atriqo
ProductScannerDemoDocsPricingContactBlog
EN ES
Log in Start for free
atriqo
Product Scanner Demo Docs Pricing Contact Blog
Language
EN ES
Log in Start for free

← Back to Atriqo

Atriqo Data Processing Agreement

Version 1.1 | 22 September 2026 | Pamplona, Spain

This Data Processing Agreement sets out the terms on which Atriqo processes personal data on the Customer's behalf when providing its web analytics service. It applies to every service plan, including the free plan. The annexes form part of this agreement.

1 Parties and acceptance

1.1 The parties are the business, organisation or natural person acting in a professional capacity identified as the Customer in the Atriqo account or applicable order (the Customer), and Iñigo Larrea Arina, a sole trader established in Spain, trading under the name Atriqo, NIF 72813588G, with a business address at Calle Monasterio de la Oliva 31, entreplanta, 31011 Pamplona (Navarra), Spain (Atriqo). Atriqo is a trade name and does not identify a separate legal entity.

1.2 This agreement (DPA) supplements the agreement governing the Customer's use of the Atriqo web analytics service (Service). It takes effect when accepted through the electronic contracting process or another agreement expressly incorporating it, before Atriqo begins processing personal data on the Customer's behalf. The person accepting confirms that they are authorised to bind the Customer. Atriqo shall make the accepted version available in a form that the Customer can store and reproduce.

1.3 Requests and notices to Atriqo under this DPA shall be sent to hello@atriqo.com. Atriqo shall send contractual and data protection notices to the contact email designated by the Customer in its account or order. The Customer shall keep that address current and monitored. Each party may update its contact details by written notice.

2 Scope definitions and roles

2.1 GDPR means Regulation (EU) 2016/679. Applicable Data Protection Law means the GDPR and national data protection legislation applicable to the processing, including Spanish Organic Law 3/2018 where applicable. Terms defined in the GDPR have the same meaning here.

2.2 Customer Personal Data means personal data processed by Atriqo on the Customer's behalf in providing the Service, as described in Annex 1. A Sub-processor is another processor engaged by Atriqo to process Customer Personal Data in providing the Service.

2.3 The Customer acts as controller and Atriqo as processor where the Customer determines the purposes and essential means of processing. Where the Customer acts as processor for an end controller, Atriqo acts as its sub-processor. The Customer shall hold the authorisations required to engage Atriqo and permit the further sub-processing described in this DPA, and shall transmit only instructions consistent with that controller's documented instructions. Atriqo's obligations apply correspondingly. The Customer coordinates communications with the end controller without restricting rights conferred directly by applicable law.

2.4 The Customer may provide this DPA and relevant processing information to the end controllers on whose behalf it acts. That disclosure does not, by itself, make them parties to the contract with Atriqo.

2.5 Atriqo's processing of account, subscription, payment and business contact data for its own purposes as controller is outside the scope of this DPA and is addressed in its privacy information. This exclusion does not remove Customer Personal Data from this DPA merely because it appears in a support request, diagnostic record or security record relating to processing on the Customer's behalf.

3 Instructions and responsibilities of the Customer

3.1 The Customer instructs Atriqo to carry out the processing described in Annex 1 through the features and configurations made available in the Service, including the authorised sub-processing and international transfer arrangements in this DPA. Further documented instructions relating to the agreed processing may be sent through the contact channel in Section 1.

3.2 Atriqo shall process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless Union or Member State law applicable to Atriqo requires otherwise. Atriqo shall inform the Customer of that requirement before processing unless the law prohibits such information on important grounds of public interest.

3.3 Atriqo shall immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. It may suspend the affected processing while the parties clarify or replace the instruction. If lawful processing cannot be resumed, either party may terminate the affected Service and Section 10 shall apply.

3.4 If an instruction requires a material change to the agreed Service or additional services, Atriqo shall explain the implications. Any change to the scope of the Service, implementation or charges requires the parties' agreement. This does not make compliance with mandatory obligations under this DPA conditional on purchasing additional services.

3.5 The Customer is responsible for the lawful basis, privacy notices and any consent or other authorisation required for its use of the Service; its entitlement to give instructions; the configuration of the data it submits; its selection of a necessary and proportionate retention period; and the security of its credentials and authorised users. These responsibilities do not relieve Atriqo of obligations applicable to it as processor.

