此文本仅提供英文版本。
最后更新于 十月 1, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer (the “controller”) and Two Phase LLC, a Wyoming limited liability company that operates Privatus Analytics (the “processor”). It applies whenever we process personal data on the Customer's behalf, and it is accepted when you accept the Terms. A countersigned copy can be requested at [email protected]. How we handle data as a controller, for example about our customers' own accounts, is in the Privacy Policy.
1. Scope and roles
- Subject matter: web and product analytics for the Customer's websites and applications, with related reports, alerts, shared dashboards, uptime checks and status pages.
- Data subjects: visitors to the Customer's websites and users of its applications, and people whose email address the Customer enters in the Service, such as report recipients and status page subscribers.
- Categories of data:
- IP address and user agent, processed transiently in memory during each request and never stored.
- Page host and path, referrer and campaign parameters after minimization (query strings removed except an allowlist, patterns that look like personal data scrubbed).
- Country only, from the country code Cloudflare adds to each request. No more precise location is collected.
- Browser and operating system family and major version, device type, a screen size range and browser language.
- Random visit identifiers lasting at most one day.
- Engagement time, scroll depth, Web Vitals, click targets (a short CSS selector) and custom event names, properties and revenue the Customer chooses to send.
- Email addresses of report recipients and status page subscribers the Customer adds.
- Special categories: none. The Customer must not send special category data or protected health information.
- Frequency and duration: continuous, for the term of the Terms, plus the deletion period in section 9.
2. Processor obligations (GDPR Article 28(3))
- We process personal data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's configuration of the Service, unless the law requires otherwise (in which case we'll inform the Customer where legally allowed).
- Everyone authorized to process the data is bound by confidentiality.
- We implement the technical and organizational measures in Annex 2.
- We assist the Customer, taking into account the nature of the processing, with data subject requests, security, breach notification, DPIAs and prior consultations.
- We make available the information needed to demonstrate compliance, and allow audits as described in section 7.
- We tell the Customer promptly if we believe an instruction infringes data protection law.
- CCPA: we act as the Customer's service provider. We don't sell or share the personal information, retain, use or disclose it outside our direct business relationship with the Customer or for any purpose other than providing the Service, or combine it with personal information from other sources, except as the CCPA permits.
3. Subprocessors
The Customer authorizes the subprocessors listed on our subprocessors page. We'll give at least 30 days' notice of any new subprocessor by email to workspace owners and on that page. The Customer may object on reasonable data protection grounds. If we can't resolve the objection, the Customer may terminate the affected Service and receive a pro-rated refund of prepaid fees. We impose data protection terms on each subprocessor at least as protective as this DPA and remain responsible for them.
4. International transfers
Customer Data is stored and processed in the United States, including requests from visitors in the EU, EEA, UK and Switzerland. Visitors' IP addresses and user agents are processed in memory only, for the duration of each request, and are never stored. To the extent personal data is transferred to a third country, the parties agree to:
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor), incorporated by reference, with Clause 7 (docking) included, Clause 9 option 2 (general authorization, 30 days' notice), the optional wording in Clause 11 omitted, Clause 17 option 1 with the law of Ireland, and Clause 18 with the courts of Ireland. Annex I is section 1 of this DPA, Annex II is Annex 2 below and Annex III is the subprocessors page.
- UK: the International Data Transfer Addendum to the EU SCCs issued by the ICO (version B1.0), with Table 1 completed with the parties' details, Tables 2 and 3 by reference to the SCCs above, and in Table 4 neither party may end the Addendum.
- Switzerland: the SCCs as amended for the Swiss FADP, with the FDPIC as competent supervisory authority where the transfer is governed by the FADP.
We are not currently certified under the EU-US Data Privacy Framework. If we certify, we'll add it here and the SCCs will remain as a fallback. We provide a transfer impact assessment on request. It relies mainly on data minimization: IP addresses and user agents are processed in memory only and never stored, and no persistent identifiers exist.
5. Personal data breaches
We'll notify the Customer without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting Customer Data, with the information the Customer needs to meet its own obligations.
6. Data subject requests
Because the Service stores no directly identifying data about visitors and visit identifiers expire within a day, individual requests usually can't be matched to stored data. We'll help the Customer respond where matching is possible, for example by deleting a site's data for a date range, and by removing report recipients or status page subscribers.
7. Audits
We'll provide our most recent security documentation and, when available, third-party audit reports. If these aren't sufficient to demonstrate compliance, the Customer may conduct an audit once a year, with 30 days' notice, during business hours, at its own cost and under confidentiality.
8. Government requests
We'll review each request for legality, challenge requests we consider unlawful, disclose the minimum required, and notify the Customer unless legally prohibited.
9. Return and deletion
The Customer can export its data at any time and can delete sites, date ranges or whole workspaces itself. A deleted workspace or site is permanently deleted after 7 days, and copies in backups expire in the normal backup cycle. When a paid plan ends, the workspace continues on the Free plan, and data older than the Free plan's retention is deleted 60 days after the plan ends. We keep only what the law requires us to keep, such as invoice records, which contain no analytics data.
Annex 2: Technical and organizational measures
- Minimization by design: IP addresses and user agents are used in memory only and never written to disk, logs, queues or databases. Daily salts are held only in memory with an expiry and never persisted. A PII scrubber, path masking and a query-string allowlist run before storage. Location is country only.
- Encryption: TLS in transit, including to the database, with HSTS on our domain. Secrets such as two-factor keys, webhook secrets and integration credentials are encrypted in the database. Passwords and API tokens are stored only as one-way hashes.
- Access control: least privilege for staff. Staff can view a Customer's workspace only while the Customer has granted time-limited support access, read-only, and every view is recorded in the workspace's audit log.
- Application security: role-based permissions, scoped API tokens with optional IP allowlists and expiry, two-factor authentication and passkeys, SSO for Business plans, rate limits on sign-in and APIs, bot protection on public forms, audit logging, and dependency and static analysis in continuous integration.
- Availability: a database read replica, queued ingestion so accepted events are processed after an incident, and database backups.
- Error monitoring: error reports keep only an allowlist of request headers, and strip tokens from URLs and job arguments before they leave our systems.
- Incident response: Customer notification within 48 hours, as in section 5.
- Vendor management: data protection terms with every subprocessor, plus transfer safeguards where needed.