Skip to content

Version 1.0, effective 14 September 2026

Data processing addendum

When people visit your website, Statsy processes their data on your behalf. This addendum is our promise about how. Every clause comes with a plain-English summary; the summaries help you read the clauses and do not change them.

  • Your instructions only

    We process visitor data to run Statsy for you. Never to sell, advertise or profile.

  • 48-hour breach notice

    If a breach touches your data, you hear from us within 48 hours of us knowing.

  • 14 days before a new subprocessor

    Every provider is listed. You get notice, and a way out if you object.

  • Deleted when you delete

    Delete a site or your account and its data goes, including from backups within 35 days.

  • Security in writing

    The measures in Annex II are the ones running in production today.

  • Countersigned on request

    Fill in your details below, sign, and we return it within five business days.

Parties

Customer (controller)

The customer that accepts the Statsy Terms of Service

Statsy (processor)

Meek Media LLP

Operating Statsy (https://statsy.co)

Privacy contact: [email protected]

1.This addendum

This Data Processing Addendum (“DPA”) is between the Customer and Meek Media LLP, which operates Statsy (https://statsy.co) (“Statsy”, “Processor”). It forms part of the Terms of Service and applies automatically when the Customer uses Statsy to process personal data. A countersigned copy is available but not needed for this DPA to apply.

If this DPA and the Terms conflict on the protection of personal data, this DPA prevails. If this DPA and the Standard Contractual Clauses conflict, the Clauses prevail.

2.Definitions

  • Data Protection Law means every law that applies to the processing of Customer Personal Data, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act and other US state privacy laws, and India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
  • Customer Personal Data means personal data about visitors to the Customer’s websites, or people the Customer identifies, that Statsy processes for the Customer. It does not include account data about the Customer’s own users of Statsy, which our Privacy Policy covers.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • Subprocessor means a third party engaged by Statsy that processes Customer Personal Data.
  • Standard Contractual Clauses means the clauses adopted by European Commission Implementing Decision (EU) 2021/914, and the UK International Data Transfer Addendum where relevant.

3.Roles and scope

The Customer is the controller of Customer Personal Data and Statsy is its processor. Under US state privacy laws Statsy acts as the Customer’s service provider, and under the DPDP Act the Customer is the Data Fiduciary and Statsy a Data Processor. The subject matter, duration, nature, purpose and categories of data are set out in Annex I.

4.The Customer’s responsibilities

  • Have a lawful basis for the processing and give visitors the notices, choices and, where required, consent that Data Protection Law demands for the tracking mode the Customer selects.
  • Not send Statsy special category data, children’s data collected without required parental consent, payment card numbers, passwords or government identifiers in URLs, events or identify calls.
  • Make sure its instructions to Statsy comply with Data Protection Law.

5.Statsy’s obligations

Statsy will:

  • Process Customer Personal Data only on the Customer’s documented instructions. The Terms, this DPA and the Customer’s settings in Statsy are those instructions. Statsy will tell the Customer if it believes an instruction breaks Data Protection Law.
  • Not sell or share Customer Personal Data, use it for advertising or profiling, or combine it with data from other customers or other sources, except to provide the service the Customer configured.
  • Ensure everyone authorised to access Customer Personal Data is bound by confidentiality and accesses it only as needed to operate, support or secure Statsy.
  • Use only aggregated, de-identified measurements (such as event volumes) to run and improve the service. These never identify the Customer, its sites or its visitors.

6.Security

Statsy maintains the technical and organisational measures in Annex II, appropriate to the risk of the processing. Statsy may update them as technology changes, but will not reduce the overall level of protection.

7.Subprocessors

The Customer gives general authorisation for the Subprocessors in Annex III. Statsy binds each Subprocessor to data protection terms at least as protective as this DPA and remains responsible for its performance.

Statsy will update Annex III and email account owners at least 14 days before a new Subprocessor begins processing. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may stop using the affected part of Statsy or close its account, and receive a pro-rata refund of any prepaid fees for the unused period.

8.Helping with requests and assessments

Taking into account the nature of the processing, Statsy will assist the Customer, by appropriate technical and organisational measures, in responding to requests from data subjects and Data Principals, and will give reasonable help with data protection impact assessments and consultations with supervisory authorities. The Customer can look up a visitor’s journey in Statsy itself; Statsy will delete a specific visitor’s data when the Customer asks. If a request reaches Statsy directly, Statsy will pass it to the Customer rather than answer it.

9.Personal data breaches

Statsy will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notice will describe, as far as then known, the nature of the breach, the categories and approximate volume of data and people affected, the likely consequences, and the measures taken or proposed. Statsy will update the Customer as it learns more and will take reasonable steps to contain and remedy the breach.

Notifying a breach is not an admission of fault or liability.

10.Deletion and return

The Customer can export its data from Statsy at any time. When the Customer deletes a site or closes its account, Statsy deletes the related Customer Personal Data from its live systems, and it is removed from encrypted backups within 35 days, unless Data Protection Law requires Statsy to keep it. On request, Statsy will confirm the deletion in writing.

11.Audits and information

Statsy will make available the information reasonably needed to demonstrate compliance with this DPA. Once every twelve months, on written request, Statsy will answer a reasonable security questionnaire. Where Data Protection Law or a supervisory authority requires more, the Customer or an independent auditor bound by confidentiality may carry out an audit with at least 30 days’ notice, during business hours, without disrupting the service, at the Customer’s cost.

