// legal
Data processing addendum
The terms that apply when Alitycs processes personal data on your behalf: your instructions, our security obligations, subprocessors, transfers, and the two annexes.
How this addendum works
This data processing addendum (“DPA”) forms part of the terms of service or other written agreement between [legal entity name] (“Alitycs”, “we”) and the customer that opens an Alitycs account (“Customer”, “you”). It applies whenever we process personal data on your behalf in connection with the service.
You do not need to sign anything for it to apply: accepting the terms of service accepts this DPA. If your procurement process needs a countersigned copy, ask us at privacy@alitycs.com and we will send one.
Where this DPA conflicts with the terms of service, this DPA wins for the processing of personal data. Where it conflicts with the standard contractual clauses, the clauses win.
This DPA covers only personal data we process as your processor. The personal data we hold about you as a controller — your account, billing and support records — is covered by our privacy policy instead.
Definitions
“Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” have the meanings given to them in Article 4 of the GDPR.
“Data protection law” means every law on the protection of personal data that applies to the processing under this DPA, including the EU General Data Protection Regulation (2016/679), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable United States state privacy laws.
“Customer personal data” means the personal data contained in customer data that we process on your behalf under the service.
“Subprocessor” means a third party we engage to process customer personal data.
“SCCs” means the standard contractual clauses approved by the European Commission in Decision 2021/914, together with the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018 where the UK GDPR applies.
Terms defined in the terms of service keep their meaning here.
Roles and scope of processing
You are the controller of customer personal data and we are your processor. Where you are yourself a processor for another controller, we are a subprocessor, and your instructions to us must be consistent with that controller's instructions to you.
You decide what events to send, which properties to attach and which identifiers to use. You are responsible for the lawfulness of the collection, for giving data subjects the notice their law requires, and for having a lawful basis for the processing.
The subject matter, duration, nature, purpose, categories of data subject and categories of personal data are described in Annex I.
Each of us will comply with the obligations that data protection law places on us in our respective roles.
Your instructions
We process customer personal data only on your documented instructions, including for international transfers, unless the law we are subject to requires otherwise. Where it does, we will tell you before processing, unless the law prohibits us from telling you.
Your documented instructions are: this DPA, the terms of service, your configuration of the service, and the requests you make through the application and the APIs. Anything beyond that is a separate instruction, and we will agree it in writing with you first; if it costs us more to carry out, we will tell you before we do.
We will tell you if, in our opinion, an instruction breaches data protection law. We may pause the processing concerned while the question is resolved.
We do not sell customer personal data, do not share it for cross-context behavioural advertising, and do not use it for our own purposes. We do not retain, use or disclose it outside the direct business relationship with you or for any purpose other than providing the service.
Confidentiality of personnel
We limit access to customer personal data to the personnel who need it to provide, secure or support the service.
Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement, is trained on data protection and secure handling, and has their access reviewed and removed when it is no longer needed.
Security measures
We implement appropriate technical and organisational measures to protect customer personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the risk to data subjects.
The measures in force are summarised in Annex II and described in more detail on our security page. The authoritative, versioned annex that accompanies a countersigned DPA is [security annex reference and version].
We may update the measures as technology changes, provided we do not materially reduce the level of protection.
You are responsible for the parts of security you control: who you invite to your workspace, what roles you grant, how you store your secret API keys, and what you choose to send us. Sending special categories of personal data, government identifiers or credentials in events is a breach of the terms of service.
Subprocessors
You give us general authorisation to engage subprocessors to process customer personal data. The current list, naming each subprocessor, its role and the country it processes in, is published at [subprocessor list URL].
Before a new subprocessor starts processing, we impose data protection obligations on it that are no less protective than those in this DPA, and we check that it can meet them. We remain fully liable to you for a subprocessor's performance.
We will give you at least [subprocessor change notice period] notice of a new or replaced subprocessor. To receive those notices, subscribe at [subprocessor notification signup].
You may object to a new subprocessor on reasonable data protection grounds within [subprocessor objection window] of the notice, by writing to privacy@alitycs.com and explaining your grounds. We will work with you to find a solution — a different configuration, a different region, or a different subprocessor. If we cannot, you may terminate the affected part of the service and we will refund the unused portion of prepaid fees for it.
Assistance with data-subject requests
The service gives you the tools to find, export, correct and delete customer personal data yourself, which is normally the fastest way to answer a data subject.
Where you cannot answer a request with those tools, we will provide reasonable assistance, taking into account the nature of the processing.
If a data subject contacts us directly about customer personal data, we will not respond to the substance ourselves. We will tell them to contact you, and pass the request to you without undue delay, unless the law requires us to act differently.
