Data Processing Agreement
Last updated: not yet published
Parties and roles
This agreement is between the customer, who is the controller, and Rahul Kumar, a sole proprietor established in India, who is the processor. It applies to personal data contained in session recordings made on the customer's websites. It forms part of the Terms of Service.
Subject matter and duration
We process recordings so that the customer can replay and analyse sessions on their own websites. Processing lasts for as long as the customer has an account, and each recording is kept for the retention window of the plan in force when it was made.
Nature and purpose of processing
Receiving recordings from the customer's websites, storing them, indexing them so they can be searched, serving them back to people the customer has authorised, and deleting them when their retention window ends or when the customer asks.
Categories of data subject
Visitors to the customer's websites, and the customer's own staff who use the dashboard.
Categories of personal data
- Page content as rendered, excluding what is masked on the device before sending.
- Interaction events: clicks, scrolls, navigation between pages.
- Page addresses, with the values of credential-carrying parameters removed.
- Browser family, operating system and device type, read from the request the browser sends, and the size of the browser window.
- An identifier supplied by the customer, or a random identifier we generate.
- Errors the page reported, which may include text from the page.
Special category data is out of scope. The customer must not use the service to record health, biometric, financial account or other special category data, and must mask any field that would capture it.
Our obligations
- We process personal data only on the customer's documented instructions, which the Terms and the product settings constitute.
- Everybody who operates the service is bound by confidentiality, and nobody can open a customer's recordings without a time-limited grant that names the individual and is recorded. Spectra is currently operated by one person, so that is the whole of the access list.
- We keep the security measures described below and will not reduce them during the agreement.
- We help the customer answer requests from data subjects. The dashboard can delete everything held about one person, one recording, or a whole site, and the customer can do that themselves without asking us.
- We tell the customer without undue delay if we become aware of a personal data breach affecting their data. We do so without undue delay and in any event within 72 hours of becoming aware, with what we know at the time, and we follow up as we learn more rather than waiting until the picture is complete.
- On termination we delete the customer's data, or return it first if they ask before deletion.
- We make available the information needed to demonstrate compliance and allow audits. A customer may audit once in any twelve months on 30 days' written notice, during business hours, at their own cost and subject to confidentiality, and more often than that if a supervisory authority requires it or following a personal data breach affecting their data. We will answer a security questionnaire in place of an audit where that satisfies the customer.
Security measures
- All traffic to the service is encrypted in transit.
- Form fields are masked on the visitor's device before anything is transmitted; passwords are never sent.
- Ingest keys are stored only as hashes, so a database copy yields no working credential.
- Access is scoped to a workspace and limited by role, with separate roles for reading, changing what is recorded, and destructive actions.
- Staff access requires a time-limited grant naming the individual, visible to the customer and revocable by them.
- We never collect or store visitor IP addresses. There is no column for one anywhere in the system, so the most common piece of personal data in web analytics is one we simply do not hold.
- Data is encrypted at rest, and recordings are held on managed storage in France and copied nowhere else.
- The infrastructure the service runs on is operated under ISO 27001 certification by its operator. Spectra's own processes are not yet separately audited, and we answer security questionnaires directly and in full.
Sub-processors
The customer authorises the sub-processors described by category in the Privacy Policy. We name each of them, and what they do, to any customer on request: write to privacy@spectra-trace.com and we will send the current list.
We give 30 days' notice by email before a new sub-processor starts processing. A customer may object within that period on reasonable data protection grounds. If we cannot resolve the objection, the customer may terminate the affected part of the service and we refund the unused portion of what they have paid. We will not start the new sub-processor on that customer's data while an objection is open.
International transfers
Recordings are stored in France, inside the European Economic Area, and running the service does not move them out of it. The account database and transactional email are handled by providers who may process data outside the EEA under their own data processing terms.
We are established in India, which has no adequacy decision, and the service is administered from there. Where the customer is a controller in the EEA or the United Kingdom, that access is a restricted transfer and is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two, controller to processor, and under the UK International Data Transfer Addendum where UK data is involved. Both are incorporated into this agreement by reference, and this agreement supplies the appendices they call for. We will send the executed clauses and the completed appendices to any customer who asks.
Alongside them we rely on the measures described above: data resides in the EEA rather than being exported, recordings are scoped to one workspace, nobody can open a recording without a time-limited grant that names the individual, and every grant is visible to the customer and revocable by them. We have never received a government request for customer data. If we receive one we will challenge it where there are grounds, and tell the customer unless the law forbids us from doing so.
Data subject requests
The customer can act on a request without contacting us: individual visitors' recordings can be deleted, a site and everything recorded under it can be deleted, and both remove the data wherever we hold it, including everywhere it is listed or searched. Where a request reaches us directly we pass it to the customer rather than acting on it ourselves.
Return and deletion
On termination, or on request, we delete the customer's recordings. Deletion is permanent and covers every copy we hold. Backups, where they exist, expire on their own schedule.
Deletion takes effect immediately wherever a recording is held, listed or searched, and there is no archived copy anywhere to outlive it, so for recordings immediate is the whole of it. Backups of account data roll off within 30 days, which is the longest a deleted record can persist anywhere. We do not restore a backup in order to recover data a customer has deleted.
Liability and precedence
Liability under this agreement is subject to the limit of liability in the Terms of Service, and the two form one aggregate cap rather than two separate ones, except where the law does not allow that. Where this agreement conflicts with the Terms of Service on the handling of personal data, this agreement prevails; on anything else, the Terms prevail. Where either conflicts with the Standard Contractual Clauses, the Clauses prevail.