Data Processing Agreement
Article 28 GDPR in one document. The processor is Webcode, ul. Oleśnicka 17, 50-320 Wrocław, NIP 8431590186, REGON 021693410. This agreement takes effect when you create an account and needs no separate signature.
Effective from September 8, 2026
1. How this agreement is concluded
This agreement is concluded when you create a metuno account and accept the terms of service. It needs no separate signature and no returned scan; if your organisation requires a signed document, write to contact@metuno.com and we will send the same text in a signable form.
Where this agreement conflicts with the terms of service on the processing of personal data of Visitors, this agreement prevails.
2. Roles of the parties
For the data collected by the measurement script on your site you are the controller and we are the processor.
For your account data, that is the email address, display name and billing details, we are the controller. That part is not processing on your behalf and is described in the privacy policy.
3. Subject matter, duration and scope
- Subject matter
- Measuring traffic on your sites and making the resulting statistics available to you.
- Duration
- For as long as the service agreement is in force, that is until the account or the site is deleted.
- Nature and purpose
- Collecting events, storing them and computing reports on request. We do not profile, we make no automated decisions and we do not use this data for our own purposes.
- Categories of data subjects
- People visiting your sites.
- Types of data
- Page path, referrer with campaign parameters, browser and operating system name and version, device type and window width band, country, region and city, language, time zone, time on page, scroll depth, speed metrics, and a daily pseudonym and visit identifier.
- What is absent
- We store no IP address, no cookies, no user identifiers and no device fingerprint. The database schema has no columns for them.
4. Processing on documented instructions only
We process the entrusted data only on your documented instructions. Those instructions are: this agreement, the settings of your account and sites, and the queries the panel sends while you use it.
If Union or member state law requires us to process beyond your instructions, we will tell you before processing unless that law forbids it.
We will tell you if, in our view, an instruction of yours infringes data protection law.
5. Confidentiality
Access to entrusted data is limited to people who need it to deliver the service and who are bound by confidentiality.
We do not sell entrusted data, we do not share it with advertisers or data brokers, and we do not use it to train models.
6. Security measures
We apply technical and organisational measures appropriate to the risk, within the meaning of Article 32 GDPR. Below are the ones that can be verified from the outside or that follow directly from how the service is built.
- Traffic to the panel and to the event collector is encrypted.
- The network address is truncated before it enters the pseudonym calculation and is never stored. The database schema has no column for it.
- The pseudonym is computed with a daily salt that is deleted after two days, so linking visits across days becomes impossible for us as well.
- The site identifier goes into the pseudonym, so the same person on two sites has two different pseudonyms and cannot be tracked between them.
- The event collector, the only process exposed to the open internet, has no access to the account database or to passwords.
- Passwords are stored only as hashes.
- Servers are located in Warsaw, in an OVH data centre, with access limited to the people who need it.
- We take backups of account data. Measurement data, because of its volume, is not covered by backups on our side and you can download it yourself, as described below.
7. Copies of the data on your side
In the panel of every site we provide a download of a full copy of the raw events, month by month, in CSV format, within the history window of your plan. The tool works on the free plan as well and carries no extra charge.
Measurement data is not covered by our backups, so a failure may destroy it in whole or in part. If it has value to you beyond the day to day view of statistics, download it regularly and keep it yourself. We recommend once a month.
8. Sub-processors
You give general authorisation for our use of sub-processors. The current list is below. We will give at least thirty days notice before adding or changing one, and during that time you may object and terminate the agreement at no cost.
We impose on each of them data protection obligations no lower than those in this agreement and remain liable for their acts as for our own.
- OVH SAS, France
- The servers the service runs on. All of them are in Warsaw. This provider has access to entrusted data only to the extent that maintaining the infrastructure requires.
- Resend, Plus Five Five, Inc.
- Delivery of account emails: address confirmation, password reset, payment notices and, if the Customer turns them on, the weekly summary and traffic drop alerts. It receives the account owner email address and, in the summary and the alert, aggregated figures from the Sites: name, domain, visitor and pageview counts and a few of the largest sources. Individual events and Visitor pseudonyms do not reach it. Delivery runs in the Irish region.
- Mollie B.V., Netherlands
- Taking payments for the Pro plan. It receives the account owner billing details, never entrusted data from sites.
9. Transfers outside the EEA
Entrusted data never leaves the European Union under any circumstances. It sits on servers in Warsaw with no non EU service connected to it.
This concerns the data collected on your sites. The account owner email address, which is not entrusted data, is additionally processed by Resend under standard contractual clauses; the privacy policy describes this.
10. Assistance with data subject rights and controller duties
We will help you meet requests from data subjects to the extent our architecture allows. If a data subject contacts us directly, we will pass the request to you and will not answer it ourselves.
Note one limitation that follows from how the service is built rather than from unwillingness: the pseudonym expires after a day and the material needed to reconstruct it is deleted after two. Beyond that point we cannot locate one person data, because there is nothing left to search. In practice, access and erasure requests concerning older events are impossible for both sides, and that data is no longer data that identifies a person.
We will also assist with data protection impact assessments and prior consultations, where required, by providing the information about the processing that we hold.
11. Personal data breaches
We will notify you of a breach affecting entrusted data without undue delay after becoming aware of it, and no later than forty eight hours, to the account email address.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take. Where some of that information is not yet available, we will provide it in phases.
Notifying the supervisory authority and the data subjects is yours to do as the controller.
12. Deletion after the end of processing
When the service ends we delete the entrusted data. Deleting an account or a site in the panel drops the event tables rather than archiving them.
Events are additionally deleted automatically twenty five months after collection, whether or not the account still exists.
We keep no copy of entrusted data after deletion unless a statutory retention duty applies, and no such duty applies to measurement data.
13. Information and audits
On request we will make available the information needed to demonstrate compliance with Article 28 GDPR and will answer security questionnaires.
We are a small team and we do not offer on site audits or certifications we do not hold. Instead we describe how the service is built in enough detail to be assessed: what the script collects, what it does not, and why certain things are technically impossible for us.
14. Liability
Liability of the parties under this agreement is subject to the limitations set out in the terms of service, to the extent the law permits.
Those limitations do not apply to liability towards data subjects or to administrative liability, neither of which can be excluded by contract.
15. Contact
For data protection matters write to contact@metuno.com. We have not appointed a data protection officer because none of the conditions in Article 37 GDPR apply; correspondence on these matters is handled at that address.