Data Processing Agreement (DPA)
pursuant to Art. 28(3) GDPR
Version 2026-10.1 — last updated: 10 October 2026 (the German version is legally binding)
This agreement is concluded between the customer of trackd.one ("controller") and Eduard Ditler, trading as Mignuti Media, Pfarrer-Mengesstr. 5, 56112 Lahnstein, Germany ("processor"). It specifies the parties' data protection obligations and supplements the Terms. In the event of conflicts, this DPA takes precedence over the Terms in data protection matters.
§ 1 Conclusion
The DPA is concluded in electronic form at registration by express acceptance (checkbox) (Art. 28(9) GDPR). The time and version of acceptance are stored. This page contains the current version; the controller can print it or save it as a PDF at any time.
§ 2 Subject matter and duration
The subject matter is the collection, storage and analysis of usage data of the controller's websites and apps and its provision in the dashboard, via exports and interfaces (audience measurement and product analytics). Processing begins as soon as the controller uses the tracking script, an SDK or the collect interface, and lasts as long as the main contract exists and data has not yet been deleted under § 12.
§ 3 Nature, purpose and scope of processing
The processor processes personal data solely to provide the controller with statistical analyses. This covers:
- the tracking script for websites (including optional modules for Web Vitals and heatmaps),
- the SDKs for Android, iOS/macOS, Flutter and JavaScript and the HTTP interface (collect API),
- storage, aggregation, analysis in the dashboard, exports, the read API, reports and notifications,
- features configured by the controller such as goals, funnels, A/B tests, revenue tracking, uptime monitoring and disclosures (§ 15).
Data subjects are visitors of the controller's websites and users of its apps, as well as persons whose data the controller sends in events.
§ 4 Types of data
- pseudonymous visitor identifier (SHA-256 of IP address, secret key, daily deleted salt and website ID) and session identifier (hash); the IP address itself is not stored
- page URL (query parameters except utm_* removed; fragment only for #/ routes), path, page or screen title
- referrer (origin and path), UTM parameters
- language, device type, browser and operating system family (for websites derived on the server from request headers; the user agent string is not stored), country
- for apps: platform, app version, operating system version, screen size
- events with the event data sent by the controller
- revenue data (amount, currency, order ID)
- optional: Web Vitals metrics, click positions (heatmap, not linked to visitors), A/B test variants
The controller ensures that no data directly identifying persons (e.g. names, email addresses, phone numbers) and no special categories of personal data under Art. 9 GDPR are sent in event names, event data, titles, paths, order IDs or A/B test seeds.
§ 5 Instructions
The processor processes the data only on documented instructions from the controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in such a case, the processor informs the controller of that legal requirement before processing, unless that law prohibits such information (Art. 28(3)(a) GDPR).
The instructions result from this DPA, the Terms and the settings the controller makes in the dashboard (e.g. creating and deleting websites, configuring features and disclosures, deleting the account). Further instructions are given by the account owner in text form to trackdone@mignuti.com.
If the processor considers that an instruction infringes data protection law, it informs the controller without undue delay and may suspend its execution until the instruction is confirmed or changed.
§ 6 Confidentiality
The processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). Only persons who need access for their tasks are granted it.
§ 7 Technical and organisational measures
The processor takes the measures required under Art. 32 GDPR, in particular:
- pseudonymisation and data minimisation: no storage of IP addresses; visitor identifier as SHA-256 hash with a secret key and a salt generated anew each day that is deleted after the day ends (lifetime about 24 hours); removal of query parameters except utm_*; referrer limited to origin and path; no storage of the user agent string; no device identifiers in the SDKs; no cookies and no storage on end devices by the tracking script
- access control: server-side authorisation check on every request based on role (owner, team, organisation); separation of data by website ID; invitations only effective after acceptance
- authentication: passwords with PBKDF2-SHA-256 and individual salt; session tokens, API keys and one-time links stored only as hashes; session cookies HttpOnly, Secure, SameSite; limiting of sign-in attempts
- transmission: TLS encryption of all connections, HSTS, rejection of unencrypted API requests
- storage: database (Cloudflare D1) with EU jurisdiction, encryption at rest by the infrastructure provider
- integrity: validation and size limits for all input, origin check for web requests, rate limiting
- availability and resilience: distributed infrastructure with DDoS protection (Cloudflare), restore from database backups (Time Travel, up to 30 days)
- deletion concept: automatic daily deletion according to the agreed periods (individual records at most 400 days, aggregated statistics per plan)
- administrative access: limited to expressly authorised administrators, read-only access for at most 60 minutes, recorded in the audit log
- logging: no email addresses, URLs or response bodies in own log output; technical logs at most 7 days
- regular review and adaptation of the measures to the state of the art
The processor may develop the measures further provided the level of protection is not reduced.