Impact assessments and personal data breaches
Impact assessments and prior consultation
We will give you reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, where these relate to our processing and you cannot reasonably get the information elsewhere — for example from our security page, this DPA, or our documentation.
Personal data breaches
We will notify you without undue delay, and in any case within [breach notification timeframe] of becoming aware of a personal data breach affecting customer personal data.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned where known, the likely consequences, the measures we have taken or propose to take, and a contact point for more information. Where we cannot provide everything at once, we will provide it in phases as the investigation progresses.
We will help you meet your own notification obligations to supervisory authorities and data subjects. Notifying is your decision as controller — we will not notify your data subjects or your supervisory authority on your behalf unless you ask us to in writing.
A notification is not an admission of fault or liability.
Deletion and return of data
You can export and delete customer personal data at any time during the term, using the application or the APIs.
On termination, we make customer data available for export for [post-termination export window]. After that, at your choice, we return or delete customer personal data, and delete existing copies, unless the law requires us to keep it.
Deletion removes the data from the live service within [post-termination deletion window]. Copies in encrypted backups are not individually erasable; they are overwritten on our normal backup rotation within [backup retention period], and remain protected by this DPA until they are.
We will confirm deletion in writing if you ask.
Audits and information rights
We make available the information you reasonably need to demonstrate our compliance with this DPA, and we allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
In the first instance we satisfy this by providing our security documentation, the current version of Annex II, and written answers to your security questionnaire. We ask you to accept these where they answer your question, because they answer it without adding risk to anyone's data.
Where they do not, you may request an audit no more than [audit frequency limit] and on at least [audit notice period] written notice. An audit takes place during business hours, does not unreasonably disrupt the service, is subject to confidentiality, and must not give access to another customer's data or to anything that would compromise our security. You bear your own costs; we may charge for a materially disruptive audit at our then-current professional services rates.
You may also audit after a personal data breach affecting your customer personal data, without the frequency limit.
Any assurance report we hold, and its scope, is described at [assurance report and scope]. We do not claim any certification or audit report that is not named there.
International transfers
We do not transfer customer personal data outside the region you select for your workspace except as needed to provide, secure or support the service, and never without a lawful transfer mechanism.
Where a transfer out of the European Economic Area, the United Kingdom or Switzerland is to a country without an adequacy decision, the parties agree to the SCCs, which are incorporated into this DPA by reference and completed as follows: [SCC module and version], with you as data exporter and Alitycs as data importer; the governing law and forum are [SCC governing law and forum]; the optional docking clause [SCC docking clause election]; the audit and subprocessor clauses take the options recorded in [SCC clause elections]. Annex I and Annex II of the SCCs are Annex I and Annex II of this DPA.
Where the UK GDPR applies, the UK International Data Transfer Addendum applies to the SCCs with the elections at [UK IDTA elections]. Where the Swiss FADP applies, references in the SCCs are read as [Swiss FADP adaptations].
We carry out a transfer risk assessment for each transfer, apply supplementary measures where it calls for them, and tell you if we can no longer meet our obligations under the transfer mechanism.
If a public authority makes a binding request for customer personal data, we will review its legality, challenge it where there are reasonable grounds, disclose only the minimum required, and tell you unless we are legally prohibited from doing so.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the terms of service, except where data protection law does not allow that.
Nothing in this DPA limits a data subject's rights under the SCCs or under data protection law, and nothing limits either party's liability to a supervisory authority.
This DPA continues for as long as we process customer personal data, and the obligations that by their nature should survive termination do survive it.
Annex I: details of processing
This annex describes the processing we carry out as your processor. Where the SCCs apply, it serves as their Annex I.
Parties, subject matter and duration
| Item | Detail |
|---|---|
| Data exporter | The Customer, acting as controller (or as processor for its own controller). Contact details are the ones on the Alitycs account. |
| Data importer | [legal entity name], [registered address], acting as processor. Contact: privacy@alitycs.com. |
| Subject matter | Provision of the Alitycs product analytics service: ingesting, storing, querying and displaying the events the Customer sends. |
| Duration | The term of the agreement, plus the export and deletion windows in the DPA and the backup rotation described there. |
| Frequency of transfer | Continuous, for the lifetime of the agreement. |
Categories of data subject
- End users of the Customer's websites, applications and services, whether identified or pseudonymous.
- The Customer's own personnel, where they appear in event data as users of the Customer's product.
- Authorised users of the Customer's Alitycs workspace, where their activity appears in workspace audit logs.
