Data processing agreement

Draft for the public beta. This page has not been reviewed by a lawyer yet.

This agreement applies between you (the “controller”) and the publisher of upTake (the “processor”) for the personal data of the visitors of your site. It forms part of the terms of use and meets Article 28 of the GDPR.

1. Roles

2. Purpose

Measuring the visits of your site, linking them to the posts, links and releases that caused them, linking payments to visits, and producing your reports.

3. Data processed

About the visitors of your site:

About your customers, through your Stripe key: the amount, currency, date and identifier of each payment, and the Stripe customer identifier. No card data, name or email address is read.

No special category of data (Article 9 GDPR) is meant to be processed. You must not send any through the script.

4. Duration and retention

5. Sub-processors

You authorise the following sub-processors. You will be told before one is added or replaced, and can object by closing your account.

Transfers outside the European Union: [À COMPLÉTER : mécanisme de transfert pour Vercel et Anthropic (clauses contractuelles types, Data Privacy Framework) à vérifier dans leurs propres DPA].

6. Security

7. Assistance, breaches and audits

8. End of the agreement

You can export your data from Settings. Deleting your account deletes your projects and their data from the database; copies in backups disappear as the backups expire.

9. Contact

[À COMPLÉTER : email de contact pour les questions de données personnelles]