This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer”) and DevDome (“we”, “us”). It applies whenever the DevDome services process personal data of your website’s visitors on your behalf and the GDPR or a similar data protection law applies to that data.
In plain words: your visitors’ data is yours. You are the data controller for it, we are your data processor, and this document sets out what we may and must do with it — matching what the product actually does, which you can verify on our Trust page.
Subject matter, duration, nature and purpose
We process personal data of your website visitors solely to provide the DevDome services you have enabled: website analytics, click and conversion tracking, bot detection, site health monitoring, and the WordPress plugin features you switch on (for example spam filtering). Processing lasts for as long as you have a DevDome account with connected sites, plus the deletion window in section 9.
Categories of data and data subjects
Data subjects are the visitors of the websites you connect. Depending on the features you enable, the personal data processed is:
- page view and click events: URL, referrer, timestamps, and campaign parameters
- technical attributes: browser, operating system, device type, screen size, language, timezone, and user-agent string
- location derived from the IP address: country, and (unless you enable reduced precision) region and city
- the visitor’s IP address, processed in memory to derive the above and stored only as a keyed hash, never in the clear
- a visitor identifier: in the default cookieless mode, a server-derived identifier that rotates daily and cannot follow a visitor across sites or days; if you enable returning-visitor tracking, a first-party cookie identifier
- where you use the Anti-Spam plugin: submitted names, email addresses, and bounded content excerpts of flagged submissions, as described in that plugin’s own documentation
We do not process special categories of data (Art. 9 GDPR) on your behalf, and you agree not to use the services to collect them.
Your instructions
We process visitor data only on your documented instructions. Your instructions are: this DPA, the Terms, and the settings you choose in the product — the privacy toggles (location precision, cookieless mode, Do-Not-Track), your data retention period, and the deletion actions you take. We will inform you if we believe an instruction violates data protection law.
Your responsibilities as controller
- you have a lawful basis for the visitor data the services process for you
- your own privacy policy discloses the use of DevDome (the product generates a technical disclosure snippet for you under Website Settings → Privacy)
- if you enable returning-visitor tracking, you obtain any consent your jurisdiction requires for its first-party cookie — the product warns you where this applies
- you respond to your visitors’ data protection requests; we provide the tools in section 7
Confidentiality and security
We apply the technical and organizational measures described on the Trust page. In summary:
- all traffic is encrypted in transit (HTTPS/TLS)
- visitor IP addresses are stored only as keyed hashes; the key never leaves our infrastructure
- visitor data is stored in the European Union (see section 8)
- access to production systems is limited to the people who operate the service, under confidentiality obligations
- every account’s data is scoped to that account; one customer can never read another customer’s sites
- daily backups with defined retention, so deletion is not defeated by an old copy lingering indefinitely
Sub-processors
You authorize the sub-processors listed on the Trust page, which names each provider, its role, and where the data is hosted. That list is the single, current source — we keep it accurate rather than duplicating it here.
Before adding or replacing a sub-processor that processes visitor data, we will update that list and announce the change on the changelog at least 14 days in advance. If you object to a change, you may terminate the affected service and delete your data before the change takes effect. Every sub-processor is bound by a data processing agreement imposing obligations no less protective than this DPA.
Assisting with data subject rights
If a visitor exercises their rights against you, the product gives you the means to answer without contacting us:
- Erasure: Website Settings → Privacy → “Erase one visitor” permanently deletes every stored event matching a visitor identifier or IP address, across all our data stores, and reports the exact number of records removed
- Access / portability: the dashboard’s CSV export returns the stored events for a site
- Restriction / objection: you can exclude IPs and paths from collection, enable Do-Not-Track respect, or disconnect a site at any time
In the default cookieless mode, stored events carry no lasting identifier, so records older than a day generally cannot be tied back to one person by us or by anyone else (Art. 11 GDPR). If a request reaches us directly, we forward it to you without undue delay and do not answer it ourselves except where the law requires us to.
Where the data lives, and transfers
Visitor data is stored in the European Union, on the infrastructure named on the Trust page. Requests are received at the Cloudflare edge location nearest the visitor and processed in transit there; Cloudflare acts under its own data processing addendum, which incorporates the EU Standard Contractual Clauses. Any future transfer of stored visitor data outside the EU would be treated as a sub-processor change under section 6.
Deletion and return
- events older than your configured retention period are deleted automatically every day, from all data stores
- removing a site deletes its collected data; resetting a site deletes its traffic data and keeps the configuration
- deleting your account deletes the analytics data of all your sites and cancels billing first, so deletion never leaves a charge running
- deletion is permanent and irreversible; backup copies expire on the backup retention schedule
Export your data (CSV, section 7) before deleting if you want a copy — there is nothing to “return” afterwards, because nothing is kept.
Personal data breach
If we become aware of a personal data breach affecting your visitor data, we will notify you without undue delay, and in any case within 48 hours, at your account email — describing the nature of the breach, the likely consequences, and the measures taken. We will reasonably assist you with your own notification obligations under Articles 33 and 34 GDPR.
Audit and information
We make the information needed to demonstrate compliance with this DPA available on the Trust page and will answer reasonable written audit questions within 30 days. Where that is genuinely insufficient for your legal obligations, an audit may be conducted at your cost, at most once per year, on 30 days’ notice, without access to other customers’ data.
Liability, duration, and acceptance
Liability under this DPA follows the limitations in the Terms of Service, and the Terms’ governing law applies. This DPA takes effect when you first use the services to process visitor data covered by the GDPR, remains in force for as long as we process that data for you, and ends automatically when the deletion in section 9 completes.
Use of the services constitutes acceptance of this DPA. No separate signature is required. If your organization needs a countersigned copy, email support@devdome.com and we will return a signed PDF of this document.
Contact
Questions about this DPA or our data processing: support@devdome.com, or the contact form.