Categories of personal data
| Category | Examples | Chosen by |
|---|---|---|
| Identifiers | User ID supplied by the Customer, anonymous or device ID generated by the SDK, session ID. | Customer |
| Contact and profile properties | Email address, name, company, plan, role — whatever the Customer attaches to a user profile. | Customer |
| Behavioural data | Event names, event properties, timestamps, and the order in which events occurred. | Customer |
| Technical and device data | IP address, user agent, browser, operating system, device type, screen size, locale. | Collected by the SDK; some fields can be disabled by the Customer |
| Page and campaign context | Page URL, path, referrer, and UTM parameters present in the URL. | Collected by the SDK; can be disabled by the Customer |
| Approximate location | Country, region and city derived from IP address. We do not collect precise geolocation. | Collected by the SDK; can be disabled by the Customer |
| Workspace audit data | Sign-ins, API key operations and administrative actions by authorised users. | Alitycs, as part of providing the service |
Special categories of personal data
None. The terms of service prohibit sending special categories of personal data, data about criminal convictions and offences, government identifiers, payment card numbers and credentials. We do not design for them, and the service applies no additional restrictions or safeguards for them. If the Customer needs to process them, they must not be sent to Alitycs without a separate written agreement — [special category handling — to be agreed with counsel if ever offered].
Purpose and retention
| Item | Detail |
|---|---|
| Nature and purpose | Collecting, recording, organising, structuring, storing, retrieving, aggregating, querying and displaying event data so the Customer can analyse product usage; and answering the Customer's natural-language questions about their own workspace. |
| Retention | The retention window of the Customer's plan — [event retention window by plan] — or until the Customer deletes the data, whichever is sooner. |
| Transfers to subprocessors | Subject matter, nature and duration as described in the subprocessor list at [subprocessor list URL]. |
| Competent supervisory authority | [competent supervisory authority for SCC purposes] |
Annex II: technical and organisational measures
These are the measures we take to protect customer personal data. Where the SCCs apply, this annex serves as their Annex II. Our security page describes the same controls in plain language. The versioned annex issued with a countersigned DPA is [security annex reference and version].
| Measure | What we do |
|---|---|
| Pseudonymisation and minimisation | The Customer chooses the identifiers it sends and can send pseudonymous IDs only. SDK-collected fields such as IP address and precise page context can be disabled. |
| Encryption in transit | TLS is required on every endpoint, for ingestion, queries and the application. Plain HTTP is redirected, not served. |
| Encryption at rest | Event data, backups and object storage are encrypted at rest. Secrets and API keys are stored hashed or encrypted, never in plain text. |
| Tenant isolation | Every query is scoped to a workspace by the tenant context established at authentication. Workspace identifiers are checked on every request, not only at the edge. |
| Access control | Access to production is role-based and least-privilege, requires multi-factor authentication, is granted for a business reason, and is reviewed and revoked on a defined cycle and on departure. |
| Authentication | Publishable keys (pk_) are write-only and safe for client code; secret keys (sk_) are server-side and can be rotated and revoked at any time. Enterprise plans support single sign-on. |
| Logging and monitoring | Administrative and authentication events are logged with an actor and a timestamp, retained for [security log retention period], and monitored for anomalies. Logs are protected against alteration. |
| Availability and resilience | Redundant infrastructure, health checking, and capacity monitoring. Ingestion is buffered so a query-side incident does not lose events. |
| Backup and recovery | Automated encrypted backups on a [backup frequency] schedule, retained for [backup retention period], with restore procedures tested [restore test frequency]. |
| Secure development | Peer review before merge, automated tests, dependency and secret scanning in continuous integration, and separate development, staging and production environments with no production data in the lower ones. |
| Change management | Changes are version-controlled, reviewed, and released through an auditable pipeline with a documented rollback path. |
| Incident response | A documented process with named owners, severity levels, customer communication steps, and a post-incident review. Breach notification follows the timeframe in this DPA. |
| Vendor management | Subprocessors are assessed before engagement, bound by written data protection terms, and reviewed on a defined cycle. |
| Personnel security | Background checks where the law allows, confidentiality obligations, security and data protection training on joining and periodically after, and prompt deprovisioning on departure. |
| Physical security | Production runs in the facilities of our infrastructure providers; physical access is controlled by them under [hosting provider physical security assurances]. Alitycs holds no customer data on office premises. |
| Deletion | Documented deletion routines for workspace and account closure, with the windows set out in this DPA. |
Where a measure above depends on a value in square brackets, the value is set in the countersigned annex and not in this page.
The rest of the paperwork
These four documents are written to be read together. Each one assumes the others.
Privacy policy
What we hold about you as a controller, and what we only ever hold on a customer's behalf.
Read itTerms of service
Accounts, acceptable use, data ownership, fees, liability and how either of us ends the agreement.
Read itSecurity
The controls behind the promises above, and how to report a vulnerability to us.
Read itDPA reviews, subprocessor notices and countersignature requests: privacy@alitycs.com. A real person reads everything sent there.