature or, where the Subprocessor is necessary for the core service, Customer may terminate the Agreement before the Subprocessor begins processing. Termination rights do not create a refund beyond amounts required by the Agreement or mandatory law.

SYNCDEV remains responsible to Customer for each Subprocessor's performance of its processor obligations to the extent required by Article 28(4) GDPR.

Annex 3 must contain the actual production Subprocessor Register before this DPA is offered for acceptance. A generic statement such as "cloud, email and AI providers" is not a sufficient operational register.

11. International transfers

SYNCDEV will not transfer Customer Personal Data outside the EEA or allow access from a third country except:

  • on Customer's documented instruction; or
  • where a valid Chapter V GDPR transfer mechanism and required supplementary measures are in place.

Depending on the recipient, the mechanism may be an applicable adequacy decision, the recipient's valid participation in the EU-US Data Privacy Framework for covered data, or the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914.

Where Standard Contractual Clauses are required:

  • the appropriate controller-to-processor or processor-to-processor module applies;
  • Annexes 1 to 3 of this DPA may supply the corresponding factual annex information to the extent complete;
  • the optional docking clause applies;
  • Romanian law governs the clauses where a Member State law must be selected;
  • Romanian courts are the selected forum where permitted; and
  • SYNCDEV will carry out and document a transfer impact assessment and supplementary safeguards where needed.

SYNCDEV will make information about the relevant safeguard available to Customer on request, subject to necessary confidentiality redactions.

12. Return, export and deletion

During the Agreement and the applicable exit period, Customer may use the available export functions to retrieve the complete set of Customer Personal Data in a structured, commonly used, machine-readable form: newline-delimited JSON, one file per table, together with every uploaded file, in a single downloadable archive. The structures, formats, identifiers and known technical limitations are set out in the Data Export and Switching Register at https://elvpro.eu/data-export-and-switching.

On termination or Customer's written deletion instruction, Customer chooses return or deletion, unless the Agreement already records that choice. Subject to security and identity verification:

  • Customer should export data before the deletion date;
  • an approved permanent yard-deletion request enters a reversible 30-day grace period by default;
  • after the grace period, active Customer Personal Data is deleted or irreversibly anonymised;
  • data in Hetzner infrastructure backups expires through seven rolling daily restore points; application-level pre-deletion or recovery backups, where created, expire within 90 days;
  • if a backup is restored, applicable erasure records must be replayed; and
  • SYNCDEV will provide reasonable confirmation of completed deletion on request.

Customer instructs SYNCDEV to retain full fiscal invoices/orders and ELV compliance records only for the period Customer configures or applicable law requires, and then to strip personal identifiers or delete the record. Under the current Article 25 of Romanian Accounting Law no. 82/1991, the general accounting-document period is five years from 1 July of the following year, subject to other specific statutory periods and documented legal holds.

If Union or Member State law applicable to SYNCDEV requires storage after Customer's deletion instruction, SYNCDEV will isolate the data, process it only for that legal purpose, protect it and delete it when the requirement ends. Where legally permitted, SYNCDEV will inform Customer of the requirement.

Termination, suspension, downgrade or non-payment does not itself instruct permanent deletion. ELVPro may preserve hidden/restorable tenant data during those non-destructive states as described in the Agreement.

13. Demonstrating compliance and audits

SYNCDEV will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

No more than once per 12-month period, unless a breach, regulator request or credible material non-compliance justifies more, Customer may audit compliance. The parties will use the least disruptive method:

  1. current independent reports/certifications and written responses;
  2. a scoped remote review; and
  3. an on-site inspection only where the earlier evidence is insufficient.

Customer must give at least 30 days' notice unless an urgent legal reason prevents it. Auditors must be independent, qualified, not direct competitors of SYNCDEV, and bound by confidentiality. An audit may not compromise another customer's data, system security or privileged information. Customer bears its costs; SYNCDEV bears its ordinary cooperation costs, but may charge pre-agreed reasonable costs for unusually burdensome bespoke work.

Audit restrictions do not limit a competent supervisory authority's powers.

14. Records and regulatory cooperation

SYNCDEV will maintain records required of a processor under Article 30(2) GDPR and cooperate with competent supervisory authorities as required by Articles 31 and 58 GDPR.

15. Liability

Liability between the parties is governed by the Agreement, subject to Articles 82 and 83 GDPR and any liability that cannot lawfully be excluded or limited. Nothing in the Agreement or DPA deprives a Data Subject of rights or remedies under Data Protection Law.

