Data Processing Agreement
Last updated: July 28, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Traceten ("Processor") and the customer identified in the signature block below ("Controller") for the provision of the Traceten analytics service (the "Services"). It applies whenever the Controller's use of the Services involves the processing of personal data subject to the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, or any other applicable data protection law (together, "Data Protection Laws").
1. Definitions
Terms such as "controller", "processor", "data subject", "personal data", "processing", and "supervisory authority" have the meanings given in the GDPR. Other capitalised terms not defined here have the meanings given in the underlying Terms of Service.
2. Subject matter, nature, and purpose of processing
Subject matter: the processing of behavioral analytics data collected from visitors to the Controller's websites in order to detect AI-referred traffic and attribute it to revenue.
Nature of processing: collection, classification, storage, aggregation, deletion, and disclosure to the Controller through the Services.
Purpose of processing: providing the Services as described in the Terms of Service.
Duration of processing: for the term of the underlying agreement, plus the retention periods set out in the Privacy Policy, after which the data is deleted.
3. Categories of personal data and data subjects
- Categories of personal data: hashed IP addresses (HMAC-SHA-256 with a per-site salt; raw IPs are never stored), first-party session and visitor cookie identifiers, user-agent strings, screen size, language, timezone, country and city (both derived from IP at the edge; no postcode, street address, or coordinates is derived or stored), URLs visited, referrers, behavioral signals (scroll depth, click events, timing, and interaction counts), a coarse device memory class, and, only with visitor consent, WebGL availability and a canvas entropy score.
- Categories of data subjects: visitors to the Controller's websites.
- Special categories of personal data: none. The Services are not designed to process special categories of data under GDPR Art. 9, and the Controller must not configure the Services to do so.
4. Roles of the parties
With respect to visitor data, the Controller is the controller and Traceten is the processor. Traceten processes personal data only on documented instructions from the Controller, which include the Terms of Service, this DPA, the configuration of the Services by the Controller, and any further written instructions consistent with the Services.
5. Controller obligations
The Controller will:
- Establish a lawful basis under Data Protection Laws for the processing carried out through the Services, and obtain any consents required (including under the EU ePrivacy Directive where the use of cookies requires it).
- Provide data subjects with the information required by Articles 13 and 14 GDPR, including the categories of recipients (Traceten and its sub-processors).
- Configure the Services so that the Controller does not transmit special categories of personal data, payment card data, or government identifiers to Traceten.
- Promptly forward any data subject requests it cannot resolve directly, so that Traceten can assist as described in Section 9.
6. Processor obligations
Traceten will:
- Process personal data only on the Controller's documented instructions, including with regard to international transfers, unless required to do so by Union or Member State law (in which case Traceten will, where lawful, inform the Controller before processing).
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement and maintain the technical and organisational security measures described in Section 7.
- Engage sub-processors only as permitted under Section 8.
- Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to data subject requests under Articles 12 to 22 GDPR.
- Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Traceten.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller to meet its own notification obligations under Articles 33 and 34 GDPR.
- On termination of the Services, delete or return all personal data to the Controller as described in Section 11.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 10.
7. Security measures
Traceten implements the following technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage:
- Encryption in transit: TLS 1.3 between the snippet, the edge ingestion layer, and all internal services.
- Encryption at rest: ClickHouse Cloud and Postgres both encrypt stored data.
- IP minimisation at the edge: raw IP addresses are hashed (HMAC-SHA-256 with a per-site salt) at the Cloudflare Workers edge layer. Raw IPs never reach the analytics database, persistent logs, or disk.
- Credential protection: OAuth tokens are encrypted with envelope encryption (KMS); API keys are stored as Argon2id hashes.
- Access control: least-privilege access to production systems, enforced by SSO and hardware-key MFA.
- Logging and monitoring: centralised, integrity-protected audit logs; alerts on anomalous access patterns; secret-pattern scrubbing in application logs.
- Software supply chain: dependency vulnerability scanning, signed deploys, infrastructure-as-code reviewed under multi-party approval.
- Vendor management: sub-processors are contractually bound to security obligations no less protective than those in this DPA.
- Backups and recovery: regular backups with documented restore procedures; periodic restore tests.
- Personnel: background checks where lawful, security and privacy training on hire and annually thereafter, written confidentiality obligations.
Traceten may update these measures from time to time, provided the level of protection does not materially decrease.
8. Sub-processors
The Controller authorises Traceten to engage the active sub-processors listed at /legal/sub-processors. Providers shown in the Planned section of that page are not yet processing personal data and are listed for advance notice only; they are not authorised until they move to the active list. Traceten will provide at least 30 days' prior notice of the addition or replacement of a sub-processor that processes personal data — including the promotion of a planned sub-processor to active — by updating that page and notifying the Controller's primary administrative contact by email.
The Controller may object on reasonable grounds related to data protection within the notice period. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the Services with prorated refund of prepaid fees as its sole remedy.
Traceten remains responsible for the acts and omissions of its sub-processors with respect to personal data to the same extent as for its own acts and omissions.
9. Data subject requests
Taking into account the nature of the processing, Traceten will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to data subject requests for access, rectification, erasure, restriction, portability, and objection.
The Controller can submit deletion requests at legal@traceten.com. Traceten will action verified requests across all production storage within 30 days.
If a data subject contacts Traceten directly, Traceten will, without undue delay, forward the request to the Controller and instruct the data subject to contact the Controller, except where Data Protection Laws require Traceten to act directly.
10. Audits
Traceten will make available to the Controller, on reasonable written request and no more than once per twelve-month period (or more often if required by a supervisory authority or following a personal data breach), the information necessary to demonstrate compliance with this DPA. This may take the form of Traceten's most recent SOC 2 Type II report, ISO 27001 certificate, or equivalent third-party assessment under appropriate confidentiality obligations.
On-site audits are available to enterprise customers under a separately agreed scope, notice period, and confidentiality terms, and at the Controller's expense.
11. Return or deletion on termination
On termination or expiry of the Services, Traceten will, at the Controller's choice, delete or return all personal data and delete existing copies, unless Union or Member State law requires storage of the personal data. Deletion will be completed within 30 days of termination, except where data is held in encrypted backups with documented destruction schedules; such backups are isolated from production access and are deleted in accordance with our retention schedule, after which the data cannot be restored.
12. International transfers
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree to be bound by the EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), which are incorporated into this DPA by reference. The optional docking clause applies. For UK transfers, the parties additionally rely on the UK International Data Transfer Addendum issued under Section 119A of the UK Data Protection Act 2018.
The annexes to the SCCs are populated as follows:
- Annex I.A (Parties): Controller is the customer named in the signature block below; Processor is Traceten, [address].
- Annex I.B (Description of transfer): as set out in Sections 2 and 3 of this DPA.
- Annex I.C (Competent supervisory authority): the supervisory authority of the EU Member State where the Controller's representative is established, or where the data subjects are located.
- Annex II (Technical and organisational measures): as set out in Section 7 of this DPA.
- Annex III (Sub-processors): the active sub-processors published at /legal/sub-processors. Providers in the Planned section of that page are not agreed sub-processors under these Clauses until they are promoted to the active list in accordance with Section 8.
13. Liability and term
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the underlying Terms of Service. This DPA takes effect on the date the Controller signs the signature block below (or the effective date of the underlying agreement, whichever is later) and remains in force for as long as Traceten processes personal data on the Controller's behalf.
14. Order of precedence
In the event of conflict between this DPA, the SCCs, and the underlying Terms of Service, the SCCs prevail in respect of cross-border transfers, then this DPA, then the Terms of Service.
15. Signature block
To request a signed copy of this DPA, email legal@traceten.com with your company name, Traceten account email, and the legal entity that will be signing. We will return a counter-signed copy within five business days.
Controller
Company name: ____________________________________
Address: ___________________________________________
Authorised representative (name and title): __________________
Signature: _________________________________________
Date: ____________________
Processor
Traceten, [address]
Authorised representative (name and title): __________________
Signature: _________________________________________
Date: ____________________