i
InfoPeak

Data Processing Agreement

GDPR Article 28 · InfoPeak Analytics · Document analytics-v1.0

Data Controller
Data Processor
InfoPeak
CVR: 42161543
Mergelsigvej 10, DK-7400 Herning, Denmark
infopeak.io · legal@infopeak.io

1.Subject Matter and Duration

This Data Processing Agreement (“Agreement”) governs the processing of personal data by InfoPeak (“Processor”) on behalf of the customer named on acceptance (“Controller”) in connection with InfoPeak Analytics, the website statistics service the Controller embeds on websites it operates.

The Agreement covers every website registered in InfoPeak Analytics under the account from which it was accepted, including websites added later. It enters into force on electronic acceptance and remains in force for as long as the Processor processes personal data under it, subject to Section 11.

The Agreement concerns InfoPeak Analytics only. The InfoPeak productivity suite is covered by a separate data processing agreement.

2.Nature and Purpose of Processing

The Processor processes personal data solely to provide InfoPeak Analytics to the Controller, on the Controller’s documented instructions. Those instructions are this Agreement and the settings the Controller chooses for each website. The processing consists of:

The Processor does not use the data for its own purposes, does not combine data from different websites or different customers, does not build profiles of visitors, and does not sell or disclose the data.

3.Types of Personal Data

The visitor identifier is a SHA-256 value calculated on the Processor’s server from the visitor’s IP address, the browser’s user-agent string, the website and the date (UTC), together with a secret value that is never disclosed. It changes at midnight UTC and is different for every website. The IP address and the user-agent string are used in memory to calculate the identifier, the country and the device categories and to recognise automated traffic. They are not stored, and the screen width is stored only as a range.

4.Categories of Data Subjects

Visitors to the websites the Controller has registered in InfoPeak Analytics.

5.Obligations of the Controller

6.Obligations of the Processor

InfoPeak undertakes to:

7.Technical and Organisational Measures

The Processor maintains the following measures:

8.Sub-processors

The Controller grants the Processor general authorisation to engage sub-processors. For InfoPeak Analytics the Processor currently engages one: Contabo GmbH, Germany, which operates the servers and the database. The current list of sub-processors for all InfoPeak services, with their roles and locations, is maintained at infopeak.io/privacy.

The Processor will notify the Controller at least 30 days before engaging a new sub-processor for InfoPeak Analytics. The Controller may object within that period by writing to legal@infopeak.io; if the objection cannot be resolved, the Controller may end the processing by deleting its websites.

Every sub-processor is bound by data protection obligations equivalent to those in this Agreement, and the Processor remains liable to the Controller for its sub-processors.

Payment for a paid plan is handled by Stripe under the InfoPeak Terms of Service. It concerns the Controller as a customer, not the visitors to its websites, and falls outside this Agreement.

9.Data Transfers

Visitor data is stored and processed on servers in Germany and is not transferred to a country outside the European Economic Area. The Processor will notify the Controller at least 30 days before any change to this.

10.Data Subject Rights

The Processor assists the Controller in responding to requests under GDPR Articles 12 to 22. Requests the Processor receives directly from visitors are forwarded to the Controller within 72 hours, where the Controller can be identified from the request.

Because no IP address is stored and the visitor identifier changes daily, the Processor generally cannot attribute the stored records to a particular person. Where a request makes this possible, the Processor locates the records concerned and deletes them on the Controller’s instruction.

11.Retention, Return and Deletion

12.Audits

The Controller may audit the Processor’s compliance with this Agreement, including by inspection, with reasonable prior notice, during normal business hours and at its own cost, or through an independent auditor bound by confidentiality. The Processor will cooperate and provide the information reasonably required.

13.Liability

Each party is liable for damage caused by processing that infringes the GDPR or this Agreement, in accordance with GDPR Article 82. Liability is otherwise subject to the limitations in the InfoPeak Terms of Service.

14.Governing Law and Language

This Agreement is governed by the laws of Denmark and the European Union. Disputes are submitted to the courts of Denmark, without prejudice to the rights of data subjects, the powers of supervisory authorities and any mandatory provisions applicable in the Controller’s jurisdiction.

The Agreement is available in English and German. Both versions have the same content; if they differ, the English version prevails.

InfoPeak · Data Processing Agreement for InfoPeak Analytics · analytics-v1.0 · infopeak.io/privacy