Data Processing Agreement
Version 1.0 · Effective
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Altias and the website owner ("Controller") and governs the processing of data under GDPR Art. 28.
Data Controller
You — the website owner
The individual or organisation that registered an account on Altias and added one or more websites for tracking.
Data Processor
Altias
The operator of altias.vercel.app, which processes visitor analytics data on behalf of the Controller.
Definitions
Subject matter & nature of processing
2.1 Altias processes Visitor Data solely for the purpose of generating aggregate analytics reports accessible to the Controller via the Altias dashboard.
2.2 The duration of processing is the period during which the Controller maintains an active Altias account and has one or more sites registered.
2.3 The categories of data subjects are visitors to websites owned or operated by the Controller.
2.4 As documented in the Visitor Privacy Notice, Altias is designed to avoid collecting personal data. To the extent any data incidentally meets the GDPR definition of personal data (e.g. IP addresses briefly processed in memory), this DPA governs its handling.
Subject matter
Web traffic analytics
Duration
Term of account
Data subjects
Website visitors
Processor obligations
3.1 Documented instructions. Altias processes Visitor Data only on documented instructions from the Controller (i.e. by the Controller having registered a site and embedded the tracking snippet).
3.2 Confidentiality. Altias ensures that all personnel authorised to process Visitor Data are bound by confidentiality obligations.
3.3 No secondary use. Altias will not use Visitor Data for any purpose other than providing the Services. Data is never sold, licensed, or shared with third parties for advertising, profiling, or any other commercial purpose.
3.4 Assistance. Altias will provide reasonable assistance to the Controller in fulfilling obligations under GDPR Chapter III (data subject rights), Chapter IV (security, DPIA, breach notification), to the extent technically possible given the anonymised nature of the data.
3.5 Breach notification. In the event of a personal data breach affecting Visitor Data, Altias will notify the Controller without undue delay and within 72 hours of becoming aware of the breach.
3.6 Privacy by design. Altias maintains a technical architecture that avoids collecting personal data, including but not limited to: no cookie setting, no raw IP storage, daily-rotating one-way hashes, and server-side-only IP processing.
Controller obligations
4.1 The Controller is solely responsible for ensuring they have a lawful basis for embedding the Altias tracking snippet on their website.
4.2 The Controller shall include a reference to Altias in their website's privacy policy, noting that Altias is used for privacy-friendly analytics and linking to the Visitor Privacy Notice at altias.vercel.app/privacy/visitors.
4.3 The Controller shall not configure the tracking snippet in a manner intended to circumvent Altias's privacy-by-design protections.
4.4 The Controller shall promptly notify Altias of any data subject requests it receives relating to Visitor Data that Altias may be required to assist with.
Sub-processors
5.1 The Controller provides general authorisation for Altias to engage the following sub-processors. Altias will inform the Controller of any intended changes to this list with at least 14 days' notice.
Vercel Inc.
Hosting, serverless compute, and edge network. Processes incoming tracking requests.
Supabase Inc.
PostgreSQL database hosting. Stores anonymised pageview records.
5.2 Altias imposes equivalent data protection obligations on each sub-processor and remains liable to the Controller for the performance of those obligations.
Security measures
Altias implements the following technical and organisational measures (TOMs) appropriate to the risk, in accordance with GDPR Art. 32:
Return & deletion of data
7.1 Upon deletion of a site by the Controller, all Visitor Data associated with that site is permanently deleted from Altias's database immediately.
7.2 Upon termination of the Controller's account, all sites and all associated Visitor Data are permanently deleted.
7.3 Altias does not maintain secondary backups that preserve Visitor Data after deletion. Deleted data is unrecoverable.
7.4 Upon request, Altias will provide a written confirmation of deletion within 14 days.
Audit rights
8.1 Altias will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and in GDPR Art. 28.
8.2 The Controller may conduct audits or inspections, or commission an independent auditor, with a minimum of 30 days' prior written notice, no more than once per calendar year, and during normal business hours. The Controller shall bear all costs of such audits.
8.3 Altias may satisfy an audit request by providing relevant third-party audit reports (e.g. SOC 2 reports from sub-processors) where these address the subject matter of the audit.
Liability
9.1 Each party's liability under this DPA is subject to the limitations and exclusions set out in the Altias Terms of Service.
9.2 The Controller indemnifies Altias against any losses, damages, or regulatory penalties arising from the Controller's failure to comply with clause 4 of this DPA.
Termination
10.1 This DPA remains in effect for as long as Altias processes Visitor Data on behalf of the Controller.
10.2 This DPA terminates automatically upon termination of the Controller's Altias account, subject to the deletion obligations in clause 7.
10.3 Altias may update this DPA from time to time to reflect changes in law or processing activities. Material changes will be communicated by email with at least 30 days' notice. Continued use of the Services after the effective date constitutes acceptance.
Questions about this DPA
If you have questions about this agreement or need a signed PDF copy for your own compliance records, contact us:
Altias legal
legal@altias.app