Data Processing Agreement
Last updated: September 6, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Traceten ("Processor") and the customer identified in the signature block below ("Controller") for the provision of the Traceten analytics service (the "Services"). It applies whenever the Controller's use of the Services involves the processing of personal data subject to the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, or any other applicable data protection law (together, "Data Protection Laws").
1. Definitions
Terms such as "controller", "processor", "data subject", "personal data", "processing", and "supervisory authority" have the meanings given in the GDPR. Other capitalised terms not defined here have the meanings given in the underlying Terms of Service.
2. Subject matter, nature, and purpose of processing
Subject matter: the processing of behavioral analytics data collected from visitors to the Controller's websites in order to detect AI-referred traffic and attribute it to revenue; where the Controller enables AI crawler tracking, the processing of records of automated crawler requests reported by the Controller's own servers; and, where the Controller enables AI answer-engine visibility, the transmission of the Controller's own prompt text to third-party answer engines and the storage of the responses those engines return.
Nature of processing: collection, classification, storage, aggregation, deletion, and disclosure to the Controller through the Services. For the AI answer-engine visibility feature only, the nature of processing additionally includes transmission to third parties (the answer engines listed as planned sub-processors) of text authored by the Controller. That feature is not enabled in any Traceten deployment; see Section 3.
Purpose of processing: providing the Services as described in the Terms of Service.
Duration of processing: for the term of the underlying agreement, plus the retention periods set out in the Privacy Policy, after which the data is deleted.
3. Categories of personal data and data subjects
- Categories of personal data: hashed IP addresses (HMAC-SHA-256 under a key derived per site; raw visitor IPs are never stored), first-party session and visitor identifiers (a cookie value for an anonymous visitor, or a keyed hash of an email address once the Controller identifies one; see the next bullet for the two routes that produce it), user-agent strings, screen size, language, timezone, country and city (both derived from IP at the edge; no postcode, street address, or coordinates is derived from a visitor or stored; a coordinate used to draw a map is taken from a public list at render time and is the city's own point, or the country's where the city is unknown or too small to name), URLs visited, referrers, the domain name (never the path or query string) of an outbound link a visitor followed off the site, behavioral signals (scroll depth, click events, timing, and interaction counts), a coarse device memory class, and, only with visitor consent, WebGL availability and a canvas entropy score.
- Categories of personal data, email addresses: an email address reaches Traceten by two routes, and is stored only as a keyed hash on both. First, when the Controller calls
identify(), where the address is hashed at the edge and the plaintext is discarded before the request returns. Second, on the revenue path, where a connected provider sends the buyer’s address on an order, or the Controller posts one to the Payment API: there it is placed on an internal processing queue and hashed by the consuming process, so the plaintext exists in transit for that window and is never written to the analytics database or to a log. Not every provider sends one: Paddle does not, and Traceten does not request it. Traceten also stores the provider’s own opaque customer, order and subscription identifiers, which are not directly identifying but are personal data by association. - Categories of data subjects: visitors to the Controller's websites.
- AI crawler tracking (optional feature): where the Controller installs the server-side crawler package, Traceten additionally processes, for each request made by an automated crawler to the Controller's site, the requested URL, the response status, the User-Agent string, and the IP address the request came from. The URL is transmitted in full, including any query string. The query string and any fragment are removed on receipt at Traceten's edge, before the record is stored or placed on any queue. The HTTP method is likewise transmitted but is not retained in Traceten's analytics database. Where an IP address is reported it is hashed on receipt (HMAC-SHA-256 under a key derived per site). Where the published-range check does not match and the crawler's claimed vendor supports reverse-DNS verification, the reported address is additionally transmitted to Cloudflare's public DNS resolver as part of that lookup, before the address is verified. The address is also held, in memory only, in a per-instance cache of recent lookups for up to one hour so that repeat lookups for the same address and vendor do not contact the resolver again; that cache is never written to disk and never logged. A holder of a valid crawl token can therefore cause an address of their choosing to be sent to that resolver, by reporting it with a user agent claiming a vendor that supports reverse-DNS verification. Two controls bound this: authentication is mandatory on the crawl endpoint, so the actor is always an identified customer and can be identified and stopped; and the endpoint is rate-limited in its own scope, separate from all other traffic, capping the rate at which it could be done. The lookup cache is deliberately not counted as a control here: it is keyed on the address being looked up, so it prevents repeat lookups of the same address only, and a party submitting a different address each time misses it every time. The address itself is retained only where Traceten has matched it to an IP range the AI vendor publishes for its own crawlers, or to a hostname that vendor's DNS forward-confirms. In every other case Traceten stores only the hash and discards the address; it does not resolve or store the network operator or the country for these requests. That boundary is enforced by a database constraint, not only by application code: a crawl record that is not network-verified is rejected if it carries an address. Traceten currently applies the rule more narrowly than the constraint requires, discarding the address where the only evidence is a third-party routing database rather than the vendor's own published range. Individual crawl records are deleted after 90 days on every plan; the daily totals derived from them carry no address, no hash, and no identifier of any person, and are retained until the account is closed. One of those two daily totals is grouped by the requested page path, so page paths from crawl records persist in aggregate beyond the 90-day life of the records themselves.
