Effective May 27, 2026

Data Processing Addendum

This Data Processing Addendum ("DPA") governs the processing of personal data that Trafnova performs on behalf of the customer ("Controller") when the customer installs our tracker on a website they operate. It forms part of the Terms of Service and is binding on both parties from the customer's first use of the service.

Operator action required before public launch. Replace the placeholders [OPERATOR_NAME], [OPERATOR_ADDRESS], and [JURISDICTION] with the real legal entity, registered postal address, and governing-law jurisdiction. Have a lawyer review before charging the first paid customer; this draft is a starting point, not legal advice.

1. Definitions

Capitalised terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679). "Personal data", "processing", "data subject", "controller", and "processor" carry their GDPR meanings.

"Trafnova", "we", "us" refers to [OPERATOR_NAME], the processor under this DPA.
"Customer", "Controller", "you" refers to the natural or legal person that has signed up for a Trafnova account.

2. Roles & subject matter

The Customer is the Controller of personal data collected via the Trafnova tracker on the Customer's website. Trafnova is the Processor. The subject matter of the processing is the operation of the Trafnova service as described in the Terms of Service and the Privacy Policy.

3. Duration

This DPA is in force for as long as the Customer has an active Trafnova account and applies to all processing performed during that period.

4. Nature & purpose

Trafnova processes personal data to provide first-party web analytics: collecting page-view and event data via the t.js snippet, deriving aggregated stats, sending a daily digest summarising those stats, and raising anomaly alerts. We do not process the data for any other purpose, do not enrich it from external sources beyond the local MaxMind GeoLite2 database, and do not share it with advertisers or data brokers.

5. Categories of data subjects

Visitors to the Customer's website who load a page containing the Trafnova tracker.

6. Categories of personal data

Per event sent by the tracker:

We do not store the raw IP address, do not set cookies, and do not fingerprint individual devices beyond the daily session hash. The Customer is responsible for not passing additional personal data in custom event properties.

7. Processor obligations (GDPR Art. 28)

Trafnova will:

  1. Process personal data only on documented instructions from the Controller, including the instructions implicit in the configuration of the service (which sites to track, retention, anomaly thresholds, digest recipients). Sending the data to the sub-processors listed below also counts as an instruction.
  2. Ensure persons authorised to process the data are bound by confidentiality;
  3. Take all technical and organisational security measures required by GDPR Art. 32 (see Section 9);
  4. Engage sub-processors only as described in Section 10, and impose equivalent obligations on them;
  5. Assist the Controller, to the extent reasonably possible, in responding to data subject requests, performing DPIAs, and meeting Art. 32–36 obligations;
  6. Notify the Controller without undue delay (within 72 hours) after becoming aware of a personal data breach affecting their data;
  7. At the Controller's choice, return or delete all personal data at the end of the service (see Section 11);
  8. Make available to the Controller all information necessary to demonstrate compliance with Art. 28 and allow for audits as described in Section 12.

8. Controller obligations

The Customer warrants that they:

9. Security measures

We implement the following technical and organisational measures:

10. Sub-processors

Customer authorises Trafnova to engage the sub-processors below. Trafnova will give Customer notice (via email or a status page entry) at least 30 days before engaging any new sub-processor; Customer may object on legitimate data-protection grounds, in which case the parties will work in good faith to find a resolution, including the Customer's right to terminate without further charge.

Sub-processorPurposeRegion
MailerooTransactional email (magic links, digests, alerts to Customer admins)EU
MaxMindGeoLite2 IP-to-geo database (local; no API calls)n/a
Anthropic (Claude API)Generates the natural-language daily digest body. Receives only pre-aggregated Customer stats — no individual visitor records.US
Google (Search Console API)Reads GSC stats only for properties the Customer has explicitly connectedUS
Hosting providerServer infrastructure (Caddy, Rails, Postgres, Solid Queue)EU

11. Return or deletion at end of service

On account closure or written request from the Customer, Trafnova will delete all personal data processed on the Customer's behalf within 30 days, unless retention is required by law. The Customer can export data at any time via the in-app CSV download or the Stats API. Backups containing the deleted data age out within 30 days of the next backup rotation.

12. Audit

Trafnova will provide reasonable information needed for the Controller to verify compliance with this DPA, on request and no more than once per year (more often only if required by a competent authority or following a security incident). Where the Customer requires an on-site audit, the parties will agree timing and scope in advance to avoid disrupting Trafnova's other customers; the Customer bears its own audit costs.

13. International transfers

Trafnova processes personal data within the EU/EEA. Transfers to the US sub-processors listed above (Anthropic, Google) are covered by Standard Contractual Clauses (Module 3) and the EU-US Data Privacy Framework where applicable. Trafnova maintains an updated record of these mechanisms and will provide copies on request.

14. Liability & governing law

Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the law of [JURISDICTION].

15. Order of precedence

In case of conflict between this DPA and the Terms of Service, this DPA controls for matters of personal-data processing; the Terms control for everything else.

16. Contact

Data-protection notices under this DPA: [email protected].