Data Processing Agreement
Last updated: June 27, 2026
This Data Processing Agreement ("DPA") is a draft template. Complete the placeholders and have it reviewed by a qualified legal professional before relying on it. It forms part of the Terms of Service between you (the "Customer", acting as data controller) and [Legal entity name] ("Datyze", acting as data processor).
1. Subject matter & duration
Datyze processes personal data of the Customer's website visitors solely to provide the analytics Service. This DPA lasts for the duration of the Customer's use of the Service and any period during which data is retained.
2. Nature & purpose of processing
Collection, aggregation, storage and presentation of website-analytics data on the Customer's documented instructions (i.e. the Customer's configuration of the Service, including the chosen privacy mode).
3. Categories of data & data subjects
- Data subjects: visitors to the Customer's websites.
- Data — cookieless mode: a daily, rotating server-side visitor hash; page URL and referrer; device/browser type; country-level location; UTM parameters. The raw IP address is never stored.
- Data — full mode (with consent): additionally a persistent identifier (
_datyze_id), enabling multi-day journeys and returning-visitor recognition, plus optional city-level location and any identifier the Customer passes toidentify(). - Special-category data: none is intended; the Customer must not configure the Service to collect it.
4. Obligations of Datyze (processor)
- Process personal data only on the Customer's documented instructions.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (section 6).
- Respect the conditions for engaging sub-processors (section 5).
- Assist the Customer in responding to data-subject rights requests.
- Assist the Customer with security, breach notification and data protection impact assessments.
- On the Customer's choice, delete or return personal data at the end of the Service.
- Make available information needed to demonstrate compliance and allow audits.
5. Sub-processors
The Customer authorises Datyze to engage the following sub-processors. We will inform the Customer of intended changes and give a reasonable opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| [Hosting provider] | Hosting / infrastructure (self-hosted via Coolify) | European Union |
| Lemon Squeezy | Subscription billing | United States (SCCs) |
| Brevo | Transactional email | European Union |
| Stripe (optional) | Revenue attribution via Stripe Connect, when enabled by the Customer | United States (SCCs) |
| Sentry (optional) | Error monitoring | [Region] |
6. Security measures
- Encryption in transit (TLS) and at rest
- The raw visitor IP address is never written to storage
- Access controls, authentication and least-privilege practices
- Daily-rotating salt so historical cookieless hashes cannot be re-derived
- Configurable data retention (default 365 days)
7. Data-subject requests & breach notification
Datyze will promptly notify the Customer of any personal-data breach affecting the Customer's data, and will assist with data-subject requests it receives by referring them to the Customer or acting on the Customer's instructions.
8. International transfers
Where a sub-processor is located outside the European Union, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Return & deletion
On termination, and at the Customer's choice, Datyze will delete or return all personal data and delete existing copies, unless retention is required by law.
10. Contact
Data protection contact: contact@datyze.fr. See also our Privacy Policy and Legal Notice.