Simplytics

Data Processing Agreement

These are the data-processing terms Simplytics offers to every customer. They take effect when you start using the service and need no signature — but if your organisation needs a countersigned copy, email nikhil@simplytics.dev and you will get one.

Read this first: you may not need a DPA at all

A data-processing agreement governs personal data that a processor holds on a controller's behalf. Simplytics is designed so that there is almost none of it:

So in practice this agreement is mostly about your data as an account holder — your email address and your subscription — plus the hours before each day's raw rows are deleted. We are telling you that up front rather than letting the length of this page imply otherwise.

This page describes what the product does and the terms offered. It is not legal advice, and it is not a substitute for your own assessment of whether it meets your obligations.

1. Roles

For data collected from your website's visitors and for your own account data, you are the controller and Simplytics is the processor. Simplytics processes that data only to provide the service, and only on your instructions — the instructions being your use of the product and these terms. Simplytics does not sell, rent, share or use your data for its own purposes, and does not use it to train anything.

2. What is processed

3. Our obligations

4. Subprocessors

You give general authorisation for the subprocessors listed on the subprocessors page, which is the canonical list and is kept current. Each is bound by data-protection terms no less protective than these.

Adding or replacing one is published on that page and on the changelog. If you want advance notice by email, and a chance to object, ask and you will be added to that list — it is a single email to nikhil@simplytics.dev and there is no reason to make it harder.

5. Where the data goes

The analytics database's primary storage is in the European Union (Warsaw). Requests are served from whichever Cloudflare edge location is nearest the visitor, which is how a beacon reaches us quickly; the processing done there is the derivation described above, and nothing is stored at the edge. Email is delivered through Amazon SES in eu-west-1 (Ireland).

Where one of our providers processes data outside the EEA or the UK, that processing is covered by the relevant provider's Standard Contractual Clauses and the UK Addendum, which are incorporated here by reference. Their current terms are linked from the subprocessors page.

That does not cover everything, and it would be easy to let you assume it did. Simplytics is operated by one person based in India, and administering the service means reading the EU-hosted database from India. A provider's clauses say nothing about that access, because the provider is not the one making it. It is a restricted transfer in its own right, India has no EU adequacy decision and is not covered by UK adequacy regulations, and no Article 46 safeguard is in place for it yet — there are no Standard Contractual Clauses between us on this, no transfer risk assessment, and no EU or UK representative appointed. The privacy policy sets out what does limit it. If that gap is a problem for your own compliance record, say so before you subscribe rather than after.

6. Liability and precedence

These terms sit alongside the Terms of Service; where the two conflict on a data-protection question, this page wins. Liability is as set out in the Terms.

7. Changes

Material changes to this page are listed on the changelog with the date they took effect. If a change would reduce your protection and you have a subscription, you will be emailed before it applies.