Data Processing Agreement
Last updated: October 7, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Rafa Marco, 334******, Calderón de la Barca, 42 · 03201 Elche (Alicante), Spain ("Processor"), and applies to personal data processed on behalf of the Controller under Article 28 GDPR.
1. Subject matter and duration
The Processor provides web analytics. Processing lasts for the duration of the Terms and ends with the deletion of the data as described in section 9.
2. Nature and purpose
Collection, aggregation, storage and presentation of website usage statistics for the Controller.
3. Categories of data and data subjects
- Data subjects: visitors of the Controller's websites; members of the Controller's workspaces.
- Data: page URLs, referrers, screen width, browser language, derived country, device, browser and operating system, event names and properties sent by the Controller, and a daily-rotating pseudonymous hash. IP addresses and user agents are processed transiently in memory and never stored.
The Controller shall not send special categories of data or direct identifiers as event properties.
4. Processor obligations
The Processor shall:
- process data only on documented instructions of the Controller, including these Terms and the Controller's configuration of the service;
- ensure that authorised personnel are bound by confidentiality;
- implement the technical and organisational measures in Annex I;
- assist the Controller in responding to data subject requests and in meeting its obligations under Articles 32–36 GDPR;
- notify the Controller without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach;
- make available the information necessary to demonstrate compliance and allow for audits, at the Controller's cost, with reasonable notice and no more than once per year unless required by a supervisory authority.
5. Sub-processors
The Controller grants general authorisation to engage sub-processors. The current list:
| Sub-processor | Purpose | Location |
|---|---|---|
| Banahosting | Hosting and storage | Europe |
| Banahosting | Transactional email | Europe |
| Stripe Payments Europe, Ltd. | Billing (customer account data only) | Ireland |
The Processor will inform the Controller of intended changes at least 30 days in advance; the Controller may object on reasonable grounds and terminate the affected service.
6. International transfers
Analytics data is stored in the EU. Any transfer outside the EEA relies on an adequacy decision or the Standard Contractual Clauses.
7. Controller obligations
The Controller is responsible for the lawfulness of the processing, for informing data subjects and for the content of the events it sends.
8. Liability
Liability is governed by the Terms of Service and Article 82 GDPR.
9. Return and deletion
The Controller may export reports at any time. Upon deletion of a site or workspace, or termination, data is deleted from the live systems immediately and from backup copies within 30 days, except where retention is required by law.
Annex I — Technical and organisational measures
- Encryption in transit (TLS) and encryption of third-party credentials at rest.
- No storage of IP addresses; daily-rotating salts deleted after use.
- Role-based access control, mandatory per-workspace isolation, audit log of administrative actions.
- Two-factor authentication available to all users; account lockout after repeated failed logins.
- Backups, monitoring of queues and scheduled tasks, and dependency updates.
- Data minimisation: raw events retained only for the plan's retention period.
Contact
Data protection requests: our contact form