Skip to content

Data Processing Agreement (DPA)

Effective Date: 01.08.2026

Last Updated: 01.08.2026

This Data Processing Agreement ("DPA") forms an integral part of the SiteAlytic Terms of Service & License Agreement and applies whenever SiteAlytic processes Personal Data on behalf of a Customer.

This DPA is entered into between:

YSP LOGISTIK 2000 EOOD

Registration No.: 207700929

VAT No.: BG207700929

25 Shipka St., Plovdiv, Bulgaria

("Processor", "SiteAlytic", "we", "our", "us")

and

The Customer using the SiteAlytic Services

("Controller", "Customer", "you").

By using the Services, the Controller accepts this Data Processing Agreement.

1. Purpose of this Agreement

This Agreement governs the processing of Personal Data carried out by SiteAlytic on behalf of the Customer in connection with the provision of the SiteAlytic cloud-based Software-as-a-Service platform.

The parties intend this Agreement to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), the UK GDPR where applicable, and other applicable data protection laws governing processor relationships.

2. Definitions

Unless otherwise defined in the Terms of Service, the following definitions apply:

  • Controller means the legal person or organization determining the purposes and means of processing Personal Data.
  • Processor means SiteAlytic acting on behalf of the Controller.
  • Personal Data means any information relating to an identified or identifiable natural person.
  • Processing means any operation performed on Personal Data, including collection, storage, organization, consultation, transmission, deletion or destruction.
  • Subprocessor means a third party engaged by SiteAlytic to process Personal Data on behalf of the Controller.
  • Data Subject means the individual to whom Personal Data relates.
  • Security Incident means any confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by SiteAlytic.

3. Scope of Processing

SiteAlytic processes Personal Data solely for the purpose of providing the Services requested by the Controller.

Processing activities may include:

  • hosting Customer Data;
  • storing information;
  • organizing information;
  • displaying information to authorized Users;
  • synchronizing data;
  • transmitting information;
  • securing Customer Data;
  • creating backups;
  • generating reports;
  • maintaining audit logs;
  • providing technical support;
  • enabling collaboration;
  • operating Platform functionality;
  • restoring data following technical failures;
  • complying with legal obligations.

SiteAlytic does not process Personal Data for its own marketing purposes when acting as Processor.

4. Duration of Processing

Processing continues only for as long as:

  • the Customer maintains an active Account;
  • the Services are being provided;
  • SiteAlytic is required to retain information by applicable law;
  • retention is necessary to establish, exercise or defend legal claims;
  • backup retention periods have not expired.

Upon termination of the Services, Personal Data shall be handled in accordance with this Agreement, the Privacy Policy and the Account Deletion Policy.

5. Roles of the Parties

The Customer acts as the Data Controller with respect to Personal Data contained in Customer Data.

SiteAlytic acts as the Data Processor.

Nothing in this Agreement prevents SiteAlytic from acting as an independent Controller regarding information relating to:

  • website visitors;
  • subscriptions;
  • billing;
  • invoices;
  • payments;
  • customer support;
  • security logs;
  • legal compliance;
  • fraud prevention;
  • service administration.

Such processing is governed by the SiteAlytic Privacy Policy.

6. Controller Responsibilities

The Controller is responsible for ensuring that:

  • Personal Data has been lawfully collected;
  • appropriate notices have been provided;
  • valid legal bases exist;
  • required consents have been obtained where applicable;
  • Data Subjects' rights are respected;
  • uploaded Personal Data is accurate;
  • only necessary Personal Data is processed;
  • access permissions are managed appropriately.

The Controller remains responsible for determining:

  • why Personal Data is processed;
  • which Personal Data is uploaded;
  • who receives access;
  • applicable retention requirements;
  • compliance with sector-specific obligations.

7. Processor Obligations

SiteAlytic shall:

  • process Personal Data only on documented instructions from the Controller unless otherwise required by law;
  • ensure that persons authorized to process Personal Data are bound by confidentiality obligations;
  • implement appropriate technical and organizational measures;
  • assist the Controller where reasonably required;
  • notify the Controller of Security Incidents as required by this Agreement;
  • maintain records where required by law;
  • cooperate with supervisory authorities where legally required;
  • delete or return Personal Data upon termination as provided herein.

SiteAlytic shall not sell Customer Personal Data.

8. Categories of Personal Data

Depending on how the Services are used, SiteAlytic may process:

Identity Information

  • names;
  • usernames;
  • profile photographs;
  • employee identifiers;
  • job titles.

Contact Information

  • email addresses;
  • telephone numbers;
  • company addresses;
  • contact details.

Organization Information

  • company name;
  • registration numbers;
  • VAT numbers;
  • organizational structure;
  • roles;
  • permissions.

