Legal
Data Processing Agreement
A Data Processing Agreement (DPA) template, in accordance with Art. 28 GDPR, for the relationship between Analytics and customers who use the service to collect data about their own sites' visitors.
This is a template, not legal advice.
The document below is a general model, provided as a starting point. It does not constitute legal advice and does not replace a signed contract. We recommend that any site owner relying on this document review it with their own legal counsel before using it or attaching it to an actual contract.
1.Subject Matter and Duration
This Agreement governs the processing of personal data carried out by Analytics (the “Processor”) on behalf of the customer (the “Controller”), in connection with the provision of the web analytics service. The Agreement takes effect on the date the account is activated and remains valid for the entire duration of the service's use, as well as for the subsequent period necessary to fulfill the data deletion or return obligations described in Section 8.
2.Nature and Purpose of Processing
The Processor processes data on behalf of the Controller solely for the purpose of providing the contracted web analytics service: collecting, aggregating, and displaying statistics about traffic and usage of the Controller's site(s) (pageviews, events, traffic sources, conversions, attributed revenue, journeys, funnels).
Processing is limited to the technical operations necessary for this purpose: collection via the tracking script, storage, statistical aggregation, approximate IP-based geolocation (without retaining the raw IP), and display in the dashboard.
3.Categories of Data Subjects and Categories of Data
Data subjects: visitors to the Controller's site(s).
Categories of data: a locally generated (non-cookie) visitor identifier, pages visited, referrer and UTM parameters, approximate country / region / city derived from IP, device type, browser, operating system, and, if the Controller connects billing, conversion/revenue events associated with a visitor session. No special categories of data (Art. 9 GDPR) are processed.
4.Obligations of the Processor
- processes data solely in accordance with the Controller's documented instructions and for the purpose described in Section 2;
- ensures confidentiality by imposing confidentiality obligations on any person authorized to process the data;
- implements appropriate technical and organizational measures (Art. 32 GDPR) to ensure the security of processing;
- assists the Controller in fulfilling its obligations regarding data subject rights and the security of processing;
- makes available to the Controller the information necessary to demonstrate compliance with this Agreement.
5.Sub-processors
The Controller grants general authorization for the Processor to engage sub-processors for specific technical operations (hosting and database, transactional email delivery, payment processing). The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
The Processor informs the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such a change for reasonable data-protection grounds.
6.Assistance with Data Subject Rights
Taking into account the nature of the processing, the Processor assists the Controller, through appropriate technical and organizational measures, in fulfilling its obligation to respond to requests for the exercise of data subject rights (right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object) set out in Chapter III GDPR.
7.Personal Data Breach Notification
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the data processed under this Agreement, and provides the information reasonably available to enable the Controller to fulfill its own notification obligations, where applicable, under Art. 33-34 GDPR.
8.Deletion or Return of Data upon Termination
Upon termination of the service, at the Controller's choice, the Processor deletes or returns to the Controller all personal data processed under this Agreement and deletes existing copies, unless applicable law requires continued storage of that data.
9.Audit and Information
The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in this Agreement, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, within reasonable limits and upon prior notice.
10.Final Provisions
This document is a general template and does not, by itself, constitute a signed agreement. Any element specific to the contractual relationship between the Controller and the Processor (exact terms, notification contacts, governing law, technical annexes) is to be completed by the parties before use.
Want details about the data we collect?
Our GDPR compliance page explains, in plain language, exactly what data we collect, how we use IP addresses for geolocation, and how long we retain data.
View the GDPR page