3.6 The Customer shall not submit special categories of personal data under Article 9 GDPR or data relating to criminal convictions and offences under Article 10 through URLs, custom events or other inputs. It shall not submit direct identifiers or other personal data unnecessary for the agreed analytics purposes. Data inadvertently received remains protected by this DPA pending appropriate restriction, correction or deletion on documented instructions. Any processing beyond Annex 1 must be documented before it begins.

3.7 Atriqo may determine the practical technical and organisational means of providing the Service, subject to this DPA and lawful instructions. It shall not use Customer Personal Data for its own independent purposes, including its own advertising or profiling.

4 Confidentiality and security

4.1 Atriqo shall keep Customer Personal Data confidential. Persons authorised to process it shall be subject to a contractual or appropriate statutory duty of confidentiality and shall process it only as authorised for their functions. Confidentiality continues after the relevant authorisation or this DPA ends.

4.2 Atriqo shall implement and maintain the measures required by Article 32 GDPR, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals. Annex 2 describes the technical and organisational measures applicable to the Service.

4.3 Atriqo may update those measures to reflect technical developments, changes to the Service or identified risks, provided that changes do not reduce the protection required by Article 32 or materially reduce the overall level of security described in Annex 2. Atriqo shall provide updated information concerning material changes relevant to the Customer's assessment. Changes requiring instructions or sub-processor authorisation remain subject to this DPA's relevant procedures.

5 Subprocessors

5.1 The Customer gives Atriqo general written authorisation to engage the Sub-processors identified in Annex 3 for the activities described there.

5.2 Before a Sub-processor processes Customer Personal Data, Atriqo shall enter into a binding written agreement imposing the same data protection obligations as this DPA, as applicable to the processing entrusted to it, including sufficient guarantees concerning appropriate security measures. Atriqo remains fully liable to the Customer for the performance of its Sub-processors' data protection obligations.

5.3 Atriqo shall notify the Customer by email at least fourteen calendar days before an intended addition or replacement begins processing Customer Personal Data. The notice shall identify the provider, activities, relevant processing locations and applicable international transfer safeguards. If no objection is received within that period, the engagement is covered by the Customer's general authorisation.

5.4 The Customer may object within that period on reasonable data protection grounds. The parties shall seek a reasonable solution before the proposed processing starts. Atriqo is not required to provide a bespoke version of the Service or continue an affected Service indefinitely if no reasonable solution is available. If the objection cannot be resolved, either party may terminate the affected Service before the proposed processing begins, without an early termination penalty, and Section 10 shall apply. Atriqo shall not disclose the Customer's data to the disputed Sub-processor while the objection remains unresolved. An urgent change may instead proceed on the Customer's prior specific written authorisation.

5.5 Where necessary to avoid unauthorised processing while an objection or urgent replacement is being resolved, Atriqo may suspend the affected processing and shall inform the Customer without undue delay.

6 International transfers

6.1 The primary analytics database is hosted in Germany. The processing locations and transfer arrangements of authorised Sub-processors are described in Annex 3. Storage in the EEA does not, by itself, determine whether international access or onward processing occurs.

6.2 Atriqo shall transfer Customer Personal Data outside the European Economic Area, including by making it available to another recipient established there, only in accordance with documented instructions and Chapter V GDPR. Before a transfer begins, Atriqo shall ensure that an applicable adequacy decision or another valid Chapter V mechanism covers it. Where Standard Contractual Clauses are used, the appropriate clauses shall bind the relevant parties and any required assessment and supplementary measures shall be addressed.

6.3 Atriqo shall provide the information necessary for the Customer to assess the relevant arrangements and shall not commence, or shall suspend, a transfer for which the legal requirements cannot be met.

7 Assistance with rights and compliance

7.1 Taking account of the nature of processing, Atriqo shall assist the Customer through appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise rights under Chapter III GDPR.

7.2 Assistance requests shall use the contact channel in Section 1 and identify the relevant site, period and available identifiers to the extent reasonably necessary. Atriqo shall explain practical limitations arising from the data it holds. Atriqo is not required to collect additional data solely to identify a person where Applicable Data Protection Law does not require it. Atriqo shall promptly forward requests received directly concerning Customer Personal Data and shall not respond on the Customer's behalf unless authorised or legally required.

