Legal
Data processing agreement
Last updated
The short version
- This agreement is part of the terms of service. You accept it when you accept the terms.
- You are the controller of your visitors’ data. We process it only on your instructions.
- Nothing is written to your visitors’ devices, masking happens in their browser, page addresses are trimmed before they are sent, and no IP address is ever stored.
- We give you 30 days’ notice before adding a subprocessor, and you can object.
- We report a personal data breach to you within 72 hours of becoming aware of it.
- Your data is hosted in the European Union.
- Transfers out of Europe are covered by the Standard Contractual Clauses, governed by Irish law.
This summary is for convenience. The full text below is what applies.
1. Parties and how this agreement applies
This agreement is between the organization that holds a WebMetric account (“you”, the controller) and Mivo Solutions Ltd, KN 78 St, Nyarugenge, Kigali, Rwanda (“we”, the processor). It forms part of the terms of service and applies from the moment you accept them. No separate signature is needed.
It applies to personal data we process for you under the GDPR, the UK GDPR, Rwanda’s law on the protection of personal data and privacy, and any other data protection law that applies to that processing. If you are yourself a processor for someone else, you confirm that your controller has authorised you to use us.
2. Subject matter, nature and duration
- Subject matter: providing WebMetric, which collects, stores, aggregates and displays behaviour data from the websites you install it on.
- Nature and purpose: receiving events from your sites, turning them into sessions, heatmaps, funnels and reports, and, where your plan includes it, storing and replaying masked session recordings.
- Duration: for as long as your account is open, and afterwards until the data is deleted under section 13.
3. Categories of data and data subjects
Data subjects are the visitors to your websites and the members of your organization.
| Category | What it is |
|---|---|
| Visitor identifier | A pseudonymous hash computed at our collector with a secret that changes every half-year and is deleted one day after that half-year ends. Nothing is stored on the visitor’s device. |
| Pages | Page addresses with the part after a # and every query parameter except utm_* campaign tags removed, and referrers as origin and path only |
| Device | Device type, browser and operating system, derived from the user agent |
| Location | Country, region and city. The IP address is used in memory to look them up and to compute the visitor hash, and then discarded. |
| Interactions | Click coordinates, CSS selectors and the labels of clicked buttons and links, scroll depth, form submissions and timing |
| Custom events | The event names and custom properties your site sends |
| Session recordings | The page structure and its changes during a visit, masked in the browser before sending. Only on plans that include replay. |
| Page snapshots | The layout and styles of a page with all of its text masked, so heatmaps can be drawn on it. Captured only when snapshots are turned on. |
You must not send special category data, and you must keep personal data such as email addresses and names out of custom properties and URLs, as the terms require.
4. Processing on your instructions
We process personal data only on your documented instructions. These are the terms, this agreement, the settings you choose in WebMetric, and any other written instruction you give us. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data in another way, we will tell you first unless the law forbids it.
5. Confidentiality
Everyone on our team who can reach your data is bound by a duty of confidentiality. Access is limited to what they need to run and support the service.
6. Security measures
We apply the following technical and organizational measures:
- Our script writes nothing to the visitor’s device: no cookies and no browser storage.
- IP addresses are discarded at the collector. No stored column holds one.
- Do Not Track and Global Privacy Control are honoured in the script and again at the collector.
- Session replay is masked in the visitor’s browser by default. Password fields are never captured, and masking cannot be turned off for them.
- Heatmap page captures mask all text on the page, as well as form inputs, in the visitor’s browser before they are sent.
- Page addresses lose the part after a # and every query parameter except campaign tags, in the browser and again at the collector.
- Known bots are dropped at ingest.
- Every request to the API is authorised against the organization that owns the data.
- Session recordings are served only through the API, after that check. There are no shareable links to them.
- Passwords and read keys are hashed with Argon2id. Session tokens are stored only as hashes.
- The service that receives events can only write to object storage. The service that serves the dashboard can only read, list and delete.
- Expired recordings are removed by a job that runs every hour.
- Staff support access is limited as described in section 11.
We hold no third-party security certification at this time.
7. Subprocessors
You give us general authorisation to use subprocessors. The current list, with each one’s purpose and region, is on the subprocessors page. Each subprocessor is bound by data protection terms that give at least the protection in this agreement, and we stay responsible for its work.
We will tell your organization’s admins at least 30 days before we add or replace a subprocessor. You can object on reasonable data protection grounds within that time. If we cannot address the objection, you can close your account before the change takes effect.
8. Helping with data subject requests
On every plan you can export your data and erase a visitor yourself, which deletes their events, sessions, session recordings and the page captures taken during their visits. Where you cannot answer a request with those tools, we will help within a reasonable time. If a data subject writes to us directly, we will pass the request to you.
9. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data. We will tell you what we know, what we are doing about it, and keep you updated as we learn more.
10. Impact assessments and consultation
We will give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority about WebMetric.
11. Staff support access
Our support staff can view your workspace only in a support session. A session covers one organization, lasts one hour, requires a written reason and is recorded in your audit log when it starts and ends. It is read-only, and it cannot open session recordings or read your member list. The privacy policy has the full list of limits.
12. Retention
Session recordings are kept for 30 days. Aggregated rollups are kept for 25 months. Audit logs are kept for 12 months. Raw events are kept for the history period of your plan:
| Plan | Raw events kept for |
|---|---|
| Free | 60 days |
| Starter | 180 days |
| Growth | 365 days |
| Enterprise | 760 days |
13. Deletion or return at the end
For 30 days after your account closes, you can ask us for an export of your data. We delete it from our live systems, including rollups, within 30 days of the account closing, and copies in our backups roll off within a further 35 days. We keep data longer only where the law requires it.
14. Audits
We will make available the information you reasonably need to show that we meet this agreement. If that is not enough, you may audit our compliance, or have an independent auditor do so, with reasonable notice, during business hours and no more than once a year unless a breach or a regulator requires it. You bear the cost of your audit.
15. International transfers and the Standard Contractual Clauses
Your data is hosted on our own server, in a data centre in the European Union, as listed on the subprocessors page. We are based in Rwanda, so access by our team is a transfer out of the European Economic Area. For that access, and wherever data about people in the European Economic Area goes to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 apply and are incorporated into this agreement:
- Module Two (controller to processor) applies where you are a controller.
- Module Three (processor to processor) applies where you are a processor.
- Under Clause 9, option 2 applies: general written authorisation for subprocessors, with 30 days’ notice as in section 7.
- The optional wording in Clause 11 does not apply.
- Clauses 17 and 18: the clauses are governed by the law of Ireland, and disputes under them are resolved by the courts of Ireland.
- Annex I is completed by sections 1 to 3 of this agreement, Annex II by section 6, and Annex III by the subprocessors page.
For data about people in the United Kingdom, the UK International Data Transfer Addendum applies alongside the clauses. For Switzerland, the clauses apply with references to the GDPR read as references to Swiss law. If this agreement and the clauses conflict, the clauses win.
16. Order of precedence and contact
If this agreement conflicts with the terms of service on data protection, this agreement wins. Questions about it go to info@mivosolutions.com.