Tracya
EN FR
← tracya.io
GDPR / Art. 28

Data Processing Agreement

Effective: July 21, 2026 - Version 2.0

⬇ PDF (EN) ⬇ PDF (FR)

This is an English translation provided for convenience. In the event of any discrepancy, the French version prevails.

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

ProcessorAthivia Labs SAS, operating under the "Tracya" brand. Centre d'Affaires, 29 Rue de Sarre, 57070 Metz, France. SIREN 104 290 911 R.C.S. Metz.
ControllerThe Client, meaning any natural or legal person who has accepted Tracya's Terms of Sale and uses the Tracya platform and JavaScript widget on its own application.

This DPA is incorporated by reference into Tracya's Terms of Sale and forms an integral part thereof. In the event of any conflict between this DPA and the Terms of Sale on a data protection matter, this DPA prevails.

Governing language. This DPA exists in French and English. In the event of any discrepancy in interpretation between the two versions, the French version prevails.

2. Subject matter and nature of the processing

The Controller uses the Tracya platform and JavaScript widget to create and deploy in-app onboarding flows for the end users of its own application. In doing so, Tracya, as Processor, processes personal data on behalf of and under the instructions of the Controller.

Categories of dataPseudonymous visitor identifier: a randomly generated UUID, stable per visitor and per project, stored in the end user's browser in order to relate a given visitor's measurements to one another. Onboarding flow events: flow started, step viewed, step completed, flow completed, flow abandoned. Timestamps.
Data subjectsEnd users and visitors of the Controller's application in which the Tracya widget is installed.
Nature of operationsCollection, storage, aggregation, analysis and deletion of behavioural flow data.
Special categoriesNone. Tracya does not process special-category data within the meaning of Art. 9 GDPR.

Tracya does not collect names, email addresses, IP addresses or device fingerprints relating to the Controller's end users. The visitor identifier is a technical pseudonym. It is not linked to any identity and serves only to compute onboarding metrics such as completion rate or step-level drop-off. State markers strictly necessary for the operation of the service, which remember which flows have already been shown, are also stored in the end user's browser and are not transmitted to the Processor.

Legal basis and end-user information. The Controller, in its capacity as data controller, determines the legal basis for the processing, informs its end users and obtains their consent where applicable law requires it, in particular under Article 82 of the French Data Protection Act on storing and accessing information in the user's terminal. The Processor provides the information necessary to enable the Controller to meet these obligations.

3. Purpose of the processing

Tracya processes the data listed in Article 2 only for the following purposes, as instructed by the Controller:

  • Providing the Controller with aggregated analytics on onboarding flow performance: completion rates, step-level drop-off, flow starts.
  • Enabling the Controller to improve the onboarding experience for its end users.
  • Detecting technical errors or anomalies in flow delivery.

Tracya does not process this data for its own purposes, nor for profiling, advertising or any purpose not documented in writing by the Controller.

4. Duration

This DPA enters into force on the date of acceptance (see Article 8) and remains in effect for the duration of the Controller's active subscription to the Tracya service. Upon expiry or termination of the subscription, Tracya retains the data for a maximum transitional period of 30 days before permanent deletion, unless the Controller requests earlier deletion or export under Article 5.7.

5. Obligations of the Processor (Art. 28.3 GDPR)

5.1 - Instructions only

Tracya processes personal data only on documented instructions from the Controller. These instructions result from the Controller's use of the Tracya platform, for example the choice of flows to deploy and events to track. If Union or Member State law requires Tracya to process data beyond these instructions, Tracya informs the Controller before the processing, unless the law prohibits it on grounds of public interest.

5.2 - Confidentiality

Tracya ensures that persons authorised to process the Controller's data have committed to confidentiality or are under an appropriate statutory confidentiality obligation. Access to data is limited to Tracya personnel needed to perform the service.

