Data processing agreement (DPA)
Updated August 30, 2026
Subject of processing
Metrimato produces visitor statistics for the customer from anonymised event data. The data is collected from the customer's site according to the customer's instructions.
Duration and nature of processing
Processing lasts for the term of the contract. Data is deleted once the retention period chosen by the customer ends, or immediately when the account is deleted.
Subprocessors
A data centre service in Finland, Lettermint for delivering account management messages, Stripe for the payment and invoicing of the Metrimato subscription, and Cloudflare Turnstile for bot protection on the public invite request form. Neither Stripe nor Cloudflare has any access to the analytics data of the tracked sites: Stripe processes the subscription to Metrimato and nothing else, and Cloudflare sees no customer data at all. The full list is on the security page.
Technical and organisational measures
- Anonymisation at the moment of receipt, identifying details are never written to disk
- Encrypted transfer
- Access control and a record of admin actions
- Automatic deletion of data once the retention period ends
Transfers outside the EU
The analytics data of the tracked sites is never transferred outside the EU/EEA. Neither is the customer data held in the service itself. Two named suppliers are the exception, and neither of them touches analytics data: Cloudflare protects the service's own invite request form against bots and sees the IP address of the person filling it in, and Stripe handles the payment of the Metrimato subscription as an Irish company whose group companies may process payment data outside the EU under standard contractual clauses. Stripe's processing covers the subscription only, never the analytics data of the sites.