Legal

Data Processing Agreement

Last updated October 6, 2026 · WebTracko is operated by Xapp Digital Solutions

This agreement sets out how Xapp Digital Solutions processes the website visitor data that WebTracko collects on behalf of its customers, and the commitments we make to protect it.

1. Introduction and scope

This Data Processing Agreement (“DPA”) supplements the WebTracko Terms of Service between you (the “Customer”) and Xapp Digital Solutions (“WebTracko”, “we”). It applies whenever WebTracko processes personal data on the Customer's behalf in the course of providing the Service and that processing is subject to data protection law, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and comparable laws.

If there is a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.

2. Definitions

  • Controller — the Customer, who decides to install WebTracko on its websites and determines why visitor data is processed.
  • Processor — Xapp Digital Solutions, which processes visitor data only to provide the Service to the Customer.
  • Visitor Data — personal data about visitors to the Customer's websites that is collected by the WebTracko script and processed by the Service.
  • Sub-processor — a third party engaged by WebTracko that may process Customer personal data.
  • Personal Data Breach, Data Subject and Processing have the meanings given in the GDPR.

3. Details of the processing

ItemDescription
Subject matterProviding website analytics and real-time visitor observation to the Customer.
DurationFor as long as the Customer uses the Service, until deletion as described in section 7.
Nature and purposeCollecting, storing, analysing and displaying website usage to the Customer: live visitor lists, live visitor view, visitor journeys and historical analytics.
Data subjectsVisitors to the Customer's websites on which the WebTracko script is installed.
Categories of personal dataIP address (derived on our servers); country derived from the IP; random visitor and session identifiers stored in the visitor's browser storage; browser, operating system, device type, language, screen and window size; referrer and UTM campaign parameters; visited page URLs (without query strings) and titles; sampled pointer positions, clicks (position and element type, never text), scrolling and navigation with timestamps; and, only while the Customer watches a visitor live, a sanitized structural copy of the visible page held in memory.
Excluded dataKeystrokes, text typed into forms, form field values, passwords and payment details are never collected by the Service.
Special categoriesNone intended. The Customer must not use the Service in a way that collects special category data (see section 8).

4. Our obligations as processor

WebTracko will:

  • Process Visitor Data only on the Customer's documented instructions — which are the Terms of Service, this DPA and the Customer's configuration and use of the Service — unless required to do otherwise by law, in which case we will inform the Customer where legally permitted.
  • Never sell Visitor Data, use it for advertising, combine it across customers or use it to build profiles of individuals.
  • Ensure that personnel authorized to access Visitor Data are bound by confidentiality and access it only as needed to operate, secure and support the Service.
  • Implement the technical and organizational measures described in section 5.
  • Taking into account the nature of the processing, assist the Customer in responding to requests from data subjects exercising their rights, and with data protection impact assessments and consultations with supervisory authorities where required.
  • Notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Visitor Data, providing the information reasonably available to help the Customer meet its own notification obligations.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA (see section 9).

5. Technical and organizational measures

  • Hosting: the WebTracko application and database are hosted on servers located in Germany (European Union).
  • Encryption in transit: all communication between browsers, the collection endpoint, the API and the dashboard uses TLS (HTTPS).
  • Tenant isolation: all Visitor Data is stored per website and every dashboard request is authorized against the account that owns the website.
  • Data minimization: visits are recorded only after real user interaction; URL query strings are discarded; pointer movement is sampled; live page copies exist only in memory while being viewed and are sanitized to remove scripts, embedded frames and form values.
  • Collection controls: domain allow-listing, strict schema validation, payload size limits and rate limiting on the public collection endpoint.
  • Account security: passwords stored as salted bcrypt hashes, HTTP-only session cookies, one-time codes for sensitive account actions and rate-limited authentication.
  • Access control: production systems are accessible only to authorized personnel of Xapp Digital Solutions.
  • Customer controls: masking (data-wt-mask) and blocking (data-wt-block) of page elements, a visitor opt-out switch, domain restrictions and per-website pausing.

6. Sub-processors

The Customer gives general authorization for WebTracko to engage the following sub-processors:

Sub-processorPurpose and data
Infrastructure provider (Germany, EU)Hosting of the application and database, including Visitor Data.
Amazon Web Services — Simple Email ServiceDelivery of transactional emails to Customer account users. Processes account email addresses only; no Visitor Data.
StripeSubscription billing for Customers. Processes Customer billing data only; no Visitor Data.

We impose data protection obligations on each sub-processor that are no less protective than this DPA, and remain responsible for their performance. We will inform Customers of any intended addition or replacement of a sub-processor that processes Visitor Data at least 30 days in advance by email or in the dashboard. The Customer may object on reasonable data protection grounds; if we cannot reasonably accommodate the objection, the Customer may terminate the affected Service.

7. Deletion and retention

  • Visitor Data is retained while the corresponding website exists in the Customer's account, so historical analytics remain available.
  • When the Customer deletes a website, all Visitor Data for that website is permanently deleted from the live database.
  • When the Customer deletes its account, all websites and their Visitor Data are permanently deleted and any active subscription is cancelled.
  • Live page copies used for live viewing are discarded from memory shortly after viewing ends and are never stored.
  • Before deleting data, the Customer may ask us at info@xappdigital.com for reasonable assistance in obtaining a copy of its analytics.

8. Customer responsibilities

The Customer is responsible for the lawfulness of the processing it instructs, and in particular will:

  • Have a valid legal basis for collecting Visitor Data and, where required by law (for example the EU ePrivacy rules on storing information in a visitor's browser), obtain visitor consent before loading the WebTracko script.
  • Disclose its use of WebTracko, including live visitor observation, in its privacy notice.
  • Not install the script on pages that display special category data, health information, payment card data or other highly sensitive information, and use masking or blocking for any sensitive content on tracked pages.
  • Install the script only on websites it owns or is authorized to manage, and keep its account credentials secure.

9. Information and audits

On written request, we will provide information reasonably necessary to demonstrate compliance with this DPA, including answers to security questionnaires. Where that information is not sufficient, the Customer may, at its own cost, conduct an audit on at least 30 days' notice, no more than once per year, during business hours and subject to confidentiality, in a manner that does not compromise the security of other customers.

10. International transfers

Visitor Data is stored and processed in the European Union. Where Customer account data is processed by a sub-processor outside the European Economic Area, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, together with any supplementary measures required.

11. Liability

Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where such limitations are not permitted by law.

12. Duration and termination

This DPA takes effect when the Customer starts using the Service and remains in force for as long as WebTracko processes Visitor Data on the Customer's behalf. Confidentiality obligations survive termination.

13. Acceptance

By creating an account and using the Service, the Customer accepts this DPA; no separate signature is required. Customers who need a countersigned copy for their records can request one at info@xappdigital.com.

14. Contact

Questions about this DPA or data protection at WebTracko: info@xappdigital.com. See also our Privacy Policy and Compliance overview.