Data Processing Agreement
Effective date: August 8, 2026
Thank you for using RevScope. Processing and storing data in a secure, fair, and transparent way is important to us. Our servers and analytics data are hosted in the European Union and subject to strong EU data protection rules.
This Data Processing Agreement (“DPA”) is an addendum to the agreement between RevScope and the customer for use of the RevScope service. It applies to visitor data processed by RevScope on behalf of the customer in connection with that service.
If you are accepting this DPA on behalf of a customer, you warrant that: (a) you have full legal authority to bind that customer to this DPA; (b) you have read and understand this DPA; and (c) you agree, on behalf of that customer, to this DPA.
Definitions
- “You” or “customer” refers to the company or organization that signs up to use RevScope to analyze website visitors and revenue attribution.
- In the course of providing the RevScope service, RevScope may process visitor data on behalf of the customer.
- “Data Protection Legislation” means the General Data Protection Regulation (Regulation (EU) 2016/679) and all other applicable laws relating to processing of visitor data and privacy that may exist in any relevant jurisdiction.
- “data controller”, “data processor”, “data subject”, “personal data”, and “processing” shall be interpreted in accordance with applicable Data Protection Legislation.
- The parties agree that the customer is the data controller and that RevScope is its data processor in relation to visitor data processed in the course of providing the service.
Privacy and security of visitor data
When you use RevScope to measure your website and revenue attribution, RevScope will collect information about your visitors as described in our Privacy Policy and product documentation. You entrust us with that site data; you retain full ownership and control of it. We obtain no rights from you to your website data. We do not sell it and only share it with trusted service providers where necessary to operate and provide the service.
RevScope is designed to measure website usage and attribution in a privacy-friendly way. We minimize data collection. We do not sell visitor data, build advertising profiles, or use customer analytics data to train unrelated AI models. Depending on region and consent settings, measurement may use a first-party cookie or cookieless, server-side attribution. We do not store raw IP addresses for visitors.
The group of data subjects affected includes end-users of the controller’s websites that use the service. More detail is in our Privacy Policy and GDPR documentation.
Organizational and technical security measures
Visitor and account analytics data is processed and stored within the European Union. We use HTTPS in transit, access controls, private networking where appropriate, and secure backups. We take reasonable technical and organizational measures to protect visitor data from unauthorized access, disclosure, or misuse.
Processor’s obligations with respect to the controller
- RevScope processes visitor data only in accordance with documented instructions from the customer through use of the service and this DPA.
- RevScope will notify the customer without undue delay if an instruction appears to infringe applicable Data Protection Legislation.
- RevScope ensures confidentiality of visitor data.
- Authorized personnel may access visitor data where necessary to provide support, maintain the service, and ensure security.
- RevScope implements appropriate technical and organizational measures to protect visitor data.
- RevScope uses subprocessors where necessary to operate the service (including infrastructure and CDN providers such as Cloudflare). Those subprocessors are bound by data protection terms and may process data only to provide the services RevScope has retained them for. Material changes to subprocessors that process customer visitor data will be communicated via the service, email, or our website. The customer may object and terminate the agreement if necessary.
- RevScope will notify the customer of any personal data breach affecting customer visitor data without undue delay (and in any event no later than 48 hours after becoming aware of it) and take appropriate mitigation steps.
- RevScope does not modify or delete customer visitor data except as instructed through the service, required to provide the service, or required by law.
- RevScope will assist the customer, where reasonably possible, with data protection obligations and will forward data subject requests relating to customer visitor data to the customer when they are directed to us.
How we handle delete instructions
You can delete a site’s stats or close your account by contacting support or using account controls where available. Upon a valid deletion request, applicable visitor and site data will be permanently deleted without undue delay, except where we must retain records required by law (for example billing history). Deletion of analytics data is irreversible.
Customer undertakings and RevScope assistance
- Customer warrants that it has the necessary rights and lawful basis to provide visitor data for processing and to instruct RevScope to process it.
- Customer is responsible for determining the lawfulness of processing, providing privacy notices to data subjects, implementing appropriate safeguards on its websites, and notifying authorities where required.
Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the main service agreement between the parties, except to the extent Data Protection Legislation does not allow such limitation.
Duration and termination
This DPA is effective as of the effective date above, replaces any previously agreed data processing agreement between you and RevScope for the same subject matter, and may be updated from time to time. We will update the effective date when we make changes. Confidentiality obligations survive termination. Upon termination, RevScope will delete or return customer visitor data in accordance with the deletion section above, unless retention is required by law.
Acceptance
Use of the RevScope service constitutes acceptance of this DPA. No separate signature is required unless we agree otherwise in writing.
Contact
Questions about this DPA? Contact us: