Data Processing Agreement
Effective: July 21, 2026 - Version 2.0
This is an English translation provided for convenience. In the event of any discrepancy, the French version prevails.
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
This DPA is incorporated by reference into Tracya's Terms of Sale and forms an integral part thereof. In the event of any conflict between this DPA and the Terms of Sale on a data protection matter, this DPA prevails.
Governing language. This DPA exists in French and English. In the event of any discrepancy in interpretation between the two versions, the French version prevails.
2. Subject matter and nature of the processing
The Controller uses the Tracya platform and JavaScript widget to create and deploy in-app onboarding flows for the end users of its own application. In doing so, Tracya, as Processor, processes personal data on behalf of and under the instructions of the Controller.
Tracya does not collect names, email addresses, IP addresses or device fingerprints relating to the Controller's end users. The visitor identifier is a technical pseudonym. It is not linked to any identity and serves only to compute onboarding metrics such as completion rate or step-level drop-off. State markers strictly necessary for the operation of the service, which remember which flows have already been shown, are also stored in the end user's browser and are not transmitted to the Processor.
Legal basis and end-user information. The Controller, in its capacity as data controller, determines the legal basis for the processing, informs its end users and obtains their consent where applicable law requires it, in particular under Article 82 of the French Data Protection Act on storing and accessing information in the user's terminal. The Processor provides the information necessary to enable the Controller to meet these obligations.
3. Purpose of the processing
Tracya processes the data listed in Article 2 only for the following purposes, as instructed by the Controller:
- Providing the Controller with aggregated analytics on onboarding flow performance: completion rates, step-level drop-off, flow starts.
- Enabling the Controller to improve the onboarding experience for its end users.
- Detecting technical errors or anomalies in flow delivery.
Tracya does not process this data for its own purposes, nor for profiling, advertising or any purpose not documented in writing by the Controller.
4. Duration
This DPA enters into force on the date of acceptance (see Article 8) and remains in effect for the duration of the Controller's active subscription to the Tracya service. Upon expiry or termination of the subscription, Tracya retains the data for a maximum transitional period of 30 days before permanent deletion, unless the Controller requests earlier deletion or export under Article 5.7.
5. Obligations of the Processor (Art. 28.3 GDPR)
Tracya processes personal data only on documented instructions from the Controller. These instructions result from the Controller's use of the Tracya platform, for example the choice of flows to deploy and events to track. If Union or Member State law requires Tracya to process data beyond these instructions, Tracya informs the Controller before the processing, unless the law prohibits it on grounds of public interest.
Tracya ensures that persons authorised to process the Controller's data have committed to confidentiality or are under an appropriate statutory confidentiality obligation. Access to data is limited to Tracya personnel needed to perform the service.
Tracya has put in place the following measures to ensure a level of security appropriate to the risk:
- Encryption in transit: all data is transmitted over HTTPS/TLS, with HSTS enforced.
- Authentication: JWT access tokens valid for 15 minutes, rotating refresh tokens valid for 30 days, bcrypt-hashed passwords (cost factor 12).
- Access control: two-factor authentication (TOTP) available for all accounts, superuser access required for administrative functions.
- Infrastructure: hosted exclusively on Hetzner (Germany, EU). No end-user data leaves the EEA.
- Network security: GeoIP-based IP blocking, rate limiting on all endpoints, hardened SSH (key-only authentication, non-standard port).
- Application security: input sanitisation (DOMPurify), Content Security Policy, anti-clickjacking headers, SQL-injection protection through ORM-only queries.
- Data minimisation: the visitor identifier is a pseudonym not linked to any identity, and no IP addresses are stored for widget events.
Tracya uses the following sub-processors to deliver the service:
Tracya informs the Controller of any intended change to sub-processors, whether an addition or a replacement, by email at least 14 days in advance, which gives the Controller the opportunity to object. If the Controller raises a legitimate objection that the parties cannot resolve, the Controller may terminate the subscription without penalty.
Tracya assists the Controller, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights under Chapter III of the GDPR: access, rectification, erasure, restriction, portability and objection. To request assistance: admin@tracya.io.
Taking into account the nature of the processing and the information available to it, Tracya assists the Controller in meeting its obligations regarding security of processing (Art. 32), notification of personal-data breaches to the supervisory authority (Art. 33), communication of breaches to data subjects (Art. 34), data protection impact assessments (Art. 35) and prior consultation of the supervisory authority (Art. 36).
Upon termination of the service, Tracya will, at the Controller's choice, either delete all personal data and certify such deletion in writing, or return all personal data in a machine-readable format, with a JSON export available from the dashboard. The Controller must make this choice within 30 days of termination. After this period, Tracya proceeds with permanent deletion.
Tracya makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in this Article and allows for audits, including inspections, conducted by the Controller or an auditor it mandates. Tracya may require reasonable advance notice, of at least 30 days, and may charge reasonable costs for audit support that goes beyond standard compliance documentation. Tracya may also satisfy such requests by providing up-to-date third-party certifications or audit reports where available.
6. Personal-data breach notification
In the event of a personal-data breach affecting the Controller's data, Tracya notifies the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification is sent to the Controller's registered email address. It states, according to the information available at the time, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
7. International transfers
8. Acceptance
The Controller accepts this DPA in one of the following ways:
- Electronic acceptance: by checking the "I agree to the Data Processing Agreement" box during registration on app.tracya.io. This constitutes a legally binding acceptance.
- Signed PDF: the Controller may request a PDF version for wet or electronic signature by writing to admin@tracya.io. Use the PDF download buttons above to obtain a copy.
Continued use of the Tracya platform constitutes acceptance of the most recent version of this DPA. Tracya provides at least 30 days' notice of any material change.
9. Contact
For any question regarding this DPA, to exercise your rights, or to request a signed PDF copy: admin@tracya.io
Data protection queries may also be addressed to the supervisory authority: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr
10. Signature
For and on behalf of Athivia Labs SAS (Processor)
Name: Thomas Schneider
Title: Président
Company: Athivia Labs SAS
Date: July 21, 2026