Data Processing Agreement (DPA)
This DPA governs processing of personal data by PureMetrix (operated by Lydia Rebers, Destouchesstr. 3, 80803 Munich, Germany) on behalf of you (the “Customer”) under Article 28 GDPR. It forms part of our Terms of Service.
1. Summary
- Roles: You are the controller; PureMetrix is the processor.
- Purpose: Cookieless website analytics on your behalf.
- Hosting: Analytics databases and core servers in Germany (EU) via Hetzner.
- IP handling: IP-related signals hashed with a daily salt and discarded; raw IPs not stored.
- Breach notice: Without undue delay, and within 48 hours of becoming aware of a personal data breach affecting visitor data.
- Subprocessors: Listed below; Art. 28 contracts and transfer safeguards as applicable.
2. Scope
- GDPR terms (controller, processor, personal data, etc.) apply as defined in Regulation (EU) 2016/679.
- This DPA covers visitor data collected via the PureMetrix script or API on Customer sites.
- Customer account and billing data are handled under the Privacy Policy as controller.
3. Processing details
- Subject: Privacy-oriented cookieless web analytics.
- Duration: Subscription term plus applicable retention.
- Nature: Receive events, hash, aggregate metrics, show dashboards.
- Data subjects: Visitors to Customer websites.
- Data types: IP and User-Agent (transient for hash/geo, then discarded), page URLs, referrers, optional custom events.
4. Processor obligations (Art. 28)
PureMetrix undertakes to:
- Process only on documented Customer instructions, unless law requires otherwise.
- Ensure authorized persons are bound by confidentiality.
- Implement TOMs appropriate to the risk (see section 6).
- Engage subprocessors only under Art. 28(2)/(4) with equivalent obligations.
- Assist with data-subject requests where feasible given the nature of processing.
- Notify breaches as above.
- Delete or return visitor data on termination at Customer’s choice, unless retention is legally required.
- Provide information reasonably needed to demonstrate Art. 28 compliance and contribute to audits as agreed.
5. Subprocessors
- Hetzner Online GmbH (Germany / EU): hosting, databases, EU backups.
- Cloudflare, Inc.: DNS, CDN for script delivery, DDoS protection (DPF and/or SCCs as applicable).
- Stripe Payments Europe Ltd. / Stripe, Inc.: payments and billing.
- Amazon Web Services EMEA SARL (SES): transactional email.
We will give reasonable advance notice of material subprocessor changes so you can object.
6. TOMs (summary)
- TLS in transit.
- Daily-salt hashing of visitor IP signals; no raw IP storage.
- Access controls, SSH keys, firewalling.
- EU-based backups.
7. Governing law
German law. Mandatory consumer/data-protection rules remain unaffected where applicable.
Last updated: September 2026