Data Processing Addendum
Last updated 2026-09-26
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”, the controller) and Edge Case Studios, LLC (“Processor”) and applies when the Processor processes personal data in Customer Data on the Customer's behalf.
1. Scope and roles
The Customer is the controller and the Processor is a processor of personal data contained in Customer Data. The Processor processes it only to provide the Service and on the Customer's documented instructions, which are these Terms, this DPA, and the Customer's configuration of the Service.
2. Details of processing
| Subject matter | Website and app analytics, uptime monitoring, app metrics, alerts and reporting. |
|---|---|
| Duration | The term of the agreement, plus the deletion period in section 8. |
| Data subjects | Visitors to the Customer's sites and apps; the Customer's workspace members. |
| Categories of data | Page paths, referrer hostnames, UTM tags, device class, browser and OS family, country, a daily-rotating visitor hash, custom event names and properties, error messages, and app metrics. IP addresses are processed in memory only and not stored. |
| Special categories | None. The Customer must not send special-category data to the Service. |
3. Confidentiality
The Processor ensures that anyone authorised to process personal data is bound by confidentiality obligations.
4. Security
The Processor maintains appropriate technical and organisational measures, including: encryption in transit; encryption at rest of customer secrets; tenant isolation between workspaces; role-based access; hashing of sign-in tokens, sessions and IP addresses used for rate limiting; daily-rotating salts for visitor hashes, deleted after 2 days; audit logging of security-relevant actions; and dependency and secret scanning in its build process.
5. Subprocessors
The Customer authorises the subprocessors listed on the Subprocessors page. The Processor imposes data protection obligations on each subprocessor at least as protective as this DPA, remains responsible for their performance, and gives at least 30 days' notice of new subprocessors, during which the Customer may object on reasonable grounds.
6. Assistance
Taking into account the nature of the processing, the Processor helps the Customer respond to data subject requests and meet its obligations on security, breach notification, impact assessments and consultations with authorities.
7. Personal data breaches
The Processor notifies the Customer without undue delay, and in any case within[72] hours, after becoming aware of a personal data breach affecting Customer Data, with the information the Customer reasonably needs to meet its own obligations.
8. Deletion and return
Analytics data is deleted automatically at the end of the retention period of the Customer's plan. When the Customer deletes a site, a workspace or its account, the related data is permanently deleted after a 7-day recovery window, unless the law requires the Processor to keep it.
9. Audits
The Processor makes available the information reasonably necessary to demonstrate compliance with this DPA, and allows for audits by the Customer or an auditor it appoints, on reasonable notice and no more than once a year, unless a supervisory authority requires otherwise.
10. International transfers
[Transfer mechanism, e.g. EU Standard Contractual Clauses and UK Addendum: to be completed after legal review]
Contact
Edge Case Studios, LLC
Contact form