7.3 Taking account of the nature of processing and the information available to it, Atriqo shall also assist the Customer with Articles 32 to 36 GDPR. Assistance includes available information about processing, security and incidents, and appropriate cooperation with impact assessments and prior consultations.

7.4 The Customer shall promptly communicate requests and relevant legal deadlines. Atriqo shall provide assistance without undue delay and with regard to those deadlines. For work beyond ordinary Service functionality and included support, the parties may agree reasonable and proportionate charges in advance. Charges shall not prevent mandatory assistance or effective exercise of rights; urgent mandatory action shall not be delayed by a dispute over charges. Atriqo shall not charge the Customer for remedying its own non-compliance.

8 Personal data breaches

8.1 Atriqo shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, using the Customer's designated contact email. The initial notification shall not be delayed until the investigation is complete.

8.2 The notification shall include, to the extent known, the nature of the breach, the categories and approximate numbers of affected individuals and records, a contact point for further information, likely consequences, and measures taken or proposed to address the breach and mitigate adverse effects. Information may be provided in phases, with further relevant information supplied without undue delay as it becomes available.

8.3 Atriqo shall take appropriate measures to contain and address the breach and assist the Customer with Articles 33 and 34 GDPR. Notifications to authorities or individuals on the Customer's behalf require documented instructions unless applicable law requires Atriqo to act directly. A notification does not, by itself, constitute an admission of liability.

9 Information and audits

9.1 Atriqo shall make available the information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by it.

9.2 The parties shall ordinarily begin with available documentation, written responses or remote assessment where suitable. This does not prevent an inspection necessary to verify compliance. Routine audits may normally take place once in any twelve-month period, during reasonable business hours and on at least fourteen calendar days' notice. These arrangements do not restrict additional audits or shorter notice reasonably necessary following a Personal Data Breach, reasonable indications of non-compliance, material changes affecting the processing or a requirement of a supervisory authority.

9.3 Audits shall be proportionate, minimise unnecessary disruption and protect confidentiality, system security and other customers' information. Appropriate confidentiality and security arrangements may be required of an external auditor, but shall not prevent or unreasonably delay verification. Atriqo need not disclose unrelated personal data or permit access to unrelated areas, systems or information. Appropriate redaction or controlled access shall still permit verification of the relevant compliance matter.

9.4 The Customer shall bear its own audit and external-auditor costs. Any charges for extraordinary assistance by Atriqo must be reasonable, proportionate and agreed in advance, and shall not make the audit right ineffective. Atriqo shall not charge the Customer for remedying Atriqo's own non-compliance.

10 Retention return and deletion

10.1 Atriqo shall retain Customer Personal Data in accordance with Annex 1 and documented instructions. Expiry or cancellation of a paid subscription does not itself terminate processing where the Customer continues under an agreed free plan. Account closure or termination of the relevant processing Service activates the following provisions.

10.2 At the Customer's choice, Atriqo shall delete or return all Customer Personal Data still held on its behalf at the end of the Service and delete existing copies, unless Union or Member State law requires storage. By accepting this DPA, the Customer instructs deletion by default and may choose return before deletion is carried out.

10.3 During the Service, the Customer may use the self-service analytics export made available in the dashboard. As of this DPA version, CSV export is available on all plans and JSON export on Growth and higher plans. The standard self-service export intentionally excludes certain service-internal pseudonymous and technical identifiers, including visitor_hash, session_hash and site_id. Upon termination, where the Customer elects return, Atriqo shall make the standard export available and, on request, provide any remaining Customer Personal Data still held on the Customer's behalf and not contained in that export, to the Customer or its designated replacement processor in a reasonable, commonly used electronic format. Any supplementary return may be performed manually. Atriqo is not required to disclose cryptographic secrets, salts, private keys, authentication credentials, source code or other security-sensitive material used to generate or protect pseudonymous identifiers, nor to recreate data already lawfully deleted or information never retained, or develop a bespoke import tool for the recipient.

10.4 Annex 1 sets out the timing of return, active deletion and residual backup deletion. Pending deletion, residual copies remain protected under this DPA and excluded from ordinary processing. If a backup is restored, deletion instructions shall be reapplied before the restored data is used for ordinary processing. New backups or restorations shall not extend the agreed final deletion deadline.

