Skip to content
Features Integrations Pricing Docs

Data Processing Agreement

Last updated: October 7, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Rafa Marco, 334******, Calderón de la Barca, 42 · 03201 Elche (Alicante), Spain ("Processor"), and applies to personal data processed on behalf of the Controller under Article 28 GDPR.

1. Subject matter and duration

The Processor provides web analytics. Processing lasts for the duration of the Terms and ends with the deletion of the data as described in section 9.

2. Nature and purpose

Collection, aggregation, storage and presentation of website usage statistics for the Controller.

3. Categories of data and data subjects

  • Data subjects: visitors of the Controller's websites; members of the Controller's workspaces.
  • Data: page URLs, referrers, screen width, browser language, derived country, device, browser and operating system, event names and properties sent by the Controller, and a daily-rotating pseudonymous hash. IP addresses and user agents are processed transiently in memory and never stored.

The Controller shall not send special categories of data or direct identifiers as event properties.

4. Processor obligations

The Processor shall:

  1. process data only on documented instructions of the Controller, including these Terms and the Controller's configuration of the service;
  2. ensure that authorised personnel are bound by confidentiality;
  3. implement the technical and organisational measures in Annex I;
  4. assist the Controller in responding to data subject requests and in meeting its obligations under Articles 32–36 GDPR;
  5. notify the Controller without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach;
  6. make available the information necessary to demonstrate compliance and allow for audits, at the Controller's cost, with reasonable notice and no more than once per year unless required by a supervisory authority.

5. Sub-processors

The Controller grants general authorisation to engage sub-processors. The current list:

Sub-processor Purpose Location
Banahosting Hosting and storage Europe
Banahosting Transactional email Europe
Stripe Payments Europe, Ltd. Billing (customer account data only) Ireland

The Processor will inform the Controller of intended changes at least 30 days in advance; the Controller may object on reasonable grounds and terminate the affected service.

6. International transfers

Analytics data is stored in the EU. Any transfer outside the EEA relies on an adequacy decision or the Standard Contractual Clauses.

7. Controller obligations

The Controller is responsible for the lawfulness of the processing, for informing data subjects and for the content of the events it sends.

8. Liability

Liability is governed by the Terms of Service and Article 82 GDPR.

9. Return and deletion

The Controller may export reports at any time. Upon deletion of a site or workspace, or termination, data is deleted from the live systems immediately and from backup copies within 30 days, except where retention is required by law.

Annex I — Technical and organisational measures

  • Encryption in transit (TLS) and encryption of third-party credentials at rest.
  • No storage of IP addresses; daily-rotating salts deleted after use.
  • Role-based access control, mandatory per-workspace isolation, audit log of administrative actions.
  • Two-factor authentication available to all users; account lockout after repeated failed logins.
  • Backups, monitoring of queues and scheduled tasks, and dependency updates.
  • Data minimisation: raw events retained only for the plan's retention period.

Contact

Data protection requests: our contact form