16. Duration and termination

This DPA begins when SYNCDEV first processes Customer Personal Data under the Agreement and continues until that processing ends, including the deletion/return period. Provisions that must logically survive, including confidentiality, retained-data restrictions, audits relating to the term and international-transfer protections, remain effective for as long as relevant data is retained.

17. Governing law

This DPA is governed by Romanian law, without prejudice to mandatory GDPR rights and the jurisdiction provisions of any applicable Standard Contractual Clauses.

Privacy and incident contact: dpa@elvpro.eu

ANNEX 1 — DETAILS OF PROCESSING

A. Subject matter

Provision of the ELVPro multi-tenant SaaS service, including yard administration, inventory, public storefront, member/customer accounts, enquiries, live chat, orders, reservations, payment/invoicing workflows, delivery integrations, customer management, analytics, GDPR tooling, support, imports/exports, API/product feeds, AI-assisted drafts, vehicle/parts reference data and ELV compliance workflows, to the extent enabled and used by Customer.

B. Duration

Continuous for the term of the Agreement, the documented exit/deletion period and any lawful retention period described in Section 12.

C. Nature and purpose

Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission to Customer-authorised providers, restriction, export, anonymisation and deletion, solely to provide, secure, support and improve the contracted service on Customer's instructions.

"Improve" does not authorise training a provider's general-purpose AI model on Customer Personal Data. Any such use requires a separate lawful instruction and appropriate notice/consent where applicable.

D. Categories of Data Subjects

  • Customer's owners, directors, employees, contractors and authorised users;
  • storefront visitors, prospects, buyers and registered members;
  • people submitting enquiries, chat messages, comments, reviews or newsletter registrations;
  • customers' representatives, delivery recipients and company delegates;
  • vehicle owners/holders and other persons appearing in lawful ELV intake, chain-of-custody or certificate records;
  • suppliers, carriers, partners and professional contacts whose data Customer enters; and
  • persons whose images, voices or other identifiers appear in Customer-uploaded content.

E. Categories of personal data

  • identity and contact data: names, email, phone, addresses, signatures and customer identifiers;
  • business/fiscal data: company name, registration and VAT number, representative, bank/IBAN and invoice details;
  • account/security data: username, password hash, role, permissions, MFA data, login/security metadata and audit events;
  • customer/member data: profile, addresses, garage/vehicle preferences, favourites, alerts and consent history;
  • transaction data: enquiries, chats, messages, attachments, carts, reservations, orders, returns, refunds, invoices, delivery and payment-provider references;
  • device/online data: IP address, user agent, pseudonymous hashes, cookie/consent choice, request/API/feed logs, approximate location and device/browser categories;
  • vehicle/ELV data: VIN, registration data, previous-owner/holder reference, photos, intake/custody/treatment/certificate information and supporting documents;
  • content: listings, photos, documents, comments, support content and AI prompts/outputs;
  • employee/operational data: assigned staff, technician identity, actions and notes; and
  • any other personal data Customer chooses to enter consistently with this DPA.

F. Sensitive data

The service is not intended for special categories under Article 9 GDPR, criminal-offence data under Article 10, or data about children. Such data may be processed only under an express written amendment covering necessity, lawful condition and additional safeguards.

G. Frequency

Continuous or as initiated by Customer and its users/Data Subjects.

H. Controller rights and obligations

As stated in the Agreement, DPA and GDPR, including determining purposes/legal bases, giving notices, handling rights, configuring features and issuing lawful instructions.

ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES

1. Access control

  • unique accounts and no shared privileged credentials;
  • role-based access and least privilege;
  • mandatory multi-factor authentication for platform administrators and configurable/required MFA for tenant users;
  • periodic review and prompt removal of access;
  • controlled, logged support impersonation; and
  • confidentiality obligations and security training.

2. Tenant and application security

  • logical tenant separation using tenant identifiers, scoped queries and server-side authorization;
  • permission checks at protected actions and resources;
  • secure password hashing;
  • input validation, output escaping, CSRF protection and rate limiting where appropriate;
  • secure secret/integration-credential handling; and
  • dependency and vulnerability-management process.

3. Encryption and transmission

  • TLS for production browser/API traffic;
  • HTTP-only, secure and same-site cookie attributes where appropriate;
  • encryption at rest for selected high-risk PII fields and integration credentials;
  • managed encryption for production disks/databases/backups where supported; and
  • key access restricted and separated from application data.

