Back to OpenWebTrack
Last updated: January 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and OpenWebTrack ("Processor") and applies whenever the Customer uses the OpenWebTrack Cloud service to process personal data of visitors to the Customer's websites. It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent laws.

1. Definitions

  • Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject have the meanings given in the GDPR.
  • Customer Data means the personal data the Customer submits to the Service through the tracking script.
  • Service means the OpenWebTrack Cloud hosted service.

2. Roles

  • The Customer is the Controller of Customer Data.
  • OpenWebTrack is the Processor, processing Customer Data only on the Customer's documented instructions.

3. Processing instructions

The Processor will process Customer Data for the purpose of providing the Service, which includes: storing events, computing aggregations, generating dashboards, sending weekly reports, and providing the MCP/API endpoints. The Processor will not process Customer Data for any other purpose, including its own purposes, except where required by law.

4. Customer obligations

The Customer is responsible for:

  • Having a lawful basis to process the personal data of its visitors.
  • Providing any required notices and obtaining any required consents.
  • Configuring the tracking mode (cookieless vs. cookie) appropriately for its visitors.
  • Responding to data subject requests, with reasonable assistance from the Processor.

5. Processor obligations

The Processor will:

  • Process Customer Data only on documented instructions from the Controller.
  • Ensure that persons authorised to process Customer Data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see Annex A below).
  • Engage sub-processors only with the Controller's general authorisation, and notify the Controller of intended changes so the Controller may object.
  • Assist the Controller in fulfilling its obligations under GDPR Articles 32–36.
  • At the Controller's choice, delete or return all Customer Data at the end of the service, subject to legal retention.
  • Make available all information necessary to demonstrate compliance with this DPA.

6. Sub-processors

The Controller grants the Processor general authorisation to engage sub-processors, listed in the Privacy Policy. The Processor will inform the Controller of any intended additions or replacements at least 14 days in advance, giving the Controller an opportunity to object. If the Controller objects on reasonable grounds, the parties will work in good faith to find a remedy; if none is found, the Controller may terminate the affected service.

7. International transfers

The Processor will only transfer Customer Data outside the European Economic Area, the United Kingdom, or other adequate jurisdictions where it has put in place a valid transfer mechanism such as Standard Contractual Clauses or the EU-US Data Privacy Framework. Primary hosting is in the EU.

8. Security measures (Annex A)

The Processor implements at least the following measures:

  • Encryption of Customer Data in transit (TLS 1.2+) and at rest.
  • Access controls with role-based permissions and audit logging.
  • Regular vulnerability scanning and timely security patches.
  • Daily encrypted backups, retained with according to.
  • Documented incident response process with a target notification time of 72 hours after discovery of a personal data breach affecting the Controller's data.
  • Staff training on data protection.

9. Personal data breaches

The Processor will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Controller's Customer Data. The notification will include the information required by GDPR Article 33(3) to the extent known.

10. Audits

The Processor will make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow audits, including inspections, conducted by the Controller or a mutually agreed auditor, with reasonable prior notice and at the Controller's expense, no more than once per year unless required by a supervisory authority.

11. Data subject requests

The Processor will assist the Controller, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests from data subjects. The Customer is responsible for responding to such requests via the dashboard or by emailing privacy@openwebtrack.com.

12. Termination

On termination of the Service, the Processor will, at the Controller's choice, delete or return all Customer Data within 60 days, subject to legal retention obligations.

13. Changes to this DPA

We may update this DPA from time to time. Material changes will be announced by email or in-app at least 30 days before they take effect. If the Controller does not agree with a change, the Controller may terminate the Service.

14. Contact

To exercise rights or ask questions about this DPA, email privacy@openwebtrack.com.