Project Information

  • project names;
  • construction site details;
  • schedules;
  • tasks;
  • materials;
  • equipment;
  • documents;
  • comments;
  • reports;
  • photos;
  • uploaded files.

Technical Information

  • IP addresses;
  • browser information;
  • authentication logs;
  • audit logs;
  • system events;
  • timestamps;
  • security records.

Billing Information

  • invoice information;
  • billing contacts;
  • subscription data;
  • payment status.

Payment card numbers and sensitive payment credentials are processed by Stripe and are not stored directly by SiteAlytic.

9. Categories of Data Subjects

Personal Data processed through the Platform may relate to:

  • employees;
  • contractors;
  • subcontractors;
  • consultants;
  • project managers;
  • technical managers;
  • administrative staff;
  • company representatives;
  • suppliers;
  • customers of the Controller;
  • authorized Platform Users;
  • other individuals whose Personal Data is lawfully uploaded by the Controller.

10. Instructions

SiteAlytic processes Personal Data only:

  • under the documented instructions of the Controller;
  • as necessary to provide the Services;
  • as required by applicable law;
  • as required to protect the security and integrity of the Platform.

If SiteAlytic believes that an instruction violates applicable data protection law, SiteAlytic may suspend the relevant processing and inform the Controller where legally permitted.

Where no documented instruction exists regarding a specific processing activity necessary for providing the Services, this Agreement, the Terms of Service and the Customer's use of the Platform shall constitute the Controller's documented instructions.

11. Confidentiality

All SiteAlytic personnel, contractors and authorized subprocessors with access to Personal Data are subject to appropriate confidentiality obligations.

Access to Personal Data is limited to individuals who require such access in order to perform their duties.

Confidentiality obligations continue after employment or contractual relationships end.

12. Technical and Organizational Security Measures

SiteAlytic implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access or other unlawful forms of Processing.

Such measures are designed taking into account:

  • the state of the art;
  • implementation costs;
  • the nature, scope, context and purposes of Processing;
  • the risks presented by Processing;
  • the likelihood and severity of potential harm to Data Subjects.

Depending on the Services provided, such measures may include:

  • encryption of data in transit using HTTPS/TLS;
  • logical access controls;
  • role-based permissions;
  • authentication controls;
  • password hashing where applicable;
  • audit logging;
  • security monitoring;
  • vulnerability management;
  • firewall protection;
  • infrastructure redundancy;
  • backup and disaster recovery procedures;
  • incident response procedures;
  • change management;
  • secure software deployment;
  • least-privilege access principles;
  • personnel confidentiality obligations;
  • periodic review of security practices.

SiteAlytic continually evaluates and may improve these measures without reducing the overall level of protection required by applicable law.

13. Confidentiality

SiteAlytic ensures that every employee, contractor, consultant or authorized person processing Personal Data:

  • is subject to confidentiality obligations;
  • receives access only where necessary;
  • processes Personal Data only for authorized purposes;
  • receives appropriate internal instructions regarding confidentiality and security.

Confidentiality obligations continue after termination of employment or contractual relationships.

14. Subprocessors

The Controller authorizes SiteAlytic to engage Subprocessors where reasonably necessary for providing the Services.

Current Subprocessors may include:

SiteAlytic may replace, remove or appoint additional Subprocessors where reasonably necessary.

Where required by applicable law:

  • Subprocessors will be bound by contractual obligations providing a level of protection substantially equivalent to this Agreement;
  • SiteAlytic remains responsible for the performance of its Subprocessors to the extent required by law.

The current list of Subprocessors may be updated from time to time as the Platform evolves.

15. International Transfers

Because SiteAlytic provides Services internationally, Personal Data may be processed outside the country in which the Controller or Data Subjects are located.

Where transfers outside the European Economic Area, United Kingdom or other protected jurisdictions occur, SiteAlytic shall implement appropriate safeguards where required by applicable law.

Such safeguards may include:

  • Standard Contractual Clauses approved by the European Commission;
  • UK International Data Transfer Addendum where applicable;
  • adequacy decisions;
  • contractual safeguards;
  • technical and organizational measures;
  • encryption;
  • access restrictions;
  • other lawful transfer mechanisms recognized by applicable legislation.

SiteAlytic will not transfer Personal Data in violation of applicable data protection law.

16. Assistance with Data Subject Requests

Taking into account the nature of the Processing, SiteAlytic shall provide reasonable assistance to the Controller in responding to requests from Data Subjects concerning:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent where applicable;
  • other rights granted by applicable law.

Where SiteAlytic receives a request directly from a Data Subject relating to Customer Data, SiteAlytic may:

  • refer the request to the Controller;
  • notify the Controller;
  • respond only where legally required.

The Controller remains responsible for determining how such requests should ultimately be handled.