- AI answer-engine visibility (optional feature, not currently enabled): this feature does not process visitor data at all, and no data collected from the Controller's websites is transmitted under it. What is transmitted is text the Controller authored: a list of questions the Controller configures, sent on a schedule to third-party answer engines, together with a location signal derived from the language and region the Controller set on each question: an approximate country for the three sent as chat requests, and a location code, a language code and a fixed device and operating-system profile for the one sent as a search query. No visitor or session identifier, no cookie, no IP address or hash of one, no page URL and no account or site identifier is sent. A question is limited to 2,000 characters and is otherwise transmitted as written, so the Controller must not place personal data in one; Traceten's retention limits and deletion tooling do not reach inside a recipient's systems. Traceten stores each engine's response verbatim, up to 100,000 characters, together with its list of cited sources, up to 100 entries with titles up to 512 characters. Both are unredacted prose authored by the third-party engine and may name natural persons who are neither the Controller's visitors nor its customers; Traceten neither authors nor filters that text. Responses and their source lists are deleted after 90 days, derived mention and citation records after 365 days, and daily counts are retained until the account is closed. None of those records carries a visitor identifier, a session identifier or an IP address in any form, so a data subject request keyed on any of those cannot reach them. The feature is gated by two deployment-level switches, both currently off; the recipient engines are listed in the Planned section of the sub-processors page and are not authorised under Section 8 until they are promoted to the active list.
- Special categories of personal data: none. The Services are not designed to process special categories of data under GDPR Art. 9, and the Controller must not configure the Services to do so.
4. Roles of the parties
With respect to visitor data, the Controller is the controller and Traceten is the processor. Traceten processes personal data only on documented instructions from the Controller, which include the Terms of Service, this DPA, the configuration of the Services by the Controller, and any further written instructions consistent with the Services.
5. Controller obligations
The Controller will:
- Establish a lawful basis under Data Protection Laws for the processing carried out through the Services, and obtain any consents required (including under the EU ePrivacy Directive where the use of cookies requires it).
- Provide data subjects with the information required by Articles 13 and 14 GDPR, including the categories of recipients (Traceten, its sub-processors, and any other recipients identified in Section 3).
- Configure the Services so that the Controller does not transmit special categories of personal data, payment card data, or government identifiers to Traceten.
- Promptly forward any data subject requests it cannot resolve directly, so that Traceten can assist as described in Section 9.
6. Processor obligations
Traceten will:
- Process personal data only on the Controller's documented instructions, including with regard to international transfers, unless required to do so by Union or Member State law (in which case Traceten will, where lawful, inform the Controller before processing).
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement and maintain the technical and organisational security measures described in Section 7.
- Engage sub-processors only as permitted under Section 8.
- Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to data subject requests under Articles 12 to 22 GDPR.
- Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Traceten.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller to meet its own notification obligations under Articles 33 and 34 GDPR.
- On termination of the Services, delete or return all personal data to the Controller as described in Section 11.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 10.
7. Security measures
Traceten implements the following technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage:
- Encryption in transit: TLS 1.2 or higher between the snippet, the edge ingestion layer, and all internal services.
- Encryption at rest: ClickHouse Cloud and Postgres both encrypt stored data.
- IP minimisation at the edge: raw IP addresses are hashed (HMAC-SHA-256 under a key derived per site) at the Cloudflare Workers edge layer. Raw visitor IPs never reach the analytics database, persistent logs, or disk. The single exception is the optional AI crawler tracking feature described in section 3: where a crawler's address matches an IP range the AI vendor publishes for its own crawlers, or a hostname that vendor's DNS forward-confirms, that address is retained with the crawl record for 90 days. Every other crawler address is discarded and only its hash is kept.
- Credential protection: API keys are stored as two one-way hashes of the same key, Argon2id and SHA-256, and server-side crawl tokens as a SHA-256 hash. All are 256-bit random values and none is recoverable from what Traceten stores. Secrets that must be usable again are stored as AES-256-GCM ciphertext under a 256-bit key held as a deployment secret, never in source or in the database: credentials for connected integrations (a pasted Stripe restricted key, a Lemon Squeezy or Paddle API key, a Polar organization access token, a Shopify OAuth access token); the signing secret for the webhook endpoint Traceten creates at connect (returned by the provider for Stripe and Paddle, and generated by Traceten for Lemon Squeezy and Polar, read once at creation either way); and the signing secret for each outbound webhook the Customer configures. Shopify has no per-connection signing secret. These secrets are not wrapped by a key-management service and the key is not customer-managed.
