Data Processing Agreement
Last updated: [EFFECTIVE DATE]
[placeholder]below must be filled in, and the whole document should be reviewed by qualified counsel for your jurisdiction and business before it's relied on or linked as a real policy.This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer") and [LEGAL ENTITY NAME]("ShonyLabs") governing ShonyLabs' processing of personal data collected via the ShonyLabs tracking snippet and APIs on the Customer's behalf.
1. Key terms
- Controller:the Customer — the party that decides what data is collected from their website's visitors and why (e.g. by choosing which tracking snippet to install, which custom events to send, and whether to use the identify or transactions APIs).
- Processor:ShonyLabs — processes visitor data solely to provide the analytics Service, on the Customer's documented instructions.
- Subprocessor: a third party ShonyLabs engages to help provide the Service (see Section 4).
2. Scope of processing
ShonyLabs processes the categories of visitor data described in our Privacy Policy — page/session activity, approximate geographic location, device/browser information, and, depending on the tracking snippet the Customer installs, either a cookie/localStorage-based visitor identifier or a server-derived, storage-free one (see GDPR & cookieless tracking) — solely to provide analytics, goal/funnel tracking, and revenue attribution back to the Customer. ShonyLabs does not use this data for its own marketing purposes and does not sell it.
3. Data retention
[State actual retention periods for visitor analytics data (Postgres shonylabs_events), identity records (Postgres visitor_identities), and account data, including what happens on account/site deletion.]
4. Subprocessors
ShonyLabs self-hosts its ingestion API, queue, and analytics database. Current infrastructure subprocessors:
- Cloudflare — CDN/proxy in front of the tracking endpoint, providing geographic headers used to resolve visitor location.
- [HOSTING PROVIDER] — hosts the servers running the ingestion API, queue, and databases.
We will update this list as our infrastructure changes and consider notifying customers of material changes.
5. International data transfers
[State where infrastructure is physically located relative to the Customer's visitors, and, if data leaves the EEA/UK, what transfer mechanism applies — e.g. Standard Contractual Clauses with the hosting provider.]
6. Security measures
ShonyLabs encrypts data in transit (HTTPS), restricts access to production systems, and applies the access-control model described in our architecture (per-site roles, API-key authentication for server-to-server endpoints). [Add specifics: backup policy, who has production access, incident response process.]
7. Roles and responsibilities
The Customer (Controller) is responsible for:
- Having a lawful basis for collecting visitor data via the tracking snippet.
- Obtaining visitor consent where required (e.g. a cookie banner for the default snippet).
- Maintaining an accurate privacy notice on their own website.
- Handling data subject requests from their own visitors.
ShonyLabs (Processor) is responsible for:
- Processing data only on the Customer's documented instructions (i.e. as configured through the dashboard and APIs).
- Applying appropriate technical and organizational security measures.
- Assisting the Customer in responding to data subject requests and regulator inquiries, to the extent required by applicable law.
- Notifying the Customer without undue delay of any personal data breach affecting their data.
8. Data access and export
The Customer can access their processed data at any time via the dashboard. [State whether a bulk export/API exists, or whether access is limited to the dashboard UI.]
9. Governing law
This DPA is governed by the laws of [JURISDICTION].
10. Contact
Questions about this DPA can be sent to [CONTACT EMAIL].