Piqo Analyticspiqo
How it worksFeaturesPricingFAQ
Log inSign up
How it worksFeaturesPricingFAQLog inSign up

Data processing agreement

Fill in your details — the agreement on the right updates live. Download it as a PDF when you’re done.

Cookie mode — uses a first-party cookie for analytics; a consent banner is your responsibility.

Data Processing Agreement

Effective date: 28/07/2026 · Tracking mode: Cookie-based

This Data Processing Agreement (“DPA”) forms part of the agreement between [Customer company name] (the “Controller”) and MVP Stack LLC, operator of Piqo Analytics (the “Processor”), and governs the processing of personal data under the EU General Data Protection Regulation (GDPR), the UK GDPR, and — where it applies — the Swiss Federal Act on Data Protection (FADP).

01Roles of the parties

The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller’s documented instructions — this DPA and the Piqo Analytics Terms of Service constitute those instructions.

02Subject matter & duration

The Processor processes personal data to provide privacy-friendly web analytics and revenue-attribution services for the duration of the Controller’s subscription, beginning on the effective date above.

03Nature & purpose of processing

Collecting and aggregating website-visit data and payment-conversion data so the Controller can measure traffic and attribute revenue to traffic sources.

04Categories of data subjects

  • Visitors to the Controller’s website(s).
  • The Controller’s paying customers — for revenue and conversion attribution only.

05Categories of personal data

Analytics (cookie mode): a first-party piqo_visitor cookie containing a random 16-character identifier, stored on the visitor’s device for up to 12 months to keep visitor identity stable across sessions; together with page URL, referrer, UTM parameters, device/OS/browser type, and approximate geolocation (country, region, city) derived from IP. The IP address itself is not stored.

Because this mode sets a cookie, the Controller is responsible for obtaining any consent required under applicable law (e.g. the ePrivacy Directive) and for displaying a consent banner on its website. The Controller may switch the site to cookieless mode at any time in its Piqo Analytics settings.

Conversion tracking (Stripe / Polar / Paddle / Dodo / Creem / Lemon Squeezy): transaction amount, currency, the payment provider’s customer and payment identifiers, the customer email address as supplied by the payment provider, conversion country, and the anonymous visitor identifier linking the sale to the original visit. No card or payment-credential data is stored — that remains with the payment provider.

06Sub-processors

The Controller authorises the following sub-processors. The Processor will give 30 days’ notice before adding or replacing any sub-processor.

Sub-processorPurposeLocationGovernment access
Stripe, Inc.Payment processing & subscription billingUSAUS FISA 702 · CLOUD Act
Amazon Web Services (SES)Transactional email deliveryUSAUS FISA 702 · CLOUD Act
Cloudflare, Inc.CDN & DDoS protection for the trackerUSAUS FISA 702 · CLOUD Act
DigitalOcean, LLCServer hosting & databasesSingaporeSingapore PDPA
Google (Firebase Auth)Customer sign-in & account managementUSAUS FISA 702 · CLOUD Act

07International transfers

Personal data is hosted in Singapore (DigitalOcean). Where a sub-processor is located outside the EEA, the UK, or Switzerland, transfers are made under the European Commission’s Standard Contractual Clauses (SCCs) on the basis of Module Two (controller to processor), incorporated into this DPA by reference, with the UK Addendum and the Swiss adaptations (§14) applied where applicable. The Controller acts as data exporter and the Processor as data importer.

08Security measures

The Processor maintains appropriate technical and organisational measures including encryption in transit (TLS), access controls, an anonymous-by-default analytics design, and regular encrypted backups.

09Data subject rights

The Processor will assist the Controller in responding to data subject requests (access, erasure, rectification, portability) and will delete or return the relevant data on request within 30 days.

10Personal data breach

The Processor will notify the Controller without undue delay, and within 72 hours of becoming aware of a personal data breach affecting the Controller’s data.

11Deletion & retention

Event/analytics data is retained for up to 5 years from the date of the event, or until the Controller deletes it. On termination, the Processor deletes the Controller’s personal data within 30 days, except where retention is required by law.

12Audit

The Processor will make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for reasonable audits on request. Questions may be sent to [email protected].

13Transfer impact assessment

The Processor has assessed the risk that public authorities in the countries listed in §6 may seek access to personal data. That risk is low by design: event data contains no names, emails, or precise identifiers, and visitor identity is a salted, daily-rotating hash — so what the sub-processors hold is pseudonymised and of limited use to third parties. All data is encrypted in transit (TLS) and at rest, and access is limited to authorised personnel.

The §6 table records, for each sub-processor, its location and the principal government-access laws to which it may be subject — chiefly section 702 of the US FISA and the US CLOUD Act for US providers, and the Singapore PDPA for the hosting region. Transfers outside the EEA, UK, or Switzerland rely on the SCCs (§7). On request, the Processor will provide further information to support the Controller’s own transfer impact assessment.

14Swiss Federal Act on Data Protection (FADP)

This section supplements the DPA where the Controller is established in Switzerland and/or the FADP applies. Where it conflicts with the rest of the DPA, this section controls for such processing.

  • Applicable law. References to the GDPR are deemed to include the FADP to the extent the FADP applies, and “applicable data protection law” includes the FADP.
  • Standard Contractual Clauses. The SCCs incorporated under §7 apply on the basis of Module Two (controller to processor), with the Controller as data exporter and the Processor as data importer.
  • Swiss adaptations. For transfers governed by the FADP: (a) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); (b) references in the SCCs to the GDPR are read as references to the FADP to the extent it applies; and (c) the term “Member State” must not be read to deprive data subjects in Switzerland of the right to bring claims in their place of habitual residence.
Controller
[Signatory name]
[Signatory title], [Company]
Date: 28/07/2026
Processor
MVP Stack LLC
On behalf of Piqo Analytics
Date: 28/07/2026
Piqo Analyticspiqo

Privacy-first web analytics for indie devs, agencies, and SMBs.

Start free trial →

Product

  • Features
  • How to start
  • Pricing
  • Docs
  • Blog
  • FAQ
  • Roadmap

Account

  • Start free trial
  • Log in
  • [email protected]

Legal

  • Privacy
  • Terms

My products

  • Click Dash
  • Kagaz
  • SuperDev Pro
  • Maillayer
  • No Code Web Scraper
  • Post Scheduler
© 2026 MVP Stack LLC · Piqo Analytics