Legal

Data Processing Agreement

For customers who need one under GDPR or UK GDPR. It's part of our Terms automatically — there's nothing to sign. If your company needs a signed copy, email us.

Last updated October 12, 2026

1. Parties and roles

This agreement is between you, the customer (the controller), and Cool Analytics, run by Mohd Anas, India (the processor). It covers personal data we process on your behalf when your websites use Cool Analytics. It forms part of the Terms of Service.

2. What we process

  • Purpose: measuring visits to your websites and linking your payments to those visits, so you can see your traffic and revenue.
  • People: visitors of your websites, and your customers whose payments you connect.
  • Data: pages viewed, referrer and campaign tags, approximate location (country, region, city), browser, operating system, device, screen width, language, a random visitor ID stored in the browser, custom events you send, and — if you connect a payment provider — payment amounts, currency, and hashed customer emails or IDs.
  • Not processed: IP addresses are not stored, no cookies are set, and no special categories of data are collected.
  • Duration: for as long as you use Cool Analytics, then deleted as described below.

3. Our commitments

  • We only process the data to provide the service, following your documented instructions (your use of the product and its settings).
  • Anyone who can access the data is bound to keep it confidential.
  • We keep appropriate security measures in place (section 6).
  • We help you answer requests from people exercising their rights (access, deletion and so on), and with data protection impact assessments where needed.
  • We tell you without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting your data.
  • We never sell the data, use it for advertising, or combine it across customers.

4. Sub-processors

You allow us to use these sub-processors. We'll tell you at least 30 days before adding a new one, so you can object.

  • Hetzner Online GmbH — Germany — server hosting and storage.
  • Cloudflare, Inc. — global network — security, caching and approximate location of a connection.
  • Dodo Payments — payments for your Cool Analytics subscription (only your own billing details).

We make sure each sub-processor protects the data at least as well as this agreement requires.

5. International transfers

Data is stored in the EU (Germany). Where data is accessed or handled outside the EU/EEA or UK — including by us in India for support and maintenance — we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), which are incorporated into this agreement by reference.

6. Security measures

  • Encryption in transit (HTTPS) everywhere; payment provider keys encrypted at rest.
  • No IP addresses or cookies stored; visitor IDs are random.
  • Firewalled servers, automatic security updates and brute-force protection.
  • Access to production data limited to the owner, with SSH key login.
  • Nightly backups, kept for 14 days.

7. Deletion

You can delete a site or your account at any time. Its data is deleted within 30 days, and from backups within 14 days after that. You can export your data before deleting.

8. Audits

We'll answer reasonable written questions about how we protect your data and give you the information needed to show compliance with this agreement, once a year or after a breach.

9. Contact

Data protection questions or a signed copy: [email protected].

See your visitors live in a minute.

One line of code. No cookies. 7 days free.