12.International transfers

Statsy may process Customer Personal Data in the countries listed in Annex III. Transfers of personal data from the EEA, Switzerland or the UK to a country without an adequacy decision are governed by the Standard Contractual Clauses as described in Annex IV, which are incorporated into this DPA by reference. Transfers of personal data out of India follow the DPDP Act and any restrictions notified under it.

13.Duration and liability

This DPA lasts for as long as Statsy processes Customer Personal Data. Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow liability to be limited.

14.Governing law

This DPA is governed by the laws of India, and the courts of India have jurisdiction over any dispute arising from it, except that the Standard Contractual Clauses are governed by the law and forum they specify.

Annex I. Details of the processing

ControllerThe Customer
ProcessorMeek Media LLP, operating Statsy (https://statsy.co)
Subject matterWebsite analytics, revenue attribution, session replay and heatmaps for the Customer’s websites
DurationWhile the Customer uses Statsy, plus the deletion periods in section 10
Nature and purposeCollecting, storing, aggregating, analysing and displaying website usage data for the Customer
Data subjectsVisitors to websites where the Customer installed the Statsy script; people the Customer identifies through the identify feature or payment records
Categories of dataPseudonymous visitor and session identifiers; pages viewed, referrers, campaign parameters and ad click identifiers; approximate location (country, region, city); browser, operating system, device, screen size, language and time zone; events, goals and payments linked to visits; masked session recordings; click positions; identifiers the Customer chooses to attach, such as an email address
Special categoriesNone. The Customer agrees not to send them.
FrequencyContinuous, while the script is installed
RetentionAs in Annex II “Retention”, or until the Customer deletes the data

Annex II. Technical and organisational measures

AreaMeasures
EncryptionTLS for all traffic with HSTS; integration secrets encrypted at rest with AES-256-GCM; database backups encrypted with AES-256 before they leave the server.
Access controlEvery request checked against the workspace and role it acts for; viewers are read-only; API tokens scoped to a workspace or a single site and stored only as hashes; team and account changes require a signed-in person.
AuthenticationSalted password hashing; email verification; rate-limited sign-in, reset and email endpoints; all sessions and connected AI app grants revoked on password reset; AI app grants expire after 90 days.
NetworkDatabases on private networks with no public ports; internal endpoints blocked at the edge; client addresses trusted only from verified proxy ranges; request size limits.
ApplicationNonce-based Content Security Policy and strict security headers; output escaping in emails and reports; protection against open redirects and spreadsheet formula injection; secrets redacted from logs.
Data minimisationVisitor IP addresses used only for location lookup and daily cookieless keys, never stored; cookieless mode by default for EU, UK and Swiss visitors; replay form inputs masked.
RetentionRaw events and sessions deleted after 90 days; session replays after 90 days; heatmap totals after 400 days; site and account deletion erase related data.
AvailabilityDaily encrypted backups kept off-server with a tested restore procedure; health checks and automatic restarts.
Integrity of the softwareDependencies pinned by lockfile; containers run without root privileges; security reviews of authentication, tenant isolation, ingest and the web application before launch.
Incident responseA documented process to contain, investigate and notify within the timeline in section 9.

Annex III. Subprocessors

SubprocessorPurposeLocation
VultrCloud servers that run Statsy and store its databasesServer region chosen at deployment
CloudflareDNS, TLS and protection against abusive trafficGlobal edge network
Email delivery providerSending account, alert and report emailsDepends on provider
S3-compatible object storageDatabase backups, encrypted before uploadDepends on bucket region
OpenAIWriting the optional weekly AI digest from aggregated totals, the site domain and top page paths (no visitor-level data)United States

Integrations the Customer connects itself, such as payment providers, Google Search Console, Slack or Discord, are not Subprocessors: the Customer instructs Statsy to exchange data with them.

Annex IV. International transfers

  • EEA. Module Two (controller to processor) of the Standard Contractual Clauses applies between the Customer and Statsy, and Module Three (processor to processor) to onward transfers to Subprocessors. Clause 7 (docking) applies; option 2 of clause 9 (general written authorisation, with the notice period in section 7 of this DPA) applies; the optional wording in clause 11 does not; under clause 17 option 1 the law of Ireland applies, and under clause 18 the courts of Ireland are chosen.
  • United Kingdom. The International Data Transfer Addendum issued by the Information Commissioner applies, with the parties’ details and the Annexes of this DPA completing its tables; either party may end it as its section 19 allows.
  • Switzerland. The Standard Contractual Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner as the competent authority.
  • Annexes to the Clauses. Annex I of this DPA completes Annex I.B of the Clauses, Annex II completes Annex II, and Annex III completes Annex III.

Signatures

This DPA already applies without a signature. If your procurement team needs a signed copy, fill this in, then print or save it as a PDF.

Your details stay in this browser. Sign the copy and email it to [email protected]; we return it countersigned within five business days.

Signed for the Customer

Customer legal name

Signature

Name
Title
Date
 

Signed for Statsy

Meek Media LLP

Signature

Name
Authorised signatory
Title
Designated partner
Date