17. Assistance with Compliance

SiteAlytic shall, taking into account the nature of the Processing and information available to it, provide reasonable assistance to the Controller regarding:

  • Data Protection Impact Assessments (DPIAs);
  • consultations with supervisory authorities where required;
  • compliance documentation;
  • information concerning security measures;
  • compliance with Articles 32–36 GDPR where applicable.

Such assistance shall be limited to information reasonably available to SiteAlytic.

Where assistance requires substantial manual work beyond ordinary support obligations, SiteAlytic may charge reasonable professional service fees, provided these are communicated in advance.

18. Personal Data Breaches

If SiteAlytic becomes aware of a confirmed Personal Data Breach affecting Customer Data, SiteAlytic shall notify the Controller without undue delay after becoming aware of the incident.

Where reasonably available, the notification may include:

  • description of the incident;
  • categories of affected Personal Data;
  • categories of affected Data Subjects;
  • likely consequences;
  • measures already taken;
  • measures proposed;
  • recommendations for the Controller;
  • contact details for further communication.

Where complete information is not immediately available, SiteAlytic may provide information in phases as investigations continue.

Notification of an incident does not constitute an admission of liability.

19. Audits

Upon reasonable written request, SiteAlytic shall provide the Controller with information reasonably necessary to demonstrate compliance with this Agreement.

Such information may include:

  • security documentation;
  • compliance summaries;
  • certifications where available;
  • organizational measures;
  • technical safeguards;
  • Subprocessor information.

Audits shall:

  • occur during normal business hours;
  • be subject to reasonable advance notice;
  • avoid disruption of other Customers;
  • protect confidential information;
  • comply with SiteAlytic security procedures.

Where an on-site audit is requested and legally justified, the parties shall cooperate in good faith to agree an appropriate scope.

SiteAlytic may refuse requests that:

  • compromise Platform security;
  • expose confidential information belonging to other Customers;
  • are repetitive or excessive;
  • are clearly disproportionate.

20. Return or Deletion of Personal Data

Upon termination of the Services, the Controller may, where technically feasible:

  • export Customer Data;
  • request deletion of Customer Data.

Following expiration of any applicable export period, SiteAlytic shall delete or anonymize Personal Data unless retention is required by:

  • applicable law;
  • accounting obligations;
  • tax obligations;
  • fraud prevention;
  • dispute resolution;
  • litigation;
  • backup retention cycles;
  • legal claims.

Deletion from active systems may not result in immediate deletion from backup media.

Backup copies shall continue to be protected until securely overwritten or destroyed.

21. Liability

Each party remains responsible for its own compliance with applicable data protection legislation.

Nothing in this Agreement shall:

  • exclude liability that cannot legally be excluded;
  • alter mandatory rights of Data Subjects;
  • reduce obligations imposed by applicable law.

Liability relating to the Services shall otherwise be governed by the SiteAlytic Terms of Service & License Agreement unless mandatory law requires otherwise.

22. Changes to this Agreement

SiteAlytic may update this Agreement where necessary to reflect:

  • changes in applicable law;
  • regulatory guidance;
  • new Platform functionality;
  • new Subprocessors;
  • infrastructure changes;
  • security improvements;
  • changes to business operations.

Where changes materially affect Processing, SiteAlytic shall provide reasonable notice before such changes become effective.

Continued use of the Services after the effective date constitutes acceptance of the revised Agreement, where permitted by applicable law.

23. Governing Law

This Agreement shall be governed by:

  • Regulation (EU) 2016/679 (General Data Protection Regulation), where applicable;
  • the UK GDPR, where applicable;
  • applicable national data protection legislation;
  • the laws of the Republic of Bulgaria.

Any dispute relating specifically to this Agreement shall be resolved in accordance with the dispute resolution provisions contained in the SiteAlytic Terms of Service & License Agreement.

24. Contact Information

Questions regarding this Agreement may be directed to:

SiteAlytic

Operated by:

YSP LOGISTIK 2000 EOOD

Registration No.: 207700929

VAT No.: BG207700929

25 Shipka St.

Plovdiv

Bulgaria

Email:

support.sitealytic@gmail.com

Websites:

https://sitealytic.com

https://app.sitealytic.com

25. Order of Precedence

In the event of any conflict between this Agreement and the SiteAlytic Terms of Service & License Agreement concerning the Processing of Personal Data, this Data Processing Agreement shall prevail to the extent of that conflict.

This Agreement shall be interpreted together with:

  • the SiteAlytic Privacy Policy;
  • the SiteAlytic Terms of Service & License Agreement;
  • the Account Deletion Policy;
  • any applicable Enterprise Agreement or Order Form.

Effective Date: 01.08.2026

Last Updated: 01.08.2026

We use cookies

We use cookies to ensure the proper functioning of the site, improve the user experience, and analyze service usage. You can accept all cookies, reject optional ones, or manage your preferences in our Cookie Policy.