Data Processing Agreement
Last updated: 2026-05-14
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Ankan Systems / Tracemetry ("Processor"). It applies when Processor handles Personal Data on behalf of Controller.
1. Scope & Roles
Controller determines the purposes and means of processing. Processor processes Personal Data only on documented instructions from Controller, which include the Terms of Service, this DPA, and Controller's use of the service.
2. Sub-processors
Processor uses the following sub-processors, listed in the Privacy Policy: Supabase, Stripe, Resend, OpenRouter, Exa, Firecrawl, Sentry, PostHog, Cloudflare, Hetzner/Hostinger. Processor remains liable for sub-processor performance.
3. Security Measures
Processor implements appropriate technical and organizational measures including: TLS in transit, encryption at rest via cloud provider, role-based access for staff, least-privilege service accounts, row-level security in the database, secrets stored in encrypted environment configuration, and periodic vulnerability review.
4. International Transfers
Personal Data may be transferred to the United States and the European Union. Standard Contractual Clauses apply where required.
5. Breach Notification
Processor will notify Controller without undue delay (and where feasible within 72 hours) after becoming aware of a Personal Data breach affecting Controller's data, including a description of the breach, categories of data affected, and mitigation steps.
6. Assistance
Processor will assist Controller with data-subject requests (access, correction, deletion, portability) and with data protection impact assessments to the extent reasonably required.
7. Audit
Once per 12 months and with 30 days' advance notice, Controller may request a summary of Processor's security measures and applicable certifications.
8. Deletion / Return
At Controller's written request following termination, Processor will delete or return all Personal Data within 30 days, except where applicable law requires retention.
9. Liability
The liability provisions of the Terms of Service apply to this DPA.
Contact
To execute a countersigned copy or ask DPA questions: privacy@tracemetry.com.