Data Processing Agreement

Last updated: 18 February 2026

This agreement applies whenever you use Citealytics to process personal data under the GDPR or UK GDPR. It forms part of our Terms of Service and needs no signature to take effect, though we will sign a copy on request.

Roles

You are the controller of the data collected through your sites. Citealytics is the processor and acts only on your documented instructions, which are given by your use of the product and its settings.

Subject matter and duration

Subject matter: provision of cookieless web analytics with AI-engine attribution. Duration: for as long as your account is active, plus the retention period of your plan. Purpose: producing the reports and exports you configure — nothing else.

Categories of data

We process the requested URL, the referrer, a coarse country derived at request time, device class, browser family, the user-agent string, and the engine classification derived from it. We do not store IP addresses, do not set cookies or other device storage, do not fingerprint, and do not create cross-site identifiers. Data subjects are visitors to your sites.

Sub-processors

We use a small number of sub-processors: a managed Postgres and authentication provider for application data, an edge hosting provider for serving the application and ingest endpoint, a payment processor for billing, and an email provider for transactional messages. We will give at least 30 days’ notice by email before adding or replacing one, and you may object on reasonable data-protection grounds.

International transfers

You choose the storage region for each site: EU or US. Where a transfer outside the EEA or UK occurs, it is covered by the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the technical measures described below.

Security measures

Encryption in transit and at rest; row-level access control so tenants cannot read one another’s data; least-privilege access for staff with access granted only when needed for support and revoked afterwards; audit logging of administrative actions; and separation of production from development environments. Because no cookies, identifiers or IP addresses are stored, the blast radius of any incident is structurally limited.

Assistance, breach notification and deletion

We will assist you with data subject requests, impact assessments and consultations insofar as the data we hold allows. We notify you without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting your data. On account closure or written request, we delete your data within 30 days, including from backups on their normal rotation.

Audit

On reasonable notice and no more than once a year, we will answer a written security questionnaire and provide the documentation needed to demonstrate compliance with this agreement. Requests go to hello@citealytics.com.