Data Processing Agreement
Between the Customer, as controller, and FI-DATA, a simplified joint-stock company (SAS) under French law with a share capital of €1,500, registered with the Auch Trade and Companies Register under number 900 033 622, whose registered office is at 80 rue Jean Jaurès, 32500 Fleurance, France, as processor, for the personal data processed through causalIT on the Customer's behalf. It implements Article 28 of Regulation (EU) 2016/679 (GDPR), forms part of the Terms of Service and is accepted electronically with them. A signed copy is available on request at contact@causalit.fr.
1. Scope and roles
The Customer determines the purposes and means of the audience measurement of its Sites and is the controller. FI-DATA processes the data solely on the Customer's behalf and documented instructions and is the processor. This agreement does not cover the Customer's account data, for which FI-DATA is itself the controller (see the Privacy Policy).
2. Description of the processing (Annex I)
| Item | Description |
|---|---|
| Subject matter | Measurement and analysis of the audience of the Customer's websites and applications |
| Duration | The term of the contract, plus the deletion period set out in section 9 |
| Nature | Collection through the tag, SDKs or API; storage; aggregation; computation of statistics and explanations; display; export; automatic deletion |
| Purpose | Providing the Customer with audience statistics and insights about its Sites |
| Data subjects | Visitors and users of the Customer's Sites |
| Categories of data | Page addresses (without query string), referrer, browser and operating system families, device type and screen size, language, approximate location (country, region, city) derived from the IP address and stored without it, date and time, custom events and properties defined by the Customer, a daily non-reversible visitor identifier. In identified mode only: a hashed user identifier supplied by the Customer. |
| Special categories | None. The Customer undertakes not to send any. |
3. Instructions
FI-DATA processes the data only to provide the Service as configured by the Customer in the application (sites, retention, goals, funnels, reports, identified mode), which constitutes the Customer's documented instructions. FI-DATA informs the Customer if an instruction appears to infringe data protection law. The Customer warrants that it has a lawful basis for the processing and informs data subjects as required.
4. Confidentiality
Persons authorised by FI-DATA to process the data are bound by a contractual obligation of confidentiality and access the data only when operations or support require it.
5. Security (Annex II)
- Data minimisation by design: no cookies, IP addresses used only in memory and never stored, daily per-site identifier salted with a global and a per-site secret, query strings stripped, user agent reduced to browser and OS families.
- Encryption in transit (TLS) for every connection, including the tag and the API.
- Authentication: passwords hashed with scrypt, API keys and tokens stored as SHA-256 hashes, rate limiting of login attempts, session revocation.
- Access control: role-based access within Organisations, restricted administration area, every administrator action on a Customer account logged — including impersonation for support.
- Infrastructure: hardened servers (key-only SSH, firewall, intrusion banning, automatic security updates), containerised services, secrets kept out of the code base.
- Backups: daily backups of the configuration database retained 14 days.
- Retention: per-site retention enforced by a daily purge job; 24-month ceiling; deleting a Site deletes its events.
6. Sub-processors (Annex III)
The Customer gives a general authorisation for the following sub-processors:
| Sub-processor | Processing | Location |
|---|---|---|
| OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France | Hosting of servers, databases and backups | France |
Payment processing by Stripe concerns the Customer's billing data, not the data covered by this agreement. FI-DATA informs the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by e-mail or in the application; the Customer may object on reasonable grounds within that period, in which case either party may terminate the affected Service. FI-DATA imposes the same data protection obligations on its sub-processors and remains liable for their performance.
7. Assistance to the controller
- Data subject requests: the application lets the Customer delete a Site, which erases all its events; on request, FI-DATA deletes the events tied to a given identifier in identified mode and assists with any other request the Customer receives, taking into account the nature of the processing.
- Security and impact assessments: FI-DATA provides the information reasonably needed for the Customer's obligations under Articles 32 to 36, including this agreement and its annexes.
- Personal data breach: FI-DATA notifies the Customer without undue delay, and at the latest 48 hours after becoming aware of a breach affecting the Customer's data, with the information available at that time, then completes it as the investigation progresses.
8. International transfers
The data is hosted and processed in France. FI-DATA does not transfer it outside the European Economic Area. Should a future sub-processor require such a transfer, it would be framed by an adequacy decision or by the European Commission's standard contractual clauses, and notified under section 6.
9. Deletion and return
The Customer can export statistics at any time (CSV and API). Audience events are deleted continuously according to the retention period set by the Customer, immediately when a Site is deleted, and at the end of the contract when the account is deleted. Backups expire within 14 days. FI-DATA does not keep copies beyond those periods unless Union or Member State law requires it.
10. Audits
FI-DATA makes available all information necessary to demonstrate compliance with this agreement. The Customer may conduct, at its own expense and no more than once a year, an audit by itself or by an independent auditor bound by confidentiality, with at least 30 days' written notice, during business hours and without disrupting the Service. Audit reports are confidential.
11. Liability, duration and law
The liability provisions of the Terms of Service apply to this agreement. It remains in force for as long as FI-DATA processes data on the Customer's behalf. It is governed by French law; in case of conflict with the Terms of Service, this agreement prevails for matters of personal data protection.
Last updated: August 21, 2026
← Back to home