Data Processing Addendum
This Data Processing Addendum ("DPA") governs the processing of personal data that Trafnova performs on behalf of the customer ("Controller") when the customer installs our tracker on a website they operate. It forms part of the Terms of Service and is binding on both parties from the customer's first use of the service.
1. Definitions
Capitalised terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679). "Personal data", "processing", "data subject", "controller", and "processor" carry their GDPR meanings.
"Trafnova", "we", "us" refers to
[OPERATOR_NAME], the processor under
this DPA.
"Customer", "Controller", "you" refers to the natural or legal person
that has signed up for a Trafnova account.
2. Roles & subject matter
The Customer is the Controller of personal data collected via the Trafnova tracker on the Customer's website. Trafnova is the Processor. The subject matter of the processing is the operation of the Trafnova service as described in the Terms of Service and the Privacy Policy.
3. Duration
This DPA is in force for as long as the Customer has an active Trafnova account and applies to all processing performed during that period.
4. Nature & purpose
Trafnova processes personal data to provide first-party web analytics:
collecting page-view and event data via the
t.js snippet, deriving aggregated stats, sending a daily
digest summarising those stats, and raising anomaly alerts. We do not
process the data for any other purpose, do not enrich it from external
sources beyond the local MaxMind GeoLite2 database, and do not
share it with advertisers or data brokers.
5. Categories of data subjects
Visitors to the Customer's website who load a page containing the Trafnova tracker.
6. Categories of personal data
Per event sent by the tracker:
- URL, path, hostname, referrer URL
- UTM parameters present in the URL
- Browser, browser major version, OS, OS major version, device type (derived from the User-Agent string)
- Country, region, city (derived from visitor IP via a local MaxMind GeoLite2 lookup; the raw IP is not stored)
- A 16-character anonymous session hash (derived from IP, User-Agent and site token, rotated daily)
- Custom event names and properties the Customer passes via
tn('event', ...)
We do not store the raw IP address, do not set cookies, and do not fingerprint individual devices beyond the daily session hash. The Customer is responsible for not passing additional personal data in custom event properties.
7. Processor obligations (GDPR Art. 28)
Trafnova will:
- Process personal data only on documented instructions from the Controller, including the instructions implicit in the configuration of the service (which sites to track, retention, anomaly thresholds, digest recipients). Sending the data to the sub-processors listed below also counts as an instruction.
- Ensure persons authorised to process the data are bound by confidentiality;
- Take all technical and organisational security measures required by GDPR Art. 32 (see Section 9);
- Engage sub-processors only as described in Section 10, and impose equivalent obligations on them;
- Assist the Controller, to the extent reasonably possible, in responding to data subject requests, performing DPIAs, and meeting Art. 32–36 obligations;
- Notify the Controller without undue delay (within 72 hours) after becoming aware of a personal data breach affecting their data;
- At the Controller's choice, return or delete all personal data at the end of the service (see Section 11);
- Make available to the Controller all information necessary to demonstrate compliance with Art. 28 and allow for audits as described in Section 12.
8. Controller obligations
The Customer warrants that they:
- Have a lawful basis under Art. 6 for collecting the analytics data via the Trafnova tracker on their website;
- Have given visitors the privacy notice required by Art. 13/14, including the categories of data above and the sub-processors below;
- Have obtained any consent required by ePrivacy or local equivalents (note: because Trafnova sets no cookies and stores no IPs, most EU customers rely on legitimate interest without a consent banner, but this is the Customer's call);
- Won't pass special-category data, children's data, or otherwise sensitive personal data through the tracker without an appropriate lawful basis.
9. Security measures
We implement the following technical and organisational measures:
- TLS 1.2+ for all HTTP traffic to the dashboard and the collector
- Encrypted backups stored on the same EU server cluster
- Per-customer logical separation in the database (every event row is keyed by a tenant-scoped site token)
- Scoped service credentials, no shared admin accounts
- Passwordless sign-in via short-lived magic links
- Source code under version control with peer review on every change
- Centralised error tracking and alerting
- Incident response process for security events affecting personal data, with 72-hour breach notification to the Controller
10. Sub-processors
Customer authorises Trafnova to engage the sub-processors below. Trafnova will give Customer notice (via email or a status page entry) at least 30 days before engaging any new sub-processor; Customer may object on legitimate data-protection grounds, in which case the parties will work in good faith to find a resolution, including the Customer's right to terminate without further charge.
| Sub-processor | Purpose | Region |
|---|---|---|
| Maileroo | Transactional email (magic links, digests, alerts to Customer admins) | EU |
| MaxMind | GeoLite2 IP-to-geo database (local; no API calls) | n/a |
| Anthropic (Claude API) | Generates the natural-language daily digest body. Receives only pre-aggregated Customer stats — no individual visitor records. | US |
| Google (Search Console API) | Reads GSC stats only for properties the Customer has explicitly connected | US |
| Hosting provider | Server infrastructure (Caddy, Rails, Postgres, Solid Queue) | EU |
11. Return or deletion at end of service
On account closure or written request from the Customer, Trafnova will delete all personal data processed on the Customer's behalf within 30 days, unless retention is required by law. The Customer can export data at any time via the in-app CSV download or the Stats API. Backups containing the deleted data age out within 30 days of the next backup rotation.
12. Audit
Trafnova will provide reasonable information needed for the Controller to verify compliance with this DPA, on request and no more than once per year (more often only if required by a competent authority or following a security incident). Where the Customer requires an on-site audit, the parties will agree timing and scope in advance to avoid disrupting Trafnova's other customers; the Customer bears its own audit costs.
13. International transfers
Trafnova processes personal data within the EU/EEA. Transfers to the US sub-processors listed above (Anthropic, Google) are covered by Standard Contractual Clauses (Module 3) and the EU-US Data Privacy Framework where applicable. Trafnova maintains an updated record of these mechanisms and will provide copies on request.
14. Liability & governing law
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the law of [JURISDICTION].
15. Order of precedence
In case of conflict between this DPA and the Terms of Service, this DPA controls for matters of personal-data processing; the Terms control for everything else.
16. Contact
Data-protection notices under this DPA: [email protected].