Data Processing Agreement
GDPR Article 28 · InfoPeak Analytics · Document analytics-v1.0
For review. Not yet accepted from this account.
Data Processor
InfoPeak
CVR: 42161543
Mergelsigvej 10, DK-7400 Herning, Denmark
infopeak.io · legal@infopeak.io
1.Subject Matter and Duration
This Data Processing Agreement (“Agreement”) governs the processing of personal data by InfoPeak (“Processor”) on behalf of the customer named on acceptance (“Controller”) in connection with InfoPeak Analytics, the website statistics service the Controller embeds on websites it operates.
The Agreement covers every website registered in InfoPeak Analytics under the account from which it was accepted, including websites added later. It enters into force on electronic acceptance and remains in force for as long as the Processor processes personal data under it, subject to Section 11.
The Agreement concerns InfoPeak Analytics only. The InfoPeak productivity suite is covered by a separate data processing agreement.
2.Nature and Purpose of Processing
The Processor processes personal data solely to provide InfoPeak Analytics to the Controller, on the Controller’s documented instructions. Those instructions are this Agreement and the settings the Controller chooses for each website. The processing consists of:
- receiving the page views and events that the InfoPeak Analytics script sends from the Controller’s websites;
- rejecting requests from domains not registered for the website and from recognised automated traffic;
- deriving the visitor’s country, device categories and a daily visitor identifier, and grouping page views into visits, as described in Section 3;
- storing the resulting records and presenting them to the Controller’s account as aggregated reports;
- deleting the records when the retention period set for the website has passed.
The Processor does not use the data for its own purposes, does not combine data from different websites or different customers, does not build profiles of visitors, and does not sell or disclose the data.
3.Types of Personal Data
- For each page view: the page address without query string or fragment, the host name of the website, the domain of the referring website, campaign tags from the address (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the visitor identifier, the time, and how long the page was in view and how far it was scrolled.
- For each visit (page views less than 30 minutes apart): the entry and exit page, the visitor’s country, the browser language as a language code, the device type, browser family and operating system, and a screen width range.
- For each event: the event name, which the Controller registers in advance, the page address, any event properties the Controller chooses to send (at most 4 KB), the visitor identifier and the time. Automatic events are recorded without registration and carry only fixed properties: clicks on links to other websites (the destination host), file downloads (file name and extension), scrolling to 90 % of a page and, only where the Controller enables it, site search (the search term, at most 100 characters).
The visitor identifier is a SHA-256 value calculated on the Processor’s server from the visitor’s IP address, the browser’s user-agent string, the website and the date (UTC), together with a secret value that is never disclosed. It changes at midnight UTC and is different for every website. The IP address and the user-agent string are used in memory to calculate the identifier, the country and the device categories and to recognise automated traffic. They are not stored, and the screen width is stored only as a range.
4.Categories of Data Subjects
Visitors to the websites the Controller has registered in InfoPeak Analytics.
5.Obligations of the Controller
- The Controller is responsible for the lawfulness of the processing, including the legal basis for measuring visits and for informing visitors in its own privacy notice.
- The Controller shall not place personal data, such as names, email addresses or customer numbers, in page addresses, event names or event properties. Query strings are removed automatically, apart from campaign tags; page paths and event properties are stored as they are sent.
- If the Controller enables site search, the Controller is responsible for informing visitors that search terms entered on its website are recorded.
- The Controller shall inform the Processor without undue delay if it finds errors or irregularities in the processing.
6.Obligations of the Processor
InfoPeak undertakes to:
- process personal data only on the Controller’s documented instructions, unless required to do so by EU or Member State law, and inform the Controller if, in its opinion, an instruction infringes data protection law;
- ensure that all persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Section 7, in accordance with GDPR Article 32;
- assist the Controller in responding to requests from data subjects under Chapter III of the GDPR, as described in Section 10;
- assist the Controller in meeting its obligations under GDPR Articles 32 to 36, taking into account the nature of the processing and the information available to the Processor;
- notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data;
- make available the information necessary to demonstrate compliance with GDPR Article 28, and allow for and contribute to audits under Section 12.
