Skip to content

Data processing agreement (DPA)

Updated August 28, 2026

Metrimato is built so that no personal data about site visitors is processed. In practice a data processing agreement is therefore not needed. We provide one anyway, for clarity, as part of the contract.

Subject of processing

Metrimato produces visitor statistics for the customer from anonymised event data. The data is collected from the customer's site according to the customer's instructions.

Duration and nature of processing

Processing lasts for the term of the contract. Data is deleted once the retention period chosen by the customer ends, or immediately when the account is deleted.

Subprocessors

A data centre service in Finland, Lettermint for delivering account management messages and Cloudflare Turnstile for bot protection on the public invite request form. Cloudflare sees no customer data and no visitor data. The full list is on the security page.

Technical and organisational measures

  • Anonymisation at the moment of receipt, identifying details are never written to disk
  • Encrypted transfer
  • Access control and a record of admin actions
  • Automatic deletion of data once the retention period ends

Transfers outside the EU

Customer data and the visitor data of the sites are not transferred outside the EU/EEA. The only supplier outside the EU is Cloudflare, which protects the service's own invite request form against bots and handles neither of those.