Company and legal
Data Processing Agreement
This agreement describes how DataVisitors would process customer personal data, follow instructions, protect information, and assist with privacy obligations. The schedules identify the intended processing scope.
Policy review copy · Revised 8 September 2026
Document status and parties
Last revised: 8 September 2026. Status: proposed Data Processing Agreement. Legal review: not yet recorded. This version has no effective date.
This review copy requires the customer's details, the DataVisitors operator's legal identity, and the applicable service agreement before execution. Reading or downloading this page does not execute an agreement or authorize a new subprocessor.
“Customer” means the organization identified in the completed service agreement. “DataVisitors” means the operator identified there. “Customer Personal Data” means personal data DataVisitors processes on the customer's behalf through the service.
Roles and applicable law
The customer normally acts as controller for analytics collected from its websites, applications, or users. DataVisitors acts as processor for that instructed processing.
If the customer acts as processor for another controller, it must have authority to appoint DataVisitors as a further processor. References to customer instructions include the instructions that the customer can lawfully pass through.
This agreement addresses the relevant requirements of applicable data protection law. References to EU or UK GDPR apply only to processing within that law's scope. Account administration that DataVisitors performs as a separate controller is described in the Privacy Policy.
Scope, duration, and priority
The subject matter is the provision of the analytics service described in the service agreement and Schedule A below. Processing continues for the service term and the return or deletion period required by the completed agreement or applicable law.
This agreement governs Customer Personal Data if a general service term conflicts with it. Mandatory law and any applicable, validly executed transfer clauses take precedence over inconsistent terms.
No customer data ownership transfers to DataVisitors through this agreement.
Documented customer instructions
DataVisitors shall process Customer Personal Data only on documented customer instructions, including instructions about transfers, unless applicable law requires otherwise.
Instructions include the completed service agreement, enabled project settings, lawful API requests, and authorized support requests. A request outside the supported service can require separate written agreement about scope and cost.
If a legal obligation requires processing outside the customer's instructions, DataVisitors shall inform the customer beforehand unless the law prohibits that notice. DataVisitors shall inform the customer if an instruction appears to violate applicable data protection law.
Customer responsibilities
The customer shall establish the lawful basis for its collection and instructions. It shall provide appropriate notices, obtain consent where necessary, and configure the service consistently with those choices.
The customer shall limit submissions to information necessary for its stated analytics purposes. It shall control its authorized users, integration keys, external destinations, and optional identified-data settings.
The customer shall not submit sensitive categories of data or information about children requiring special safeguards without a separate, suitable processing arrangement. Product filtering does not transfer the customer's collection responsibilities to DataVisitors.
Confidentiality and personnel
DataVisitors shall limit access to personnel who need it for the instructed service, security, or support. It shall ensure those personnel have an appropriate confidentiality obligation or applicable legal duty of confidentiality.
Access shall reflect assigned responsibilities. Confidentiality duties continue after the relevant person no longer needs access, subject to applicable law.
Security measures
DataVisitors shall maintain technical and organizational measures appropriate to the risk, taking account of the data and the processing circumstances. Schedule B identifies the implemented application controls and the operational details that require completion.
Measures shall address unauthorized access, unlawful processing, accidental loss, destruction, and damage. A material change must not reduce protection below the requirements of the completed agreement and applicable law.
A software feature, security review, or deployment setting is not a certification or an unconditional security warranty.
Subprocessor authorization
DataVisitors shall not appoint a subprocessor for Customer Personal Data without the customer's prior specific or general written authorization, as recorded in the completed agreement.
Under general authorization, DataVisitors shall give advance written notice of intended additions or replacements. The completed order must state the notice method and a reasonable objection period. Notice must identify the provider, function, processing location, and relevant safeguards.
The customer can object on reasonable data protection grounds. The parties shall seek an alternative or another documented resolution before the disputed processing begins. This review copy grants no blanket authorization to an unverified provider list.
Subprocessor obligations and responsibility
DataVisitors shall assess the suitability of an authorized subprocessor and enter an appropriate written contract. That contract shall impose data protection obligations consistent with this agreement for the relevant processing.
DataVisitors remains responsible to the customer for the performance of those subprocessor obligations as required by applicable law. The subprocessor disclosure becomes the operational reference only after its named entries and authorization are completed.
A payment provider or other recipient can act as a separate controller for some functions. The completed register must identify the actual role instead of labeling every external company a subprocessor.
International transfers
DataVisitors shall not make an international transfer of Customer Personal Data without a lawful mechanism where one is required. A hosting location alone does not establish whether remote support or further processing creates a transfer.
The completed processing record must identify relevant destinations, recipient roles, and safeguards. Where standard contractual clauses or a UK transfer instrument apply, the parties must complete the appropriate instrument and annexes.
This review copy does not execute transfer clauses, name a data importer, or make an adequacy determination. The customer may request information necessary to understand the applicable safeguards.
Individual rights requests
Taking account of the processing, DataVisitors shall assist the customer with appropriate measures for responding to individuals' rights requests. The service's available export, correction, trait-deletion, and event-erasure functions form part of that assistance.
If DataVisitors receives a request concerning Customer Personal Data, it shall notify the customer and follow lawful instructions. It shall not decide the request on the customer's behalf unless authorized or required by law.
The customer remains responsible for deciding the request, verifying the individual appropriately, and meeting its applicable response deadline.
Personal data breaches
DataVisitors shall notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
The notice shall provide available information about the nature of the breach, affected data and individuals, likely consequences, response measures, and a contact. DataVisitors may provide information in stages as the investigation progresses.
DataVisitors shall take appropriate steps to contain and investigate the incident and cooperate with the customer's lawful response. The customer remains responsible for its own required notifications to authorities and individuals, unless the law provides otherwise.
A processor's notification duty is not a promise that every investigation will finish within a fixed number of hours.
Impact assessments and regulator assistance
Taking account of the nature of processing and available information, DataVisitors shall provide reasonable assistance with required security assessments, data protection impact assessments, and prior consultation with authorities.
The parties shall coordinate the scope of information and protect confidential material. Any separately agreed charges for additional assistance must not prevent DataVisitors from meeting a mandatory legal obligation.
Return and deletion
At the customer's choice, DataVisitors shall return or delete Customer Personal Data after the relevant processing service ends, unless applicable law requires storage. The completed agreement must identify the export format, request channel, and applicable completion periods.
The customer should request supported exports before terminating access. An aggregate report is not necessarily a complete export of every original event or account record. The parties must identify any additional return requirement before agreeing to it.
Trait deletion and event erasure are separate operations. Account closure does not automatically erase all organization data. DataVisitors shall explain relevant dependencies and carry out the applicable instructions.
Backups, copies, and required retention
The completed agreement must state the backup retention window and handling of replicas. This review copy does not promise immediate removal from every backup or publish an unverified backup schedule.
Where law requires continued storage, DataVisitors shall identify that obligation where legally permitted, limit further processing to the permitted purpose, and delete data when the obligation ends.
The backup procedure must prevent restored data from returning to ordinary use after a valid deletion instruction without reapplying the required deletion. Copies exported to customer-controlled destinations remain under the customer's control.
Evidence, audits, and inspections
DataVisitors shall make available information necessary to demonstrate compliance with the applicable processor obligations. It shall allow and contribute to audits and inspections by the customer or an appropriately authorized auditor.
The parties shall use reasonable arrangements for scope, notice, confidentiality, security, and protection of other customers. Those arrangements must not prevent an audit or inspection that applicable law requires.
Existing evidence can reduce duplicate work where it adequately answers the request. A review copy or a passed software test does not replace a required audit.
Schedule A: processing description
Purpose: collect customer-authorized activity and produce analytics, goals, funnels, retention reports, permitted individual views, revenue reports, alerts, and exports.
Nature: receive, validate, reduce, store, organize, query, aggregate, display, transmit as instructed, and delete or return data.
Individuals: visitors to customer websites, users of customer applications, customer-supplied identified users, and authorized users whose details appear in submitted analytics.
Data categories: event names and timestamps; page or screen paths; source and campaign values; coarse device, browser, locale, and location categories; permitted identifiers; event properties; engagement; and revenue amounts with currency.
Optional categories: customer-supplied profile traits, click coordinates and viewport dimensions for enabled heatmaps, and configured notification destinations.
Collection frequency: ongoing while a customer integration sends events, or in batches for supported imports. Identified collection and optional features depend on customer configuration and the applicable consent state.
Sensitive data: excluded from the ordinary service scope unless a separate agreement establishes the required purpose and safeguards.
Duration: the service term plus the completed retention, return, or deletion arrangements. Analytics retention follows the selected project and plan. Trait retention follows the rule described in the Privacy Policy.
Schedule B: application safeguards
Implemented application controls include:
- Organization authorization and role checks for access to customer resources.
- Signed session-bound interface state and refusal of unauthorized browser changes.
- Revocable login sessions, API keys, and supported application grants.
- Password hashing and restricted handling of authentication secrets.
- Privacy transformations before analytics storage and filtering of ordinary event properties.
- Explicit controls for individual views, identified traits, and optional heatmap collection.
- Aggregate-only public share surfaces with revocable access.
- Audit records for supported administrative and privacy-sensitive operations.
- Retention rules, privacy exports, trait deletion, event erasure, and account closure workflows.
The final operational schedule must also confirm hosting security, transport configuration, personnel procedures, incident handling, backups, restoration tests, and processor access. These are deployment responsibilities that source code alone cannot certify.
Schedule C: details required for execution
The completed agreement must record:
- The legal names, addresses, roles, and authorized contacts of both parties.
- The governing service agreement and applicable data protection law.
- The approved subprocessor register and change-notice procedure.
- The processing locations and any required transfer instruments.
- The incident contact, return and deletion periods, and backup-removal schedule.
- The applicable operational security schedule and the acceptance or signature record.
Request completion through [[email protected]](mailto:[email protected]). Read the Privacy Policy, Security, and Terms of Service with this document.