Data Processing Agreement
These are the data-processing terms Simplytics offers to every customer. They take effect when you start using the service and need no signature — but if your organisation needs a countersigned copy, email nikhil@simplytics.dev and you will get one.
Read this first: you may not need a DPA at all
A data-processing agreement governs personal data that a processor holds on a controller's behalf. Simplytics is designed so that there is almost none of it:
- No cookies and no cross-site identifier are set on your visitors.
- Visitors are counted by a keyed hash of a truncated IP address, the user-agent and your domain, re-salted at your site's local midnight. It cannot be reversed, cannot be linked across days, and cannot be linked across sites.
- Individual visit rows are deleted every night. What remains is daily counts with nobody attached.
So in practice this agreement is mostly about your data as an account holder — your email address and your subscription — plus the hours before each day's raw rows are deleted. We are telling you that up front rather than letting the length of this page imply otherwise.
This page describes what the product does and the terms offered. It is not legal advice, and it is not a substitute for your own assessment of whether it meets your obligations.
1. Roles
For data collected from your website's visitors and for your own account data, you are the controller and Simplytics is the processor. Simplytics processes that data only to provide the service, and only on your instructions — the instructions being your use of the product and these terms. Simplytics does not sell, rent, share or use your data for its own purposes, and does not use it to train anything.
2. What is processed
| Item | Detail |
|---|---|
| Subject matter | Providing website analytics to you |
| Duration | For as long as your account exists. Deleting your account removes the data from the live database immediately; see clause 3 on backups |
| Nature and purpose | Collecting page views, aggregating them into daily counts, and showing them to you |
| Categories of data subject | Visitors to your website, and you as the account holder |
| Personal data — visitors | A truncated IP address and user-agent, used at the edge to derive a keyed daily hash, a country code and a device class, and never stored. What is stored is the hash, until the night's deletion, and daily counts thereafter |
| Personal data — you | Your email address, your subscription status, and the domains you have added |
| Special categories | None are requested or expected. Do not put them in a page path |
Scroll the table sideways to see the second column.
3. Our obligations
- Instructions. We process only on your documented instructions, including for transfers, unless required otherwise by law — in which case we will tell you first unless the law forbids it.
- Confidentiality. Everyone with access is bound to confidentiality. Today that is one person.
- Security. We apply the measures described on the security page, which also lists what is not in place. That page is part of these terms and is kept current rather than aspirational.
- Assistance. We will help you respond to data-subject requests and to any prior-consultation or impact-assessment obligation, so far as the data we hold allows. Note what that means in practice: because visitor data is de-identified within hours, we usually cannot locate a specific visitor's data — which is a limit of the design, not a refusal.
- Breach notification. If we become aware of a personal-data breach affecting your data, we will tell you without undue delay and in any case within 24 hours, with what we know at the time. The clock starts when we become aware, not when the breach happened. We say 24 rather than the usual 72 because your own notification deadline is often 72 hours from the moment we tell you — a slower promise from us would spend your deadline, not ours.
- Deletion and return. You can export everything as CSV at any time, and delete the account and its data yourself from the Account page. On termination the data is removed from the live database immediately and nothing about your account is kept to run the product. Backups are the honest exception. Cloudflare's point-in-time restore holds a restorable snapshot of the database for 30 days, and a weekly whole-database export is written to private EU storage. Those copies exist only to recover from a disaster; they are never queried, never used to rebuild a deleted account, and no feature reads them. We would rather name them than let this clause read more cleanly than the system behaves.
- Audit. We will answer written questions about this processing, and provide what we have. A one-person product cannot host an on-site audit, and pretending otherwise would be a term we could not honour.
4. Subprocessors
You give general authorisation for the subprocessors listed on the subprocessors page, which is the canonical list and is kept current. Each is bound by data-protection terms no less protective than these.
Adding or replacing one is published on that page and on the changelog. If you want advance notice by email, and a chance to object, ask and you will be added to that list — it is a single email to nikhil@simplytics.dev and there is no reason to make it harder.
5. Where the data goes
The analytics database's primary storage is in the European Union (Warsaw). Requests are served from whichever Cloudflare edge location is nearest the visitor, which is how a beacon reaches us quickly; the processing done there is the derivation described above, and nothing is stored at the edge. Email is delivered through Amazon SES in eu-west-1 (Ireland).
Where one of our providers processes data outside the EEA or the UK, that processing is covered by the relevant provider's Standard Contractual Clauses and the UK Addendum, which are incorporated here by reference. Their current terms are linked from the subprocessors page.
That does not cover everything, and it would be easy to let you assume it did. Simplytics is operated by one person based in India, and administering the service means reading the EU-hosted database from India. A provider's clauses say nothing about that access, because the provider is not the one making it. It is a restricted transfer in its own right, India has no EU adequacy decision and is not covered by UK adequacy regulations, and no Article 46 safeguard is in place for it yet — there are no Standard Contractual Clauses between us on this, no transfer risk assessment, and no EU or UK representative appointed. The privacy policy sets out what does limit it. If that gap is a problem for your own compliance record, say so before you subscribe rather than after.
6. Liability and precedence
These terms sit alongside the Terms of Service; where the two conflict on a data-protection question, this page wins. Liability is as set out in the Terms.
7. Changes
Material changes to this page are listed on the changelog with the date they took effect. If a change would reduce your protection and you have a subscription, you will be emailed before it applies.