Data Processing Agreement

Last updated: August 11, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween Key Arg B.V. ("Processor", "we", "us") and the customer ("Controller", "you") who uses our Statable analytics service.

By using Statable, you automatically accept this DPA. No separate signature is required.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
  • "Controller" means you, the customer who determines the purposes and means of processing visitor data by deploying the Statable analytics script on your website.
  • "Processor" means Key Arg B.V., which processes visitor data on behalf of the Controller.
  • "Visitor Data" means the analytics data collected by the Statablescript from visitors of the Controller's website.
  • "Sub-processor" means a third-party service provider engaged by the Processor to assist in processing Visitor Data.

2. Scope of Processing

The Processor processes Visitor Data solely for the purpose of providing web analytics services to the Controller. The categories of data processed include:

  • IP address— used to compute the per-day visitor identifier and to derive approximate location (country, region and city, including the city's approximate coordinates) from a local geolocation database. The IP address is not written to the analytics database
  • User-Agent string— used for hash generation and parsed into browser, operating system and device type. The User-Agent is not written to the analytics database
  • Page URLs and referrer URLs— stored without query strings or fragments; campaign parameters (UTM) and advertising click-id names are extracted into separate fields before the rest of the query string is discarded at ingest. The Controller is responsible for not placing personal data in URL paths (see section 7)
  • Timestamps— page view times, session duration
  • Engagement signals— engagement time, scroll depth, outbound link clicks, file downloads and the page status code
  • Custom events and properties— only if configured by the Controller

Categories of data subjects: visitors of the Controller's website.

The Processor does not intentionally collect names, email addresses, telephone numbers or other directly identifying information about website visitors. Such data may nevertheless reach the Processor if the Controller places it in page URLs or custom event properties; section 7 allocates responsibility for that to the Controller.

3. Pseudonymisation

The Processor pseudonymises Visitor Data using a keyed one-way hash:

SipHash(secret_key, site_id | ip_address | user_agent | date)

This mechanism ensures:

  • The IP address and User-Agent are discarded once the identifier is computed and are not written to the analytics database
  • The secret key is held only by the Processor, so the identifier cannot be recomputed by any third party
  • The calendar date forms part of the input, so a visitor's identifier changes every day and reports do not link a visitor across days
  • Identifiers are scoped per site, so the same person visiting two sites served by the Processor is counted as two unrelated visitors
  • The hash cannot be reversed into an IP address or User-Agent

The Parties acknowledge that this constitutes pseudonymisation within the meaning of Article 4(5) GDPR, not anonymisation: Visitor Data remains personal data and is processed under this DPA.

4. Security Measures

The Processor implements the following technical and organizational measures to protect Visitor Data:

  • Encryption in transit— all data transmitted over HTTPS with TLS
  • Data minimization— only the minimum necessary data is collected
  • Pseudonymisation— keyed one-way hashing with a per-day identifier
  • Access controls— role-based access to production systems
  • DDoS protection— Bunny WAF and DDoS mitigation

For full details, see our Security Practices page.

5. Sub-Processors

The Controller authorizes the Processor to engage the following sub-processors:

Sub-processorPurposeLocation
NorthC DatacentersColocation facility — rack space and power for the Processor's own servers; no access to Visitor DataOude Meer, Netherlands (EU)
BunnyCDN and network securityEU
Stripe, Inc.Payment processingUnited States
Google LLCOAuth authentication (optional)United States

The Processor owns and operates the servers on which Visitor Data is stored. NorthC provides the facility in which those servers are housed — rack space, power and physical security — and does not process Visitor Data.

Stripe, Inc., GitHub, Inc., and Google LLC process account and payment data for which the Processor acts as controller. They do not process Visitor Data and are therefore not sub-processors under this DPA; their role is described in our Privacy Policy.

Bunny is an EU company. Its content delivery network routes requests through edge nodes worldwide, so a request originating outside the EEA may transit an edge node in that region before reaching the Processor's servers. Visitor Data is stored exclusively in the Netherlands.

The Processor will notify the Controller of any intended changes to the list of sub-processors, giving the Controller the opportunity to object to such changes.

6. Processor Obligations

The Processor shall:

  • Process Visitor Data only in accordance with the Controller's documented instructions and for the purpose of providing the analytics service
  • Ensure that all personnel authorized to process Visitor Data are bound by confidentiality obligations
  • Implement and maintain the security measures described in this DPA and our Security Practices
  • Assist the Controller in responding to data subject requests, given the pseudonymised nature of Visitor Data
  • Notify the Controller without undue delay upon becoming aware of a personal data breach
  • Immediately inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data protection law
  • Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR, including security of processing, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to the Processor
  • Delete or return all Visitor Data upon termination of the service, unless retention is required by applicable law

7. Controller Obligations

The Controller shall:

  • Ensure that there is a valid legal basis for the processing of Visitor Data. The Processor's cookie-free design is intended to support processing under legitimate interest, but the assessment and its documentation remain the Controller's responsibility
  • Provide any necessary privacy notices to website visitors regarding the use of analytics
  • Not configure the Statable script to collect personal data through custom events or properties without appropriate legal basis
  • Not place personal data in URL paths, as paths are stored as part of Visitor Data (query strings are discarded at ingest, see section 2)

8. Data Deletion

Upon the Controller's request or upon termination of the service:

  • The Controller can delete individual website data at any time through the dashboard
  • The Controller can delete their entire account and all associated data
  • Deletion is permanent and immediate: removing a website deletes its analytics data, and deleting an account deletes every website it owns together with their data
  • Analytics data is retained while the Controller's account exists. The Processor does not delete it automatically when a subscription lapses; the Controller can delete it at any time, and the Processor will do so on request

9. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Parties agree the following modalities:

  • The Processor will in the first instance satisfy audit requests by providing its then-current security documentation and, where available, third-party audit reports or certifications
  • Where that documentation is not sufficient to demonstrate compliance, or where a supervisory authority so requires, the Controller may conduct an on-site audit no more than once in any twelve-month period, on at least thirty (30) days' written notice, during normal business hours, and in a manner that does not unreasonably disrupt the Processor's operations
  • Any auditor mandated by the Controller must be independent of the Processor's competitors and bound by written confidentiality obligations no less protective than those in this DPA
  • Audits are limited to systems and documentation relevant to the processing of the Controller's Visitor Data. The Processor will not provide access to data or configuration relating to other customers, or to information whose disclosure would breach the Processor's confidentiality obligations to third parties or compromise the security of the Service
  • Each Party bears its own costs. The Controller bears the Processor's reasonable costs for any on-site audit beyond the first in a twelve-month period
  • Additional audits may be conducted where required by a supervisory authority or following a personal data breach affecting the Controller's Visitor Data

Audit requests should be submitted to support@statable.com.

10. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.

11. Duration and Termination

This DPA is effective for the duration of the Controller's use of the Statableservice and shall automatically terminate upon termination of the Controller's account.

Provisions relating to data deletion, confidentiality, and audit rights shall survive termination.

12. Governing Law

This DPA is governed by the laws of the Netherlands, without regard to conflict of law principles. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of the Netherlands.

Contact

For questions about this DPA, please contact us:

  • Email: support@statable.com
  • Key Arg B.V. (KvK 89388496), Herckenrathstraat 1, 2681 DG Monster, South Holland, Netherlands