DRAFT pending legal review. Not binding until reviewed by a lawyer.
Data processing agreement
Subject
itero processes, on behalf of the customer, behavioural data of the visitors of the customer's websites in order to run experiments and report results (GDPR art. 28).
Data and subjects
Visitors of the customer's websites. Pseudonymous identifiers, events, device, language and country. No special categories.
Security measures
EU hosting, encryption in transit, IP addresses discarded, access control with two-factor authentication for staff, audit log.
Sub-processors and retention
[LIST]. Data is retained 6 or 24 months depending on the plan and deleted afterwards.
Remaining clauses
[TO BE COMPLETED BY LAWYER]