4. Logging and monitoring

  • security, API, audit and administrative-event logs proportionate to risk;
  • monitoring of failed jobs/system errors and anomalous activity;
  • protection of logs from unauthorized alteration/access;
  • redaction and payload-size limits for AI/API logs; and
  • enforced retention schedules.

5. Availability, backup and recovery

  • production is hosted on a Hetzner Cloud CX33 virtual private server in Germany; database, application files and DNS remain within the Hetzner environment in the EEA;
  • Hetzner creates daily backups of the server disk with seven rolling restore points; attached volumes, if introduced, require a separate documented backup control;
  • application-level pre-deletion or recovery backups may be retained for up to 90 days;
  • backup access is limited to authorized SYNCDEV personnel, and selected sensitive fields and credentials remain encrypted in backup copies;
  • SYNCDEV maintains a documented restore procedure and undertakes to test it at least annually and after a material infrastructure change, on an isolated server built from a backup image rather than by rebuilding production, recording each test and its result;
  • after any restore into production, erasures recorded after the restore point are re-applied before the service is reopened, so data a Data Subject has already had erased does not silently return;
  • the Administrator SYNCDEV owns recovery decisions, the restoration record and the incident escalation path; and
  • erasure instructions recorded after a backup date are reapplied following any restore.

6. Secure development and change management

  • peer review or equivalent approval for material changes;
  • automated tests for authentication, authorization, tenant isolation, billing and erasure paths;
  • supported dependencies and security updates;
  • separation of production credentials from source code and non-production;
  • no production personal data in development/test unless specifically protected and necessary; and
  • change/incident rollback procedures.

7. Data lifecycle

  • data minimization and field-level retention rules;
  • structured export and rectification functions;
  • deletion/anonymization workflow covering related rows and uploaded files;
  • minimized erasure log for backup replay/accountability;
  • deletion of expired analytics, consent, chat, feed, AI/API payload and backup data by scheduled tasks; and
  • legal holds documented, access-restricted and reviewed.

8. Incident response

  • documented incident triage, containment, investigation, evidence preservation, recovery and notification procedure;
  • the responsible role is Administrator SYNCDEV and the operational incident address is dpa@elvpro.eu;
  • only authorized SYNCDEV personnel have administrative access to the server and backups;
  • critical incidents are escalated outside normal working hours subject to available on-call coverage; no continuous overnight response time is promised;
  • a breach register and post-incident corrective actions are maintained; and
  • Customer notification is made under Section 7 without undue delay after SYNCDEV becomes aware of a personal data breach and, where feasible, within the stated 24-hour operational target measured from that awareness, including by preliminary notice while the investigation continues.

ANNEX 3 — SUBPROCESSOR REGISTER

Effective register date: 1 August 2026

1. Hetzner Online GmbH (Hetzner)

  • Service and purpose: production virtual server, database and file storage, DNS and daily infrastructure backups.
  • Data: all Customer Personal Data stored or transmitted through the core service.
  • Location: Germany, EEA.
  • Status: essential.
  • Transfer basis: no Chapter V transfer for the core German hosting service.
  • Terms: https://www.hetzner.com/legal/terms-and-conditions/ and the data-processing agreement made available by Hetzner.

2. Sendinblue SAS (Brevo)

  • Service and purpose: SMTP relay for transactional, account, support and Customer-initiated email.
  • Data: recipient and sender details, message content, delivery metadata and technical logs.
  • Location: primarily France/Germany in the EEA; limited support or subprocessor access may occur in other countries identified by Brevo.
  • Status: essential for email delivery.
  • Transfer basis: adequacy decision where applicable; otherwise the European Commission Standard Contractual Clauses and supplementary safeguards under Brevo's data-processing terms.
  • Terms: https://www.brevo.com/legal/termsofuse/

3. OpenAI Ireland Ltd. and its listed subprocessors (OpenAI)

  • Service and purpose: optional AI-assisted generation, extraction and classification requested by an authorised Customer user.
  • Data: prompts, selected listing/vehicle/customer context where required, outputs and limited technical metadata. Users are instructed not to submit special-category data or unnecessary personal data.
  • Location: Ireland/EEA and other countries listed in OpenAI's current subprocessor register, which may include the United States.
  • Status: optional; used only when the corresponding AI provider/feature is selected.
  • Transfer basis: adequacy decision where applicable; otherwise Commission Standard Contractual Clauses and supplementary safeguards.
  • Terms: https://openai.com/policies/data-processing-addendum/

