Data Processing Agreement
Last updated: 2 May 2026 · Effective version: v1.1
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Glinto, Lda. (“Processor”, “we”) and you (“Controller”, “Customer”). It applies whenever we process personal data on your behalf under GDPR Article 28.
1. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given by GDPR Article 4.
2. Scope and purpose
- Subject matter: web analytics data collection and reporting as described in our Privacy policy.
- Duration: for the duration of the Terms of Service, plus any retention period described in §7.
- Nature and purpose: collecting, hashing, aggregating, and displaying website traffic data so the Customer can understand visitor behaviour on their sites.
- Types of personal data: IP addresses (hashed immediately, never stored raw), User-Agent strings (classified to categories, raw string discarded), page URLs (path only, query strings stripped).
- Categories of data subjects: visitors to websites where the Customer has installed the Glinto pixel.
3. Obligations of the Processor
We will:
- Process personal data only on documented instructions from the Controller (i.e. the pixel installation and dashboard configuration).
- Ensure that persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see §5).
- Not engage another processor without the Controller’s general written authorisation, which is given by accepting these terms. Our current sub-processors are listed at /subprocessors. We will notify the Controller at least 30 days before adding a new sub-processor.
- Assist the Controller in responding to data subject requests, to the extent technically feasible (note: visitor hashes are irreversible by design).
- Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, impact assessments).
- Delete or return all personal data at the end of the service, at the Controller’s choice. Data export is available on request within 30 days.
- Make available to the Controller all information necessary to demonstrate compliance and allow for audits. Audit requests must be reasonable in scope and frequency (no more than once per year) and scheduled with at least 30 days’ notice.
4. Obligations of the Controller
The Customer is responsible for:
- Ensuring they have a lawful basis for collecting analytics data (typically legitimate interest under GDPR Article 6(1)(f)).
- Including Glinto and Cloudflare in their own privacy policy as data processors.
- Informing visitors that analytics data is collected (a short note in the privacy policy is sufficient; no consent banner is required because Glinto uses no cookies).
5. Security measures
We implement the following technical and organisational measures:
- Encryption in transit: all traffic is TLS 1.3, enforced by Cloudflare.
- Encryption at rest: D1 databases are encrypted at rest by Cloudflare.
- IP anonymisation: SHA-256 hash with daily-rotating, per-site random salt. Raw IP is never written to any persistent storage.
- Data minimisation: no cookies, no localStorage, no query strings, no raw User-Agent strings stored. Only category-level device/browser/OS classification.
- Access control: API tokens stored as encrypted Cloudflare secrets; timing-safe token comparison; site ownership enforced via foreign key chain.
- Data isolation: each customer’s data is scoped by site ID at the storage layer. Cross-tenant access is not possible through the API.
- Automated cleanup: nightly cron worker enforces retention limits on all tables.
6. Data residency
- D1 database: jurisdictionally locked to the EU (
WEUR). All account data, site configuration, AI summaries, and anomaly records are stored exclusively in EU data centres. - Analytics Engine: event data (non-PII) is processed on Cloudflare’s global edge. No personal data is stored in Analytics Engine — only hashed, aggregated metrics.
- Authentication: customer account data (email, password hash) is stored exclusively in our EU-jurisdicted D1 database. No third-party authentication provider is used.
- Payments (Stripe): billing data is processed by Stripe Payments Europe, Ltd. (Ireland) for EU customers.
7. Data retention and deletion
- Analytics Engine events: 90 days (Cloudflare-managed).
- Daily rotating salts: 30 days, then automatically purged.
- AI summaries: 12 months in D1.
- Anomaly detections: 60 days in D1.
- Account data: until deletion is requested by the Customer.
- Upon termination, all Customer data is deleted within 30 days unless a longer retention period is required by law.
8. Data breach notification
If we become aware of a personal data breach, we will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:
- A description of the nature of the breach.
- The categories and approximate number of data subjects concerned.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach.
9. International transfers
All sub-processors are certified under the EU-U.S. Data Privacy Framework (DPF). Where DPF does not apply, Standard Contractual Clauses (SCCs) as approved by the European Commission are in place as a fallback mechanism. The full sub-processor list, including transfer mechanisms, is at /subprocessors.
10. Governing law
This DPA is governed by the laws of Portugal. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.
11. Contact
For any questions about this DPA, contact our Data Protection Officer at dpo@glinto.eu.