Legal · Last updated 1 September 2026
Data processing agreement
This is signed at onboarding, alongside the sub-processor list and a paragraph for your own privacy policy. It is reproduced here in full so it can be reviewed before anyone talks to you.
1. Roles
For personal data processed on your behalf, you are the controller and we are the processor. We process it only on your documented instructions, which are: run the service.
For your own account and billing data, we are the controller, and the privacy policy governs it instead.
2. Subject matter and duration
Providing cookieless traffic measurement and ad spend reporting for your website, for as long as your subscription runs, plus the 30-day export window afterwards.
3. Nature of the data
Categories of data subject: visitors to your website.
Categories of personal data: a session identifier derived from connection data with a daily-rotating salt and no stored source values; page paths on your site; UTM parameters; referrer; coarse device, browser, operating system and country; and the properties of any custom events you choose to send.
Data explicitly not processed: cookies or any device storage, stored IP addresses, names, email addresses, account identifiers, device fingerprints, persistent visitor identifiers, click ID values, and any cross-site identifier.
Special categories: none, unless you place them in a custom event property. Do not do that. If you do, you remain the controller of it and this agreement does not make it lawful.
4. Sub-processors
You give general authorisation for the sub-processors listed here. We will notify you at least 30 days before adding or replacing one. You may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, you may terminate without penalty and take an export with you.
Each sub-processor is bound by written terms no less protective than these.
5. International transfers
Processing takes place in the United States, including backups. Where personal data of EEA or UK data subjects is transferred there, it is made under the applicable Standard Contractual Clauses, with a transfer impact assessment available on request. The assessment is short: the categories in section 3 contain no persistent identifier, so there is no record of an individual to be accessed, disclosed or re-identified.
6. Security
Technical and organisational measures include:
- Row-level separation between accounts, enforced in every query path.
- TLS for all data in transit.
- Encrypted backups, retained 30 days, then destroyed.
- Ad platform credentials encrypted at rest.
- Access to production limited to personnel who require it, authenticated and logged.
- An architecture that does not collect identifiers, which is the measure that matters most.
7. Personal data breach
We will notify you without undue delay and in any case within 48 hours of becoming aware of a breach affecting your data, with the facts, the likely consequences, and the measures taken. We will assist with your own notification obligations.
8. Assistance with data subject rights
We will help you respond to access, correction, deletion, portability and objection requests, taking into account the nature of the processing.
The nature of the processing matters here more than usual. With no persistent identifier, an individual visitor generally cannot be located in the data, so there is often nothing to retrieve or erase. That is a property of the design, and we will say so in writing if you need it for a response.
9. Audit
On reasonable notice and no more than once a year, we will provide the information needed to demonstrate compliance, and will allow an audit conducted by you or an independent auditor bound by confidentiality. Where documentation answers the question, it is provided instead.
10. Deletion and return
On termination you keep dashboard access for 30 days, which is your window to export what you want to keep. After that your account and the data collected for it are deleted, and backups age out within a further 30 days. Nothing is retained beyond what law requires.
11. Liability and precedence
This agreement forms part of the terms and is subject to their liability provisions. Where the two conflict on the processing of personal data, this agreement prevails.
Signing
A countersigned copy is issued at onboarding. Request one before that, or send your own paper for review, at privacy@pearmetrics.com.