Data Processing Agreement

Last updated: 6 August 2026

This agreement applies automatically to every customer who sends visitor data to UsageStory, and forms part of the Terms of Service. No signature is required. A countersigned copy for procurement is available on request through the contact form.

1. Roles

The customer is the data controller for visitor data collected through their projects. UsageStory is the data processor. UsageStory processes that data only on the customer's documented instructions, which the Terms of Service, this agreement, and the project's own settings together constitute. UsageStory does not process visitor data for its own purposes and does not sell it or use it to train models.

2. Subject matter and duration

Subject matter: providing web analytics and session replay. Duration: for as long as the customer's account remains open, plus the retention and backup periods in section 6.

3. Categories of data subjects and personal data

Data subjects: visitors to the customer's websites and apps, and the customer's own team members who use the dashboard.

Personal data: IP address (truncated when the project enables anonymisation), country, page and referrer URLs, device, operating system, browser, screen size, time on page, a randomly generated visitor and session identifier, session recordings with form input masked by default, and any account identifier or event data the customer chooses to send.

UsageStory does not require special-category data and asks customers not to send it. What reaches UsageStory through identify(), track(), or an unmasked recording is determined by the customer.

4. UsageStory's obligations

  • Process personal data only on the customer's documented instructions
  • Bind everyone with access to a duty of confidentiality
  • Maintain the technical and organisational measures in section 7
  • Engage sub-processors only under section 5
  • Assist the customer in responding to data subject requests
  • Assist with impact assessments and regulator consultations, to the extent applicable
  • Delete or return personal data at the end of the agreement, per section 6
  • Make available the information needed to demonstrate compliance
  • Notify the customer without undue delay, and at most within 72 hours, of a personal data breach affecting their data

5. Sub-processors

The customer gives general authorisation for the sub-processors below. UsageStory will give at least 30 days' notice by email before adding or replacing one, and the customer may object; if the objection cannot be resolved, the customer may terminate and receive a pro-rata refund of any prepaid fees.

Sub-processorPurposeLocation
DigitalOceanServer and database hostingLondon, United Kingdom
CloudflareEncrypted off-site backupsPer bucket jurisdiction
PostmarkAccount email (password resets)United States

Each sub-processor is bound by data protection obligations no less protective than these.

6. Retention and deletion

Session recordings are deleted automatically once they pass the project's retention period, 30 days by default. Pageviews and events are kept until the customer deletes the project or closes the account. Deleting a project removes its data from the live database immediately.

Encrypted backups are retained for up to 5 weeks and then overwritten, so deleted data can survive in backups until that cycle completes. On termination, live data is deleted within 30 days and backup copies expire on the same cycle. A written confirmation of deletion is available on request.

7. Security measures

  • TLS encryption for all data in transit, including every beacon from a host app
  • Encrypted backups, held separately from the primary database
  • Access to production restricted to named administrators using key-based authentication
  • Passwords stored only as salted hashes
  • Per-project write keys with an origin allowlist, revocable independently
  • Form input masked by default in session recordings
  • Optional IP truncation before storage, configurable per project
  • Role-based access within a workspace, so team members see only their organisation's projects

UsageStory is in beta and holds no independent security certification such as ISO 27001 or SOC 2. Customers requiring certified processors should factor this in.

8. International transfers

Primary storage is in London, United Kingdom. Transfers from the EEA to the United Kingdom rely on the European Commission's adequacy decision for the UK. Where a sub-processor places data outside the UK or EEA, that transfer relies on the Standard Contractual Clauses together with the UK Addendum where relevant.

9. Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, UsageStory will answer reasonable questions about its processing and provide documentation of the measures in section 7.

10. Customer responsibilities

The customer is responsible for having a lawful basis for collection, for giving visitors the notice their law requires, for obtaining consent where it is required, and for what they choose to send through identify(), track(), and unmasked recordings.

11. Contact

Data protection questions, sub-processor objections, audit requests, and deletion confirmations go through the contact form, choosing the "Data & privacy" topic.