Data Processing Agreement
Standard DPA for customers who need one for procurement.
Standard version, ready to sign. Need a countersigned or custom version? Email privacy@metrixs.eu.
Article 28
GDPR-aligned
EU-only data
No visitor data leaves the EU
Sign on request
For procurement teams
1. Parties
This DPA is between MetriXs Analytics (Wethouder Hollaan 24, 3984 KC Odijk, Netherlands, KVK 63879131), the Processor, and the customer entity that uses MetriXs, the Controller.
2. Scope & purpose
The Processor processes personal data on behalf of the Controller only for the purpose of providing the MetriXs web analytics service, as described in the Data Policy and the Terms of Service. The Processor processes data only on the Controller’s documented instructions.
3. Categories of data
The Processor processes visitor analytics data collected via the MetriXs tracker. As documented in the Data Policy, no personal data is stored: raw IP addresses and User-Agent strings are discarded in memory, and only a daily-salted, irreversible hash is retained. The Controller warrants it has a lawful basis to measure traffic on the websites it tracks.
4. Duration & retention
Data is processed for the duration of the Controller’s subscription and retained according to the plan’s retention window (see the Data Policy). Upon termination or account deletion, all data is permanently deleted without undue delay.
5. Subprocessors
The Processor engages subprocessors as listed on the Subprocessors page. The Controller is notified of any new subprocessor before it begins processing data, with the right to object.
6. Security measures
The Processor implements the technical and organisational measures described on the Security page, including TLS encryption, access control, bot detection, rate limiting, and off-site backups.
7. Data subject rights
The Processor assists the Controller in responding to data subject requests where applicable. As no personal visitor data is stored, the standard rights (access, correction, deletion) do not apply to visitor analytics. For account data, see the Privacy Policy.
8. International transfers
All processing of customer and account data takes place within the EU. Our subprocessors are EU-based and process data within the EU, so no Standard Contractual Clauses are required. Visitor analytics data is processed and stored exclusively within the EU. No subprocessor receives visitor data. See Subprocessors.
9. Audit & liability
The Controller may audit the Processor’s compliance with this DPA, subject to reasonable notice and confidentiality obligations. Liability is allocated as set out in the Terms of Service.
10. Deletion on termination
On termination, the Processor deletes all personal data processed on behalf of the Controller, except where retention is required by law.
11. Contact
Need a countersigned version or have procurement questions? Email privacy@metrixs.eu.
Last updated: July 2026