5.3 - Technical and organisational security measures (Art. 32)

Tracya has put in place the following measures to ensure a level of security appropriate to the risk:

  • Encryption in transit: all data is transmitted over HTTPS/TLS, with HSTS enforced.
  • Authentication: JWT access tokens valid for 15 minutes, rotating refresh tokens valid for 30 days, bcrypt-hashed passwords (cost factor 12).
  • Access control: two-factor authentication (TOTP) available for all accounts, superuser access required for administrative functions.
  • Infrastructure: hosted exclusively on Hetzner (Germany, EU). No end-user data leaves the EEA.
  • Network security: GeoIP-based IP blocking, rate limiting on all endpoints, hardened SSH (key-only authentication, non-standard port).
  • Application security: input sanitisation (DOMPurify), Content Security Policy, anti-clickjacking headers, SQL-injection protection through ORM-only queries.
  • Data minimisation: the visitor identifier is a pseudonym not linked to any identity, and no IP addresses are stored for widget events.
5.4 - Sub-processors

Tracya uses the following sub-processors to deliver the service:

Hetzner Online GmbH - Hosting & infrastructure
CountryGermany (EU)
DataAll platform data, including flow analytics
SafeguardProcessing within the EEA - no transfer mechanism required
OVH SAS - Transactional email
CountryFrance (EU)
DataThe Controller's email address, for platform notifications only
SafeguardProcessing within the EEA - no transfer mechanism required

Tracya informs the Controller of any intended change to sub-processors, whether an addition or a replacement, by email at least 14 days in advance, which gives the Controller the opportunity to object. If the Controller raises a legitimate objection that the parties cannot resolve, the Controller may terminate the subscription without penalty.

5.5 - Assistance with data-subject rights

Tracya assists the Controller, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights under Chapter III of the GDPR: access, rectification, erasure, restriction, portability and objection. To request assistance: admin@tracya.io.

5.6 - Assistance with security obligations (Art. 32 to 36)

Taking into account the nature of the processing and the information available to it, Tracya assists the Controller in meeting its obligations regarding security of processing (Art. 32), notification of personal-data breaches to the supervisory authority (Art. 33), communication of breaches to data subjects (Art. 34), data protection impact assessments (Art. 35) and prior consultation of the supervisory authority (Art. 36).

5.7 - Deletion or return of data at termination

Upon termination of the service, Tracya will, at the Controller's choice, either delete all personal data and certify such deletion in writing, or return all personal data in a machine-readable format, with a JSON export available from the dashboard. The Controller must make this choice within 30 days of termination. After this period, Tracya proceeds with permanent deletion.

5.8 - Audit cooperation

Tracya makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in this Article and allows for audits, including inspections, conducted by the Controller or an auditor it mandates. Tracya may require reasonable advance notice, of at least 30 days, and may charge reasonable costs for audit support that goes beyond standard compliance documentation. Tracya may also satisfy such requests by providing up-to-date third-party certifications or audit reports where available.

6. Personal-data breach notification

In the event of a personal-data breach affecting the Controller's data, Tracya notifies the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification is sent to the Controller's registered email address. It states, according to the information available at the time, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

7. International transfers

Widget analytics dataProcessed only within the European Economic Area (Hetzner, Germany). No transfer outside the EEA.
Transactional emailProcessed by OVH SAS, France (EU). No transfer outside the EEA.
Billing dataProcessed by Stripe Payments Europe, Limited (Ireland, EU), the Stripe contracting entity for an account domiciled in France. Stripe Technology Europe, Limited (Ireland) may be an additional party depending on the services used. The processing may also involve Stripe, Inc. (United States). This transfer is covered by the EU-U.S. Data Privacy Framework and/or by the European Commission's Standard Contractual Clauses, in accordance with Stripe's data processing agreement. This data concerns the Controller's own payment information, not its end users' data.

8. Acceptance

The Controller accepts this DPA in one of the following ways:

  • Electronic acceptance: by checking the "I agree to the Data Processing Agreement" box during registration on app.tracya.io. This constitutes a legally binding acceptance.
  • Signed PDF: the Controller may request a PDF version for wet or electronic signature by writing to admin@tracya.io. Use the PDF download buttons above to obtain a copy.

Continued use of the Tracya platform constitutes acceptance of the most recent version of this DPA. Tracya provides at least 30 days' notice of any material change.

9. Contact

For any question regarding this DPA, to exercise your rights, or to request a signed PDF copy: admin@tracya.io

Data protection queries may also be addressed to the supervisory authority: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr

10. Signature

For and on behalf of Athivia Labs SAS (Processor)

Name: Thomas Schneider

Title: Président

Company: Athivia Labs SAS

Date: July 21, 2026

Legal home Legal notice Terms of sale Privacy policy Security Acceptable use Accessibility FAQ Contact us Cookie preferences
Legal notice Terms of sale Privacy policy DPA Security Acceptable use Accessibility FAQ Contact us Cookie preferences

© 2026 Athivia Labs SAS - All rights reserved.