Data Processing Agreement

Last updated: July 18, 2026

This Data Processing Agreement (DPA) forms part of the Terms of Service between you (the Customer) and Ometra, operated by Ometra Analytics. It applies where Ometra processes personal data on your behalf and reflects the requirements of Article 28 of the GDPR.

1. Roles

For the personal data of your website's visitors processed through Ometra, you are the controller and Ometra is the processor. Each party will comply with the data protection laws applicable to it. Note that, by design, Ometra collects no cookies and no directly identifying personal data — see our Data Policy.

2. Scope and instructions

Ometra will process personal data only to provide the service and only on your documented instructions, which include these terms and your configuration of the product. We will inform you if we believe an instruction infringes applicable law.

3. Confidentiality

We ensure that personnel authorized to process personal data are bound by confidentiality and access it only on a need-to-know basis.

4. Security

We implement appropriate technical and organizational measures as described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature and risk of the processing.

5. Sub-processors

You authorize us to engage the sub-processors listed in Annex 3 to help deliver the service. We impose data protection obligations on each sub-processor equivalent to those in this DPA, and we remain responsible for their performance. We will give advance notice of any new sub-processor and you may object on reasonable data protection grounds.

6. International transfers

Analytics data is stored in Canada, which benefits from a European Commission adequacy decision for commercial organizations. Where a sub-processor is located outside Canada or the EEA (for example, in the United States), we rely on an appropriate transfer mechanism such as the Standard Contractual Clauses.

7. Assistance with data-subject requests

Taking into account the nature of the processing, we will assist you with appropriate measures to respond to requests from data subjects to exercise their rights. Because Ometra does not store identifiers or directly identifying data, we are generally unable to locate data about a specific individual, which is itself a privacy protection.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information reasonably needed for you to meet your own notification obligations.

9. Deletion and return

On termination, and at your choice, we will delete or return your personal data, and delete existing copies unless retention is required by law. Analytics data is in any case pruned automatically at the end of your plan's retention window.

10. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable notice, confidentiality, and frequency limits.

11. Term and general

This DPA remains in effect for as long as we process personal data on your behalf. It is governed by the same law as the Terms of Service. If a conflict arises, this DPA prevails for matters of data protection.

Annex 1 — Details of processing

  • Subject matter: provision of the Ometra web analytics service.
  • Duration: the term of the customer's subscription, plus applicable retention windows.
  • Nature and purpose: collecting and aggregating website usage metrics for the customer.
  • Types of data: page URLs and referrers, UTM parameters, User-Agent-derived browser/OS/device, approximate location (country/region/city) derived transiently from IP, custom event and revenue values chosen by the customer, and aggregate scroll/click data. No cookies, no stored IP addresses, no persistent identifiers.
  • Categories of data subjects: visitors to the customer's website(s).

Annex 2 — Technical and organizational measures

  • Data minimization by design: no cookies, no stored IPs, no persistent identifiers; unique visitors counted via a daily-rotating salted hash that cannot be reversed or linked across days or sites.
  • Encryption: TLS/HTTPS for data in transit; encryption at rest on managed infrastructure.
  • Access control: role-based access within the product; restricted, need-to-know administrative access to systems.
  • Credential protection: passwords stored only as salted hashes.
  • Resilience: managed database backups provided by our infrastructure provider.
  • Abuse protection: bot filtering and rate limiting on data ingestion.

Annex 3 — Sub-processors

  • DigitalOcean — cloud hosting, managed database, and object storage. Location: Canada.
  • Lemon Squeezy — payments and subscription billing (Merchant of Record). Location: United States.
  • Resend — transactional and report email delivery. Location: United States.
  • ScreenshotOne — screenshots of customer public pages for heatmap backdrops, only when the customer enables that feature. Location: European Union and United States.

Contact

To raise a data protection matter or request a countersigned copy of this DPA, email [email protected].