7.Technical and Organisational Measures
The Processor maintains the following measures:
- Data minimisation by design: no IP address and no user-agent string is stored, and because the visitor identifier changes daily and differs per website, visits cannot be linked across days, websites or customers.
- Nothing is stored on the visitor’s device: the script sets no cookies and uses no local storage. If the browser sends a Do Not Track signal, the script sends nothing.
- The server that receives visits keeps no access log containing visitor IP addresses, and its error logs do not record client IP addresses.
- The country is looked up in a database file held on the Processor’s own servers; no request about the visitor is sent to a third party.
- InfoPeak Analytics has its own database. The application reaches it through a database user that may only read, write and delete records in that database and has no access to the data of the InfoPeak productivity suite.
- Domain binding: records are accepted only from the domains registered for the website.
- Reports are available only through the Controller’s signed-in account, and every request is checked against ownership of the website.
- The embed snippet loads the script over HTTPS, the script sends visits over HTTPS, and the account is served over HTTPS.
- A nightly job deletes records older than the retention period set for each website.
- The servers are located in data centres in Germany operated by Contabo GmbH.
8.Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors. For InfoPeak Analytics the Processor currently engages one: Contabo GmbH, Germany, which operates the servers and the database. The current list of sub-processors for all InfoPeak services, with their roles and locations, is maintained at infopeak.io/privacy.
The Processor will notify the Controller at least 30 days before engaging a new sub-processor for InfoPeak Analytics. The Controller may object within that period by writing to legal@infopeak.io; if the objection cannot be resolved, the Controller may end the processing by deleting its websites.
Every sub-processor is bound by data protection obligations equivalent to those in this Agreement, and the Processor remains liable to the Controller for its sub-processors.
Payment for a paid plan is handled by Stripe under the InfoPeak Terms of Service. It concerns the Controller as a customer, not the visitors to its websites, and falls outside this Agreement.
9.Data Transfers
Visitor data is stored and processed on servers in Germany and is not transferred to a country outside the European Economic Area. The Processor will notify the Controller at least 30 days before any change to this.
10.Data Subject Rights
The Processor assists the Controller in responding to requests under GDPR Articles 12 to 22. Requests the Processor receives directly from visitors are forwarded to the Controller within 72 hours, where the Controller can be identified from the request.
Because no IP address is stored and the visitor identifier changes daily, the Processor generally cannot attribute the stored records to a particular person. Where a request makes this possible, the Processor locates the records concerned and deletes them on the Controller’s instruction.
11.Retention, Return and Deletion
- Records are kept for the retention period set for each website, 13 months unless agreed otherwise, and are then deleted automatically.
- When the Controller deletes a website, its records are deleted at the same time.
- When the Controller’s InfoPeak account is closed, its websites and their records are deleted within 30 days.
- Before deleting a website, the Controller may request an export of its stored records in a machine-readable format by writing to legal@infopeak.io. The export is provided within 30 days.
- Deletion covers every copy held by the Processor, unless EU or Member State law requires the data to be kept.
12.Audits
The Controller may audit the Processor’s compliance with this Agreement, including by inspection, with reasonable prior notice, during normal business hours and at its own cost, or through an independent auditor bound by confidentiality. The Processor will cooperate and provide the information reasonably required.
13.Liability
Each party is liable for damage caused by processing that infringes the GDPR or this Agreement, in accordance with GDPR Article 82. Liability is otherwise subject to the limitations in the InfoPeak Terms of Service.
14.Governing Law and Language
This Agreement is governed by the laws of Denmark and the European Union. Disputes are submitted to the courts of Denmark, without prejudice to the rights of data subjects, the powers of supervisory authorities and any mandatory provisions applicable in the Controller’s jurisdiction.
The Agreement is available in English and German. Both versions have the same content; if they differ, the English version prevails.