10.5 Any continued storage required by applicable law shall be restricted to that requirement and end when it ceases. Where applicable Spanish law requires data to be returned to the Customer for legal retention, Atriqo shall do so. This DPA does not authorise continued analytics processing for the defence of legal claims. Atriqo shall confirm completion of return or deletion on request.

11 Liability

11.1 Each party is responsible for the obligations applicable to its role. Subject to the exceptions below and to the extent permitted by applicable law, Atriqo's total aggregate liability to the Customer for contractual damages under this DPA arising from events occurring in a Contract Year shall not exceed the greater of (a) EUR 1,000 and (b) the fees paid or payable by the Customer for the Service during the twelve months immediately preceding the first event giving rise to that liability in the Contract Year.

11.2 A Contract Year is each successive twelve-month period starting when the Customer accepts this DPA. Solely for allocating claims to a Contract Year, connected events shall be attributed to the year in which the first event occurred. The same loss may not be recovered more than once.

11.3 This limitation does not apply to fraud, wilful misconduct, gross negligence or liability that cannot lawfully be excluded or limited. It does not limit data subjects' rights under Article 82 GDPR, rights of recourse under Article 82(5), or the powers of supervisory authorities. Nothing in this section relieves Atriqo of its obligations or responsibility under Article 28(4). Applicable Standard Contractual Clauses prevail to the extent of a conflict.

11.4 This DPA does not create a separate contractual indemnity or liquidated-damages obligation in favour of either party. Each party remains subject to the obligations and liabilities imposed by applicable law.

12 Duration changes and precedence

12.1 This DPA remains effective for as long as Atriqo processes Customer Personal Data on the Customer's behalf, including the period needed to complete return or deletion after the Service ends. Confidentiality survives termination. Restrictions on retained copies continue for as long as relevant data is held. Termination does not affect rights arising from earlier processing.

12.2 Atriqo may propose revised versions by providing the text and explaining material changes. Publication alone does not amend the version already accepted. Contractual changes take effect through a valid agreement or acceptance process. Updates to Sub-processors and security measures follow the procedures specifically provided in this DPA.

12.3 For processing of Customer Personal Data, this DPA and its annexes prevail over conflicting Service terms, privacy notices or other documentation. Applicable Standard Contractual Clauses prevail where required by those clauses. An unenforceable provision shall not affect the remainder to the extent it can continue to operate lawfully.

13 Applicable law

13.1 This DPA is governed by the GDPR and, to the extent applicable, Spanish law, without prejudice to mandatory provisions of applicable law. Disputes shall be submitted to the courts having jurisdiction under the applicable procedural rules. Nothing restricts data subjects' rights to bring proceedings under Articles 79 and 82 GDPR or the jurisdiction and powers of competent supervisory authorities.

Annex 1 Processing details and retention

A Subject matter purpose and operations

The subject matter is the provision of web analytics for the websites designated by the Customer. The purpose is to measure traffic, page views and events on those websites and make the resulting analytics available to the Customer. Processing also includes the support, diagnosis, security and recovery activities necessary to provide that service on the Customer's behalf.

The processing consists of collection and transient use of incoming technical data, pseudonymisation, country-level geolocation, organisation, storage, aggregation, consultation, disclosure to authorised users and Sub-processors, return and deletion. Collection occurs when visitors generate supported page views or events; subsequent processing is ongoing during provision of the Service. The processing lasts for the agreed Service duration and the limited return and deletion periods below.

B Categories of individuals and personal data

The individuals concerned are visitors to the Customer's designated websites. Depending on the Customer's use, these may include its customers, registered users, prospects, employees or contractors visiting those websites or participating in the web events measured through the Service. Additional categories or purposes outside this description require documented instructions before processing begins.

The data may comprise the following, according to the enabled features and data actually submitted:

  • Pseudonymous visitor and session identifiers and their association with the relevant site and events.
  • Visitor IP address, used transiently for pseudonymisation and country-level geolocation, and user-agent information used to derive technical metadata and the pseudonymous identifier.
  • Event date and time, page address or path, referring page or source, campaign parameters, browser, operating system and device characteristics, screen width, language and country.
  • Custom event names and properties submitted by the Customer within the scope of the Service.
  • Technical request, site or event references and diagnostic information associated with those operations, where they constitute personal data; limited DNS metadata as described in Annex 3.

