Data Processing Agreement

Last updated: August 6, 2026

Article 28 of the GDPR requires a written contract between a controller and its processor. This is that contract. It takes effect automatically when you create a StorePilot account — you do not need to sign or request anything, though we will sign a countersigned copy on request.

1. Parties and scope

This agreement is between you (the Controller) and:

[COMPANY NAME] sp. z o.o.
[STREET], [POSTCODE] [CITY], Poland
KRS [0000000000] · NIP [0000000000]
contact@store-pilot.net

(the Processor). It forms part of the Terms of Service and governs all personal data we process on your behalf. Where it conflicts with the Terms of Service, this agreement prevails on data protection matters.

It does not cover data for which we are ourselves the controller — your own account details, for example. Those are in the Privacy Policy.

2. Subject matter of the processing

ItemDetail
Subject matterProviding website analytics, session recording, error monitoring and lead capture for websites you control
DurationFor as long as your account exists, plus the deletion period in §9
Nature and purposeCollection, storage, structuring, aggregation, display and deletion of visitor data, solely to present it back to you
Categories of data subjectVisitors to, and registered users of, your websites
Categories of personal dataOnline identifiers, IP address, device and browser characteristics, approximate location (country), behavioural data including session recordings, error diagnostics, and — where you enable lead capture — contact details and cart contents entered into forms
Special-category dataNone is requested or intended. You must not configure the service to capture it — see §4(e)

3. Our obligations as processor

We will:

  1. process personal data only on your documented instructions. Your configuration of the service — which sites, what masking, what retention — constitutes those instructions. If we are required by EU or member state law to process it otherwise, we will tell you first unless that law forbids it;
  2. ensure that everyone authorised to process the data is bound by confidentiality;
  3. implement the technical and organisational measures described in §6;
  4. engage sub-processors only under §5, and remain fully liable to you for their performance;
  5. help you respond to data subject requests, using the erasure and export tools built into the dashboard, and assist further where those tools are not enough;
  6. help you with data protection impact assessments and with prior consultation of a supervisory authority, taking into account the information available to us;
  7. notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need for your own 72-hour notification;
  8. delete or return the data as set out in §9;
  9. make available the information needed to demonstrate compliance with Article 28, and allow audits under §8.

We will not sell your data, use it for our own advertising, use it to train machine-learning models, or disclose it to anyone except as set out here or as required by law.

4. Your obligations as controller

You confirm and agree that:

  1. you have a lawful basis for the collection you instruct us to perform;
  2. you have given your visitors the information required by Articles 13 and 14 — that session recording and analytics are in use, by whom, and for how long;
  3. where the ePrivacy Directive requires consent for storing identifiers in a visitor's browser, you have obtained it before our collector runs. The Cookie Policy lists exactly what is stored;
  4. you own or administer every website on which you install the collector;
  5. you will not weaken the default input masking on pages handling payment card data, health data or other special-category data, and you accept responsibility if you do.

5. Sub-processors

You give general written authorisation for us to engage sub-processors. The current list is published at Sub-processors and is part of this agreement.

We will give at least 30 days' notice before adding or replacing one, by email to account administrators and by updating that page. If you reasonably object on data protection grounds within those 30 days, you may terminate your account and we will refund any prepaid fees for the unused period.

Every sub-processor is bound by written terms no less protective than these, and we remain liable to you for what they do.

6. Security measures (Article 32)

  • TLS encryption for all data in transit, including between our own services.
  • Encryption at rest for stored credentials; passwords stored only as bcrypt hashes.
  • Tenant isolation enforced in the data model: every record carries the owning site, and authorisation is re-checked on every request rather than assumed from a prior one.
  • Session recordings and heatmap images are served only to authenticated members of the owning organisation.
  • Input masking on by default in recordings; password fields never captured at all.
  • Rate limiting on ingest, keyed per site, to contain abuse of a leaked key.
  • Least-privilege access for our personnel, with access logged.
  • Automated retention enforcement, so data is deleted on schedule rather than on memory.

7. International transfers

All processing takes place on servers within the European Union. Neither we nor our sub-processors transfer personal data outside the European Economic Area, so Chapter V transfer mechanisms — Standard Contractual Clauses, adequacy decisions — do not apply.

Should that ever change, we will give notice under §5 and put appropriate safeguards in place before any transfer begins.

8. Audit

On request, and no more than once in any 12 months unless a supervisory authority or a breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this agreement. Where that is not sufficient, we will cooperate with an audit conducted by you or an independent auditor bound by confidentiality, at your cost, on 30 days' notice and during business hours, in a manner that does not compromise other customers' data.

9. Deletion and return

You may export your data at any time while the account is active. On termination we keep it for 30 days so an account closed by mistake can be recovered, and then delete it, including from backups on their normal rotation.

Deleting a visitor during the life of the account removes their recordings, page views, leads, click data and stored recording files. Aggregated daily statistics that identify no one are retained.

10. Liability and governing law

Liability under this agreement is subject to the limits in the Terms of Service, except where the GDPR provides otherwise. It is governed by the law of Poland.

11. Requesting a signed copy

Email contact@store-pilot.net with your account and company details and we will return a countersigned PDF. If your organisation requires its own DPA template, send it — we will review it.