4. Anthropic Ireland, Limited and its listed subprocessors (Anthropic)

  • Service and purpose: optional AI-assisted generation, extraction and classification requested by an authorised Customer user.
  • Data: prompts, selected listing/vehicle/customer context where required, outputs and limited technical metadata.
  • Location: Ireland/EEA and other countries listed in Anthropic's current subprocessor register, which may include the United States.
  • Status: optional; used only when the corresponding AI provider/feature is selected.
  • Transfer basis: adequacy decision where applicable; otherwise Commission Standard Contractual Clauses and supplementary safeguards.
  • Terms: https://www.anthropic.com/legal/commercial-terms

5. Google Cloud EMEA Limited and its listed subprocessors (Gemini API)

  • Service and purpose: optional AI-assisted generation, extraction and classification requested by an authorised Customer user.
  • Data: prompts, selected listing/vehicle/customer context where required, outputs and limited technical metadata.
  • Location: EEA and other countries listed in Google's current subprocessor register, which may include the United States.
  • Status: optional; used only when the corresponding AI provider/feature is selected.
  • Transfer basis: adequacy decision where applicable; otherwise Commission Standard Contractual Clauses and supplementary safeguards.
  • Terms: https://cloud.google.com/terms/data-processing-addendum

6. RapidAPI gateway, and the publisher of the Auto Parts Catalog API

Two distinct recipients, not one. Requests are addressed to the RapidAPI marketplace gateway at auto-parts-catalog.p.rapidapi.com, which authenticates them against SYNCDEV's platform key and forwards them to the API publisher that operates the catalogue itself. The publisher's legal entity, establishment and processing location are those stated in the current listing for that API, and are confirmed and recorded by SYNCDEV before the feature is enabled in production; SYNCDEV does not represent them here on the basis of the marketplace listing alone.

  • Service and purpose: gateway and source API for optional VIN decoding, vehicle, parts, OEM and cross-reference catalogue lookups.
  • Data sent: the VIN or the vehicle/part query itself, plus the request metadata any HTTPS call carries (server IP, timestamp, API key). No customer, member, order or staff identifier is sent, and no yard identifier is included in the query. A VIN can relate to an identifiable vehicle keeper and is therefore treated as personal data.
  • Data returned: reference data only — manufacturers, models, engine types, articles, cross-references and specifications.
  • Location: the gateway is operated outside the EEA; the publisher's location is as recorded for the enabled API.
  • Status: optional; used only when the reference-data feature is invoked.
  • Transfer basis: adequacy decision where applicable; otherwise Commission Standard Contractual Clauses and supplementary safeguards.
  • Terms: https://rapidapi.com/privacy/ and the publisher terms displayed for the enabled API.

The optional AI and catalogue services use ELVPro's centrally managed credentials. SYNCDEV remains responsible for the subprocessor relationship under Section 10. The selected provider and feature are recorded in the relevant request/usage record. Customer Personal Data is not authorised for training a provider's general-purpose model.

As of the effective register date, ELVPro does not use Cloudflare, Sentry, an external Redis service or server-side tag delivery in production. Search indexing (Meilisearch) and real-time messaging (Reverb) run on the same Hetzner server as the application, with no third-party service involved. Geolocation uses an offline database held on that server, so no lookup leaves it.

Google and Meta/Facebook social login are enabled at the user's request and generally act as separate controllers for their own identity service; they are recipients described in the Privacy Policy rather than subprocessors under this Annex.

Stripe and SmartBill are used for SYNCDEV's own SaaS subscription payments and fiscal invoicing. They process data for SYNCDEV's separate-controller activities and are therefore listed in the Privacy Policy, not as subprocessors of Customer Personal Data under this DPA.

A yard's payment processor, courier, invoicing provider, analytics service or advertising platform is contracted directly by that yard. ELVPro provides the technical exchange using Customer-configured credentials and acts on Customer's instruction; those providers are not engaged by SYNCDEV as subprocessors under this Annex.

Web push. Where a storefront visitor or member enables browser notifications, the encrypted message is delivered through the push service their own browser vendor operates — Google, Mozilla or Apple, depending on the browser — using the subscription endpoint that browser issued. SYNCDEV holds no account with those services and sends no content in the clear: the payload is encrypted end-to-end under the VAPID keys, and the recipient is identified only by the browser-issued endpoint. They are recipients of that delivery, not processors of Customer Personal Data held in ELVPro.