Special categories of data under Article 9 GDPR, criminal-offence data under Article 10 and unnecessary direct identifiers are not authorised inputs. Section 3.6 applies to any inadvertently received data. Pseudonymisation and aggregation do not, by themselves, establish that data has become anonymous.

C Retention during the Service

The following maximum retention periods apply to analytics event data in active systems, measured from the event date, unless the Customer instructs a shorter period:

Plan Analytics retention
Free 2 years
Starter 2 years
Growth 3 years
Business 5 years

The selected plan records the Customer's instruction for that retention period. The Customer shall assess whether the period is necessary for its purposes. It may request shorter retention through the contact channel in Section 1; handling may be manual. Atriqo shall implement lawful deletion instructions without undue delay, taking account of any applicable legal deadline. A change of plan does not authorise retaining data beyond the period applicable to the agreed replacement plan.

Technical diagnostics shall be retained only for as long as necessary for the relevant operational purpose. For Sentry error events, the standard retention under the free Developer plan is thirty days from ingestion. Events ingested during a trial may retain the longer period assigned when ingested, up to ninety days. These are the periods in Sentry's retention documentation; they do not delay earlier deletion required by lawful instructions. Atriqo shall make the applicable diagnostic and DNS retention information available to the Customer and give effect to deletion instructions. Diagnostic and DNS records are not authorised for the multi-year analytics retention periods merely because they support the Service.

D Return and deletion when processing ends

The Customer may communicate its choice of return or deletion to hello@atriqo.com at or before termination, or before deletion is carried out. The default instruction is deletion, as set out in Section 10.2.

The Customer may use the Service's standard self-service export before termination. As of this DPA version, it provides analytics-event exports in CSV on all plans and JSON on Growth and higher plans. The standard export excludes visitor_hash, session_hash and site_id. If the Customer elects return under Section 10.2, Atriqo shall make that export available and, on request, provide any remaining Customer Personal Data still held on the Customer's behalf that is not included in the standard export, in accordance with Section 10.3. The supplementary step may be performed manually.

Atriqo shall complete any elected return and deletion from the live analytics systems it administers within thirty calendar days after termination of the relevant processing Service. Data subject requests subject to a shorter legal deadline remain governed by Section 7.

Residual copies of those analytics systems in Atriqo's local and external backup repositories shall be deleted within a further four weeks, meaning twenty-eight calendar days, after deletion from the live systems, and no later than fifty-eight calendar days after termination. Atriqo shall use scheduled expiry or manual deletion as necessary to meet that deadline, including for retained object versions and repositories previously used for the data. The deadline is not extended by a failed or disabled backup job.

Where diagnostic or DNS records held by a Sub-processor contain Customer Personal Data, Atriqo shall promptly exercise the available deletion functions and issue any additional instructions needed to obtain return or deletion. Atriqo remains responsible for ensuring completion without undue delay and shall follow up until completion. Sending a deletion request does not itself constitute completed deletion.

Sentry's residual diagnostic backups follow a separate cycle: each backup is deleted within ninety days after its creation. The four-week period for Atriqo's analytics backup archives does not apply to those Sentry backups. The ordinary retention cycle does not excuse an avoidable delay in deleting active diagnostic records.

All residual copies remain protected, excluded from ordinary processing and subject to the restoration restrictions in Section 10.4. Atriqo shall not renew or extend their retention merely because deletion remains pending. It shall inform the Customer without undue delay of any material delay or inability to complete deletion as required and take appropriate corrective action. Any legally required continued storage is limited by Section 10.5. Atriqo shall provide the status of return or deletion, identifying outstanding provider operations, and confirmation when completed, on request.

Annex 2 Technical and organisational measures

The measures below apply to the processing described in Annex 1. Their implementation and review are governed by Article 32 GDPR and Section 4 of this DPA.

A Data minimisation and separation

Visitor IP addresses are used transiently to derive a pseudonymous identifier using an HMAC with a secret, the IP address, user-agent information and a daily salt. The salt changes daily. The IP address is also used for country-level geolocation against a locally installed MaxMind database and is discarded immediately after these operations. Atriqo does not store raw visitor IP addresses in its analytics records.

