Data processing agreement
Draft of 3 October 2026.
This agreement ("DPA") forms part of the terms of service between the customer (the "controller") and [legal entity name] (the "processor") and applies whenever UsherStats processes personal data on the customer's behalf. It sets out the terms required by Article 28 of the General Data Protection Regulation (GDPR) and the UK GDPR.
1. Subject matter and duration
The processor provides web analytics and bot protection for the controller's websites, for as long as the controller's account exists and until the data is deleted under section 9.
2. Nature and purpose
Collecting, classifying, storing, aggregating and displaying data about visits and requests to the controller's websites, and deciding whether requests are automated, solely to provide the service to the controller.
3. Types of data and data subjects
Data subjects: visitors to the controller's websites. Data: pages visited, referring host, campaign tags, browser language, time zone and window size, country, network operator, device class, interaction measures, named events, and, while a request is handled and not stored, IP address and browser identification string. No special categories of data are processed. Details are in the privacy policy.
4. Processor obligations (Article 28(3))
- (a) Process personal data only on the controller's documented instructions, including these terms and the controller's settings, unless the law requires otherwise, in which case the processor will tell the controller first unless the law forbids it.
- (b) Ensure everyone authorised to process the data is bound by confidentiality.
- (c) Take the measures required by Article 32; the current measures are described on our security page.
- (d) Engage subprocessors only as in section 5.
- (e) Help the controller, by appropriate measures, to answer data subjects' requests.
- (f) Help the controller meet Articles 32 to 36, including notifying a personal data breach without undue delay and within [notification period, e.g. 48 hours] of becoming aware of it.
- (g) At the controller's choice, delete or return all personal data at the end of the service, unless the law requires it to be kept.
- (h) Make available the information needed to demonstrate compliance, and allow for and contribute to audits, [audit terms: frequency, notice, cost].
5. Subprocessors
The controller gives general authorisation for the subprocessors listed on our subprocessors page. The processor will give at least 30 days' notice of a new subprocessor by email and on that page; the controller may object on reasonable grounds and, if no solution is found, terminate the affected service. The processor imposes the same data protection obligations on each subprocessor and remains liable for it.
6. International transfers
Where personal data is transferred outside the European Economic Area, the UK or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor) and, for onward transfers, Module Three, with the UK International Data Transfer Addendum where the UK GDPR applies. [SCC annex details: docking clause, governing law, competent supervisory authority]
7. Controller obligations
The controller is responsible for the lawfulness of the collection, including any notices and consents its jurisdiction requires, and for its instructions complying with data protection law.
8. Data minimisation by design
The service sets no cookies on visitors for analytics (bot protection sets one, us_pass, only on a visitor who has completed a challenge), stores no IP addresses or browser identification strings with analytics, and does not record browsers that send Global Privacy Control.
9. Retention and deletion
Data is kept until the controller deletes it, sets a retention period, or closes the account, after which it is deleted [deletion period]. The controller can export its data at any time.