Data Processing Agreement
Last updated: August 10, 2026
This agreement governs how AGHAZADA LLC processes personal data on behalf of its customers under the GDPR and equivalent laws. It is part of our Terms of Service, applies to every customer automatically, and does not require a signature: using the service accepts it, and this published version is the agreement.
1. Parties, scope, and roles
The parties are the customer (the "Controller") and AGHAZADA LLC, New Mexico, United States (the "Processor"). This agreement applies wherever the customer's use of Open Analytics involves personal data protected by the GDPR, the UK GDPR, or comparable laws. For the data described in section 3 the customer decides purposes and means and is the Controller; we process only on the customer's documented instructions, which consist of these terms, the service's settings as the customer configures them, and its documented behaviour.
2. Definitions
"Personal data", "processing", "data subject", "controller", "processor", and "supervisory authority" carry the meanings the GDPR gives them. "Visitor data" means the data generated by the tracking script on the customer's sites. "Revenue data" means transaction records the customer routes to us through the Stripe integration.
3. Details of the processing
- Subject matter and purpose: producing aggregate web analytics, and, where connected, revenue analytics, for the customer's own sites. Nothing else.
- Duration: the life of the customer's account, plus the deletion windows in section 8.
- Data subjects: visitors of the customer's sites; where revenue data is connected, the customer's own end customers as represented in transaction records.
- Categories of data: usage data (pages, referrers, campaign parameters, device and browser family, country and city, timing), short-lived pseudonymous identifiers as described in section 4, customer supplied pseudonymous user IDs, custom event names and properties the customer defines, and transaction records (amount, currency, time, provider identifiers).
- Special categories: none. The customer agrees not to route special-category data, or directly identifying data, into event names, properties, or the identify call.
4. Anonymization by design
The service is built so that visitor data is pseudonymized at the moment of collection: unique visitors are counted with a keyed hash (HMAC-SHA256) whose inputs are a derivation version, the key version, the site's ID, the current UTC calendar date, a normalized browser class, and the IP address. Because the calendar date is an input, the identifier expires at UTC midnight; because the site ID is an input, it differs on every site; because the hash is keyed and one-way, it cannot be reversed into an address. Raw IP addresses are discarded after this derivation and are never stored in analytics data; no cookies or device identifiers are used. One bounded exception is disclosed in the Privacy Policy: a visit in progress at UTC midnight may be joined across that single midnight, within a 30-minute window and a matching per-tab hint, and the joined session is flagged as such in the data. Beyond it, the identifiers cannot be linked across sites, across days, or back to a person, and both parties rely on this design as the primary technical safeguard for visitor data.
5. The Processor's obligations
- Process personal data only on the documented instructions in section 1, unless a law we are subject to requires otherwise, in which case we inform the customer before processing unless that law forbids it.
- Ensure everyone we authorize to process the data is bound by confidentiality.
- Maintain the technical and organizational measures in section 6 and not lower them in ways that reduce protection during a term.
- Inform the customer without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting their data, with what we know and what we are doing about it.
- Assist the customer, taking the nature of the processing into account, with data subject requests, security, breach notification, and data protection impact assessments, to the extent the customer cannot fulfil these alone.
- Make available the information reasonably necessary to demonstrate compliance with this agreement, as set out in section 9.
6. Security measures
- All analytics data is stored and processed on dedicated infrastructure in the European Union (Helsinki, Finland).
- Transport encryption (HTTPS/TLS) everywhere, for the script, the dashboard, and every API.
- The anonymization design of section 4, applied at ingestion, before storage.
- Access control by role on the customer's side and least-privilege operational access on ours; API credentials are scope-bound, and destructive operations are unavailable to machine credentials.
- Isolation of customer analytics per site, idempotent ingestion with short-lived transit buffers, and deletion propagated to every store, including those buffers.
- Secrets and passwords are stored only in hashed or vaulted form; raw IPs and plaintext credentials are never written to analytics storage.
7. Subprocessors
The customer authorizes the subprocessors listed in the Privacy Policy, which names each provider, its location, and its purpose, and is the living register for this agreement. We will update that list and notify customers at least 30 days before adding or replacing a subprocessor that touches personal data. If a customer reasonably objects on data protection grounds and we cannot offer a workaround, the customer may terminate and receive a pro-rated refund of prepaid, unused fees. We remain responsible to the customer for our subprocessors' performance, and we bind each one to obligations no weaker than this agreement.
8. Deletion, return, and data subject requests
Deletion is self-serve and immediate: removing a site or an account in the dashboard permanently deletes the associated personal data from every store, and we treat that instruction as final. On termination of the service we delete remaining customer data within the retention windows stated in the Terms (90 days after a lapse, immediately on explicit deletion). Export of analytics data is available through the product and the read API, which together satisfy return-of-data requests. If a data subject contacts us directly about a customer's site, we will refer them to the customer and assist the customer as section 5 describes; for visitor data, note that the design in section 4 leaves us with no means to identify any individual's records.
9. Audits
At most once in any 12-month period, and on 30 days' written notice, the customer may audit our compliance with this agreement by requesting written responses and supporting documentation, which we will provide within a reasonable time. If those are insufficient to satisfy a genuine regulatory requirement, the parties will agree on the scope, timing, and confidentiality of any further exercise. Audits do not extend to other customers' data or to information that would compromise security.
10. International transfers
Visitor analytics data is stored in the EU and is not transferred to the United States. Where processing under this agreement involves a transfer of personal data out of the EU or UK to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (processor module), which are incorporated by reference, or on the subprocessor's Data Privacy Framework certification where it holds one.
11. Liability, precedence, and term
The liability terms of the Terms of Service apply to this agreement as one whole. If this agreement conflicts with the Terms on a data protection matter, this agreement wins. It takes effect when the customer first uses the service, remains in force as long as we process personal data for them, and its confidentiality and deletion duties survive termination. We may update it as the law evolves, with notice as for the Terms; the version published at this address, with its date, is authoritative. Questions: support@getopen.so.