Data processing agreement
Draft for the public beta. This page has not been reviewed by a lawyer yet.
This agreement applies between you (the “controller”) and the publisher of upTake (the “processor”) for the personal data of the visitors of your site. It forms part of the terms of use and meets Article 28 of the GDPR.
1. Roles
- You decide to install the upTake script on your site and to connect your Stripe account: you are the controller of that data.
- upTake processes it on your behalf, only on your documented instructions, which are these terms and the settings you choose in the app.
- For your own account data (email, projects), upTake is the controller: see the privacy policy.
2. Purpose
Measuring the visits of your site, linking them to the posts, links and releases that caused them, linking payments to visits, and producing your reports.
3. Data processed
About the visitors of your site:
- pages viewed, page titles, referring site and campaign parameters;
- country and city, type of device and browser;
- an anonymous identifier computed from the IP address and browser with a secret that changes every day. The IP address itself is never stored;
- a random identifier kept in the browser tab for the length of the visit;
- only if you turn the option on: a random identifier kept in the browser for 90 days;
- the signups and payments your site reports.
About your customers, through your Stripe key: the amount, currency, date and identifier of each payment, and the Stripe customer identifier. No card data, name or email address is read.
No special category of data (Article 9 GDPR) is meant to be processed. You must not send any through the script.
4. Duration and retention
- This agreement lasts as long as your account exists.
- Visits, link clicks and the signups reported by the script are deleted automatically after 13 months (395 days), every day.
- Payments imported from your payment provider are kept as long as the project exists: they are your revenue records and carry no visitor data.
- Everything is deleted when you delete the project or your account.
5. Sub-processors
You authorise the following sub-processors. You will be told before one is added or replaced, and can object by closing your account.
- Vercel Inc. (United States): hosting of the application and of the collection endpoint.
- Supabase Inc.: database and accounts, stored in the European Union (Ireland).
- Anthropic PBC (United States): writing of reports and drafts from aggregated numbers and titles. No visitor-level data is sent.
- PostHog Inc. (data hosted in the European Union): usage statistics of the upTake app, about your account only. No visitor data is sent.
- Resend (United States): delivery of the emails upTake sends you. No visitor data is sent.
Transfers outside the European Union: [À COMPLÉTER : mécanisme de transfert pour Vercel et Anthropic (clauses contractuelles types, Data Privacy Framework) à vérifier dans leurs propres DPA].
6. Security
- Data is encrypted in transit (HTTPS).
- Each account can only read its own projects (row level security in the database).
- The Stripe and GitHub access you provide is stored encrypted (AES-256-GCM) and never sent back to a browser.
- IP addresses, card data and source code are never stored.
- People with access to the data are bound by confidentiality.
7. Assistance, breaches and audits
- upTake helps you answer requests from the people concerned (access, deletion, objection), as far as the data allows a person to be found.
- upTake tells you without undue delay after becoming aware of a personal data breach that affects your data.
- On request, upTake gives you the information needed to show that this agreement is respected.
8. End of the agreement
You can export your data from Settings. Deleting your account deletes your projects and their data from the database; copies in backups disappear as the backups expire.
9. Contact
[À COMPLÉTER : email de contact pour les questions de données personnelles]