Last updated: August 11, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween Key Arg B.V. ("Processor", "we", "us") and the customer ("Controller", "you") who uses our Statable analytics service.
By using Statable, you automatically accept this DPA. No separate signature is required.
The Processor processes Visitor Data solely for the purpose of providing web analytics services to the Controller. The categories of data processed include:
Categories of data subjects: visitors of the Controller's website.
The Processor does not intentionally collect names, email addresses, telephone numbers or other directly identifying information about website visitors. Such data may nevertheless reach the Processor if the Controller places it in page URLs or custom event properties; section 7 allocates responsibility for that to the Controller.
The Processor pseudonymises Visitor Data using a keyed one-way hash:
This mechanism ensures:
The Parties acknowledge that this constitutes pseudonymisation within the meaning of Article 4(5) GDPR, not anonymisation: Visitor Data remains personal data and is processed under this DPA.
The Processor implements the following technical and organizational measures to protect Visitor Data:
For full details, see our Security Practices page.
The Controller authorizes the Processor to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| NorthC Datacenters | Colocation facility — rack space and power for the Processor's own servers; no access to Visitor Data | Oude Meer, Netherlands (EU) |
| Bunny | CDN and network security | EU |
| Stripe, Inc. | Payment processing | United States |
| Google LLC | OAuth authentication (optional) | United States |
The Processor owns and operates the servers on which Visitor Data is stored. NorthC provides the facility in which those servers are housed — rack space, power and physical security — and does not process Visitor Data.
Stripe, Inc., GitHub, Inc., and Google LLC process account and payment data for which the Processor acts as controller. They do not process Visitor Data and are therefore not sub-processors under this DPA; their role is described in our Privacy Policy.
Bunny is an EU company. Its content delivery network routes requests through edge nodes worldwide, so a request originating outside the EEA may transit an edge node in that region before reaching the Processor's servers. Visitor Data is stored exclusively in the Netherlands.
The Processor will notify the Controller of any intended changes to the list of sub-processors, giving the Controller the opportunity to object to such changes.
The Processor shall:
The Controller shall:
Upon the Controller's request or upon termination of the service:
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Parties agree the following modalities:
Audit requests should be submitted to support@statable.com.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
This DPA is effective for the duration of the Controller's use of the Statableservice and shall automatically terminate upon termination of the Controller's account.
Provisions relating to data deletion, confidentiality, and audit rights shall survive termination.
This DPA is governed by the laws of the Netherlands, without regard to conflict of law principles. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of the Netherlands.
For questions about this DPA, please contact us: