LEGAL
Data Processing Agreement (DPA)
When you use Anonymetrics to measure your sites, you are the controller and we are the processor. This is the Article 28 GDPR agreement; it applies to every customer without a separate signature.
Last updated: September 21, 2026
1. Parties and acceptance
This agreement is entered into between the customer (controller) and Monolit Digital, S.L. (“Anonymetrics”, processor), registered at Carrer Medes 4, 08023 Barcelona, España, VAT B-05336086. It forms part of the Terms of Service and is accepted by using the service. For a signed copy, write to info@anonymetrics.io.
2. Subject matter
We process personal data on behalf of the customer for the sole purpose of providing the analytics, behaviour and monitoring service they subscribed to, following their documented instructions (including those given through account settings). Details are in Annex I.
3. Instructions and limits
- We never use customer data for our own purposes: no advertising, no model training, no selling or sharing.
- If an instruction appears to infringe data protection law, we will say so before acting on it.
- If law requires processing beyond the instructions, we will inform the customer unless that law forbids it.
4. Confidentiality
Everyone with access to customer data is bound by confidentiality. Staff access is named, minimal and logged: administrative actions record who, what and when.
5. Security (Art. 32 GDPR)
- Encryption in transit (TLS) and at rest in the database.
- Per-organisation isolation enforced in the database itself (row level security), not only in the application.
- Per-person roles (owner, admin, editor, viewer) and anti-bot verification on sign-in.
- Minimisation at source: cookieless by default, no IP storage, daily identifiers that cannot be linked across days, and form fields masked in recordings before they leave the browser.
- Daily backups and disaster recovery provided by the database vendor.
- Automated tests of the access rules on every deployment.
6. Sub-processors
The customer grants general authorisation for the sub-processors in Annex II. We announce any addition or replacement 30 days in advance by email to account admins. The customer may object on reasonable data protection grounds and terminate without penalty before the change takes effect. Sub-processors are bound by the same obligations we assume here.
7. Assistance
- Data subject rights: the product itself exports and deletes a site's data; beyond that we assist within a reasonable time at no extra cost.
- Personal data breaches: we notify the customer without undue delay and within 48 hours of becoming aware, with the information available so they can meet Article 33.
- Impact assessments: we provide the technical information needed for DPIAs and prior consultations.
8. Return and deletion
On termination the customer can export their data (CSV and API). 30 days after the account closes we delete the personal data processed on their behalf, unless the law requires otherwise. During the relationship, raw data retention is set by the customer according to their plan.
9. Audit
We make available the information needed to demonstrate compliance and allow audits by the customer or an independent third party, with reasonable notice, once a year and without disrupting the service, unless a supervisory authority requires otherwise.
10. Location and international transfers
Analytics data is stored in the European Union. Some sub-processors may process data outside the EEA under the European Commission's Standard Contractual Clauses, with supplementary measures where appropriate. Annex II states each one's location and basis.
11. Term and precedence
This agreement is in force while the customer uses the service. Where it conflicts with the Terms of Service on personal data processing, this agreement prevails.
Annex I · Processing details
- Nature and purpose: audience and behaviour measurement, uptime monitoring, technical audits and alerts, on behalf of the customer.
- Duration: for the term of the contract, plus the deletion period in section 8.
- Categories of data subjects: visitors to the customer's sites and users of their account.
- Types of data: technical identifiers that cannot be linked across days or, with consent, a first-party identifier; page views and events; referrer; country and region derived from the network; device type, browser and OS; relative click coordinates and scroll depth; session recordings with form fields masked, only with consent; and account data of users (name and email).
- What we do not process: we do not store IP addresses, we do not fingerprint or track across sites, and we do not process special categories of data.
Annex II · Sub-processors
- Supabase — database and authentication · EU (Ireland).
- Vercel — hosting of the app and website · EU deployment (Dublin); US entity, under Standard Contractual Clauses.
- Cloudflare — edge ingestion, delivery network and anti-bot verification · global network, under Standard Contractual Clauses.
- Resend — transactional email and alerts · US, under Standard Contractual Clauses.
- Stripe — payments and billing (not involved in analytics data) · EU and US, under Standard Contractual Clauses.
- Monolit AI — language models for automatic insights, on the group's own EU infrastructure. No data is sent to third-party AI providers.
- Google — only if the customer voluntarily connects Search Console or requests performance audits · read-only access, for the purpose stated in the Privacy Policy.
This list was last reviewed in September 2026. Write to info@anonymetrics.io to be notified of changes.