TRACKLAYERv4.2
ProductIntegrationsPricingCompareComplianceSIGN INSTART
§ 00 · LEGAL · DATA PROCESSING AGREEMENT

Data Processing Agreement.

Version 2.1 · Effective 2026-01-01 · EU-standard SCCs incorporated by reference. This is the canonical, read-only copy. To countersign a copy for your records, email legal@tracklayer.io or use the in-app DPA signing flow.

§ 01

Parties

This Data Processing Agreement (“DPA”) forms part of the Subscription Agreement between TrackLayer Ltd., a Polish limited-liability company with offices at ul. Przykładowa 1, 00-001 Warsaw (“Processor”), and the subscribing customer identified in the TrackLayer dashboard (“Controller”).

§ 02

Scope and subject matter

The Processor processes personal data on behalf of the Controller solely for the purpose of providing the TrackLayer server-side tracking and analytics service. The categories of data are listed in Annex I (Article 28(3) GDPR).

§ 03

Nature of processing

The Processor collects, hashes, stores, enriches, and forwards event data submitted by the Controller via the TrackLayer pixel, webhook, or API. Processing includes deduplication, PII hashing, fan-out to Controller-configured third-party platforms, and ancillary operations necessary to operate the service.

§ 04

Categories of data subjects

End-users of the Controller's online store or website.

§ 05

Categories of personal data

  • Identifiers (email-hash, phone-hash, external_id)
  • Cookie identifiers (fbp, fbc, gclid, tl_fp)
  • Technical data (user-agent, IP, timestamp)
  • Commerce data (order ID, value, currency, line items)
  • Optional geographic data (city, postal code, country)
§ 06

Subprocessors

The Processor uses the subprocessors listed at /legal/subprocessors. The Controller is notified at least 14 calendar days before any new subprocessor is added. The Controller may object in writing during that period.

§ 07

International transfers

By default, all personal data is stored in the EU (eu-west-1, Frankfurt). Where the Controller elects a non-EU region, transfers are covered by the EU Standard Contractual Clauses (SCCs) dated 2021-06-04, incorporated by reference.

§ 08

Technical and organisational measures

The Processor maintains, without limitation:

  • SHA-256 hashing of PII at the edge before storage
  • TLS 1.3 in transit; AES-256 at rest
  • Role-based access control; least-privilege on all internal systems
  • Segregated production / staging / dev environments
  • Annual penetration test; continuous dependency scanning
  • Incident response plan; 72-hour breach notification
  • SOC 2 Type II audit in progress (Q3 2026)
§ 09

Data subject rights

The Processor provides an API endpoint (DELETE /v1/identity/{profile_id}) that cascades deletion across the identity graph, event store, delivery log, and downstream platform CAPIs. Response time is under two (2) minutes from request to completion.

§ 10

Breach notification

The Processor will notify the Controller of any Personal Data Breach affecting the Controller's data without undue delay and in any event within seventy-two (72) hours of becoming aware, via the email on file.

§ 11

Audits

The Controller may audit the Processor's compliance with this DPA once per twelve-month period, at the Controller's expense, on thirty (30) days' written notice. The SOC 2 report (once available) will satisfy such audit requests.

§ 12

Term and termination

This DPA remains in force for the duration of the Subscription Agreement. Upon termination, the Processor will delete or return all Personal Data within ninety (90) days, at the Controller's option.

§ 13

Governing law

This DPA is governed by the laws of Poland and interpreted in accordance with the GDPR. Disputes are subject to the exclusive jurisdiction of the courts of Warsaw.

TRACKLAYER
© 2026 · Warsaw · Amsterdam
A telemetry console
for your pixel.
Product
Server-side tracking
Identity resolution
Event intelligence
Anomaly detection
Data quality
AI agent
Resources
Pricing
Integrations
vs. Stape
vs. Elevar
vs. Converge
vs. GTM
Signal
status.tracklayer.io ● operational
hello@tracklayer.io
Compliance · SOC2 · GDPR
DPA · Subprocessors
SER. TLR-04-21·2026