Foresite Data Processing Agreement

Written to the EU GDPR (Art. 28) standard so that one agreement also covers UK GDPR, Canada's PIPEDA, and US state privacy laws.

Effective date: 7 October 2026

This Data Processing Agreement ("DPA") forms part of the Foresite Terms of Service ("Terms") between the Customer ("Controller", "you") and Devon Theriault, carrying on business as Devs Industries ("Processor", "Foresite", "we"). It applies automatically when you accept the Terms. No signature is needed.

Words not defined here have the meaning given in the Terms or in the GDPR. If this DPA conflicts with the Terms, this DPA wins for matters of personal data.

1. Definitions

  • Data Protection Laws: all laws that apply to the processing of Personal Data under the Terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial laws, and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
  • Personal Data: any information relating to an identified or identifiable natural person that we process on your behalf in providing the Service, as described in Annex 1.
  • Visitor: a person who visits a website on which you have installed the Tracking Script.
  • Subprocessor: a third party we engage that processes Personal Data on your behalf.
  • Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

2. Roles

2.1 You are the controller (or, under CCPA, the "business") of Personal Data about Visitors. We are your processor (or "service provider").

2.2 For your own account data (such as your email address), we are an independent controller, as described in our Privacy Policy. That data falls outside this DPA.

3. Our obligations

3.1 Instructions. We process Personal Data only on your documented instructions. Those instructions are the Terms, this DPA, and your configuration of the Service (for example, which Sites you add and which automatic events you enable). If we believe an instruction breaks Data Protection Laws, we'll tell you.

3.2 Data minimisation by design. The Service is built to process as little Personal Data as possible:

  • IP addresses and User-Agent strings are processed in memory only and are never written to persistent storage;
  • unique visitors are counted using a hash with a salt that rotates daily, and each salt is destroyed within 24 hours after its day ends;
  • location is determined to region level at most, never city;
  • nothing is stored on Visitors' devices;
  • values that look like personal data (such as email addresses, phone numbers, IP addresses and payment card numbers) are automatically discarded from custom event properties.

3.3 Confidentiality. Anyone we authorise to process Personal Data is bound by confidentiality.

3.4 Security. We maintain the technical and organisational measures in Annex 2.

3.5 No selling or sharing. We will not sell or share Personal Data (as those terms are defined in the CCPA), or use it for any purpose other than providing the Service. That includes using it for advertising, profiling, or combining it with data from other sources.

4. Your obligations

4.1 You are responsible for having a lawful basis for the processing, and for giving Visitors any notices your Data Protection Laws require.

4.2 You must not send us Personal Data beyond what is described in Annex 1, in particular names, email addresses, account identifiers or other direct identifiers in custom events, page URLs or any other field (see section 8 of the Terms).

5. Subprocessors

5.1 You give general authorisation for us to use the Subprocessors listed at foresite.dev/subprocessors (current list).

5.2 We'll give you at least 30 days' notice by email before adding or replacing a Subprocessor. If you object on reasonable data protection grounds and we can't resolve your objection, you may terminate the affected Subscription and we'll refund any prepaid fees for the period after termination.

5.3 We impose data protection obligations on each Subprocessor that are no less protective than this DPA, and we remain responsible to you for their performance.

6. International transfers

6.1 Visitor event data is stored in the European Union.

6.2 Foresite is operated from Canada, which the European Commission has recognised as providing an adequate level of protection for commercial organisations subject to PIPEDA.

6.3 For any transfer of Personal Data from the EU/EEA, UK or Switzerland to a country without an adequacy decision, the parties agree to the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, with the UK Addendum where relevant. These are incorporated by reference, with Annex 1 and Annex 2 of this DPA completing their appendices. For Clause 17 and Clause 18, the governing law and courts are those of Ireland.

7. Helping you

7.1 Data subject requests. Because the Service holds no direct identifiers and visitor hashes cannot be recomputed after the daily salt is destroyed, we generally cannot link data to a specific Visitor. To the extent we can, we will help you respond to requests to exercise data subject rights. If we receive a request directly, we'll redirect the requester to you.

7.2 Assessments. We'll provide information reasonably needed for your data protection impact assessments and any prior consultation with a supervisory authority.

8. Security Incidents

8.1 We'll notify you without undue delay, and in any case within 48 hours, after becoming aware of a Security Incident affecting your Personal Data.

8.2 The notice will describe, as far as known, the nature of the incident, the data and approximate number of people affected, likely consequences, and the measures taken or proposed. We'll update you as more information becomes available.

9. Deletion and return

9.1 You can export your data as CSV from the dashboard at any time while your account is active and during the 30-day read-only period after it lapses.

9.2 Personal Data is deleted from our live systems at the end of that 30-day period, or within 24 hours if you delete your account yourself, and from all backups within a further 30 days. The exception is any data we are legally required to keep.

10. Audits

10.1 Once a year, on request, we'll answer a reasonable written security questionnaire and provide documentation demonstrating our compliance with this DPA.

10.2 If a supervisory authority requires it, or after a Security Incident, you may conduct an audit at your own cost. It requires 30 days' notice, must be conducted during business hours, must not disrupt the Service, and is subject to confidentiality.

11. Liability and term

11.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.

11.2 This DPA lasts as long as we process Personal Data on your behalf.


Annex 1: Description of processing

Subject matter Providing privacy-focused web analytics for the Customer's websites
Duration For the term of the Customer's Subscription, plus the deletion periods in section 9
Nature and purpose Collecting, aggregating and displaying website usage statistics; filtering bot and abusive traffic; exporting statistics and events at the Customer's request
Data subjects Visitors to the Customer's websites
Categories of data Processed transiently (in memory, never stored): IP address and User-Agent. Stored: daily visitor hash (cannot be linked once the daily salt is destroyed); page URL; referrer; UTM parameters; country and region; browser, operating system and device type; timestamp; custom event names, properties and revenue amounts as configured by the Customer; automatic events (outbound link clicks, file downloads, 404 pages) if enabled by the Customer
Special categories None. The Customer must not send special-category data.
Frequency Continuous, for every pageview and event
Retention While the Subscription is active, then deleted as described in section 9

Annex 2: Technical and organisational measures

  1. Minimisation by design: as described in section 3.2. No cookies or device storage for Visitors, IP addresses never persisted, salts destroyed daily, location capped at region, personal-data patterns filtered from event properties.
  2. Encryption: TLS for all data in transit; encryption at rest for all databases and backups.
  3. Access control: production access limited to the operator, protected by multi-factor authentication, with least-privilege credentials; there is no shared access to production.
  4. Separation: Visitor event collection runs on a separate, cookie-free host, isolated from the customer dashboard.
  5. Tenant isolation: each Site's data is accessible only to its owning Customer and to holders of that Site's Share Links.
  6. Resilience: managed database services with automated backups, kept for 30 days; incoming events are queued if the database is unavailable; continuous monitoring with alerting to the operator; a public status page.
  7. Abuse protection: bot, data-centre and rate-based filtering; forwarded IPs from proxies are accepted only with the Site's secret.
  8. Verifiability: the Tracking Script is open source (https://github.com/devontheriault/foresite-tracker), so anyone can inspect exactly what it collects.
  9. Deletion: automated deletion on lapse and on account deletion, as described in section 9.
  10. Incident response: a documented process to assess, contain and notify within 48 hours.

Annex 3: Subprocessors

See Subprocessors.