§ 8 Sub-processors
The controller authorises the use of the following sub-processors:
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA — hosting (Cloudflare Workers, Workers Assets), database (Cloudflare D1, storage in the EU), CDN, protection against attacks, technical logs
- Resend (Plus Five Five, Inc., USA) — sending emails to the controller and its team members (e.g. invitations, notifications, weekly reports). These emails contain only aggregated statistics and no data of individual visitors.
The processor informs the controller in text form at least 30 days in advance of any intended changes (addition or replacement). The controller may object to the change within this period for an important data protection reason; if no agreement is reached, the controller may terminate the contract with effect from the date of the change (Art. 28(2) GDPR).
The processor imposes on each sub-processor by contract the same data protection obligations as set out in this DPA, in particular sufficient guarantees for appropriate technical and organisational measures. Where a sub-processor fails to fulfil its obligations, the processor remains liable to the controller for the performance of that sub-processor's obligations (Art. 28(4) GDPR).
§ 9 Transfers to third countries
Analytics data is stored in the EU. As Cloudflare processes requests in its global network and both sub-processors are based in the USA, transfers to third countries cannot be ruled out. These are based on the adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR) where the recipient is certified, and additionally on standard contractual clauses (Art. 46(2)(c) GDPR).
§ 10 Assistance to the controller
The processor assists the controller with appropriate technical and organisational measures in responding to requests from data subjects (Art. 12–22 GDPR). In particular, export and deletion functions are available in the dashboard for this purpose. If data subjects contact the processor directly, it forwards the request to the controller without undue delay, where the controller can be identified, and does not respond itself.
Taking into account the nature of processing and the information available to it, the processor also assists the controller in complying with the obligations under Art. 32 to 36 GDPR (security, breach notification, communication to data subjects, data protection impact assessment, prior consultation).
§ 11 Notification of personal data breaches
The processor notifies the controller of a personal data breach without undue delay, at the latest within 48 hours after becoming aware of it, at the email address stored in the account. The notification contains, as far as available, the information under Art. 33(3) GDPR; missing information is provided subsequently. The processor takes containment measures without undue delay and documents the incident.
§ 12 Deletion and return
During the term, the controller can export (CSV/JSON) and delete its data at any time. After the end of processing — by deleting a website or the account — the processor deletes all personal data of the controller unless Union or Member State law requires storage (Art. 28(3)(g) GDPR). Deletion runs asynchronously in daily clean-up runs; data may remain in database backups for up to 30 days and is then overwritten automatically. Return takes place via the export function before deletion.
§ 13 Evidence and audits
The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by it who is bound to confidentiality (Art. 28(3)(h) GDPR). Inspections must be announced with reasonable notice and conducted so that operations and the confidentiality of other customers' data are not impaired. For sub-processors, evidence may be provided by their current certifications and audit reports.
§ 14 Support access
To handle support requests and analyse errors, expressly authorised administrators of the processor may view the controller's account in a read-only view for at most 60 minutes per session. Keys and secrets are hidden and exports blocked. Every access is recorded in the audit log with time and the account IDs involved (retention 2 years).
§ 15 Disclosures set up by the controller
If the controller sets up features that transmit data to third parties or the public — in particular public or password-protected dashboard links, embedded statistics (embeds), Slack or webhook notifications, API keys, exports or uptime monitors for URLs it specifies — the transmission takes place on its instruction and under its responsibility. The recipients are not sub-processors of the processor.
§ 16 Place of processing
Data is stored in a database with EU jurisdiction. Incoming requests are processed at the nearest location in Cloudflare's global network. Storage is only relocated to a third country in compliance with Art. 44 et seq. GDPR and after prior notice under § 8.
§ 17 Term and termination
This DPA applies for the term of the main contract and ends with it. It cannot be terminated separately for convenience. Obligations relating to deletion and confidentiality continue as long as the processor processes data of the controller.
§ 18 Liability and final provisions
Liability is governed by Art. 82 GDPR; otherwise the liability provisions of the Terms apply. Changes to this DPA require text form; § 14 of the Terms applies accordingly. German law applies. Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.