Data Processing Agreement

Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR (Auftragsverarbeitungsvertrag, AVV).

Version 1.0 — 19 September 2026

1. Parties and scope

Controller: the customer who uses sub.analytics on one or more of their websites.

Processor: Tilman Richter, operating sub.analytics, Auf den Häfen 5, 28203 Bremen, Germany, hello@subnodes.net.

This agreement forms part of the Terms of Service and applies to every account without a separate signature. A countersigned copy is available on request. Where this agreement and the Terms conflict on the protection of personal data, this agreement prevails.

2. Subject, duration, nature and purpose

The processor measures website traffic on the controller’s websites and presents it in a dashboard. Processing consists of receiving pageview requests from visitors’ browsers, reducing them to the data listed in section 3, storing that data and producing aggregated statistics from it.

Processing lasts as long as the controller’s account exists, plus the deletion periods in section 10.

3. Types of data and data subjects

Data subjects: visitors to the controller’s websites.

DataHandling
IP addressUsed in memory to derive the country and the daily hash, then discarded. Never stored.
User-agent stringUsed in memory to derive the browser family and the daily hash, then discarded. Never stored.
Daily hashSHA-256 of a random per-day salt, the site, the IP address and the user agent. Stored. The salt is deleted when its day ends and is never backed up, so the hash cannot afterwards be traced to an IP address.
Page pathStored, without query string or fragment.
ReferrerOnly the referring domain is stored.
Country, browser family, device typeStored.
Time of visit, time on pageStored.

No cookies are set and nothing is stored on the visitor’s device. Requests from browsers that send a Do Not Track signal are not processed.

4. Instructions

The processor processes personal data only on documented instructions from the controller. The instructions are this agreement, the Terms of Service and the settings the controller makes in the service. The processor informs the controller without delay if it believes an instruction infringes data protection law.

5. Confidentiality

Only the processor personally has access to the personal data. The processor is bound to confidentiality. Should anyone else be given access in future, they will be bound to confidentiality in writing first.

6. Security of processing

The processor implements the technical and organisational measures in Annex 1 (Art. 32 GDPR). The processor may improve them over time, provided the level of protection does not fall.

7. Sub-processors

The controller authorises the following sub-processor:

Sub-processorServiceLocation
Hetzner Online GmbH, Industriestr. 25, 91710 GunzenhausenServer hosting and encrypted backup storageGermany

Stripe processes the controller’s own billing details as an independent controller and never receives visitor data, so it is not a sub-processor under this agreement.

The processor informs the controller by e-mail at least 30 days before adding or replacing a sub-processor. The controller may object within that period; if no solution is found, the controller may terminate the service. Visitor data is not transferred outside the European Economic Area.

8. Assistance

The processor helps the controller, as far as possible, to respond to requests from data subjects exercising their rights, and to meet the obligations in Art. 32–36 GDPR, including data protection impact assessments. Because stored data cannot be linked to an individual, requests about a specific visitor can usually only be answered with that fact.

9. Personal data breaches

The processor informs the controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the controller’s data, with the information the controller needs to meet its own obligations under Art. 33 and 34 GDPR.

10. Deletion and return

When the account is deleted or the service ends, the processor deletes the controller’s data from the live system within 30 days. Encrypted backups are kept for up to 12 months and cannot be edited, so the data disappears from them as they rotate out — within 12 months at the latest. On request before deletion, the processor provides a CSV export of the controller’s data.

11. Audits

The processor provides all information needed to demonstrate compliance with this agreement. The controller, or an auditor bound to confidentiality, may carry out an inspection once a year with at least 30 days’ notice, during normal working hours and at the controller’s cost.

12. Liability and law

Liability follows Art. 82 GDPR and, beyond that, the Terms of Service. This agreement is governed by German law; the courts of Bremen, Germany, have jurisdiction.

Annex 1 — Technical and organisational measures (Art. 32 GDPR)

  • Data minimisation. IP addresses and user-agent strings are never stored. Visitors are represented only by a daily hash whose salt is random, deleted when its day ends, and excluded from backups.
  • Encryption in transit. All traffic uses TLS (HTTPS) with HTTP Strict Transport Security.
  • Protection of backups. The off-site backup copy is encrypted on the server before it is transferred, and stored encrypted. The on-server copy is readable only by the administrator account.
  • Access control. Server login by SSH key only; password login is disabled. Repeated failed logins are blocked automatically. Only the ports for SSH, HTTP and HTTPS are reachable from the internet; databases and application services listen only on the server itself.
  • Separation. Each customer’s data is tied to their account and only returned for that account. Each tracked site accepts data only from its registered domain.
  • Integrity. All input is validated on the server. Ingestion is rate-limited per client address.
  • Availability and recovery. Databases are backed up every night, copied to a second location, and restore-tested every month by restoring into a separate database and comparing row counts.
  • Maintenance. Operating system and software security updates are applied regularly.
  • Location. All servers and backups are in Germany.