Data Processing Agreement

Version 1.0. Effective date: 29 August 2026.

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service. By accepting the Terms of Service you conclude this DPA, and no separate signature is required. A signed copy is available on request for customers whose procurement process requires one.

It is concluded under Article 28 of Regulation (EU) 2016/679 (GDPR) between the customer as the Controller and Tilen Ledic s.p., Zupanciceva ulica 2A, 8250 Brezice, Slovenia, as the Processor.

1. Subject matter and duration

1.1. This Agreement governs the processing of personal data carried out by the Processor on behalf of the Controller within the Enalitica service (order and lead analytics and attribution, reporting and related features), in accordance with Article 28 GDPR.

1.2. The Agreement applies for the duration of the subscription and ends upon deletion or return of the data under Section 9.

2. Nature and purpose of processing

2.1. The Processor processes personal data solely to provide the service: capture of attribution data on the Controller's websites, import and enrichment of orders or leads, computation of reports and metrics, sending of system notifications and, at the Controller's choice, forwarding of conversions to advertising platforms (server-side tracking).

2.2. The data types, categories of data subjects and duration are specified in Annex A.

2.3. The Processor does not use the Controller's personal data for its own purposes, for product development or for training artificial intelligence models. This does not cover aggregated statistics that contain no personal data and do not allow identification of the Controller or of any data subject.

3. Controller's instructions

3.1. The Processor processes personal data only on documented instructions from the Controller. Documented instructions are this Agreement, the settings the Controller selects in the application (enabled modules, scope of field capture, platform connections) and written instructions by email.

3.2. If the Processor considers an instruction to infringe the GDPR or other data protection law, it shall inform the Controller without delay.

3.3. The Controller warrants that it has a valid legal basis for the processing and has obtained all necessary consents, including consent for cookies and tracking on all of its websites, and that data subjects have been informed. Installing and correctly operating a consent management platform is the Controller's responsibility.

4. Confidentiality

4.1. Access to personal data is limited to persons who need it to provide the service and who are bound to confidentiality by contract or by law. The confidentiality obligation survives the end of the engagement.

5. Security of processing

5.1. The Processor implements the technical and organisational measures in Annex B, ensuring a level of security appropriate to the risk pursuant to Article 32 GDPR.

5.2. The Processor may update the measures, provided the overall level of security does not fall below the level described in Annex B.

6. Sub-processors

6.1. The Controller grants a general written authorisation for the engagement of the sub-processors listed in Annex C.

6.2. The Processor shall inform the Controller of any intended replacement or addition of a sub-processor at least 30 days in advance (email suffices). The Controller may object on reasonable data-protection grounds; if no solution can be found, the Controller may terminate the affected part of the service without notice period.

6.3. The Processor imposes on each sub-processor, by contract, data protection obligations at least equivalent to those in this Agreement and remains liable to the Controller for the sub-processor's performance.

6.4. Services the Controller connects with its own accounts (for example Google Ads, GA4, Google Search Console, Meta, LinkedIn, Mailchimp, payment and delivery providers) are not sub-processors of the Processor. The Controller's relationship with each such provider is governed directly with that provider.

7. Assistance to the Controller

7.1. Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures in fulfilling its obligations regarding data subject rights (access, rectification, erasure, restriction, portability, objection).

7.2. The Processor assists the Controller in complying with Articles 32 to 36 GDPR (security, breach notification, impact assessments), taking into account the nature of the processing and the information available to it.

7.3. If the Processor receives a data subject request directly, it forwards it to the Controller without undue delay and does not respond itself unless required by law.

7.4. For extensive or repeated assistance requests and for audits, the Processor may charge reasonable costs, notified and agreed in advance.

8. Personal data breach

8.1. The Processor notifies the Controller of a personal data breach without undue delay after becoming aware of it, as a rule within 48 hours, to the Controller's contact email address on the account.

8.2. The notification contains at least: a description of the breach, the likely categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. If not all information is available yet, it is provided in phases.

9. Deletion and return of data

9.1. After the end of the subscription the Processor, at the Controller's choice, returns the personal data in a machine-readable format or deletes them, within 30 days at the latest, unless EU or Member State law requires retention.

9.2. Data in backups are deleted through the regular backup rotation cycle, at most 30 days. Until then they remain protected by the measures in Annex B and are not processed for any other purpose.

10. Audits and evidence

10.1. The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR (description of measures, sub-processor list, responses to security questionnaires).

10.2. The Controller may, at most once per year, with at least 30 days' notice and during normal business hours, audit the processing under this Agreement, itself or through an independent auditor bound to confidentiality. An additional audit may be carried out after a demonstrated personal data breach. The audit must not endanger the security of other customers' data. Each Party bears its own audit costs.

11. Transfers to third countries

11.1. Processing takes place on servers in the EU (Annex B). Where a sub-processor in Annex C processes data in a third country, the transfer is based on a valid Chapter V GDPR mechanism (an adequacy decision or Standard Contractual Clauses). Where hashed values are transmitted to advertising platforms, only SHA-256 hashes are sent, never plaintext contact data.

12. United States state privacy laws

12.1. Where the Controller is subject to United States state privacy laws, the Processor acts as a service provider or processor as defined by those laws. The Processor does not sell or share personal data, does not retain, use or disclose it for any purpose other than providing the service, and does not combine it with personal data received from other sources except as permitted by those laws.