Daily salt rotation does not delete previously stored event records or establish that those records are anonymous. The Service keeps each site's analytics separate and does not link visitor identities across different sites. It does not use cookies to identify website visitors or perform device fingerprinting. The session cookie used for access to the Customer's Atriqo dashboard serves a separate account-access purpose.

B Transport and administrative access

The analytics endpoints and Customer dashboard use HTTPS with TLS, provided through Caddy and automatically renewed Let's Encrypt certificates. Administrative and database access is restricted. Server administration uses key-based SSH over a private network; the SSH administration port is not exposed to the public internet. Access to Customer Personal Data is limited to authorised persons who need it for their functions and are subject to the confidentiality obligations in Section 4.

C Backups and restoration

Atriqo maintains backup archives encrypted with age. The external upload process transfers encrypted archives. The current backup architecture retains seven daily backup generations locally and four weekly generations in each of two operational external repositories. Under normal scheduled operation, the external rotation cycle is approximately four weeks.

Atriqo currently operates two external backup repositories: Hetzner Storage Box in Falkenstein, Germany, and OVHcloud Object Storage in Paris, France (EU-WEST-PAR). Transfers to Hetzner use SFTP with host-key verification against a pinned key. OVHcloud Object Storage uses object versioning and a lifecycle rule configured to retain four generations. Both destinations receive backup archives encrypted by Atriqo before transfer. This description records the current architecture and does not create an availability commitment that both repositories will remain continuously reachable or unchanged; any replacement or material change is governed by Sections 4.3, 5 and 6 as applicable.

These arrangements do not provide immutable or WORM backup storage. The rotation description does not replace the termination deletion requirements in Annex 1, including deletion of retained versions.

Atriqo maintains documented recovery procedures covering three restoration routes and has completed and documented a full restoration test. Atriqo shall assess the effectiveness of recovery and other security measures at intervals appropriate to the risks and following material changes affecting those measures. This DPA does not establish a separate fixed recovery-time or recovery-point service level.

D Error diagnostics

Sentry is used for error diagnostics in both the Customer dashboard and the analytics collection service, with EU-region data storage. Before sending diagnostic information, Atriqo applies filtering that removes cookies, authorisation headers and URL query strings and redacts tokens embedded in paths. Default personal-data collection is disabled. These controls minimise disclosure; any remaining diagnostic information that constitutes Customer Personal Data remains subject to this DPA.

E Operational procedures

Atriqo shall restrict and review access as appropriate, address identified security weaknesses according to their risk, and maintain the information needed to demonstrate the measures applied. It shall manage incidents in accordance with Section 8 and keep appropriate records of the incident, measures taken and notifications.

Return may use the standard self-service export described in Section 10.3, supplemented manually where necessary to return remaining Customer Personal Data. Deletion and any supplementary return may use a manual procedure. That procedure shall identify the relevant Customer and sites, carry out the selected return or deletion, address active data and residual copies, prevent deleted data from re-entering ordinary use after a restoration, and record completion. Security measures may be updated only in accordance with Section 4.3.

Annex 3 Subprocessors and international transfers

A Authorised subprocessors

The following providers are authorised only for the activities specified here. Atriqo shall maintain the binding agreements and safeguards required by Sections 5 and 6 before making Customer Personal Data available to them.

Hetzner Online GmbH — Industriestrasse 25, 91710 Gunzenhausen, Germany. Hosting of the analytics service and databases and storage of encrypted backup archives through Hetzner Storage Box. Hosting and Storage Box are located in Falkenstein, Germany. This entry does not authorise relocation of Customer Personal Data outside the EEA. Hosting covers the data described in Annex 1; external backup content is encrypted before upload.

OVH HISPANO S.L.U. — Calle Alcalá 21, 5ª planta, 28014 Madrid, Spain. Operational external storage of encrypted backup archives through OVHcloud Object Storage in Paris, France, region EU-WEST-PAR. The archives contain copies of the data described in Annex 1 and are encrypted by Atriqo before upload. The backup and deletion provisions in Annexes 1 and 2 apply.

Functional Software Inc trading as Sentry — 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States. Error monitoring and diagnosis for the collection service and dashboard, insofar as the information concerns processing on the Customer's behalf. The filtering in Annex 2 applies. Data storage uses Sentry's EU region. The provider is established in the United States, and support or further processing may involve recipients outside the EEA within its documented processing chain. The safeguards in part C below apply. Diagnostic backup retention is described in Annex 1.

Cloudflare Inc — 101 Townsend Street, San Francisco, CA 94107, United States. Authoritative DNS only, insofar as personal DNS metadata is processed on the Customer's behalf to provide the Service. This metadata may include source-network information and information supplied by recursive resolvers. The Service does not use Cloudflare's HTTP proxy or CDN, and analytics HTTP request contents are not routed through Cloudflare under this configuration. Cloudflare operates distributed DNS infrastructure, including outside the EEA; part C below applies to the relevant transfers.

Scaleway SAS — 8 rue de la Ville-l'Évêque, 75008 Paris, France. Delivery of the analytics report emails the Customer subscribes to, which contain aggregate metrics and top pages and referrers derived from Customer Personal Data. Processing takes place in the Paris region (fr-par). Atriqo does not enable open or click tracking for these emails.

Further processing-chain information is available in Sentry's sub-processor list and Cloudflare's sub-processor list. Those lists describe the providers' wider services and do not mean that every listed activity is used for Atriqo. Atriqo shall maintain and make available the identities, contact details, processing countries and safeguards of further processors relevant to Customer Personal Data. Relevant changes remain subject to Section 5; an external webpage update does not by itself expand this DPA's purposes or scope.

B Backup repository use

As of this DPA version, Atriqo operates two external backup repositories: Hetzner Storage Box in Falkenstein, Germany, and OVHcloud Object Storage in Paris, France (EU-WEST-PAR). This describes the current processing architecture and does not constitute a service-level or continuous-availability commitment for either repository. Atriqo may replace or reconfigure a repository in accordance with Sections 4.3, 5 and 6, as applicable, while maintaining appropriate backup and recovery measures under Article 32 GDPR.

C Transfer mechanisms

Atriqo shall ensure that each transfer of Customer Personal Data outside the EEA, including relevant onward transfers and remote access, is covered by a valid mechanism under Chapter V GDPR.

For transfers to United States recipients, Atriqo may rely on the EU-US Data Privacy Framework only while the applicable adequacy decision remains valid and the recipient's current participation covers the transferred data. Where it does not apply, Atriqo shall establish appropriate safeguards under Article 46 GDPR before the transfer. These may include the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with the appropriate module, completed annexes and required assessments and supplementary measures. For transfers by Atriqo as processor to a sub-processor, Module 3 applies where those clauses are the applicable mechanism.

Sentry's published DPA and Cloudflare's published DPA contain transfer arrangements addressing these mechanisms. Atriqo shall ensure that the relevant provider agreement is binding and covers the processing concerned. Merely linking to published terms does not establish that contractual relationship. If an applicable mechanism ceases to provide the required protection, Atriqo shall implement a lawful alternative before continuing the affected transfer or suspend it.

D Providers and activities outside this DPA

MaxMind supplies the locally installed geolocation database. Country-level lookups occur on Atriqo's servers without disclosing Customer Personal Data to MaxMind. MaxMind is therefore not a Sub-processor for those lookups.

Stripe Payments Europe Limited, Scaleway SAS and Brevo support Atriqo's own payment administration, account emails (such as login codes) and scanner communications, as applicable. Scaleway delivers Atriqo's transactional emails; its delivery of the Customer's analytics reports is covered in part A above. Brevo stores the contact details of people who opt in to communications in Atriqo's scanner and does not send email. To the extent Atriqo determines the purposes of these activities as controller, they are outside this DPA and are addressed in its privacy information and arrangements with those providers.

Processing of dashboard or infrastructure data for which Atriqo or a provider determines its own purposes as controller is likewise addressed under the applicable privacy information. This does not exclude Customer Personal Data from this DPA merely because it appears in dashboard diagnostics or infrastructure records.

atriqo

Privacy-first web analytics, hosted in the EU. No cookies, no cross-site tracking, no fingerprinting.

Product

  • Product
  • Pricing
  • Demo
  • Cookie scanner
  • Docs

Legal

  • Privacy Policy
  • Terms of Service
  • DPA
  • Cookie Policy
  • Legal Notice

Connect

  • hello@atriqo.com
  • X · @larreaio
  • LinkedIn

Built in the EU. Privacy-first analytics — no cookies, no cross-site tracking, no fingerprinting.

© 2026 Atriqo