Data processing agreement
Last updated 2026-09-25
This agreement applies whenever TraceLog processes personal data on a customer's behalf. It forms part of the terms of service, and it is entered into by creating an account — no signature is required.
Roles
The customer is the controller. TraceLog is the processor and acts only on the customer's documented instructions: the declared conversion path and the settings chosen in the application.
Subject matter, duration, nature and purpose
Subject matter: the conversion record TraceLog captures from the customer's declared path. Duration: for as long as the account exists, plus the retention windows stated in the privacy policy. Nature and purpose: capturing, storing, aggregating, and alerting on the events the customer declares, so that the customer can tell whether that conversion record is complete.
Categories of data and of data subjects
Data subjects are visitors to the customer's website and the customer's own account members. No special-category data is processed; the product has no field for it.
| Category | What it holds |
|---|---|
| Session record | Referrer, campaign parameters, acquisition channel and AI platform where confirmed, device class, country, landing page, start time |
| Conversion path | Declared conversion name, the customer's own stable identifier, optional value and currency, declared preceding steps and their context |
| Account data | Member name, email address, role, and the authentication records better-auth keeps in TraceLog's own database |
Security measures
- Data in the European Union, in one PostgreSQL instance, with transport encryption in front of it
- Every trusted operation and every query carries a project identifier, and every data access path has a tenant-isolation test
- Access to a customer's data by TraceLog's own operator is limited to named, individually authorized people, working through one interface whose reads of an account are recorded with who made them and why, in a log TraceLog can add to but cannot edit or delete
- Credentials are stored as verifier material, never as recoverable secrets; a secret is rendered once, at creation or rotation
- No secrets, credentials, or raw payloads are written to logs
- Raw events expire from the hot window on a schedule the product runs itself, not on a person remembering
Subprocessors
TraceLog engages the subprocessors listed on the subprocessors page and gives notice before adding one, so a customer can object. Each is bound by terms no less protective than these.
Assistance, breach, and deletion
TraceLog assists the customer in answering data-subject requests, in carrying out impact assessments, and in consulting a supervisory authority where one is required.
TraceLog notifies the customer without undue delay after becoming aware of a personal data breach, with what is known at the time and what is being done.
On termination TraceLog deletes the customer's data on the schedule stated in the privacy policy. A customer may export it from the application before then.
Audit
The customer may verify compliance with this agreement once a year, and after a breach, by written request to info@tracelog.io. TraceLog answers with the information needed to demonstrate it.
If you have questions about this page, email info@tracelog.io. A person from TraceLog will reply.