13. Liability and final provisions

13.1. The Parties' liability is governed by Article 82 GDPR and the limitations of liability in the Terms of Service, which do not apply to damage caused intentionally or by gross negligence.

13.2. This Agreement is governed by the law of the Republic of Slovenia. The competent court in Ljubljana has jurisdiction.

13.3. This Agreement forms an integral part of the Terms of Service. In case of conflict concerning personal data protection, this Agreement prevails.

Annex A: Description of processing

Categories of data subjects

  • the Controller's customers and prospective customers (website visitors, persons placing an order or submitting an enquiry)
  • for the document processing module: contact persons named on business documents (invoices, delivery notes) of the Controller's suppliers

Types of personal data

  • identification and contact data from orders or enquiries: name, email address, phone number, delivery address, enquiry message (where message capture is enabled)
  • purchase data: order contents and value, order history, payment and delivery status
  • attribution and technical data: advertising click identifiers (gclid, gbraid, wbraid, dclid, fbclid, msclkid, ttclid, li_fat_id), UTM parameters, first landing page, first referrer, device type, screen resolution, browser language, session duration, IP address in server logs
  • derived data: SHA-256 hash of the email address for cross-device linking and server-side tracking (the plaintext address is not stored for this purpose)

A Controller may reduce this set. Where the Controller's shop transmits contact identifiers only as SHA-256 hashes, no plaintext email address, phone number, name or address is received at all.

Special categories of data (Article 9 GDPR)

Not processed intentionally. The service is not designed to collect them.

Duration of processing

  • order and enquiry data: for the duration of the subscription
  • cross-device linking records (hashed email plus attribution): 90 days at most, deleted automatically each day
  • attribution data in the individual's browser: first-party cookies and localStorage, up to 90 days, under the Controller's own domain
  • after the end of the subscription: deletion or return under Section 9

Processing at the Controller's choice

Enabled in the application: server-side conversion forwarding (Meta Conversions API, Google Ads Enhanced Conversions; hashed contact data and click identifiers are transmitted), document processing, AI reports (aggregated sales and advertising data are transmitted).

Annex B: Technical and organisational measures

Infrastructure and network

  • Hosting on dedicated Hetzner servers in the EU, connected through a private network.
  • All public traffic over TLS. Certificates renewed automatically, Full (strict) mode.
  • Firewall: ports 80 and 443 reachable only through the protective proxy. SSH and administrative interfaces restricted to authorised IP addresses.
  • The database is not publicly reachable. Separate production and development environments, development access through a least-privilege database user.

Application security

  • Multi-tenant isolation: every data access is scoped to the tenant in code. A mandatory security checklist and automated security checks run before every release.
  • Authentication with expiring sessions, login rate limiting, account lockout, CAPTCHA and optional two-factor authentication.
  • The tracking script honours consent management platforms. Without consent it neither stores nor sends data.
  • Connection credentials (OAuth tokens, API keys) stored encrypted. Secrets managed centrally, never in source code.
  • Tenant-level data encryption: order personal data are encrypted at field level using envelope encryption, with keys held by a dedicated key management service on a separate host and a separate key per tenant. Access to encrypted data is recorded in an audit trail.
  • Email addresses used for cross-device linking are stored exclusively as SHA-256 hashes and deleted automatically after 90 days.
  • Error messages shown to users are generic. Details are logged server-side only, without sensitive content.

Backups

  • Daily backups, compressed and additionally encrypted with envelope encryption: every backup file has its own key, generated and wrapped by the key management service on a separate host, so the application server never holds the master key.
  • Retention 30 days, stored in the EU. Restore is an administrator-only operation and the restore procedure is tested.
  • On deletion the tenant's encryption keys are deleted as well, which renders any residual data unreadable.

Organisational measures

  • Production access is limited to a small circle of authorised persons bound to confidentiality, on a least-privilege basis.
  • Monitoring of operations and security signals with alerting. Documented incident handling procedure with notification under Section 8.
  • System software and dependencies kept up to date, with a vulnerability review on every dependency change.

Annex C: Sub-processors

Sub-processor Service Processing location Transfer basis
Hetzner Online GmbH Server and database hosting Germany, Finland (EU) No third-country transfer
Cloudflare, Inc. DNS, proxy, attack protection (data in transit only) EU points of presence Standard Contractual Clauses
Resend (Plus Five Five, Inc.) Transactional email delivery USA Standard Contractual Clauses
Anthropic, PBC AI report generation (aggregated data), only where the module is enabled USA Standard Contractual Clauses
OpenAI, L.L.C. AI report generation (aggregated data), only where the module is enabled USA Standard Contractual Clauses
Google Ireland Ltd AI report generation and document processing, only where the module is enabled EU, USA Standard Contractual Clauses

Anthropic, OpenAI and Google are used only where the Controller has enabled the corresponding module, and only aggregated data containing no personal data are transmitted to them. Where an AI module is enabled, only a paid provider account on which submitted data are not used for model training may be used.

Services connected with the Controller's own accounts (Google, Meta, LinkedIn, Mailchimp, payment and delivery providers) are not sub-processors, as set out in Section 6.4.

Contact

Questions about this Agreement, or a request for a signed copy:
Tilen Ledic s.p., Zupanciceva ulica 2A, 8250 Brezice, Slovenia
Email: [email protected]