Legal

Data processing agreement

Summary of the processor terms that apply to customer event data. The full agreement is provided during onboarding and on request.

Last updated: 2026-09-03

Subject matter

Collection, normalization, consent evaluation, storage and delivery of website and server events to destinations configured by the customer, plus dashboards, diagnostics and the setup assistant.

Instructions

The customer instructs the operator through the product configuration: sites, destinations, mappings, consent policy and retention. Configuration versions are signed and auditable, so instructions are documented.

Technical and organizational measures

See the security page: tenant isolation with row-level security, envelope encryption, signed configuration, kill switches, PII scanning, truncated IPs, RBAC with MFA, audit trail, EU hosting.

Subprocessors

Listed on the subprocessors page; customers are informed about changes 30 days in advance and may object.

Data subject requests and deletion

The privacy center processes export and deletion requests against pseudonymous identifiers across all sites of the organization and records the outcome. Retention runs delete data at the end of the configured windows.

Audit and termination

Audit logs, integration matrices and version histories are available in the product. At termination the customer can export data; residual copies are deleted within 30 days.