You already have a signed DPA. Section 14.1 of our Terms and Conditions is our Data Processing Agreement under Article 28(3) of the GDPR. It applies to every customer on every plan, including the Free plan, and takes effect when you accept the Terms. No separate signature is needed. This page explains what it means in practice. Where the two differ, Section 14.1 is the binding text.
1. What we process, and for how long
- Subject matter: Providing the VitalSentinel service.
- Duration: The term of your subscription, plus the retention periods in Section 12 of the Privacy Policy.
- Nature and purpose: Website performance monitoring, analytics, and alerting.
- Types of personal data: The categories listed in Sections 4.1 and 4.2 of the Privacy Policy. In summary: technical and performance measurements, a pseudonymous visitor and session identifier, country, and the page addresses, page titles, and event data your own website sends us.
- Categories of data subject: Visitors to the websites you monitor.
For your own account, billing, and support data we act as the controller, not as your processor. That data is covered by the Privacy Policy rather than by this page.
2. Your instructions
We process visitor data only on your documented instructions. Your instructions are the Terms, the Privacy Policy, and the settings you choose in the product: which domains you monitor, the sampling rate, the storage level, the integrations you connect, and whether page titles and site-search terms are stored at all. We do not use that data for our own purposes.
Two things are set by us rather than by you, and are the same for every customer: the pseudonymous visitor identifier is generated on our servers, and retention periods follow your plan rather than being configured per domain.
3. Security
The measures we have in place:
- TLS on every connection reaching us from outside: your browser, your website, and the third-party APIs we call
- Encryption at rest
- An isolated internal network with restricted access between services
- Access controls, activity logging, and two-factor authentication support
- Encrypted backups
- Personnel authorized to process the data are bound by a duty of confidentiality
One limit, stated because a security questionnaire will ask. We hold the encryption keys for data at rest, so we do not claim the data would be unreadable to someone who obtained it from us, and we do not describe the Service as end-to-end encrypted. If your assessment needs detail on our internal architecture, ask us directly and we will answer it under NDA rather than publish it.
4. Sub-processors
Accepting the Terms is your general authorization for us to engage the providers listed at vitalsentinel.com/subprocessors. That page states what each one receives and whose data it is, and it carries the date it last changed.
We give at least 30 days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the affected part of the service and receive a pro rata refund. We remain liable for our sub-processors' performance. Sub-processors are engaged on terms consistent with these.
5. Helping you answer a data subject request
We assist you with requests from your website visitors so far as is possible, taking into account the nature of the processing. What that means concretely is worth spelling out, because the limit is real and it is not a limit of tooling.
If you supply a visitor or session identifier, we can assemble or delete the records carrying it for one of your domains. Email privacy@vitalsentinel.com with the identifier, the domain, and a reference for the request.
We cannot derive the identifier for you. There is no path from a person, an email address, an IP address, or a description of a visit to a visitor identifier, and it is not reconstructable after the fact. Article 11 of the GDPR is the relevant provision: a controller who cannot identify a data subject is not required to acquire more data purely in order to comply.
How far one identifier reaches depends on the storage level you chose. In the default cookieless mode it addresses about one day of records. In "session" mode no visitor identifier is stored, so it addresses nothing. Only in "persistent" mode does it reach back, up to 180 days. A session identifier addresses a single visit. Aggregated report tables carry no visitor identifier at all.
An empty result is not proof that we hold nothing. If we search and find no records, the honest answer to give the requester is that we found none for that identifier, not that no data about them exists.
6. Deletion, and what it reaches
At the end of the service we delete or return the data, at your choice, except where EU or member state law requires us to keep it, and we delete existing copies in line with the retention periods in the Privacy Policy.
Deleting an account also:
- Anonymizes the customer record at our payment processor. It is not deleted, because invoices are statutory accounting records we are required to retain, and deleting the customer object would not remove them anyway
- Revokes our access to your Google account, so we no longer appear there as an authorized application
- Deletes workspace invitations addressed to that email address
- Deletes stored file attachments before the record pointing at them is removed
We should be clear about what deletion does not do. It does not automatically propagate to every recipient the data was previously disclosed to. The two paths above are specific integrations, not a general mechanism. If you need recipients notified of an erasure or rectification, tell us and we will work through the sub-processor list by hand.
7. Records of what we did
Routine operational log entries are kept for 30 days. Entries that evidence a privacy obligation – a visitor lookup or erasure, an account, workspace, or domain deletion, and similar actions – are kept for six years, because Article 5(2) of the GDPR requires us to be able to demonstrate that we carried them out. Those entries never store a visitor identifier itself.
8. Breach notification and audits
We assist you with Articles 32 to 36 of the GDPR, including security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of the processing and the information available to us.
We make available the information needed to demonstrate compliance with Article 28 of the GDPR and will contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once in any twelve-month period unless required by a supervisory authority or following a personal data breach, must be reasonable in scope and timing, must not compromise the security or confidentiality of other customers' data, and are at your cost.
9. What you are responsible for
Two obligations sit with you rather than with us, and both are easy to miss.
Consent for the storage level. Our default mode stores nothing on a visitor's device, which is why it can run without a cookie banner. If you raise the storage level to "session" or "persistent", that changes: those levels write to the visitor's device and read characteristics from it, and you must obtain valid consent before enabling them. We built the switch, but the choice to flip it is yours and so is the consent obligation that comes with it.
What your own site sends us. Page addresses, page titles, query strings, campaign parameters, and custom event properties are authored by your website, and they reach us as your site sends them. We replace recognizable patterns automatically – email addresses, payment card numbers, national ID numbers, tokens, long digit runs – but that is pattern matching, not comprehension. A name, a case reference, or a diagnosis in a page title or URL path is not recognized and is stored. If your site handles special categories of data under Article 9 of the GDPR, this matters: consider switching off page title and site-search storage for that domain in your analytics settings, which removes those fields at ingestion rather than filtering them.
10. International transfers
Where we transfer personal data outside the EEA, we do so under an adequacy decision or the European Commission's Standard Contractual Clauses. Where the Standard Contractual Clauses apply, they take precedence over any conflicting term in the Terms. The per-provider position, and the reason we are not yet publishing a location for each one, is set out on the sub-processors page.
11. A countersigned copy
Section 14.1 gives you the full protection of Article 28 of the GDPR without a signature, so most customers need nothing further. If your procurement process requires a countersigned standalone agreement, that is available on Enterprise and custom plans – email privacy@vitalsentinel.com.