Legal

Data Processing Agreement

Version 1.0 · Effective

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Altias and the website owner ("Controller") and governs the processing of data under GDPR Art. 28.

Data Controller

You — the website owner

The individual or organisation that registered an account on Altias and added one or more websites for tracking.

Data Processor

Altias

The operator of altias.vercel.app, which processes visitor analytics data on behalf of the Controller.

1

Definitions

"Personal Data"Has the meaning given in GDPR Art. 4(1). For the avoidance of doubt, the anonymised hashes and aggregate statistics processed by Altias are not considered personal data.
"Processing"Any operation performed on data on behalf of the Controller, including collection, storage, retrieval, and deletion.
"Services"The Altias web analytics platform, including the tracking script, ingestion API, and analytics dashboard.
"Visitor Data"The data collected by the tracking snippet as described in the Visitor Privacy Notice at altias.vercel.app/privacy/visitors.
"Sub-processor"Any third-party infrastructure provider engaged by Altias to assist in delivering the Services.
2

Subject matter & nature of processing

2.1 Altias processes Visitor Data solely for the purpose of generating aggregate analytics reports accessible to the Controller via the Altias dashboard.

2.2 The duration of processing is the period during which the Controller maintains an active Altias account and has one or more sites registered.

2.3 The categories of data subjects are visitors to websites owned or operated by the Controller.

2.4 As documented in the Visitor Privacy Notice, Altias is designed to avoid collecting personal data. To the extent any data incidentally meets the GDPR definition of personal data (e.g. IP addresses briefly processed in memory), this DPA governs its handling.

Subject matter

Web traffic analytics

Duration

Term of account

Data subjects

Website visitors

3

Processor obligations

3.1 Documented instructions. Altias processes Visitor Data only on documented instructions from the Controller (i.e. by the Controller having registered a site and embedded the tracking snippet).

3.2 Confidentiality. Altias ensures that all personnel authorised to process Visitor Data are bound by confidentiality obligations.

3.3 No secondary use. Altias will not use Visitor Data for any purpose other than providing the Services. Data is never sold, licensed, or shared with third parties for advertising, profiling, or any other commercial purpose.

3.4 Assistance. Altias will provide reasonable assistance to the Controller in fulfilling obligations under GDPR Chapter III (data subject rights), Chapter IV (security, DPIA, breach notification), to the extent technically possible given the anonymised nature of the data.

3.5 Breach notification. In the event of a personal data breach affecting Visitor Data, Altias will notify the Controller without undue delay and within 72 hours of becoming aware of the breach.

3.6 Privacy by design. Altias maintains a technical architecture that avoids collecting personal data, including but not limited to: no cookie setting, no raw IP storage, daily-rotating one-way hashes, and server-side-only IP processing.

4

Controller obligations

4.1 The Controller is solely responsible for ensuring they have a lawful basis for embedding the Altias tracking snippet on their website.

4.2 The Controller shall include a reference to Altias in their website's privacy policy, noting that Altias is used for privacy-friendly analytics and linking to the Visitor Privacy Notice at altias.vercel.app/privacy/visitors.

4.3 The Controller shall not configure the tracking snippet in a manner intended to circumvent Altias's privacy-by-design protections.

4.4 The Controller shall promptly notify Altias of any data subject requests it receives relating to Visitor Data that Altias may be required to assist with.

5

Sub-processors

5.1 The Controller provides general authorisation for Altias to engage the following sub-processors. Altias will inform the Controller of any intended changes to this list with at least 14 days' notice.

Vercel Inc.

SOC 2 Type IIUSA (SCCs in place)

Hosting, serverless compute, and edge network. Processes incoming tracking requests.

Supabase Inc.

SOC 2 Type IIUSA / AWS (SCCs in place)

PostgreSQL database hosting. Stores anonymised pageview records.

5.2 Altias imposes equivalent data protection obligations on each sub-processor and remains liable to the Controller for the performance of those obligations.

6

Security measures

Altias implements the following technical and organisational measures (TOMs) appropriate to the risk, in accordance with GDPR Art. 32:

—All data in transit encrypted via TLS 1.2+
—All data at rest encrypted by the database provider
—Row-level security on the database (each site's data isolated)
—No raw personal data written to disk at any stage
—One-way hashing with SHA-256 for all visitor identifiers
—Daily rotation of visitor hashes to prevent long-term tracking
—Access to production systems restricted to authorised personnel
—Dependency and security updates applied on a rolling basis
7

Return & deletion of data

7.1 Upon deletion of a site by the Controller, all Visitor Data associated with that site is permanently deleted from Altias's database immediately.

7.2 Upon termination of the Controller's account, all sites and all associated Visitor Data are permanently deleted.

7.3 Altias does not maintain secondary backups that preserve Visitor Data after deletion. Deleted data is unrecoverable.

7.4 Upon request, Altias will provide a written confirmation of deletion within 14 days.

8

Audit rights

8.1 Altias will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and in GDPR Art. 28.

8.2 The Controller may conduct audits or inspections, or commission an independent auditor, with a minimum of 30 days' prior written notice, no more than once per calendar year, and during normal business hours. The Controller shall bear all costs of such audits.

8.3 Altias may satisfy an audit request by providing relevant third-party audit reports (e.g. SOC 2 reports from sub-processors) where these address the subject matter of the audit.

9

Liability

9.1 Each party's liability under this DPA is subject to the limitations and exclusions set out in the Altias Terms of Service.

9.2 The Controller indemnifies Altias against any losses, damages, or regulatory penalties arising from the Controller's failure to comply with clause 4 of this DPA.

10

Termination

10.1 This DPA remains in effect for as long as Altias processes Visitor Data on behalf of the Controller.

10.2 This DPA terminates automatically upon termination of the Controller's Altias account, subject to the deletion obligations in clause 7.

10.3 Altias may update this DPA from time to time to reflect changes in law or processing activities. Material changes will be communicated by email with at least 30 days' notice. Continued use of the Services after the effective date constitutes acceptance.

Questions about this DPA

If you have questions about this agreement or need a signed PDF copy for your own compliance records, contact us:

Altias legal

legal@altias.app