- Access control: least-privilege access to production systems, enforced by SSO and hardware-key MFA.
- Logging and monitoring: centralised, integrity-protected audit logs; alerts on anomalous access patterns; secret-pattern scrubbing in application logs.
- Software supply chain: dependency vulnerability scanning, signed deploys, infrastructure-as-code reviewed under multi-party approval.
- Vendor management: sub-processors are contractually bound to security obligations no less protective than those in this DPA.
- Backups and recovery: regular backups with documented restore procedures; periodic restore tests.
- Personnel: background checks where lawful, security and privacy training on hire and annually thereafter, written confidentiality obligations.
Traceten may update these measures from time to time, provided the level of protection does not materially decrease.
8. Sub-processors
The Controller authorises Traceten to engage the active sub-processors listed at /legal/sub-processors. Providers shown in the Planned section of that page are not yet processing personal data and are listed for advance notice only; they are not authorised until they move to the active list. Traceten will provide at least 30 days' prior notice of the addition or replacement of a sub-processor that processes personal data (including the promotion of a planned sub-processor to active) by updating that page and notifying the Controller's primary administrative contact by email.
The Controller may object on reasonable grounds related to data protection within the notice period. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the Services with prorated refund of prepaid fees as its sole remedy.
Traceten remains responsible for the acts and omissions of its sub-processors with respect to personal data to the same extent as for its own acts and omissions.
9. Data subject requests
Taking into account the nature of the processing, Traceten will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to data subject requests for access, rectification, erasure, restriction, portability, and objection.
The Controller can submit deletion requests at privacy@traceten.com. Traceten will action verified requests across all production storage within 30 days.
If a data subject contacts Traceten directly, Traceten will, without undue delay, forward the request to the Controller and instruct the data subject to contact the Controller, except where Data Protection Laws require Traceten to act directly.
10. Audits
Traceten will make available to the Controller, on reasonable written request and no more than once per twelve-month period (or more often if required by a supervisory authority or following a personal data breach), the information necessary to demonstrate compliance with this DPA. This may take the form of Traceten's most recent SOC 2 Type II report, ISO 27001 certificate, or equivalent third-party assessment under appropriate confidentiality obligations.
On-site audits are available to enterprise customers under a separately agreed scope, notice period, and confidentiality terms, and at the Controller's expense.
11. Return or deletion on termination
On termination or expiry of the Services, Traceten will, at the Controller's choice, delete or return all personal data and delete existing copies, unless Union or Member State law requires storage of the personal data. Deletion begins 30 days after termination (see the recovery window below) and completes without undue delay thereafter, except where data is held in encrypted backups with documented destruction schedules; such backups are isolated from production access and are deleted in accordance with our retention schedule, after which the data cannot be restored.
The Controller can exercise this directly in the Traceten dashboard, at the level of a single property or of the whole account. Deleting a site, or closing the account, stops the collection of new analytics data for the affected sites immediately, and all personal data for those sites is erased 30 days later. The request is reversible for the duration of that window and irreversible afterwards. The window exists to protect the Controller against accidental or unauthorised deletion; Traceten will waive it and erase sooner on written request to privacy@traceten.com.
12. International transfers
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree to be bound by the EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), which are incorporated into this DPA by reference. The optional docking clause applies. For UK transfers, the parties additionally rely on the UK International Data Transfer Addendum issued under Section 119A of the UK Data Protection Act 2018.
The annexes to the SCCs are populated as follows:
- Annex I.A (Parties): Controller is the customer named in the signature block below; Processor is Traceten, [address].
- Annex I.B (Description of transfer): as set out in Sections 2 and 3 of this DPA.
- Annex I.C (Competent supervisory authority): the supervisory authority of the EU Member State where the Controller's representative is established, or where the data subjects are located.
- Annex II (Technical and organisational measures): as set out in Section 7 of this DPA.
- Annex III (Sub-processors): the active sub-processors published at /legal/sub-processors. Providers in the Planned section of that page are not agreed sub-processors under these Clauses until they are promoted to the active list in accordance with Section 8.
13. Liability and term
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the underlying Terms of Service. This DPA takes effect on the date the Controller signs the signature block below (or the effective date of the underlying agreement, whichever is later) and remains in force for as long as Traceten processes personal data on the Controller's behalf.
14. Order of precedence
In the event of conflict between this DPA, the SCCs, and the underlying Terms of Service, the SCCs prevail in respect of cross-border transfers, then this DPA, then the Terms of Service.
15. Signature block
To request a signed copy of this DPA, email legal@traceten.com with your company name, Traceten account email, and the legal entity that will be signing. We will return a counter-signed copy within five business days.
Controller
Company name: ____________________________________
Address: ___________________________________________
Authorised representative (name and title): __________________
Signature: _________________________________________
Date: ____________________
Processor
Traceten, [address]
Authorised representative (name and title): __________________
Signature: _________________________________________
Date: ____________________