Data Processing Addendum (DPA)
Last updated: September 9, 2026. Supplementary terms governing privacy-compliant data processing.
1. Scope and Applicability
This Data Processing Addendum ("DPA") supplements the Terms of Service between VeloStats ("Processor") and the customer agreeing to these terms ("Controller").
This DPA applies to the processing of personal or pseudonymous telemetry data originating from end-user visits to websites registered by Controller to the extent regulated under European Data Protection Law (including GDPR 2016/679, UK GDPR, and Swiss FADP).
2. Roles and Instructions
Controller Status: Controller determines the purposes and essential means of integrating the VeloStats tracker on its web properties.
Processor Obligations: Processor shall process telemetry data only in accordance with Controller's documented instructions (including configuration settings in the VeloStats dashboard) and as necessary to provide the Service, unless required to do otherwise by applicable law.
3. Nature, Purpose & Categories of Data
- Purpose of Processing: Website traffic analytics, Core Web Vitals performance telemetry, bot classification, and hourly/daily aggregation reporting.
- Categories of Data: URL paths visited, referrer URLs, coarse device and browser parameters, coarse geographic attributes (country, region, city via local GeoIP lookup), and pseudonymous daily visitor hashes generated via HMAC-SHA256.
- Special Categories of Data: The Service is not intended for the collection of sensitive personal data (e.g., medical, biometric, racial, or financial records), and Controller agrees not to transmit such data via custom URLs or metadata.
4. Technical and Organizational Security Measures (TOMs)
Processor implements and maintains industry-standard technical and organizational measures to ensure a level of security appropriate to the risk:
Zero IP Retention
IP addresses are strictly memory-resident for coarse Geo/ASN lookups and discarded immediately. No raw IP addresses are ever written to database tables or logs.
Cryptographic Salt Rotation
Daily visitor identifiers are hashed using a rotating secret salt that is automatically invalidated every 24 hours, preventing cross-day correlation.
Transport & Storage Security
All telemetry transmissions require modern TLS (HTTPS). Databases reside on private, isolated internal networks with strict access controls.
Automated Purging
Raw event records are partitioned and automatically dropped after 90 days. Full tenant data deletion cascades immediately upon request.
5. Authorized Sub-Processors
Controller grants general authorization for Processor to engage the following sub-processors to assist in delivering the Service:
- Cloudflare, Inc.: Reverse proxy, DDoS mitigation, and Turnstile challenge services.
- Resend, Inc.: Transactional email service for account-related notifications.
Processor remains fully liable for the performance of each sub-processor's obligations under applicable data protection laws.
6. Data Subject Rights Assistance
Given that VeloStats does not store personal identifiable information, raw IP addresses, or persistent cookies, Processor is technically unable to identify any specific natural person in historical event logs without additional external data. In the event Controller receives a data subject request under GDPR (e.g., Articles 15–22), Processor shall provide reasonable technical assistance to Controller to verify and respond to such requests.
7. Security Incidents & Breach Notification
Processor shall notify Controller without undue delay (and in any event within 72 hours) upon confirming any actual security incident leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Controller telemetry data.
8. Deletion and Return of Data
Upon termination of Controller's account or explicit request, Processor shall permanently delete all Controller site configurations, telemetry records, and aggregated statistics in accordance with our documented data deletion protocol, unless required by applicable law to retain specific records.
9. Contact Details
For DPA execution inquiries or compliance questions, please contact: